Skip to content

Commit fc0d6b6

Browse files
committed
audio: mixin_mixout: reject prepare of an unconnected instance
mixin_prepare() and mixout_prepare() dereferenced sinks[0] without checking num_of_sinks. The connection arrays in struct processing_module are only populated by module_adapter_bind(), and module_adapter_sink_src_prepare() forwards them verbatim, so a module instance that the host created but never bound is still prepared with num_of_sinks == 0 and sinks[0] == NULL. A host that issues CREATE_PIPELINE, INIT_MODULE_INSTANCE (mixin/mixout) and then SET_PIPELINE_STATE without any BIND therefore made pipeline_prepare() walk into mixout_params(), where sink_set_valid_fmt(mod->sinks[0], ...) faulted while writing sink->audio_stream_params (SEGV on NULL + 0x14). mixin_prepare() has the same unguarded sink_get_valid_fmt(sinks[0]) one function later; both are fixed here. Reject an instance with no sink in .prepare() with -ENOTCONN before the dereference, matching the existing guards in rtnr_prepare() and mux_process(). This cannot reject a valid configuration: a functional mixin/mixout must have at least one bound sink. The mixout_prepare() entry trace is moved above the check so the rejected case is traced too. Found by the IPC4 libFuzzer harness on native_sim under ASan. Signed-off-by: Tomasz Leman <tomasz.m.leman@intel.com>
1 parent 48d80e3 commit fc0d6b6

1 file changed

Lines changed: 13 additions & 2 deletions

File tree

‎src/audio/mixin_mixout/mixin_mixout.c‎

Lines changed: 13 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -717,6 +717,12 @@ static int mixin_prepare(struct processing_module *mod,
717717
int ret;
718718

719719
comp_info(dev, "entry");
720+
721+
if (!num_of_sinks) {
722+
comp_err(dev, "no sink buffer");
723+
return -ENOTCONN;
724+
}
725+
720726
#if CONFIG_XRUN_NOTIFICATIONS_ENABLE
721727
md->eos_delay_configured = false;
722728
#endif
@@ -787,12 +793,17 @@ static int mixout_prepare(struct processing_module *mod,
787793
struct mixout_data *md;
788794
int ret, i;
789795

796+
comp_dbg(dev, "entry");
797+
798+
if (!num_of_sinks) {
799+
comp_err(dev, "no sink buffer");
800+
return -ENOTCONN;
801+
}
802+
790803
ret = mixout_params(mod);
791804
if (ret < 0)
792805
return ret;
793806

794-
comp_dbg(dev, "entry");
795-
796807
/*
797808
* Since mixout sink buffer stream is reset on .prepare(), let's
798809
* reset counters for not yet produced frames in that buffer.

0 commit comments

Comments
 (0)