From 92846ca4b6e4e8aaba5926feb9d958f851439c66 Mon Sep 17 00:00:00 2001 From: sheenam monga Date: Mon, 7 Sep 2020 17:23:33 +0530 Subject: [PATCH] prima: Protect pHashTable with lock lim_is_assoc_req_for_drop() uses pHashTable which can be accessed by peDeleteSession simulataneously. This can lead to crash as memory for pHashTable can be deleted. Fix this by protecting usage of pHashTable with a lock. Change-Id: Iaef7a26d9f3e1ccb76807c9dcf140a6f3de34d8e CRs-Fixed: 2771345 (cherry picked from commit 0c398c2bd44fd1370eca2b1aa01a80f4675fea13) --- .../prima/CORE/MAC/src/pe/lim/limApi.c | 36 ++++++++++++++----- 1 file changed, 28 insertions(+), 8 deletions(-) diff --git a/drivers/staging/prima/CORE/MAC/src/pe/lim/limApi.c b/drivers/staging/prima/CORE/MAC/src/pe/lim/limApi.c index 344773409e4..de84d7d86fa 100644 --- a/drivers/staging/prima/CORE/MAC/src/pe/lim/limApi.c +++ b/drivers/staging/prima/CORE/MAC/src/pe/lim/limApi.c @@ -2415,6 +2415,8 @@ bool lim_is_assoc_req_for_drop(tpAniSirGlobal pMac, uint8_t *rx_pkt_info) tpPESession session_entry; tpSirMacMgmtHdr pMacHdr; tpDphHashNode sta_ds; + bool status; + eHalStatus lock_status = eHAL_STATUS_SUCCESS; pMacHdr = WDA_GET_RX_MAC_HEADER(rx_pkt_info); session_entry = peFindSessionByBssid(pMac, pMacHdr->bssId, &session_id); @@ -2425,27 +2427,45 @@ bool lim_is_assoc_req_for_drop(tpAniSirGlobal pMac, uint8_t *rx_pkt_info) pMacHdr->sa);); return false; } + + lock_status = pe_AcquireGlobalLock(&pMac->lim); + if (lock_status != eHAL_STATUS_SUCCESS) + { + limLog(pMac, LOGE, FL("pe_AcquireGlobalLock error")); + return TRUE; + } + sta_ds = dphLookupHashEntry(pMac, pMacHdr->sa, &aid, &session_entry->dph.dphHashTable); if (!sta_ds) { PELOG1(limLog(pMac, LOG1, FL("pStaDs is NULL"));); - return false; + status = false; + goto end; } - if (!sta_ds->rmfEnabled) - return false; + if (!sta_ds->rmfEnabled) { + status = false; + goto end; + } - if (sta_ds->pmfSaQueryState == DPH_SA_QUERY_IN_PROGRESS) - return true; + if (sta_ds->pmfSaQueryState == DPH_SA_QUERY_IN_PROGRESS) { + status = true; + goto end; + } if (sta_ds->last_assoc_received_time && ((vos_timer_get_system_time() - - sta_ds->last_assoc_received_time) < 1000)) - return true; + sta_ds->last_assoc_received_time) < 1000)) { + status = true; + goto end; + } sta_ds->last_assoc_received_time = vos_timer_get_system_time(); - return false; + status = false; +end: + pe_ReleaseGlobalLock(&pMac->lim); + return status; } #endif