When a fastrpc client process dies abnormally without closing its file
descriptor, fastrpc_device_release() is never called and the compute-cb
session slot is never freed. The abnormal client death on the DSP side
triggers a glink channel teardown which propagates up through the rpmsg
bus and calls fastrpc_rpmsg_remove().

fastrpc_rpmsg_remove() nulls cctx->rpdev before calling
misc_deregister(). If a concurrent open() enters fastrpc_device_open()
in this window and fastrpc_session_alloc() returns NULL (sessions
exhausted by the leaked slot), the error path dereferences
cctx->rpdev->dev causing a NULL pointer dereference:

  Unable to handle kernel NULL pointer dereference at virtual address 
0000000000000000
  pc : fastrpc_device_open+0x1b8/0x258 [fastrpc]
  Call trace:
   fastrpc_device_open+0x1b8/0x258 [fastrpc] (P)
   misc_open+0xd8/0x1a0

Fix by moving misc_deregister() before rpdev = NULL. misc_open() and
misc_deregister() both take misc_mtx, so misc_deregister() will either
block until fastrpc_device_open() completes or prevent new opens from
entering it entirely.

Fixes: 7c11df42d0c7 ("misc: fastrpc: Fix device_open when no session is 
available")
Signed-off-by: Vinayak Katoch <[email protected]>
---
 drivers/misc/fastrpc.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c
index b29c1fd00de2..7ab1cbbf19bb 100644
--- a/drivers/misc/fastrpc.c
+++ b/drivers/misc/fastrpc.c
@@ -2706,6 +2706,12 @@ static void fastrpc_rpmsg_remove(struct rpmsg_device 
*rpdev)
        struct fastrpc_user *user;
        unsigned long flags;
 
+       if (cctx->fdevice)
+               misc_deregister(&cctx->fdevice->miscdev);
+
+       if (cctx->secure_fdevice)
+               misc_deregister(&cctx->secure_fdevice->miscdev);
+
        /* No invocations past this point */
        spin_lock_irqsave(&cctx->lock, flags);
        cctx->rpdev = NULL;
@@ -2713,12 +2719,6 @@ static void fastrpc_rpmsg_remove(struct rpmsg_device 
*rpdev)
                fastrpc_notify_users(user);
        spin_unlock_irqrestore(&cctx->lock, flags);
 
-       if (cctx->fdevice)
-               misc_deregister(&cctx->fdevice->miscdev);
-
-       if (cctx->secure_fdevice)
-               misc_deregister(&cctx->secure_fdevice->miscdev);
-
        list_for_each_entry_safe(buf, b, &cctx->invoke_interrupted_mmaps, node)
                list_del(&buf->node);
 

-- 
2.34.1

Reply via email to