Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "James Calligeros" <jcalligeros99@gmail.com>
Cc: robh@kernel.org, devicetree@vger.kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v2 07/21] ASoC: ops: Introduce 'soc_set_enum_kctl'
Date: Sun, 04 Oct 2026 06:22:18 +0000	[thread overview]
Message-ID: <20261004062219.014BD1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261004-macaudio-v2-7-7b47ed6335a8@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] ASoC: snd_soc_set_enum_kctl passes uninitialized control ID to callbacks
- [Low] ASoC: soc_set_enum_kctl allocates massive ALSA structures on kernel stack
--

commit e3f835f860aa8d0eaf39868ba9b6ebbdc3975a2c
Author: Martin Povišer <povik+lin@cutebit.org>

ASoC: ops: Introduce 'soc_set_enum_kctl'

The new function is to be used to set enumerated controls to desired
values. It is something a machine driver may call in fixup_controls.

> diff --git a/sound/soc/soc-ops.c b/sound/soc/soc-ops.c
> index 4d799c5e44f1b..b1eb74e241932 100644
> --- a/sound/soc/soc-ops.c
> +++ b/sound/soc/soc-ops.c

[ ... ]

> @@ -505,6 +505,75 @@ int snd_soc_deactivate_kctl(struct snd_soc_card *card,
>  }
>  EXPORT_SYMBOL_GPL(snd_soc_deactivate_kctl);
>  
> +static int soc_set_enum_kctl(struct snd_kcontrol *kctl, const char *value)
> +{
> +	struct snd_ctl_elem_value evalue = { 0 };
> +	struct snd_ctl_elem_info info = { 0 };

[Severity: Low]
Are these ALSA structures too large to be allocated on the stack here?

struct snd_ctl_elem_value is typically around 1220 bytes on 64-bit
architectures since it contains unions with large fixed-size arrays. With
struct snd_ctl_elem_info adding another 272 bytes, allocating both on the
stack consumes approximately 1.5 KB of stack space.

Could this exceed the 1024-byte FRAME_WARN threshold on some architectures
and increase the risk of a kernel stack overflow?

The ALSA core usually relies on heap allocation for these large structures
to avoid exhausting the stack.

> +	int sel, i, ret;
> +
> +	ret = kctl->info(kctl, &info);
> +	if (ret < 0)
> +		return ret;

[ ... ]

> +	for (i = 0; i < info.count; i++)
> +		evalue.value.enumerated.item[i] = sel;
> +
> +	if (kctl->put)
> +		return kctl->put(kctl, &evalue);

[Severity: High]
Does this pass an uninitialized control ID to the put callback?

The evalue and info structures are zero-initialized above, which leaves
their id fields completely empty. The kctl->id is never copied into them
before being passed to kctl->info() or kctl->put().

The core ALSA API guarantees that ucontrol->id is fully populated before
invoking control callbacks. Some drivers rely on this contract. For example,
rt700_mux_put() uses the control name to identify which specific control
is being accessed:

sound/soc/codecs/rt700.c:rt700_mux_put() {
    ...
    if (strstr(ucontrol->id.name, "HPO Mux"))
        ...
}

Because evalue.id.name is an empty string here, will such callbacks fail
or execute incorrect logic?

> +	else
> +		return -EINVAL;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261004-macaudio-v2-0-7b47ed6335a8@gmail.com?part=7

  reply	other threads:[~2026-10-04  6:22 UTC|newest]

Thread overview: 49+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-04  6:03 [PATCH v2 00/21] Add speaker and headset jack support for Apple Silicon Macs James Calligeros
2026-10-04  6:03 ` [PATCH v2 01/21] ASoC: dt-bindings: cs42l84: Document sound-name-prefix property James Calligeros
2026-10-09  7:09   ` Krzysztof Kozlowski
2026-10-04  6:03 ` [PATCH v2 02/21] ASoC: dt-bindings: cs42l42: Do not require chip power supplies James Calligeros
2026-10-09  7:10   ` Krzysztof Kozlowski
2026-10-04  6:03 ` [PATCH v2 03/21] ASoC: dt-bindings: cs42l42: Document #sound-dai-cells property James Calligeros
2026-10-09  7:10   ` Krzysztof Kozlowski
2026-10-04  6:03 ` [PATCH v2 04/21] ASoC: dt-bindings: cs42l42: Document sound-name-prefix property James Calligeros
2026-10-09  7:11   ` Krzysztof Kozlowski
2026-10-04  6:03 ` [PATCH v2 05/21] ASoC: dt-bindings: Add binding for Apple Silicon Mac audio James Calligeros
2026-10-04  6:15   ` sashiko-bot
2026-10-09  7:17   ` Krzysztof Kozlowski
2026-10-09  7:21     ` James Calligeros
2026-10-09  7:29       ` Krzysztof Kozlowski
2026-10-04  6:03 ` [PATCH v2 06/21] ASoC: ops: Introduce 'snd_soc_deactivate_kctl' James Calligeros
2026-10-09  8:16   ` Cezary Rojewski
2026-10-04  6:03 ` [PATCH v2 07/21] ASoC: ops: Introduce 'soc_set_enum_kctl' James Calligeros
2026-10-04  6:22   ` sashiko-bot [this message]
2026-10-07 17:36   ` Ajay Kumar Nandam
2026-10-09  8:27   ` Cezary Rojewski
2026-10-04  6:03 ` [PATCH v2 08/21] ASoC: card: Let 'fixup_controls' return errors James Calligeros
2026-10-07 14:23   ` Charles Keepax
2026-10-04  6:03 ` [PATCH v2 09/21] ASoC: apple: Add macaudio machine driver James Calligeros
2026-10-04  6:24   ` sashiko-bot
2026-10-07 18:04   ` Ajay Kumar Nandam
2026-10-04  6:03 ` [PATCH v2 10/21] arm64: dts: apple: t8103-j274: Add speaker/headset jack nodes James Calligeros
2026-10-04  6:17   ` sashiko-bot
2026-10-07 18:17   ` Ajay Kumar Nandam
2026-10-04  6:03 ` [PATCH v2 11/21] arm64: dts: apple: t8103-j313: " James Calligeros
2026-10-04  6:19   ` sashiko-bot
2026-10-07 18:32   ` Ajay Kumar Nandam
2026-10-08  8:46     ` James Calligeros
2026-10-08  9:34       ` Ajay Kumar Nandam
2026-10-04  6:03 ` [PATCH v2 12/21] arm64: dts: apple: t8103-j293: " James Calligeros
2026-10-04  6:25   ` sashiko-bot
2026-10-04  6:03 ` [PATCH v2 13/21] arm64: dts: apple: t8103-j45x: Add headset " James Calligeros
2026-10-04  6:21   ` sashiko-bot
2026-10-08  6:18   ` Ajay Kumar Nandam
2026-10-04  6:03 ` [PATCH v2 14/21] arm64: dts: apple: t8112-j413: Add speaker/headset " James Calligeros
2026-10-04  6:03 ` [PATCH v2 15/21] arm64: dts: apple: t8112-j415: " James Calligeros
2026-10-04  6:21   ` sashiko-bot
2026-10-04  6:03 ` [PATCH v2 16/21] arm64: dts: apple: t8112-j473: " James Calligeros
2026-10-04  6:03 ` [PATCH v2 17/21] arm64: dts: apple: t8112-j493: " James Calligeros
2026-10-04  6:03 ` [PATCH v2 18/21] arm64: dts: apple: t600x-j31x: " James Calligeros
2026-10-04  6:24   ` sashiko-bot
2026-10-04  6:03 ` [PATCH v2 19/21] arm64: dts: apple: t600x-j375: " James Calligeros
2026-10-04  6:03 ` [PATCH v2 20/21] arm64: dts: apple: t602x-j41x: " James Calligeros
2026-10-04  6:03 ` [PATCH v2 21/21] arm64: dts: apple: t602x-j47x: " James Calligeros
2026-10-08  9:29   ` Ajay Kumar Nandam

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261004062219.014BD1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=jcalligeros99@gmail.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox