From nobody Fri Oct 2 13:14:01 2026 Received: from mail-pg1-f179.google.com (mail-pg1-f179.google.com [209.85.215.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 946F33B52FF for ; Fri, 31 Jul 2026 07:44:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.179 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785483844; cv=none; b=BCGFoW93jPCJpC19/324c98qWDUg4cKvrIe1USVjidxMR7DDe1qyk5xP7NVjJtLvM0eLhJBwD+7QNjXs6nwptX1v94HlyhBJ0C+9NBGnuiVViRRx8zEETPDfCslu+sBc76FhiTxHeVG8qxceDI3XJxYO4+N2IcXRIqPxY2NEASU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785483844; c=relaxed/simple; bh=yE69Eme228d1LmreT7Y4hRtJZh1nZD7/C0FT5+F3hWs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=LHlcAw7p850jgQovpORvAaEiaQKZUoZXmgis8hJwhB36q12wa/Spw+HRVzkhwKmA/enfGXP3djRIdHVTM89Ez+7BgNrOs4QTeAS2tgay5rGFCBTqMAeB4oKXCEjtbk9DVPR/mKxWMgO9VVvHmbRn3x2ScHkkn4NpvaQ8taPG4bE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=chromium.org; spf=pass smtp.mailfrom=chromium.org; dkim=pass (1024-bit key) header.d=chromium.org header.i=@chromium.org header.b=CVCGVjlj; arc=none smtp.client-ip=209.85.215.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=chromium.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=chromium.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=chromium.org header.i=@chromium.org header.b="CVCGVjlj" Received: by mail-pg1-f179.google.com with SMTP id 41be03b00d2f7-ca97d139d8dso355070a12.2 for ; Fri, 31 Jul 2026 00:44:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; t=1785483842; x=1786088642; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=AazHT0RVZ5SXR5gPgJOo7RhEyRbnTq3IhCor0nbYEic=; b=CVCGVjljxqh6jMMYBrZQ2TxNHDup1a+y3XwF/OOpEeIZP+AP+Ohr86rKu0iyT6sRIo qZGiPR/Tiiytu44xmNRAhwjresjhoFjlJrWr8Au5FIN7ROpMF2uXLwaZeRSSyWZDNDWC sCersOcweBUsqZ5hKE1cpXW3aH1/TLeaEtG6k= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785483842; x=1786088642; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=AazHT0RVZ5SXR5gPgJOo7RhEyRbnTq3IhCor0nbYEic=; b=QkwydZhNaVVvO4fLmxymkRPIniqLcQPDbBTkF/Qh3bGxDYRBMERDj6UUBLTSoU2foz VKkV9jqXnA70R9nF3kkg3ExlXda7kLKyNGgHxNxFnoOQWqmkSWUyYnpi3BmIsDG+6zwn tMl8yICnB+B0wKAJ7Ndx7XO3Ih+z0E6oZ5+0sNRRyoDdcICAMF377OxcBfvojTkN74mu yn0rP3KjGFsaraXTBObn3Aplf09XZSNKBkwyX4PudXA/neaSVPl1oK3gUDRMSdpF/GVp U+0KzIVW31v9LuStYrYE8Lei1ekj5ls9YptKpHP0NpHEfuo1Fe00i8O6xUyBiGqPUPOy HxCA== X-Gm-Message-State: AOJu0YzivkApm0h72Meww0vhTdxOB1m5W610UF2mAh/oRoZLnhDjdIu9 dRzpbId50N55TMyCmJ9WkMsm2BRxroGeHtUJZBxD+yDQVQsLmmr3Tily/j2UrmNibFt7fs3Uaf8 DTyo= X-Gm-Gg: AR+sD13VuqjcQVMMQ2Pdrv8NtamQKPCQqStCGaVzlNl0W71oH3ym/oyTs02cy5F/EH8 PrJeGcoXjh3nI2j3+QyqXxgy68gNofiofPILYYAMIKbGjpGDirI3aWxl6dQFkCWiW6Jz6aSeD/w tCgDFI7NR1sFVFgSIt2hbFKuWkTi7Ayn7e1JpO2lSCKr6pCU3LObfcOQgHpSblm/d60lv/1rgbQ XjB4Xek7RFkluZdPJRPzGfqZZ5CMCeysihtRrjX+bdLS41kVcJxhocaRl4ZIWoYJ9AL7hAERJHk QoFHndRVkdXSQ2fBejH8bdCenvR58gVQozrI8dPyUqQOscfM70uMPboKMeq4CZ2NJ/QcG3OWlH7 8QyeW4uqM9zGJcKzYshIpkRfFxSvKow5WgdTi7GTEQPxWhSKwRRH/Jq8b1ER4Sn+Nq3AE3rlti7 iJNS2PuEJ39ERIBAbaDMrMMZhakeXfB8GY9ILRPcwWv3GuGgPWiVEY43eEDK90RvdCsaZzHcBpy 6/CttksD659v09pn+BW4rkARqTLCw== X-Received: by 2002:a05:6a20:728c:b0:3bf:e2f1:1b08 with SMTP id adf61e73a8af0-3c91b3a9745mr899592637.40.1785483841867; Fri, 31 Jul 2026 00:44:01 -0700 (PDT) Received: from localhost (79.162.199.104.bc.googleusercontent.com. [104.199.162.79]) by smtp.gmail.com with UTF8SMTPSA id 5a478bee46e88-3153dd4e5c7sm3124503eec.5.2026.07.31.00.43.59 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 31 Jul 2026 00:44:01 -0700 (PDT) From: Yu-Hsuan Hsu To: linux-kernel@vger.kernel.org Cc: Jaroslav Kysela , Takashi Iwai , Yu-Hsuan Hsu , =?UTF-8?q?C=C3=A1ssio=20Gabriel?= , linux-sound@vger.kernel.org Subject: [PATCH] ALSA: aloop: Fix spinlock deadlock in loopback_hrtimer_stop() Date: Fri, 31 Jul 2026 07:39:35 +0000 Message-ID: <20260731074255.1513402-1-yuhsuan@chromium.org> X-Mailer: git-send-email 2.55.0.508.g3f0d502094-goog Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In loopback_hrtimer_stop(), calling hrtimer_cancel() while holding cable->lock triggers an AB-BA spinlock deadlock if the hrtimer softirq is executing concurrently on another CPU: 1) CPU A runs loopback_trigger(STOP), acquires spin_lock(&cable->lock), and calls hrtimer_cancel(). Since hrtimer_cancel() is synchronous, it spins waiting for the executing callback to complete before returning. 2) CPU B executes loopback_hrtimer_function(), which immediately tries to acquire spin_lock(&cable->lock). This mutual dependency leads to a CPU hard lockup and NMI watchdog panic when multiple streams start and stop concurrently with small period sizes. Replace hrtimer_cancel() in loopback_hrtimer_stop() with the non-blocking hrtimer_try_to_cancel(), matching the behavior of jiffies timers (timer_delete vs timer_delete_sync). If try_to_cancel returns -1 because the handler is running, CPU A releases cable->lock cleanly. When the running handler subsequently acquires cable->lock, it observes that the stream is no longer in running state (cleared by trigger STOP) and terminates without re-arming the timer. Synchronous hrtimer_cancel() remains preserved in loopback_hrtimer_stop_sync() where cable->lock is not held. Fixes: bf08a5f698dc ("ALSA: aloop: Add 'hrtimer' option to timer_source") Signed-off-by: Yu-Hsuan Hsu --- sound/drivers/aloop.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sound/drivers/aloop.c b/sound/drivers/aloop.c index 236f49a7fb8b..60f5bf1e48bb 100644 --- a/sound/drivers/aloop.c +++ b/sound/drivers/aloop.c @@ -303,7 +303,7 @@ static inline int loopback_jiffies_timer_stop(struct lo= opback_pcm *dpcm) /* call in cable->lock */ static inline int loopback_hrtimer_stop(struct loopback_pcm *dpcm) { - hrtimer_cancel(&dpcm->hrtimer); + hrtimer_try_to_cancel(&dpcm->hrtimer); =20 return 0; } --=20 2.55.0.508.g3f0d502094-goog