ALSA: hda: Check snd_hda_power_pm construct error before executing verb

When userspace writes 1 to /sys/bus/pci/devices/XX/remove to remove
HDA PCI device, the HDA hardware control path is shut down and devres
unmaps the BAR virtual address bus->remap_addr automatically during
driver removal.

If a delayed HDA verb command arrives after the MMIO region is
unmapped, the driver will access invalid virtual addresses and trigger
a page fault splat.

So add an error check right after constructing snd_hda_power_pm.

Signed-off-by: Bob Song <songxiebing@kylinos.cn>
Link: https://patch.msgid.link/20260717024948.506335-1-songxiebing@kylinos.cn
Signed-off-by: Takashi Iwai <tiwai@suse.de>
This commit is contained in:
Bob Song 2026-07-17 10:49:48 +08:00 committed by Takashi Iwai
parent 260fc7a0fe
commit df27e4dc80

View File

@ -39,6 +39,12 @@ static int call_exec_verb(struct hda_bus *bus, struct hda_codec *codec,
int err;
CLASS(snd_hda_power_pm, pm)(codec);
if (pm.err < 0 && !bus->core.chip_init) {
codec_warn(codec,
"Failed to send cmd 0x%x ret=[%d], hda control stopped\n",
cmd, pm.err);
return pm.err;
}
guard(mutex)(&bus->core.cmd_mutex);
if (flags & HDA_RW_NO_RESPONSE_FALLBACK)
bus->no_response_fallback = 1;