alsa-devel.alsa-project.org archive mirror
 help / color / mirror / Atom feed
From: Vinod Koul <vinod.koul@intel.com>
To: Takashi Iwai <tiwai@suse.de>
Cc: liam.r.girdwood@linux.intel.com, patches.audio@intel.com,
	alsa-devel@alsa-project.org, broonie@kernel.org
Subject: Re: [PATCH] amixer: add support for TLV byte control read
Date: Fri, 22 Jan 2016 13:16:23 +0530	[thread overview]
Message-ID: <20160122074623.GC11130@localhost> (raw)
In-Reply-To: <s5hoace5e75.wl-tiwai@suse.de>

On Fri, Jan 22, 2016 at 07:19:10AM +0100, Takashi Iwai wrote:
> On Fri, 22 Jan 2016 06:46:52 +0100,
> Vinod Koul wrote:
> > 
> > TLV byte control are new type of byte controls added in kernel where
> > controls can have large sizes.
> >
> > For these controls querying with 4096 size fails, so use the queried size to
> > read the control
> > 
> > This fixes the crash with current cget/contents on these type of controls
> 
> Hmm...  Theoretically the TLV size and the element size are
> independent.  So, it's not good to check only the type being
> SND_CTL_ELEM_TYPE_BYTES.  This can be used legally by other cases,
> too.
> 
> Basically it is an abuse in ASoC side to return the size of
> TLV by the element's info.  Usually such value would lead to crash,
> but the unique point of ASoC ext bytes ctl is that it doesn't have RW
> accesses but only TLV_RW accesses.

But isn't that already checked? Since we are in the code which will be
executed only for tlv as snd_ctl_elem_info_is_tlv_readable() ensures that.
So this is only for tlv + bytes ...

> 
> So, instead of only checking the type being BYTES, check the
> accesses.  Only when all these conditions are met, we may take the
> count as TLV (element) size.  (And still we should have the sanity
> check of the value, too.)
> 
> Yet, this isn't a really "fix" for the crash.  Even without the patch
> it shouldn't crash -- it should receive 4096 bytes, and tries to
> decode.  Where did you get the crash exactly?

in alsa-lib snd_ctl_hw_elem_tlv() when it tries to do memcpy for tlv read.
But the crash is caused as tlv read is large and we have only 4096 size
buffer, so we ensure we give right size buffer here

-- 
~Vinod
> > Signed-off-by: Vinod Koul <vinod.koul@intel.com>
> > ---
> >  amixer/amixer.c | 15 +++++++++++----
> >  1 file changed, 11 insertions(+), 4 deletions(-)
> > 
> > diff --git a/amixer/amixer.c b/amixer/amixer.c
> > index db1849333da3..cfe13592347f 100644
> > --- a/amixer/amixer.c
> > +++ b/amixer/amixer.c
> > @@ -588,7 +588,7 @@ static int show_control(const char *space, snd_hctl_elem_t *elem,
> >  			int level)
> >  {
> >  	int err;
> > -	unsigned int item, idx, count, *tlv;
> > +	unsigned int item, idx, count, *tlv, tlv_sz;
> >  	snd_ctl_elem_type_t type;
> >  	snd_ctl_elem_id_t *id;
> >  	snd_ctl_elem_info_t *info;
> > @@ -682,13 +682,20 @@ static int show_control(const char *space, snd_hctl_elem_t *elem,
> >  	      __skip_read:
> >  		if (!snd_ctl_elem_info_is_tlv_readable(info))
> >  			goto __skip_tlv;
> > -		tlv = malloc(4096);
> > -		if ((err = snd_hctl_elem_tlv_read(elem, tlv, 4096)) < 0) {
> > +
> > +		if (type == SND_CTL_ELEM_TYPE_BYTES)
> > +			tlv_sz = count + 2 * sizeof(unsigned int);
> > +		else
> > +			tlv_sz = 4096;
> > +
> > +		tlv = malloc(tlv_sz);
> > +
> > +		if ((err = snd_hctl_elem_tlv_read(elem, tlv, tlv_sz)) < 0) {
> >  			error("Control %s element TLV read error: %s\n", card, snd_strerror(err));
> >  			free(tlv);
> >  			return err;
> >  		}
> > -		decode_tlv(strlen(space), tlv, 4096);
> > +		decode_tlv(strlen(space), tlv, tlv_sz);
> >  		free(tlv);
> >  	}
> >        __skip_tlv:
> > -- 
> > 1.9.1
> > 

  reply	other threads:[~2016-01-22  7:42 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-01-22  5:46 [PATCH] amixer: add support for TLV byte control read Vinod Koul
2016-01-22  6:19 ` Takashi Iwai
2016-01-22  7:46   ` Vinod Koul [this message]
2016-01-22  8:09     ` Takashi Iwai
2016-01-22  8:26       ` Takashi Iwai
2016-01-22  9:57         ` Vinod Koul
2016-01-22  9:56       ` Vinod Koul
2016-01-22 10:50         ` Takashi Iwai
2016-01-27 17:47           ` Vinod Koul
2016-01-27 18:49             ` Takashi Iwai
2016-01-28  4:25               ` Vinod Koul
2016-01-28  5:49                 ` Takashi Iwai
2016-01-28  9:26                   ` Vinod Koul
2016-01-28 16:19                     ` Takashi Iwai
2016-01-29  6:51                       ` Vinod Koul
2016-01-29 11:13                         ` Vinod Koul
2016-01-29 13:17                           ` Takashi Iwai
2016-01-29 13:53                             ` Vinod Koul
2016-01-29 13:53                               ` Takashi Iwai

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20160122074623.GC11130@localhost \
    --to=vinod.koul@intel.com \
    --cc=alsa-devel@alsa-project.org \
    --cc=broonie@kernel.org \
    --cc=liam.r.girdwood@linux.intel.com \
    --cc=patches.audio@intel.com \
    --cc=tiwai@suse.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).