Re: [PATCH v2] ALSA: seq: midi: Serialize input teardown with event_input

From: Takashi Iwai

Date: Thu Aug 13 2026 - 12:25:25 EST


On Thu, 13 Aug 2026 17:08:08 +0200,
John Keeping wrote:
>
> snd_midi_input_event() must not be running while a rawmidi substream is
> closing, since this can lead to the trigger state becoming out-of-step
> through this sequence in snd_rawmidi_input_trigger():
>
> snd_rawmidi_input_trigger(up=0)
> snd_midi_input_event()
> -> snd_rawmidi_kernel_read()
> -> snd_rawmidi_input_trigger(up=1)
> -> cancel_work_sync()
>
> which ends with the underlying device being active unexpectedly.
>
> When this is called from close_substream(), further input can re-trigger
> the input event leaving it running after rawmidi_release_priv() has set
> rfile->rmidi to NULL which leads to:
>
> Unable to handle kernel NULL pointer dereference at virtual address 00000000000000b0
> Call trace:
> snd_midi_input_event+0x3c/0x134 [snd_seq_midi] (P)
> snd_rawmidi_input_event_work+0x1c/0x2c
> process_one_work+0x150/0x3a4
> worker_thread+0x190/0x318
>
> Apply a similar approach to commit ef7607ab1c8ad ("ALSA: seq: midi:
> Serialize output teardown with event_input") which fixed the same issue
> in the output direction, but updated to use RCU following Takashi Iwai's
> proposed follow-on patch [1].
>
> With this change in place, midisynth_unsubscribe() clears the input file
> so snd_midi_input_event() will not re-trigger the stream and will be
> quiesced by the cancel_work_sync() in snd_rawmidi_input_trigger().
>
> [1] https://lore.kernel.org/linux-sound/20260813144224.753399-1-tiwai@xxxxxxx/
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Signed-off-by: John Keeping <jkeeping@xxxxxxxxxxxxxxxxx>
> ---
> Changes in v2:
> - Switch to using RCU following Takashi's suggestion

Applied to for-next branch now. Thanks.


Takashi