From ba099643cb2805403d43740e1b2b36ae8fc1a7d8 Mon Sep 17 00:00:00 2001 From: Sourav Mohapatra Date: Wed, 18 Mar 2020 10:48:40 +0530 Subject: [PATCH] qcacld-3.0: Return success for sched_scan_stop Presently in the driver, the function __cfg80211_stop_sched_scan clears rdev->sched_scan_req only when the sched_scan_stop returns success. If it returns a failure, then its next invocation due to the clean up of the second interface will have the dev pointer corresponding to the first one leading to incorrect memory access. To resolve this issue, return 0 for stop_sched_scan irrespective of the return status. Change-Id: I129e3e9c6d9f6a688d0aa97be120ba9731e8df37 CRs-Fixed: 2623160 --- core/hdd/src/wlan_hdd_scan.c | 22 ++++++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/core/hdd/src/wlan_hdd_scan.c b/core/hdd/src/wlan_hdd_scan.c index a613b146764c..9fd7dd2d240e 100644 --- a/core/hdd/src/wlan_hdd_scan.c +++ b/core/hdd/src/wlan_hdd_scan.c @@ -1489,7 +1489,16 @@ int wlan_hdd_cfg80211_sched_scan_stop(struct wiphy *wiphy, osif_vdev_sync_op_stop(vdev_sync); - return errno; + /* The return 0 is intentional. We observed a crash due to a return of + * failure in sched_scan_stop , especially for a case where the unload + * of the happens at the same time. The function + * __cfg80211_stop_sched_scan was clearing rdev->sched_scan_req only + * when the sched_scan_stop returns success. If it returns a failure , + * then its next invocation due to the clean up of the second interface + * will have the dev pointer corresponding to the first one leading to + * a crash. + */ + return 0; } #else int wlan_hdd_cfg80211_sched_scan_stop(struct wiphy *wiphy, @@ -1507,7 +1516,16 @@ int wlan_hdd_cfg80211_sched_scan_stop(struct wiphy *wiphy, osif_vdev_sync_op_stop(vdev_sync); - return errno; + /* The return 0 is intentional. We observed a crash due to a return of + * failure in sched_scan_stop , especially for a case where the unload + * of the happens at the same time. The function + * __cfg80211_stop_sched_scan was clearing rdev->sched_scan_req only + * when the sched_scan_stop returns success. If it returns a failure , + * then its next invocation due to the clean up of the second interface + * will have the dev pointer corresponding to the first one leading to + * a crash. + */ + return 0; } #endif /* KERNEL_VERSION(4, 12, 0) */ #endif /*FEATURE_WLAN_SCAN_PNO */