mirror of
https://kernel.googlesource.com/pub/scm/linux/kernel/git/torvalds/linux
synced 2025-09-15 00:56:46 +10:00
usb: musb: Get the musb_qh poniter after musb_giveback
When multiple threads are performing USB transmission, musb->lock will be
unlocked when musb_giveback is executed. At this time, qh may be released
in the dequeue process in other threads, resulting in a wild pointer, so
it needs to be here get qh again, and judge whether qh is NULL, and when
dequeue, you need to set qh to NULL.
Fixes: dbac5d07d1
("usb: musb: host: don't start next rx urb if current one failed")
Cc: stable@vger.kernel.org
Signed-off-by: Xingxing Luo <xingxing.luo@unisoc.com>
Link: https://lore.kernel.org/r/20230919033055.14085-1-xingxing.luo@unisoc.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
6658a62e1d
commit
33d7e37232
@ -321,10 +321,16 @@ static void musb_advance_schedule(struct musb *musb, struct urb *urb,
|
|||||||
musb_giveback(musb, urb, status);
|
musb_giveback(musb, urb, status);
|
||||||
qh->is_ready = ready;
|
qh->is_ready = ready;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* musb->lock had been unlocked in musb_giveback, so qh may
|
||||||
|
* be freed, need to get it again
|
||||||
|
*/
|
||||||
|
qh = musb_ep_get_qh(hw_ep, is_in);
|
||||||
|
|
||||||
/* reclaim resources (and bandwidth) ASAP; deschedule it, and
|
/* reclaim resources (and bandwidth) ASAP; deschedule it, and
|
||||||
* invalidate qh as soon as list_empty(&hep->urb_list)
|
* invalidate qh as soon as list_empty(&hep->urb_list)
|
||||||
*/
|
*/
|
||||||
if (list_empty(&qh->hep->urb_list)) {
|
if (qh && list_empty(&qh->hep->urb_list)) {
|
||||||
struct list_head *head;
|
struct list_head *head;
|
||||||
struct dma_controller *dma = musb->dma_controller;
|
struct dma_controller *dma = musb->dma_controller;
|
||||||
|
|
||||||
@ -2398,6 +2404,7 @@ static int musb_urb_dequeue(struct usb_hcd *hcd, struct urb *urb, int status)
|
|||||||
* and its URB list has emptied, recycle this qh.
|
* and its URB list has emptied, recycle this qh.
|
||||||
*/
|
*/
|
||||||
if (ready && list_empty(&qh->hep->urb_list)) {
|
if (ready && list_empty(&qh->hep->urb_list)) {
|
||||||
|
musb_ep_set_qh(qh->hw_ep, is_in, NULL);
|
||||||
qh->hep->hcpriv = NULL;
|
qh->hep->hcpriv = NULL;
|
||||||
list_del(&qh->ring);
|
list_del(&qh->ring);
|
||||||
kfree(qh);
|
kfree(qh);
|
||||||
|
Loading…
Reference in New Issue
Block a user