mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 04:12:04 -04:00
| Filename | Latest commit message | Latest commit date |
|---|---|---|
In async invoke path, fastrpc_update_invoke_count is called at invoke_end with perf_counter pointing into ctx->perf. After fastrpc_invoke_send returns, the async response thread may call context_free(ctx), freeing ctx->perf before invoke_end. This causes a use-after-free write that corrupts the SLUB freelist and may trigger a kernel panic on next allocation. Fix by storing submission timestamp in ctx->invoke_start_time before send, removing unsafe call from invoke_end, and moving fastrpc_update_invoke_count to fastrpc_wait_on_async_queue. There, ctx is guaranteed valid before context_free. This also aligns async perf->invoke with sync, measuring full end-to-end latency instead of submission-only latency. Acked-by: Sharad Kumar <sharku@qti.qualcomm.com> Change-Id: I91f2a2479b508fde2fe7c26783ee56dc9391eb17 Signed-off-by: Santosh Sakore <ssakore@qti.qualcomm.com> |
||
| .. | ||
| agp | ||
| hw_random | ||
| ipmi | ||
| mwave | ||
| pcmcia | ||
| tpm | ||
| virtio_eavb | ||
| xilinx_hwicap | ||
| xillybus | ||
| adi.c | ||
| adsprpc.c | ||
| adsprpc_compat.c | ||
| adsprpc_compat.h | ||
| adsprpc_shared.h | ||
| apm-emulation.c | ||
| applicom.c | ||
| applicom.h | ||
| bsr.c | ||
| ds1620.c | ||
| dsp56k.c | ||
| dtlk.c | ||
| efirtc.c | ||
| fastcvpd.c | ||
| hangcheck-timer.c | ||
| hpet.c | ||
| Kconfig | ||
| lp.c | ||
| Makefile | ||
| mem.c | ||
| misc.c | ||
| msm_smd_pkt.c | ||
| mspec.c | ||
| nsc_gpio.c | ||
| nvram.c | ||
| nwbutton.c | ||
| nwbutton.h | ||
| nwflash.c | ||
| pc8736x_gpio.c | ||
| powernv-op-panel.c | ||
| ppdev.c | ||
| ps3flash.c | ||
| random.c | ||
| raw.c | ||
| rdbg.c | ||
| rtc.c | ||
| scx200_gpio.c | ||
| sonypi.c | ||
| tb0219.c | ||
| tlclk.c | ||
| toshiba.c | ||
| ttyprintk.c | ||
| uv_mmtimer.c | ||
| virtio_console.c | ||
| virtio_fastrpc.c | ||