From: Takashi Iwai <tiwai@suse.de>
To: linux-sound@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: [PATCH v3 1/7] ALSA: seq: Fix missing direction and ump_group handling in 32bit compat ioctl
Date: Wed, 7 Oct 2026 19:25:19 +0200 [thread overview]
Message-ID: <20261007172533.14667-2-tiwai@suse.de> (raw)
In-Reply-To: <20261007172533.14667-1-tiwai@suse.de>
I forgot to cover the two new fields, direction and ump_group, in
struct snd_seq_port_info for the 32bit compat ioctls of
SNDRV_SEQ_IOCTL_GET_PORT_INFO & co, which ended up with the garbage
copies in those fields. Add the handling of those two fields in the
compat layer.
Also, avoid over-copying the 64bit snd_seq_port_info but only the first
part (before the field kernel); this avoids the copy of kernel-space
garbage value in the reserved field.
Fixes: ff166a9d19fa ("ALSA: seq: Add port direction to snd_seq_port_info")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
sound/core/seq/seq_compat.c | 15 +++++++++++----
1 file changed, 11 insertions(+), 4 deletions(-)
diff --git a/sound/core/seq/seq_compat.c b/sound/core/seq/seq_compat.c
index 80110501da6f..57aaa39afb9d 100644
--- a/sound/core/seq/seq_compat.c
+++ b/sound/core/seq/seq_compat.c
@@ -25,7 +25,9 @@ struct snd_seq_port_info32 {
u32 kernel; /* reserved for kernel use (must be NULL) */
u32 flags; /* misc. conditioning */
unsigned char time_queue; /* queue # for timestamping */
- char reserved[59]; /* for future use */
+ unsigned char direction; /* port usage direction (r/w/bidir) */
+ unsigned char ump_group; /* 0 = UMP EP (no conversion), 1-16 = UMP group number */
+ char reserved[57]; /* for future use */
};
static int snd_seq_call_port_info_ioctl(struct snd_seq_client *client, unsigned int cmd,
@@ -40,7 +42,9 @@ static int snd_seq_call_port_info_ioctl(struct snd_seq_client *client, unsigned
if (copy_from_user(data, data32, sizeof(*data32)) ||
get_user(data->flags, &data32->flags) ||
- get_user(data->time_queue, &data32->time_queue))
+ get_user(data->time_queue, &data32->time_queue) ||
+ get_user(data->direction, &data32->direction) ||
+ get_user(data->ump_group, &data32->ump_group))
return -EFAULT;
data->kernel = NULL;
@@ -50,9 +54,12 @@ static int snd_seq_call_port_info_ioctl(struct snd_seq_client *client, unsigned
if (err < 0)
return err;
- if (copy_to_user(data32, data, sizeof(*data32)) ||
+ if (copy_to_user(data32, data,
+ offsetof(struct snd_seq_port_info32, kernel)) ||
put_user(data->flags, &data32->flags) ||
- put_user(data->time_queue, &data32->time_queue))
+ put_user(data->time_queue, &data32->time_queue) ||
+ put_user(data->direction, &data32->direction) ||
+ put_user(data->ump_group, &data32->ump_group))
return -EFAULT;
return err;
--
2.55.0
next prev parent reply other threads:[~2026-10-07 17:25 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 17:25 [PATCH v3 0/7] ALSA: Fix yet more bugs reported by Sashiko Takashi Iwai
2026-10-07 17:25 ` Takashi Iwai [this message]
2026-10-07 17:25 ` [PATCH v3 2/7] ALSA: pcmtest: Fix leak at probe error Takashi Iwai
2026-10-07 17:25 ` [PATCH v3 3/7] ALSA: pcmtest: Use platform_device_register_simple() Takashi Iwai
2026-10-07 17:25 ` [PATCH v3 4/7] ALSA: info: Fix memory leak at card removal Takashi Iwai
2026-10-07 17:25 ` [PATCH v3 5/7] ALSA: aloop: Avoid a bad mixure of guard() and goto Takashi Iwai
2026-10-07 17:25 ` [PATCH v3 6/7] ALSA: core: Fix leaks at snd_card_init() error paths Takashi Iwai
2026-10-07 17:25 ` [PATCH v3 7/7] ALSA: seq: Don't lose partial read failure Takashi Iwai
2026-10-08 8:32 ` Cezary Rojewski
2026-10-08 8:53 ` Takashi Iwai
2026-10-08 11:43 ` Cezary Rojewski
2026-10-08 11:59 ` Takashi Iwai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007172533.14667-2-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®