Commit dbe8ccc2 authored by Takashi Iwai's avatar Takashi Iwai Committed by Sasha Levin

ALSA: hda - Fix bad dereference of jack object

[ Upstream commit 2ebab40e ]

The hda_jack_tbl entries are managed by snd_array for allowing
multiple jacks.  It's good per se, but the problem is that struct
hda_jack_callback keeps the hda_jack_tbl pointer.  Since snd_array
doesn't preserve each pointer at resizing the array, we can't keep the
original pointer but have to deduce the pointer at each time via
snd_array_entry() instead.  Actually, this resulted in the deference
to the wrong pointer on codecs that have many pins such as CS4208.

This patch replaces the pointer to the NID value as the search key.
As an unexpected good side effect, this even simplifies the code, as
only NID is needed in most cases.

Cc: <stable@vger.kernel.org>
Signed-off-by: default avatarTakashi Iwai <tiwai@suse.de>
Signed-off-by: default avatarSasha Levin <sasha.levin@oracle.com>
parent 9b728394
...@@ -3998,9 +3998,9 @@ static void pin_power_callback(struct hda_codec *codec, ...@@ -3998,9 +3998,9 @@ static void pin_power_callback(struct hda_codec *codec,
struct hda_jack_callback *jack, struct hda_jack_callback *jack,
bool on) bool on)
{ {
if (jack && jack->tbl->nid) if (jack && jack->nid)
sync_power_state_change(codec, sync_power_state_change(codec,
set_pin_power_jack(codec, jack->tbl->nid, on)); set_pin_power_jack(codec, jack->nid, on));
} }
/* callback only doing power up -- called at first */ /* callback only doing power up -- called at first */
......
...@@ -259,7 +259,7 @@ snd_hda_jack_detect_enable_callback(struct hda_codec *codec, hda_nid_t nid, ...@@ -259,7 +259,7 @@ snd_hda_jack_detect_enable_callback(struct hda_codec *codec, hda_nid_t nid,
if (!callback) if (!callback)
return ERR_PTR(-ENOMEM); return ERR_PTR(-ENOMEM);
callback->func = func; callback->func = func;
callback->tbl = jack; callback->nid = jack->nid;
callback->next = jack->callback; callback->next = jack->callback;
jack->callback = callback; jack->callback = callback;
} }
......
...@@ -21,7 +21,7 @@ struct hda_jack_callback; ...@@ -21,7 +21,7 @@ struct hda_jack_callback;
typedef void (*hda_jack_callback_fn) (struct hda_codec *, struct hda_jack_callback *); typedef void (*hda_jack_callback_fn) (struct hda_codec *, struct hda_jack_callback *);
struct hda_jack_callback { struct hda_jack_callback {
struct hda_jack_tbl *tbl; hda_nid_t nid;
hda_jack_callback_fn func; hda_jack_callback_fn func;
unsigned int private_data; /* arbitrary data */ unsigned int private_data; /* arbitrary data */
struct hda_jack_callback *next; struct hda_jack_callback *next;
......
...@@ -4401,13 +4401,16 @@ static void ca0132_process_dsp_response(struct hda_codec *codec, ...@@ -4401,13 +4401,16 @@ static void ca0132_process_dsp_response(struct hda_codec *codec,
static void hp_callback(struct hda_codec *codec, struct hda_jack_callback *cb) static void hp_callback(struct hda_codec *codec, struct hda_jack_callback *cb)
{ {
struct ca0132_spec *spec = codec->spec; struct ca0132_spec *spec = codec->spec;
struct hda_jack_tbl *tbl;
/* Delay enabling the HP amp, to let the mic-detection /* Delay enabling the HP amp, to let the mic-detection
* state machine run. * state machine run.
*/ */
cancel_delayed_work_sync(&spec->unsol_hp_work); cancel_delayed_work_sync(&spec->unsol_hp_work);
schedule_delayed_work(&spec->unsol_hp_work, msecs_to_jiffies(500)); schedule_delayed_work(&spec->unsol_hp_work, msecs_to_jiffies(500));
cb->tbl->block_report = 1; tbl = snd_hda_jack_tbl_get(codec, cb->nid);
if (tbl)
tbl->block_report = 1;
} }
static void amic_callback(struct hda_codec *codec, struct hda_jack_callback *cb) static void amic_callback(struct hda_codec *codec, struct hda_jack_callback *cb)
......
...@@ -1179,7 +1179,7 @@ static void check_presence_and_report(struct hda_codec *codec, hda_nid_t nid) ...@@ -1179,7 +1179,7 @@ static void check_presence_and_report(struct hda_codec *codec, hda_nid_t nid)
static void jack_callback(struct hda_codec *codec, static void jack_callback(struct hda_codec *codec,
struct hda_jack_callback *jack) struct hda_jack_callback *jack)
{ {
check_presence_and_report(codec, jack->tbl->nid); check_presence_and_report(codec, jack->nid);
} }
static void hdmi_intrinsic_event(struct hda_codec *codec, unsigned int res) static void hdmi_intrinsic_event(struct hda_codec *codec, unsigned int res)
......
...@@ -277,7 +277,7 @@ static void alc_update_knob_master(struct hda_codec *codec, ...@@ -277,7 +277,7 @@ static void alc_update_knob_master(struct hda_codec *codec,
uctl = kzalloc(sizeof(*uctl), GFP_KERNEL); uctl = kzalloc(sizeof(*uctl), GFP_KERNEL);
if (!uctl) if (!uctl)
return; return;
val = snd_hda_codec_read(codec, jack->tbl->nid, 0, val = snd_hda_codec_read(codec, jack->nid, 0,
AC_VERB_GET_VOLUME_KNOB_CONTROL, 0); AC_VERB_GET_VOLUME_KNOB_CONTROL, 0);
val &= HDA_AMP_VOLMASK; val &= HDA_AMP_VOLMASK;
uctl->value.integer.value[0] = val; uctl->value.integer.value[0] = val;
......
...@@ -493,9 +493,9 @@ static void jack_update_power(struct hda_codec *codec, ...@@ -493,9 +493,9 @@ static void jack_update_power(struct hda_codec *codec,
if (!spec->num_pwrs) if (!spec->num_pwrs)
return; return;
if (jack && jack->tbl->nid) { if (jack && jack->nid) {
stac_toggle_power_map(codec, jack->tbl->nid, stac_toggle_power_map(codec, jack->nid,
snd_hda_jack_detect(codec, jack->tbl->nid), snd_hda_jack_detect(codec, jack->nid),
true); true);
return; return;
} }
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment