From 8694f8c885eb0d924d60f427cc0f9fba68adab0c Mon Sep 17 00:00:00 2001 From: Tejas Prajapati Date: Thu, 17 Dec 2020 11:39:11 +0530 Subject: [PATCH] msm: camera: reqmgr: check validity of last_applied_idx last_applied_idx is updated on every successful applied request and the buf_done. After buf_done last_applied_idx is set to -1. While accessing last applied req the same index is used, if the last_applied_idx is -1 accessing last applied request will result in slab out of bound error, so check last_applied_idx before accessing last applied request. CRs-Fixed: 2840329 Change-Id: I8f49b9df097859cde20e651149167db7316976bb Signed-off-by: Tejas Prajapati --- drivers/cam_req_mgr/cam_req_mgr_core.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/cam_req_mgr/cam_req_mgr_core.c b/drivers/cam_req_mgr/cam_req_mgr_core.c index 646cb6783f54..78be9bcf3e2d 100644 --- a/drivers/cam_req_mgr/cam_req_mgr_core.c +++ b/drivers/cam_req_mgr/cam_req_mgr_core.c @@ -2072,7 +2072,9 @@ static int __cam_req_mgr_process_sof_freeze(void *priv, void *data) in_q = link->req.in_q; if (in_q) { mutex_lock(&link->req.lock); - last_applied_req_id = in_q->slot[in_q->last_applied_idx].req_id; + if (in_q->last_applied_idx >= 0) + last_applied_req_id = + in_q->slot[in_q->last_applied_idx].req_id; mutex_unlock(&link->req.lock); }