• Steven Rostedt's avatar
    Bluetooth: hci_qca: Use del_timer_sync() before freeing · 72ef9844
    Steven Rostedt authored
    While looking at a crash report on a timer list being corrupted, which
    usually happens when a timer is freed while still active. This is
    commonly triggered by code calling del_timer() instead of
    del_timer_sync() just before freeing.
    
    One possible culprit is the hci_qca driver, which does exactly that.
    
    Eric mentioned that wake_retrans_timer could be rearmed via the work
    queue, so also move the destruction of the work queue before
    del_timer_sync().
    
    Cc: Eric Dumazet <eric.dumazet@gmail.com>
    Cc: stable@vger.kernel.org
    Fixes: 0ff252c1
    
     ("Bluetooth: hciuart: Add support QCA chipset for UART")
    Signed-off-by: default avatarSteven Rostedt (Google) <rostedt@goodmis.org>
    Signed-off-by: default avatarMarcel Holtmann <marcel@holtmann.org>
    72ef9844
hci_qca.c 60.3 KB