Takashi Iwai e7343a
From 08880f8e08cbd814e870e9d3ab9530abc1bce226 Mon Sep 17 00:00:00 2001
Takashi Iwai e7343a
From: Jia-Ju Bai <baijiaju1990@163.com>
Takashi Iwai e7343a
Date: Sun, 8 Oct 2017 19:54:07 +0800
Takashi Iwai e7343a
Subject: [PATCH] rtl8188eu: Fix a possible sleep-in-atomic bug in rtw_disassoc_cmd
Takashi Iwai e7343a
Git-commit: 08880f8e08cbd814e870e9d3ab9530abc1bce226
Takashi Iwai e7343a
Patch-mainline: v4.15-rc1
Takashi Iwai e7343a
References: bsc#1051510
Takashi Iwai e7343a
Takashi Iwai e7343a
The driver may sleep under a spinlock, and the function call path is:
Takashi Iwai e7343a
rtw_set_802_11_bssid(acquire the spinlock)
Takashi Iwai e7343a
  rtw_disassoc_cmd
Takashi Iwai e7343a
    kzalloc(GFP_KERNEL) --> may sleep
Takashi Iwai e7343a
Takashi Iwai e7343a
To fix it, GFP_KERNEL is replaced with GFP_ATOMIC.
Takashi Iwai e7343a
This bug is found by my static analysis tool and my code review.
Takashi Iwai e7343a
Takashi Iwai e7343a
Signed-off-by: Jia-Ju Bai <baijiaju1990@163.com>
Takashi Iwai e7343a
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Takashi Iwai e7343a
Acked-by: Takashi Iwai <tiwai@suse.de>
Takashi Iwai e7343a
Takashi Iwai e7343a
---
Takashi Iwai e7343a
 drivers/staging/rtl8188eu/core/rtw_cmd.c |    2 +-
Takashi Iwai e7343a
 1 file changed, 1 insertion(+), 1 deletion(-)
Takashi Iwai e7343a
Takashi Iwai e7343a
--- a/drivers/staging/rtl8188eu/core/rtw_cmd.c
Takashi Iwai e7343a
+++ b/drivers/staging/rtl8188eu/core/rtw_cmd.c
Takashi Iwai e7343a
@@ -522,7 +522,7 @@ u8 rtw_disassoc_cmd(struct adapter *pada
Takashi Iwai e7343a
 
Takashi Iwai e7343a
 	if (enqueue) {
Takashi Iwai e7343a
 		/* need enqueue, prepare cmd_obj and enqueue */
Takashi Iwai e7343a
-		cmdobj = kzalloc(sizeof(*cmdobj), GFP_KERNEL);
Takashi Iwai e7343a
+		cmdobj = kzalloc(sizeof(*cmdobj), GFP_ATOMIC);
Takashi Iwai e7343a
 		if (!cmdobj) {
Takashi Iwai e7343a
 			res = _FAIL;
Takashi Iwai e7343a
 			kfree(param);