Re: [PATCH 1/2] ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses

Srinivas Kandagatla <[email protected]>
Newsgroups org.kernel.vger.linux-sound,org.kernel.vger.linux-arm-msm,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On 7/29/26 8:38 PM, Dawid Wróbel via B4 Relay wrote:
> From: Dawid Wróbel <[email protected]>
> 
> The "DEC0 MODE" to "DEC7 MODE" controls are enumerated, but
> tx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their
> value through ucontrol->value.integer.value[0] (a long) instead of
> ucontrol->value.enumerated.item[0] (an unsigned int).
> 
> This same pattern was fixed in the sibling drivers by
> commit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array
> out of bounds for enum type") and
> commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array
> out of bounds for enum type"), but tx-macro was missed.
> 
> On 64-bit kernels built with CONFIG_SND_CTL_DEBUG, the elem value
> sanity check catches the 4 bytes written past the enumerated item
> and every read of these controls fails with -EINVAL:
> 
>   snd-sm8250 sound: control 2:0:0:DEC0 MODE:0: access overflow
> 
> Fixes: c39667ddcfc5 ("ASoC: codecs: lpass-tx-macro: add support for lpass tx macro")
> Assisted-by: Claude:claude-fable-5
> Signed-off-by: Dawid Wróbel <[email protected]>

CC Stable

Once added


Reviewed-by: Srinivas Kandagatla <[email protected]>

--srini
> ---
>  sound/soc/codecs/lpass-tx-macro.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/sound/soc/codecs/lpass-tx-macro.c b/sound/soc/codecs/lpass-tx-macro.c
> index f7d168f557dd..0cbf50647ff5 100644
> --- a/sound/soc/codecs/lpass-tx-macro.c
> +++ b/sound/soc/codecs/lpass-tx-macro.c
> @@ -1075,7 +1075,7 @@ static int tx_macro_dec_mode_get(struct snd_kcontrol *kcontrol,
>  	struct soc_enum *e = (struct soc_enum *)kcontrol->private_value;
>  	int path = e->shift_l;
>  
> -	ucontrol->value.integer.value[0] = tx->dec_mode[path];
> +	ucontrol->value.enumerated.item[0] = tx->dec_mode[path];
>  
>  	return 0;
>  }
> @@ -1084,7 +1084,7 @@ static int tx_macro_dec_mode_put(struct snd_kcontrol *kcontrol,
>  				 struct snd_ctl_elem_value *ucontrol)
>  {
>  	struct snd_soc_component *component = snd_kcontrol_chip(kcontrol);
> -	int value = ucontrol->value.integer.value[0];
> +	int value = ucontrol->value.enumerated.item[0];
>  	struct soc_enum *e = (struct soc_enum *)kcontrol->private_value;
>  	int path = e->shift_l;
>  	struct tx_macro *tx = snd_soc_component_get_drvdata(component);
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.