From df27e4dc80c4a30ad206432cb848aab00de22ca7 Mon Sep 17 00:00:00 2001 From: Bob Song Date: Fri, 17 Jul 2026 10:49:48 +0800 Subject: [PATCH] ALSA: hda: Check snd_hda_power_pm construct error before executing verb When userspace writes 1 to /sys/bus/pci/devices/XX/remove to remove HDA PCI device, the HDA hardware control path is shut down and devres unmaps the BAR virtual address bus->remap_addr automatically during driver removal. If a delayed HDA verb command arrives after the MMIO region is unmapped, the driver will access invalid virtual addresses and trigger a page fault splat. So add an error check right after constructing snd_hda_power_pm. Signed-off-by: Bob Song Link: https://patch.msgid.link/20260717024948.506335-1-songxiebing@kylinos.cn Signed-off-by: Takashi Iwai --- sound/hda/common/codec.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/sound/hda/common/codec.c b/sound/hda/common/codec.c index b9ded149ea11..641083c2376f 100644 --- a/sound/hda/common/codec.c +++ b/sound/hda/common/codec.c @@ -39,6 +39,12 @@ static int call_exec_verb(struct hda_bus *bus, struct hda_codec *codec, int err; CLASS(snd_hda_power_pm, pm)(codec); + if (pm.err < 0 && !bus->core.chip_init) { + codec_warn(codec, + "Failed to send cmd 0x%x ret=[%d], hda control stopped\n", + cmd, pm.err); + return pm.err; + } guard(mutex)(&bus->core.cmd_mutex); if (flags & HDA_RW_NO_RESPONSE_FALLBACK) bus->no_response_fallback = 1;