Alsa-Devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/2] SX control bounds check fixups
@ 2022-11-25 15:48 Charles Keepax
  2022-11-25 15:48 ` [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls Charles Keepax
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Charles Keepax @ 2022-11-25 15:48 UTC (permalink / raw)
  To: broonie; +Cc: patches, alsa-devel, guille.rodriguez, lgirdwood

These two SX control fixups seem to have got lost somewhere along the
line. They were merged back in 5.18 but never seems to actually make it
into the kernel:

https://lore.kernel.org/all/165236477046.1016627.15470197691244479154.b4-ty@kernel.org/

Apologies if resending isn't the correct course but it seemed the safest
way to go. Note I have made a slight fixup to the second patch.

Thanks,
Charles

Mark Brown (2):
  ASoC: ops: Fix bounds check for _sx controls
  ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()

 sound/soc/soc-ops.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

-- 
2.30.2


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls
  2022-11-25 15:48 [PATCH 0/2] SX control bounds check fixups Charles Keepax
@ 2022-11-25 15:48 ` Charles Keepax
  2022-11-25 15:48 ` [PATCH 2/2] ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() Charles Keepax
  2022-11-25 15:52 ` [PATCH 0/2] SX control bounds check fixups Mark Brown
  2 siblings, 0 replies; 4+ messages in thread
From: Charles Keepax @ 2022-11-25 15:48 UTC (permalink / raw)
  To: broonie; +Cc: patches, alsa-devel, guille.rodriguez, lgirdwood

From: Mark Brown <broonie@kernel.org>

For _sx controls the semantics of the max field is not the usual one, max
is the number of steps rather than the maximum value. This means that our
check in snd_soc_put_volsw_sx() needs to just check against the maximum
value.

Fixes: 4f1e50d6a9cf ("ASoC: ops: Reject out of bounds values in snd_soc_put_volsw_sx()")
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
---
 sound/soc/soc-ops.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sound/soc/soc-ops.c b/sound/soc/soc-ops.c
index bd88de0563583..47691119306fb 100644
--- a/sound/soc/soc-ops.c
+++ b/sound/soc/soc-ops.c
@@ -452,7 +452,7 @@ int snd_soc_put_volsw_sx(struct snd_kcontrol *kcontrol,
 	val = ucontrol->value.integer.value[0];
 	if (mc->platform_max && val > mc->platform_max)
 		return -EINVAL;
-	if (val > max - min)
+	if (val > max)
 		return -EINVAL;
 	val_mask = mask << shift;
 	val = (val + min) & mask;
-- 
2.30.2


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [PATCH 2/2] ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx()
  2022-11-25 15:48 [PATCH 0/2] SX control bounds check fixups Charles Keepax
  2022-11-25 15:48 ` [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls Charles Keepax
@ 2022-11-25 15:48 ` Charles Keepax
  2022-11-25 15:52 ` [PATCH 0/2] SX control bounds check fixups Mark Brown
  2 siblings, 0 replies; 4+ messages in thread
From: Charles Keepax @ 2022-11-25 15:48 UTC (permalink / raw)
  To: broonie; +Cc: patches, alsa-devel, guille.rodriguez, lgirdwood

From: Mark Brown <broonie@kernel.org>

The bounds checks in snd_soc_put_volsw_sx() are only being applied to the
first channel, meaning it is possible to write out of bounds values to the
second channel in stereo controls. Add appropriate checks.

Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
---

Slight fixup was made over your original version to make the check of
val2 > max be without the min and mask applied.

Thanks,
Charles

 sound/soc/soc-ops.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/sound/soc/soc-ops.c b/sound/soc/soc-ops.c
index 47691119306fb..55b009d3c6815 100644
--- a/sound/soc/soc-ops.c
+++ b/sound/soc/soc-ops.c
@@ -464,10 +464,15 @@ int snd_soc_put_volsw_sx(struct snd_kcontrol *kcontrol,
 	ret = err;
 
 	if (snd_soc_volsw_is_stereo(mc)) {
-		unsigned int val2;
+		unsigned int val2 = ucontrol->value.integer.value[1];
+
+		if (mc->platform_max && val2 > mc->platform_max)
+			return -EINVAL;
+		if (val2 > max)
+			return -EINVAL;
 
 		val_mask = mask << rshift;
-		val2 = (ucontrol->value.integer.value[1] + min) & mask;
+		val2 = (val2 + min) & mask;
 		val2 = val2 << rshift;
 
 		err = snd_soc_component_update_bits(component, reg2, val_mask,
-- 
2.30.2


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH 0/2] SX control bounds check fixups
  2022-11-25 15:48 [PATCH 0/2] SX control bounds check fixups Charles Keepax
  2022-11-25 15:48 ` [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls Charles Keepax
  2022-11-25 15:48 ` [PATCH 2/2] ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() Charles Keepax
@ 2022-11-25 15:52 ` Mark Brown
  2 siblings, 0 replies; 4+ messages in thread
From: Mark Brown @ 2022-11-25 15:52 UTC (permalink / raw)
  To: Charles Keepax; +Cc: patches, alsa-devel, guille.rodriguez, lgirdwood

[-- Attachment #1: Type: text/plain, Size: 519 bytes --]

On Fri, Nov 25, 2022 at 03:48:35PM +0000, Charles Keepax wrote:
> These two SX control fixups seem to have got lost somewhere along the
> line. They were merged back in 5.18 but never seems to actually make it
> into the kernel:
> 
> https://lore.kernel.org/all/165236477046.1016627.15470197691244479154.b4-ty@kernel.org/
> 
> Apologies if resending isn't the correct course but it seemed the safest
> way to go. Note I have made a slight fixup to the second patch.

These should already be queued as fixes.

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2022-11-25 15:53 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-11-25 15:48 [PATCH 0/2] SX control bounds check fixups Charles Keepax
2022-11-25 15:48 ` [PATCH 1/2] ASoC: ops: Fix bounds check for _sx controls Charles Keepax
2022-11-25 15:48 ` [PATCH 2/2] ASoC: ops: Check bounds for second channel in snd_soc_put_volsw_sx() Charles Keepax
2022-11-25 15:52 ` [PATCH 0/2] SX control bounds check fixups Mark Brown

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox