From nobody Sat Jul 25 16:49:30 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B8B414D2ED0; Wed, 15 Jul 2026 20:18:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784146706; cv=none; b=k2n6vGnVDY3fk0j4OSWti9iAt4v4s0RRb88MmyCiNtEa1PwQE23O2S9XYZ9lpAoRcHUgeQUBZCE1UGTmi3yyXm9phP55MQ8GoMBGvYaFRIAWIryi3nB9DRWoO07/gsRponJQWu1efA7RF0mIPapSoOmsnUkclw30wQ63PPlMBjQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784146706; c=relaxed/simple; bh=CJhV7PGj47iIAspFHu/JLaN2UhNXEyvLQbBS54wp4lE=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=YK/wXjgE48//Tv/fH+kk8l4qP1/zJqr/NaXN0XnrKKnVwFfHTZywdRmFFcH6aLqc13oYkb5sXuuXTGrjtLiqVocWZsXOEU0KVgt6oitgk5xcwRzit8wDyJ/yYQ+l2PWM4t93n5WYbPuuTK5fAywDMp2pLc8bv+J3v/ETrmcFh3Q= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Swp0cKst; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Swp0cKst" Received: by smtp.kernel.org (Postfix) with ESMTPSA id C7B0E1F000E9; Wed, 15 Jul 2026 20:18:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1784146705; bh=hMHXuZkbXdkLujkt+PsLDj2e6FLgA5od1ICzzv2H3ww=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=Swp0cKst1yEDIbKLTlu5KOJ7TPOQhi1WF1JzbYymnI1SZXFY42kBsB/AhBPqXHI5B yGsIGVqt86tLjrPi98qQZoIEohx2YvZtZ5d2m+POb00RChZJ6yWWwRXDI+l1v35CHJ awkbiVq6bPR+jMnKACTrVztzmd7BlWFP0swDvPD2K7sV3ACgAVD9D2t1GEYMlGPypH sUJEIi+kFhZ8A8BBSDknQ+6EZGu+yrEHi31p6g9Uqz0fCtSqZM60ZFxV2cL8u74a4K Jbqr+4KYYPkLs5HiRMLJd8VUV1z5wrY3GuNK2Y8XCFLweS7tZN5y1Kh7+LLvjYBDYg 5hCdkV1js4BKw== From: Mark Brown Date: Wed, 15 Jul 2026 21:18:09 +0100 Subject: [PATCH 1/3] ASoC: tas2562: Validate values for volume writes Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260715-asoc-tas2562-put-retval-v1-1-97bf467c924e@kernel.org> References: <20260715-asoc-tas2562-put-retval-v1-0-97bf467c924e@kernel.org> In-Reply-To: <20260715-asoc-tas2562-put-retval-v1-0-97bf467c924e@kernel.org> To: Shenghao Ding , Kevin Lu , Baojun Xu , Sen Wang , Liam Girdwood Cc: Haidar Lee , linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org, Mark Brown , stable@vger.kernel.org X-Mailer: b4 0.16-dev X-Developer-Signature: v=1; a=openpgp-sha256; l=1325; i=broonie@kernel.org; h=from:subject:message-id; bh=CJhV7PGj47iIAspFHu/JLaN2UhNXEyvLQbBS54wp4lE=; b=owEBbQGS/pANAwAKASTWi3JdVIfQAcsmYgBqV+sL1V2V5bL2rzAhAL2BSwhxtsTziV8wanolv G2CT2NQoY+JATMEAAEKAB0WIQSt5miqZ1cYtZ/in+ok1otyXVSH0AUCalfrCwAKCRAk1otyXVSH 0CxsB/sHsMw/6m6wTOFOZy28Yzk2w2w6UbGVEOgdXFQ+yYc0Xnznv17dTqTeZkRQlxJ0rW/upUr lwlG2uDplsBHme1T7LnF2om4d5/xcbI1PBo+kguGgA1LidBYXtnbHYfqDSaljSM50+doU1jPwej uWoW2+v7JHwMJhTSrRDSw5wHz4o+ystb0dkuns0YuDNoEtvk3/lpOMUNWHj1Mxg0fVJAfZo/WnB fntesOOjUpdZHqnhM/z8hrqOEVdvLgF7bPL6lb7OVcgVde+3Idj2gJpEX2T5fFfV/5bbyLgcOHu z3ZdheTxE49mtXHQ9jf/oPZ9LQgojp68Q2ridEJWU2ZWLhBa X-Developer-Key: i=broonie@kernel.org; a=openpgp; fpr=3F2568AAC26998F9E813A1C5C3F436CA30F5D8EB tas2562_volume_control_put() does not do any validation of the control value written by userspace, it uses it to look up a value in a fixed size array which can easily be overflowed and then writes whatever value it gets back to the device. Add validation that we are loading a value we have in the array. Signed-off-by: Mark Brown Cc: stable@vger.kernel.org Reviewed-by: Cezary Rojewski --- sound/soc/codecs/tas2562.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/sound/soc/codecs/tas2562.c b/sound/soc/codecs/tas2562.c index 2f7cfc2be970..82bc0078a5c7 100644 --- a/sound/soc/codecs/tas2562.c +++ b/sound/soc/codecs/tas2562.c @@ -471,10 +471,14 @@ static int tas2562_volume_control_put(struct snd_kcon= trol *kcontrol, { struct snd_soc_component *component =3D snd_kcontrol_chip(kcontrol); struct tas2562_data *tas2562 =3D snd_soc_component_get_drvdata(component); - int ret; + int ret, index; u32 reg_val; =20 - reg_val =3D float_vol_db_lookup[ucontrol->value.integer.value[0]/2]; + index =3D ucontrol->value.integer.value[0] / 2; + if (index < 0 || index >=3D ARRAY_SIZE(float_vol_db_lookup)) + return -EINVAL; + + reg_val =3D float_vol_db_lookup[index]; ret =3D snd_soc_component_write(component, TAS2562_DVC_CFG4, (reg_val & 0xff)); if (ret) --=20 2.47.3 From nobody Sat Jul 25 16:49:30 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EC4CA4D2EC5; Wed, 15 Jul 2026 20:18:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784146709; cv=none; b=ua9NuUNZuAZRYvCoYfHzxNx83Vkx5xPalThZp/3dsaMuk8fqajna5sifsiSZC1lNSeL20HMnTSQkrZAOciaAy9LOHBrKok5gw0CGYhnnJhxoaMTfKGAL+I1Sxa77TxsNx7nf+dtU73+9QzdUwuirwz60dbhtpqi/4Aeha0i+DZc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784146709; c=relaxed/simple; bh=w+9XrHsEFWF0eclQwXVzewT4xPRYC8WW9OGu/ZxMg5U=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=F7CbJOSK0P+TJpzoEKRoqnHtH8x7lUCmkultGPLgWCYNzR1BOPSkL1dlFi50/gf2bIW4KZwqAg0OOvvLEUUy8B261YjFTEXjQOLFC5X9qE21k6QK5Fuu50A048VYbKWT/L13kfu3GXnAymH0Vxo+yp1kkR2klKW2nTJEvwb4mZ0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=gwSKIuUZ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="gwSKIuUZ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 08A771F00A3A; Wed, 15 Jul 2026 20:18:25 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1784146707; bh=EMxlaPdqelI2GuvNfa9bRbTnnxJqw7/jTKDRud+pUfs=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=gwSKIuUZs2RjO/L5wKtthv64oLRd96CfLl/5kDUiEEdpFmGfN6jfQ5hW8jVC75Z/t /aJOdr2S8HZN17Qs3xoXURlBpnJp6lzZ3pKYIMb9rfW4kRz976coGyxZcv0Cy30hdB lZjgq0Y1Ay+dlXqVwklg+FGPKKUF/FEw/aP7sBQs5iBRQdjEtNsEnzyYBwkDSOJZk2 q7HH9LfYTiRNQcKAtdLiQhzgK10fCWvCw7L6/fBHh+ipmfkoY/wMA47dCRpDwFJDaC 3QTzXAKn4SJtuMyjIQGsJfDV/MwgoPzuUszqHw7xAZXxHCI6Pf5rxDkJndjPggeADd OF+w5gmSenZbA== From: Mark Brown Date: Wed, 15 Jul 2026 21:18:10 +0100 Subject: [PATCH 2/3] ASoC: tas2562: Fix event generation for volume control Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260715-asoc-tas2562-put-retval-v1-2-97bf467c924e@kernel.org> References: <20260715-asoc-tas2562-put-retval-v1-0-97bf467c924e@kernel.org> In-Reply-To: <20260715-asoc-tas2562-put-retval-v1-0-97bf467c924e@kernel.org> To: Shenghao Ding , Kevin Lu , Baojun Xu , Sen Wang , Liam Girdwood Cc: Haidar Lee , linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org, Mark Brown X-Mailer: b4 0.16-dev X-Developer-Signature: v=1; a=openpgp-sha256; l=1371; i=broonie@kernel.org; h=from:subject:message-id; bh=w+9XrHsEFWF0eclQwXVzewT4xPRYC8WW9OGu/ZxMg5U=; b=owEBbQGS/pANAwAKASTWi3JdVIfQAcsmYgBqV+sLGOMiGFg2jwkjbu1KZi7UvtYeEUxK0LseW 79c5JV1g7qJATMEAAEKAB0WIQSt5miqZ1cYtZ/in+ok1otyXVSH0AUCalfrCwAKCRAk1otyXVSH 0JSACACDLorA+Gcklp062VlgyPx/kBCIYBI+oZvVjf25DZb/1/6li4NvNPlK8gndEg2LQXZ8Ly/ 2El38Dlh9/8d0rHkOvv7LgUYldPjuaMXHimfaGCUdjIbV+jiXCNjdHQrbbTGDI7/rdhvkJOuX8T OFzBOHbsPv5I10XlBvMujRTvE7Fwtj2dws3EcMlRqvpeoWWrvBRNQDEL0CS6UOJVyb7xGxNylxc rSxS2Z6jZ4I+M11GrUQ2jnSP1TxFkNIjW90rRBiz18z9wefw98fRdzbdKGw77AC54d3uAVssBGI ki9YcPMaothbMDTYTVXUL4ZkidrYEXt0jDrrljOyhXB70acZ X-Developer-Key: i=broonie@kernel.org; a=openpgp; fpr=3F2568AAC26998F9E813A1C5C3F436CA30F5D8EB ALSA put() operations should return 0 for noop updates and 1 if the value of the control changed, this is used by the ALSA core to generate events to userspace. tas2562_volume_control_put() does not implement this, it just writes whatever value userspace wrote to the device and returns 0 regardless of what the previous value was. Fix this by suppressing writes if the value is unchanged and returning 1 if the writes succeed. Signed-off-by: Mark Brown Reviewed-by: Cezary Rojewski --- sound/soc/codecs/tas2562.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/sound/soc/codecs/tas2562.c b/sound/soc/codecs/tas2562.c index 82bc0078a5c7..9b863b000470 100644 --- a/sound/soc/codecs/tas2562.c +++ b/sound/soc/codecs/tas2562.c @@ -474,6 +474,9 @@ static int tas2562_volume_control_put(struct snd_kcontr= ol *kcontrol, int ret, index; u32 reg_val; =20 + if (tas2562->volume_lvl =3D=3D ucontrol->value.integer.value[0]) + return 0; + index =3D ucontrol->value.integer.value[0] / 2; if (index < 0 || index >=3D ARRAY_SIZE(float_vol_db_lookup)) return -EINVAL; @@ -498,7 +501,7 @@ static int tas2562_volume_control_put(struct snd_kcontr= ol *kcontrol, =20 tas2562->volume_lvl =3D ucontrol->value.integer.value[0]; =20 - return 0; + return 1; } =20 /* Digital Volume Control. From 0 dB to -110 dB in 1 dB steps */ --=20 2.47.3 From nobody Sat Jul 25 16:49:30 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D54134D2ECA; Wed, 15 Jul 2026 20:18:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784146710; cv=none; b=m8h9b18nB+0Sks1wgg/feMgvIA6JYUzPPwMPT0UAWgIkdMBbcIoJUkI5ntQaVc+TGyxFGtfkKqlNdysAC3+oMi1HRZNnvGmFXDR5m4JBZFTzUWakWMu1RzO5zc4CpwkzooeJ00wa3VnpBbcLKhIoOzfhU8HEAlq+NCRJ2RA/Ses= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784146710; c=relaxed/simple; bh=ZRWIcPjGXHC/LgYkFOepiJ/eK9S/BY/5+ULJ/6ePEGU=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Lm7P8KP4Ed6K2A4Fho6Yy1Bsit6IOkrdH/JMi8YdfH3/oruMZPFCq/4xJMnqsxEfayulukpP8EHJv83zRkyKPHS2NhNXbpSY+vT5XVxR391pZpfaELiT9zorePAA0NeW9ncv77MCDjOj36pHDCXRs61IlfLHU+R1vR9L5wdOj+g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=bmzYtwO6; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="bmzYtwO6" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 1403E1F000E9; Wed, 15 Jul 2026 20:18:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1784146709; bh=6Ubpidue3FInWGDSczhOjU4t/kQ+IccUQZOrRYBPZWs=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=bmzYtwO6TJOPz6VAxZ2yDOZanqoaSskcJY+vBZxYwSZAMhTAnerXprIvion9zXaGn WdvhQ5pukNo5QB1Ch0X59Cg1aEwxR8Ct4qKGFtt2Eyx4+YSFUTM8FGvTHYAdxZ0SVw x4W6H/RHuBWanJFRInbIshxJbnNHh3GkxNGyKy0QbembEraBcBfIh5+qBHGpG8rHV7 vjUzDG7owOx2PFTyQ2EBgG4DVGKM2tHVf5xzV13l9loD4ttfV2yZJ7EdSrskKD/khY obAH19wFY8dD2E9R3nV5ZgLOV+Dm8Zx+DNZ0njy/xLuoK5D+VhHFp8BBzscxFdA+Im AQui98/ttKpfg== From: Mark Brown Date: Wed, 15 Jul 2026 21:18:11 +0100 Subject: [PATCH 3/3] ASoC: tas2562: Fix default digital volume Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260715-asoc-tas2562-put-retval-v1-3-97bf467c924e@kernel.org> References: <20260715-asoc-tas2562-put-retval-v1-0-97bf467c924e@kernel.org> In-Reply-To: <20260715-asoc-tas2562-put-retval-v1-0-97bf467c924e@kernel.org> To: Shenghao Ding , Kevin Lu , Baojun Xu , Sen Wang , Liam Girdwood Cc: Haidar Lee , linux-sound@vger.kernel.org, linux-kernel@vger.kernel.org, Mark Brown X-Mailer: b4 0.16-dev X-Developer-Signature: v=1; a=openpgp-sha256; l=1139; i=broonie@kernel.org; h=from:subject:message-id; bh=ZRWIcPjGXHC/LgYkFOepiJ/eK9S/BY/5+ULJ/6ePEGU=; b=owEBbQGS/pANAwAKASTWi3JdVIfQAcsmYgBqV+sM3pgV+PoP6lUHw9C0CIzuCQuwgjtl6QPfE nAHqVmVGteJATMEAAEKAB0WIQSt5miqZ1cYtZ/in+ok1otyXVSH0AUCalfrDAAKCRAk1otyXVSH 0KvQB/44n6J+xWG+8ahJ4V1N/A1ss2PGy2KIxd3uDF24kYA2v7b/AtM7X/9//jYfOHSDMAUQZ7L fkccvg5Em4IVjIRt8koDbeU+ZkL9VBA5WaX4nM+I672PKMBJFb67FhA4wBfxJrz0U1UHu+A4lZz 3a2TlenPzh3HzdfdPtMcxsqU3ZG6AR7NY52JsJqabLXhbXTbvH7ocVV02oRQi0+C0wRn5fqRv11 A/owa1qeGsMqR7tqkGWRLpy2QEd0Y/Is2EzEUmeUHMMwi7CFkfSyY+CR4m8+nWIh5zjCvP0mt96 vtKuJPdznLeh2jXahEmIDIdRrMgh9K6AHrAdV9F79gIOyRmR X-Developer-Key: i=broonie@kernel.org; a=openpgp; fpr=3F2568AAC26998F9E813A1C5C3F436CA30F5D8EB The tas2562 digital volume is spread over four registers and is implemented as lookups into a table so the driver stores the value for the userspace control in the driver data. This defaults to 0 due to kzalloc() but the register default is 0x40400000 which maps onto something a bit over the largest value defined in the lookup table. While it's not an exact match update the default to the largest value, avoiding user surprise due to a sudden change on first write. Signed-off-by: Mark Brown Reviewed-by: Cezary Rojewski --- sound/soc/codecs/tas2562.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/sound/soc/codecs/tas2562.c b/sound/soc/codecs/tas2562.c index 9b863b000470..5fdbfec8ce3f 100644 --- a/sound/soc/codecs/tas2562.c +++ b/sound/soc/codecs/tas2562.c @@ -738,6 +738,8 @@ static int tas2562_probe(struct i2c_client *client) data->client =3D client; data->dev =3D &client->dev; data->model_id =3D (uintptr_t)i2c_get_match_data(client); + /* Register default is 0x40400000, this is closest */ + data->volume_lvl =3D (ARRAY_SIZE(float_vol_db_lookup) - 1) * 2; =20 tas2562_parse_dt(data); =20 --=20 2.47.3