From c36b185506b020fde547a7998990a923af132c4f Mon Sep 17 00:00:00 2001 From: Vinayaka B M Date: Fri, 22 Apr 2022 08:02:54 +0530 Subject: [PATCH 1/3] msm: ipa: Set the logbuf NULL after destroy Set the ipa3_ctx->logbuf NULL after destroy,or IPAERR will use the ipa3_ctx->logbuf after free it, that can make crash Change-Id: I470c4a043d426d7620c01fadac1f1cd12ad54b08 --- drivers/platform/msm/ipa/ipa_v3/ipa.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/platform/msm/ipa/ipa_v3/ipa.c b/drivers/platform/msm/ipa/ipa_v3/ipa.c index b95f98e5da48..c0d813316098 100644 --- a/drivers/platform/msm/ipa/ipa_v3/ipa.c +++ b/drivers/platform/msm/ipa/ipa_v3/ipa.c @@ -7947,8 +7947,10 @@ fail_mem_ctrl: kfree(ipa3_ctx->ipa_tz_unlock_reg); ipa3_ctx->ipa_tz_unlock_reg = NULL; fail_tz_unlock_reg: - if (ipa3_ctx->logbuf) + if (ipa3_ctx->logbuf) { ipc_log_context_destroy(ipa3_ctx->logbuf); + ipa3_ctx->logbuf = NULL; + } fail_uc_file_alloc: kfree(ipa3_ctx->gsi_fw_file_name); ipa3_ctx->gsi_fw_file_name = NULL; From 9c3cb3f994df6753804a868739fda1eb51417658 Mon Sep 17 00:00:00 2001 From: Ashok Vuyyuru Date: Fri, 15 Apr 2022 11:46:09 +0530 Subject: [PATCH 2/3] msm: ipa3: Reduce the QMI timeout value to avoid race condition In SSR scenario if QMI response delayed SSR events getting timeout, To avoid this issue reduce the QMI timeout value from 60sec to 10sec. Change-Id: Ib0113a91f9bd60b3ea0e374bf249d4859a22a040 Signed-off-by: Ashok Vuyyuru --- drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c b/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c index ae02f21d11de..1ae4f5699f29 100644 --- a/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c +++ b/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c @@ -27,7 +27,7 @@ #define IPA_Q6_SERVICE_INS_ID 2 #define QMI_SEND_STATS_REQ_TIMEOUT_MS 5000 -#define QMI_SEND_REQ_TIMEOUT_MS 60000 +#define QMI_SEND_REQ_TIMEOUT_MS 10000 #define QMI_MHI_SEND_REQ_TIMEOUT_MS 1000 #define QMI_IPA_FORCE_CLEAR_DATAPATH_TIMEOUT_MS 1000 From 1a79536d0ec22a533b8fcb99dd53e9cc32d0cd1f Mon Sep 17 00:00:00 2001 From: Raghavendar rao l Date: Mon, 14 Mar 2022 20:19:10 +0530 Subject: [PATCH 3/3] msm: ipa3: Handle race condition to avoid NULL access Updated change to avoid race condition and NULL pointer access, In case of SSR and ioctl call while performing QMI transaction. Change-Id: I09dbf33d76a3a0d9e4917e62aaf1257a1abe2db9 Signed-off-by: Raghavendar rao l --- .../platform/msm/ipa/ipa_v3/ipa_qmi_service.c | 19 ++++++++++++------- 1 file changed, 12 insertions(+), 7 deletions(-) diff --git a/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c b/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c index ae02f21d11de..df60c8e59f12 100644 --- a/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c +++ b/drivers/platform/msm/ipa/ipa_v3/ipa_qmi_service.c @@ -467,14 +467,22 @@ static int ipa3_qmi_send_req_wait(struct qmi_handle *client_handle, struct qmi_txn txn; int ret; + mutex_lock(&ipa3_qmi_lock); + + if (!client_handle) { + + mutex_unlock(&ipa3_qmi_lock); + return -EINVAL; + } + ret = qmi_txn_init(client_handle, &txn, resp_desc->ei_array, resp); if (ret < 0) { IPAWANERR("QMI txn init failed, ret= %d\n", ret); + mutex_unlock(&ipa3_qmi_lock); return ret; } - mutex_lock(&ipa3_qmi_lock); ret = qmi_send_request(client_handle, &ipa3_qmi_ctx->server_sq, &txn, @@ -483,19 +491,16 @@ static int ipa3_qmi_send_req_wait(struct qmi_handle *client_handle, req_desc->ei_array, req); - if (unlikely(!ipa_q6_clnt)) { - mutex_unlock(&ipa3_qmi_lock); - return -EINVAL; - } - mutex_unlock(&ipa3_qmi_lock); if (ret < 0) { qmi_txn_cancel(&txn); + mutex_unlock(&ipa3_qmi_lock); return ret; } - ret = qmi_txn_wait(&txn, msecs_to_jiffies(timeout_ms)); + ret = qmi_txn_wait(&txn, msecs_to_jiffies(timeout_ms)); + mutex_unlock(&ipa3_qmi_lock); return ret; }