From: sashiko-bot@kernel.org
To: "Mikhail Gavrilov" <mikhail.v.gavrilov@gmail.com>
Cc: linux-input@vger.kernel.org, dmitry.torokhov@gmail.com
Subject: Re: [PATCH v4 2/2] ALSA: usb-audio: let the M62's outputs say what they listen to
Date: Sun, 23 Aug 2026 22:46:49 +0000 [thread overview]
Message-ID: <20260823224649.E45331F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260823222946.171345-3-mikhail.v.gavrilov@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Concurrent ALSA control access during USB disconnect causes a Use-After-Free or NULL pointer dereference in the get/put handlers.
--
--- Patch [2]: [PATCH v4 2/2] ALSA: usb-audio: let the M62's outputs say what they listen to ---
commit 4881f3c183895a107d4e643799ad16e76377b10a
Author: Mikhail Gavrilov <mikhail.v.gavrilov@gmail.com>
ALSA: usb-audio: let the M62's outputs say what they listen to
This commit adds enumerated controls for the Topping M62 mixer outputs to
select their playback source. It handles the specific hardware behaviour
where the current selection cannot be queried from the device.
> diff --git a/sound/usb/mixer_topping.c b/sound/usb/mixer_topping.c
> index 2f2365b9b4762..e71ea70ec4b00 100644
> --- a/sound/usb/mixer_topping.c
> +++ b/sound/usb/mixer_topping.c
[ ... ]
> @@ -332,6 +372,66 @@ static int topping_ctl_put(struct snd_kcontrol *kctl,
> return 1;
> }
>
> +static int topping_sel_info(struct snd_kcontrol *kctl,
> + struct snd_ctl_elem_info *uinfo)
> +{
> + return snd_ctl_enum_info(uinfo, 1, ARRAY_SIZE(topping_sources),
> + topping_sources);
> +}
> +
> +static int topping_sel_get(struct snd_kcontrol *kctl,
> + struct snd_ctl_elem_value *ucontrol)
> +{
> + struct usb_mixer_elem_info *elem = kctl->private_data;
> + struct topping_mixer *tm = elem->head.mixer->private_data;
> +
> + guard(mutex)(&tm->write_lock);
[Severity: High]
This is a pre-existing issue, but does this dereference of tm risk a
use-after-free or NULL pointer dereference if the USB device is disconnected
concurrently?
If an ALSA control ioctl is executing while the USB device is disconnected,
the disconnect sequence calls usb_audio_disconnect_components() which calls
snd_usb_mixer_disconnect(). This triggers topping_private_free() which
frees the tm struct and sets mixer->private_data to NULL.
If the control callback executes without first calling
snd_usb_lock_shutdown() to check for device disconnection, it can extract
and dereference tm (e.g., locking tm->write_lock here) either after it has
been freed or while it is NULL.
> + ucontrol->value.enumerated.item[0] = tm->sel[elem->control];
> + return 0;
> +}
> +
> +static int topping_sel_put(struct snd_kcontrol *kctl,
> + struct snd_ctl_elem_value *ucontrol)
> +{
> + struct usb_mixer_elem_info *elem = kctl->private_data;
> + struct topping_mixer *tm = elem->head.mixer->private_data;
> + const struct topping_enum_desc *d;
> + unsigned int item;
> + int err;
> +
> + item = ucontrol->value.enumerated.item[0];
> + if (item >= ARRAY_SIZE(topping_sources))
> + return -EINVAL;
> +
> + guard(mutex)(&tm->write_lock);
[Severity: High]
This is a pre-existing issue, but could this also trigger a use-after-free
or NULL pointer dereference for the same reasons as in topping_sel_get()?
As this issue is also present in the pre-existing topping_ctl_put() and
topping_ctl_get(), perhaps snd_usb_lock_shutdown() needs to be used to
safeguard these control callbacks against concurrent USB teardown.
> +
> + /*
> + * "Unknown" is what this control reports until a hand has chosen,
> + * and alsactl stores and restores it like any other value. It is
> + * not a choice, so writing it changes nothing -- quietly, rather
> + * than failing a restore of the driver's own report.
> + */
> + if (!item || tm->sel[elem->control] == item)
> + return 0;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260823222946.171345-1-mikhail.v.gavrilov@gmail.com?part=2
next prev parent reply other threads:[~2026-08-23 22:46 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-12 17:10 snd-usb-audio: exposing a vendor HID control channel as mixer controls (Topping M62, 152a:875c) Mikhail Gavrilov
2026-08-13 7:24 ` Takashi Iwai
2026-08-20 15:13 ` [RFC 0/2] Two ways to reach the Topping M62's analogue gains Mikhail Gavrilov
2026-08-20 15:13 ` [RFC 1/2] ALSA: usb-audio: expose the Topping M62's analogue gains as mixer controls Mikhail Gavrilov
2026-08-20 15:13 ` [RFC 2/2] HID: topping: driver for the M62's vendor control channel Mikhail Gavrilov
2026-08-21 11:23 ` [RFC 0/2] Two ways to reach the Topping M62's analogue gains Mikhail Gavrilov
2026-08-23 8:50 ` Takashi Iwai
2026-08-23 14:22 ` [PATCH v2 0/2] ALSA: usb-audio: the Topping M62's vendor controls Mikhail Gavrilov
2026-08-23 14:22 ` [PATCH v2 1/2] ALSA: usb-audio: expose the Topping M62's analogue gains as mixer controls Mikhail Gavrilov
2026-08-23 14:38 ` sashiko-bot
2026-08-23 14:22 ` [PATCH v2 2/2] ALSA: usb-audio: let the M62's outputs say what they listen to Mikhail Gavrilov
2026-08-23 14:38 ` sashiko-bot
2026-08-23 19:48 ` [PATCH v3 0/2] ALSA: usb-audio: the Topping M62's vendor controls Mikhail Gavrilov
2026-08-23 19:48 ` [PATCH v3 1/2] ALSA: usb-audio: expose the Topping M62's analogue gains as mixer controls Mikhail Gavrilov
2026-08-23 20:07 ` sashiko-bot
2026-08-23 19:48 ` [PATCH v3 2/2] ALSA: usb-audio: let the M62's outputs say what they listen to Mikhail Gavrilov
2026-08-23 20:03 ` sashiko-bot
2026-08-23 22:29 ` [PATCH v4 0/2] ALSA: usb-audio: the Topping M62's vendor controls Mikhail Gavrilov
2026-08-23 22:29 ` [PATCH v4 1/2] ALSA: usb-audio: expose the Topping M62's analogue gains as mixer controls Mikhail Gavrilov
2026-08-23 22:46 ` sashiko-bot
2026-08-23 22:29 ` [PATCH v4 2/2] ALSA: usb-audio: let the M62's outputs say what they listen to Mikhail Gavrilov
2026-08-23 22:46 ` sashiko-bot [this message]
2026-08-24 20:13 ` [PATCH v5 0/2] ALSA: usb-audio: the Topping M62's vendor controls Mikhail Gavrilov
2026-08-24 20:13 ` [PATCH v5 1/2] ALSA: usb-audio: expose the Topping M62's analogue gains as mixer controls Mikhail Gavrilov
2026-08-24 20:40 ` sashiko-bot
2026-08-24 20:13 ` [PATCH v5 2/2] ALSA: usb-audio: let the M62's outputs say what they listen to Mikhail Gavrilov
2026-08-24 20:25 ` sashiko-bot
2026-08-24 22:31 ` [PATCH v6 0/2] ALSA: usb-audio: the Topping M62's vendor controls Mikhail Gavrilov
2026-08-24 22:31 ` [PATCH v6 1/2] ALSA: usb-audio: expose the Topping M62's analogue gains as mixer controls Mikhail Gavrilov
2026-08-24 22:47 ` sashiko-bot
2026-08-24 22:31 ` [PATCH v6 2/2] ALSA: usb-audio: let the M62's outputs say what they listen to Mikhail Gavrilov
2026-08-24 22:58 ` sashiko-bot
2026-08-25 8:56 ` [PATCH v7 0/2] ALSA: usb-audio: the Topping M62's vendor controls Mikhail Gavrilov
2026-08-25 8:56 ` [PATCH v7 1/2] ALSA: usb-audio: expose the Topping M62's analogue gains as mixer controls Mikhail Gavrilov
2026-08-25 9:12 ` sashiko-bot
2026-08-25 8:56 ` [PATCH v7 2/2] ALSA: usb-audio: let the M62's outputs say what they listen to Mikhail Gavrilov
2026-08-25 11:12 ` [PATCH v8 0/2] ALSA: usb-audio: the Topping M62's vendor controls Mikhail Gavrilov
2026-08-25 11:12 ` [PATCH v8 1/2] ALSA: usb-audio: expose the Topping M62's analogue gains as mixer controls Mikhail Gavrilov
2026-08-25 11:12 ` [PATCH v8 2/2] ALSA: usb-audio: let the M62's outputs say what they listen to Mikhail Gavrilov
2026-08-26 18:06 ` [PATCH v8 0/2] ALSA: usb-audio: the Topping M62's vendor controls Mikhail Gavrilov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260823224649.E45331F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dmitry.torokhov@gmail.com \
--cc=linux-input@vger.kernel.org \
--cc=mikhail.v.gavrilov@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox