From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f177.google.com (mail-pf1-f177.google.com [209.85.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D6C5238F947 for ; Mon, 18 May 2026 19:40:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.177 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779133232; cv=none; b=d486ODYfpoaS3soAc+qZrUL5qLspbqBZkmNkiczue3R4movTMloP73q4x55CTajN93Hy9SZB0+rcPFJE87tpDJy3No6ugARv7gwPiH/+1735qf80lB0S+fUyuuhQpwkt0/WsdOpWn7GDBsw6yY6HL+K/varkzu2Xs0zotBvea/o= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779133232; c=relaxed/simple; bh=wKXl8y8wUe+rJNJmHqOBxEz0hRo+ZGkdSMCkKFWiIbE=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Wq9kZqGQ1lepqVoo5S2GIkzkbx5NaEDV7yM+4QH5E5ciXr/D0bbJCfxjt17g524XVpZPAh/YEXwr5G3wglFmap54sX48vpkQ2R8ezI0fWwGlCiDWmg529XPwkPrwXyww6+lGDWrpNTC5w0Ud+UAvBHYEhoccY2PT3yollcYmrr0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=iov1aCj1; arc=none smtp.client-ip=209.85.210.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="iov1aCj1" Received: by mail-pf1-f177.google.com with SMTP id d2e1a72fcca58-837dfccd950so1221415b3a.0 for ; Mon, 18 May 2026 12:40:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779133230; x=1779738030; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=JwhsmHK7kOuOjmpUhw7nH/iDxBwlkv7cOTMO53PauZM=; b=iov1aCj1B5kLO/CyqR41fCrLiXy/x4ERvlbv7EIJNLRkYN3MaG66fcMV43zPJhDSUd iyqZA3gMNcReelt+zhTwHwXY7xPnfG1rIEraltoUzzDrwXuupnYjo+Ri4DGgCJ8BEHsW gOU5CpCTKF+xc3bVix5X7tAF8DcHwegE8TGOAH4ynn893m5SPJPtD9RJjL9D/4Bk36bX zXkhvKlby+DoquapRurYImVZmmF2s4++Thrfz3KA/8i7WVvMAjDXO563xdUUDtXWEHTX dYt06aeGd+TJHZoo3/OHYUSe+t2zWhTCWKKr9j9UPqNJbgdaPl+fLYXg4eLEZRA6A0bs HGYQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779133230; x=1779738030; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=JwhsmHK7kOuOjmpUhw7nH/iDxBwlkv7cOTMO53PauZM=; b=ZH4FvdBQSMZ+f4v+hdf6boqrEa8uVWfyXcrReJNTOV+Uu4YE+Mgmt9/f2WJHP83fDH i42mIk6F6JJ/u6pStxvdThE7/IufHg01zNjQ702WiHhQa6nerJYFBotB8k1yt32Kda6e k6fRI1a1vd809kevwWPoSgIsr9QqdgZPOdISK0wk4kMF/clHG0Nc4LEKMH0BwvnMRqvr u9kkqCUV3GKHAYeIlLZGZpWGeKZJZddiWL2UpzStSteUA2e9EDCEw29titjopU6vcPo7 gZEpGPuuBP0xB+QmW6UjTS24gf+s2ayI12UqJ2VeFfHuDkstD2nBAyjSNrup4aFS5zmX D3RQ== X-Forwarded-Encrypted: i=1; AFNElJ+kn3SX/R7hMLonUJ6PVTFA2Cq4gMu0xXXX12MjdlYC2H8nFNwSlBaS/PtI2GJMSaQVFt+J/Mxr9S6D5iQ=@vger.kernel.org X-Gm-Message-State: AOJu0YwSPUGpbTRQ+C/UcN13dkS8n40jdDLX4RZRTkov1TPmb+//S0NX MsKw2McbPc5/fZYlMLC/Osvp7nNz94EsAAXrbKyL7Zfr6IdoV9QHPCm5 X-Gm-Gg: Acq92OF2PWrNB1RyybGtx7265iDMtkiM1dmmVa+vyqy3ceU2libBzYGoQM/lb0XFbve MHK/F5u3V9U4z1tWhDJBwnZ2uARSTSMKSy4tzTjXiGIF7Q+q2qLhyG7PESHPkHcLHtmpRT0GmfD Q/FSk2fVF8CPr81Rctw+TCCAOWJreMZtw0XDj2E5YevBbwBmMv135IEBiaS10793pMvzm1quixQ 1OU7qVknN0jX3LdhT568Zs18D7Y/cFp8RJpMgn7ABKywNt2CleBWQsHOgVwGkjTknXxtUY0WZmA 5qjWaT/r0F0TNqkNwqdxKmzhQWVSrB2apzozFC9sqKdP4aCWpqPwytFhjHZqZRV+x+A7Z2eqwF0 DkQwBaJNgLYthBqxJSR3qBbvWXxnFApmqoeMb35yn3dg4hy6t+7qbkqpG7WMqavAhp0CwbpWmQu zyKLH3fqg4xLtDOsMakMP/AwfNUgW0iXAiV85DEBkgb6gOG9/7DLFYDET3DCk= X-Received: by 2002:a05:6a20:7f93:b0:3aa:60e0:b2ed with SMTP id adf61e73a8af0-3b22ebc68ddmr18073852637.27.1779133230087; Mon, 18 May 2026 12:40:30 -0700 (PDT) Received: from csl-conti-dell7858.ntu.edu.sg ([155.69.195.57]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-c82bb07d2fesm14237808a12.9.2026.05.18.12.40.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 18 May 2026 12:40:29 -0700 (PDT) From: Maoyi Xie To: Takashi Iwai , Jaroslav Kysela Cc: linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 1/2] ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() Date: Tue, 19 May 2026 03:40:22 +0800 Message-Id: <20260518194023.1667857-2-maoyixie.tju@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260518194023.1667857-1-maoyixie.tju@gmail.com> References: <87o6ic4izy.wl-tiwai@suse.de> <20260518194023.1667857-1-maoyixie.tju@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit snd_timer_dev_register() walks snd_timer_list looking for the ordered insertion point and on loop fall-through passes &timer1->device_list to list_add_tail(): list_for_each_entry(timer1, &snd_timer_list, device_list) { ... break; /* on found-position */ ... } list_add_tail(&timer->device_list, &timer1->device_list); When the loop walks all entries without break, timer1 is past-the-end. &timer1->device_list aliases &snd_timer_list (the list head) via container_of offset cancellation, so the insert lands at the list tail. That is the intended behaviour, but the access is undefined per C11 even though it works in practice. Track an explicit insert_before pointer initialised to the list head and overwritten to &timer1->device_list only when the loop breaks early. The observable behaviour is unchanged. Fixes: 9244b2c3079f ("[ALSA] alsa core: convert to list_for_each_entry*") Signed-off-by: Maoyi Xie --- sound/core/timer.c | 19 ++++++++++++++----- 1 file changed, 14 insertions(+), 5 deletions(-) --- a/sound/core/timer.c 2026-05-18 19:17:08.274971549 +0800 +++ b/sound/core/timer.c 2026-05-18 19:17:46.598676455 +0800 @@ -1007,6 +1007,7 @@ { struct snd_timer *timer = dev->device_data; struct snd_timer *timer1; + struct list_head *insert_before = &snd_timer_list; if (snd_BUG_ON(!timer || !timer->hw.start || !timer->hw.stop)) return -ENXIO; @@ -1016,28 +1017,36 @@ guard(mutex)(®ister_mutex); list_for_each_entry(timer1, &snd_timer_list, device_list) { - if (timer1->tmr_class > timer->tmr_class) + if (timer1->tmr_class > timer->tmr_class) { + insert_before = &timer1->device_list; break; + } if (timer1->tmr_class < timer->tmr_class) continue; if (timer1->card && timer->card) { - if (timer1->card->number > timer->card->number) + if (timer1->card->number > timer->card->number) { + insert_before = &timer1->device_list; break; + } if (timer1->card->number < timer->card->number) continue; } - if (timer1->tmr_device > timer->tmr_device) + if (timer1->tmr_device > timer->tmr_device) { + insert_before = &timer1->device_list; break; + } if (timer1->tmr_device < timer->tmr_device) continue; - if (timer1->tmr_subdevice > timer->tmr_subdevice) + if (timer1->tmr_subdevice > timer->tmr_subdevice) { + insert_before = &timer1->device_list; break; + } if (timer1->tmr_subdevice < timer->tmr_subdevice) continue; /* conflicts.. */ return -EBUSY; } - list_add_tail(&timer->device_list, &timer1->device_list); + list_add_tail(&timer->device_list, insert_before); return 0; } -- 2.34.1