Bluetooth: RFCOMM: don't call kfree_skb() under spin_lock_irqsave()
authorYang Yingliang <yangyingliang@huawei.com>
Wed, 7 Dec 2022 02:18:35 +0000 (10:18 +0800)
committerLuiz Augusto von Dentz <luiz.von.dentz@intel.com>
Mon, 12 Dec 2022 22:19:26 +0000 (14:19 -0800)
It is not allowed to call kfree_skb() from hardware interrupt
context or with interrupts being disabled. So replace kfree_skb()
with dev_kfree_skb_irq() under spin_lock_irqsave().

Fixes: 81be03e026dc ("Bluetooth: RFCOMM: Replace use of memcpy_from_msg with bt_skb_sendmmsg")
Signed-off-by: Yang Yingliang <yangyingliang@huawei.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
net/bluetooth/rfcomm/core.c

index 7324764384b6773074032ad671777bf86bd3360e..8d6fce9005bddf1bd4e7a53ea02b3a4663bf7ebd 100644 (file)
@@ -590,7 +590,7 @@ int rfcomm_dlc_send(struct rfcomm_dlc *d, struct sk_buff *skb)
 
                ret = rfcomm_dlc_send_frag(d, frag);
                if (ret < 0) {
-                       kfree_skb(frag);
+                       dev_kfree_skb_irq(frag);
                        goto unlock;
                }