From nobody Mon Sep 28 09:59:41 2026 Received: from mail-ed1-f47.google.com (mail-ed1-f47.google.com [209.85.208.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AE556353A69 for ; Sun, 23 Aug 2026 17:37:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787506670; cv=none; b=qkB7edVxEv1dcFNZNnDc8xcmYPYv4KQcXrFa+2nPNZxD+E06nVy2ZhFK7dC9jfeNAJFDNs2reNbHInr4Zh3iMvbkJkOZrP9ie/SUJSyqkKRCnm+r9TslL7KZyvJhJRAW1FuioeCfwoLje4kFJqceYE22JYTjnnjQe2cxDgVODrc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787506670; c=relaxed/simple; bh=vDzC1lXQTX20zA2uT4KvproTMpd8ikDZ7Uz9qaUggPI=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=Lpfr+SXxjhK045JmX2fQSiGHtylP997W/DZGV7BQ4cqmsTLGjX8t8deyECYT1qlInAlPyHhyIqpViWbBBfdAH+EcOtdV4LbwlzhUYl3g5spzJoO53DvP3cBeM9XNZREOsTZKPFxu444DUiyUpU/xoDPsr3/dePEyVkEpTlawyWY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=pQacU6NX; arc=none smtp.client-ip=209.85.208.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="pQacU6NX" Received: by mail-ed1-f47.google.com with SMTP id 4fb4d7f45d1cf-69c600f76ccso4512747a12.0 for ; Sun, 23 Aug 2026 10:37:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787506667; x=1788111467; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=WzxtLwRD92+TCzzKKRXbUxryNiIrjmzaSY4Z8wvm3PE=; b=pQacU6NXgdwzVgaamRqgbVzWhlcLvjBztie4RtyJLUrQHp2L4NKw616g3JngzNBDd8 25xUYQDJJylCNt7sGiw9GPtMC/GwThJq0CIft1otleNIrBCyZf0Ia69O2vHYymJk6jJ4 Jvh/wiCbT/D2aIJDPjAI6YRsopbagDb2yK9XzGI6O7EUtKbqdJfK/IYTZSqSsmiahIpA Ibck/zQu4+RTs78ZOMJdB72aSEJ/3CVk7BqYx/Q8kPCNvryXfdNUl84XpeJKQ1qq3XEg drO100RRuPdI9swX012HwWiz9FqP0zCYc8orybXc7Sowl/B+3p/z25NS6v24ku5xakzX jKpg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787506667; x=1788111467; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=WzxtLwRD92+TCzzKKRXbUxryNiIrjmzaSY4Z8wvm3PE=; b=IpV2ZPxVFyavngcvbgDHIRMsSgy3MyBfD/o4496/VgYYqwFRlWpIXzWO63MxaF7N05 n33IRaO4hs43k1DtvqSxoMrEZJQ1oZj7mtdGIvT/n5/18cTHmr18N7Lp692bF7BpLTW2 xWuKJZtHEMh+GZ4H0wDgx5ULHfdMh2UXCGjlLy0l9ZqCdwUipw41814ESg2ra5I93yWO L39/sp9LdwRCK1d2qWCXwGXx2KXYt+O76RsYdaquAvLHHLyBcD1TS+JeT6cyaYPS7LT0 QmtwYwcWMUAMeUwfXjezqyTN3Io6TVYQvULm0ssjZqE0NIysfTWTWHpLUe6R6LULUfBI Ze8Q== X-Forwarded-Encrypted: i=1; AHgh+Rr4DDl8+fVPdv4HvfT8eV2/MdAhmW3kOv2hgSTrnnqCS7yUbr0WyKkwIUuC6jBRtoHeZAB9y0JzgOxzdPU=@vger.kernel.org X-Gm-Message-State: AFuF++mURFCvFbT99jY11L7W8bYglUpjxKtQkA7nrF4xEahPkfqKTj5/ T0JvipvLKG4CjM27APoP9ytH4buwrfORclM8lIVJ5bhW/3CT8wGmuztH X-Gm-Gg: AR+sD12pVH3RQ6g1yO2h/G0bVcn0g3NZ3nYcIMrkZBtCfGqh5i0S1/P7g/S4TzmMPek SSUiH/DBguMWdnUoMSI52Lhcz9l4+QGmE8TevL6r6UxQ2Twbwcu9p+SZnbJmBe5ziWeEihwDH94 f8KlWf5BYxralu58iI2r2Vup2pTIyrh0MBANcKHgXjiT5hW8m0RPTZ11vu9LNrDl7zLTP6B7H60 +4m2tYqsil90fiOR55tb64ALmyoR44nX+ann4wLFxo2p4PNqrS93jLNARa8VwwmzQFwMoQzTUWM 48QdCSHJNK2NYJaCXkvz0ClehrzRKeM2edAENvRlDtiGnt1Ja+mPBrvwARFUKUWIoRyGndA8Cn2 ksD96kCgEmerJ3YW4UiPtf6dixeLCRIqV8UWZxX+GPV3/p7GoCLh5pabuOxgu5tvuvj6IYMwqMw 0j7YQiqtnjn2gvzmVwyS/WXkRgkU7w3Dmq2hpBrjVK1XteVBQe33hrasazVwe9wPg1HmtpzMqRP fnVmRRn8U2pW7Ne9oYBJ3njfWstjseOLpmbIzPEkIf3EyD6ii78gbbwNIBzB+LR/8gWrukSVCS2 dYMjRPxVbl9eyKjelpJdGCjcqPc6kGdUFTkw5DeKLPmD+kYl74tnOqNlpj5zdtwhET2N1Syi1w= = X-Received: by 2002:a17:907:7b83:b0:c20:fe93:a86 with SMTP id a640c23a62f3a-c246a62b495mr2653594366b.18.1787506666570; Sun, 23 Aug 2026 10:37:46 -0700 (PDT) Received: from localhost.localdomain (dynamic-2a02-3100-b027-cd01-554a-ffde-5279-f351.310.pool.telefonica.de. [2a02:3100:b027:cd01:554a:ffde:5279:f351]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c249689fa1dsm791239266b.56.2026.08.23.10.37.45 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 23 Aug 2026 10:37:46 -0700 (PDT) From: Karl Mehltretter To: Maxime Ripard , Dave Stevenson Cc: Karl Mehltretter , =?UTF-8?q?Ma=C3=ADra=20Canal?= , Raspberry Pi Kernel Maintenance , Maarten Lankhorst , Thomas Zimmermann , David Airlie , Simona Vetter , Mark Brown , Liam Girdwood , Cezary Rojewski , Kuninori Morimoto , linux-sound@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v2] drm/vc4: hdmi: Unregister the ASoC card on unbind Date: Sun, 23 Aug 2026 19:37:40 +0200 Message-Id: <20260823173740.2983-1-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" vc4_hdmi, including the embedded ASoC card, is DRM-managed and freed with the DRM device when the aggregate device is torn down. The card is registered with devm_snd_soc_register_card() on the HDMI platform device from the component bind callback, so its devres node starts out in the component's devres group and used to be released at component unbind, while vc4_hdmi is still alive. Whenever an ASoC component is registered, the core retries every card waiting for components. For a devm-managed card, each retry destroys and re-adds its devres node. Because snd_soc_bind_card() requeues the card and converts -EPROBE_DEFER to success, even a retry that still defers can move the node outside the now-closed component devres group. It is then only released at platform driver detach, after vc4_hdmi has been freed: # modprobe vc4; rmmod vc4 BUG: KASAN: slab-use-after-free in snd_soc_unregister_card Read of size 1 at addr ffff0000456a8450 by task rmmod/262 devm_card_bind_release / devres_release_all / driver_detach Allocated by task 171: drmm_kmalloc / vc4_hdmi_bind Freed by task 262 (rmmod): drm_dev_put / component_del Register the card without devm and unregister it from a component unbind callback, where the HDMI device resources and the DRM-managed structure are both still alive, regardless of where the card got bound. Fixes: 42d99857d6f0 ("ASoC: core: Move all users to deferrable card binding= ") Cc: stable@vger.kernel.org Assisted-by: LLM Signed-off-by: Karl Mehltretter --- v2: - Preserve the existing ASoC component-lifetime comment and document at the card registration site how deferrable binding can move the card's devres node outside the component devres group. - Point Fixes at the deferrable card binding change. - Add the ASoC maintainers and linux-sound recipients, add the stable trailer, and update Assisted-by to the current format. Tested on a Raspberry Pi 400 (BCM2711), v7.2-11658-g26260251022f, with KASAN: report gone, rmmod/insmod loop clean. drivers/gpu/drm/vc4/vc4_hdmi.c | 24 +++++++++++++++++++++--- drivers/gpu/drm/vc4/vc4_hdmi.h | 1 + 2 files changed, 22 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/vc4/vc4_hdmi.c b/drivers/gpu/drm/vc4/vc4_hdmi.c index 17c8635c5afa..7e312932488a 100644 --- a/drivers/gpu/drm/vc4/vc4_hdmi.c +++ b/drivers/gpu/drm/vc4/vc4_hdmi.c @@ -2422,12 +2422,18 @@ static int vc4_hdmi_audio_init(struct vc4_hdmi *vc4= _hdmi) * snd_soc_card_get_drvdata() if needed. */ snd_soc_card_set_drvdata(card, vc4_hdmi); - ret =3D devm_snd_soc_register_card(dev, card); + + /* + * Deferred card binding can move a devm registration outside the + * component devres group, so unregister the card explicitly at unbind. + */ + ret =3D snd_soc_register_card(card); if (ret) - dev_err_probe(dev, ret, "Could not register sound card\n"); + return dev_err_probe(dev, ret, "Could not register sound card\n"); =20 - return ret; + vc4_hdmi->audio.card_registered =3D true; =20 + return 0; } =20 static irqreturn_t vc4_hdmi_hpd_irq_thread(int irq, void *priv) @@ -3345,8 +3351,20 @@ err_put_runtime_pm: return ret; } =20 +static void vc4_hdmi_unbind(struct device *dev, struct device *master, + void *data) +{ + struct vc4_hdmi *vc4_hdmi =3D dev_get_drvdata(dev); + + if (vc4_hdmi->audio.card_registered) { + snd_soc_unregister_card(&vc4_hdmi->audio.card); + vc4_hdmi->audio.card_registered =3D false; + } +} + static const struct component_ops vc4_hdmi_ops =3D { .bind =3D vc4_hdmi_bind, + .unbind =3D vc4_hdmi_unbind, }; =20 static int vc4_hdmi_dev_probe(struct platform_device *pdev) diff --git a/drivers/gpu/drm/vc4/vc4_hdmi.h b/drivers/gpu/drm/vc4/vc4_hdmi.h index 29d461d4ee49..444c73513d86 100644 --- a/drivers/gpu/drm/vc4/vc4_hdmi.h +++ b/drivers/gpu/drm/vc4/vc4_hdmi.h @@ -106,6 +106,7 @@ struct vc4_hdmi_audio { struct snd_soc_dai_link_component platform; struct snd_dmaengine_dai_dma_data dma_data; bool streaming; + bool card_registered; }; =20 /* General HDMI hardware state. */ --=20 2.39.5 (Apple Git-154)