prima: Protect pHashTable with lock

lim_is_assoc_req_for_drop() uses pHashTable which can be accessed
by peDeleteSession simulataneously. This can lead to crash as
memory for pHashTable can be deleted.

Fix this by protecting usage of pHashTable with a lock.

Change-Id: Iaef7a26d9f3e1ccb76807c9dcf140a6f3de34d8e
CRs-Fixed: 2771345
(cherry picked from commit 0c398c2bd44fd1370eca2b1aa01a80f4675fea13)
This commit is contained in:
sheenam monga
2021-10-10 23:46:46 +02:00
committed by Francescodario Cuzzocrea
parent 73f11d4d96
commit 92846ca4b6
@@ -2415,6 +2415,8 @@ bool lim_is_assoc_req_for_drop(tpAniSirGlobal pMac, uint8_t *rx_pkt_info)
tpPESession session_entry;
tpSirMacMgmtHdr pMacHdr;
tpDphHashNode sta_ds;
bool status;
eHalStatus lock_status = eHAL_STATUS_SUCCESS;
pMacHdr = WDA_GET_RX_MAC_HEADER(rx_pkt_info);
session_entry = peFindSessionByBssid(pMac, pMacHdr->bssId, &session_id);
@@ -2425,27 +2427,45 @@ bool lim_is_assoc_req_for_drop(tpAniSirGlobal pMac, uint8_t *rx_pkt_info)
pMacHdr->sa););
return false;
}
lock_status = pe_AcquireGlobalLock(&pMac->lim);
if (lock_status != eHAL_STATUS_SUCCESS)
{
limLog(pMac, LOGE, FL("pe_AcquireGlobalLock error"));
return TRUE;
}
sta_ds = dphLookupHashEntry(pMac, pMacHdr->sa, &aid,
&session_entry->dph.dphHashTable);
if (!sta_ds)
{
PELOG1(limLog(pMac, LOG1, FL("pStaDs is NULL")););
return false;
status = false;
goto end;
}
if (!sta_ds->rmfEnabled)
return false;
if (!sta_ds->rmfEnabled) {
status = false;
goto end;
}
if (sta_ds->pmfSaQueryState == DPH_SA_QUERY_IN_PROGRESS)
return true;
if (sta_ds->pmfSaQueryState == DPH_SA_QUERY_IN_PROGRESS) {
status = true;
goto end;
}
if (sta_ds->last_assoc_received_time &&
((vos_timer_get_system_time() -
sta_ds->last_assoc_received_time) < 1000))
return true;
sta_ds->last_assoc_received_time) < 1000)) {
status = true;
goto end;
}
sta_ds->last_assoc_received_time = vos_timer_get_system_time();
return false;
status = false;
end:
pe_ReleaseGlobalLock(&pMac->lim);
return status;
}
#endif