* [PATCH v1 0/2] ASoC: amd: Fix borrowed ACPI codec device references
@ 2026-09-19 12:13 Yibo Tan
2026-09-19 12:13 ` [PATCH v1 1/2] ASoC: amd: acp-es8336: Use an owned codec device reference Yibo Tan
2026-09-19 12:13 ` [PATCH v1 2/2] ASoC: amd: acp3x-es83xx: Keep " Yibo Tan
0 siblings, 2 replies; 4+ messages in thread
From: Yibo Tan @ 2026-09-19 12:13 UTC (permalink / raw)
To: Vijendar Mukunda, Mark Brown
Cc: Venkata Prasad Potturu, Liam Girdwood, Jaroslav Kysela,
Takashi Iwai, linux-sound, linux-kernel
Two AMD machine drivers obtain a borrowed physical device pointer from
acpi_get_first_physical_node() and later treat it as owned. The ES8336 driver
drops it on GPIO defer. The ACP3x driver drops it on private-data OOM and
otherwise stores it for later use.
The patches convert both sites to the newer owned helper. Their reference
scope differs: ES8336 uses the device only within late probe, while ACP3x
publishes the pointer and ties the credit to card-device devres teardown.
Both defects reproduce on current mainline with direct calls to the real
static callbacks and normal ACPI/device-core unregister. In both cases the
vulnerable arm reports a KASAN slab-use-after-free in device_del(), while the
corresponding patched arm preserves the injected error and teardown with no
KASAN, WARNING, Oops or panic.
The validation does not emulate a complete ASoC production pipeline and was
not run on physical AMD/Huawei hardware.
Assisted-by: LLM
Yibo Tan (2):
ASoC: amd: acp-es8336: Use an owned codec device reference
ASoC: amd: acp3x-es83xx: Keep an owned codec device reference
sound/soc/amd/acp-es8336.c | 5 ++---
sound/soc/amd/acp/acp3x-es83xx/acp3x-es83xx.c | 13 ++++++++++++-
2 files changed, 14 insertions(+), 4 deletions(-)
base-commit: 0ed6f7f62318a581fe9698f8a4e98c7ca01160e4
--
2.39.5
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v1 1/2] ASoC: amd: acp-es8336: Use an owned codec device reference
2026-09-19 12:13 [PATCH v1 0/2] ASoC: amd: Fix borrowed ACPI codec device references Yibo Tan
@ 2026-09-19 12:13 ` Yibo Tan
2026-09-19 12:13 ` [PATCH v1 2/2] ASoC: amd: acp3x-es83xx: Keep " Yibo Tan
1 sibling, 0 replies; 4+ messages in thread
From: Yibo Tan @ 2026-09-19 12:13 UTC (permalink / raw)
To: Vijendar Mukunda, Mark Brown
Cc: Venkata Prasad Potturu, Liam Girdwood, Jaroslav Kysela,
Takashi Iwai, linux-sound, linux-kernel
acpi_get_first_physical_node() returns a borrowed device pointer. If the
pa-enable GPIO lookup fails, st_es8336_late_probe() puts that pointer
despite not owning a reference. A later physical-node teardown can then
release the device while device_del() is still using it.
This was reproduced on current mainline with the real static late-probe
callback and normal platform-device unregister. The GPIO lookup returned
-EPROBE_DEFER and KASAN reported a slab-use-after-free in device_del(),
with the object freed by acpi_unbind_one().
Use acpi_bus_get_primary_device(), which obtains a stable device
reference under the physical-node lock, and release it at callback exit
with scoped cleanup. Keep the reference callback-local because late probe
can be retried; registering one devres action per attempt would accumulate
references.
The same KASAN guest with this change reached the same -EPROBE_DEFER and
unregister path without KASAN, WARNING, Oops or panic. The test directly
invoked the production callback and did not emulate a complete ASoC card or
physical AMD hardware.
Fixes: 02527c3f2300 ("ASoC: amd: add Machine driver for Jadeite platform")
Assisted-by: LLM
Signed-off-by: Yibo Tan <lhfff@tju.edu.cn>
---
sound/soc/amd/acp-es8336.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/sound/soc/amd/acp-es8336.c b/sound/soc/amd/acp-es8336.c
index 9f3f11256788..0cb0ee76191d 100644
--- a/sound/soc/amd/acp-es8336.c
+++ b/sound/soc/amd/acp-es8336.c
@@ -30,7 +30,6 @@
static unsigned long acp2x_machine_id;
static struct snd_soc_jack st_jack;
-static struct device *codec_dev;
static struct gpio_desc *gpio_pa;
static int sof_es8316_speaker_power_event(struct snd_soc_dapm_widget *w,
@@ -191,6 +190,7 @@ static const struct acpi_gpio_mapping acpi_es8336_gpios[] = {
static int st_es8336_late_probe(struct snd_soc_card *card)
{
+ struct device *codec_dev __free(put_device) = NULL;
struct acpi_device *adev;
int ret;
@@ -198,7 +198,7 @@ static int st_es8336_late_probe(struct snd_soc_card *card)
if (!adev)
return -ENODEV;
- codec_dev = acpi_get_first_physical_node(adev);
+ codec_dev = acpi_bus_get_primary_device(adev);
acpi_dev_put(adev);
if (!codec_dev) {
dev_err(card->dev, "can not find codec dev\n");
@@ -213,7 +213,6 @@ static int st_es8336_late_probe(struct snd_soc_card *card)
if (IS_ERR(gpio_pa)) {
ret = dev_err_probe(card->dev, PTR_ERR(gpio_pa),
"could not get pa-enable GPIO\n");
- put_device(codec_dev);
return ret;
}
return 0;
--
2.39.5
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v1 2/2] ASoC: amd: acp3x-es83xx: Keep an owned codec device reference
2026-09-19 12:13 [PATCH v1 0/2] ASoC: amd: Fix borrowed ACPI codec device references Yibo Tan
2026-09-19 12:13 ` [PATCH v1 1/2] ASoC: amd: acp-es8336: Use an owned codec device reference Yibo Tan
@ 2026-09-19 12:13 ` Yibo Tan
2026-09-21 8:50 ` Mark Brown
1 sibling, 1 reply; 4+ messages in thread
From: Yibo Tan @ 2026-09-19 12:13 UTC (permalink / raw)
To: Vijendar Mukunda, Mark Brown
Cc: Venkata Prasad Potturu, Liam Girdwood, Jaroslav Kysela,
Takashi Iwai, linux-sound, linux-kernel
acpi_get_first_physical_node() returns a borrowed device pointer. The
private data allocation failure path in acp3x_es83xx_probe() puts that
pointer despite not owning a reference. The successful path also saves the
borrowed pointer for later card operations.
This was reproduced on current mainline with failslab restricted to the
real static callback. The rejected devm_kzalloc() returned -ENOMEM, and
normal codec platform-device unregister then produced a KASAN
slab-use-after-free in device_del(), with allocation in
acpi_create_platform_device() and release in acpi_unbind_one().
Use acpi_bus_get_primary_device() to acquire the reference while the
physical-node lock is held. After allocating private data, register a
devres put action before publishing the pointer. This balances action
allocation and later probe failures, keeps the saved pointer alive during
card use, and drops the credit after ASoC card unregister during successful
teardown. The existing OOM put now correctly balances the owned lookup.
The same filtered KASAN guest with this change reached the same -ENOMEM and
unregister path without KASAN, WARNING, Oops or panic. The test directly
invoked the production callback and did not emulate a complete ACP/ASoC
card or physical Huawei hardware.
Fixes: 54fcd9dd44b2 ("ASoC: amd: acp: Add machine driver that enables sound for systems with a ES8336 codec")
Assisted-by: LLM
Signed-off-by: Yibo Tan <lhfff@tju.edu.cn>
---
sound/soc/amd/acp/acp3x-es83xx/acp3x-es83xx.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/sound/soc/amd/acp/acp3x-es83xx/acp3x-es83xx.c b/sound/soc/amd/acp/acp3x-es83xx/acp3x-es83xx.c
index 3a640e652314..568142b6d115 100644
--- a/sound/soc/amd/acp/acp3x-es83xx/acp3x-es83xx.c
+++ b/sound/soc/amd/acp/acp3x-es83xx/acp3x-es83xx.c
@@ -41,6 +41,11 @@ struct acp3x_es83xx_private {
struct snd_soc_dapm_route mic_map[2];
};
+static void acp3x_es83xx_put_codec_device(void *data)
+{
+ put_device(data);
+}
+
static const unsigned int channels[] = {
DUAL_CHANNEL,
};
@@ -428,7 +433,7 @@ static int acp3x_es83xx_probe(struct snd_soc_card *card)
return -ENXIO;
}
- codec_dev = acpi_get_first_physical_node(adev);
+ codec_dev = acpi_bus_get_primary_device(adev);
acpi_dev_put(adev);
if (!codec_dev) {
dev_warn(dev, "Error cannot find codec device, will defer probe\n");
@@ -441,6 +446,12 @@ static int acp3x_es83xx_probe(struct snd_soc_card *card)
return -ENOMEM;
}
+ ret = devm_add_action_or_reset(dev,
+ acp3x_es83xx_put_codec_device,
+ codec_dev);
+ if (ret)
+ return ret;
+
priv->codec_dev = codec_dev;
priv->quirk = (unsigned long)dmi_id->driver_data;
acp_drvdata->mach_priv = priv;
--
2.39.5
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH v1 2/2] ASoC: amd: acp3x-es83xx: Keep an owned codec device reference
2026-09-19 12:13 ` [PATCH v1 2/2] ASoC: amd: acp3x-es83xx: Keep " Yibo Tan
@ 2026-09-21 8:50 ` Mark Brown
0 siblings, 0 replies; 4+ messages in thread
From: Mark Brown @ 2026-09-21 8:50 UTC (permalink / raw)
To: Yibo Tan
Cc: Vijendar Mukunda, Venkata Prasad Potturu, Liam Girdwood,
Jaroslav Kysela, Takashi Iwai, linux-sound, linux-kernel
[-- Attachment #1: Type: text/plain, Size: 562 bytes --]
On Sat, Sep 19, 2026 at 08:13:18PM +0800, Yibo Tan wrote:
> @@ -428,7 +433,7 @@ static int acp3x_es83xx_probe(struct snd_soc_card *card)
> return -ENXIO;
> }
>
> - codec_dev = acpi_get_first_physical_node(adev);
> + codec_dev = acpi_bus_get_primary_device(adev);
> acpi_dev_put(adev);
> if (!codec_dev) {
> dev_warn(dev, "Error cannot find codec device, will defer probe\n");
This function is declared in acpi/acpi_bus.h which is only included by
linux/acpi.h if CONFIG_ACPI is enabled, this will break the build
otherwise.
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-21 8:50 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-19 12:13 [PATCH v1 0/2] ASoC: amd: Fix borrowed ACPI codec device references Yibo Tan
2026-09-19 12:13 ` [PATCH v1 1/2] ASoC: amd: acp-es8336: Use an owned codec device reference Yibo Tan
2026-09-19 12:13 ` [PATCH v1 2/2] ASoC: amd: acp3x-es83xx: Keep " Yibo Tan
2026-09-21 8:50 ` Mark Brown
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®