From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f173.google.com (mail-pf1-f173.google.com [209.85.210.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 21895385D64 for ; Sat, 25 Jul 2026 15:51:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.173 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784994690; cv=none; b=nAirEsQo1FA1dj1DyLWBNnBExE8wkLVo1cYTuoQox6nvZvLF42aeQ1nwp80f6iPOjRbEEQhGrDDtMMYCOirGw6APAFcWpPHGsplyZGFkLiwErpdh9IL/Gq6aXC8lHP0+jmSdKnd4KjFKAnSA6X8kJzrcBD7UJQ+2PDMOufu5cfY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784994690; c=relaxed/simple; bh=Tmn2H+coHp+aXqT7nJrE7fJQeOzk6A1X1pgMjKiPtIk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=Nrt0fizymNTM5yLAR/mZZtrYkvQaS3Ng0/+Ggfx5PIUllVtTnMgnxEaeUHNd/e+zzUUi2uj9MF8hbsy74wBLy/5L3E3nGhnzds9yFeZ0b6jT0vZXidgYeTA4jyxpKKupfs8RDCZnIZsAr0frsVIBSw1oEPg9+Cf4c/j+s/xWekE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=AEgnm3Zw; arc=none smtp.client-ip=209.85.210.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="AEgnm3Zw" Received: by mail-pf1-f173.google.com with SMTP id d2e1a72fcca58-84830c774a0so1406967b3a.1 for ; Sat, 25 Jul 2026 08:51:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784994679; x=1785599479; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=hmZB8vxgqONx/9fM+xBM/ZafnHK7P0YzFF7u9E03lJ8=; b=AEgnm3ZwuvFjPaAa1fme3Z/Jxk9UlnyXiudxgt72g8PnbnnK1fImWsV8DMepIbNl7x ADSn5L1mNDLa31fZ2VhfFVpofygZG+q8XarXZKqweKWzck8UPw0u+kd9TVfJ6Ak8JQFW WU/IBMXmCvcB4EBD2IDnMvbxbQtYx/5UHAnV5fvf7s4hhml/hCbvejVO7ZvV7dqD2rKP yuF2L/o/Mn1yDUo8OWWyl8A19s/QCYMB2CI3S5lpE4nNaNHX8E6rz0m81pE5g0UqQtM0 Pj43z/mvM5Ncm0LXFy2ilZ4R9o+avlpSiL1kofACzyULyFrkSFHE6j0bP9PZMCOoq2WP 2Y/w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784994679; x=1785599479; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=hmZB8vxgqONx/9fM+xBM/ZafnHK7P0YzFF7u9E03lJ8=; b=I/6SiWpsQYCdnMXTYdt1Xrog53AgWZUTT4xjrTQAuVWBkMOo96g5NX4SRcY/y5/bCW 6NY4x0YwqRaLxph19CWM+WtQIDY9za7wzxa3k3XQJNEdfvDXYqBqqQPCK44LcPQSbI9n K4Mce4btesSMbdWTj1iRt5H5BMWOTUF8oTDVILI1wbFadmqqNmz0GiIiuMhBe4mhiqq0 xJDyrFx9jrQL5iEDSioeaAXzp1IG1TRC1bwdAu02yI6YYyZGpiSmlzS4flLFsjuyuFY/ j3s5Lf/Bbj7bJ1ZF8JRu1PKDBcLhRK2/FLRgZumkGcdfVa0rkUSgf/akRgwsReaK4bU3 ARmA== X-Forwarded-Encrypted: i=1; AHgh+RoLBvxTxfubAVu5qk2PL12yuqmZdMkjsQ1p5SJfTkq/5hPeVUnVgOAssDIF0w4M2QQjPBFKRZluOzlGVAA=@vger.kernel.org X-Gm-Message-State: AOJu0Yw4lA32S3TQjioVg0MPHvhmz6xGUFDhYHvYkjEK4+YSGTqu35wB N9R2pUdvHw0qn/y4y83tIC2+JnfPZiaAwm62m2EMXpZS0SC13yoBQTBSLXA5yv6y X-Gm-Gg: AR+sD1017LNkKtCYf5a9OTbOgifxSQXODQzfxkTFEGGFsbV5uSYI3mSi7SfeXH+hEcC LZ9aTTCG0uBifRHNQwSqRQr/z2VpcnO7931zSsaVyCAmTd/6o1dTl8SWGs6w59Xo/cZtyjZAYpB k6DUORm8b1zzRTNfEfw8ih8gQpHJuAZEfWhWIoaHx2E4pvIeijpO8SC9OnIGUHRc8yqFFTuX+Kq 7jZnllV/aue8VmNpeqDhuNV8XVQfCH1wQpVMQv4HHFh5cROxBjHCe2PSUUcjHG2jGwbXViBVWS6 XVOMrRvZcDzqppJcLNSl7tuwcT37JeXl3jyX/DYCVlZzYj03jT/YcnCZqQvPuHrV7bTNL5CtJO8 /AnnGEASON97YxkCldwG4a7BXCT4s2EprnK/o6EseWpCJLNiUmvpEjke5qUunSYajxnmHkPf3Gm 96Wdzq3H3NxFQevkCv07fJhxD10WIqCxs= X-Received: by 2002:a05:6a21:6b02:b0:3c3:6cfb:4ed7 with SMTP id adf61e73a8af0-3c67daecd42mr2418919637.30.1784994679431; Sat, 25 Jul 2026 08:51:19 -0700 (PDT) Received: from kernel-dev ([49.36.97.234]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-314bc59e9fesm10492872eec.27.2026.07.25.08.51.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 25 Jul 2026 08:51:18 -0700 (PDT) From: Aditya Chari To: gregkh@linuxfoundation.org Cc: vaibhav.sr@gmail.com, mgreer@animalcreek.com, johan@kernel.org, elder@kernel.org, error27@gmail.com, greybus-dev@lists.linaro.org, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org, Aditya Chari Subject: [PATCH v4] greybus: audio: Split gb_audio_gb_get_topology() into size query and data fetch Date: Sat, 25 Jul 2026 21:21:08 +0530 Message-ID: <20260725155108.7060-1-adi25charis@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `gb_audio_gb_get_topology()` combined three separate responsibilities into a single call: querying the topology size, allocating a buffer for it, and fetching the topology data into that buffer. This left callers with no way to perform any of these steps independently, and forced the kzalloc() allocation to live inside the protocol‑layer driver rather than the caller, as already flagged by a FIXME comment at the call site in `audio_module.c`. Split the function into two: - `gb_audio_gb_get_topology_size()` – queries only the topology size - `gb_audio_gb_get_topology()` – fetches topology data into a caller‑supplied buffer of a given size Update the only caller, `gb_audio_probe()` in `audio_module.c`, to query the size first, allocate the topology buffer itself, then fetch the data into it, freeing the buffer via the existing `free_topology` error path on failure. The topology size is now stored as `size_t` and validated in the caller before allocation, addressing the earlier TODO and FIXME comments. This resolves both the "TODO: Split into separate calls" comment above the original function in `audio_gb.c` and the FIXME comment at the call site in `audio_module.c`, both of which are removed as part of this change. No functional change in behavior for the existing probe path. Signed-off-by: Aditya Chari S Reviewed-by: Dan Carpenter --- v4: - Reorder tags (Signed-off-by before Reviewed-by) as suggested by Dan. v3: - Rebased against latest staging-next. v2: - Fold in review feedback from Dan Carpenter. - Store topology size as size_t instead of u16. - Move topology size validation into gb_audio_probe() before kzalloc(). - Use -EINVAL for invalid topology size. - Drop unrelated dev_err() formatting cleanup. - Compile-tested with `make M=drivers/staging/greybus`. - Run checkpatch.pl on the updated patch; no issues reported. --- drivers/staging/greybus/audio_codec.h | 4 ++- drivers/staging/greybus/audio_gb.c | 45 +++++++------------------- drivers/staging/greybus/audio_module.c | 27 ++++++++++++---- 3 files changed, 35 insertions(+), 41 deletions(-) diff --git a/drivers/staging/greybus/audio_codec.h b/drivers/staging/greybus/audio_codec.h index f3f7a7ec6..b45cd257d 100644 --- a/drivers/staging/greybus/audio_codec.h +++ b/drivers/staging/greybus/audio_codec.h @@ -178,8 +178,10 @@ int gbaudio_register_module(struct gbaudio_module_info *module); void gbaudio_unregister_module(struct gbaudio_module_info *module); /* protocol related */ +int gb_audio_gb_get_topology_size(struct gb_connection *connection, + size_t *size); int gb_audio_gb_get_topology(struct gb_connection *connection, - struct gb_audio_topology **topology); + struct gb_audio_topology *topology, size_t size); int gb_audio_gb_get_control(struct gb_connection *connection, u8 control_id, u8 index, struct gb_audio_ctl_elem_value *value); diff --git a/drivers/staging/greybus/audio_gb.c b/drivers/staging/greybus/audio_gb.c index 144591f1a..2e6f155d8 100644 --- a/drivers/staging/greybus/audio_gb.c +++ b/drivers/staging/greybus/audio_gb.c @@ -8,13 +8,10 @@ #include #include "audio_codec.h" -/* TODO: Split into separate calls */ -int gb_audio_gb_get_topology(struct gb_connection *connection, - struct gb_audio_topology **topology) +int gb_audio_gb_get_topology_size(struct gb_connection *connection, + size_t *size) { struct gb_audio_get_topology_size_response size_resp; - struct gb_audio_topology *topo; - u16 size; int ret; ret = gb_operation_sync(connection, GB_AUDIO_TYPE_GET_TOPOLOGY_SIZE, @@ -22,38 +19,18 @@ int gb_audio_gb_get_topology(struct gb_connection *connection, if (ret) return ret; - size = le16_to_cpu(size_resp.size); - if (size < sizeof(*topo)) - return -ENODATA; - - topo = kzalloc(size, GFP_KERNEL); - if (!topo) - return -ENOMEM; - - ret = gb_operation_sync(connection, GB_AUDIO_TYPE_GET_TOPOLOGY, NULL, 0, - topo, size); - if (ret) { - kfree(topo); - return ret; - } - - /* - * The size_* fields are supplied by the module and are used by - * gbaudio_tplg_parse_data() to compute offsets into the blob; make - * sure the sections fit within the fetched topology, so walking it - * cannot read out of bounds. - */ - if ((u64)le32_to_cpu(topo->size_dais) + le32_to_cpu(topo->size_controls) + - le32_to_cpu(topo->size_widgets) + le32_to_cpu(topo->size_routes) > - size - sizeof(*topo)) { - kfree(topo); - return -EINVAL; - } - - *topology = topo; + *size = le16_to_cpu(size_resp.size); return 0; } +EXPORT_SYMBOL_GPL(gb_audio_gb_get_topology_size); + +int gb_audio_gb_get_topology(struct gb_connection *connection, + struct gb_audio_topology *topology, size_t size) +{ + return gb_operation_sync(connection, GB_AUDIO_TYPE_GET_TOPOLOGY, NULL, 0, + topology, size); +} EXPORT_SYMBOL_GPL(gb_audio_gb_get_topology); int gb_audio_gb_get_control(struct gb_connection *connection, diff --git a/drivers/staging/greybus/audio_module.c b/drivers/staging/greybus/audio_module.c index 12c376c47..4cd1f42c1 100644 --- a/drivers/staging/greybus/audio_module.c +++ b/drivers/staging/greybus/audio_module.c @@ -239,6 +239,7 @@ static int gb_audio_probe(struct gb_bundle *bundle, struct gb_audio_manager_module_descriptor desc; struct gbaudio_data_connection *dai, *_dai; int ret, i; + size_t size; struct gb_audio_topology *topology; /* There should be at least one Management and one Data cport */ @@ -304,16 +305,30 @@ static int gb_audio_probe(struct gb_bundle *bundle, } gbmodule->dev_id = gbmodule->mgmt_connection->intf->interface_id; - /* - * FIXME: malloc for topology happens via audio_gb driver - * should be done within codec driver itself - */ - ret = gb_audio_gb_get_topology(gbmodule->mgmt_connection, &topology); + ret = gb_audio_gb_get_topology_size(gbmodule->mgmt_connection, &size); if (ret) { - dev_err(dev, "%d:Error while fetching topology\n", ret); + dev_err(dev, "%d:Error while fetching topology size\n", ret); + goto disable_connection; + } + + if (size < sizeof(*topology)) { + dev_err(dev, "Invalid topology size: %zu\n", size); + ret = -EINVAL; goto disable_connection; } + topology = kzalloc(size, GFP_KERNEL); + if (!topology) { + ret = -ENOMEM; + goto disable_connection; + } + + ret = gb_audio_gb_get_topology(gbmodule->mgmt_connection, topology, size); + if (ret) { + dev_err(dev, "%d:Error while fetching topology\n", ret); + goto free_topology; + } + /* process topology data */ ret = gbaudio_tplg_parse_data(gbmodule, topology); if (ret) { -- 2.53.0