]> git.hungrycats.org Git - linux/commitdiff
ASoC: sdw_utils: fix double put_device() on aggregated amps
authorJack Yu <jack.yu@realtek.com>
Tue, 18 Aug 2026 02:30:18 +0000 (10:30 +0800)
committerMark Brown <broonie@kernel.org>
Tue, 18 Aug 2026 17:29:43 +0000 (18:29 +0100)
In aggregation mode with two identical amplifiers,
a stress test that repeatedly triggers card unbind/rebind
can hit a NULL pointer dereference during the exit path.
ctx->amp_dev1 / ctx->amp_dev2 are single shared resources,
so the release must be safe against being called more than once.
Clear each pointer after put_device() so a second invocation
becomes a no-op, this could address NULL pointer dereference issue.

Signed-off-by: Jack Yu <jack.yu@realtek.com>
Link: https://patch.msgid.link/20260818023018.2564212-1-jack.yu@realtek.com
Signed-off-by: Mark Brown <broonie@kernel.org>
sound/soc/sdw_utils/soc_sdw_rt_amp.c

index 4e9b08cb653d14c38176f3c5d091ad31fa961abd..81d2cbac0ea3cd7cf05baab54a6097e7cf73ca6d 100644 (file)
@@ -252,11 +252,13 @@ int asoc_sdw_rt_amp_exit(struct snd_soc_card *card, struct snd_soc_dai_link *dai
        if (ctx->amp_dev1) {
                device_remove_software_node(ctx->amp_dev1);
                put_device(ctx->amp_dev1);
+               ctx->amp_dev1 = NULL;
        }
 
        if (ctx->amp_dev2) {
                device_remove_software_node(ctx->amp_dev2);
                put_device(ctx->amp_dev2);
+               ctx->amp_dev2 = NULL;
        }
 
        return 0;