Re: [PATCH] ASoC: xilinx: formatter_pcm: fix stream_data leak on open error

Michal Simek <[email protected]>
Newsgroups gmane.linux.kernel,gmane.linux.sound,gmane.linux.ports.arm.kernel
Message-ID <[email protected]>

On 8/7/26 02:40, Rosen Penev wrote:
> In xlnx_formatter_pcm_open(), stream_data is allocated and
> adata->play_stream or adata->capture_stream is assigned early.  If a
> later step, such as snd_pcm_hw_constraint_step() or
> snd_pcm_hw_constraint_integer(), fails, the function returns the error
> immediately.  ALSA does not call the close callback when open fails, so
> stream_data is leaked and the stream pointer is left dangling, pointing
> to a substream that ALSA frees.  A later interrupt would then call
> snd_pcm_period_elapsed() on the freed substream.
> 
> Free stream_data and clear the stream pointer on the error paths.
> 
> Fixes: 6f6c3c36f091 ("ASoC: xlnx: add pcm formatter platform driver")
> Assisted-by: opencode:deepseek-v4-flash-free
> Signed-off-by: Rosen Penev <[email protected]>
> ---
>   sound/soc/xilinx/xlnx_formatter_pcm.c | 14 +++++++++++---
>   1 file changed, 11 insertions(+), 3 deletions(-)
> 
> diff --git a/sound/soc/xilinx/xlnx_formatter_pcm.c b/sound/soc/xilinx/xlnx_formatter_pcm.c
> index 7eba3a0205f1..4f4c1e650aaf 100644
> --- a/sound/soc/xilinx/xlnx_formatter_pcm.c
> +++ b/sound/soc/xilinx/xlnx_formatter_pcm.c
> @@ -385,7 +385,7 @@ static int xlnx_formatter_pcm_open(struct snd_soc_component *component,
>   	if (err) {
>   		dev_err(component->dev,
>   			"Unable to set constraint on period bytes\n");
> -		return err;
> +		goto err;
>   	}
>   
>   	/* Resize the buffer bytes as divisible by 64 */
> @@ -395,7 +395,7 @@ static int xlnx_formatter_pcm_open(struct snd_soc_component *component,
>   	if (err) {
>   		dev_err(component->dev,
>   			"Unable to set constraint on buffer bytes\n");
> -		return err;
> +		goto err;
>   	}
>   
>   	/* Set periods as integer multiple */
> @@ -404,7 +404,7 @@ static int xlnx_formatter_pcm_open(struct snd_soc_component *component,
>   	if (err < 0) {
>   		dev_err(component->dev,
>   			"Unable to set constraint on periods to be integer\n");
> -		return err;
> +		goto err;
>   	}
>   
>   	/* enable DMA IOC irq */
> @@ -413,6 +413,14 @@ static int xlnx_formatter_pcm_open(struct snd_soc_component *component,
>   	writel(val, stream_data->mmio + XLNX_AUD_CTRL);
>   
>   	return 0;
> +
> +err:

err is also variable in this code that's why I suggest you to rename this label.

> +	if (substream->stream == SNDRV_PCM_STREAM_PLAYBACK)
> +		adata->play_stream = NULL;
> +	else
> +		adata->capture_stream = NULL;
> +	kfree(stream_data);
> +	return err;
>   }
>   
>   static int xlnx_formatter_pcm_close(struct snd_soc_component *component,

With that fixed fell free to add

Reviewed-by: Michal Simek <[email protected]>

Thanks,
Michal
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.