From: sashiko-bot@kernel.org
To: "James Calligeros" <jcalligeros99@gmail.com>
Cc: robh@kernel.org, devicetree@vger.kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v2 07/21] ASoC: ops: Introduce 'soc_set_enum_kctl'
Date: Sun, 04 Oct 2026 06:22:18 +0000 [thread overview]
Message-ID: <20261004062219.014BD1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261004-macaudio-v2-7-7b47ed6335a8@gmail.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] ASoC: snd_soc_set_enum_kctl passes uninitialized control ID to callbacks
- [Low] ASoC: soc_set_enum_kctl allocates massive ALSA structures on kernel stack
--
commit e3f835f860aa8d0eaf39868ba9b6ebbdc3975a2c
Author: Martin Povišer <povik+lin@cutebit.org>
ASoC: ops: Introduce 'soc_set_enum_kctl'
The new function is to be used to set enumerated controls to desired
values. It is something a machine driver may call in fixup_controls.
> diff --git a/sound/soc/soc-ops.c b/sound/soc/soc-ops.c
> index 4d799c5e44f1b..b1eb74e241932 100644
> --- a/sound/soc/soc-ops.c
> +++ b/sound/soc/soc-ops.c
[ ... ]
> @@ -505,6 +505,75 @@ int snd_soc_deactivate_kctl(struct snd_soc_card *card,
> }
> EXPORT_SYMBOL_GPL(snd_soc_deactivate_kctl);
>
> +static int soc_set_enum_kctl(struct snd_kcontrol *kctl, const char *value)
> +{
> + struct snd_ctl_elem_value evalue = { 0 };
> + struct snd_ctl_elem_info info = { 0 };
[Severity: Low]
Are these ALSA structures too large to be allocated on the stack here?
struct snd_ctl_elem_value is typically around 1220 bytes on 64-bit
architectures since it contains unions with large fixed-size arrays. With
struct snd_ctl_elem_info adding another 272 bytes, allocating both on the
stack consumes approximately 1.5 KB of stack space.
Could this exceed the 1024-byte FRAME_WARN threshold on some architectures
and increase the risk of a kernel stack overflow?
The ALSA core usually relies on heap allocation for these large structures
to avoid exhausting the stack.
> + int sel, i, ret;
> +
> + ret = kctl->info(kctl, &info);
> + if (ret < 0)
> + return ret;
[ ... ]
> + for (i = 0; i < info.count; i++)
> + evalue.value.enumerated.item[i] = sel;
> +
> + if (kctl->put)
> + return kctl->put(kctl, &evalue);
[Severity: High]
Does this pass an uninitialized control ID to the put callback?
The evalue and info structures are zero-initialized above, which leaves
their id fields completely empty. The kctl->id is never copied into them
before being passed to kctl->info() or kctl->put().
The core ALSA API guarantees that ucontrol->id is fully populated before
invoking control callbacks. Some drivers rely on this contract. For example,
rt700_mux_put() uses the control name to identify which specific control
is being accessed:
sound/soc/codecs/rt700.c:rt700_mux_put() {
...
if (strstr(ucontrol->id.name, "HPO Mux"))
...
}
Because evalue.id.name is an empty string here, will such callbacks fail
or execute incorrect logic?
> + else
> + return -EINVAL;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261004-macaudio-v2-0-7b47ed6335a8@gmail.com?part=7
next prev parent reply other threads:[~2026-10-04 6:22 UTC|newest]
Thread overview: 49+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-04 6:03 [PATCH v2 00/21] Add speaker and headset jack support for Apple Silicon Macs James Calligeros
2026-10-04 6:03 ` [PATCH v2 01/21] ASoC: dt-bindings: cs42l84: Document sound-name-prefix property James Calligeros
2026-10-09 7:09 ` Krzysztof Kozlowski
2026-10-04 6:03 ` [PATCH v2 02/21] ASoC: dt-bindings: cs42l42: Do not require chip power supplies James Calligeros
2026-10-09 7:10 ` Krzysztof Kozlowski
2026-10-04 6:03 ` [PATCH v2 03/21] ASoC: dt-bindings: cs42l42: Document #sound-dai-cells property James Calligeros
2026-10-09 7:10 ` Krzysztof Kozlowski
2026-10-04 6:03 ` [PATCH v2 04/21] ASoC: dt-bindings: cs42l42: Document sound-name-prefix property James Calligeros
2026-10-09 7:11 ` Krzysztof Kozlowski
2026-10-04 6:03 ` [PATCH v2 05/21] ASoC: dt-bindings: Add binding for Apple Silicon Mac audio James Calligeros
2026-10-04 6:15 ` sashiko-bot
2026-10-09 7:17 ` Krzysztof Kozlowski
2026-10-09 7:21 ` James Calligeros
2026-10-09 7:29 ` Krzysztof Kozlowski
2026-10-04 6:03 ` [PATCH v2 06/21] ASoC: ops: Introduce 'snd_soc_deactivate_kctl' James Calligeros
2026-10-09 8:16 ` Cezary Rojewski
2026-10-04 6:03 ` [PATCH v2 07/21] ASoC: ops: Introduce 'soc_set_enum_kctl' James Calligeros
2026-10-04 6:22 ` sashiko-bot [this message]
2026-10-07 17:36 ` Ajay Kumar Nandam
2026-10-09 8:27 ` Cezary Rojewski
2026-10-04 6:03 ` [PATCH v2 08/21] ASoC: card: Let 'fixup_controls' return errors James Calligeros
2026-10-07 14:23 ` Charles Keepax
2026-10-04 6:03 ` [PATCH v2 09/21] ASoC: apple: Add macaudio machine driver James Calligeros
2026-10-04 6:24 ` sashiko-bot
2026-10-07 18:04 ` Ajay Kumar Nandam
2026-10-04 6:03 ` [PATCH v2 10/21] arm64: dts: apple: t8103-j274: Add speaker/headset jack nodes James Calligeros
2026-10-04 6:17 ` sashiko-bot
2026-10-07 18:17 ` Ajay Kumar Nandam
2026-10-04 6:03 ` [PATCH v2 11/21] arm64: dts: apple: t8103-j313: " James Calligeros
2026-10-04 6:19 ` sashiko-bot
2026-10-07 18:32 ` Ajay Kumar Nandam
2026-10-08 8:46 ` James Calligeros
2026-10-08 9:34 ` Ajay Kumar Nandam
2026-10-04 6:03 ` [PATCH v2 12/21] arm64: dts: apple: t8103-j293: " James Calligeros
2026-10-04 6:25 ` sashiko-bot
2026-10-04 6:03 ` [PATCH v2 13/21] arm64: dts: apple: t8103-j45x: Add headset " James Calligeros
2026-10-04 6:21 ` sashiko-bot
2026-10-08 6:18 ` Ajay Kumar Nandam
2026-10-04 6:03 ` [PATCH v2 14/21] arm64: dts: apple: t8112-j413: Add speaker/headset " James Calligeros
2026-10-04 6:03 ` [PATCH v2 15/21] arm64: dts: apple: t8112-j415: " James Calligeros
2026-10-04 6:21 ` sashiko-bot
2026-10-04 6:03 ` [PATCH v2 16/21] arm64: dts: apple: t8112-j473: " James Calligeros
2026-10-04 6:03 ` [PATCH v2 17/21] arm64: dts: apple: t8112-j493: " James Calligeros
2026-10-04 6:03 ` [PATCH v2 18/21] arm64: dts: apple: t600x-j31x: " James Calligeros
2026-10-04 6:24 ` sashiko-bot
2026-10-04 6:03 ` [PATCH v2 19/21] arm64: dts: apple: t600x-j375: " James Calligeros
2026-10-04 6:03 ` [PATCH v2 20/21] arm64: dts: apple: t602x-j41x: " James Calligeros
2026-10-04 6:03 ` [PATCH v2 21/21] arm64: dts: apple: t602x-j47x: " James Calligeros
2026-10-08 9:29 ` Ajay Kumar Nandam
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261004062219.014BD1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=jcalligeros99@gmail.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox