Re: [PATCH v2] ASoC: SOF: validate topology volume range before allocation

From: Péter Ujfalusi

Date: Fri Aug 14 2026 - 09:20:54 EST




On 14/08/2026 11:12, Pengpeng Hou wrote:
> SOF treats the topology mixer min and max values as non-negative indices
> into its volume table. It stores them in signed fields, allocates max + 1
> entries through an int argument, and later indexes the table with the
> stored range.
>
> An inverted range is invalid, while a maximum at or above INT_MAX cannot
> be represented safely after the increment or in the signed fields.
> Validate the complete range before storing it or allocating the table.
>
> Fixes: 311ce4fe7637 ("ASoC: SOF: Add support for loading topologies")
> Assisted-by: Codex:gpt-5
> Signed-off-by: Pengpeng Hou <pengpeng@xxxxxxxxxxx>
> ---
> Changes since v1: https://lore.kernel.org/all/20260722041532.14085-1-pengpeng@xxxxxxxxxxx/
> - validate SOF's non-negative table-index range before signed storage
> - require max + 1 to remain representable by the allocator's int argument
> - rebase on current SOF topology sources

The patch appears to be identical to v1 to my non agent eyes ;)

Acked-by: Peter Ujfalusi <peter.ujfalusi@xxxxxxxxxxxxxxx>

>
> The SOF table-index consumers and allocator conversion were reviewed
> statically; no SOF topology or hardware test was performed.
>
> sound/soc/sof/topology.c | 18 ++++++++++++------
> 1 file changed, 12 insertions(+), 6 deletions(-)
>
> diff --git a/sound/soc/sof/topology.c b/sound/soc/sof/topology.c
> index 42a2d90bb705..31dd7a66a9cf 100644
> --- a/sound/soc/sof/topology.c
> +++ b/sound/soc/sof/topology.c
> @@ -846,6 +846,7 @@ static int sof_control_load_volume(struct snd_soc_component *scomp,
> struct snd_soc_tplg_mixer_control *mc =
> container_of(hdr, struct snd_soc_tplg_mixer_control, hdr);
> int tlv[SOF_TLV_ITEMS];
> + u32 min, max;
> unsigned int mask;
> int ret;
>
> @@ -853,6 +854,11 @@ static int sof_control_load_volume(struct snd_soc_component *scomp,
> if (le32_to_cpu(mc->num_channels) > SND_SOC_TPLG_MAX_CHAN)
> return -EINVAL;
>
> + min = le32_to_cpu(mc->min);
> + max = le32_to_cpu(mc->max);
> + if (min > max || max >= INT_MAX)
> + return -EINVAL;
> +
> /*
> * If control has more than 2 channels we need to override the info. This is because even if
> * ASoC layer has defined topology's max channel count to SND_SOC_TPLG_MAX_CHAN = 8, the
> @@ -863,12 +869,12 @@ static int sof_control_load_volume(struct snd_soc_component *scomp,
> kc->info = snd_sof_volume_info;
>
> scontrol->comp_id = sdev->next_comp_id;
> - scontrol->min_volume_step = le32_to_cpu(mc->min);
> - scontrol->max_volume_step = le32_to_cpu(mc->max);
> + scontrol->min_volume_step = min;
> + scontrol->max_volume_step = max;
> scontrol->num_channels = le32_to_cpu(mc->num_channels);
>
> - scontrol->max = le32_to_cpu(mc->max);
> - if (le32_to_cpu(mc->max) == 1)
> + scontrol->max = max;
> + if (max == 1)
> goto skip;
>
> /* extract tlv data */
> @@ -878,7 +884,7 @@ static int sof_control_load_volume(struct snd_soc_component *scomp,
> }
>
> /* set up volume table */
> - ret = set_up_volume_table(scontrol, tlv, le32_to_cpu(mc->max) + 1);
> + ret = set_up_volume_table(scontrol, tlv, max + 1);
> if (ret < 0) {
> dev_err(scomp->dev, "error: setting up volume table\n");
> return ret;
> @@ -911,7 +917,7 @@ static int sof_control_load_volume(struct snd_soc_component *scomp,
> return 0;
>
> err:
> - if (le32_to_cpu(mc->max) > 1)
> + if (max > 1)
> kfree(scontrol->volume_table);
>
> return ret;

--
Péter