mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports
@ 2026-10-08 19:25 Takashi Iwai
  2026-10-08 19:25 ` [PATCH 01/11] ALSA: hda: intel: Cancel delayed work at shutdown, too Takashi Iwai
                   ` (10 more replies)
  0 siblings, 11 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

Hi,

here are a few more fixes I've worked quickly for issues Sashiko and
other AI reported.


Takashi

===

Takashi Iwai (11):
  ALSA: hda: intel: Cancel delayed work at shutdown, too
  ALSA: hda: Disable unsol event handling at error and shutdown paths
  ALSA: hda: Add lock around codec->registered flag manipulations
  ALSA: hda: Add NULL check for the driver pointer at unsol event work
  ALSA: caiaq: Register card at the final step
  ALSA: caiaq: Fix races at MIDI URB and trigger accesses
  ALSA: usb: us16x08: Fix racy accesses of mixer elements
  ASoC: fsl_asrc_m2m: Fix bogus compress task pointer assignments
  ALSA: line6: Reject too small max packet sizes
  ALSA: line6: Fix potential OOB write in line6_capture_copy()
  ALSA: line6: Fix handling of zero-length capture packets

 sound/hda/common/bind.c       |  2 ++
 sound/hda/common/codec.c      |  5 +++++
 sound/hda/controllers/intel.c |  7 ++++++-
 sound/hda/core/bus.c          |  2 +-
 sound/soc/fsl/fsl_asrc_m2m.c  |  2 ++
 sound/usb/caiaq/device.c      | 13 +++++++------
 sound/usb/caiaq/device.h      |  3 ++-
 sound/usb/caiaq/midi.c        |  2 ++
 sound/usb/line6/capture.c     |  3 ++-
 sound/usb/line6/pcm.c         | 10 ++++++++--
 sound/usb/line6/playback.c    |  4 ++--
 sound/usb/mixer_us16x08.c     | 16 ++++++++++++++++
 12 files changed, 55 insertions(+), 14 deletions(-)

-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 01/11] ALSA: hda: intel: Cancel delayed work at shutdown, too
  2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
@ 2026-10-08 19:25 ` Takashi Iwai
  2026-10-08 19:25 ` [PATCH 02/11] ALSA: hda: Disable unsol event handling at error and shutdown paths Takashi Iwai
                   ` (9 subsequent siblings)
  10 siblings, 0 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

The shutdown procedure needs to cancel the delayed probe work in case
where the probe work stalls or is slow but still possible to
reactivated.

Fixes: c0f1886de7e1 ("ALSA: hda: intel: Allow repeatedly probing on codec configuration errors")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 sound/hda/controllers/intel.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/sound/hda/controllers/intel.c b/sound/hda/controllers/intel.c
index 88b0207fde9c..2b5b5d555f2c 100644
--- a/sound/hda/controllers/intel.c
+++ b/sound/hda/controllers/intel.c
@@ -2484,12 +2484,17 @@ static void azx_remove(struct pci_dev *pci)
 static void azx_shutdown(struct pci_dev *pci)
 {
 	struct snd_card *card = pci_get_drvdata(pci);
+	struct hda_intel *hda;
 	struct azx *chip;
 
 	if (!card)
 		return;
 	chip = card->private_data;
-	if (chip && chip->running)
+	if (!chip)
+		return;
+	hda = container_of(chip, struct hda_intel, chip);
+	cancel_delayed_work_sync(&hda->probe_work);
+	if (chip->running)
 		__azx_shutdown_chip(chip, true);
 }
 
-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 02/11] ALSA: hda: Disable unsol event handling at error and shutdown paths
  2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
  2026-10-08 19:25 ` [PATCH 01/11] ALSA: hda: intel: Cancel delayed work at shutdown, too Takashi Iwai
@ 2026-10-08 19:25 ` Takashi Iwai
  2026-10-08 19:25 ` [PATCH 03/11] ALSA: hda: Add lock around codec->registered flag manipulations Takashi Iwai
                   ` (8 subsequent siblings)
  10 siblings, 0 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

When the HD-audio controller driver probe fails, it still leaves the
unsolicited event handling and jackpoll work active, hence if they are
pending, they might fire up later after the resource gets released,
which may lead to a UAF.  A similar problem may be seen at shutdown,
too.

Add the recently added helper to disable unsol events and the cancel
of jackpoll_work at the appropriate places.

Fixes: c3ec8ac82105 ("ASoC: hdac_hda: fix memleak on module unload")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 sound/hda/common/bind.c  | 2 ++
 sound/hda/common/codec.c | 1 +
 2 files changed, 3 insertions(+)

diff --git a/sound/hda/common/bind.c b/sound/hda/common/bind.c
index 4772ca154a29..f2a498c78891 100644
--- a/sound/hda/common/bind.c
+++ b/sound/hda/common/bind.c
@@ -147,6 +147,8 @@ static int hda_codec_driver_probe(struct device *dev)
 	module_put(owner);
 
  error:
+	snd_hdac_device_disable_unsol(&codec->core);
+	cancel_delayed_work_sync(&codec->jackpoll_work);
 	snd_hda_codec_cleanup_for_unbind(codec);
 	codec->preset = NULL;
 	return err;
diff --git a/sound/hda/common/codec.c b/sound/hda/common/codec.c
index c99fe61c29db..94da4f3a21ed 100644
--- a/sound/hda/common/codec.c
+++ b/sound/hda/common/codec.c
@@ -3039,6 +3039,7 @@ void snd_hda_codec_shutdown(struct hda_codec *codec)
 
 	codec->jackpoll_interval = 0; /* don't poll any longer */
 	cancel_delayed_work_sync(&codec->jackpoll_work);
+	snd_hdac_device_disable_unsol(&codec->core);
 	list_for_each_entry(cpcm, &codec->pcm_list_head, list)
 		snd_pcm_suspend_all(cpcm->pcm);
 
-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 03/11] ALSA: hda: Add lock around codec->registered flag manipulations
  2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
  2026-10-08 19:25 ` [PATCH 01/11] ALSA: hda: intel: Cancel delayed work at shutdown, too Takashi Iwai
  2026-10-08 19:25 ` [PATCH 02/11] ALSA: hda: Disable unsol event handling at error and shutdown paths Takashi Iwai
@ 2026-10-08 19:25 ` Takashi Iwai
  2026-10-08 19:25 ` [PATCH 04/11] ALSA: hda: Add NULL check for the driver pointer at unsol event work Takashi Iwai
                   ` (7 subsequent siblings)
  10 siblings, 0 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

Currently the places setting or clearing codec->registered flag have
no locking, while its reference in the unsol handling work
snd_hdac_bus_process_unsol_events() takes the bus->reg_lock lock.
Let's add the same bus->reg_lock at the places where codec->registered
is set and cleared for avoiding the races.

Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 sound/hda/common/codec.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/sound/hda/common/codec.c b/sound/hda/common/codec.c
index 94da4f3a21ed..7fbced571282 100644
--- a/sound/hda/common/codec.c
+++ b/sound/hda/common/codec.c
@@ -761,7 +761,9 @@ void snd_hda_codec_cleanup_for_unbind(struct hda_codec *codec)
 		/* pm_runtime_put() is called in snd_hdac_device_exit() */
 		pm_runtime_get_noresume(hda_codec_dev(codec));
 		pm_runtime_disable(hda_codec_dev(codec));
+		spin_lock_irq(&bus->reg_lock);
 		codec->core.registered = false;
+		spin_unlock_irq(&bus->reg_lock);
 	}
 
 	snd_hda_codec_disconnect_pcms(codec);
@@ -815,7 +817,9 @@ void snd_hda_codec_register(struct hda_codec *codec)
 		pm_runtime_enable(hda_codec_dev(codec));
 		/* it was powered up in snd_hda_codec_new(), now all done */
 		snd_hda_power_down(codec);
+		spin_lock_irq(&bus->reg_lock);
 		codec->core.registered = true;
+		spin_unlock_irq(&bus->reg_lock);
 	}
 }
 EXPORT_SYMBOL_GPL(snd_hda_codec_register);
-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 04/11] ALSA: hda: Add NULL check for the driver pointer at unsol event work
  2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
                   ` (2 preceding siblings ...)
  2026-10-08 19:25 ` [PATCH 03/11] ALSA: hda: Add lock around codec->registered flag manipulations Takashi Iwai
@ 2026-10-08 19:25 ` Takashi Iwai
  2026-10-08 19:25 ` [PATCH 05/11] ALSA: caiaq: Register card at the final step Takashi Iwai
                   ` (6 subsequent siblings)
  10 siblings, 0 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

snd_hdac_bus_process_unsol_events() assumes that the codec driver is
always set when it's accessible from the codec table.  It's true in
general, but in a sheer timing, it might have been already NULLified
at the driver unbinding.

As a safety, let's add a NULL check before dereferencing and calling
the driver's unsol_event callback.

Fixes: c637fa151259 ("ALSA: hda: Fix potential race in unsol event handler")
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 sound/hda/core/bus.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/hda/core/bus.c b/sound/hda/core/bus.c
index 8d4ed9834aaa..96fd9bd221c9 100644
--- a/sound/hda/core/bus.c
+++ b/sound/hda/core/bus.c
@@ -184,7 +184,7 @@ static void snd_hdac_bus_process_unsol_events(struct work_struct *work)
 			continue;
 		spin_unlock_irq(&bus->reg_lock);
 		drv = drv_to_hdac_driver(codec->dev.driver);
-		if (drv->unsol_event)
+		if (drv && drv->unsol_event)
 			drv->unsol_event(codec, res);
 		spin_lock_irq(&bus->reg_lock);
 	}
-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 05/11] ALSA: caiaq: Register card at the final step
  2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
                   ` (3 preceding siblings ...)
  2026-10-08 19:25 ` [PATCH 04/11] ALSA: hda: Add NULL check for the driver pointer at unsol event work Takashi Iwai
@ 2026-10-08 19:25 ` Takashi Iwai
  2026-10-08 19:25 ` [PATCH 06/11] ALSA: caiaq: Fix races at MIDI URB and trigger accesses Takashi Iwai
                   ` (5 subsequent siblings)
  10 siblings, 0 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

caiaq driver calls snd_card_register() before creating the mixer
elements, which is rather confusing to user-space, as the devices have
been published before adding the control elements.

Swap the call order to make the card registration as the final step
(as written in the comment).

Fixes: 8e3cd08ed8e5 ("[ALSA] caiaq - add control API and more input features")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 sound/usb/caiaq/device.c | 12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/sound/usb/caiaq/device.c b/sound/usb/caiaq/device.c
index a596f5f763b8..c68ed16d7ac4 100644
--- a/sound/usb/caiaq/device.c
+++ b/sound/usb/caiaq/device.c
@@ -395,6 +395,12 @@ static int setup_card(struct snd_usb_caiaqdev *cdev)
 		return ret;
 	}
 
+	ret = snd_usb_caiaq_control_init(cdev);
+	if (ret < 0) {
+		dev_err(dev, "Unable to set up control system (ret=%d)\n", ret);
+		return ret;
+	}
+
 	/* finally, register the card and all its sub-instances */
 	ret = snd_card_register(cdev->chip.card);
 	if (ret < 0) {
@@ -402,12 +408,6 @@ static int setup_card(struct snd_usb_caiaqdev *cdev)
 		return ret;
 	}
 
-	ret = snd_usb_caiaq_control_init(cdev);
-	if (ret < 0) {
-		dev_err(dev, "Unable to set up control system (ret=%d)\n", ret);
-		return ret;
-	}
-
 	return 0;
 }
 
-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 06/11] ALSA: caiaq: Fix races at MIDI URB and trigger accesses
  2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
                   ` (4 preceding siblings ...)
  2026-10-08 19:25 ` [PATCH 05/11] ALSA: caiaq: Register card at the final step Takashi Iwai
@ 2026-10-08 19:25 ` Takashi Iwai
  2026-10-08 19:25 ` [PATCH 07/11] ALSA: usb: us16x08: Fix racy accesses of mixer elements Takashi Iwai
                   ` (4 subsequent siblings)
  10 siblings, 0 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

URB completion and rawmidi trigger callbacks can race with each other,
which may put the state inconsistent, causing double submissions, etc.

Guard both with a new spinlock for avoiding the races.

Fixes: f3f80a9205da ("ALSA: caiaq - Fix Oops with MIDI")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 sound/usb/caiaq/device.c | 1 +
 sound/usb/caiaq/device.h | 3 ++-
 sound/usb/caiaq/midi.c   | 2 ++
 3 files changed, 5 insertions(+), 1 deletion(-)

diff --git a/sound/usb/caiaq/device.c b/sound/usb/caiaq/device.c
index c68ed16d7ac4..634dc36f2ead 100644
--- a/sound/usb/caiaq/device.c
+++ b/sound/usb/caiaq/device.c
@@ -455,6 +455,7 @@ static int create_card(struct usb_device *usb_dev,
 	cdev->chip.usb_id = USB_ID(le16_to_cpu(usb_dev->descriptor.idVendor),
 				  le16_to_cpu(usb_dev->descriptor.idProduct));
 	spin_lock_init(&cdev->spinlock);
+	spin_lock_init(&cdev->midi_lock);
 	mutex_init(&cdev->ep1_out_mutex);
 
 	*cardp = card;
diff --git a/sound/usb/caiaq/device.h b/sound/usb/caiaq/device.h
index dd726ca68e80..16f65e7867d1 100644
--- a/sound/usb/caiaq/device.h
+++ b/sound/usb/caiaq/device.h
@@ -77,7 +77,8 @@ struct snd_usb_caiaqdev {
 	unsigned char midi_out_buf[EP1_BUFSIZE];
 
 	struct caiaq_device_spec spec;
-	spinlock_t spinlock;
+	spinlock_t spinlock;	/* for PCM audio */
+	spinlock_t midi_lock;	/* midi_x_stream, midi_out_active */
 	wait_queue_head_t ep1_wait_queue;
 	wait_queue_head_t prepare_wait_queue;
 	int spec_received, audio_parm_answer;
diff --git a/sound/usb/caiaq/midi.c b/sound/usb/caiaq/midi.c
index 18529484c8dc..b7d7d24937a7 100644
--- a/sound/usb/caiaq/midi.c
+++ b/sound/usb/caiaq/midi.c
@@ -79,6 +79,7 @@ static void snd_usb_caiaq_midi_output_trigger(struct snd_rawmidi_substream *subs
 {
 	struct snd_usb_caiaqdev *cdev = substream->rmidi->private_data;
 
+	guard(spinlock_irqsave)(&cdev->midi_lock);
 	if (up) {
 		cdev->midi_out_substream = substream;
 		if (!cdev->midi_out_active)
@@ -151,6 +152,7 @@ void snd_usb_caiaq_midi_output_done(struct urb* urb)
 {
 	struct snd_usb_caiaqdev *cdev = urb->context;
 
+	guard(spinlock_irqsave)(&cdev->midi_lock);
 	cdev->midi_out_active = 0;
 	if (urb->status != 0)
 		return;
-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 07/11] ALSA: usb: us16x08: Fix racy accesses of mixer elements
  2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
                   ` (5 preceding siblings ...)
  2026-10-08 19:25 ` [PATCH 06/11] ALSA: caiaq: Fix races at MIDI URB and trigger accesses Takashi Iwai
@ 2026-10-08 19:25 ` Takashi Iwai
  2026-10-08 19:25 ` [PATCH 08/11] ASoC: fsl_asrc_m2m: Fix bogus compress task pointer assignments Takashi Iwai
                   ` (3 subsequent siblings)
  10 siblings, 0 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

All get and put callbacks for us16x08 mixer have no proper protection,
hence the concurrent accesses to multiple elements may face data
races, resulting in unexpected values.

Put the new mixer->lock mutex for protecting the concurrent accesses.

Fixes: d2bb390a2081 ("ALSA: usb-audio: Tascam US-16x08 DSP mixer quirk")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 sound/usb/mixer_us16x08.c | 16 ++++++++++++++++
 1 file changed, 16 insertions(+)

diff --git a/sound/usb/mixer_us16x08.c b/sound/usb/mixer_us16x08.c
index 8e5ccd3282a7..b447c4f7a161 100644
--- a/sound/usb/mixer_us16x08.c
+++ b/sound/usb/mixer_us16x08.c
@@ -189,6 +189,7 @@ static int snd_us16x08_route_get(struct snd_kcontrol *kcontrol,
 	struct usb_mixer_elem_info *elem = snd_kcontrol_chip(kcontrol);
 	int index = ucontrol->id.index;
 
+	guard(mutex)(&elem->head.mixer->lock);
 	/* route has no bias */
 	ucontrol->value.enumerated.item[0] = elem->cache_val[index];
 
@@ -204,6 +205,7 @@ static int snd_us16x08_route_put(struct snd_kcontrol *kcontrol,
 	char buf[sizeof(route_msg)];
 	int val, val_org, err;
 
+	guard(mutex)(&elem->head.mixer->lock);
 	/*  get the new value (no bias for routes) */
 	val = ucontrol->value.enumerated.item[0];
 
@@ -258,6 +260,7 @@ static int snd_us16x08_master_get(struct snd_kcontrol *kcontrol,
 	struct usb_mixer_elem_info *elem = snd_kcontrol_chip(kcontrol);
 	int index = ucontrol->id.index;
 
+	guard(mutex)(&elem->head.mixer->lock);
 	ucontrol->value.integer.value[0] = elem->cache_val[index];
 
 	return 0;
@@ -272,6 +275,7 @@ static int snd_us16x08_master_put(struct snd_kcontrol *kcontrol,
 	int val, err;
 	int index = ucontrol->id.index;
 
+	guard(mutex)(&elem->head.mixer->lock);
 	/* new control value incl. bias*/
 	val = ucontrol->value.integer.value[0];
 
@@ -310,6 +314,7 @@ static int snd_us16x08_bus_put(struct snd_kcontrol *kcontrol,
 
 	val = ucontrol->value.integer.value[0];
 
+	guard(mutex)(&elem->head.mixer->lock);
 	/* prepare the message buffer from template */
 	switch (elem->head.id) {
 	case SND_US16X08_ID_BYPASS:
@@ -346,6 +351,7 @@ static int snd_us16x08_bus_get(struct snd_kcontrol *kcontrol,
 {
 	struct usb_mixer_elem_info *elem = snd_kcontrol_chip(kcontrol);
 
+	guard(mutex)(&elem->head.mixer->lock);
 	switch (elem->head.id) {
 	case SND_US16X08_ID_BUSS_OUT:
 		ucontrol->value.integer.value[0] = elem->cache_val[0];
@@ -368,6 +374,7 @@ static int snd_us16x08_channel_get(struct snd_kcontrol *kcontrol,
 	struct usb_mixer_elem_info *elem = snd_kcontrol_chip(kcontrol);
 	int index = ucontrol->id.index;
 
+	guard(mutex)(&elem->head.mixer->lock);
 	ucontrol->value.integer.value[0] = elem->cache_val[index];
 
 	return 0;
@@ -382,6 +389,7 @@ static int snd_us16x08_channel_put(struct snd_kcontrol *kcontrol,
 	int val, err;
 	int index = ucontrol->id.index;
 
+	guard(mutex)(&elem->head.mixer->lock);
 	val = ucontrol->value.integer.value[0];
 
 	/* sanity check */
@@ -428,6 +436,7 @@ static int snd_us16x08_comp_get(struct snd_kcontrol *kcontrol,
 	int index = ucontrol->id.index;
 	int val_idx = COMP_STORE_IDX(elem->head.id);
 
+	guard(mutex)(&elem->head.mixer->lock);
 	ucontrol->value.integer.value[0] = store->val[val_idx][index];
 
 	return 0;
@@ -445,6 +454,7 @@ static int snd_us16x08_comp_put(struct snd_kcontrol *kcontrol,
 	int threshold, ratio, attack, release, gain, switch_on;
 	int err;
 
+	guard(mutex)(&elem->head.mixer->lock);
 	val = ucontrol->value.integer.value[0];
 
 	/* sanity check */
@@ -521,6 +531,7 @@ static int snd_us16x08_eqswitch_get(struct snd_kcontrol *kcontrol,
 	struct snd_us16x08_eq_store *store = elem->private_data;
 	int index = ucontrol->id.index;
 
+	guard(mutex)(&elem->head.mixer->lock);
 	/* get low switch from cache is enough, cause all bands are together */
 	val = store->val[EQ_STORE_BAND_IDX(elem->head.id)]
 		[EQ_STORE_PARAM_IDX(elem->head.id)][index];
@@ -540,6 +551,7 @@ static int snd_us16x08_eqswitch_put(struct snd_kcontrol *kcontrol,
 	int val, err = 0;
 	int b_idx;
 
+	guard(mutex)(&elem->head.mixer->lock);
 	/* new control value incl. bias*/
 	val = ucontrol->value.integer.value[0] + SND_US16X08_KCBIAS(kcontrol);
 
@@ -582,6 +594,7 @@ static int snd_us16x08_eq_get(struct snd_kcontrol *kcontrol,
 	int b_idx = EQ_STORE_BAND_IDX(elem->head.id) - 1;
 	int p_idx = EQ_STORE_PARAM_IDX(elem->head.id);
 
+	guard(mutex)(&elem->head.mixer->lock);
 	val = store->val[b_idx][p_idx][index];
 
 	ucontrol->value.integer.value[0] = val;
@@ -601,6 +614,7 @@ static int snd_us16x08_eq_put(struct snd_kcontrol *kcontrol,
 	int b_idx = EQ_STORE_BAND_IDX(elem->head.id) - 1;
 	int p_idx = EQ_STORE_PARAM_IDX(elem->head.id);
 
+	guard(mutex)(&elem->head.mixer->lock);
 	val = ucontrol->value.integer.value[0];
 
 	/* sanity check */
@@ -729,6 +743,7 @@ static int snd_us16x08_meter_get(struct snd_kcontrol *kcontrol,
 	struct snd_us16x08_meter_store *store = elem->private_data;
 	u8 meter_urb[64] = {0};
 
+	guard(mutex)(&elem->head.mixer->lock);
 	switch (kcontrol->private_value) {
 	case 0: {
 		char tmp[sizeof(mix_init_msg1)];
@@ -788,6 +803,7 @@ static int snd_us16x08_meter_put(struct snd_kcontrol *kcontrol,
 	struct snd_us16x08_meter_store *store = elem->private_data;
 	int val;
 
+	guard(mutex)(&elem->head.mixer->lock);
 	val = ucontrol->value.integer.value[0];
 
 	/* sanity check */
-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 08/11] ASoC: fsl_asrc_m2m: Fix bogus compress task pointer assignments
  2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
                   ` (6 preceding siblings ...)
  2026-10-08 19:25 ` [PATCH 07/11] ALSA: usb: us16x08: Fix racy accesses of mixer elements Takashi Iwai
@ 2026-10-08 19:25 ` Takashi Iwai
  2026-10-08 19:25 ` [PATCH 09/11] ALSA: line6: Reject too small max packet sizes Takashi Iwai
                   ` (2 subsequent siblings)
  10 siblings, 0 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

When a creation of input or output compress-offload task fails in
fsl-asrc driver, the task->input or task->output pointer is left with
ERR_PTR(), which is non-NULL.  Then it's handled in the compress
offload core and it tries to release via dma_buf_put(), resulting in
an access to a wrong address.

Clear the bogus pointers properly before returning an error.

Fixes: 24a01710f627 ("ASoC: fsl_asrc_m2m: Add memory to memory function")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 sound/soc/fsl/fsl_asrc_m2m.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/sound/soc/fsl/fsl_asrc_m2m.c b/sound/soc/fsl/fsl_asrc_m2m.c
index 4bc40f328f58..42b0e21f281c 100644
--- a/sound/soc/fsl/fsl_asrc_m2m.c
+++ b/sound/soc/fsl/fsl_asrc_m2m.c
@@ -475,6 +475,7 @@ static int fsl_asrc_m2m_comp_task_create(struct snd_compr_stream *stream,
 	task->input = dma_buf_export(&exp_info_in);
 	if (IS_ERR(task->input)) {
 		ret = PTR_ERR(task->input);
+		task->input = NULL;
 		return ret;
 	}
 
@@ -485,6 +486,7 @@ static int fsl_asrc_m2m_comp_task_create(struct snd_compr_stream *stream,
 	task->output = dma_buf_export(&exp_info_out);
 	if (IS_ERR(task->output)) {
 		ret = PTR_ERR(task->output);
+		task->output = NULL;
 		return ret;
 	}
 
-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 09/11] ALSA: line6: Reject too small max packet sizes
  2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
                   ` (7 preceding siblings ...)
  2026-10-08 19:25 ` [PATCH 08/11] ASoC: fsl_asrc_m2m: Fix bogus compress task pointer assignments Takashi Iwai
@ 2026-10-08 19:25 ` Takashi Iwai
  2026-10-08 19:25 ` [PATCH 10/11] ALSA: line6: Fix potential OOB write in line6_capture_copy() Takashi Iwai
  2026-10-08 19:25 ` [PATCH 11/11] ALSA: line6: Fix handling of zero-length capture packets Takashi Iwai
  10 siblings, 0 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

Although the LINE6 driver has a sanity check for the given max packet
sizes, it still has an implicit requirement of the minimal size being
bytes-per-frame; e.g. the impulse test signal assuming the fixed size,
and when a too small size is specified by a malformed USB descriptor,
this may lead to an OOB access.

Change the sanity check conditions to reject too small max packet
sizes for avoiding the scenario above.

Fixes: 3450121997ce ("ALSA: line6: Fix write on zero-sized buffer")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 sound/usb/line6/pcm.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/sound/usb/line6/pcm.c b/sound/usb/line6/pcm.c
index 2932eaf157f4..998869dc4613 100644
--- a/sound/usb/line6/pcm.c
+++ b/sound/usb/line6/pcm.c
@@ -554,7 +554,11 @@ int line6_init_pcm(struct usb_line6 *line6,
 	line6pcm->max_packet_size_out =
 		usb_maxpacket(line6->usbdev,
 			usb_sndisocpipe(line6->usbdev, ep_write));
-	if (!line6pcm->max_packet_size_in || !line6pcm->max_packet_size_out) {
+	/* reject max packet sizes smaller than bytes-per-frame;
+	 * (the magic number 6 is taken from the playback case)
+	 */
+	if (line6pcm->max_packet_size_in < 6 ||
+	    line6pcm->max_packet_size_out < 6) {
 		dev_err(line6pcm->line6->ifcdev,
 			"cannot get proper max packet size\n");
 		return -EINVAL;
-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 10/11] ALSA: line6: Fix potential OOB write in line6_capture_copy()
  2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
                   ` (8 preceding siblings ...)
  2026-10-08 19:25 ` [PATCH 09/11] ALSA: line6: Reject too small max packet sizes Takashi Iwai
@ 2026-10-08 19:25 ` Takashi Iwai
  2026-10-08 19:25 ` [PATCH 11/11] ALSA: line6: Fix handling of zero-length capture packets Takashi Iwai
  10 siblings, 0 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

line6_capture_copy() copies the data for the original byte size, but
the buffer overwrap is checked against the frame size.  Because of it,
when the data size isn't aligned in frames, the remaining bytes might
be still copied above the buffer size.

For avoiding the potential OOB write, correct the copied data size in
line6_capture_copy() to be aligned with frames.

Fixes: 1027f476f507 ("staging: line6: sync with upstream")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 sound/usb/line6/capture.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/sound/usb/line6/capture.c b/sound/usb/line6/capture.c
index 6dbaf30232f9..3e1f40d6b481 100644
--- a/sound/usb/line6/capture.c
+++ b/sound/usb/line6/capture.c
@@ -117,7 +117,8 @@ void line6_capture_copy(struct snd_line6_pcm *line6pcm, char *fbuf, int fsize)
 	} else {
 		/* copy single chunk */
 		memcpy(runtime->dma_area +
-		       line6pcm->in.pos_done * bytes_per_frame, fbuf, fsize);
+		       line6pcm->in.pos_done * bytes_per_frame, fbuf,
+		       frames * bytes_per_frame);
 	}
 
 	line6pcm->in.pos_done += frames;
-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

* [PATCH 11/11] ALSA: line6: Fix handling of zero-length capture packets
  2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
                   ` (9 preceding siblings ...)
  2026-10-08 19:25 ` [PATCH 10/11] ALSA: line6: Fix potential OOB write in line6_capture_copy() Takashi Iwai
@ 2026-10-08 19:25 ` Takashi Iwai
  10 siblings, 0 replies; 12+ messages in thread
From: Takashi Iwai @ 2026-10-08 19:25 UTC (permalink / raw)
  To: linux-sound; +Cc: linux-kernel

The LINE6 playback engine assumes that line6pcm->prev_fsize=0
indicates that there was no input packet to be processed, and
synthesizes the frames.  But, when a capture stream receives a
zero-length (or a very small size) packet, it sets 0 to prev_fsize,
while playback engine still believes it's for synthesis, hence it
tries to copy the larger data than the actual input data.

As prev_fsize=0 can't be a good indication for "no input", change the
meaning slightly: now prev_fsize=-1 means no input, while prev_fsize=0
means it's a zero-length packet.

Fixes: 1027f476f507 ("staging: line6: sync with upstream")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 sound/usb/line6/pcm.c      | 4 +++-
 sound/usb/line6/playback.c | 4 ++--
 2 files changed, 5 insertions(+), 3 deletions(-)

diff --git a/sound/usb/line6/pcm.c b/sound/usb/line6/pcm.c
index 998869dc4613..e2b99e7a08e0 100644
--- a/sound/usb/line6/pcm.c
+++ b/sound/usb/line6/pcm.c
@@ -217,7 +217,7 @@ static void line6_stream_stop(struct snd_line6_pcm *line6pcm, int direction,
 	if (direction == SNDRV_PCM_STREAM_CAPTURE) {
 		guard(spinlock_irqsave)(&pstr->lock);
 		line6pcm->prev_fbuf = NULL;
-		line6pcm->prev_fsize = 0;
+		line6pcm->prev_fsize = -1;
 	}
 }
 
@@ -538,6 +538,8 @@ int line6_init_pcm(struct usb_line6 *line6,
 	line6pcm->volume_playback[0] = line6pcm->volume_playback[1] = 255;
 	line6pcm->volume_monitor = 255;
 	line6pcm->line6 = line6;
+	line6pcm->prev_fbuf = NULL;
+	line6pcm->prev_fsize = -1;
 
 	spin_lock_init(&line6pcm->out.lock);
 	spin_lock_init(&line6pcm->in.lock);
diff --git a/sound/usb/line6/playback.c b/sound/usb/line6/playback.c
index aa6ddf8746a0..6682ebaac646 100644
--- a/sound/usb/line6/playback.c
+++ b/sound/usb/line6/playback.c
@@ -171,7 +171,7 @@ static int submit_audio_out_urb(struct snd_line6_pcm *line6pcm)
 		    &urb_out->iso_frame_desc[i];
 
 		fsize = line6pcm->prev_fsize;
-		if (fsize == 0) {
+		if (fsize == -1) {
 			int n;
 
 			line6pcm->out.count += frame_increment;
@@ -271,7 +271,7 @@ static int submit_audio_out_urb(struct snd_line6_pcm *line6pcm)
 						   bytes_per_frame);
 		}
 		line6pcm->prev_fbuf = NULL;
-		line6pcm->prev_fsize = 0;
+		line6pcm->prev_fsize = -1;
 	}
 	spin_unlock(&line6pcm->in.lock);
 
-- 
2.55.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2026-10-08 19:26 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
2026-10-08 19:25 ` [PATCH 01/11] ALSA: hda: intel: Cancel delayed work at shutdown, too Takashi Iwai
2026-10-08 19:25 ` [PATCH 02/11] ALSA: hda: Disable unsol event handling at error and shutdown paths Takashi Iwai
2026-10-08 19:25 ` [PATCH 03/11] ALSA: hda: Add lock around codec->registered flag manipulations Takashi Iwai
2026-10-08 19:25 ` [PATCH 04/11] ALSA: hda: Add NULL check for the driver pointer at unsol event work Takashi Iwai
2026-10-08 19:25 ` [PATCH 05/11] ALSA: caiaq: Register card at the final step Takashi Iwai
2026-10-08 19:25 ` [PATCH 06/11] ALSA: caiaq: Fix races at MIDI URB and trigger accesses Takashi Iwai
2026-10-08 19:25 ` [PATCH 07/11] ALSA: usb: us16x08: Fix racy accesses of mixer elements Takashi Iwai
2026-10-08 19:25 ` [PATCH 08/11] ASoC: fsl_asrc_m2m: Fix bogus compress task pointer assignments Takashi Iwai
2026-10-08 19:25 ` [PATCH 09/11] ALSA: line6: Reject too small max packet sizes Takashi Iwai
2026-10-08 19:25 ` [PATCH 10/11] ALSA: line6: Fix potential OOB write in line6_capture_copy() Takashi Iwai
2026-10-08 19:25 ` [PATCH 11/11] ALSA: line6: Fix handling of zero-length capture packets Takashi Iwai

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®