From: Pavel Andrianov <hidden> Date: 2016-08-02 10:19:45
Likely wl3501_reset should acquire spinlock as wl3501_{open, close}.
One of calls of wl3501_reset has been already protected.
The others were unprotected and might lead to a race condition.
The patch adds spinlock into the wl3501_reset and removes it from
wl3501_tx_timeout.
Found by Linux Driver Verification project (linuxtesting.org)
Signed-off-by: Pavel Andrianov <redacted>
---
drivers/net/wireless/wl3501_cs.c | 7 +++----
1 file changed, 3 insertions(+), 4 deletions(-)
On Tuesday 02 August 2016 03:11 PM, Pavel Andrianov wrote:
Likely wl3501_reset should acquire spinlock as wl3501_{open, close}.
One of calls of wl3501_reset has been already protected.
The others were unprotected and might lead to a race condition.
The patch adds spinlock into the wl3501_reset and removes it from
wl3501_tx_timeout.
Found by Linux Driver Verification project (linuxtesting.org)
Signed-off-by: Pavel Andrianov <redacted>
@@ -1247,7 +1247,9 @@ static int wl3501_reset(struct net_device *dev){structwl3501_card*this=netdev_priv(dev);intrc=-ENODEV;+unsignedlongflags;+spin_lock_irqsave(&this->lock,flags);wl3501_block_interrupt(this);if(wl3501_init_firmware(this)){
@@ -1269,20 +1271,17 @@ static int wl3501_reset(struct net_device *dev)pr_debug("%s: device reset",dev->name);rc=0;out:+spin_unlock_irqrestore(&this->lock,flags);returnrc;}staticvoidwl3501_tx_timeout(structnet_device*dev){-structwl3501_card*this=netdev_priv(dev);structnet_device_stats*stats=&dev->stats;-unsignedlongflags;intrc;stats->tx_errors++;-spin_lock_irqsave(&this->lock,flags);rc=wl3501_reset(dev);-spin_unlock_irqrestore(&this->lock,flags);if(rc)printk(KERN_ERR"%s: Error %d resetting card on Tx timeout!\n",dev->name,rc);
--
Vaishali
--
To unsubscribe from this list: send the line "unsubscribe linux-wireless" in
the body of a message to majordomo-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
From: Kalle Valo <hidden> Date: 2016-09-03 10:11:07
Pavel Andrianov [off-list ref] wrote:
Likely wl3501_reset should acquire spinlock as wl3501_{open, close}.
One of calls of wl3501_reset has been already protected.
The others were unprotected and might lead to a race condition.
The patch adds spinlock into the wl3501_reset and removes it from
wl3501_tx_timeout.
Found by Linux Driver Verification project (linuxtesting.org)
Signed-off-by: Pavel Andrianov <redacted>
Acked-by: Vaishali Thakkar <redacted>