| From dd7b836d6bc935df95c826f69ff4d051f5561604 Mon Sep 17 00:00:00 2001 |
| From: Takashi Sakamoto <o-takashi@sakamocchi.jp> |
| Date: Fri, 12 Mar 2021 18:34:07 +0900 |
| Subject: ALSA: dice: fix null pointer dereference when node is disconnected |
| |
| From: Takashi Sakamoto <o-takashi@sakamocchi.jp> |
| |
| commit dd7b836d6bc935df95c826f69ff4d051f5561604 upstream. |
| |
| When node is removed from IEEE 1394 bus, any transaction fails to the node. |
| In the case, ALSA dice driver doesn't stop isochronous contexts even if |
| they are running. As a result, null pointer dereference occurs in callback |
| from the running context. |
| |
| This commit fixes the bug to release isochronous contexts always. |
| |
| Cc: <stable@vger.kernel.org> # v5.4 or later |
| Fixes: e9f21129b8d8 ("ALSA: dice: support AMDTP domain") |
| Signed-off-by: Takashi Sakamoto <o-takashi@sakamocchi.jp> |
| Link: https://lore.kernel.org/r/20210312093407.23437-1-o-takashi@sakamocchi.jp |
| Signed-off-by: Takashi Iwai <tiwai@suse.de> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| sound/firewire/dice/dice-stream.c | 5 ++--- |
| 1 file changed, 2 insertions(+), 3 deletions(-) |
| |
| --- a/sound/firewire/dice/dice-stream.c |
| +++ b/sound/firewire/dice/dice-stream.c |
| @@ -493,11 +493,10 @@ void snd_dice_stream_stop_duplex(struct |
| struct reg_params tx_params, rx_params; |
| |
| if (dice->substreams_counter == 0) { |
| - if (get_register_params(dice, &tx_params, &rx_params) >= 0) { |
| - amdtp_domain_stop(&dice->domain); |
| + if (get_register_params(dice, &tx_params, &rx_params) >= 0) |
| finish_session(dice, &tx_params, &rx_params); |
| - } |
| |
| + amdtp_domain_stop(&dice->domain); |
| release_resources(dice); |
| } |
| } |