Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 688d7b16 authored by Meng Wang's avatar Meng Wang
Browse files

Revert "ASoC: msm: qdspv2: add spin lock to protect ac"



This reverts commit c6316fe1
("ASoC: msm: qdspv2: add spin lock to protect ac"). Add another
patch apply cleanly to fix the ac used-after-free issue.

Change-Id: I494e4666e76490c37f17a774ce640f4af276e6ae
Signed-off-by: default avatarMeng Wang <mwang@codeaurora.org>
parent 5454b7ff
Loading
Loading
Loading
Loading
+31 −94
Original line number Diff line number Diff line
/*
 * Copyright (c) 2012-2017, The Linux Foundation. All rights reserved.
 * Copyright (c) 2012-2018, The Linux Foundation. All rights reserved.
 * Author: Brian Swetland <swetland@google.com>
 *
 * This software is licensed under the terms of the GNU General Public
@@ -92,13 +92,8 @@ struct asm_mmap {
};

static struct asm_mmap this_mmap;

struct audio_session {
	struct audio_client *ac;
	spinlock_t session_lock;
};
/* session id: 0 reserved */
static struct audio_session session[ASM_ACTIVE_STREAMS_ALLOWED + 1];
static struct audio_client *session[ASM_ACTIVE_STREAMS_ALLOWED + 1];

struct asm_buffer_node {
	struct list_head list;
@@ -550,8 +545,8 @@ static int q6asm_session_alloc(struct audio_client *ac)
{
	int n;
	for (n = 1; n <= ASM_ACTIVE_STREAMS_ALLOWED; n++) {
		if (!(session[n].ac)) {
			session[n].ac = ac;
		if (!session[n]) {
			session[n] = ac;
			return n;
		}
	}
@@ -559,38 +554,25 @@ static int q6asm_session_alloc(struct audio_client *ac)
	return -ENOMEM;
}

static int q6asm_get_session_id_from_audio_client(struct audio_client *ac)
static bool q6asm_is_valid_audio_client(struct audio_client *ac)
{
	int n;
	for (n = 1; n <= ASM_ACTIVE_STREAMS_ALLOWED; n++) {
		if (session[n].ac == ac)
			return n;
		if (session[n] == ac)
			return 1;
	}
	return 0;
}

static bool q6asm_is_valid_audio_client(struct audio_client *ac)
{
	return q6asm_get_session_id_from_audio_client(ac) ? 1 : 0;
}

static void q6asm_session_free(struct audio_client *ac)
{
	int session_id;

	pr_debug("%s: sessionid[%d]\n", __func__, ac->session);
	session_id = ac->session;
	rtac_remove_popp_from_adm_devices(ac->session);
	spin_lock_bh(&(session[session_id].session_lock));
	session[ac->session].ac = NULL;
	session[ac->session] = NULL;
	ac->session = 0;
	ac->perf_mode = LEGACY_PCM_MODE;
	ac->fptr_cache_ops = NULL;
	ac->cb = NULL;
	ac->priv = NULL;
	kfree(ac);
	ac = NULL;
	spin_unlock_bh(&(session[session_id].session_lock));

	return;
}

@@ -1101,6 +1083,8 @@ void q6asm_audio_client_free(struct audio_client *ac)
	pr_debug("%s: APR De-Register\n", __func__);

/*done:*/
	kfree(ac);
	ac = NULL;
	mutex_unlock(&session_lock);

	return;
@@ -1235,7 +1219,6 @@ struct audio_client *q6asm_audio_client_alloc(app_cb cb, void *priv)
	if (n <= 0) {
		pr_err("%s: ASM Session alloc fail n=%d\n", __func__, n);
		mutex_unlock(&session_lock);
		kfree(ac);
		goto fail_session;
	}
	ac->session = n;
@@ -1312,6 +1295,7 @@ fail_apr2:
fail_apr1:
	q6asm_session_free(ac);
fail_session:
	kfree(ac);
	return NULL;
}

@@ -1326,11 +1310,11 @@ struct audio_client *q6asm_get_audio_client(int session_id)
		goto err;
	}

	if (!(session[session_id].ac)) {
	if (!session[session_id]) {
		pr_err("%s: session not active: %d\n", __func__, session_id);
		goto err;
	}
	return session[session_id].ac;
	return session[session_id];
err:
	return NULL;
}
@@ -1541,8 +1525,6 @@ static int32_t q6asm_srvc_callback(struct apr_client_data *data, void *priv)
	struct audio_client *ac = NULL;
	struct audio_port_data *port;

	int session_id;

	if (!data) {
		pr_err("%s: Invalid CB\n", __func__);
		return 0;
@@ -1583,22 +1565,13 @@ static int32_t q6asm_srvc_callback(struct apr_client_data *data, void *priv)
		rtac_clear_mapping(ASM_RTAC_CAL);
		return 0;
	}

	asm_token.token = data->token;
	session_id = asm_token._token.session_id;

	if ((session_id > 0 && session_id <= ASM_ACTIVE_STREAMS_ALLOWED))
		spin_lock(&(session[session_id].session_lock));

	ac = q6asm_get_audio_client(session_id);
	ac = q6asm_get_audio_client(asm_token._token.session_id);
	dir = q6asm_get_flag_from_token(&asm_token, ASM_DIRECTION_OFFSET);

	if (!ac) {
		pr_debug("%s: session[%d] already freed\n",
			 __func__, session_id);
		if ((session_id > 0 &&
			session_id <= ASM_ACTIVE_STREAMS_ALLOWED))
			spin_unlock(&(session[session_id].session_lock));
			 __func__, asm_token._token.session_id);
		return 0;
	}

@@ -1649,9 +1622,6 @@ static int32_t q6asm_srvc_callback(struct apr_client_data *data, void *priv)
						__func__, payload[0]);
			break;
		}
		if ((session_id > 0 &&
			session_id <= ASM_ACTIVE_STREAMS_ALLOWED))
			spin_unlock(&(session[session_id].session_lock));
		return 0;
	}

@@ -1686,9 +1656,6 @@ static int32_t q6asm_srvc_callback(struct apr_client_data *data, void *priv)
	if (ac->cb)
		ac->cb(data->opcode, data->token,
			data->payload, ac->priv);
	if ((session_id > 0 && session_id <= ASM_ACTIVE_STREAMS_ALLOWED))
		spin_unlock(&(session[session_id].session_lock));

	return 0;
}

@@ -1756,7 +1723,6 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
	uint8_t buf_index;
	struct msm_adsp_event_data *pp_event_package = NULL;
	uint32_t payload_size = 0;
	int session_id;

	if (ac == NULL) {
		pr_err("%s: ac NULL\n", __func__);
@@ -1766,19 +1732,15 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
		pr_err("%s: data NULL\n", __func__);
		return -EINVAL;
	}

	session_id = q6asm_get_session_id_from_audio_client(ac);
	if (session_id <= 0 || session_id > ASM_ACTIVE_STREAMS_ALLOWED) {
		pr_err("%s: Session ID is invalid, session = %d\n", __func__,
			session_id);
		return -EINVAL;
	}

	spin_lock(&(session[session_id].session_lock));
	if (!q6asm_is_valid_audio_client(ac)) {
		pr_err("%s: audio client pointer is invalid, ac = %pK\n",
				__func__, ac);
		spin_unlock(&(session[session_id].session_lock));
		return -EINVAL;
	}

	if (ac->session <= 0 || ac->session > ASM_ACTIVE_STREAMS_ALLOWED) {
		pr_err("%s: Session ID is invalid, session = %d\n", __func__,
			ac->session);
		return -EINVAL;
	}

@@ -1791,9 +1753,7 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
	}

	if (data->opcode == RESET_EVENTS) {
		spin_unlock(&(session[session_id].session_lock));
		mutex_lock(&ac->cmd_lock);
		spin_lock(&(session[session_id].session_lock));
		atomic_set(&ac->reset, 1);
		if (ac->apr == NULL) {
			ac->apr = ac->apr2;
@@ -1814,7 +1774,6 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
		wake_up(&ac->time_wait);
		wake_up(&ac->cmd_wait);
		wake_up(&ac->mem_wait);
		spin_unlock(&(session[session_id].session_lock));
		mutex_unlock(&ac->cmd_lock);
		return 0;
	}
@@ -1829,7 +1788,6 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
	    (data->opcode != ASM_SESSION_EVENT_RX_UNDERFLOW)) {
		if (payload == NULL) {
			pr_err("%s: payload is null\n", __func__);
			spin_unlock(&(session[session_id].session_lock));
			return -EINVAL;
		}
		dev_vdbg(ac->dev, "%s: Payload = [0x%x] status[0x%x] opcode 0x%x\n",
@@ -1855,7 +1813,6 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
		ret = q6asm_is_valid_session(data, priv);
		if (ret != 0) {
			pr_err("%s: session invalid %d\n", __func__, ret);
			spin_unlock(&(session[session_id].session_lock));
			return ret;
		}
		case ASM_SESSION_CMD_SET_MTMX_STRTR_PARAMS_V2:
@@ -1895,8 +1852,6 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
								payload[1]);
					wake_up(&ac->cmd_wait);
				}
				spin_unlock(
					&(session[session_id].session_lock));
				return 0;
			}
			if ((is_adsp_reg_event(payload[0]) >= 0) ||
@@ -1927,8 +1882,6 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
					atomic_set(&ac->mem_state, payload[1]);
					wake_up(&ac->mem_wait);
				}
				spin_unlock(
					&(session[session_id].session_lock));
				return 0;
			}
			if (atomic_read(&ac->mem_state) && wakeup_flag) {
@@ -1976,8 +1929,6 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
							__func__, payload[0]);
			break;
		}

		spin_unlock(&(session[session_id].session_lock));
		return 0;
	}

@@ -1991,8 +1942,6 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
			if (port->buf == NULL) {
				pr_err("%s: Unexpected Write Done\n",
								__func__);
				spin_unlock(
					&(session[session_id].session_lock));
				return -EINVAL;
			}
			spin_lock_irqsave(&port->dsp_lock, dsp_flags);
@@ -2007,8 +1956,6 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
					__func__, payload[0], payload[1]);
				spin_unlock_irqrestore(&port->dsp_lock,
								dsp_flags);
				spin_unlock(
					&(session[session_id].session_lock));
				return -EINVAL;
			}
			port->buf[buf_index].used = 1;
@@ -2079,8 +2026,6 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
		if (ac->io_mode & SYNC_IO_MODE) {
			if (port->buf == NULL) {
				pr_err("%s: Unexpected Write Done\n", __func__);
				spin_unlock(
					&(session[session_id].session_lock));
				return -EINVAL;
			}
			spin_lock_irqsave(&port->dsp_lock, dsp_flags);
@@ -2155,10 +2100,8 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
		pr_debug("%s: ASM_STREAM_EVENT payload[0][0x%x] payload[1][0x%x]",
				 __func__, payload[0], payload[1]);
		i = is_adsp_raise_event(data->opcode);
		if (i < 0) {
			spin_unlock(&(session[session_id].session_lock));
		if (i < 0)
			return 0;
		}

		/* repack payload for asm_stream_pp_event
		 * package is composed of event type + size + actual payload
@@ -2167,10 +2110,8 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
		pp_event_package = kzalloc(payload_size
				+ sizeof(struct msm_adsp_event_data),
				GFP_ATOMIC);
		if (!pp_event_package) {
			spin_unlock(&(session[session_id].session_lock));
		if (!pp_event_package)
			return -ENOMEM;
		}

		pp_event_package->event_type = i;
		pp_event_package->payload_len = payload_size;
@@ -2179,7 +2120,6 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
		ac->cb(data->opcode, data->token,
			(void *)pp_event_package, ac->priv);
		kfree(pp_event_package);
		spin_unlock(&(session[session_id].session_lock));
		return 0;
	case ASM_SESSION_CMDRSP_ADJUST_SESSION_CLOCK_V2:
		pr_debug("%s: ASM_SESSION_CMDRSP_ADJUST_SESSION_CLOCK_V2 sesion %d status 0x%x msw %u lsw %u\n",
@@ -2205,7 +2145,7 @@ static int32_t q6asm_callback(struct apr_client_data *data, void *priv)
	if (ac->cb)
		ac->cb(data->opcode, data->token,
			data->payload, ac->priv);
	spin_unlock(&(session[session_id].session_lock));

	return 0;
}

@@ -9326,7 +9266,7 @@ int q6asm_get_apr_service_id(int session_id)
		return -EINVAL;
	}

	return ((struct apr_svc *)(session[session_id].ac)->apr)->id;
	return ((struct apr_svc *)session[session_id]->apr)->id;
}

int q6asm_get_asm_topology(int session_id)
@@ -9337,12 +9277,12 @@ int q6asm_get_asm_topology(int session_id)
		pr_err("%s: invalid session_id = %d\n", __func__, session_id);
		goto done;
	}
	if (session[session_id].ac == NULL) {
	if (session[session_id] == NULL) {
		pr_err("%s: session not created for session id = %d\n",
		       __func__, session_id);
		goto done;
	}
	topology = (session[session_id].ac)->topology;
	topology = session[session_id]->topology;
done:
	return topology;
}
@@ -9355,12 +9295,12 @@ int q6asm_get_asm_app_type(int session_id)
		pr_err("%s: invalid session_id = %d\n", __func__, session_id);
		goto done;
	}
	if (session[session_id].ac == NULL) {
	if (session[session_id] == NULL) {
		pr_err("%s: session not created for session id = %d\n",
		       __func__, session_id);
		goto done;
	}
	app_type = (session[session_id].ac)->app_type;
	app_type = session[session_id]->app_type;
done:
	return app_type;
}
@@ -9703,10 +9643,7 @@ static int __init q6asm_init(void)
	int lcnt, ret;
	pr_debug("%s:\n", __func__);

	memset(session, 0, sizeof(struct audio_session) *
		(ASM_ACTIVE_STREAMS_ALLOWED + 1));
	for (lcnt = 0; lcnt <= ASM_ACTIVE_STREAMS_ALLOWED; lcnt++)
		spin_lock_init(&(session[lcnt].session_lock));
	memset(session, 0, sizeof(session));
	set_custom_topology = 1;

	/*setup common client used for cal mem map */