From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 122B6435A9E for ; Wed, 12 Aug 2026 11:32:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.177 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786534367; cv=none; b=DwMiNGtx+OLHvTRAcp1/giidrYxriJaT+/drcH4DT1/yklkoQ4BqA3GB/o1MhcRHrp4GDbIROtVQq5Tj1IBJlETmeDe3L7aLQpz/rueSStbswX5ZHZoimFJ3anzzgFSbujQGxG7XbJrA4/8hy+/P/Lx/XgFA0hOegNiMcNQa/MY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786534367; c=relaxed/simple; bh=vKHGtjMHgyqB1+vSyKomwJLSzFHbToePjolE4qP3+QA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=BUi63/M656mvX/OOx8QCzwVnMG0n0cN8ldMIDzEUxxGdlyF2kRh0zfJnLtBa3uWy35MRfGNoGa6sZqC/sddMOBWnTDOj4KfCZOPV5g2gQcJSU7+BA2F2wjbIWZBsZRYbHKSmb96eP51PCct/rcfGyYAFerJTWImwJNKa+X4NnL0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=WHqOh4Wx; arc=none smtp.client-ip=209.85.214.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="WHqOh4Wx" Received: by mail-pl1-f177.google.com with SMTP id d9443c01a7336-2caea3f742bso11319505ad.0 for ; Wed, 12 Aug 2026 04:32:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786534365; x=1787139165; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=pTa2maH+C+1uwPCaL1BG7q+MNRY6RdcBHt+XiQzKuEw=; b=WHqOh4WxZyBzNJBPu+/18u6bjX6+epP7U4qTDckxvOhN2/NdB6FlseSiE0UL42IXRr umqCQ6bbfweqhtQJMiLut6k+3KY9dklyy9upVAXIU27cYOmyqIBTAzMuXnvoLAMN7Ekw DlGyD4xqtyUWFXawDNnt+wLslHGxHOjx/XYkvzxG6QZS2mDp3X44UBLAeVIsDbUcf/Zq 0XxJGLIE8UuozvsULIRPQ+bdwdjA6i4CL9SPtU1DZ/fmS1+64ATf830Vwq+Nrkfhj6V2 evbuCCB9zg4Zm9JQQnSCHgX+6ClP3Nyl82Am9xc+NNn/sHC3136tW1axQBRAA60MANW6 Gotw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786534365; x=1787139165; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pTa2maH+C+1uwPCaL1BG7q+MNRY6RdcBHt+XiQzKuEw=; b=jQWnF8t0ZO8Wmk0nHt6d4AGTF27fjt8OHjjkuLDZO/RQUvp6ayoG56S/1qrbvmR0AO a8/tSFraQ0ln6p8TG+j3VAOiP/1oN38s8shtBM9TcOcDsqV2jfyTTzcuK95bbi9RFD0u cYjno86+wV4A8GS9lZ8zDY5X3YNNcTB6WhzJTNwUpxZKpmyjMQnHZmGL9OpLlrYuQYB4 nkePW+ovJS5Suszqp1iAaXZO2msyPfgki7iVXsaS0opDCriAC3w/Wwa85bq2BBkjLwMM FymhsaT2DNIf5o4lnTJ4uYeAPa29yfFwMvA8Yvz701u2zP3iin8y2CLMqxscu/kH6xvP hbdQ== X-Forwarded-Encrypted: i=1; AHgh+Rr3oz5/BQoa0/mOm6ooXhfDK/buwJM+XMaeIqmA/mknsqn341ZNOs2k5GH85L2vGtx+Bb4zUhX6AXobz0I=@vger.kernel.org X-Gm-Message-State: AOJu0Yycx9vTX95lMKSczxKW4rFuEZZ5wzj5gRU4qGXze/XW7ibop8ys SGtqtODIezWknjLb4RpOC4qdMRmR7jpic28CLqWndEEfVXoo1IxubSYN5f4w/Q== X-Gm-Gg: AR+sD11p04MRekLwH/2v7DSMTvTZPr0Gx7BWna/PdimWadhfwkPaedZtU2me9jIbvUQ wEtAnYWPtwMmObcJ+Bz4Xq2KjEyywE5GK5IlW9kLeR8sg/22R2aw2jJftz+g2c8qXsA1zYlvIH0 O2CvmLWUlmL6ZpqQQsh3T/X065X0opEUMqL2b2VyeRtBC214J6kvyhcC4e2f7+EQ7X6Ry31DURu 3dJt1XXcMZCWzGef1ijj/HNV5RrLWn9xlbj3cis0wbemWTru3F2OXs300+3j5m2GKqLyRQuFHYd rU8CI0OW55ExkkcHnpOkrim4NibGr05l+fvjuAgt6MsWrZCUI8b18hRii+wlc1B37AvJmHuG4V7 7n0BFfIxDR/3AhHQoKOoYW0PnIgDkOkebgArmRN/aXx1AikUCNT1rRatLGnBC7oU5U5pt1MdLNG w1ntbdwPPeHIXJGiERmKTe+IxseHcgToy867+Y8CZxkRCQ8cZF8mhRYZ9bx+Crj4XardMZBNkI+ 7Ti7jr2voiUAF8vrPu5TS5o7XGwF1o7mhQiSODoldsqWk/UTBEKDMOlkyI+3F+b X-Received: by 2002:a17:90b:520a:b0:38e:8021:2ea9 with SMTP id 98e67ed59e1d1-393017b1e79mr5178137a91.19.1786534365280; Wed, 12 Aug 2026 04:32:45 -0700 (PDT) Received: from nugod-NUC15CRHU5.tail9f095a.ts.net ([218.237.104.87]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-392f94d30f4sm3504029a91.14.2026.08.12.04.32.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 04:32:44 -0700 (PDT) From: HyeongJun An To: Takashi Iwai , Jaroslav Kysela Cc: linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org, HyeongJun An Subject: [PATCH] ALSA: seq: Restore the delivery error code in the bounce event Date: Wed, 12 Aug 2026 20:32:36 +0900 Message-ID: <20260812113236.3941391-1-sammiee5311@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Commit efc86691e4d8 ("ALSA: seq: Fix kernel heap address leak in bounce_error_event()") moved the data.quote.value assignment into the kernel client branch. A user client that sets SNDRV_SEQ_FILTER_BOUNCE used to get the delivery error code there. Now it gets none, and nothing else reports it, because a queued event's write() has already returned success by the time delivery fails. Send struct snd_seq_event_bounce instead, the error code followed by the original event record, which is what the UAPI header has described all along. Store the negative errno. The kernel client branch negates it only because data.quote.value is an unsigned short. The payload grows from 28 to 32 bytes. The snd_seq_read() rounds a variable-length payload up to a multiple of the event size, so a legacy client now needs an 84 byte buffer instead of 56. That is what any event carrying 29 payload bytes has always needed. A UMP client reads 64 bytes either way. Drop the stale promise to copy the external data after the event record as well. That was never implemented, and bounce_error_event() runs with atomic set from the timer interrupt. Fixes: efc86691e4d8 ("ALSA: seq: Fix kernel heap address leak in bounce_error_event()") Assisted-by: Claude:claude-opus-5 Signed-off-by: HyeongJun An --- Notes for the reviewer, not part of the change. A UMP event does not fit the payload. A struct snd_seq_ump_event is 32 bytes while quoted.event is 28, so ump[3] is dropped while SNDRV_SEQ_EVENT_UMP stays set in the copy. That is already true today, but this locks it into the UAPI. Clear the flag, skip bouncing UMP events, or a different layout? I did not want to guess. The err field carries the negative errno. Nothing has ever produced or consumed this struct, so the sign is being chosen here for the first time. Say if you want the positive value instead. I could not check whether any user space sets SNDRV_SEQ_FILTER_BOUNCE, or what buffer size it reads with. sound/core/seq/seq_clientmgr.c | 22 +++++++++++++--------- 1 file changed, 13 insertions(+), 9 deletions(-) diff --git a/sound/core/seq/seq_clientmgr.c b/sound/core/seq/seq_clientmgr.c index 11fa7e825819..c334f88de542 100644 --- a/sound/core/seq/seq_clientmgr.c +++ b/sound/core/seq/seq_clientmgr.c @@ -530,9 +530,10 @@ static struct snd_seq_client *get_event_dest_client(struct snd_seq_event *event) * Return the error event. * * If the receiver client is a user client, the original event is - * encapsulated in SNDRV_SEQ_EVENT_BOUNCE as variable length event. If - * the original event is also variable length, the external data is - * copied after the event record. + * encapsulated in SNDRV_SEQ_EVENT_BOUNCE as variable length event. The + * payload is struct snd_seq_event_bounce, the error code followed by the + * original event record. The external data of a variable length event + * is not copied along. * If the receiver client is a kernel client, the original event is * quoted in SNDRV_SEQ_EVENT_KERNEL_ERROR, since this requires no extra * kmalloc. @@ -541,7 +542,8 @@ static int bounce_error_event(struct snd_seq_client *client, struct snd_seq_event *event, int err, int atomic, int hop) { - struct snd_seq_event bounce_ev, quoted; + struct snd_seq_event_bounce quoted; + struct snd_seq_event bounce_ev; int result; if (client == NULL || @@ -565,14 +567,16 @@ static int bounce_error_event(struct snd_seq_client *client, * variable-length event carries the address of its own * extension cell, and the payload goes out verbatim. */ - quoted = *event; - if (snd_seq_ev_is_variable("ed)) { - quoted.data.ext.len &= ~SNDRV_SEQ_EXT_MASK; - quoted.data.ext.ptr = NULL; + memset("ed, 0, sizeof(quoted)); + quoted.err = err; + quoted.event = *event; + if (snd_seq_ev_is_variable("ed.event)) { + quoted.event.data.ext.len &= ~SNDRV_SEQ_EXT_MASK; + quoted.event.data.ext.ptr = NULL; } bounce_ev.type = SNDRV_SEQ_EVENT_BOUNCE; bounce_ev.flags = SNDRV_SEQ_EVENT_LENGTH_VARIABLE; - bounce_ev.data.ext.len = sizeof(struct snd_seq_event); + bounce_ev.data.ext.len = sizeof(quoted); bounce_ev.data.ext.ptr = (char *)"ed; } else { /* -- 2.43.0