Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa into android13-5.4-lahaina

LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa:
  ipa: Added changes to move the hdr entry to free list
  msm: ipa: Avoid use-after-free scenario

Change-Id: I53d9b6e5cd83948d5a7cd67b8b7ffa58af13efef
This commit is contained in:
Michael Bestas 2026-04-30 21:15:00 +03:00
commit be47524e56
No known key found for this signature in database
GPG key ID: CC95044519BE6669
2 changed files with 12 additions and 6 deletions

View file

@ -710,7 +710,10 @@ static int __ipa3_del_hdr_proc_ctx(u32 proc_ctx_hdl,
return 0;
}
if (release_hdr)
if (entry->hdr && entry == entry->hdr->proc_ctx)
entry->hdr->proc_ctx = NULL;
if (entry->hdr && release_hdr)
__ipa3_del_hdr(entry->hdr->id, false);
/* move the offset entry to appropriate free list */
@ -774,17 +777,19 @@ int __ipa3_del_hdr(u32 hdr_hdl, bool by_user)
return 0;
}
if (entry->proc_ctx && entry == entry->proc_ctx->hdr)
entry->proc_ctx->hdr = NULL;
if (entry->is_hdr_proc_ctx || entry->proc_ctx) {
dma_unmap_single(ipa3_ctx->pdev,
entry->phys_base,
entry->hdr_len,
DMA_TO_DEVICE);
__ipa3_del_hdr_proc_ctx(entry->proc_ctx->id, false, false);
} else {
/* move the offset entry to appropriate free list */
list_move(&entry->offset_entry->link,
&htbl->head_free_offset_list[entry->offset_entry->bin]);
}
/* move the offset entry to appropriate free list */
list_move(&entry->offset_entry->link,
&htbl->head_free_offset_list[entry->offset_entry->bin]);
list_del(&entry->link);
htbl->hdr_cnt--;
entry->cookie = 0;

View file

@ -1,6 +1,7 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
* Copyright (c) 2017-2021, The Linux Foundation. All rights reserved.
* Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries.
*/
#include <linux/debugfs.h>
@ -770,9 +771,9 @@ int ipa_pm_register(struct ipa_pm_register_params *params, u32 *hdl)
client->skip_clk_vote = params->skip_clk_vote;
client->wlock = wakeup_source_register(NULL, client->name);
if (!client->wlock) {
ipa_pm_deregister(*hdl);
IPA_PM_ERR("IPA wakeup source register failed %s\n",
client->name);
ipa_pm_deregister(*hdl);
return -ENOMEM;
}