* [PATCH] ALSA: usb-audio: Protect Roland control activation
@ 2026-09-29 7:40 Runyu Xiao
2026-09-29 13:34 ` Takashi Iwai
0 siblings, 1 reply; 4+ messages in thread
From: Runyu Xiao @ 2026-09-29 7:40 UTC (permalink / raw)
To: Clemens Ladisch
Cc: Jaroslav Kysela, Takashi Iwai, Runyu Xiao, Jianhao Xu,
linux-sound, linux-kernel
The USB MIDI driver changes the Roland MIDI Input Mode control's access
flags directly from the rawmidi open and close paths. These changes are
not protected by the ALSA control core and the corresponding notifications
can race with control access.
Use snd_ctl_activate_id() so that the control core updates the access flags
and sends the notification under its lock. Release the USB MIDI mutex
before calling it because the control write path holds controls_rwsem while
roland_load_put() takes the USB MIDI mutex.
Keep the state transition and alternate-setting change under the USB MIDI
mutex; rawmidi's open mutex serializes the enclosing open and close paths.
Fixes: 96f61d9ade82 ("sound: usb-audio: allow switching altsetting on Roland USB MIDI devices")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
---
sound/usb/midi.c | 53 ++++++++++++++++++++++++------------------------
1 file changed, 27 insertions(+), 26 deletions(-)
diff --git a/sound/usb/midi.c b/sound/usb/midi.c
index f8996416c..94664bf07 100644
--- a/sound/usb/midi.c
+++ b/sound/usb/midi.c
@@ -1145,41 +1145,42 @@ static int substream_open(struct snd_rawmidi_substream *substream, int dir,
int open)
{
struct snd_usb_midi *umidi = substream->rmidi->private_data;
- struct snd_kcontrol *ctl;
+ struct snd_ctl_elem_id ctl_id;
+ bool activate_ctl = false;
+ bool active;
guard(rwsem_read)(&umidi->disc_rwsem);
if (umidi->disconnected)
return open ? -ENODEV : 0;
- guard(mutex)(&umidi->mutex);
- if (open) {
- if (!umidi->opened[0] && !umidi->opened[1]) {
- if (umidi->roland_load_ctl) {
- ctl = umidi->roland_load_ctl;
- ctl->vd[0].access |=
- SNDRV_CTL_ELEM_ACCESS_INACTIVE;
- snd_ctl_notify(umidi->card,
- SNDRV_CTL_EVENT_MASK_INFO, &ctl->id);
- update_roland_altsetting(umidi);
+ scoped_guard(mutex, &umidi->mutex) {
+ if (open) {
+ if (!umidi->opened[0] && !umidi->opened[1]) {
+ if (umidi->roland_load_ctl) {
+ ctl_id = umidi->roland_load_ctl->id;
+ activate_ctl = true;
+ active = false;
+ update_roland_altsetting(umidi);
+ }
}
- }
- umidi->opened[dir]++;
- if (umidi->opened[1])
- snd_usbmidi_input_start(&umidi->list);
- } else {
- umidi->opened[dir]--;
- if (!umidi->opened[1])
- snd_usbmidi_input_stop(&umidi->list);
- if (!umidi->opened[0] && !umidi->opened[1]) {
- if (umidi->roland_load_ctl) {
- ctl = umidi->roland_load_ctl;
- ctl->vd[0].access &=
- ~SNDRV_CTL_ELEM_ACCESS_INACTIVE;
- snd_ctl_notify(umidi->card,
- SNDRV_CTL_EVENT_MASK_INFO, &ctl->id);
+ umidi->opened[dir]++;
+ if (umidi->opened[1])
+ snd_usbmidi_input_start(&umidi->list);
+ } else {
+ umidi->opened[dir]--;
+ if (!umidi->opened[1])
+ snd_usbmidi_input_stop(&umidi->list);
+ if (!umidi->opened[0] && !umidi->opened[1]) {
+ if (umidi->roland_load_ctl) {
+ ctl_id = umidi->roland_load_ctl->id;
+ activate_ctl = true;
+ active = true;
+ }
}
}
}
+ if (activate_ctl)
+ snd_ctl_activate_id(umidi->card, &ctl_id, active);
return 0;
}
--
2.34.1
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] ALSA: usb-audio: Protect Roland control activation
2026-09-29 7:40 [PATCH] ALSA: usb-audio: Protect Roland control activation Runyu Xiao
@ 2026-09-29 13:34 ` Takashi Iwai
2026-09-29 14:17 ` [PATCH v2] " Runyu Xiao
0 siblings, 1 reply; 4+ messages in thread
From: Takashi Iwai @ 2026-09-29 13:34 UTC (permalink / raw)
To: Runyu Xiao
Cc: Clemens Ladisch, Jaroslav Kysela, Takashi Iwai, Jianhao Xu,
linux-sound, linux-kernel
On Tue, 29 Sep 2026 09:40:26 +0200,
Runyu Xiao wrote:
>
> The USB MIDI driver changes the Roland MIDI Input Mode control's access
> flags directly from the rawmidi open and close paths. These changes are
> not protected by the ALSA control core and the corresponding notifications
> can race with control access.
>
> Use snd_ctl_activate_id() so that the control core updates the access flags
> and sends the notification under its lock. Release the USB MIDI mutex
> before calling it because the control write path holds controls_rwsem while
> roland_load_put() takes the USB MIDI mutex.
>
> Keep the state transition and alternate-setting change under the USB MIDI
> mutex; rawmidi's open mutex serializes the enclosing open and close paths.
>
> Fixes: 96f61d9ade82 ("sound: usb-audio: allow switching altsetting on Roland USB MIDI devices")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
The patch couldn't be applied cleanly on top of the latest sound git
tree for-next branch. Could you try to rebase and resubmit?
thanks,
Takashi
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v2] ALSA: usb-audio: Protect Roland control activation
2026-09-29 13:34 ` Takashi Iwai
@ 2026-09-29 14:17 ` Runyu Xiao
2026-09-29 14:27 ` Takashi Iwai
0 siblings, 1 reply; 4+ messages in thread
From: Runyu Xiao @ 2026-09-29 14:17 UTC (permalink / raw)
To: Clemens Ladisch
Cc: Jaroslav Kysela, Takashi Iwai, stable, Runyu Xiao, Jianhao Xu,
linux-sound, linux-kernel
The USB MIDI driver changes the Roland MIDI Input Mode control's access
flags directly from the rawmidi open and close paths. These changes are
not protected by the ALSA control core and the corresponding notifications
can race with control access.
Use snd_ctl_activate_id() so that the control core updates the access flags
and sends the notification under its lock. Release the USB MIDI mutex
before calling it because the control write path holds controls_rwsem while
roland_load_put() takes the USB MIDI mutex.
Keep the state transition and alternate-setting change under the USB MIDI
mutex; rawmidi's open mutex serializes the enclosing open and close paths.
Fixes: 96f61d9ade82 ("sound: usb-audio: allow switching altsetting on Roland USB MIDI devices")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
---
v2:
- Rebased onto sound.git for-next at 025877a3833d (2026-09-19).
- Preserved the for-next keep_input_running condition in the input stop path.
sound/usb/midi.c | 53 ++++++++++++++++++++++++------------------------
1 file changed, 27 insertions(+), 26 deletions(-)
diff --git a/sound/usb/midi.c b/sound/usb/midi.c
index 0480a9b89..e3d157554 100644
--- a/sound/usb/midi.c
+++ b/sound/usb/midi.c
@@ -1150,41 +1150,42 @@ static int substream_open(struct snd_rawmidi_substream *substream, int dir,
int open)
{
struct snd_usb_midi *umidi = substream->rmidi->private_data;
- struct snd_kcontrol *ctl;
+ struct snd_ctl_elem_id ctl_id;
+ bool activate_ctl = false;
+ bool active;
guard(rwsem_read)(&umidi->disc_rwsem);
if (umidi->disconnected)
return open ? -ENODEV : 0;
- guard(mutex)(&umidi->mutex);
- if (open) {
- if (!umidi->opened[0] && !umidi->opened[1]) {
- if (umidi->roland_load_ctl) {
- ctl = umidi->roland_load_ctl;
- ctl->vd[0].access |=
- SNDRV_CTL_ELEM_ACCESS_INACTIVE;
- snd_ctl_notify(umidi->card,
- SNDRV_CTL_EVENT_MASK_INFO, &ctl->id);
- update_roland_altsetting(umidi);
+ scoped_guard(mutex, &umidi->mutex) {
+ if (open) {
+ if (!umidi->opened[0] && !umidi->opened[1]) {
+ if (umidi->roland_load_ctl) {
+ ctl_id = umidi->roland_load_ctl->id;
+ activate_ctl = true;
+ active = false;
+ update_roland_altsetting(umidi);
+ }
}
- }
- umidi->opened[dir]++;
- if (umidi->opened[1])
- snd_usbmidi_input_start(&umidi->list);
- } else {
- umidi->opened[dir]--;
- if (!umidi->opened[1] && !umidi->keep_input_running)
- snd_usbmidi_input_stop(&umidi->list);
- if (!umidi->opened[0] && !umidi->opened[1]) {
- if (umidi->roland_load_ctl) {
- ctl = umidi->roland_load_ctl;
- ctl->vd[0].access &=
- ~SNDRV_CTL_ELEM_ACCESS_INACTIVE;
- snd_ctl_notify(umidi->card,
- SNDRV_CTL_EVENT_MASK_INFO, &ctl->id);
+ umidi->opened[dir]++;
+ if (umidi->opened[1])
+ snd_usbmidi_input_start(&umidi->list);
+ } else {
+ umidi->opened[dir]--;
+ if (!umidi->opened[1] && !umidi->keep_input_running)
+ snd_usbmidi_input_stop(&umidi->list);
+ if (!umidi->opened[0] && !umidi->opened[1]) {
+ if (umidi->roland_load_ctl) {
+ ctl_id = umidi->roland_load_ctl->id;
+ activate_ctl = true;
+ active = true;
+ }
}
}
}
+ if (activate_ctl)
+ snd_ctl_activate_id(umidi->card, &ctl_id, active);
return 0;
}
--
2.34.1
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH v2] ALSA: usb-audio: Protect Roland control activation
2026-09-29 14:17 ` [PATCH v2] " Runyu Xiao
@ 2026-09-29 14:27 ` Takashi Iwai
0 siblings, 0 replies; 4+ messages in thread
From: Takashi Iwai @ 2026-09-29 14:27 UTC (permalink / raw)
To: Runyu Xiao
Cc: Clemens Ladisch, Jaroslav Kysela, Takashi Iwai, stable,
Jianhao Xu, linux-sound, linux-kernel
On Tue, 29 Sep 2026 16:17:26 +0200,
Runyu Xiao wrote:
>
> The USB MIDI driver changes the Roland MIDI Input Mode control's access
> flags directly from the rawmidi open and close paths. These changes are
> not protected by the ALSA control core and the corresponding notifications
> can race with control access.
>
> Use snd_ctl_activate_id() so that the control core updates the access flags
> and sends the notification under its lock. Release the USB MIDI mutex
> before calling it because the control write path holds controls_rwsem while
> roland_load_put() takes the USB MIDI mutex.
>
> Keep the state transition and alternate-setting change under the USB MIDI
> mutex; rawmidi's open mutex serializes the enclosing open and close paths.
>
> Fixes: 96f61d9ade82 ("sound: usb-audio: allow switching altsetting on Roland USB MIDI devices")
> Cc: stable@vger.kernel.org
> Assisted-by: LLM
> Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Applied to for-next branch. Thanks.
Takashi
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-29 14:27 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-29 7:40 [PATCH] ALSA: usb-audio: Protect Roland control activation Runyu Xiao
2026-09-29 13:34 ` Takashi Iwai
2026-09-29 14:17 ` [PATCH v2] " Runyu Xiao
2026-09-29 14:27 ` Takashi Iwai
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®