All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Tomi Valkeinen" <tomi.valkeinen@ideasonboard.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH] ASoC: ti: omap-hdmi: Fix build error from a merge commit
Date: Thu, 03 Sep 2026 09:45:38 +0000	[thread overview]
Message-ID: <20260903094538.C0E1D1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260903-omap-hdmi-fix-v1-1-b0447a1d35d5@ideasonboard.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Incorrect devres device used for component and PCM registration causing use-after-free on driver unbind.
--

commit d20d30b72e20d6e45546f7cb8a33e56c5ed791b9
Author: Tomi Valkeinen <tomi.valkeinen@ideasonboard.com>

ASoC: ti: omap-hdmi: Fix build error from a merge commit
    
This commit removes an invalid assignment to a deleted member 'card' in the
hdmi_audio_data structure to fix a build error caused by an incorrect merge.

Closes: https://lore.kernel.org/all/apbbvQSfUbzYRFaw@sirena.org.uk/

> diff --git a/sound/soc/ti/omap-hdmi.c b/sound/soc/ti/omap-hdmi.c
> index c32ec7c0b0cf5..2cabd4cc5b0bd 100644
> --- a/sound/soc/ti/omap-hdmi.c
> +++ b/sound/soc/ti/omap-hdmi.c
> @@ -405,7 +405,6 @@ static int omap_hdmi_audio_probe(struct platform_device *pdev)
>  	card->dev = dev;
>  
>  	atomic_set(&ad->jack_state, -1);
> -	ad->card = card;

[Severity: High]
This isn't a bug introduced by this patch, but earlier in this function,
component and PCM devres registration are attached to the parent device
(ad->dssdev) instead of the child platform device (dev):

	ret = devm_snd_soc_register_component(ad->dssdev, &omap_hdmi_component,
					 dai_drv, 1);
	...
	ret = sdma_pcm_platform_register(ad->dssdev, "audio_tx", NULL);

Could this cause a use-after-free on child driver unbind?

If the omap-hdmi-audio driver is manually unbound via sysfs or its module
is unloaded, the child device's devres hooks execute and memory allocated
for the child (including the hdmi_audio_data struct ad) is freed.

Because devm_snd_soc_register_component() and sdma_pcm_platform_register()
were called using the parent device (ad->dssdev), their devres cleanup
hooks remain attached to the parent and do not execute during child unbind.

Does this leave the ASoC core with dangling pointers to the unloaded module's
static component structures and freed data?

>  
>  	snd_soc_card_set_drvdata(card, ad);
>  	ret = devm_snd_soc_register_card(dev, card);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260903-omap-hdmi-fix-v1-1-b0447a1d35d5@ideasonboard.com?part=1

  reply	other threads:[~2026-09-03  9:45 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03  9:38 [PATCH] ASoC: ti: omap-hdmi: Fix build error from a merge commit Tomi Valkeinen
2026-09-03  9:45 ` sashiko-bot [this message]
2026-09-07 21:01 ` Ivaylo Dimitrov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260903094538.C0E1D1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=tomi.valkeinen@ideasonboard.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.