Linux kernel and device drivers for NXP i.MX platforms
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: phucduc.bui@gmail.com
Cc: imx@lists.linux.dev, Frank.Li@kernel.org,
	wsa+renesas@sang-engineering.com
Subject: Re: [PATCH 06/24] ASoC: amd: vangogh: Fix acp5x_dma_close() being skipped on rollback
Date: Thu, 08 Oct 2026 10:54:09 +0000	[thread overview]
Message-ID: <sashiko-outbox-164055@kernel.org> (raw)
In-Reply-To: <20261008103831.542533-7-phucduc.bui@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] ASoC: amd: vangogh: Uninitialized i2s_instance in acp5x_dma_close() corrupts concurrent streams
--

commit 0fa96f07228732634c84e9e1736847a1c270fb29
Author: bui duc phuc <phucduc.bui@gmail.com>

ASoC: amd: vangogh: Fix acp5x_dma_close() being skipped on rollback

This commit explicitly returns 0 on success in acp5x_dma_open() to ensure
ASoC correctly marks the component as opened. This prevents .close() from
being skipped during a rollback if .open() initially returned 1 from
snd_pcm_hw_constraint_integer().

> diff --git a/sound/soc/amd/vangogh/acp5x-pcm-dma.c b/sound/soc/amd/vangogh/acp5x-pcm-dma.c
> index 831e30e9b0426..33d59d992ee0c 100644
> --- a/sound/soc/amd/vangogh/acp5x-pcm-dma.c
> +++ b/sound/soc/amd/vangogh/acp5x-pcm-dma.c
> @@ -231,7 +231,7 @@ static int acp5x_dma_open(struct snd_soc_component *component,
>  	}
>  	i2s_data->acp5x_base = adata->acp5x_base;
>  	runtime->private_data = i2s_data;
> -	return ret;
> +	return 0;

[Severity: Critical]
By ensuring acp5x_dma_open() returns 0, ALSA SoC will now call
acp5x_dma_close() on rollback if a stream is aborted before hw_params()
is called.

Can this regression corrupt the state of concurrent streams?

When acp5x_dma_open() allocates i2s_data via kzalloc(), the i2s_instance
field is initialized to 0. It is only set to its correct value later in
acp5x_dma_hw_params().

If acp5x_dma_close() runs on rollback before hw_params() is called:

sound/soc/amd/vangogh/acp5x-pcm-dma.c:acp5x_dma_close() {
    ...
	if (substream->stream == SNDRV_PCM_STREAM_PLAYBACK) {
		switch (ins->i2s_instance) {
		case I2S_HS_INSTANCE:
			adata->play_stream = NULL;
			break;
		case I2S_SP_INSTANCE:
		default:
			adata->i2ssp_play_stream = NULL;
		}
    ...
}

Because ins->i2s_instance is 0, it falls through to the default case
and sets adata->i2ssp_play_stream = NULL.

Since adata is shared per-device data, this incorrectly clears the stream
tracking pointer for a completely separate, concurrently running stream.

When the hardware fires a threshold interrupt for the active stream,
the handler will fail to clear it:

sound/soc/amd/vangogh/acp5x-pcm-dma.c:i2s_irq_handler() {
    ...
	if ((val & BIT(I2S_TX_THRESHOLD)) && vg_i2s_data->i2ssp_play_stream) {
		acp_writel(BIT(I2S_TX_THRESHOLD),
			   vg_i2s_data->acp5x_base + ACP_EXTERNAL_INTR_STAT);
		snd_pcm_period_elapsed(vg_i2s_data->i2ssp_play_stream);
		irq_flag = 1;
	}
    ...
}

Because the pointer was nullified, the interrupt remains asserted and the
handler returns IRQ_NONE, causing an infinite hardirq loop.

>  }
>  
>  static int acp5x_dma_hw_params(struct snd_soc_component *component,

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261008103831.542533-1-phucduc.bui@gmail.com?part=6

  reply	other threads:[~2026-10-08 10:54 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08 10:38 [PATCH 00/24] ASoC: Fix constraint return value handling phucduc.bui
2026-10-08 10:38 ` [PATCH 01/24] ASoC: amd: acp: Fix .close() being skipped on rollback phucduc.bui
2026-10-08 10:38 ` [PATCH 02/24] ASoC: amd: ps: Fix acp63_pdm_dma_close() " phucduc.bui
2026-10-08 10:38 ` [PATCH 03/24] ASoC: amd: ps: Fix acp63_sdw_dma_close() " phucduc.bui
2026-10-08 10:38 ` [PATCH 04/24] ASoC: amd: raven: Fix acp3x_dma_close() " phucduc.bui
2026-10-08 10:38 ` [PATCH 05/24] ASoC: amd: renoir: Fix acp_pdm_dma_close() " phucduc.bui
2026-10-08 10:38 ` [PATCH 06/24] ASoC: amd: vangogh: Fix acp5x_dma_close() " phucduc.bui
2026-10-08 10:54   ` sashiko-bot [this message]
2026-10-08 10:38 ` [PATCH 07/24] ASoC: amd: yc: Fix acp6x_pdm_dma_close() " phucduc.bui
2026-10-08 10:38 ` [PATCH 08/24] ASoC: apple: mca: Ensure the DAI is marked as started on success phucduc.bui
2026-10-08 10:38 ` [PATCH 09/24] ASoC: atmel: atmel-pcm-pdc: Fix atmel_pcm_close() being skipped on rollback phucduc.bui
2026-10-08 10:38 ` [PATCH 10/24] ASoC: codecs: cs42l42: Ensure the DAI is marked as started on success phucduc.bui
2026-10-08 10:47   ` Richard Fitzgerald
2026-10-08 11:00     ` Bui Duc Phuc
2026-10-08 10:38 ` [PATCH 11/24] ASoC: codecs: nau8325: " phucduc.bui
2026-10-08 10:38 ` [PATCH 12/24] ASoC: codecs: nau8540: " phucduc.bui
2026-10-08 10:38 ` [PATCH 13/24] ASoC: codecs: nau8821: " phucduc.bui
2026-10-08 10:38 ` [PATCH 14/24] ASoC: codecs: nau8824: " phucduc.bui
2026-10-08 10:38 ` [PATCH 15/24] ASoC: codecs: nau8825: " phucduc.bui
2026-10-08 10:38 ` [PATCH 16/24] ASoC: codecs: wm8580: " phucduc.bui
2026-10-08 10:38 ` [PATCH 17/24] ASoC: codecs: wm8782: " phucduc.bui
2026-10-08 10:38 ` [PATCH 18/24] ASoC: imx-pcm-rpmsg: Fix imx_rpmsg_pcm_close() being skipped on rollback phucduc.bui
2026-10-08 10:38 ` [PATCH 19/24] ASoC: intel: atom: Fix .shutdown() " phucduc.bui
2026-10-08 10:38 ` [PATCH 20/24] ASoC: renesas: fsi: Ensure the component is marked as opened on success phucduc.bui
2026-10-08 10:38 ` [PATCH 21/24] ASoC: renesas: msiof: Fix msiof_close() being skipped on rollback phucduc.bui
2026-10-08 10:57   ` sashiko-bot
2026-10-08 10:38 ` [PATCH 22/24] ASoC: renesas: rz-ssi: Ensure the component is marked as opened on success phucduc.bui
2026-10-08 10:38 ` [PATCH 23/24] ASoC: rockchip: rk3399_gru_sound: Mark the link as started " phucduc.bui
2026-10-08 10:38 ` [PATCH 24/24] ASoC: rockchip: rockchip_max98090: " phucduc.bui

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-164055@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=imx@lists.linux.dev \
    --cc=phucduc.bui@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wsa+renesas@sang-engineering.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox