Linux Sound subsystem development
 help / color / mirror / Atom feed
From: Takashi Iwai <tiwai@suse.de>
To: linux-sound@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: [PATCH 1/3] ALSA: hda: Stop unsol events and jack polling before codec unbind
Date: Wed,  7 Oct 2026 23:56:46 +0200	[thread overview]
Message-ID: <20261007215650.159871-2-tiwai@suse.de> (raw)
In-Reply-To: <20261007215650.159871-1-tiwai@suse.de>

At unbinding a codec driver, hda_codec_driver_remove() calls the
codec's remove callback that releases the driver resources, followed
by snd_hda_codec_cleanup_for_unbind().  Meanwhile, the unsolicited
events are processed asynchronously in bus->unsol_work, and
snd_hdac_bus_process_unsol_events() checks only codec->registered flag
before calling the driver's unsol_event callback without the lock.
Since codec->registered is cleared only in
snd_hda_codec_cleanup_for_unbind(), and there is no flush of the unsol
work at unbinding, the unsol event handler may run concurrently during
the running remove callback, which may lead to a UAF.  The same
problem applies to the jack polling work, which is canceled only after
the remove callback.

For addressing those races, introduce a new flag unsol_disabled to
hdac_device, to be checked it in the unsol event worker, while a new
helper snd_hdac_device_disable_unsol() sets this flag and flushes the
pending unsol work.  The helper is called at hda_codec_driver_remove()
together with the cancel of jackpoll_work to assure that no
asynchronous jack handling can run.  The flag is cleared again at
probing the codec driver, while the events are still blocked by the
registered flag until the codec gets registered.

Reported-by: Sashiko <sashiko-bot@kernel.org>
Assisted-by: LLM
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
 include/sound/hdaudio.h |  2 ++
 sound/hda/common/bind.c |  7 +++++++
 sound/hda/core/bus.c    | 21 ++++++++++++++++++++-
 3 files changed, 29 insertions(+), 1 deletion(-)

diff --git a/include/sound/hdaudio.h b/include/sound/hdaudio.h
index 4cbbb1744740..285f7c4d262d 100644
--- a/include/sound/hdaudio.h
+++ b/include/sound/hdaudio.h
@@ -97,6 +97,7 @@ struct hdac_device {
 	bool caps_overwriting:1; /* caps overwrite being in process */
 	bool cache_coef:1;	/* cache COEF read/write too */
 	unsigned int registered:1; /* codec was registered */
+	bool unsol_disabled;	/* unsol events blocked; protected by bus->reg_lock */
 };
 
 /* device/driver type used for matching */
@@ -123,6 +124,7 @@ int snd_hdac_device_init(struct hdac_device *dev, struct hdac_bus *bus,
 			 const char *name, unsigned int addr);
 void snd_hdac_device_exit(struct hdac_device *dev);
 int snd_hdac_device_register(struct hdac_device *codec);
+void snd_hdac_device_disable_unsol(struct hdac_device *codec);
 void snd_hdac_device_unregister(struct hdac_device *codec);
 int snd_hdac_device_set_chip_name(struct hdac_device *codec, const char *name);
 int snd_hdac_codec_modalias(const struct hdac_device *hdac, char *buf, size_t size);
diff --git a/sound/hda/common/bind.c b/sound/hda/common/bind.c
index 6a728a773556..4772ca154a29 100644
--- a/sound/hda/common/bind.c
+++ b/sound/hda/common/bind.c
@@ -100,6 +100,9 @@ static int hda_codec_driver_probe(struct device *dev)
 	if (WARN_ON(!codec->preset))
 		return -EINVAL;
 
+	/* unsol events are still blocked until registered */
+	codec->core.unsol_disabled = false;
+
 	err = snd_hda_codec_set_name(codec, codec->preset->name);
 	if (err < 0)
 		goto error;
@@ -160,6 +163,10 @@ static int hda_codec_driver_remove(struct device *dev)
 		return codec->bus->core.ext_ops->hdev_detach(&codec->core);
 	}
 
+	/* stop asynchronous jack handling before freeing driver resources */
+	snd_hdac_device_disable_unsol(&codec->core);
+	cancel_delayed_work_sync(&codec->jackpoll_work);
+
 	snd_hda_codec_disconnect_pcms(codec);
 	snd_hda_jack_tbl_disconnect(codec);
 	snd_refcount_sync(&codec->pcm_ref);
diff --git a/sound/hda/core/bus.c b/sound/hda/core/bus.c
index 20fe1c4a2977..8d4ed9834aaa 100644
--- a/sound/hda/core/bus.c
+++ b/sound/hda/core/bus.c
@@ -180,7 +180,7 @@ static void snd_hdac_bus_process_unsol_events(struct work_struct *work)
 		if (!(caddr & (1 << 4))) /* no unsolicited event? */
 			continue;
 		codec = bus->caddr_tbl[caddr & 0x0f];
-		if (!codec || !codec->registered)
+		if (!codec || !codec->registered || codec->unsol_disabled)
 			continue;
 		spin_unlock_irq(&bus->reg_lock);
 		drv = drv_to_hdac_driver(codec->dev.driver);
@@ -191,6 +191,25 @@ static void snd_hdac_bus_process_unsol_events(struct work_struct *work)
 	spin_unlock_irq(&bus->reg_lock);
 }
 
+/**
+ * snd_hdac_device_disable_unsol - block and flush unsol events for the codec
+ * @codec: the HDA core device
+ *
+ * Stop dispatching the unsolicited events to the given codec, and wait for
+ * the pending unsol event handler to finish.  Called at unbinding the codec
+ * driver before releasing the driver resources.
+ */
+void snd_hdac_device_disable_unsol(struct hdac_device *codec)
+{
+	struct hdac_bus *bus = codec->bus;
+
+	spin_lock_irq(&bus->reg_lock);
+	codec->unsol_disabled = true;
+	spin_unlock_irq(&bus->reg_lock);
+	flush_work(&bus->unsol_work);
+}
+EXPORT_SYMBOL_GPL(snd_hdac_device_disable_unsol);
+
 /**
  * snd_hdac_bus_add_device - Add a codec to bus
  * @bus: HDA core bus
-- 
2.55.0


  reply	other threads:[~2026-10-07 21:56 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07 21:56 [PATCH 0/3] ALSA/ASoC: hda: Fix race between unsol events and unbind Takashi Iwai
2026-10-07 21:56 ` Takashi Iwai [this message]
2026-10-08  9:08   ` [PATCH 1/3] ALSA: hda: Stop unsol events and jack polling before codec unbind Cezary Rojewski
2026-10-08 10:16     ` Takashi Iwai
2026-10-08 11:52       ` Cezary Rojewski
2026-10-08 12:01         ` Takashi Iwai
2026-10-07 21:56 ` [PATCH 2/3] ASoC: codecs: hda: Stop unsol events and jack polling before codec removal Takashi Iwai
2026-10-07 21:56 ` [PATCH 3/3] ALSA: hda: Make hdac_device.registered a plain bool Takashi Iwai
2026-10-09  7:44 ` [PATCH 0/3] ALSA/ASoC: hda: Fix race between unsol events and unbind Cezary Rojewski

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261007215650.159871-2-tiwai@suse.de \
    --to=tiwai@suse.de \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-sound@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox