提交 04b2d9c9 编写于 作者: T Takashi Sakamoto 提交者: Takashi Iwai

ALSA: firewire-tascam: accessing to user space outside spinlock

In hwdep interface of firewire-tascam driver, accessing to user space is
in a critical section with disabled local interrupt. Depending on
architecture, accessing to user space can cause page fault exception. Then
local processor stores machine status and handle the synchronous event. A
handler corresponding to the event can call task scheduler to wait for
preparing pages. In a case of usage of single core processor, the state to
disable local interrupt is worse because it doesn't handle usual interrupts
from hardware.

This commit fixes this bug, by performing the accessing outside spinlock.
Reported-by: NVaishali Thakkar <vaishali.thakkar@oracle.com>
Cc: stable@vger.kernel.org
Fixes: e5e0c3dd('ALSA: firewire-tascam: add hwdep interface')
Signed-off-by: NTakashi Sakamoto <o-takashi@sakamocchi.jp>
Signed-off-by: NTakashi Iwai <tiwai@suse.de>
上级 fd06c77e
...@@ -16,31 +16,14 @@ ...@@ -16,31 +16,14 @@
#include "tascam.h" #include "tascam.h"
static long hwdep_read_locked(struct snd_tscm *tscm, char __user *buf,
long count)
{
union snd_firewire_event event;
memset(&event, 0, sizeof(event));
event.lock_status.type = SNDRV_FIREWIRE_EVENT_LOCK_STATUS;
event.lock_status.status = (tscm->dev_lock_count > 0);
tscm->dev_lock_changed = false;
count = min_t(long, count, sizeof(event.lock_status));
if (copy_to_user(buf, &event, count))
return -EFAULT;
return count;
}
static long hwdep_read(struct snd_hwdep *hwdep, char __user *buf, long count, static long hwdep_read(struct snd_hwdep *hwdep, char __user *buf, long count,
loff_t *offset) loff_t *offset)
{ {
struct snd_tscm *tscm = hwdep->private_data; struct snd_tscm *tscm = hwdep->private_data;
DEFINE_WAIT(wait); DEFINE_WAIT(wait);
union snd_firewire_event event; union snd_firewire_event event = {
.lock_status.type = SNDRV_FIREWIRE_EVENT_LOCK_STATUS,
};
spin_lock_irq(&tscm->lock); spin_lock_irq(&tscm->lock);
...@@ -54,10 +37,16 @@ static long hwdep_read(struct snd_hwdep *hwdep, char __user *buf, long count, ...@@ -54,10 +37,16 @@ static long hwdep_read(struct snd_hwdep *hwdep, char __user *buf, long count,
spin_lock_irq(&tscm->lock); spin_lock_irq(&tscm->lock);
} }
memset(&event, 0, sizeof(event)); event.lock_status.status = (tscm->dev_lock_count > 0);
count = hwdep_read_locked(tscm, buf, count); tscm->dev_lock_changed = false;
spin_unlock_irq(&tscm->lock); spin_unlock_irq(&tscm->lock);
count = min_t(long, count, sizeof(event.lock_status));
if (copy_to_user(buf, &event, count))
return -EFAULT;
return count; return count;
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册