From: Pierre-Louis Bossart <pierre-louis.bossart@linux.dev>
To: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>,
vkoul@kernel.org, perex@perex.cz, tiwai@suse.com,
lgirdwood@gmail.com, broonie@kernel.org,
srinivas.kandagatla@oss.qualcomm.com
Cc: linux-sound@vger.kernel.org, kai.vehmanen@linux.intel.com,
yung-chuan.liao@linux.intel.com, daniel.baluta@nxp.com
Subject: Re: [PATCH v2 09/24] ASoC: SOF: sof-audio: do not dereference swidget->spipe unconditionally on free
Date: Wed, 9 Sep 2026 14:39:53 +0200 [thread overview]
Message-ID: <f57fb6d1-31d8-46cc-be16-aaa85fce99a0@linux.dev> (raw)
In-Reply-To: <20260909090949.7503-10-peter.ujfalusi@linux.intel.com>
On 9/9/26 11:09, Peter Ujfalusi wrote:
> sof_widget_free_unlocked() dereferences swidget->spipe without checking
> it for two things: swidget->spipe->complete for a scheduler widget, and
> swidget->spipe->pipe_widget for the recursive free of the pipeline's
> scheduler widget. Both can be reached with spipe or pipe_widget not
> set, which oopses in the free path - where there is nothing left to
> bail out to.
>
> Check both before use and cache swidget->spipe in the local spipe
> variable that is already there. A widget with no pipeline has nothing
> to put or complete, and no scheduler widget to free, so skipping is the
> correct behaviour.
>
> No functional change for a widget that was successfully set up:
> sof_widget_setup_unlocked() already rejects a dynamic pipeline widget
> with no spipe or no spipe->pipe_widget with -EINVAL.
>
> Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
> Reviewed-by: Liam Girdwood <liam.r.girdwood@intel.com>
> ---
> sound/soc/sof/sof-audio.c | 8 ++++----
> 1 file changed, 4 insertions(+), 4 deletions(-)
same, this doesn't seem directly related to compresss offload. Maybe
it's required because of new transitions?
I'd move this earlier or submit as a cleanup separately to reduce the
volume of reviews (24 patches!)
> diff --git a/sound/soc/sof/sof-audio.c b/sound/soc/sof/sof-audio.c
> index d244e90a734b..0b2f41f4a59b 100644
> --- a/sound/soc/sof/sof-audio.c
> +++ b/sound/soc/sof/sof-audio.c
> @@ -103,7 +103,7 @@ static int sof_widget_free_unlocked(struct snd_sof_dev *sdev,
> * decrement ref count for cores associated with all modules in the pipeline and clear
> * the complete flag
> */
> - if (swidget->id == snd_soc_dapm_scheduler) {
> + if (swidget->id == snd_soc_dapm_scheduler && spipe) {
> int i;
>
> for_each_set_bit(i, &spipe->core_mask, sdev->num_cores) {
> @@ -115,16 +115,16 @@ static int sof_widget_free_unlocked(struct snd_sof_dev *sdev,
> err = ret;
> }
> }
> - swidget->spipe->complete = 0;
> + spipe->complete = 0;
> }
>
> /*
> * free the scheduler widget (same as pipe_widget) associated with the current swidget.
> * skip for static pipelines
> */
> - if (swidget->spipe && swidget->dynamic_pipeline_widget &&
> + if (spipe && spipe->pipe_widget && swidget->dynamic_pipeline_widget &&
> swidget->id != snd_soc_dapm_scheduler) {
> - ret = sof_widget_free_unlocked(sdev, swidget->spipe->pipe_widget);
> + ret = sof_widget_free_unlocked(sdev, spipe->pipe_widget);
> if (ret < 0 && !err)
> err = ret;
> }
next prev parent reply other threads:[~2026-09-09 14:23 UTC|newest]
Thread overview: 47+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 9:09 [PATCH v2 00/24] ALSA compress / ASoC compress / SOF: Compressed audio support with IPC4 Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 01/24] ALSA: compress: pin card module while stream is open Peter Ujfalusi
2026-09-09 15:12 ` Takashi Iwai
2026-09-09 9:09 ` [PATCH v2 02/24] ALSA: compress: register the open file with the card Peter Ujfalusi
2026-09-09 15:12 ` Takashi Iwai
2026-09-09 9:09 ` [PATCH v2 03/24] ALSA: compress: stop active streams on disconnect Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 04/24] ASoC: soc-compress: Provide a runtime for the compressed FE substream Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 05/24] ASoC: soc-compress: Implement trigger FE-BE sequencing as with normal PCMs Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 06/24] ASoC: soc-compress: Stop running dpcm on free Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 07/24] ASoC: SOF: compress: Rename compress ops with ipc3 prefix Peter Ujfalusi
2026-09-09 12:34 ` Pierre-Louis Bossart
2026-09-10 14:13 ` Péter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 08/24] ASoC: SOF: ipc4-pcm: harden pipeline teardown races Peter Ujfalusi
2026-09-09 12:37 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 09/24] ASoC: SOF: sof-audio: do not dereference swidget->spipe unconditionally on free Peter Ujfalusi
2026-09-09 12:39 ` Pierre-Louis Bossart [this message]
2026-09-09 9:09 ` [PATCH v2 10/24] ASoC: SOF: sof-audio: Expose a couple of functions Peter Ujfalusi
2026-09-09 12:41 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 11/24] ASoC: SOF: pcm: Modify the signature of a couple of PCM IPC ops Peter Ujfalusi
2026-09-09 12:43 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 12/24] ASoC: SOF: intel: hda-stream: Clear the current position when releasing stream Peter Ujfalusi
2026-09-09 12:45 ` Pierre-Louis Bossart
2026-09-11 6:31 ` Péter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 13/24] ASoC: SOF: ops: Add new platform-specific ops for compress Peter Ujfalusi
2026-09-09 14:23 ` Pierre-Louis Bossart
2026-09-10 14:25 ` Péter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 14/24] ASoC: SOF: ipc4: Add definition of module data in init_ext object type Peter Ujfalusi
2026-09-09 12:49 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 15/24] ASoC: SOF: ipc4-topology: Support init_ext_module_data for process modules Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 16/24] ASoC: SOF: ipc4-pcm: Make the timestamp info usable outside of ipc4-pcm.c Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 17/24] ASoC: SOF: ipc4/ipc4-loader: Add SOF_INFO and CODEC_INFO to fw_config_params Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 18/24] ASoC: SOF: ipc4-pcm: Handle COMPR DRAIN triggers as EOS pipeline state Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 19/24] ASoC: SOF: ipc4-topology: Set FAST_MODE for host copier in compr mode Peter Ujfalusi
2026-09-09 13:21 ` Pierre-Louis Bossart
2026-09-10 14:49 ` Péter Ujfalusi
2026-09-11 19:08 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 20/24] ASoC: SOF: Add support for IPC4 compressed Peter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 21/24] ASoC: SOF: ipc4: Handle compressed drain done notification from firmware Peter Ujfalusi
2026-09-09 13:28 ` Pierre-Louis Bossart
2026-09-10 15:08 ` Péter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 22/24] ASoC: SOF: Intel: Kconfig: Remove redundant IPC version selects Peter Ujfalusi
2026-09-09 13:29 ` Pierre-Louis Bossart
2026-09-09 9:09 ` [PATCH v2 23/24] ASoC: SOF: Intel: Kconfig: Select compress support for TGL+ platforms Peter Ujfalusi
2026-09-09 13:37 ` Pierre-Louis Bossart
2026-09-10 14:57 ` Péter Ujfalusi
2026-09-09 9:09 ` [PATCH v2 24/24] ASoC: SOF: topology: Add support for decoder and encoder widgets Peter Ujfalusi
2026-09-09 13:42 ` [PATCH v2 00/24] ALSA compress / ASoC compress / SOF: Compressed audio support with IPC4 Pierre-Louis Bossart
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f57fb6d1-31d8-46cc-be16-aaa85fce99a0@linux.dev \
--to=pierre-louis.bossart@linux.dev \
--cc=broonie@kernel.org \
--cc=daniel.baluta@nxp.com \
--cc=kai.vehmanen@linux.intel.com \
--cc=lgirdwood@gmail.com \
--cc=linux-sound@vger.kernel.org \
--cc=perex@perex.cz \
--cc=peter.ujfalusi@linux.intel.com \
--cc=srinivas.kandagatla@oss.qualcomm.com \
--cc=tiwai@suse.com \
--cc=vkoul@kernel.org \
--cc=yung-chuan.liao@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox