From: Takashi Iwai <tiwai@suse.de>
To: linux-sound@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: [PATCH v3 6/8] ALSA: pcmtest: Fix a bogus pointer read in snd_pcmtst_pcm_pointer()
Date: Wed, 7 Oct 2026 19:20:42 +0200 [thread overview]
Message-ID: <20261007172051.13240-7-tiwai@suse.de> (raw)
In-Reply-To: <20261007172051.13240-1-tiwai@suse.de>
Sashiko reported a potential bogus value for a pcmtest driver when a
concurrent call to PCM pointer is invoked while the pcmtest's timer
callback is running: since the position is updated in the timer
callback without locking, the following wrapping in inc_buf_pos()
might be screwed up:
if (v_iter->buf_pos >= bytes)
v_iter->buf_pos %= bytes;
Although it was reported as an OOB, the actual return is corrected
inside buffer_size, so no corruption is expected in this scenario, but
an error message could show a bogus value.
Also, the whole state is read and modified locklessly in the timer
callback, which can be racy against the pause operation, too.
For avoiding those races, simply put the PCM stream lock in the timer
callback (while the snd_pcm_period_elapsed() must be changed to its
*_under_stream_lock() variant for avoiding the deadlock).
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 315a3d57c64c ("ALSA: Implement the new Virtual PCM Test Driver")
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
sound/drivers/pcmtest.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/sound/drivers/pcmtest.c b/sound/drivers/pcmtest.c
index 186e982d42e1..fea9580593e6 100644
--- a/sound/drivers/pcmtest.c
+++ b/sound/drivers/pcmtest.c
@@ -345,6 +345,7 @@ static void timer_timeout(struct timer_list *data)
v_iter = timer_container_of(v_iter, data, timer_instance);
substream = v_iter->substream;
+ guard(pcm_stream_lock_irqsave)(substream);
if (v_iter->suspend)
return;
@@ -358,7 +359,7 @@ static void timer_timeout(struct timer_list *data)
v_iter->period_pos += v_iter->b_rw;
if (v_iter->period_pos >= v_iter->period_bytes) {
v_iter->period_pos %= v_iter->period_bytes;
- snd_pcm_period_elapsed(substream);
+ snd_pcm_period_elapsed_under_stream_lock(substream);
}
if (!v_iter->suspend)
--
2.55.0
next prev parent reply other threads:[~2026-10-07 17:20 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 17:20 [PATCH v3 0/8] ALSA: Fix some bugs reported by Sashiko Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 1/8] ALSA: seq: Drop the bogus RCU guard from clientptr() Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 2/8] ALSA: pcm: Fix TOCTOU state overwrite in snd_pcm_drop() Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 3/8] ALSA: hda: Fix potential UAF for gating jack Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 4/8] ALSA: usb-audio: Fix invalid UAC2/3 mixer unit matrix evaluation Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 5/8] ALSA: usb-audio: Fix data race at mixer_ctl_feature_info() Takashi Iwai
2026-10-07 17:20 ` Takashi Iwai [this message]
2026-10-07 17:20 ` [PATCH v3 7/8] ALSA: usb-audio: Fix mixer bitmap cache over 32 channels Takashi Iwai
2026-10-07 17:20 ` [PATCH v3 8/8] ALSA: core: Add missing barriers for power_ref vs card->shutdown Takashi Iwai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007172051.13240-7-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®