From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f181.google.com (mail-pg1-f181.google.com [209.85.215.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F342438A29A for ; Mon, 18 May 2026 19:40:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779133231; cv=none; b=pkPi4NjYnZah+9jIdN534k4pVWfQ2Q++iwEpfagp272P4DWCjrs8N8J7KdUkwCkgFV76YWhaQy4f9jwefzfphjft4NJk3RvD8pA3GuuPrUQRToINe2WCUpHaAiKFZN3qgsbd+mpGzkhhDz4j5inwXnelnALhrot97obHA4QnRJ4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779133231; c=relaxed/simple; bh=BuEk7fSX8V17vakuWtMqTXWlzRacwBDKMVQLZec0LYA=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=iPcjADhsk51iRHYivgFpzDZwtCmvrpG3ePY6EVB4wEUz6XoaLpJuP0GGEqEtL9LjCzDmYFv6aklMsPCGQji8aDZc9aQo81FyfSsoNOdohkn3WOzXNSUgs7QYDXNQ81vWMbGtx2O2LJgRd9D1SLIM7Cr56udb84oGeOXCAZYUnoU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=NMlK3BhI; arc=none smtp.client-ip=209.85.215.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="NMlK3BhI" Received: by mail-pg1-f181.google.com with SMTP id 41be03b00d2f7-c80203b9d7bso1113401a12.0 for ; Mon, 18 May 2026 12:40:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779133228; x=1779738028; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=icbuaBQYuTdOy7kk8RS3OZKCGtT//Fk4igqsQXH55QI=; b=NMlK3BhIHrfFcjAD+ejoiRKq5ldA8vHfDngPf26cdTbaHxHXVU4tNlNVqTbdcE4HzC e3edSdOpwhLH9p7FPxTZGTyZNq7o6/c+JumUJaBp+Kf9BFmFhhSoZsw77BDKjFum5iGR dFfQv0YYjAhcyHkOLB1HJgttj6XCXEtZIqaCvghh+tVv68ba15nmqaH+2rokglch2G0B joj7OHF6D8oNRcg46zM1CPd7TsOhPzrEhZKa1B7c1BUivSW+j7Gyaxz8YLGuuqSJiI6w pJB8gPROvjzh2yV4LOivLCAt9j3wGnYAh+i9Sq+R5s+V4YhYWSWWMNvA2yp0scsQ81o7 X9ag== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779133228; x=1779738028; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=icbuaBQYuTdOy7kk8RS3OZKCGtT//Fk4igqsQXH55QI=; b=i4YBZr4ak9iN3Ss5n4CRBuKEeVFIf4DBww5kJRITUDbJmUTOapm9bzkE8wvGiOfoT8 tw6OSRzqDDFkIHvOH61yl1O8fVs9aokog1WY6afqLxd492Wo90c1wTGKuWe/ciRrasN4 SJygcXaW9nCMZsA/7CAFY0GKP5M9ZrAZ4QWY2xHI0KdEyL5ytj9hpcmMbtmkQ1oU3m40 Aqw6eWe7ogE5iloawRHC1IL8DWKgfsArYmNRwzeh4i8yELFSZ9aGfBvHDQZljRViLfBS yhd+sMpm2/Et5Ra2o0zA2q2A2vUPnCuehlJ5KVlYE0VXXVMId8wHk22Vz3ZDtW5gLPAh R39Q== X-Forwarded-Encrypted: i=1; AFNElJ91N6AoWqg6MibMuTe0whkgCN+ICf9JvfvAdR4Z+66VgVKbuPYtNd3MV9kkRpyiX924mD1H5nRCIrZyBvY=@vger.kernel.org X-Gm-Message-State: AOJu0YxTmhpHmln2WVJTmsn1Cgry4kUemJ4mKimEhkY/rAmSY0eYJE2d EkcvjPsLjP9Zgl235wWWev3+g0fQcEVTuPs3CF4aEsklE9RBh60XccER X-Gm-Gg: Acq92OGWdN9wYKodk49bcKzZKU7RXB+tIPed3lHr7ZwATKZw27v3meQWQkGyJyOx6dQ vQWqHOrmecWrd3A1MwAoK2uvtTY/9wMoPRPAk00czdcwidLxTQAbymqS5+JEmzjZPM/Xj3iMdSX a3HowtRSGmsQj8VytR060ad43A8IwBvF0UO1MxqAuprv+13aKl2zLw9pGO6trRGDuPEnya4YtGE IYh4z75x6rWXBk0Ohuzm7A5htkz5kZNpu9vVaFPVdk8Qc8HtB9WPN8EXBOl0m1r9LnfIaEexwfe SJqGqRWSE7qkZTD9Jmr6XeB/MF4Qf3K1hCDCmlajtlvxhWnoG+IRtgzuSFGBQGjdoB4zWGgXGhn LceOBL3J51aq4Mdlkc8jaBPUTFOjYJKzbosyZRZVq1OiohQpaj3dwV10ugoAjRk52ZDpgG5POvm Nt/yECztNUl+SMlmBa7uYIhfdJNNOBAsAOeZDORdj4s+xybKG5bVBtqt1s7U984/Adko6WGQ== X-Received: by 2002:a05:6a20:7f9a:b0:39f:94cb:1bc with SMTP id adf61e73a8af0-3b22e7c24admr19330410637.1.1779133228150; Mon, 18 May 2026 12:40:28 -0700 (PDT) Received: from csl-conti-dell7858.ntu.edu.sg ([155.69.195.57]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-c82bb07d2fesm14237808a12.9.2026.05.18.12.40.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 12:40:27 -0700 (PDT) From: Maoyi Xie To: Takashi Iwai , Jaroslav Kysela Cc: linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 0/2] ALSA: avoid past-the-end iterators in timer/seq port registration Date: Tue, 19 May 2026 03:40:21 +0800 Message-Id: <20260518194023.1667857-1-maoyixie.tju@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <87o6ic4izy.wl-tiwai@suse.de> References: <87o6ic4izy.wl-tiwai@suse.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Two fixes in sound/core that remove past-the-end iterator use of the shape list_for_each_entry(iter, head, member) { if (...) break; } list_add_tail(&new, &iter->member); When the loop walks all entries without break, iter is past the end and &iter->member aliases the list head via container_of offset cancellation. The insert lands at the list tail, which is the intended behaviour, but the access is undefined per C11. Takashi Iwai confirmed on the inquiry thread that both sites are bugs introduced by commit 9244b2c3079f ("[ALSA] alsa core: convert to list_for_each_entry*"). The original list_for_each() loop terminated at the list head; the conversion to list_for_each_entry() left the post-loop access using the container struct, which aliases the head via offset cancellation. The patched code tracks an explicit insert_before pointer initialised to the list head and overwritten to &iter->member only when the loop breaks early. Observable behaviour is unchanged. Inquiry thread: https://lore.kernel.org/linux-sound/?q=iterator+used+after+loop+end+in+timer Maoyi Xie (2): ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() sound/core/seq/seq_ports.c | 7 +++++-- sound/core/timer.c | 19 ++++++++++++++----- 2 files changed, 19 insertions(+), 7 deletions(-)