From: Takashi Iwai <tiwai@suse.de>
To: linux-sound@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: [PATCH 5/8] ALSA: usb-audio: Fix data race at mixer_ctl_feature_info()
Date: Tue, 6 Oct 2026 15:40:29 +0200 [thread overview]
Message-ID: <20261006134035.478529-6-tiwai@suse.de> (raw)
In-Reply-To: <20261006134035.478529-1-tiwai@suse.de>
The info callback for USB-audio mixer controls for feature unit has a
dynamic initialization of the contents with the check of
cval->initialized flag. But, since the info callback may be
concurrently called, this may lead to a data race, giving back an
inconsistent state. Similarly, get and put callbacks may have
concurrent accesses and can get bogus states.
For avoiding the data race, introduce a mutex locking for the
controls and protect against concurrent info callback calls.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
sound/usb/mixer.c | 11 ++++++++++-
sound/usb/mixer.h | 1 +
2 files changed, 11 insertions(+), 1 deletion(-)
diff --git a/sound/usb/mixer.c b/sound/usb/mixer.c
index 9d8007ea95d5..bc71d7210eb2 100644
--- a/sound/usb/mixer.c
+++ b/sound/usb/mixer.c
@@ -1539,6 +1539,7 @@ static int mixer_ctl_feature_info(struct snd_kcontrol *kcontrol,
uinfo->count = cval->channels;
if (cval->val_type != USB_MIXER_BOOLEAN &&
cval->val_type != USB_MIXER_INV_BOOLEAN) {
+ guard(mutex)(&cval->head.mixer->lock);
if (!cval->initialized) {
ret = get_min_max_with_quirks(cval, 0, kcontrol);
if ((ret >= 0 || ret == -EAGAIN) &&
@@ -1565,6 +1566,7 @@ static int mixer_ctl_feature_get(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
int c, cnt, val, err;
+ guard(mutex)(&cval->head.mixer->lock);
ucontrol->value.integer.value[0] = cval->min;
if (cval->cmask) {
cnt = 0;
@@ -1595,10 +1597,12 @@ static int mixer_ctl_feature_put(struct snd_kcontrol *kcontrol,
struct snd_ctl_elem_value *ucontrol)
{
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
- int max_val = get_max_exposed(cval);
+ int max_val;
int c, cnt, val, oval, err;
int changed = 0;
+ guard(mutex)(&cval->head.mixer->lock);
+ max_val = get_max_exposed(cval);
if (cval->cmask) {
cnt = 0;
for (c = 0; c < MAX_CHANNELS; c++) {
@@ -1646,6 +1650,7 @@ static int mixer_ctl_master_bool_get(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
int val, err;
+ guard(mutex)(&cval->head.mixer->lock);
err = snd_usb_get_cur_mix_value(cval, 0, 0, &val);
if (err < 0)
return filter_error(cval, err);
@@ -2592,6 +2597,7 @@ static int mixer_ctl_procunit_get(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
int err, val;
+ guard(mutex)(&cval->head.mixer->lock);
err = get_cur_ctl_value(cval, cval->control << 8, &val);
if (err < 0) {
ucontrol->value.integer.value[0] = cval->min;
@@ -2609,6 +2615,7 @@ static int mixer_ctl_procunit_put(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
int val, oval, err;
+ guard(mutex)(&cval->head.mixer->lock);
err = get_cur_ctl_value(cval, cval->control << 8, &oval);
if (err < 0)
return filter_error(cval, err);
@@ -3249,6 +3256,7 @@ static void snd_usb_mixer_free(struct usb_mixer_interface *mixer)
}
usb_free_urb(mixer->rc_urb);
kfree(mixer->rc_setup_packet);
+ mutex_destroy(&mixer->lock);
kfree(mixer);
}
@@ -3885,6 +3893,7 @@ int snd_usb_create_mixer(struct snd_usb_audio *chip, int ctrlif)
mixer = kzalloc_obj(*mixer);
if (!mixer)
return -ENOMEM;
+ mutex_init(&mixer->lock);
mixer->chip = chip;
mixer->ignore_ctl_error = !!(chip->quirk_flags & QUIRK_FLAG_IGNORE_CTL_ERROR);
mixer->id_elems = kzalloc_objs(*mixer->id_elems, MAX_ID_ELEMS);
diff --git a/sound/usb/mixer.h b/sound/usb/mixer.h
index cf45c39cbccc..2ff4490f97c2 100644
--- a/sound/usb/mixer.h
+++ b/sound/usb/mixer.h
@@ -18,6 +18,7 @@ struct usb_mixer_interface {
struct usb_host_interface *hostif;
struct list_head list;
unsigned int ignore_ctl_error;
+ struct mutex lock; /* lock for feature unit callbacks */
/* UAC2 status interrupt endpoint; owned by mixer.c */
struct urb *urb;
/* array[MAX_ID_ELEMS], indexed by unit id */
--
2.55.0
next prev parent reply other threads:[~2026-10-06 13:40 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 13:40 [PATCH 0/8] ALSA: Fix some bugs reported by Sashiko Takashi Iwai
2026-10-06 13:40 ` [PATCH 1/8] ALSA: seq: Drop the bogus RCU guard from clientptr() Takashi Iwai
2026-10-06 13:40 ` [PATCH 2/8] ALSA: pcm: Fix TOCTOU state overwrite in snd_pcm_drop() Takashi Iwai
2026-10-06 13:40 ` [PATCH 3/8] ALSA: hda: Fix potential UAF for gating jack Takashi Iwai
2026-10-06 13:40 ` [PATCH 4/8] ALSA: usb-audio: Fix invalid UAC2/3 mixer unit matrix evaluation Takashi Iwai
2026-10-06 13:40 ` Takashi Iwai [this message]
2026-10-06 13:40 ` [PATCH 6/8] ALSA: pcmtest: Fix a bogus pointer read in snd_pcmtst_pcm_pointer() Takashi Iwai
2026-10-06 13:40 ` [PATCH 7/8] ALSA: usb-audio: Fix mixer bitmap cache over 32 channels Takashi Iwai
2026-10-06 13:40 ` [PATCH 8/8] ALSA: core: Add missing barriers for power_ref vs card->shutdown Takashi Iwai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261006134035.478529-6-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®