From: sashiko-bot@kernel.org
To: "David Heidelberg" <david@ixit.cz>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH v4 5/8] ASoC: cs35l36: Implement set_tdm_slot to program RX and TX slots
Date: Thu, 24 Sep 2026 13:36:14 +0000 [thread overview]
Message-ID: <20260924133615.19BB81F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924-pixel3-audio-v4-5-85b5d133aa5e@ixit.cz>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] ASoC: cs35l36: DAPM 'Input Mux' conflicts with set_tdm_slot over ASP_RX1_SLOT
--
commit b9a33ee349c8716b47c6a0d1a24434c14d2f72d5
Author: David Heidelberg <david@ixit.cz>
ASoC: cs35l36: Implement set_tdm_slot to program RX and TX slots
Program the ASP RX and TX slot registers from the TDM masks passed by
the machine driver. Each set bit in a mask names a slot; codec channels
are assigned to those slots in order, ASPRX1 taking the first RX slot
and ASPTX1..TX8 the first eight TX slots.
> diff --git a/sound/soc/codecs/cs35l36.c b/sound/soc/codecs/cs35l36.c
> index 170588be4dbe3..5fc8ec292e3c4 100644
> --- a/sound/soc/codecs/cs35l36.c
> +++ b/sound/soc/codecs/cs35l36.c
[ ... ]
> @@ -947,6 +947,49 @@ static const struct cs35l36_pll_config *cs35l36_get_clk_config(
> return NULL;
> }
>
> +static void cs35l36_mask_to_slots(struct cs35l36_private *cs35l36,
> + unsigned long mask, unsigned int base_reg,
> + unsigned int nchan)
> +{
> + unsigned int chan = 0, shift;
> + int slot;
> +
> + /* Two 6-bit slot fields per register, at bits 0 and 16 */
> + for_each_set_bit(slot, &mask, BITS_PER_TYPE(mask)) {
> + if (chan == nchan) {
> + dev_warn(cs35l36->dev,
> + "Too many slots in TDM mask: %lx\n", mask);
> + return;
> + }
> +
> + shift = (chan % 2) * CS35L36_ASP_TX2_SLOT_SHIFT;
> + regmap_update_bits(cs35l36->regmap, base_reg + (chan / 2) * 4,
> + CS35L36_ASP_RX1_SLOT_MASK << shift,
> + slot << shift);
> + chan++;
> + }
> +}
> +
> +static int cs35l36_set_tdm_slot(struct snd_soc_dai *dai,
> + unsigned int tx_mask, unsigned int rx_mask,
> + int slots, int slot_width)
> +{
> + struct cs35l36_private *cs35l36 =
> + snd_soc_component_get_drvdata(dai->component);
> +
> + /* Note: rx/tx is from point of view of the CPU end */
> + if (!slots || !rx_mask)
> + rx_mask = BIT(0); /* ASPRX1 in slot 0 */
> +
> + if (!slots || !tx_mask)
> + tx_mask = GENMASK(7, 0); /* ASPTX1..8 in slots 0..7 */
> +
> + cs35l36_mask_to_slots(cs35l36, rx_mask, CS35L36_ASP_RX1_SLOT, 1);
[Severity: High]
Does overwriting CS35L36_ASP_RX1_SLOT here conflict with the DAPM "Input Mux"
control?
The CS35L36_ASP_RX1_SLOT register is already exposed to userspace as a DAPM
enum (chansel_enum).
If a machine driver sets the TDM slot using snd_soc_dai_set_tdm_slot(), it
overwrites this register via regmap_update_bits() in cs35l36_mask_to_slots().
However, if userspace later modifies the mixer control, DAPM will write back
to the register. Because the enum only covers 1 bit (options 'RX1' and 'RX2'),
it will overwrite bit 0, corrupting the TDM slot assigned by the machine
driver.
Can this cause the ALSA DAPM state to fall out of sync with the hardware and
allow unprivileged userspace to unknowingly break audio routing?
> + cs35l36_mask_to_slots(cs35l36, tx_mask, CS35L36_ASP_TX1_TX2_SLOT, 8);
> +
> + return 0;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924-pixel3-audio-v4-0-85b5d133aa5e@ixit.cz?part=5
next prev parent reply other threads:[~2026-09-24 13:36 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 13:24 [PATCH v4 0/8] Speakers for Pixel 3 / 3 XL David Heidelberg via B4 Relay
2026-09-24 13:24 ` [PATCH v4 1/8] ASoC: qcom: sdm845: Demystify TDM masks a bit David Heidelberg via B4 Relay
2026-09-24 13:34 ` sashiko-bot
2026-09-25 8:14 ` Srinivas Kandagatla
2026-09-24 13:24 ` [PATCH v4 2/8] ASoC: qcom: sdm845: use DSP_A format for TDM codec DAIs David Heidelberg via B4 Relay
2026-09-25 8:22 ` Srinivas Kandagatla
2026-09-24 13:24 ` [PATCH v4 3/8] ASoC: qcom: sdm845: Use per-speaker RX masks for TDM slot assignment David Heidelberg via B4 Relay
2026-09-25 8:23 ` Srinivas Kandagatla
2026-09-24 13:24 ` [PATCH v4 4/8] ASoC: qcom: sdm845: Set codec dai and component sysclk during startup David Heidelberg via B4 Relay
2026-09-25 8:26 ` Srinivas Kandagatla
2026-09-24 13:24 ` [PATCH v4 5/8] ASoC: cs35l36: Implement set_tdm_slot to program RX and TX slots David Heidelberg via B4 Relay
2026-09-24 13:36 ` sashiko-bot [this message]
2026-09-24 13:24 ` [PATCH v4 6/8] arm64: dts: qcom: sdm845-google: Add basic audio support David Heidelberg via B4 Relay
2026-09-24 13:37 ` sashiko-bot
2026-09-24 13:24 ` [PATCH v4 7/8] slimbus: qcom-ngd-ctrl: Remove data channels on stream disable David Heidelberg via B4 Relay
2026-09-24 13:36 ` sashiko-bot
2026-09-25 8:09 ` Srinivas Kandagatla
2026-09-25 8:34 ` David Heidelberg
2026-09-25 14:30 ` David Heidelberg
2026-09-24 13:24 ` [PATCH v4 8/8] arm64: dts: qcom: sdm845-google: Add WCD9340 codec and microphone capture David Heidelberg via B4 Relay
2026-09-24 14:11 ` [PATCH v4 0/8] Speakers for Pixel 3 / 3 XL Mark Brown
2026-09-24 14:13 ` David Heidelberg
2026-09-25 11:18 ` (subset) " Mark Brown
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924133615.19BB81F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=david@ixit.cz \
--cc=devicetree@vger.kernel.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox