From: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
To: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>,
vkoul@kernel.org, perex@perex.cz, tiwai@suse.com,
lgirdwood@gmail.com, broonie@kernel.org,
srinivas.kandagatla@oss.qualcomm.com
Cc: linux-sound@vger.kernel.org, kai.vehmanen@linux.intel.com,
yung-chuan.liao@linux.intel.com, daniel.baluta@nxp.com
Subject: Re: [PATCH v2 09/24] ASoC: SOF: sof-audio: do not dereference swidget->spipe unconditionally on free
Date: Wed, 9 Sep 2026 14:39:53 +0200 [thread overview]
Message-ID: <f57fb6d1-31d8-46cc-be16-aaa85fce99a0@linux.dev> (raw)
In-Reply-To: <20260909090949.7503-10-peter.ujfalusi@linux.intel.com>
On 9/9/26 11:09, Peter Ujfalusi wrote:
> sof_widget_free_unlocked() dereferences swidget->spipe without checking
> it for two things: swidget->spipe->complete for a scheduler widget, and
> swidget->spipe->pipe_widget for the recursive free of the pipeline's
> scheduler widget. Both can be reached with spipe or pipe_widget not
> set, which oopses in the free path - where there is nothing left to
> bail out to.
>
> Check both before use and cache swidget->spipe in the local spipe
> variable that is already there. A widget with no pipeline has nothing
> to put or complete, and no scheduler widget to free, so skipping is the
> correct behaviour.
>
> No functional change for a widget that was successfully set up:
> sof_widget_setup_unlocked() already rejects a dynamic pipeline widget
> with no spipe or no spipe->pipe_widget with -EINVAL.
>
> Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
> Reviewed-by: Liam Girdwood <liam.r.girdwood@intel.com>
> ---
> sound/soc/sof/sof-audio.c | 8 ++++----
> 1 file changed, 4 insertions(+), 4 deletions(-)
same, this doesn't seem directly related to compresss offload. Maybe
it's required because of new transitions?
I'd move this earlier or submit as a cleanup separately to reduce the
volume of reviews (24 patches!)
> diff --git a/sound/soc/sof/sof-audio.c b/sound/soc/sof/sof-audio.c
> index d244e90a734b..0b2f41f4a59b 100644
> --- a/sound/soc/sof/sof-audio.c
> +++ b/sound/soc/sof/sof-audio.c
> @@ -103,7 +103,7 @@ static int sof_widget_free_unlocked(struct snd_sof_dev *sdev,
> * decrement ref count for cores associated with all modules in the pipeline and clear
> * the complete flag
> */
> - if (swidget->id == snd_soc_dapm_scheduler) {
> + if (swidget->id == snd_soc_dapm_scheduler && spipe) {
> int i;
>
> for_each_set_bit(i, &spipe->core_mask, sdev->num_cores) {
> @@ -115,16 +115,16 @@ static int sof_widget_free_unlocked(struct snd_sof_dev *sdev,
> err = ret;
> }
> }
> - swidget->spipe->complete = 0;
> + spipe->complete = 0;
> }
>
> /*
> * free the scheduler widget (same as pipe_widget) associated with the current swidget.
> * skip for static pipelines
> */
> - if (swidget->spipe && swidget->dynamic_pipeline_widget &&
> + if (spipe && spipe->pipe_widget && swidget->dynamic_pipeline_widget &&
> swidget->id != snd_soc_dapm_scheduler) {
> - ret = sof_widget_free_unlocked(sdev, swidget->spipe->pipe_widget);
> + ret = sof_widget_free_unlocked(sdev, spipe->pipe_widget);
> if (ret < 0 && !err)
> err = ret;
> }
next prev parent reply other threads:[~2026-09-09 14:23 UTC|newest]
Thread overview: 47+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 9:09 [PATCH v2 00/24] ALSA compress / ASoC compress / SOF: Compressed audio support with IPC4 Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 01/24] ALSA: compress: pin card module while stream is open Peter Ujfalusi
2026-09-09 15:12 ` Takashi Iwai
2026-09-09 9:09 ` [PATCH v2 02/24] ALSA: compress: register the open file with the card Peter Ujfalusi
2026-09-09 15:12 ` Takashi Iwai
2026-09-09 9:09 ` [PATCH v2 03/24] ALSA: compress: stop active streams on disconnect Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 04/24] ASoC: soc-compress: Provide a runtime for the compressed FE substream Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 05/24] ASoC: soc-compress: Implement trigger FE-BE sequencing as with normal PCMs Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 06/24] ASoC: soc-compress: Stop running dpcm on free Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 07/24] ASoC: SOF: compress: Rename compress ops with ipc3 prefix Peter Ujfalusi
2026-09-09 12:34 ` Pierre-Louis Bossart
2026-09-10 14:13 ` Péter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 08/24] ASoC: SOF: ipc4-pcm: harden pipeline teardown races Peter Ujfalusi
2026-09-09 12:37 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 09/24] ASoC: SOF: sof-audio: do not dereference swidget->spipe unconditionally on free Peter Ujfalusi
2026-09-09 12:39 ` Pierre-Louis Bossart [this message]
2026-09-09 9:09 ` [PATCH v2 10/24] ASoC: SOF: sof-audio: Expose a couple of functions Peter Ujfalusi
2026-09-09 12:41 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 11/24] ASoC: SOF: pcm: Modify the signature of a couple of PCM IPC ops Peter Ujfalusi
2026-09-09 12:43 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 12/24] ASoC: SOF: intel: hda-stream: Clear the current position when releasing stream Peter Ujfalusi
2026-09-09 12:45 ` Pierre-Louis Bossart
2026-09-11 6:31 ` Péter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 13/24] ASoC: SOF: ops: Add new platform-specific ops for compress Peter Ujfalusi
2026-09-09 14:23 ` Pierre-Louis Bossart
2026-09-10 14:25 ` Péter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 14/24] ASoC: SOF: ipc4: Add definition of module data in init_ext object type Peter Ujfalusi
2026-09-09 12:49 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 15/24] ASoC: SOF: ipc4-topology: Support init_ext_module_data for process modules Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 16/24] ASoC: SOF: ipc4-pcm: Make the timestamp info usable outside of ipc4-pcm.c Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 17/24] ASoC: SOF: ipc4/ipc4-loader: Add SOF_INFO and CODEC_INFO to fw_config_params Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 18/24] ASoC: SOF: ipc4-pcm: Handle COMPR DRAIN triggers as EOS pipeline state Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 19/24] ASoC: SOF: ipc4-topology: Set FAST_MODE for host copier in compr mode Peter Ujfalusi
2026-09-09 13:21 ` Pierre-Louis Bossart
2026-09-10 14:49 ` Péter Ujfalusi
2026-09-11 19:08 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 20/24] ASoC: SOF: Add support for IPC4 compressed Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 21/24] ASoC: SOF: ipc4: Handle compressed drain done notification from firmware Peter Ujfalusi
2026-09-09 13:28 ` Pierre-Louis Bossart
2026-09-10 15:08 ` Péter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 22/24] ASoC: SOF: Intel: Kconfig: Remove redundant IPC version selects Peter Ujfalusi
2026-09-09 13:29 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 23/24] ASoC: SOF: Intel: Kconfig: Select compress support for TGL+ platforms Peter Ujfalusi
2026-09-09 13:37 ` Pierre-Louis Bossart
2026-09-10 14:57 ` Péter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 24/24] ASoC: SOF: topology: Add support for decoder and encoder widgets Peter Ujfalusi
2026-09-09 13:42 ` [PATCH v2 00/24] ALSA compress / ASoC compress / SOF: Compressed audio support with IPC4 Pierre-Louis Bossart
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f57fb6d1-31d8-46cc-be16-aaa85fce99a0@linux.dev \
--to=pierre-louis.bossart@linux.dev \
--cc=broonie@kernel.org \
--cc=daniel.baluta@nxp.com \
--cc=kai.vehmanen@linux.intel.com \
--cc=lgirdwood@gmail.com \
--cc=linux-sound@vger.kernel.org \
--cc=perex@perex.cz \
--cc=peter.ujfalusi@linux.intel.com \
--cc=srinivas.kandagatla@oss.qualcomm.com \
--cc=tiwai@suse.com \
--cc=vkoul@kernel.org \
--cc=yung-chuan.liao@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.