From: Takashi Iwai <tiwai@suse.de>
To: linux-sound@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: [PATCH v3 5/8] ALSA: usb-audio: Fix data race at mixer_ctl_feature_info()
Date: Wed, 7 Oct 2026 19:20:41 +0200 [thread overview]
Message-ID: <20261007172051.13240-6-tiwai@suse.de> (raw)
In-Reply-To: <20261007172051.13240-1-tiwai@suse.de>
The info callback for USB-audio mixer controls for feature unit has a
dynamic initialization of the contents with the check of
cval->initialized flag. But, since the info callback may be
concurrently called, this may lead to a data race, giving back an
inconsistent state. Similarly, get and put callbacks may have
concurrent accesses and can get bogus states.
For avoiding the data race, introduce a mutex locking for the
controls and protect against concurrent info callback calls.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
sound/usb/mixer.c | 14 +++++++++++++-
sound/usb/mixer.h | 1 +
2 files changed, 14 insertions(+), 1 deletion(-)
diff --git a/sound/usb/mixer.c b/sound/usb/mixer.c
index 9d8007ea95d5..695d51f7aeb4 100644
--- a/sound/usb/mixer.c
+++ b/sound/usb/mixer.c
@@ -1531,6 +1531,7 @@ static int mixer_ctl_feature_info(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
int ret;
+ guard(mutex)(&cval->head.mixer->lock);
if (cval->val_type == USB_MIXER_BOOLEAN ||
cval->val_type == USB_MIXER_INV_BOOLEAN)
uinfo->type = SNDRV_CTL_ELEM_TYPE_BOOLEAN;
@@ -1565,6 +1566,7 @@ static int mixer_ctl_feature_get(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
int c, cnt, val, err;
+ guard(mutex)(&cval->head.mixer->lock);
ucontrol->value.integer.value[0] = cval->min;
if (cval->cmask) {
cnt = 0;
@@ -1595,10 +1597,12 @@ static int mixer_ctl_feature_put(struct snd_kcontrol *kcontrol,
struct snd_ctl_elem_value *ucontrol)
{
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
- int max_val = get_max_exposed(cval);
+ int max_val;
int c, cnt, val, oval, err;
int changed = 0;
+ guard(mutex)(&cval->head.mixer->lock);
+ max_val = get_max_exposed(cval);
if (cval->cmask) {
cnt = 0;
for (c = 0; c < MAX_CHANNELS; c++) {
@@ -1646,6 +1650,7 @@ static int mixer_ctl_master_bool_get(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
int val, err;
+ guard(mutex)(&cval->head.mixer->lock);
err = snd_usb_get_cur_mix_value(cval, 0, 0, &val);
if (err < 0)
return filter_error(cval, err);
@@ -2592,6 +2597,7 @@ static int mixer_ctl_procunit_get(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
int err, val;
+ guard(mutex)(&cval->head.mixer->lock);
err = get_cur_ctl_value(cval, cval->control << 8, &val);
if (err < 0) {
ucontrol->value.integer.value[0] = cval->min;
@@ -2609,6 +2615,7 @@ static int mixer_ctl_procunit_put(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
int val, oval, err;
+ guard(mutex)(&cval->head.mixer->lock);
err = get_cur_ctl_value(cval, cval->control << 8, &oval);
if (err < 0)
return filter_error(cval, err);
@@ -2960,6 +2967,7 @@ static int mixer_ctl_selector_get(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
int val, err;
+ guard(mutex)(&cval->head.mixer->lock);
err = get_cur_ctl_value(cval, cval->control << 8, &val);
if (err < 0) {
ucontrol->value.enumerated.item[0] = 0;
@@ -2977,6 +2985,7 @@ static int mixer_ctl_selector_put(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *cval = snd_kcontrol_chip(kcontrol);
int val, oval, err;
+ guard(mutex)(&cval->head.mixer->lock);
err = get_cur_ctl_value(cval, cval->control << 8, &oval);
if (err < 0)
return filter_error(cval, err);
@@ -3249,6 +3258,7 @@ static void snd_usb_mixer_free(struct usb_mixer_interface *mixer)
}
usb_free_urb(mixer->rc_urb);
kfree(mixer->rc_setup_packet);
+ mutex_destroy(&mixer->lock);
kfree(mixer);
}
@@ -3893,6 +3903,8 @@ int snd_usb_create_mixer(struct snd_usb_audio *chip, int ctrlif)
return -ENOMEM;
}
+ mutex_init(&mixer->lock);
+
mixer->hostif = &usb_ifnum_to_if(chip->dev, ctrlif)->altsetting[0];
switch (get_iface_desc(mixer->hostif)->bInterfaceProtocol) {
case UAC_VERSION_1:
diff --git a/sound/usb/mixer.h b/sound/usb/mixer.h
index cf45c39cbccc..2ff4490f97c2 100644
--- a/sound/usb/mixer.h
+++ b/sound/usb/mixer.h
@@ -18,6 +18,7 @@ struct usb_mixer_interface {
struct usb_host_interface *hostif;
struct list_head list;
unsigned int ignore_ctl_error;
+ struct mutex lock; /* lock for feature unit callbacks */
/* UAC2 status interrupt endpoint; owned by mixer.c */
struct urb *urb;
/* array[MAX_ID_ELEMS], indexed by unit id */
--
2.55.0
next prev parent reply other threads:[~2026-10-07 17:20 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 17:20 [PATCH v3 0/8] ALSA: Fix some bugs reported by Sashiko Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 1/8] ALSA: seq: Drop the bogus RCU guard from clientptr() Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 2/8] ALSA: pcm: Fix TOCTOU state overwrite in snd_pcm_drop() Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 3/8] ALSA: hda: Fix potential UAF for gating jack Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 4/8] ALSA: usb-audio: Fix invalid UAC2/3 mixer unit matrix evaluation Takashi Iwai
2026-10-07 17:20 ` Takashi Iwai [this message]
2026-10-07 17:20 ` [PATCH v3 6/8] ALSA: pcmtest: Fix a bogus pointer read in snd_pcmtst_pcm_pointer() Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 7/8] ALSA: usb-audio: Fix mixer bitmap cache over 32 channels Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 8/8] ALSA: core: Add missing barriers for power_ref vs card->shutdown Takashi Iwai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007172051.13240-6-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®