]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
soc: qcom: pdr: protect locator_addr with the main mutex
authorDmitry Baryshkov <dmitry.baryshkov@linaro.org>
Fri, 21 Jun 2024 22:03:40 +0000 (01:03 +0300)
committerBjorn Andersson <andersson@kernel.org>
Mon, 24 Jun 2024 03:41:39 +0000 (22:41 -0500)
If the service locator server is restarted fast enough, the PDR can
rewrite locator_addr fields concurrently. Protect them by placing
modification of those fields under the main pdr->lock.

Fixes: fbe639b44a82 ("soc: qcom: Introduce Protection Domain Restart helpers")
Tested-by: Neil Armstrong <neil.armstrong@linaro.org> # on SM8550-QRD
Tested-by: Steev Klimaszewski <steev@kali.org>
Tested-by: Alexey Minnekhanov <alexeymin@postmarketos.org>
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Link: https://lore.kernel.org/r/20240622-qcom-pd-mapper-v9-1-a84ee3591c8e@linaro.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
drivers/soc/qcom/pdr_interface.c

index a1b6a4081dea72744b64d008154bc52766d8252c..76a62c2ecc58a915798efec49e16ea4113c238a6 100644 (file)
@@ -76,12 +76,12 @@ static int pdr_locator_new_server(struct qmi_handle *qmi,
                                              locator_hdl);
        struct pdr_service *pds;
 
+       mutex_lock(&pdr->lock);
        /* Create a local client port for QMI communication */
        pdr->locator_addr.sq_family = AF_QIPCRTR;
        pdr->locator_addr.sq_node = svc->node;
        pdr->locator_addr.sq_port = svc->port;
 
-       mutex_lock(&pdr->lock);
        pdr->locator_init_complete = true;
        mutex_unlock(&pdr->lock);
 
@@ -104,10 +104,10 @@ static void pdr_locator_del_server(struct qmi_handle *qmi,
 
        mutex_lock(&pdr->lock);
        pdr->locator_init_complete = false;
-       mutex_unlock(&pdr->lock);
 
        pdr->locator_addr.sq_node = 0;
        pdr->locator_addr.sq_port = 0;
+       mutex_unlock(&pdr->lock);
 }
 
 static const struct qmi_ops pdr_locator_ops = {
@@ -365,12 +365,14 @@ static int pdr_get_domain_list(struct servreg_get_domain_list_req *req,
        if (ret < 0)
                return ret;
 
+       mutex_lock(&pdr->lock);
        ret = qmi_send_request(&pdr->locator_hdl,
                               &pdr->locator_addr,
                               &txn, SERVREG_GET_DOMAIN_LIST_REQ,
                               SERVREG_GET_DOMAIN_LIST_REQ_MAX_LEN,
                               servreg_get_domain_list_req_ei,
                               req);
+       mutex_unlock(&pdr->lock);
        if (ret < 0) {
                qmi_txn_cancel(&txn);
                return ret;