From 8beb58f70228ba1188d2396b18c34fbaf048334f Mon Sep 17 00:00:00 2001 From: Mayank Rana Date: Wed, 12 Aug 2020 15:30:16 -0700 Subject: [PATCH] sound: usb: Add NULL check against udev with uaudio_dev_cleanup() API uaudio_dev_cleanup() API can be called from ADSP SSR context (from work context) and USB headset disconnect context. When USB headset is being removed, driver sends disconnect notification to ADSP firmware and it can be blocked for 10 seconds (timeout) before calling uaudio_dev_cleanup(). If this thread is block (possibly due to ADSP SSR), and in parallel driver is handling ADSP SSR notification, driver is releasing all resource including secondary event ring. Once above thread unblocks or timeout, it goes try to release secondary USB event ring. As uaudio_dev_cleanup() is already being called, and release secondary USB event ring, it shall see udev->dev as NULL. Fix this issue by adding explicit check against udev with uaudio_dev_cleanup() API. Change-Id: I1e2e4a61dcbea4c0570ac97677bf74b453fac82c Signed-off-by: Mayank Rana --- sound/usb/usb_audio_qmi_svc.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/sound/usb/usb_audio_qmi_svc.c b/sound/usb/usb_audio_qmi_svc.c index 0a1ea34d2b95..b7ff300b9f96 100644 --- a/sound/usb/usb_audio_qmi_svc.c +++ b/sound/usb/usb_audio_qmi_svc.c @@ -860,6 +860,11 @@ static void uaudio_dev_cleanup(struct uaudio_dev *dev) { int if_idx; + if (!dev->udev) { + uaudio_dbg("USB audio device memory is already freed.\n"); + return; + } + /* free xfer buffer and unmap xfer ring and buf per interface */ for (if_idx = 0; if_idx < dev->num_intf; if_idx++) { if (!dev->info[if_idx].in_use)