[PATCH 6/8] ALSA: pcmtest: Fix a bogus pointer read in snd_pcmtst_pcm_pointer()

From: Takashi Iwai

Date: Tue Oct 06 2026 - 09:46:16 EST


Sashiko reported a potential bogus value for a pcmtest driver when a
concurrent call to PCM pointer is invoked while the pcmtest's timer
callback is running: since the position is updated in the timer
callback without locking, the following wrapping in inc_buf_pos()
might be screwed up:
if (v_iter->buf_pos >= bytes)
v_iter->buf_pos %= bytes;
Although it was reported as an OOB, the actual return is corrected
inside buffer_size, so no corruption is expected in this scenario, but
an error message could show a bogus value.

Also, the whole state is read and modified locklessly in the timer
callback, which can be racy against the pause operation, too.

For avoiding those races, simply put the PCM stream lock in the timer
callback (while the snd_pcm_period_elapsed() must be changed to its
*_under_stream_lock() variant for avoiding the deadlock).

Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
Fixes: 315a3d57c64c ("ALSA: Implement the new Virtual PCM Test Driver")
Signed-off-by: Takashi Iwai <tiwai@xxxxxxx>
---
sound/drivers/pcmtest.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/sound/drivers/pcmtest.c b/sound/drivers/pcmtest.c
index 186e982d42e1..fea9580593e6 100644
--- a/sound/drivers/pcmtest.c
+++ b/sound/drivers/pcmtest.c
@@ -345,6 +345,7 @@ static void timer_timeout(struct timer_list *data)
v_iter = timer_container_of(v_iter, data, timer_instance);
substream = v_iter->substream;

+ guard(pcm_stream_lock_irqsave)(substream);
if (v_iter->suspend)
return;

@@ -358,7 +359,7 @@ static void timer_timeout(struct timer_list *data)
v_iter->period_pos += v_iter->b_rw;
if (v_iter->period_pos >= v_iter->period_bytes) {
v_iter->period_pos %= v_iter->period_bytes;
- snd_pcm_period_elapsed(substream);
+ snd_pcm_period_elapsed_under_stream_lock(substream);
}

if (!v_iter->suspend)
--
2.55.0