From patchwork Mon Feb 8 12:01:03 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: =?utf-8?q?Marcin_=C5=9Alusarz?= X-Patchwork-Id: 12075245 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-13.7 required=3.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED,DKIM_SIGNED,DKIM_VALID,FREEMAIL_FORGED_FROMDOMAIN, FREEMAIL_FROM,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_CR_TRAILER, INCLUDES_PATCH,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED, USER_AGENT_GIT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 21282C433E6 for ; Mon, 8 Feb 2021 12:02:15 +0000 (UTC) Received: from alsa0.perex.cz (alsa0.perex.cz [77.48.224.243]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 1998364E76 for ; Mon, 8 Feb 2021 12:02:13 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 1998364E76 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=alsa-devel-bounces@alsa-project.org Received: from alsa1.perex.cz (alsa1.perex.cz [207.180.221.201]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by alsa0.perex.cz (Postfix) with ESMTPS id E89B286E; Mon, 8 Feb 2021 13:01:21 +0100 (CET) DKIM-Filter: OpenDKIM Filter v2.11.0 alsa0.perex.cz E89B286E DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=alsa-project.org; s=default; t=1612785732; bh=tuTZ3FulAH/r/u2wdwApVs3TQMLKRQjAgg2Y5Vwk8EQ=; h=From:To:Subject:Date:In-Reply-To:References:Cc:List-Id: List-Unsubscribe:List-Archive:List-Post:List-Help:List-Subscribe: From; b=ajrr4X0usKvtRETuCPDDSONGrj9S86T2YvYqWEt1DGi83cng2apXgB2c5iGxz5Pf7 ttFeZ/iG5lgfbkGxe+OtnnHFzmtOyqvcgMNM2xEGbHia8QyXAAJ0z7ei29VKReyqps k5MqYQj3BlRxvcBAEjA4V9XyuKukHY25WRIocUC4= Received: from alsa1.perex.cz (localhost.localdomain [127.0.0.1]) by alsa1.perex.cz (Postfix) with ESMTP id 6E0A8F8013A; Mon, 8 Feb 2021 13:01:21 +0100 (CET) Received: by alsa1.perex.cz (Postfix, from userid 50401) id CA37AF8022D; Mon, 8 Feb 2021 13:01:19 +0100 (CET) Received: from mail-lj1-x229.google.com (mail-lj1-x229.google.com [IPv6:2a00:1450:4864:20::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by alsa1.perex.cz (Postfix) with ESMTPS id 21E88F80114 for ; Mon, 8 Feb 2021 13:01:12 +0100 (CET) DKIM-Filter: OpenDKIM Filter v2.11.0 alsa1.perex.cz 21E88F80114 Authentication-Results: alsa1.perex.cz; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="dbyIRxu9" Received: by mail-lj1-x229.google.com with SMTP id a25so16671224ljn.0 for ; Mon, 08 Feb 2021 04:01:12 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=gpqaC8q+dDCiC/7z/gO4zBXqcNiiB51jlwzypuvmhz4=; b=dbyIRxu9Elntvw/tICXuJL2fE7et4as4CfMEcZiRUJ/gnbaIHqR9LEKUq2GkdFjXw8 Dg7cFh9yZnd/kmDfR8tvHHgwhuEsZVLbnX3FEN9TbdpI9Hyht2n1EkCa3C6ouX1ma3KQ ExBgXuKigCVbUoClaaGWyxB2b1LJ1da6bB5R9dTduGotrLuniAjJ0tVzx71VHOoi48zU hYY/R6LX8BbjI9EjqNLvHKN4tQIMGusSKvskfzFymlzNfuYSVJG7o4xy4R+uX7T5cZXc a7ReveIy4YRvJDdZ/gXRQjM2JCrp+DdB8sbkwHw6gmq+suq/WvfuyV5q7twmK0hoocW/ Fcig== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=gpqaC8q+dDCiC/7z/gO4zBXqcNiiB51jlwzypuvmhz4=; b=kMaRjhZ+xGbGWS1Q8P+tGXOjTEN+v8BDMmoriNWA9zBePyPFM7MGxkV3qMebk19+bq eHA2HxFMH4LiSn4jxi6Zq9tkk/vD2Hg3mjt8Q4bXZ0J5RQK4moYtON7Fhx43wbuNNnrp WhUuWYCOqB2FYhyVX9j64rjyYURipmpDbRQw35PZhcE2So1Z9PdxOi7OaUI2xUAMZ53E DPMlMiyoZ4oCfDxUIkp4IP9sdOVI8D1NoNLucPFM2WWxAq4cUXhT9pz4O8Cuq5Dr9hrE l8hedJPEQSL0p/M3GJc99h2pIouZV8CV1mh+xLyIlUQNPkQ67gy4ltc/2c1FNOKOKWv/ 3XTQ== X-Gm-Message-State: AOAM5338j7OQljBkxDUX2WHwlEBiTrCCx8hlr8xabNdbUKVO1YhABgN+ Giu8DsNl26zZWWjDZpfAEH5O19R67/xfpw== X-Google-Smtp-Source: ABdhPJwLCranmkEPlpkEV80x6Krw4T91MOjPD+rJNZqqEDaGa2bwb9utJcuBc4tfV+GQvDhihY9J3w== X-Received: by 2002:a2e:9b03:: with SMTP id u3mr503050lji.216.1612785671058; Mon, 08 Feb 2021 04:01:11 -0800 (PST) Received: from localhost.localdomain (109241203030.gdansk.vectranet.pl. [109.241.203.30]) by smtp.gmail.com with ESMTPSA id t15sm719086lft.239.2021.02.08.04.01.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 08 Feb 2021 04:01:10 -0800 (PST) From: =?utf-8?q?Marcin_=C5=9Alusarz?= To: alsa-devel@alsa-project.org, linux-acpi@vger.kernel.org Subject: [PATCH 1/2] soundwire: intel: fix possible crash when no device is detected Date: Mon, 8 Feb 2021 13:01:03 +0100 Message-Id: <20210208120104.204761-1-marcin.slusarz@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: References: MIME-Version: 1.0 Cc: marcin.slusarz@intel.com, Salvatore Bonaccorso , Pierre-Louis Bossart , "Rafael J. Wysocki" X-BeenThere: alsa-devel@alsa-project.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: "Alsa-devel mailing list for ALSA developers - http://www.alsa-project.org" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: alsa-devel-bounces@alsa-project.org Sender: "Alsa-devel" From: Marcin Ślusarz acpi_walk_namespace can return success without executing our callback which initializes info->handle. If the random value in this structure is a valid address (which is on the stack, so it's quite possible), then nothing bad will happen, because: sdw_intel_scan_controller -> acpi_bus_get_device -> acpi_get_device_data -> acpi_get_data_full -> acpi_ns_validate_handle will reject this handle. However, if the value from the stack doesn't point to a valid address, we get this: BUG: kernel NULL pointer dereference, address: 0000000000000050 PGD 0 P4D 0 Oops: 0000 [#1] SMP NOPTI CPU: 6 PID: 472 Comm: systemd-udevd Tainted: G W 5.10.0-1-amd64 #1 Debian 5.10.4-1 Hardware name: HP HP Pavilion Laptop 15-cs3xxx/86E2, BIOS F.05 01/01/2020 RIP: 0010:acpi_ns_validate_handle+0x1a/0x23 Code: 00 48 83 c4 10 5b 5d 41 5c 41 5d 41 5e 41 5f c3 0f 1f 44 00 00 48 8d 57 ff 48 89 f8 48 83 fa fd 76 08 48 8b 05 0c b8 67 01 c3 <80> 7f 08 0f 74 02 31 c0 c3 0f 1f 44 00 00 48 8b 3d f6 b7 67 01 e8 RSP: 0000:ffffc388807c7b20 EFLAGS: 00010213 RAX: 0000000000000048 RBX: ffffc388807c7b70 RCX: 0000000000000000 RDX: 0000000000000047 RSI: 0000000000000246 RDI: 0000000000000048 RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000 R10: ffffffffc0f5f4d1 R11: ffffffff8f0cb268 R12: 0000000000001001 R13: ffffffff8e33b160 R14: 0000000000000048 R15: 0000000000000000 FS: 00007f24548288c0(0000) GS:ffff9f781fb80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000050 CR3: 0000000106158004 CR4: 0000000000770ee0 PKRU: 55555554 Call Trace: acpi_get_data_full+0x4d/0x92 acpi_bus_get_device+0x1f/0x40 sdw_intel_acpi_scan+0x59/0x230 [soundwire_intel] ? strstr+0x22/0x60 ? dmi_matches+0x76/0xe0 snd_intel_dsp_driver_probe.cold+0xaf/0x163 [snd_intel_dspcfg] azx_probe+0x7a/0x970 [snd_hda_intel] local_pci_probe+0x42/0x80 ? _cond_resched+0x16/0x40 pci_device_probe+0xfd/0x1b0 really_probe+0x205/0x460 driver_probe_device+0xe1/0x150 device_driver_attach+0xa1/0xb0 __driver_attach+0x8a/0x150 ? device_driver_attach+0xb0/0xb0 ? device_driver_attach+0xb0/0xb0 bus_for_each_dev+0x78/0xc0 bus_add_driver+0x12b/0x1e0 driver_register+0x8b/0xe0 ? 0xffffffffc0f65000 do_one_initcall+0x44/0x1d0 ? do_init_module+0x23/0x250 ? kmem_cache_alloc_trace+0xf5/0x200 do_init_module+0x5c/0x250 __do_sys_finit_module+0xb1/0x110 do_syscall_64+0x33/0x80 entry_SYSCALL_64_after_hwframe+0x44/0xa9 CC: stable@vger.kernel.org Signed-off-by: Marcin Ślusarz Reviewed-by: Pierre-Louis Bossart Reviewed-by: Rafael J. Wysocki --- drivers/soundwire/intel_init.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/soundwire/intel_init.c b/drivers/soundwire/intel_init.c index cabdadb09a1b..bc8520eb385e 100644 --- a/drivers/soundwire/intel_init.c +++ b/drivers/soundwire/intel_init.c @@ -405,11 +405,12 @@ int sdw_intel_acpi_scan(acpi_handle *parent_handle, { acpi_status status; + info->handle = NULL; status = acpi_walk_namespace(ACPI_TYPE_DEVICE, parent_handle, 1, sdw_intel_acpi_cb, NULL, info, NULL); - if (ACPI_FAILURE(status)) + if (ACPI_FAILURE(status) || info->handle == NULL) return -ENODEV; return sdw_intel_scan_controller(info); From patchwork Mon Feb 8 12:01:04 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: =?utf-8?q?Marcin_=C5=9Alusarz?= X-Patchwork-Id: 12075247 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-13.7 required=3.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED,DKIM_SIGNED,DKIM_VALID,FREEMAIL_FORGED_FROMDOMAIN, FREEMAIL_FROM,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_CR_TRAILER, INCLUDES_PATCH,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED, USER_AGENT_GIT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8F3C6C433DB for ; Mon, 8 Feb 2021 12:03:05 +0000 (UTC) Received: from alsa0.perex.cz (alsa0.perex.cz [77.48.224.243]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id B6C7664E60 for ; Mon, 8 Feb 2021 12:03:04 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org B6C7664E60 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=alsa-devel-bounces@alsa-project.org Received: from alsa1.perex.cz (alsa1.perex.cz [207.180.221.201]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by alsa0.perex.cz (Postfix) with ESMTPS id 02A59167A; Mon, 8 Feb 2021 13:02:13 +0100 (CET) DKIM-Filter: OpenDKIM Filter v2.11.0 alsa0.perex.cz 02A59167A DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=alsa-project.org; s=default; t=1612785783; bh=/fow4WzTNyRj37UrEYakhzILHVjGuRgb6Kr6YGudMl8=; h=From:To:Subject:Date:In-Reply-To:References:Cc:List-Id: List-Unsubscribe:List-Archive:List-Post:List-Help:List-Subscribe: From; b=rZaK1VjdMqOWMrieySTGLvNV4OAnKlW41UOqBVTgYtFzlMLnyRdfR8WDEvZjdUmTL W+ErR5yIcZHdX/vAb2MU3jQi3jmhtMUpaiVkedQa3bosT56kdvHnuKcTO16w5P+Gz9 ZhHxG81tHfxvnAvn2XMOFHwKgUlNviTuElUNEQcU= Received: from alsa1.perex.cz (localhost.localdomain [127.0.0.1]) by alsa1.perex.cz (Postfix) with ESMTP id 6C33AF80240; Mon, 8 Feb 2021 13:01:22 +0100 (CET) Received: by alsa1.perex.cz (Postfix, from userid 50401) id 246EDF80169; Mon, 8 Feb 2021 13:01:20 +0100 (CET) Received: from mail-lf1-x12c.google.com (mail-lf1-x12c.google.com [IPv6:2a00:1450:4864:20::12c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by alsa1.perex.cz (Postfix) with ESMTPS id 8A0EEF8013A for ; Mon, 8 Feb 2021 13:01:13 +0100 (CET) DKIM-Filter: OpenDKIM Filter v2.11.0 alsa1.perex.cz 8A0EEF8013A Authentication-Results: alsa1.perex.cz; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="K16cTG+3" Received: by mail-lf1-x12c.google.com with SMTP id a12so21855340lfb.1 for ; Mon, 08 Feb 2021 04:01:13 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=Z8kzQS3YPM948wmJnc1Eek6a7lxZy6M65U4pTGtlXO4=; b=K16cTG+3k/StGHXC+r8CudIYqXvQ0vkKMMdiq29IfUfaGg5WhQFHyz4MzmcDyypSn0 dOnPM3izORupsA2vtRW17fDlQ/+X1nMm+/cdwhThC5IIKYEwZdgitpP/GjqX9corVK4F kq4X04HsoKT8ridfCeLaIEJta6gMCjRwChzNmFIUPUnTjzQe5LaobNnT4NWqppHgyPsF Jgj2NEIaH9mmWF51zRlCqYoS54L26cpuC1I/wL0quD2Vy+gm0AqQCBo8RQb5oUOOLZXb Cw82CsWLa/rCox+AwQ0Sg38mab0nI6CxFImAlWUfOTlKxGS1D+ZLNi0/S0VrBICofb5V CQ1w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=Z8kzQS3YPM948wmJnc1Eek6a7lxZy6M65U4pTGtlXO4=; b=OLiYS/QYfMOmIaxBdOysVJOIc5mAeDl8A/WKZQ4U92md0yP3E/hNM7vUktjGAn+X83 3waEER64g4Cgp+5sCtEcmBo7SS5djMJ5Y6r7sx4HnTKg+EnY+YHP+YF+eQDm2NZfjdlK H2UjhgdWHDWh0+yo9W4qMO49VSGG7DXdPFLq2qLZEYpYE66qX+gazY5e/U8YdEXBUuiZ je4Aa66x1hlmdS8KneqcIhUO59HgXPsuuN1fqgcx9WbWYy+JgK9LzJRLAw/7HQmnP2jf 4dLGl14KuHnAZWR1z/OCZv3gINwaGSIBcaG7xQRjvNtbtnEoPF7A07D9RgZPCf1fFVsz Oy/g== X-Gm-Message-State: AOAM532ys9Yntk0JgDvlBRS/sbsBoSzz2R3Mwee/7BKgGvEXEj6U37wD UdqyI0sWN43Nn0Ug/kRdZVOacxS/lZLKKQ== X-Google-Smtp-Source: ABdhPJzgXV3dE/YmpoPEhiHF1uxHkm2TbQ7iUL71H1BPo2N7lyBpNUlX3j1SnYiRc4hPM1t1ngZr3A== X-Received: by 2002:ac2:4e8a:: with SMTP id o10mr10273956lfr.656.1612785672291; Mon, 08 Feb 2021 04:01:12 -0800 (PST) Received: from localhost.localdomain (109241203030.gdansk.vectranet.pl. [109.241.203.30]) by smtp.gmail.com with ESMTPSA id t15sm719086lft.239.2021.02.08.04.01.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 08 Feb 2021 04:01:11 -0800 (PST) From: =?utf-8?q?Marcin_=C5=9Alusarz?= To: alsa-devel@alsa-project.org, linux-acpi@vger.kernel.org Subject: [PATCH 2/2] ACPICA: update documentation of acpi_walk_namespace Date: Mon, 8 Feb 2021 13:01:04 +0100 Message-Id: <20210208120104.204761-2-marcin.slusarz@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20210208120104.204761-1-marcin.slusarz@gmail.com> References: <20210208120104.204761-1-marcin.slusarz@gmail.com> MIME-Version: 1.0 Cc: marcin.slusarz@intel.com, Salvatore Bonaccorso , Pierre-Louis Bossart , "Rafael J. Wysocki" X-BeenThere: alsa-devel@alsa-project.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: "Alsa-devel mailing list for ALSA developers - http://www.alsa-project.org" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: alsa-devel-bounces@alsa-project.org Sender: "Alsa-devel" From: Marcin Ślusarz Signed-off-by: Marcin Ślusarz --- drivers/acpi/acpica/nsxfeval.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/drivers/acpi/acpica/nsxfeval.c b/drivers/acpi/acpica/nsxfeval.c index f9d059647cc5..7149c8f70a6e 100644 --- a/drivers/acpi/acpica/nsxfeval.c +++ b/drivers/acpi/acpica/nsxfeval.c @@ -532,8 +532,8 @@ static void acpi_ns_resolve_references(struct acpi_evaluate_info *info) * return_value - Location where return value of * user_function is put if terminated early * - * RETURNS Return value from the user_function if terminated early. - * Otherwise, returns NULL. + * RETURNS Returns status from the callback function if terminated early. + * Otherwise, returns a status of the walk, AE_OK if succeeded. * * DESCRIPTION: Performs a modified depth-first walk of the namespace tree, * starting (and ending) at the object specified by start_handle. @@ -542,6 +542,11 @@ static void acpi_ns_resolve_references(struct acpi_evaluate_info *info) * a non-zero value, the search is terminated immediately and this * value is returned to the caller. * + * Note that both the callback functions and the walk itself + * use overlapping return values (e.g. AE_OK), so user of this + * function can't rely only on the return value to tell if + * the callback function was called. + * * The point of this procedure is to provide a generic namespace * walk routine that can be called from multiple places to * provide multiple services; the callback function(s) can be