mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-09 21:59:12 -04:00
msm: mhi_dev: Check to prevent in_use_list access
Added a check for accessing in_use_list only in async case. Change-Id: I842f9b9feb688d75152f7b2639c17c25c3376236 Signed-off-by: Subramanian Ananthanarayanan <skananth@codeaurora.org> Signed-off-by: Gauri Joshi <gaurjosh@codeaurora.org>
This commit is contained in:
parent
e1a0f4d9f1
commit
cdc28c2b3f
1 changed files with 21 additions and 16 deletions
|
|
@ -1181,16 +1181,19 @@ static int mhi_uci_client_release(struct inode *mhi_inode,
|
|||
count = 0;
|
||||
|
||||
spin_lock_irqsave(&uci_handle->req_lock, flags);
|
||||
while (!(list_empty(&uci_handle->in_use_list))) {
|
||||
ureq = container_of(uci_handle->in_use_list.next,
|
||||
if (!(uci_handle->f_flags & O_SYNC)) {
|
||||
while (!(list_empty(&uci_handle->in_use_list))) {
|
||||
ureq = container_of(
|
||||
uci_handle->in_use_list.next,
|
||||
struct mhi_req, list);
|
||||
list_del_init(&ureq->list);
|
||||
ureq->is_stale = true;
|
||||
uci_log(UCI_DBG_VERBOSE,
|
||||
"Adding back req for chan %d to free list\n",
|
||||
ureq->chan);
|
||||
list_add_tail(&ureq->list, &uci_handle->req_list);
|
||||
count++;
|
||||
list_del_init(&ureq->list);
|
||||
ureq->is_stale = true;
|
||||
uci_log(UCI_DBG_VERBOSE,
|
||||
"Adding back req for chan %d to free list\n",
|
||||
ureq->chan);
|
||||
list_add_tail(&ureq->list, &uci_handle->req_list);
|
||||
count++;
|
||||
}
|
||||
}
|
||||
spin_unlock_irqrestore(&uci_handle->req_lock, flags);
|
||||
if (count)
|
||||
|
|
@ -2091,13 +2094,15 @@ static void mhi_uci_at_ctrl_client_cb(struct mhi_dev_client_cb_data *cb_data)
|
|||
mhi_dev_close_channel(client->out_handle);
|
||||
mhi_dev_close_channel(client->in_handle);
|
||||
|
||||
/* Add back reqs for in-use list, if any, to free list */
|
||||
while (!(list_empty(&client->in_use_list))) {
|
||||
ureq = container_of(client->in_use_list.next,
|
||||
struct mhi_req, list);
|
||||
list_del_init(&ureq->list);
|
||||
/* Add to in-use list */
|
||||
list_add_tail(&ureq->list, &client->req_list);
|
||||
/* Add back reqs from in-use list, if any, to free list */
|
||||
if (!(client->f_flags & O_SYNC)) {
|
||||
while (!(list_empty(&client->in_use_list))) {
|
||||
ureq = container_of(client->in_use_list.next,
|
||||
struct mhi_req, list);
|
||||
list_del_init(&ureq->list);
|
||||
/* Add to in-use list */
|
||||
list_add_tail(&ureq->list, &client->req_list);
|
||||
}
|
||||
}
|
||||
|
||||
for (i = 0; i < (client->in_chan_attr->nr_trbs); i++) {
|
||||
|
|
|
|||
Loading…
Reference in a new issue