Re: [PATCH 1/2] ALSA: timer: don't re-enter an instance callback that is still running

From: Takashi Iwai

Date: Mon Jul 20 2026 - 04:19:15 EST


On Mon, 20 Jul 2026 09:09:55 +0200,
Norbert Szetei wrote:
>
> The userspace-driven timer (utimer) TRIGGER ioctl calls
> snd_timer_interrupt() directly with no serialization, so two threads
> triggering the same utimer can run snd_timer_interrupt() on one
> snd_timer concurrently.
>
> snd_timer_process_callbacks() drops timer->lock around each instance
> callback and marks the in-flight callback with the single
> SNDRV_TIMER_IFLG_CALLBACK bit; snd_timer_close_locked() waits on that
> bit to drain an in-flight callback before freeing the instance. The bit
> cannot represent two concurrent callbacks: when a second interrupt
> re-queues an instance whose callback is still running, both run at once,
> the first to finish clears the bit, and the close-path drain then frees
> the instance (and its callback_data) while the other callback is still
> live - a use-after-free reachable by any user able to open
> /dev/snd/timer, both via a user timer instance and via a sequencer queue
> timer bound to the utimer.
>
> snd_timer_interrupt() sets IFLG_CALLBACK before dropping timer->lock, so
> a concurrent interrupt already observes it under the lock. Skip
> re-queuing an instance (and its slaves) to the ack/sack list while its
> callback is in flight; the accumulated pticks are delivered on the next
> tick, so no event is lost.
>
> Fixes: 37745918e0e7 ("ALSA: timer: Introduce virtual userspace-driven timers")
> Cc: <stable@xxxxxxxxxxxxxxx>
> Suggested-by: Takashi Iwai <tiwai@xxxxxxx>
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: Norbert Szetei <norbert@xxxxxxxxxxxx>

Applied both patches now. Thanks.


Takashi