From: Christophe JAILLET <christophe.jaillet@wanadoo.fr>
To: Guangshuo Li <lgs201920130244@gmail.com>,
Liam Girdwood <lgirdwood@gmail.com>,
Mark Brown <broonie@kernel.org>, Jaroslav Kysela <perex@perex.cz>,
Takashi Iwai <tiwai@suse.com>,
Matthias Brugger <matthias.bgg@gmail.com>,
AngeloGioacchino Del Regno
<angelogioacchino.delregno@collabora.com>,
Charles Keepax <ckeepax@opensource.cirrus.com>,
Alexandre Mergnat <amergnat@baylibre.com>,
linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-arm-kernel@lists.infradead.org,
linux-mediatek@lists.infradead.org
Cc: stable@vger.kernel.org
Subject: Re: [PATCH v2] ASoC: mediatek: mt8365: Add check for devm_kcalloc() in mt8365_afe_suspend()
Date: Mon, 22 Sep 2025 17:43:28 +0200 [thread overview]
Message-ID: <dcb6023b-8c14-4bbd-9bac-2933e91ef553@wanadoo.fr> (raw)
In-Reply-To: <20250922153448.1824447-1-lgs201920130244@gmail.com>
Le 22/09/2025 à 17:34, Guangshuo Li a écrit :
> devm_kcalloc() may fail. mt8365_afe_suspend() uses afe->reg_back_up
> unconditionally after allocation and writes afe->reg_back_up[i], which
> can lead to a NULL pointer dereference under low-memory conditions.
>
> Add a NULL check and bail out with -ENOMEM, making sure to disable the
> main clock via the existing error path to keep clock state balanced.
>
> Fixes: e1991d102bc2 ("ASoC: mediatek: mt8365: Add the AFE driver support")
> Cc: stable@vger.kernel.org
> ---
> changelog:
> v2:
> - Return -ENOMEM directly on allocation failure without goto/label.
> - Disable the main clock before returning to keep clock state balanced.
>
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
This should be above the ---
> ---
> sound/soc/mediatek/mt8365/mt8365-afe-pcm.c | 10 +++++++---
> 1 file changed, 7 insertions(+), 3 deletions(-)
>
> diff --git a/sound/soc/mediatek/mt8365/mt8365-afe-pcm.c b/sound/soc/mediatek/mt8365/mt8365-afe-pcm.c
> index 10793bbe9275..55d832e05072 100644
> --- a/sound/soc/mediatek/mt8365/mt8365-afe-pcm.c
> +++ b/sound/soc/mediatek/mt8365/mt8365-afe-pcm.c
> @@ -1975,11 +1975,15 @@ static int mt8365_afe_suspend(struct device *dev)
>
> mt8365_afe_enable_main_clk(afe);
>
> - if (!afe->reg_back_up)
> + if (!afe->reg_back_up) {
> afe->reg_back_up =
> devm_kcalloc(dev, afe->reg_back_up_list_num,
> - sizeof(unsigned int), GFP_KERNEL);
> -
> + sizeof(unsigned int), GFP_KERNEL);
you should not remove a space here.
CJ
> + if (!afe->reg_back_up) {
> + mt8365_afe_disable_main_clk(afe);
> + return -ENOMEM;
> + }
> + }
> for (i = 0; i < afe->reg_back_up_list_num; i++)
> regmap_read(regmap, afe->reg_back_up_list[i],
> &afe->reg_back_up[i]);
prev parent reply other threads:[~2025-09-22 15:53 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-09-22 15:34 [PATCH v2] ASoC: mediatek: mt8365: Add check for devm_kcalloc() in mt8365_afe_suspend() Guangshuo Li
2025-09-22 15:43 ` Christophe JAILLET [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=dcb6023b-8c14-4bbd-9bac-2933e91ef553@wanadoo.fr \
--to=christophe.jaillet@wanadoo.fr \
--cc=amergnat@baylibre.com \
--cc=angelogioacchino.delregno@collabora.com \
--cc=broonie@kernel.org \
--cc=ckeepax@opensource.cirrus.com \
--cc=lgirdwood@gmail.com \
--cc=lgs201920130244@gmail.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mediatek@lists.infradead.org \
--cc=linux-sound@vger.kernel.org \
--cc=matthias.bgg@gmail.com \
--cc=perex@perex.cz \
--cc=stable@vger.kernel.org \
--cc=tiwai@suse.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox