mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-09 21:59:12 -04:00
usb: gsi: Set setup_pending if ep_queue on EP0 is successful
Consider a scenario where setup packet gets queued from the function driver and without geting completion for that request composition switch or cable disconnect happens. Since the request is not given back to the gadget driver it will be in pending list. During composition switch or cable disconnect composite dev cleanup happens which will free the request without dequeing it since setup_pending is not set for the request. When a new setup packet is queued and the completion for the new setup packet happens driver will try to access the freed request from the pending list leading to use-after-free. Fix this by setting setup_pending to true if ep_queue on ep0 is successful. Change-Id: I7fe083dfc99663681fc0b98e02613799e526d3d4 Signed-off-by: Pratham Pratap <prathampratap@codeaurora.org>
This commit is contained in:
parent
8a7d4fed84
commit
de84d964ec
1 changed files with 6 additions and 0 deletions
|
|
@ -2091,6 +2091,7 @@ static void gsi_rndis_command_complete(struct usb_ep *ep,
|
|||
struct usb_request *req)
|
||||
{
|
||||
struct f_gsi *gsi = req->context;
|
||||
struct usb_composite_dev *cdev = gsi->function.config->cdev;
|
||||
int status;
|
||||
u32 MsgType;
|
||||
|
||||
|
|
@ -2133,6 +2134,7 @@ static void gsi_rndis_command_complete(struct usb_ep *ep,
|
|||
gsi_rndis_flow_ctrl_enable(!(*gsi->params->filter),
|
||||
gsi->params);
|
||||
}
|
||||
cdev->setup_pending = false;
|
||||
}
|
||||
|
||||
static void
|
||||
|
|
@ -2182,8 +2184,10 @@ invalid:
|
|||
static void gsi_ctrl_cmd_complete(struct usb_ep *ep, struct usb_request *req)
|
||||
{
|
||||
struct f_gsi *gsi = req->context;
|
||||
struct usb_composite_dev *cdev = gsi->function.config->cdev;
|
||||
|
||||
gsi_ctrl_send_cpkt_tomodem(gsi, req->buf, req->actual);
|
||||
cdev->setup_pending = false;
|
||||
}
|
||||
|
||||
static void gsi_ctrl_reset_cmd_complete(struct usb_ep *ep,
|
||||
|
|
@ -2403,6 +2407,8 @@ invalid:
|
|||
value = usb_ep_queue(cdev->gadget->ep0, req, GFP_ATOMIC);
|
||||
if (value < 0)
|
||||
log_event_err("response on err %d", value);
|
||||
else
|
||||
cdev->setup_pending = true;
|
||||
}
|
||||
|
||||
/* device either stalls (value < 0) or reports success */
|
||||
|
|
|
|||
Loading…
Reference in a new issue