Linux Sound subsystem development
 help / color / mirror / Atom feed
From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
To: vkoul@kernel.org, perex@perex.cz, tiwai@suse.com,
	lgirdwood@gmail.com, broonie@kernel.org,
	srinivas.kandagatla@oss.qualcomm.com
Cc: linux-sound@vger.kernel.org, kai.vehmanen@linux.intel.com,
	yung-chuan.liao@linux.intel.com, pierre-louis.bossart@linux.dev,
	daniel.baluta@nxp.com
Subject: [PATCH v5 12/28] ASoC: SOF: sof-audio: do not dereference swidget->spipe unconditionally on free
Date: Wed,  7 Oct 2026 11:49:39 +0300	[thread overview]
Message-ID: <20261007084955.1256-13-peter.ujfalusi@linux.intel.com> (raw)
In-Reply-To: <20261007084955.1256-1-peter.ujfalusi@linux.intel.com>

sof_widget_free_unlocked() dereferences swidget->spipe without checking
it for two things: swidget->spipe->complete for a scheduler widget, and
swidget->spipe->pipe_widget for the recursive free of the pipeline's
scheduler widget. Both can be reached with spipe or pipe_widget not
set, which oopses in the free path - where there is nothing left to
bail out to.

Check both before use and cache swidget->spipe in the local spipe
variable that is already there. A widget with no pipeline has nothing
to put or complete, and no scheduler widget to free, so skipping is the
correct behaviour.

No functional change for a widget that was successfully set up:
sof_widget_setup_unlocked() already rejects a dynamic pipeline widget
with no spipe or no spipe->pipe_widget with -EINVAL.

Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Reviewed-by: Liam Girdwood <liam.r.girdwood@intel.com>
---
 sound/soc/sof/sof-audio.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/sound/soc/sof/sof-audio.c b/sound/soc/sof/sof-audio.c
index 850eb2bc2b44..9f9f18b3c935 100644
--- a/sound/soc/sof/sof-audio.c
+++ b/sound/soc/sof/sof-audio.c
@@ -103,7 +103,7 @@ static int sof_widget_free_unlocked(struct snd_sof_dev *sdev,
 	 * decrement ref count for cores associated with all modules in the pipeline and clear
 	 * the complete flag
 	 */
-	if (swidget->id == snd_soc_dapm_scheduler) {
+	if (swidget->id == snd_soc_dapm_scheduler && spipe) {
 		int i;
 
 		for_each_set_bit(i, &spipe->core_mask, sdev->num_cores) {
@@ -115,16 +115,16 @@ static int sof_widget_free_unlocked(struct snd_sof_dev *sdev,
 					err = ret;
 			}
 		}
-		swidget->spipe->complete = 0;
+		spipe->complete = 0;
 	}
 
 	/*
 	 * free the scheduler widget (same as pipe_widget) associated with the current swidget.
 	 * skip for static pipelines
 	 */
-	if (swidget->spipe && swidget->dynamic_pipeline_widget &&
+	if (spipe && spipe->pipe_widget && swidget->dynamic_pipeline_widget &&
 	    swidget->id != snd_soc_dapm_scheduler) {
-		ret = sof_widget_free_unlocked(sdev, swidget->spipe->pipe_widget);
+		ret = sof_widget_free_unlocked(sdev, spipe->pipe_widget);
 		if (ret < 0 && !err)
 			err = ret;
 	}
-- 
2.56.0


  parent reply	other threads:[~2026-10-07  8:50 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07  8:49 [PATCH v5 00/28] ALSA compress / ASoC compress / SOF: Compressed audio support with IPC4 Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 01/28] ALSA: compress: pin card module while stream is open Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 02/28] ALSA: compress: register the open file with the card Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 03/28] ALSA: compress: stop active streams on disconnect Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 04/28] ALSA: compress: Set the draining state before the drain trigger Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 05/28] ASoC: soc-compress: Provide a runtime for the compressed FE substream Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 06/28] ASoC: soc-compress: Implement trigger FE-BE sequencing as with normal PCMs Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 07/28] ASoC: soc-compress: Stop running dpcm on free Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 08/28] ASoC: SOF: compress: Move the IPC agnostic helpers to sof-audio.c Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 09/28] ASoC: SOF: compress: Rename compress ops with ipc3 prefix Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 10/28] ASoC: SOF: sof-audio: Fix the pipeline_list population Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 11/28] ASoC: SOF: ipc4-pcm: Serialize the PCM free with the pipeline triggers Peter Ujfalusi
2026-10-07  8:49 ` Peter Ujfalusi [this message]
2026-10-07  8:49 ` [PATCH v5 13/28] ASoC: SOF: sof-audio: Expose a couple of functions Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 14/28] ASoC: SOF: pcm: Modify the signature of a couple of PCM IPC ops Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 15/28] ASoC: SOF: intel: hda-stream: Clear the current position when releasing stream Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 16/28] ASoC: SOF: ipc4: Add definition of module data in init_ext object type Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 17/28] ASoC: SOF: ipc4-topology: Support init_ext_module_data for process modules Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 18/28] ASoC: SOF: ipc4-pcm: Make the timestamp info usable outside of ipc4-pcm.c Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 19/28] ASoC: SOF: ipc4/ipc4-loader: Add SOF_INFO and CODEC_INFO to fw_config_params Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 20/28] ASoC: SOF: ipc4-pcm: Handle COMPR DRAIN triggers as EOS pipeline state Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 21/28] ASoC: SOF: ipc4-topology: Set FAST_MODE for host copier in compr mode Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 22/28] ASoC: SOF: ops: Add new platform-specific ops for compress Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 23/28] ASoC: SOF: Check that the audio buffer fits into the page table Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 24/28] ASoC: SOF: Add support for IPC4 compressed Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 25/28] ASoC: SOF: ipc4: Handle compressed drain done notification from firmware Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 26/28] ASoC: SOF: Intel: Kconfig: Remove redundant IPC version selects Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 27/28] ASoC: SOF: Intel: Kconfig: Select compress support for TGL+ platforms Peter Ujfalusi
2026-10-07  8:49 ` [PATCH v5 28/28] ASoC: SOF: topology: Add support for decoder and encoder widgets Peter Ujfalusi
2026-10-07 11:17 ` [PATCH v5 00/28] ALSA compress / ASoC compress / SOF: Compressed audio support with IPC4 Mark Brown

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261007084955.1256-13-peter.ujfalusi@linux.intel.com \
    --to=peter.ujfalusi@linux.intel.com \
    --cc=broonie@kernel.org \
    --cc=daniel.baluta@nxp.com \
    --cc=kai.vehmanen@linux.intel.com \
    --cc=lgirdwood@gmail.com \
    --cc=linux-sound@vger.kernel.org \
    --cc=perex@perex.cz \
    --cc=pierre-louis.bossart@linux.dev \
    --cc=srinivas.kandagatla@oss.qualcomm.com \
    --cc=tiwai@suse.com \
    --cc=vkoul@kernel.org \
    --cc=yung-chuan.liao@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox