imx.lists.linux.dev archive mirror
 help / color / mirror / Atom feed
From: Takashi Iwai <tiwai@suse.de>
To: Xu Yang <xu.yang_2@nxp.com>
Cc: Takashi Iwai <tiwai@suse.de>,
	perex@perex.cz, tiwai@suse.com, linux-sound@vger.kernel.org,
	imx@lists.linux.dev
Subject: Re: [PATCH] ALSA: usb-audio: fix potential use after free issue when remove module snd-usb-audioy
Date: Wed, 22 May 2024 07:57:24 +0200	[thread overview]
Message-ID: <87jzjmz8vv.wl-tiwai@suse.de> (raw)
In-Reply-To: <20240522033425.yztpigsv3uhdl5zv@hippo>

On Wed, 22 May 2024 05:34:25 +0200,
Xu Yang wrote:
> 
> On Tue, May 21, 2024 at 01:32:37PM +0200, Takashi Iwai wrote:
> > On Tue, 21 May 2024 12:56:05 +0200,
> > Xu Yang wrote:
> > > 
> > > On Mon, May 20, 2024 at 12:29:15PM +0200, Takashi Iwai wrote:
> > > > On Mon, 20 May 2024 19:03:49 +0200,
> > > > Xu Yang wrote:
> > > > > 
> > > > > When remove module snd-usb-audio, snd_card_free_when_closed() will not
> > > > > release the card resource if the card_dev refcount > 0 and
> > > 
> > > [...]
> > > 
> > > > > Then, even the userspace trying to cleanup the resources, kernel will not
> > > > > touch the released code memory.
> > > > 
> > > > Hm, it's an interesting report.  Could you verify whether it's really
> > > > hitting a module unload race?  The module refcount should have been
> > > > non-zero when the device is still in use, and it should have prevented
> > > > the module unloading.
> > > 
> > > Yes, the race does exist. I enable trace and got below output:
> > > It seems that snd_usb_audio module refcnt is 0 after insmod completed. So
> > > it can continue to be removed even it's still in use.
> > 
> > If no device is opened, it's not really "used", and the driver module
> > can be unloaded at any time.  That's the intended behavior.
> 
> Hh, I see wireplumber did open the card_dev when it scan card devices.
> But wireplumber didn't close the card_dev when the scan process completed.

Then rmmod shouldn't have been allowed, it's a consequence of the NULL
module pointer, I suppose.

> > (snip)
> > > Then I take some time to check why snd_usb_audio module refcnt is 0
> > > even though the card_dev is in use. Finally I got below finding:
> > > 
> > > I build kernel and module with below configuration:
> > > 
> > > CONFIG_SOUND=y
> > > CONFIG_SND=y
> > > CONFIG_SND_USB=y
> > > CONFIG_SND_USB_AUDIO=m
> > > 
> > > Then GCC will add -DMODULE when build snd-usb-audio as module, but will
> > > not add -DMODULE when build sound/core/*.c.
> > > 
> > > When insmod snd-usb-audio.ko, it will create a snd card device and call:
> > > 
> > > snd_card_init()  // sound/core/init.c
> > > 
> > >   #ifdef MODULE
> > >     WARN_ON(!module);
> > >     card->module = module;
> > >   #endif
> > > 
> > > However, MODULE is not defined for sound/core/init.c, then card->module
> > > will keep NULL pointer. With this results, snd-usb-audio module refcnt
> > > will not be a non-zero value.
> > 
> > Ah, it's a good finding!  That explains.
> > 
> > > > Practically seen, replacing snd_card_free_when_closed() with
> > > > snd_card_free() shouldn't be a big problem, and it'll work in most
> > > > cases.  But there are always some corner cases that might lead to
> > > > unexpected behavior.  So, let's try to analyze more exactly what's
> > > > happening there at first.
> > > 
> > > With above finding, we needn't to replace snd_card_free_when_closed()
> > > with snd_card_free(). We need to find a way to correctly handle module
> > > refcnt since this should be a normal usecase.
> > 
> > Right, I guess a simple fix below to replace '#ifdef MODULE' with
> > '#ifdef CONFIG_MODULES' should work instead?
> 
> Yeah, it works for me.
> Will you send a fix for the issue or suggest me send it? ^_^

I'm going to submit a proper fix patch later.


thanks,

Takashi

  reply	other threads:[~2024-05-22  5:57 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-05-20 17:03 [PATCH] ALSA: usb-audio: fix potential use after free issue when remove module snd-usb-audio Xu Yang
2024-05-20 10:29 ` Takashi Iwai
2024-05-21 10:56   ` Xu Yang
2024-05-21 11:32     ` Takashi Iwai
2024-05-22  3:34       ` [PATCH] ALSA: usb-audio: fix potential use after free issue when remove module snd-usb-audioy Xu Yang
2024-05-22  5:57         ` Takashi Iwai [this message]
2024-05-22  6:21           ` Takashi Iwai
2024-05-22  6:36             ` Xu Yang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87jzjmz8vv.wl-tiwai@suse.de \
    --to=tiwai@suse.de \
    --cc=imx@lists.linux.dev \
    --cc=linux-sound@vger.kernel.org \
    --cc=perex@perex.cz \
    --cc=tiwai@suse.com \
    --cc=xu.yang_2@nxp.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).