Skip to content

Commit 996c243

Browse files
nszeteigregkh
authored andcommitted
ALSA: timer: don't re-enter an instance callback that is still running
commit 70d28bf upstream. The userspace-driven timer (utimer) TRIGGER ioctl calls snd_timer_interrupt() directly with no serialization, so two threads triggering the same utimer can run snd_timer_interrupt() on one snd_timer concurrently. snd_timer_process_callbacks() drops timer->lock around each instance callback and marks the in-flight callback with the single SNDRV_TIMER_IFLG_CALLBACK bit; snd_timer_close_locked() waits on that bit to drain an in-flight callback before freeing the instance. The bit cannot represent two concurrent callbacks: when a second interrupt re-queues an instance whose callback is still running, both run at once, the first to finish clears the bit, and the close-path drain then frees the instance (and its callback_data) while the other callback is still live - a use-after-free reachable by any user able to open /dev/snd/timer, both via a user timer instance and via a sequencer queue timer bound to the utimer. snd_timer_interrupt() sets IFLG_CALLBACK before dropping timer->lock, so a concurrent interrupt already observes it under the lock. Skip re-queuing an instance (and its slaves) to the ack/sack list while its callback is in flight; the accumulated pticks are delivered on the next tick, so no event is lost. Fixes: 3774591 ("ALSA: timer: Introduce virtual userspace-driven timers") Cc: stable@vger.kernel.org Suggested-by: Takashi Iwai <tiwai@suse.de> Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Norbert Szetei <norbert@doyensec.com> Signed-off-by: Takashi Iwai <tiwai@suse.de> Link: https://patch.msgid.link/6F9B6501-8E65-4265-B02C-7EFB240D1664@doyensec.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent cd461bc commit 996c243

1 file changed

Lines changed: 5 additions & 2 deletions

File tree

sound/core/timer.c

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -883,12 +883,15 @@ void snd_timer_interrupt(struct snd_timer * timer, unsigned long ticks_left)
883883
ack_list_head = &timer->ack_list_head;
884884
else
885885
ack_list_head = &timer->sack_list_head;
886-
if (list_empty(&ti->ack_list))
886+
/* don't requeue an instance whose callback is still running */
887+
if (list_empty(&ti->ack_list) &&
888+
!(ti->flags & SNDRV_TIMER_IFLG_CALLBACK))
887889
list_add_tail(&ti->ack_list, ack_list_head);
888890
list_for_each_entry(ts, &ti->slave_active_head, active_list) {
889891
ts->pticks = ti->pticks;
890892
ts->resolution = resolution;
891-
if (list_empty(&ts->ack_list))
893+
if (list_empty(&ts->ack_list) &&
894+
!(ts->flags & SNDRV_TIMER_IFLG_CALLBACK))
892895
list_add_tail(&ts->ack_list, ack_list_head);
893896
}
894897
}

0 commit comments

Comments
 (0)