From: Takashi Iwai <tiwai@suse.de>
To: linux-sound@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: [PATCH 07/11] ALSA: usb: us16x08: Fix racy accesses of mixer elements
Date: Thu, 8 Oct 2026 21:25:47 +0200 [thread overview]
Message-ID: <20261008192553.300025-8-tiwai@suse.de> (raw)
In-Reply-To: <20261008192553.300025-1-tiwai@suse.de>
All get and put callbacks for us16x08 mixer have no proper protection,
hence the concurrent accesses to multiple elements may face data
races, resulting in unexpected values.
Put the new mixer->lock mutex for protecting the concurrent accesses.
Fixes: d2bb390a2081 ("ALSA: usb-audio: Tascam US-16x08 DSP mixer quirk")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Takashi Iwai <tiwai@suse.de>
---
sound/usb/mixer_us16x08.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)
diff --git a/sound/usb/mixer_us16x08.c b/sound/usb/mixer_us16x08.c
index 8e5ccd3282a7..b447c4f7a161 100644
--- a/sound/usb/mixer_us16x08.c
+++ b/sound/usb/mixer_us16x08.c
@@ -189,6 +189,7 @@ static int snd_us16x08_route_get(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *elem = snd_kcontrol_chip(kcontrol);
int index = ucontrol->id.index;
+ guard(mutex)(&elem->head.mixer->lock);
/* route has no bias */
ucontrol->value.enumerated.item[0] = elem->cache_val[index];
@@ -204,6 +205,7 @@ static int snd_us16x08_route_put(struct snd_kcontrol *kcontrol,
char buf[sizeof(route_msg)];
int val, val_org, err;
+ guard(mutex)(&elem->head.mixer->lock);
/* get the new value (no bias for routes) */
val = ucontrol->value.enumerated.item[0];
@@ -258,6 +260,7 @@ static int snd_us16x08_master_get(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *elem = snd_kcontrol_chip(kcontrol);
int index = ucontrol->id.index;
+ guard(mutex)(&elem->head.mixer->lock);
ucontrol->value.integer.value[0] = elem->cache_val[index];
return 0;
@@ -272,6 +275,7 @@ static int snd_us16x08_master_put(struct snd_kcontrol *kcontrol,
int val, err;
int index = ucontrol->id.index;
+ guard(mutex)(&elem->head.mixer->lock);
/* new control value incl. bias*/
val = ucontrol->value.integer.value[0];
@@ -310,6 +314,7 @@ static int snd_us16x08_bus_put(struct snd_kcontrol *kcontrol,
val = ucontrol->value.integer.value[0];
+ guard(mutex)(&elem->head.mixer->lock);
/* prepare the message buffer from template */
switch (elem->head.id) {
case SND_US16X08_ID_BYPASS:
@@ -346,6 +351,7 @@ static int snd_us16x08_bus_get(struct snd_kcontrol *kcontrol,
{
struct usb_mixer_elem_info *elem = snd_kcontrol_chip(kcontrol);
+ guard(mutex)(&elem->head.mixer->lock);
switch (elem->head.id) {
case SND_US16X08_ID_BUSS_OUT:
ucontrol->value.integer.value[0] = elem->cache_val[0];
@@ -368,6 +374,7 @@ static int snd_us16x08_channel_get(struct snd_kcontrol *kcontrol,
struct usb_mixer_elem_info *elem = snd_kcontrol_chip(kcontrol);
int index = ucontrol->id.index;
+ guard(mutex)(&elem->head.mixer->lock);
ucontrol->value.integer.value[0] = elem->cache_val[index];
return 0;
@@ -382,6 +389,7 @@ static int snd_us16x08_channel_put(struct snd_kcontrol *kcontrol,
int val, err;
int index = ucontrol->id.index;
+ guard(mutex)(&elem->head.mixer->lock);
val = ucontrol->value.integer.value[0];
/* sanity check */
@@ -428,6 +436,7 @@ static int snd_us16x08_comp_get(struct snd_kcontrol *kcontrol,
int index = ucontrol->id.index;
int val_idx = COMP_STORE_IDX(elem->head.id);
+ guard(mutex)(&elem->head.mixer->lock);
ucontrol->value.integer.value[0] = store->val[val_idx][index];
return 0;
@@ -445,6 +454,7 @@ static int snd_us16x08_comp_put(struct snd_kcontrol *kcontrol,
int threshold, ratio, attack, release, gain, switch_on;
int err;
+ guard(mutex)(&elem->head.mixer->lock);
val = ucontrol->value.integer.value[0];
/* sanity check */
@@ -521,6 +531,7 @@ static int snd_us16x08_eqswitch_get(struct snd_kcontrol *kcontrol,
struct snd_us16x08_eq_store *store = elem->private_data;
int index = ucontrol->id.index;
+ guard(mutex)(&elem->head.mixer->lock);
/* get low switch from cache is enough, cause all bands are together */
val = store->val[EQ_STORE_BAND_IDX(elem->head.id)]
[EQ_STORE_PARAM_IDX(elem->head.id)][index];
@@ -540,6 +551,7 @@ static int snd_us16x08_eqswitch_put(struct snd_kcontrol *kcontrol,
int val, err = 0;
int b_idx;
+ guard(mutex)(&elem->head.mixer->lock);
/* new control value incl. bias*/
val = ucontrol->value.integer.value[0] + SND_US16X08_KCBIAS(kcontrol);
@@ -582,6 +594,7 @@ static int snd_us16x08_eq_get(struct snd_kcontrol *kcontrol,
int b_idx = EQ_STORE_BAND_IDX(elem->head.id) - 1;
int p_idx = EQ_STORE_PARAM_IDX(elem->head.id);
+ guard(mutex)(&elem->head.mixer->lock);
val = store->val[b_idx][p_idx][index];
ucontrol->value.integer.value[0] = val;
@@ -601,6 +614,7 @@ static int snd_us16x08_eq_put(struct snd_kcontrol *kcontrol,
int b_idx = EQ_STORE_BAND_IDX(elem->head.id) - 1;
int p_idx = EQ_STORE_PARAM_IDX(elem->head.id);
+ guard(mutex)(&elem->head.mixer->lock);
val = ucontrol->value.integer.value[0];
/* sanity check */
@@ -729,6 +743,7 @@ static int snd_us16x08_meter_get(struct snd_kcontrol *kcontrol,
struct snd_us16x08_meter_store *store = elem->private_data;
u8 meter_urb[64] = {0};
+ guard(mutex)(&elem->head.mixer->lock);
switch (kcontrol->private_value) {
case 0: {
char tmp[sizeof(mix_init_msg1)];
@@ -788,6 +803,7 @@ static int snd_us16x08_meter_put(struct snd_kcontrol *kcontrol,
struct snd_us16x08_meter_store *store = elem->private_data;
int val;
+ guard(mutex)(&elem->head.mixer->lock);
val = ucontrol->value.integer.value[0];
/* sanity check */
--
2.55.0
next prev parent reply other threads:[~2026-10-08 19:26 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 19:25 [PATCH 00/11] ALSA: yet a few more fixes for AI bug reports Takashi Iwai
2026-10-08 19:25 ` [PATCH 01/11] ALSA: hda: intel: Cancel delayed work at shutdown, too Takashi Iwai
2026-10-08 19:25 ` [PATCH 02/11] ALSA: hda: Disable unsol event handling at error and shutdown paths Takashi Iwai
2026-10-08 19:25 ` [PATCH 03/11] ALSA: hda: Add lock around codec->registered flag manipulations Takashi Iwai
2026-10-09 10:13 ` kernel test robot
2026-10-09 10:56 ` kernel test robot
2026-10-08 19:25 ` [PATCH 04/11] ALSA: hda: Add NULL check for the driver pointer at unsol event work Takashi Iwai
2026-10-08 19:25 ` [PATCH 05/11] ALSA: caiaq: Register card at the final step Takashi Iwai
2026-10-08 19:25 ` [PATCH 06/11] ALSA: caiaq: Fix races at MIDI URB and trigger accesses Takashi Iwai
2026-10-08 19:25 ` Takashi Iwai [this message]
2026-10-08 19:25 ` [PATCH 08/11] ASoC: fsl_asrc_m2m: Fix bogus compress task pointer assignments Takashi Iwai
2026-10-08 19:25 ` [PATCH 09/11] ALSA: line6: Reject too small max packet sizes Takashi Iwai
2026-10-08 19:25 ` [PATCH 10/11] ALSA: line6: Fix potential OOB write in line6_capture_copy() Takashi Iwai
2026-10-08 19:25 ` [PATCH 11/11] ALSA: line6: Fix handling of zero-length capture packets Takashi Iwai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008192553.300025-8-tiwai@suse.de \
--to=tiwai@suse.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sound@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox