<feed xmlns='http://www.w3.org/2005/Atom'>
<title>kernel/git/stable/linux.git/sound/synth, branch linux-4.4.y</title>
<subtitle>Linux kernel stable tree</subtitle>
<id>https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/atom?h=linux-4.4.y</id>
<link rel='self' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/atom?h=linux-4.4.y'/>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/'/>
<updated>2021-11-26T10:58:34+00:00</updated>
<entry>
<title>ALSA: synth: missing check for possible NULL after the call to kstrdup</title>
<updated>2021-11-26T10:58:34+00:00</updated>
<author>
<name>Austin Kim</name>
<email>austin.kim@lge.com</email>
</author>
<published>2021-11-09T00:37:42+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=c6429e395ad01d2c15a7c56dd8a3a5986106022c'/>
<id>urn:sha1:c6429e395ad01d2c15a7c56dd8a3a5986106022c</id>
<content type='text'>
commit d159037abbe3412285c271bdfb9cdf19e62678ff upstream.

If kcalloc() return NULL due to memory starvation, it is possible for
kstrdup() to return NULL in similar case. So add null check after the call
to kstrdup() is made.

[ minor coding-style fix by tiwai ]

Signed-off-by: Austin Kim &lt;austin.kim@lge.com&gt;
Cc: &lt;stable@vger.kernel.org&gt;
Link: https://lore.kernel.org/r/20211109003742.GA5423@raspberrypi
Signed-off-by: Takashi Iwai &lt;tiwai@suse.de&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;
</content>
</entry>
<entry>
<title>ALSA: emux: Fix potential Spectre v1 vulnerabilities</title>
<updated>2019-01-13T09:05:29+00:00</updated>
<author>
<name>Gustavo A. R. Silva</name>
<email>gustavo@embeddedor.com</email>
</author>
<published>2018-12-12T17:20:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=31eadb108bf7be5e55fe725ced8a1e4c85009c95'/>
<id>urn:sha1:31eadb108bf7be5e55fe725ced8a1e4c85009c95</id>
<content type='text'>
commit 4aea96f4237cea0c51a8bc87c0db31f0f932f1f0 upstream.

info.mode and info.port are indirectly controlled by user-space,
hence leading to a potential exploitation of the Spectre variant 1
vulnerability.

These issues were detected with the help of Smatch:

sound/synth/emux/emux_hwdep.c:72 snd_emux_hwdep_misc_mode() warn: potential spectre issue 'emu-&gt;portptrs[i]-&gt;ctrls' [w] (local cap)
sound/synth/emux/emux_hwdep.c:75 snd_emux_hwdep_misc_mode() warn: potential spectre issue 'emu-&gt;portptrs' [w] (local cap)
sound/synth/emux/emux_hwdep.c:75 snd_emux_hwdep_misc_mode() warn: potential spectre issue 'emu-&gt;portptrs[info.port]-&gt;ctrls' [w] (local cap)

Fix this by sanitizing both info.mode and info.port before using them
to index emu-&gt;portptrs[i]-&gt;ctrls, emu-&gt;portptrs[info.port]-&gt;ctrls and
emu-&gt;portptrs.

Notice that given that speculation windows are large, the policy is
to kill the speculation on the first load and not worry if it can be
completed with a dependent load/store [1].

[1] https://marc.info/?l=linux-kernel&amp;m=152449131114778&amp;w=2

Signed-off-by: Gustavo A. R. Silva &lt;gustavo@embeddedor.com&gt;
Cc: stable@vger.kernel.org
Signed-off-by: Takashi Iwai &lt;tiwai@suse.de&gt;
Signed-off-by: Greg Kroah-Hartman &lt;gregkh@linuxfoundation.org&gt;

</content>
</entry>
<entry>
<title>ALSA: synth: Fix conflicting OSS device registration on AWE32</title>
<updated>2015-10-05T14:55:09+00:00</updated>
<author>
<name>Takashi Iwai</name>
<email>tiwai@suse.de</email>
</author>
<published>2015-10-05T14:55:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=225db5762dc1a35b26850477ffa06e5cd0097243'/>
<id>urn:sha1:225db5762dc1a35b26850477ffa06e5cd0097243</id>
<content type='text'>
When OSS emulation is loaded on ISA SB AWE32 chip, we get now kernel
warnings like:
  WARNING: CPU: 0 PID: 2791 at fs/sysfs/dir.c:31 sysfs_warn_dup+0x51/0x80()
  sysfs: cannot create duplicate filename '/devices/isa/sbawe.0/sound/card0/seq-oss-0-0'

It's because both emux synth and opl3 drivers try to register their
OSS device object with the same static index number 0.  This hasn't
been a big problem until the recent rewrite of device management code
(that exposes sysfs at the same time), but it's been an obvious bug.

This patch works around it just by using a different index number of
emux synth object.  There can be a more elegant way to fix, but it's
enough for now, as this code won't be touched so often, in anyway.

Reported-and-tested-by: Michael Shell &lt;list1@michaelshell.org&gt;
Cc: &lt;stable@vger.kernel.org&gt;
Signed-off-by: Takashi Iwai &lt;tiwai@suse.de&gt;
</content>
</entry>
<entry>
<title>ALSA: emux: Fix/cleanup old ifdef CONFIG_PROC_FS</title>
<updated>2015-05-29T05:58:11+00:00</updated>
<author>
<name>Takashi Iwai</name>
<email>tiwai@suse.de</email>
</author>
<published>2015-05-29T05:58:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=52262b4a5d7c3d3549985a47d96fe7d661220162'/>
<id>urn:sha1:52262b4a5d7c3d3549985a47d96fe7d661220162</id>
<content type='text'>
Build emux_proc.o and drop the unneeded ifdefs.
Replace the left CONFIG_PROC with the new CONFIG_SND_PROC_FS.

Along with this, fix the build of emux_oss.o in Makefile, too.

Signed-off-by: Takashi Iwai &lt;tiwai@suse.de&gt;
</content>
</entry>
<entry>
<title>ALSA: emux: Fix mutex deadlock in OSS emulation</title>
<updated>2015-04-28T15:45:45+00:00</updated>
<author>
<name>Takashi Iwai</name>
<email>tiwai@suse.de</email>
</author>
<published>2015-04-28T15:11:44+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=1c94e65c668f44d2c69ae7e7fc268ab3268fba3e'/>
<id>urn:sha1:1c94e65c668f44d2c69ae7e7fc268ab3268fba3e</id>
<content type='text'>
The OSS emulation in synth-emux helper has a potential AB/BA deadlock
at the simultaneous closing and opening:

  close -&gt;
    snd_seq_release() -&gt;
      sne_seq_free_client() -&gt;
        snd_seq_delete_all_ports(): takes client-&gt;ports_mutex -&gt;
	  port_delete() -&gt;
	    snd_emux_unuse(): takes emux-&gt;register_mutex

  open -&gt;
    snd_seq_oss_open() -&gt;
      snd_emux_open_seq_oss(): takes emux-&gt;register_mutex -&gt;
        snd_seq_event_port_attach() -&gt;
	  snd_seq_create_port(): takes client-&gt;ports_mutex

This patch addresses the deadlock by reducing the rance taking
emux-&gt;register_mutex in snd_emux_open_seq_oss().  The lock is needed
for the refcount handling, so move it locally.  The calls in
emux_seq.c are already with the mutex, thus they are replaced with the
version without mutex lock/unlock.

Cc: &lt;stable@vger.kernel.org&gt;
Signed-off-by: Takashi Iwai &lt;tiwai@suse.de&gt;
</content>
</entry>
<entry>
<title>ALSA: emux: Fix mutex deadlock at unloading</title>
<updated>2015-04-27T12:50:39+00:00</updated>
<author>
<name>Takashi Iwai</name>
<email>tiwai@suse.de</email>
</author>
<published>2015-04-27T12:50:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=07b0e5d49d227e3950cb13a3e8caf248ef2a310e'/>
<id>urn:sha1:07b0e5d49d227e3950cb13a3e8caf248ef2a310e</id>
<content type='text'>
The emux-synth driver has a possible AB/BA mutex deadlock at unloading
the emu10k1 driver:

  snd_emux_free() -&gt;
    snd_emux_detach_seq(): mutex_lock(&amp;emu-&gt;register_mutex) -&gt;
      snd_seq_delete_kernel_client() -&gt;
        snd_seq_free_client(): mutex_lock(&amp;register_mutex)

  snd_seq_release() -&gt;
    snd_seq_free_client(): mutex_lock(&amp;register_mutex) -&gt;
      snd_seq_delete_all_ports() -&gt;
        snd_emux_unuse(): mutex_lock(&amp;emu-&gt;register_mutex)

Basically snd_emux_detach_seq() doesn't need a protection of
emu-&gt;register_mutex as it's already being unregistered.  So, we can
get rid of this for avoiding the deadlock.

Cc: &lt;stable@vger.kernel.org&gt;
Signed-off-by: Takashi Iwai &lt;tiwai@suse.de&gt;
</content>
</entry>
<entry>
<title>ALSA: Include linux/uaccess.h and linux/bitopts.h instead of asm/*</title>
<updated>2015-01-28T16:25:07+00:00</updated>
<author>
<name>Takashi Iwai</name>
<email>tiwai@suse.de</email>
</author>
<published>2015-01-28T16:24:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=976412fbc9855176ea7e02602a601b46c4479fcc'/>
<id>urn:sha1:976412fbc9855176ea7e02602a601b46c4479fcc</id>
<content type='text'>
Signed-off-by: Takashi Iwai &lt;tiwai@suse.de&gt;
</content>
</entry>
<entry>
<title>ALSA: emux: Use setup_timer() and mod_timer()</title>
<updated>2015-01-19T10:41:13+00:00</updated>
<author>
<name>Takashi Iwai</name>
<email>tiwai@suse.de</email>
</author>
<published>2015-01-19T10:41:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=abd083526af3a8a1610e884c8e619925c3d663e6'/>
<id>urn:sha1:abd083526af3a8a1610e884c8e619925c3d663e6</id>
<content type='text'>
No functional change, refactoring with the standard helpers.

Signed-off-by: Takashi Iwai &lt;tiwai@suse.de&gt;
</content>
</entry>
<entry>
<title>ALSA: emux: Delete an unnecessary check before the function call "snd_sf_free"</title>
<updated>2015-01-04T14:12:29+00:00</updated>
<author>
<name>Markus Elfring</name>
<email>elfring@users.sourceforge.net</email>
</author>
<published>2015-01-03T17:28:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=b172e0aae6d14baf646a36052d03b301535f4ef5'/>
<id>urn:sha1:b172e0aae6d14baf646a36052d03b301535f4ef5</id>
<content type='text'>
The snd_sf_free() function tests whether its argument is NULL and then
returns immediately. Thus the test around the call is not needed.

This issue was detected by using the Coccinelle software.

Signed-off-by: Markus Elfring &lt;elfring@users.sourceforge.net&gt;
Signed-off-by: Takashi Iwai &lt;tiwai@suse.de&gt;
</content>
</entry>
<entry>
<title>ALSA: synth: emux: soundfont.c: Cleaning up memory leak</title>
<updated>2014-06-01T12:33:09+00:00</updated>
<author>
<name>Rickard Strandqvist</name>
<email>rickard_strandqvist@spectrumdigital.se</email>
</author>
<published>2014-06-01T11:35:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.rulkc.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=14577c25169beb8676577490bf2f0bd539d5e999'/>
<id>urn:sha1:14577c25169beb8676577490bf2f0bd539d5e999</id>
<content type='text'>
There is a risk for memory leak in when something unexpected happens
and the function returns.

This was largely found by using a static code analysis program called cppcheck.

[fixed a typo of kfree() by tiwai]

Signed-off-by: Rickard Strandqvist &lt;rickard_strandqvist@spectrumdigital.se&gt;
Signed-off-by: Takashi Iwai &lt;tiwai@suse.de&gt;
</content>
</entry>
</feed>
