| From 56dc118c7fcb196a347e14c6d6a287f3d541a1a0 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Sun, 17 Apr 2022 22:16:41 +0800 |
| Subject: drivers: staging: rtl8192e: Fix deadlock in rtllib_beacons_stop() |
| |
| From: Duoming Zhou <duoming@zju.edu.cn> |
| |
| [ Upstream commit 9b6bdbd9337de3917945847bde262a34a87a6303 ] |
| |
| There is a deadlock in rtllib_beacons_stop(), which is shown |
| below: |
| |
| (Thread 1) | (Thread 2) |
| | rtllib_send_beacon() |
| rtllib_beacons_stop() | mod_timer() |
| spin_lock_irqsave() //(1) | (wait a time) |
| ... | rtllib_send_beacon_cb() |
| del_timer_sync() | spin_lock_irqsave() //(2) |
| (wait timer to stop) | ... |
| |
| We hold ieee->beacon_lock in position (1) of thread 1 and |
| use del_timer_sync() to wait timer to stop, but timer handler |
| also need ieee->beacon_lock in position (2) of thread 2. |
| As a result, rtllib_beacons_stop() will block forever. |
| |
| This patch extracts del_timer_sync() from the protection of |
| spin_lock_irqsave(), which could let timer handler to obtain |
| the needed lock. |
| |
| Signed-off-by: Duoming Zhou <duoming@zju.edu.cn> |
| Link: https://lore.kernel.org/r/20220417141641.124388-1-duoming@zju.edu.cn |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/staging/rtl8192e/rtllib_softmac.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/drivers/staging/rtl8192e/rtllib_softmac.c b/drivers/staging/rtl8192e/rtllib_softmac.c |
| index da74dc49b95e..f46def63967b 100644 |
| --- a/drivers/staging/rtl8192e/rtllib_softmac.c |
| +++ b/drivers/staging/rtl8192e/rtllib_softmac.c |
| @@ -655,9 +655,9 @@ static void rtllib_beacons_stop(struct rtllib_device *ieee) |
| spin_lock_irqsave(&ieee->beacon_lock, flags); |
| |
| ieee->beacon_txing = 0; |
| - del_timer_sync(&ieee->beacon_timer); |
| |
| spin_unlock_irqrestore(&ieee->beacon_lock, flags); |
| + del_timer_sync(&ieee->beacon_timer); |
| |
| } |
| |
| -- |
| 2.35.1 |
| |