Commit fc0d6b6
committed
audio: mixin_mixout: reject prepare of an unconnected instance
mixin_prepare() and mixout_prepare() dereferenced sinks[0] without
checking num_of_sinks. The connection arrays in struct processing_module
are only populated by module_adapter_bind(), and
module_adapter_sink_src_prepare() forwards them verbatim, so a module
instance that the host created but never bound is still prepared with
num_of_sinks == 0 and sinks[0] == NULL.
A host that issues CREATE_PIPELINE, INIT_MODULE_INSTANCE (mixin/mixout)
and then SET_PIPELINE_STATE without any BIND therefore made
pipeline_prepare() walk into mixout_params(), where
sink_set_valid_fmt(mod->sinks[0], ...) faulted while writing
sink->audio_stream_params (SEGV on NULL + 0x14). mixin_prepare() has the
same unguarded sink_get_valid_fmt(sinks[0]) one function later; both are
fixed here.
Reject an instance with no sink in .prepare() with -ENOTCONN before the
dereference, matching the existing guards in rtnr_prepare() and
mux_process(). This cannot reject a valid configuration: a functional
mixin/mixout must have at least one bound sink. The mixout_prepare()
entry trace is moved above the check so the rejected case is traced too.
Found by the IPC4 libFuzzer harness on native_sim under ASan.
Signed-off-by: Tomasz Leman <tomasz.m.leman@intel.com>1 parent 48d80e3 commit fc0d6b6
1 file changed
Lines changed: 13 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
717 | 717 | | |
718 | 718 | | |
719 | 719 | | |
| 720 | + | |
| 721 | + | |
| 722 | + | |
| 723 | + | |
| 724 | + | |
| 725 | + | |
720 | 726 | | |
721 | 727 | | |
722 | 728 | | |
| |||
787 | 793 | | |
788 | 794 | | |
789 | 795 | | |
| 796 | + | |
| 797 | + | |
| 798 | + | |
| 799 | + | |
| 800 | + | |
| 801 | + | |
| 802 | + | |
790 | 803 | | |
791 | 804 | | |
792 | 805 | | |
793 | 806 | | |
794 | | - | |
795 | | - | |
796 | 807 | | |
797 | 808 | | |
798 | 809 | | |
| |||
0 commit comments