* [BUG] Kernel crash on Allwinner H3 due to sound core changes
@ 2018-03-08 1:21 ` Kuninori Morimoto
0 siblings, 0 replies; 29+ messages in thread
From: Kuninori Morimoto @ 2018-03-08 1:21 UTC (permalink / raw)
To: linux-arm-kernel
Hi Jernej
Thank you for your hard work
> I found the issue. Commit be7ee5f32a9a ("ASoC: soc-generic-dmaengine-pcm:
> replace platform to component") changes struct dmaengine_pcm:
>
> struct dmaengine_pcm {
> struct dma_chan *chan[SNDRV_PCM_STREAM_LAST + 1];
> const struct snd_dmaengine_pcm_config *config;
> - struct snd_soc_platform platform;
> + struct snd_soc_component component;
> unsigned int flags;
> };
>
> In snd_dmaengine_pcm_register():
> ret = snd_soc_add_component(dev, &pcm->component,
> &dmaengine_pcm_component, NULL, 0);
>
> And now, sun4i-codec first time returns -EPROBE_DEFER since driver for analog
> part is not yet loaded. Because of that, all components get destroyed.
>
> snd_dmaengine_pcm_unregister() calls snd_soc_unregister_component() and that
> one calls __snd_soc_unregister_component() multiple times (until it fails).
>
> Issue is that __snd_soc_unregister_component() uses kfree() on component
> pointer and that naturally can't succed since component was never kmalloc'ed
> since it is a part of a bigger structure - struct dmaengine_pcm.
>
> What would be the best fix? Changing struct dmaengine_pcm to have pointer to a
> component, so it can be freed?
Ahh.. indeed. Good catch !
How about to add such flag ?
This is just idea. No tested, No compiled, but can help you ?
One note here is that reusing "registered_as_component" flag is
not good idea, because it will be removed
when platform/codec were removed
------------------------
diff --git a/include/sound/soc.h b/include/sound/soc.h
index 1a73232..b9b1b4c 100644
--- a/include/sound/soc.h
+++ b/include/sound/soc.h
@@ -853,6 +853,7 @@ struct snd_soc_component {
unsigned int ignore_pmdown_time:1; /* pmdown_time is ignored at stop */
unsigned int registered_as_component:1;
unsigned int suspended:1; /* is in suspend PM state */
+ unsigned int alloced_component:1;
struct list_head list;
struct list_head card_aux_list; /* for auxiliary bound components */
diff --git a/sound/soc/soc-core.c b/sound/soc/soc-core.c
index c0edac8..0e33bcf 100644
--- a/sound/soc/soc-core.c
+++ b/sound/soc/soc-core.c
@@ -3492,6 +3492,7 @@ int snd_soc_register_component(struct device *dev,
if (!component)
return -ENOMEM;
+ component->alloced_component = 1;
return snd_soc_add_component(dev, component, component_driver,
dai_drv, num_dai);
}
@@ -3523,7 +3524,9 @@ static int __snd_soc_unregister_component(struct device *dev)
if (found) {
snd_soc_component_cleanup(component);
- kfree(component);
+
+ if (component->alloced_component)
+ kfree(component);
}
return found;
------------------------
^ permalink raw reply related [flat|nested] 29+ messages in thread
* Re: [BUG] Kernel crash on Allwinner H3 due to sound core changes
@ 2018-03-08 1:21 ` Kuninori Morimoto
0 siblings, 0 replies; 29+ messages in thread
From: Kuninori Morimoto @ 2018-03-08 1:21 UTC (permalink / raw)
To: Jernej Škrabec
Cc: alsa-devel, linux-kernel, wens, Mark Brown, maxime.ripard,
linux-arm-kernel
Hi Jernej
Thank you for your hard work
> I found the issue. Commit be7ee5f32a9a ("ASoC: soc-generic-dmaengine-pcm:
> replace platform to component") changes struct dmaengine_pcm:
>
> struct dmaengine_pcm {
> struct dma_chan *chan[SNDRV_PCM_STREAM_LAST + 1];
> const struct snd_dmaengine_pcm_config *config;
> - struct snd_soc_platform platform;
> + struct snd_soc_component component;
> unsigned int flags;
> };
>
> In snd_dmaengine_pcm_register():
> ret = snd_soc_add_component(dev, &pcm->component,
> &dmaengine_pcm_component, NULL, 0);
>
> And now, sun4i-codec first time returns -EPROBE_DEFER since driver for analog
> part is not yet loaded. Because of that, all components get destroyed.
>
> snd_dmaengine_pcm_unregister() calls snd_soc_unregister_component() and that
> one calls __snd_soc_unregister_component() multiple times (until it fails).
>
> Issue is that __snd_soc_unregister_component() uses kfree() on component
> pointer and that naturally can't succed since component was never kmalloc'ed
> since it is a part of a bigger structure - struct dmaengine_pcm.
>
> What would be the best fix? Changing struct dmaengine_pcm to have pointer to a
> component, so it can be freed?
Ahh.. indeed. Good catch !
How about to add such flag ?
This is just idea. No tested, No compiled, but can help you ?
One note here is that reusing "registered_as_component" flag is
not good idea, because it will be removed
when platform/codec were removed
------------------------
diff --git a/include/sound/soc.h b/include/sound/soc.h
index 1a73232..b9b1b4c 100644
--- a/include/sound/soc.h
+++ b/include/sound/soc.h
@@ -853,6 +853,7 @@ struct snd_soc_component {
unsigned int ignore_pmdown_time:1; /* pmdown_time is ignored at stop */
unsigned int registered_as_component:1;
unsigned int suspended:1; /* is in suspend PM state */
+ unsigned int alloced_component:1;
struct list_head list;
struct list_head card_aux_list; /* for auxiliary bound components */
diff --git a/sound/soc/soc-core.c b/sound/soc/soc-core.c
index c0edac8..0e33bcf 100644
--- a/sound/soc/soc-core.c
+++ b/sound/soc/soc-core.c
@@ -3492,6 +3492,7 @@ int snd_soc_register_component(struct device *dev,
if (!component)
return -ENOMEM;
+ component->alloced_component = 1;
return snd_soc_add_component(dev, component, component_driver,
dai_drv, num_dai);
}
@@ -3523,7 +3524,9 @@ static int __snd_soc_unregister_component(struct device *dev)
if (found) {
snd_soc_component_cleanup(component);
- kfree(component);
+
+ if (component->alloced_component)
+ kfree(component);
}
return found;
------------------------
^ permalink raw reply related [flat|nested] 29+ messages in thread
* Re: [alsa-devel] [BUG] Kernel crash on Allwinner H3 due to sound core changes
2018-03-08 1:21 ` Kuninori Morimoto
(?)
@ 2018-03-08 6:03 ` Jernej Škrabec
-1 siblings, 0 replies; 29+ messages in thread
From: Jernej Škrabec @ 2018-03-08 6:03 UTC (permalink / raw)
To: alsa-devel
Cc: Kuninori Morimoto, linux-kernel, wens, Mark Brown, maxime.ripard,
linux-arm-kernel
Hi,
Thank you for looking into it so quickly.
Dne četrtek, 08. marec 2018 ob 02:21:02 CET je Kuninori Morimoto napisal(a):
> Hi Jernej
>
> Thank you for your hard work
>
> > I found the issue. Commit be7ee5f32a9a ("ASoC: soc-generic-dmaengine-pcm:
> >
> > replace platform to component") changes struct dmaengine_pcm:
> > struct dmaengine_pcm {
> >
> > struct dma_chan *chan[SNDRV_PCM_STREAM_LAST + 1];
> > const struct snd_dmaengine_pcm_config *config;
> >
> > - struct snd_soc_platform platform;
> > + struct snd_soc_component component;
> >
> > unsigned int flags;
> >
> > };
> >
> > In snd_dmaengine_pcm_register():
> > ret = snd_soc_add_component(dev, &pcm->component,
> >
> > &dmaengine_pcm_component, NULL, 0);
> >
> > And now, sun4i-codec first time returns -EPROBE_DEFER since driver for
> > analog part is not yet loaded. Because of that, all components get
> > destroyed.
> >
> > snd_dmaengine_pcm_unregister() calls snd_soc_unregister_component() and
> > that one calls __snd_soc_unregister_component() multiple times (until it
> > fails).
> >
> > Issue is that __snd_soc_unregister_component() uses kfree() on component
> > pointer and that naturally can't succed since component was never
> > kmalloc'ed since it is a part of a bigger structure - struct
> > dmaengine_pcm.
> >
> > What would be the best fix? Changing struct dmaengine_pcm to have pointer
> > to a component, so it can be freed?
>
> Ahh.. indeed. Good catch !
> How about to add such flag ?
> This is just idea. No tested, No compiled, but can help you ?
>
> One note here is that reusing "registered_as_component" flag is
> not good idea, because it will be removed
> when platform/codec were removed
>
> ------------------------
> diff --git a/include/sound/soc.h b/include/sound/soc.h
> index 1a73232..b9b1b4c 100644
> --- a/include/sound/soc.h
> +++ b/include/sound/soc.h
> @@ -853,6 +853,7 @@ struct snd_soc_component {
> unsigned int ignore_pmdown_time:1; /* pmdown_time is ignored at stop */
> unsigned int registered_as_component:1;
> unsigned int suspended:1; /* is in suspend PM state */
> + unsigned int alloced_component:1;
>
> struct list_head list;
> struct list_head card_aux_list; /* for auxiliary bound components */
> diff --git a/sound/soc/soc-core.c b/sound/soc/soc-core.c
> index c0edac8..0e33bcf 100644
> --- a/sound/soc/soc-core.c
> +++ b/sound/soc/soc-core.c
> @@ -3492,6 +3492,7 @@ int snd_soc_register_component(struct device *dev,
> if (!component)
> return -ENOMEM;
>
> + component->alloced_component = 1;
> return snd_soc_add_component(dev, component, component_driver,
> dai_drv, num_dai);
> }
> @@ -3523,7 +3524,9 @@ static int __snd_soc_unregister_component(struct
> device *dev)
>
> if (found) {
> snd_soc_component_cleanup(component);
> - kfree(component);
> +
> + if (component->alloced_component)
> + kfree(component);
> }
>
> return found;
> ------------------------
I tested this patch and there is no crash anymore. If you will send it as a
fix, you can add:
Reported-by: Jernej Skrabec <jernej.skrabec@siol.net>
Tested-by: Jernej Skrabec <jernej.skrabec@siol.net>
Best regards,
Jernej
^ permalink raw reply [flat|nested] 29+ messages in thread
* [alsa-devel] [BUG] Kernel crash on Allwinner H3 due to sound core changes
@ 2018-03-08 6:03 ` Jernej Škrabec
0 siblings, 0 replies; 29+ messages in thread
From: Jernej Škrabec @ 2018-03-08 6:03 UTC (permalink / raw)
To: linux-arm-kernel
Hi,
Thank you for looking into it so quickly.
Dne ?etrtek, 08. marec 2018 ob 02:21:02 CET je Kuninori Morimoto napisal(a):
> Hi Jernej
>
> Thank you for your hard work
>
> > I found the issue. Commit be7ee5f32a9a ("ASoC: soc-generic-dmaengine-pcm:
> >
> > replace platform to component") changes struct dmaengine_pcm:
> > struct dmaengine_pcm {
> >
> > struct dma_chan *chan[SNDRV_PCM_STREAM_LAST + 1];
> > const struct snd_dmaengine_pcm_config *config;
> >
> > - struct snd_soc_platform platform;
> > + struct snd_soc_component component;
> >
> > unsigned int flags;
> >
> > };
> >
> > In snd_dmaengine_pcm_register():
> > ret = snd_soc_add_component(dev, &pcm->component,
> >
> > &dmaengine_pcm_component, NULL, 0);
> >
> > And now, sun4i-codec first time returns -EPROBE_DEFER since driver for
> > analog part is not yet loaded. Because of that, all components get
> > destroyed.
> >
> > snd_dmaengine_pcm_unregister() calls snd_soc_unregister_component() and
> > that one calls __snd_soc_unregister_component() multiple times (until it
> > fails).
> >
> > Issue is that __snd_soc_unregister_component() uses kfree() on component
> > pointer and that naturally can't succed since component was never
> > kmalloc'ed since it is a part of a bigger structure - struct
> > dmaengine_pcm.
> >
> > What would be the best fix? Changing struct dmaengine_pcm to have pointer
> > to a component, so it can be freed?
>
> Ahh.. indeed. Good catch !
> How about to add such flag ?
> This is just idea. No tested, No compiled, but can help you ?
>
> One note here is that reusing "registered_as_component" flag is
> not good idea, because it will be removed
> when platform/codec were removed
>
> ------------------------
> diff --git a/include/sound/soc.h b/include/sound/soc.h
> index 1a73232..b9b1b4c 100644
> --- a/include/sound/soc.h
> +++ b/include/sound/soc.h
> @@ -853,6 +853,7 @@ struct snd_soc_component {
> unsigned int ignore_pmdown_time:1; /* pmdown_time is ignored at stop */
> unsigned int registered_as_component:1;
> unsigned int suspended:1; /* is in suspend PM state */
> + unsigned int alloced_component:1;
>
> struct list_head list;
> struct list_head card_aux_list; /* for auxiliary bound components */
> diff --git a/sound/soc/soc-core.c b/sound/soc/soc-core.c
> index c0edac8..0e33bcf 100644
> --- a/sound/soc/soc-core.c
> +++ b/sound/soc/soc-core.c
> @@ -3492,6 +3492,7 @@ int snd_soc_register_component(struct device *dev,
> if (!component)
> return -ENOMEM;
>
> + component->alloced_component = 1;
> return snd_soc_add_component(dev, component, component_driver,
> dai_drv, num_dai);
> }
> @@ -3523,7 +3524,9 @@ static int __snd_soc_unregister_component(struct
> device *dev)
>
> if (found) {
> snd_soc_component_cleanup(component);
> - kfree(component);
> +
> + if (component->alloced_component)
> + kfree(component);
> }
>
> return found;
> ------------------------
I tested this patch and there is no crash anymore. If you will send it as a
fix, you can add:
Reported-by: Jernej Skrabec <jernej.skrabec@siol.net>
Tested-by: Jernej Skrabec <jernej.skrabec@siol.net>
Best regards,
Jernej
^ permalink raw reply [flat|nested] 29+ messages in thread
* Re: [BUG] Kernel crash on Allwinner H3 due to sound core changes
@ 2018-03-08 6:03 ` Jernej Škrabec
0 siblings, 0 replies; 29+ messages in thread
From: Jernej Škrabec @ 2018-03-08 6:03 UTC (permalink / raw)
To: alsa-devel
Cc: Kuninori Morimoto, linux-kernel, wens, Mark Brown, maxime.ripard,
linux-arm-kernel
Hi,
Thank you for looking into it so quickly.
Dne četrtek, 08. marec 2018 ob 02:21:02 CET je Kuninori Morimoto napisal(a):
> Hi Jernej
>
> Thank you for your hard work
>
> > I found the issue. Commit be7ee5f32a9a ("ASoC: soc-generic-dmaengine-pcm:
> >
> > replace platform to component") changes struct dmaengine_pcm:
> > struct dmaengine_pcm {
> >
> > struct dma_chan *chan[SNDRV_PCM_STREAM_LAST + 1];
> > const struct snd_dmaengine_pcm_config *config;
> >
> > - struct snd_soc_platform platform;
> > + struct snd_soc_component component;
> >
> > unsigned int flags;
> >
> > };
> >
> > In snd_dmaengine_pcm_register():
> > ret = snd_soc_add_component(dev, &pcm->component,
> >
> > &dmaengine_pcm_component, NULL, 0);
> >
> > And now, sun4i-codec first time returns -EPROBE_DEFER since driver for
> > analog part is not yet loaded. Because of that, all components get
> > destroyed.
> >
> > snd_dmaengine_pcm_unregister() calls snd_soc_unregister_component() and
> > that one calls __snd_soc_unregister_component() multiple times (until it
> > fails).
> >
> > Issue is that __snd_soc_unregister_component() uses kfree() on component
> > pointer and that naturally can't succed since component was never
> > kmalloc'ed since it is a part of a bigger structure - struct
> > dmaengine_pcm.
> >
> > What would be the best fix? Changing struct dmaengine_pcm to have pointer
> > to a component, so it can be freed?
>
> Ahh.. indeed. Good catch !
> How about to add such flag ?
> This is just idea. No tested, No compiled, but can help you ?
>
> One note here is that reusing "registered_as_component" flag is
> not good idea, because it will be removed
> when platform/codec were removed
>
> ------------------------
> diff --git a/include/sound/soc.h b/include/sound/soc.h
> index 1a73232..b9b1b4c 100644
> --- a/include/sound/soc.h
> +++ b/include/sound/soc.h
> @@ -853,6 +853,7 @@ struct snd_soc_component {
> unsigned int ignore_pmdown_time:1; /* pmdown_time is ignored at stop */
> unsigned int registered_as_component:1;
> unsigned int suspended:1; /* is in suspend PM state */
> + unsigned int alloced_component:1;
>
> struct list_head list;
> struct list_head card_aux_list; /* for auxiliary bound components */
> diff --git a/sound/soc/soc-core.c b/sound/soc/soc-core.c
> index c0edac8..0e33bcf 100644
> --- a/sound/soc/soc-core.c
> +++ b/sound/soc/soc-core.c
> @@ -3492,6 +3492,7 @@ int snd_soc_register_component(struct device *dev,
> if (!component)
> return -ENOMEM;
>
> + component->alloced_component = 1;
> return snd_soc_add_component(dev, component, component_driver,
> dai_drv, num_dai);
> }
> @@ -3523,7 +3524,9 @@ static int __snd_soc_unregister_component(struct
> device *dev)
>
> if (found) {
> snd_soc_component_cleanup(component);
> - kfree(component);
> +
> + if (component->alloced_component)
> + kfree(component);
> }
>
> return found;
> ------------------------
I tested this patch and there is no crash anymore. If you will send it as a
fix, you can add:
Reported-by: Jernej Skrabec <jernej.skrabec@siol.net>
Tested-by: Jernej Skrabec <jernej.skrabec@siol.net>
Best regards,
Jernej
_______________________________________________
Alsa-devel mailing list
Alsa-devel@alsa-project.org
http://mailman.alsa-project.org/mailman/listinfo/alsa-devel
^ permalink raw reply [flat|nested] 29+ messages in thread
* Re: [BUG] Kernel crash on Allwinner H3 due to sound core changes
2018-03-08 1:21 ` Kuninori Morimoto
` (2 preceding siblings ...)
(?)
@ 2018-03-08 11:13 ` Mark Brown
2018-03-08 23:49 ` Kuninori Morimoto
-1 siblings, 1 reply; 29+ messages in thread
From: Mark Brown @ 2018-03-08 11:13 UTC (permalink / raw)
To: Kuninori Morimoto
Cc: Jernej Škrabec, maxime.ripard, wens, linux-arm-kernel,
linux-kernel, alsa-devel
[-- Attachment #1: Type: text/plain, Size: 366 bytes --]
On Thu, Mar 08, 2018 at 01:21:02AM +0000, Kuninori Morimoto wrote:
> Ahh.. indeed. Good catch !
> How about to add such flag ?
> This is just idea. No tested, No compiled, but can help you ?
I think this makes sense as a patch. We might want to disallow
allocating components as part of a bigger struct so everything is more
consistent but that's a bigger thing.
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]
^ permalink raw reply [flat|nested] 29+ messages in thread
* Re: [BUG] Kernel crash on Allwinner H3 due to sound core changes
2018-03-08 11:13 ` Mark Brown
@ 2018-03-08 23:49 ` Kuninori Morimoto
0 siblings, 0 replies; 29+ messages in thread
From: Kuninori Morimoto @ 2018-03-08 23:49 UTC (permalink / raw)
To: Mark Brown
Cc: Jernej Škrabec, maxime.ripard, wens, linux-arm-kernel,
linux-kernel, alsa-devel
Hi Mark,Jernej
> > Ahh.. indeed. Good catch !
> > How about to add such flag ?
> > This is just idea. No tested, No compiled, but can help you ?
>
> I think this makes sense as a patch. We might want to disallow
> allocating components as part of a bigger struct so everything is more
> consistent but that's a bigger thing.
(snip)
> I tested this patch and there is no crash anymore. If you will send it as a
> fix, you can add:
>
> Reported-by: Jernej Skrabec <jernej.skrabec@siol.net>
> Tested-by: Jernej Skrabec <jernej.skrabec@siol.net>
previous my patch used new flag (= .alloced_component),
but I think it is not good idea.
And I noticed that snd_soc_add_component() is
also calling kfree(component) (= has same bug).
So how about below one ?
I want to post it instead of previous.
# I will go to ELC next week, thus posting patch will be
# 2weeks later
------------
diff --git a/sound/soc/soc-core.c b/sound/soc/soc-core.c
index c0edac8..4a8de23 100644
--- a/sound/soc/soc-core.c
+++ b/sound/soc/soc-core.c
@@ -3476,7 +3476,6 @@ int snd_soc_add_component(struct device *dev,
err_cleanup:
snd_soc_component_cleanup(component);
err_free:
- kfree(component);
return ret;
}
EXPORT_SYMBOL_GPL(snd_soc_add_component);
@@ -3488,7 +3487,7 @@ int snd_soc_register_component(struct device *dev,
{
struct snd_soc_component *component;
- component = kzalloc(sizeof(*component), GFP_KERNEL);
+ component = devm_kzalloc(dev, sizeof(*component), GFP_KERNEL);
if (!component)
return -ENOMEM;
@@ -3523,7 +3522,6 @@ static int __snd_soc_unregister_component(struct device *dev)
if (found) {
snd_soc_component_cleanup(component);
- kfree(component);
}
return found;
------------
^ permalink raw reply related [flat|nested] 29+ messages in thread
* [BUG] Kernel crash on Allwinner H3 due to sound core changes
@ 2018-03-08 23:49 ` Kuninori Morimoto
0 siblings, 0 replies; 29+ messages in thread
From: Kuninori Morimoto @ 2018-03-08 23:49 UTC (permalink / raw)
To: linux-arm-kernel
Hi Mark,Jernej
> > Ahh.. indeed. Good catch !
> > How about to add such flag ?
> > This is just idea. No tested, No compiled, but can help you ?
>
> I think this makes sense as a patch. We might want to disallow
> allocating components as part of a bigger struct so everything is more
> consistent but that's a bigger thing.
(snip)
> I tested this patch and there is no crash anymore. If you will send it as a
> fix, you can add:
>
> Reported-by: Jernej Skrabec <jernej.skrabec@siol.net>
> Tested-by: Jernej Skrabec <jernej.skrabec@siol.net>
previous my patch used new flag (= .alloced_component),
but I think it is not good idea.
And I noticed that snd_soc_add_component() is
also calling kfree(component) (= has same bug).
So how about below one ?
I want to post it instead of previous.
# I will go to ELC next week, thus posting patch will be
# 2weeks later
------------
diff --git a/sound/soc/soc-core.c b/sound/soc/soc-core.c
index c0edac8..4a8de23 100644
--- a/sound/soc/soc-core.c
+++ b/sound/soc/soc-core.c
@@ -3476,7 +3476,6 @@ int snd_soc_add_component(struct device *dev,
err_cleanup:
snd_soc_component_cleanup(component);
err_free:
- kfree(component);
return ret;
}
EXPORT_SYMBOL_GPL(snd_soc_add_component);
@@ -3488,7 +3487,7 @@ int snd_soc_register_component(struct device *dev,
{
struct snd_soc_component *component;
- component = kzalloc(sizeof(*component), GFP_KERNEL);
+ component = devm_kzalloc(dev, sizeof(*component), GFP_KERNEL);
if (!component)
return -ENOMEM;
@@ -3523,7 +3522,6 @@ static int __snd_soc_unregister_component(struct device *dev)
if (found) {
snd_soc_component_cleanup(component);
- kfree(component);
}
return found;
------------
^ permalink raw reply related [flat|nested] 29+ messages in thread
* Re: [alsa-devel] [BUG] Kernel crash on Allwinner H3 due to sound core changes
2018-03-08 23:49 ` Kuninori Morimoto
@ 2018-03-09 6:33 ` Jernej Škrabec
-1 siblings, 0 replies; 29+ messages in thread
From: Jernej Škrabec @ 2018-03-09 6:33 UTC (permalink / raw)
To: alsa-devel
Cc: Kuninori Morimoto, Mark Brown, linux-kernel, wens, maxime.ripard,
linux-arm-kernel
Hi,
Dne petek, 09. marec 2018 ob 00:49:18 CET je Kuninori Morimoto napisal(a):
> Hi Mark,Jernej
>
> > > Ahh.. indeed. Good catch !
> > > How about to add such flag ?
> > > This is just idea. No tested, No compiled, but can help you ?
> >
> > I think this makes sense as a patch. We might want to disallow
> > allocating components as part of a bigger struct so everything is more
> > consistent but that's a bigger thing.
>
> (snip)
>
> > I tested this patch and there is no crash anymore. If you will send it as
> > a
> > fix, you can add:
> >
> > Reported-by: Jernej Skrabec <jernej.skrabec@siol.net>
> > Tested-by: Jernej Skrabec <jernej.skrabec@siol.net>
>
> previous my patch used new flag (= .alloced_component),
> but I think it is not good idea.
> And I noticed that snd_soc_add_component() is
> also calling kfree(component) (= has same bug).
>
> So how about below one ?
> I want to post it instead of previous.
>
> # I will go to ELC next week, thus posting patch will be
> # 2weeks later
>
> ------------
> diff --git a/sound/soc/soc-core.c b/sound/soc/soc-core.c
> index c0edac8..4a8de23 100644
> --- a/sound/soc/soc-core.c
> +++ b/sound/soc/soc-core.c
> @@ -3476,7 +3476,6 @@ int snd_soc_add_component(struct device *dev,
> err_cleanup:
> snd_soc_component_cleanup(component);
> err_free:
> - kfree(component);
> return ret;
> }
> EXPORT_SYMBOL_GPL(snd_soc_add_component);
> @@ -3488,7 +3487,7 @@ int snd_soc_register_component(struct device *dev,
> {
> struct snd_soc_component *component;
>
> - component = kzalloc(sizeof(*component), GFP_KERNEL);
> + component = devm_kzalloc(dev, sizeof(*component), GFP_KERNEL);
> if (!component)
> return -ENOMEM;
>
> @@ -3523,7 +3522,6 @@ static int __snd_soc_unregister_component(struct
> device *dev)
>
> if (found) {
> snd_soc_component_cleanup(component);
> - kfree(component);
> }
>
> return found;
That patch also prevents the crash, so you can add my tested-by and reported-
by tags for this patch too.
Best regards,
Jernej
^ permalink raw reply [flat|nested] 29+ messages in thread
* [alsa-devel] [BUG] Kernel crash on Allwinner H3 due to sound core changes
@ 2018-03-09 6:33 ` Jernej Škrabec
0 siblings, 0 replies; 29+ messages in thread
From: Jernej Škrabec @ 2018-03-09 6:33 UTC (permalink / raw)
To: linux-arm-kernel
Hi,
Dne petek, 09. marec 2018 ob 00:49:18 CET je Kuninori Morimoto napisal(a):
> Hi Mark,Jernej
>
> > > Ahh.. indeed. Good catch !
> > > How about to add such flag ?
> > > This is just idea. No tested, No compiled, but can help you ?
> >
> > I think this makes sense as a patch. We might want to disallow
> > allocating components as part of a bigger struct so everything is more
> > consistent but that's a bigger thing.
>
> (snip)
>
> > I tested this patch and there is no crash anymore. If you will send it as
> > a
> > fix, you can add:
> >
> > Reported-by: Jernej Skrabec <jernej.skrabec@siol.net>
> > Tested-by: Jernej Skrabec <jernej.skrabec@siol.net>
>
> previous my patch used new flag (= .alloced_component),
> but I think it is not good idea.
> And I noticed that snd_soc_add_component() is
> also calling kfree(component) (= has same bug).
>
> So how about below one ?
> I want to post it instead of previous.
>
> # I will go to ELC next week, thus posting patch will be
> # 2weeks later
>
> ------------
> diff --git a/sound/soc/soc-core.c b/sound/soc/soc-core.c
> index c0edac8..4a8de23 100644
> --- a/sound/soc/soc-core.c
> +++ b/sound/soc/soc-core.c
> @@ -3476,7 +3476,6 @@ int snd_soc_add_component(struct device *dev,
> err_cleanup:
> snd_soc_component_cleanup(component);
> err_free:
> - kfree(component);
> return ret;
> }
> EXPORT_SYMBOL_GPL(snd_soc_add_component);
> @@ -3488,7 +3487,7 @@ int snd_soc_register_component(struct device *dev,
> {
> struct snd_soc_component *component;
>
> - component = kzalloc(sizeof(*component), GFP_KERNEL);
> + component = devm_kzalloc(dev, sizeof(*component), GFP_KERNEL);
> if (!component)
> return -ENOMEM;
>
> @@ -3523,7 +3522,6 @@ static int __snd_soc_unregister_component(struct
> device *dev)
>
> if (found) {
> snd_soc_component_cleanup(component);
> - kfree(component);
> }
>
> return found;
That patch also prevents the crash, so you can add my tested-by and reported-
by tags for this patch too.
Best regards,
Jernej
^ permalink raw reply [flat|nested] 29+ messages in thread
* Re: [BUG] Kernel crash on Allwinner H3 due to sound core changes
2018-03-08 23:49 ` Kuninori Morimoto
@ 2018-03-09 11:14 ` Mark Brown
-1 siblings, 0 replies; 29+ messages in thread
From: Mark Brown @ 2018-03-09 11:14 UTC (permalink / raw)
To: Kuninori Morimoto
Cc: Jernej Škrabec, maxime.ripard, wens, linux-arm-kernel,
linux-kernel, alsa-devel
[-- Attachment #1: Type: text/plain, Size: 453 bytes --]
On Thu, Mar 08, 2018 at 11:49:18PM +0000, Kuninori Morimoto wrote:
> previous my patch used new flag (= .alloced_component),
> but I think it is not good idea.
> And I noticed that snd_soc_add_component() is
> also calling kfree(component) (= has same bug).
> So how about below one ?
> I want to post it instead of previous.
That should work also.
> # I will go to ELC next week, thus posting patch will be
> # 2weeks later
I'll be there as well.
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]
^ permalink raw reply [flat|nested] 29+ messages in thread
* Applied "soc-core: don't call kfree() for component" to the asoc tree
2018-03-08 23:49 ` Kuninori Morimoto
@ 2018-03-19 8:08 ` Mark Brown
-1 siblings, 0 replies; 29+ messages in thread
From: Mark Brown @ 2018-03-19 8:08 UTC (permalink / raw)
To: Kuninori Morimoto
Cc: Jernej Skrabec, Jernej Skrabec, Mark Brown, Mark Brown,
alsa-devel, Jernej Škrabec, linux-kernel, wens,
maxime.ripard, linux-arm-kernel, alsa-devel
The patch
soc-core: don't call kfree() for component
has been applied to the asoc tree at
https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound.git
All being well this means that it will be integrated into the linux-next
tree (usually sometime in the next 24 hours) and sent to Linus during
the next merge window (or sooner if it is a bug fix), however if
problems are discovered then the patch may be dropped or reverted.
You may get further e-mails resulting from automated or manual testing
and review of the tree, please engage with people reporting problems and
send followup patches addressing any issues that are reported if needed.
If any updates are required or you are submitting further changes they
should be sent as incremental updates against current git, existing
patches will not be replaced.
Please add any relevant lists and maintainers to the CCs when replying
to this mail.
Thanks,
Mark
>From 7ecbd6a91b1e9bb90a4f3be641669347aacc5ab5 Mon Sep 17 00:00:00 2001
From: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
Date: Mon, 19 Mar 2018 07:27:17 +0000
Subject: [PATCH] soc-core: don't call kfree() for component
When driver register its component to ALSA SoC, almost all drivers are
using snd_soc_register_component(), but soc-generic-dmaengine-pcm is
using snd_soc_add_component().
Existing component function had been assumed that registered component
was allocated, and it calling kfree() for it.
But, the user who used snd_soc_add_component() doesn't.
This patch uses devm_kzalloc() instead of kzalloc() for component,
and doesn't call kree() anymore.
This patch fixes commit be7ee5f32a9a ("ASoC: soc-generic-dmaengine-pcm:
replace platform to component").
Allwinner H3 SoC will crash without this patch.
Thanks Jernej report.
Reported-by: Jernej Skrabec <jernej.skrabec@siol.net>
Signed-off-by: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
Tested-by: Jernej Skrabec <jernej.skrabec@siol.net>
Signed-off-by: Mark Brown <broonie@kernel.org>
---
sound/soc/soc-core.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/sound/soc/soc-core.c b/sound/soc/soc-core.c
index 9558125b448d..8b1ef90f7b57 100644
--- a/sound/soc/soc-core.c
+++ b/sound/soc/soc-core.c
@@ -3454,7 +3454,6 @@ int snd_soc_add_component(struct device *dev,
err_cleanup:
snd_soc_component_cleanup(component);
err_free:
- kfree(component);
return ret;
}
EXPORT_SYMBOL_GPL(snd_soc_add_component);
@@ -3466,7 +3465,7 @@ int snd_soc_register_component(struct device *dev,
{
struct snd_soc_component *component;
- component = kzalloc(sizeof(*component), GFP_KERNEL);
+ component = devm_kzalloc(dev, sizeof(*component), GFP_KERNEL);
if (!component)
return -ENOMEM;
@@ -3501,7 +3500,6 @@ static int __snd_soc_unregister_component(struct device *dev)
if (found) {
snd_soc_component_cleanup(component);
- kfree(component);
}
return found;
--
2.16.2
^ permalink raw reply related [flat|nested] 29+ messages in thread
* Applied "soc-core: don't call kfree() for component" to the asoc tree
@ 2018-03-19 8:08 ` Mark Brown
0 siblings, 0 replies; 29+ messages in thread
From: Mark Brown @ 2018-03-19 8:08 UTC (permalink / raw)
To: Kuninori Morimoto; +Cc: Jernej Skrabec
The patch
soc-core: don't call kfree() for component
has been applied to the asoc tree at
https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound.git
All being well this means that it will be integrated into the linux-next
tree (usually sometime in the next 24 hours) and sent to Linus during
the next merge window (or sooner if it is a bug fix), however if
problems are discovered then the patch may be dropped or reverted.
You may get further e-mails resulting from automated or manual testing
and review of the tree, please engage with people reporting problems and
send followup patches addressing any issues that are reported if needed.
If any updates are required or you are submitting further changes they
should be sent as incremental updates against current git, existing
patches will not be replaced.
Please add any relevant lists and maintainers to the CCs when replying
to this mail.
Thanks,
Mark
>From 7ecbd6a91b1e9bb90a4f3be641669347aacc5ab5 Mon Sep 17 00:00:00 2001
From: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
Date: Mon, 19 Mar 2018 07:27:17 +0000
Subject: [PATCH] soc-core: don't call kfree() for component
When driver register its component to ALSA SoC, almost all drivers are
using snd_soc_register_component(), but soc-generic-dmaengine-pcm is
using snd_soc_add_component().
Existing component function had been assumed that registered component
was allocated, and it calling kfree() for it.
But, the user who used snd_soc_add_component() doesn't.
This patch uses devm_kzalloc() instead of kzalloc() for component,
and doesn't call kree() anymore.
This patch fixes commit be7ee5f32a9a ("ASoC: soc-generic-dmaengine-pcm:
replace platform to component").
Allwinner H3 SoC will crash without this patch.
Thanks Jernej report.
Reported-by: Jernej Skrabec <jernej.skrabec@siol.net>
Signed-off-by: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
Tested-by: Jernej Skrabec <jernej.skrabec@siol.net>
Signed-off-by: Mark Brown <broonie@kernel.org>
---
sound/soc/soc-core.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/sound/soc/soc-core.c b/sound/soc/soc-core.c
index 9558125b448d..8b1ef90f7b57 100644
--- a/sound/soc/soc-core.c
+++ b/sound/soc/soc-core.c
@@ -3454,7 +3454,6 @@ int snd_soc_add_component(struct device *dev,
err_cleanup:
snd_soc_component_cleanup(component);
err_free:
- kfree(component);
return ret;
}
EXPORT_SYMBOL_GPL(snd_soc_add_component);
@@ -3466,7 +3465,7 @@ int snd_soc_register_component(struct device *dev,
{
struct snd_soc_component *component;
- component = kzalloc(sizeof(*component), GFP_KERNEL);
+ component = devm_kzalloc(dev, sizeof(*component), GFP_KERNEL);
if (!component)
return -ENOMEM;
@@ -3501,7 +3500,6 @@ static int __snd_soc_unregister_component(struct device *dev)
if (found) {
snd_soc_component_cleanup(component);
- kfree(component);
}
return found;
--
2.16.2
^ permalink raw reply related [flat|nested] 29+ messages in thread