Re: [PATCH] misc: fastrpc: initialize invoke refcount before publish

Ekansh Gupta <[email protected]>
Newsgroups org.kernel.vger.linux-arm-msm,org.freedesktop.lists.dri-devel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On 25-06-2026 00:24, Yousef Alhouseen wrote:
> fastrpc_context_alloc() adds a new invoke context to the pending list
> and the channel IDR before initializing its refcount.
> 
> A racing DSP response can find that context by ID and drop a reference
> before kref_init() has run. Initialize the refcount before publishing the
> context.
> 
Please add Fixes: tag to this.

https://www.kernel.org/doc/html/latest/process/submitting-patches.html#using-reported-by-tested-by-reviewed-by-suggested-by-and-fixes

> Signed-off-by: Yousef Alhouseen <[email protected]>
> ---
>  drivers/misc/fastrpc.c | 3 +--
>  1 file changed, 1 insertion(+), 2 deletions(-)
> 
> diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c
> index 6ced210ca..42fc128e1 100644
> --- a/drivers/misc/fastrpc.c
> +++ b/drivers/misc/fastrpc.c
> @@ -703,6 +703,7 @@ static struct fastrpc_invoke_ctx *fastrpc_context_alloc(
>  	ctx->cctx = cctx;
>  	init_completion(&ctx->work);
>  	INIT_WORK(&ctx->put_work, fastrpc_context_put_wq);
> +	kref_init(&ctx->refcount);
>  
>  	spin_lock(&user->lock);
>  	list_add_tail(&ctx->node, &user->pending);
> @@ -718,8 +719,6 @@ static struct fastrpc_invoke_ctx *fastrpc_context_alloc(
>  	ctx->ctxid = ret << 4;
>  	spin_unlock_irqrestore(&cctx->lock, flags);
>  
> -	kref_init(&ctx->refcount);
> -
>  	return ctx;
>  err_idr:
>  	spin_lock(&user->lock);
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.