mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
wifi: brcmfmac: make release_scratchbuffers idempotent
commit538c51e9d1upstream. brcmf_pcie_release_scratchbuffers() frees the shared.scratch and shared.ringupd DMA buffers with dma_free_coherent() but does not clear the pointers afterwards, unlike the sibling release_ringbuffers() which NULLs commonrings/flowrings/idxbuf on release. Both the bus_reset .reset callback (brcmf_pcie_reset) and brcmf_pcie_remove() call release_scratchbuffers. When reset teardown has run before removal, remove's own teardown would call dma_free_coherent() a second time on the already-freed DMA allocation. NULL the pointers after free, matching release_ringbuffers(), so a later release observes that the allocation has already been released. This patch makes repeated sequential release safe; the reset-work lifetime is handled separately by the following patch. This issue was found by an in-house static analysis tool. Fixes:4684997d9e("brcmfmac: reset PCIe bus on a firmware crash") Cc: stable@vger.kernel.org Signed-off-by: Fan Wu <fanwu01@zju.edu.cn> Assisted-by: Codex:gpt-5.6 Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com> Link: https://patch.msgid.link/20260718024353.3147201-2-fanwu01@zju.edu.cn Signed-off-by: Johannes Berg <johannes.berg@intel.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
ef2ee5f820
commit
b7d1d8cb1b
@@ -1381,16 +1381,20 @@ fail:
|
||||
static void
|
||||
brcmf_pcie_release_scratchbuffers(struct brcmf_pciedev_info *devinfo)
|
||||
{
|
||||
if (devinfo->shared.scratch)
|
||||
if (devinfo->shared.scratch) {
|
||||
dma_free_coherent(&devinfo->pdev->dev,
|
||||
BRCMF_DMA_D2H_SCRATCH_BUF_LEN,
|
||||
devinfo->shared.scratch,
|
||||
devinfo->shared.scratch_dmahandle);
|
||||
if (devinfo->shared.ringupd)
|
||||
devinfo->shared.scratch = NULL;
|
||||
}
|
||||
if (devinfo->shared.ringupd) {
|
||||
dma_free_coherent(&devinfo->pdev->dev,
|
||||
BRCMF_DMA_D2H_RINGUPD_BUF_LEN,
|
||||
devinfo->shared.ringupd,
|
||||
devinfo->shared.ringupd_dmahandle);
|
||||
devinfo->shared.ringupd = NULL;
|
||||
}
|
||||
}
|
||||
|
||||
static int brcmf_pcie_init_scratchbuffers(struct brcmf_pciedev_info *devinfo)
|
||||
|
||||
Reference in New Issue
Block a user