From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753372Ab1H0O4X (ORCPT ); Sat, 27 Aug 2011 10:56:23 -0400 Received: from cantor2.suse.de ([195.135.220.15]:46438 "EHLO mx2.suse.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752483Ab1H0O4R (ORCPT ); Sat, 27 Aug 2011 10:56:17 -0400 X-Mailbox-Line: From gregkh@clark.kroah.org Fri Aug 26 15:01:20 2011 Message-Id: <20110826220120.313375814@clark.kroah.org> User-Agent: quilt/0.48-16.4 Date: Fri, 26 Aug 2011 14:58:28 -0700 From: Greg KH To: linux-kernel@vger.kernel.org, stable@kernel.org Cc: stable-review@kernel.org, torvalds@linux-foundation.org, akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk, Daniel Mack , Takashi Iwai Subject: [07/19] ALSA: snd-usb-caiaq: Correct offset fields of outbound iso_frame_desc In-Reply-To: <20110826220137.GA14059@kroah.com> Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 2.6.32-longterm review patch. If anyone has any objections, please let us know. ------------------ From: Daniel Mack commit 15439bde3af7ff88459ea2b5520b77312e958df2 upstream. This fixes faulty outbount packets in case the inbound packets received from the hardware are fragmented and contain bogus input iso frames. The bug has been there for ages, but for some strange reasons, it was only triggered by newer machines in 64bit mode. Signed-off-by: Daniel Mack Reported-and-tested-by: William Light Reported-by: Pedro Ribeiro Signed-off-by: Takashi Iwai Signed-off-by: Greg Kroah-Hartman --- sound/usb/caiaq/audio.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) --- a/sound/usb/caiaq/audio.c +++ b/sound/usb/caiaq/audio.c @@ -468,6 +468,7 @@ static void read_completed(struct urb *u struct snd_usb_caiaqdev *dev; struct urb *out; int frame, len, send_it = 0, outframe = 0; + size_t offset = 0; if (urb->status || !info) return; @@ -488,7 +489,8 @@ static void read_completed(struct urb *u len = urb->iso_frame_desc[outframe].actual_length; out->iso_frame_desc[outframe].length = len; out->iso_frame_desc[outframe].actual_length = 0; - out->iso_frame_desc[outframe].offset = BYTES_PER_FRAME * frame; + out->iso_frame_desc[outframe].offset = offset; + offset += len; if (len > 0) { spin_lock(&dev->spinlock); @@ -504,7 +506,7 @@ static void read_completed(struct urb *u } if (send_it) { - out->number_of_packets = FRAMES_PER_URB; + out->number_of_packets = outframe; out->transfer_flags = URB_ISO_ASAP; usb_submit_urb(out, GFP_ATOMIC); }