Re: [PATCH] ASoC: fsl_asrc: check the second front-end DMA channel

From: Dan Carpenter

Date: Sat Sep 26 2026 - 09:20:00 EST


On Sun, Sep 13, 2026 at 08:51:47PM +0800, Slavin Liu wrote:
> The temporary Front-End DMA request can fail independently of the
> persistent channel acquired earlier in fsl_asrc_dma_hw_params(). The
> returned NULL pointer is immediately used to read its private data.
>
> Check the temporary channel and release the previously acquired
> persistent Front-End channel on failure. Clear its slot so a later
> hw_free cannot release it twice. ASoC marks a component's hw_params
> only after success and skips unmarked components during rollback, so
> returning an error alone would leak the earlier channel.
>
> Detected by static analysis and reviewed with AI-assisted source auditing.
>
> Fixes: 3117bb3109dc ("ASoC: fsl_asrc: Add ASRC ASoC CPU DAI and platform drivers")
> Assisted-by: LLM
> Signed-off-by: Slavin Liu <bolin.liu@xxxxxxxxxx>
> ---
> sound/soc/fsl/fsl_asrc_dma.c | 5 +++++
> 1 file changed, 5 insertions(+)
>
> diff --git a/sound/soc/fsl/fsl_asrc_dma.c b/sound/soc/fsl/fsl_asrc_dma.c
> index 2f662bdf14d0..64f2b0612274 100644
> --- a/sound/soc/fsl/fsl_asrc_dma.c
> +++ b/sound/soc/fsl/fsl_asrc_dma.c
> @@ -248,6 +248,11 @@ static int fsl_asrc_dma_hw_params(struct snd_soc_component *component,
>
> /* Get DMA request of Front-End */
> tmp_chan = asrc->get_dma_channel(pair, dir);

The ->get_dma_channel() function pointer returns error pointers not
NULL.

sound/soc/fsl/fsl_asrc_dma.c:254 fsl_asrc_dma_hw_params()
warn: 'tmp_chan' is an error pointer or valid

sound/soc/fsl/fsl_easrc.c | (struct fsl_asrc)->get_dma_channel | fsl_easrc_get_dma_channel | 1
sound/soc/fsl/fsl_asrc.c | (struct fsl_asrc)->get_dma_channel | fsl_asrc_get_dma_channel | 1

regards,
dan carpenter

> + if (!tmp_chan) {
> + dma_release_channel(pair->dma_chan[!dir]);
> + pair->dma_chan[!dir] = NULL;
> + return -EINVAL;
> + }
> tmp_data = tmp_chan->private;
> pair->dma_data.dma_request2 = tmp_data->dma_request;
> pair->dma_data.peripheral_type = tmp_data->peripheral_type;