Skip to content

ipc4: volume: probe: declare init payload structs 4-byte aligned - #11261

Open
tmleman wants to merge 1 commit into
thesofproject:mainfrom
tmleman:topic/upstream/pr/ipc4/struct_alignend
Open

tmleman wants to merge 1 commit into
thesofproject:mainfrom
tmleman:topic/upstream/pr/ipc4/struct_alignend

Conversation

@tmleman

@tmleman tmleman commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

struct ipc4_peak_volume_config, struct ipc4_peak_volume_module_cfg and struct ipc4_probe_module_cfg are declared __packed __aligned(8) and are dereferenced in place in the hostbox via mod->priv.cfg.init_data.

The IPC4 INIT_MODULE_INSTANCE payload only guarantees 4-byte alignment: when the extension has extended_init set, the module config follows the 12-byte struct ipc4_module_init_ext_init (plus optional 4-byte-granular ext init objects), so it lands at a 4-byte aligned offset. The Linux driver uses extended init for DP modules, so this happens on real hardware, not only under native_sim. UBSan reports "member access within misaligned address ... which requires 8 byte alignment" in volume_init() and probe_mod_init().

Relax the declared alignment to 4 bytes, matching every other IPC4 payload struct. sizeof() and all member offsets are unchanged (24/40 and 48 bytes respectively), so the wire layout is untouched.

Found by the IPC4 libFuzzer campaign with -fsanitize=undefined.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 12:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The alignment changes match IPC4 guarantees while preserving structure sizes and member offsets.

Review effort: Balanced
Findings: None

What changed in this PR

Aligns IPC4 volume and probe initialization payload declarations with the protocol’s 4-byte alignment guarantee, preventing misaligned accesses without changing wire layouts.

Changes:

  • Changes peak-volume configuration alignment from 8 to 4 bytes.
  • Changes probe module configuration alignment from 8 to 4 bytes.
File Description
src/​include/​ipc4/​probe.h Corrects probe initialization payload alignment.
src/​audio/​volume/​peak_volume.h Corrects peak-volume payload alignment.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

struct ipc4_peak_volume_config, struct ipc4_peak_volume_module_cfg and
struct ipc4_probe_module_cfg are declared __packed __aligned(8) and are
dereferenced in place in the hostbox via mod->priv.cfg.init_data.

The IPC4 INIT_MODULE_INSTANCE payload only guarantees 4-byte alignment:
when the extension has extended_init set, the module config follows the
12-byte struct ipc4_module_init_ext_init (plus optional 4-byte-granular
ext init objects), so it lands at a 4-byte aligned offset. The Linux
driver uses extended init for DP modules, so this happens on real
hardware, not only under native_sim. UBSan reports "member access within
misaligned address ... which requires 8 byte alignment" in volume_init()
and probe_mod_init().

Relax the declared alignment to 4 bytes, matching every other IPC4
payload struct. sizeof() and all member offsets are unchanged (24/40 and
48 bytes respectively), so the wire layout is untouched.

Found by the IPC4 libFuzzer campaign with -fsanitize=undefined.

Signed-off-by: Tomasz Leman <tomasz.m.leman@intel.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants