On Sun, Sep 27, 2026 at 08:07:38AM +0800, Slavin Liu wrote:
> Commit b045248399d0 ("ASoC: fsl_asrc: Replace dma_request_slave_channel()
> by dma_request_chan()") made ->get_dma_channel() propagate error
> pointers, so the !NULL check added by commit b4136c0d69ea ("ASoC:
> fsl_asrc: check the second front-end DMA channel") no longer catches
> failures and the error pointer would be dereferenced at
> tmp_chan->private.
> 
> Use IS_ERR() and propagate the error, keeping the release of the
> previously acquired persistent Front-End channel.

...

>               /* Get DMA request of Front-End */
>               tmp_chan = asrc->get_dma_channel(pair, dir);
> -             if (!tmp_chan) {
> +             if (IS_ERR(tmp_chan)) {
>                       dma_release_channel(pair->dma_chan[!dir]);

>                       pair->dma_chan[!dir] = NULL;

> -                     return -EINVAL;
> +                     return PTR_ERR(tmp_chan);

I believe this has to be left untouched as it might leak to user space.

>               }

...

I also wondering why Sashiko hasn't pointed that out during the original
submission...

-- 
With Best Regards,
Andy Shevchenko



Reply via email to