From 7a811175cab8be7390447c0c77645a3799e46d12 Mon Sep 17 00:00:00 2001 From: Panicker Harish Date: Tue, 12 Dec 2023 10:56:46 +0530 Subject: [PATCH] msm_serial_hs: Fix race between mod_timer and del_timer calls Deletion of timer and synchronization of the handler will happen during del_timer, but in the issue case the timer got deleted and before handler_sync should happen the timer is getting modified or accessed which further leads to kernel panic. Fix this by modifying del_timer to del_timer_sync so that the timer is protected until synchronization happen. Change-Id: If5dec66b9bbcb5369898536ba1c727b487a13018 Signed-off-by: Venkata Manasa Kakarla Signed-off-by: Yatish Kumar Singh Signed-off-by: Panicker Harish --- drivers/tty/serial/msm_serial_hs.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/tty/serial/msm_serial_hs.c b/drivers/tty/serial/msm_serial_hs.c index c55036f2b87d..cfee5b5799b6 100644 --- a/drivers/tty/serial/msm_serial_hs.c +++ b/drivers/tty/serial/msm_serial_hs.c @@ -1849,7 +1849,7 @@ static void msm_hs_sps_tx_callback(struct sps_event_notify *notify) &addr, notify->data.transfer.iovec.size, notify->data.transfer.iovec.flags); - del_timer(&msm_uport->tx.tx_timeout_timer); + del_timer_sync(&msm_uport->tx.tx_timeout_timer); MSM_HS_DBG("%s(): Queue kthread work\n", __func__); kthread_queue_work(&msm_uport->tx.kworker, &msm_uport->tx.kwork); }