Thread (6 messages) 6 messages, 2 authors, 7d ago

Re: [PATCH v7 2/2] ALSA: usb-audio: bind the Topping M62's vendor controls

From: Mikhail Gavrilov <hidden>
Date: 2026-09-30 22:50:01
Also in: linux-sound, sashiko-reviews

On Wed, 30 Sep 2026 21:50:22 +0000, sashiko-bot@kernel.org wrote:
Does this lockless teardown open a time-of-check to time-of-use race
window before the tm context is freed by devres?
No. The two paths are serialized by the usb_device lock, and on the
M62 the path does not exist.

The failed probe runs with the device locked. usb_bus_type sets
need_parent_lock, so the driver core takes the parent's lock around an
interface probe (__driver_attach(), device_driver_attach()), and at
enumeration the interfaces are added by usb_set_configuration(), whose
caller must own the device lock. really_probe() unwinds a failed probe
with device_unbind_cleanup() inside that region, so
topping_master_teardown() runs with the usb_device locked.

The disconnect does too. usb_audio_disconnect() runs from
usb_disconnect(), which holds usb_lock_device() across
usb_disable_device(), or from an unbind through device_driver_detach(),
which takes the same lock. A later snd_usb_mixer_free() finds
mixer->disconnected set and returns before private_free.

So cpu1 and cpu2 in the sequence above cannot overlap.

As for the premise: on the M62 only the AudioControl interface goes
through usb_audio_probe(); the streaming interfaces are claimed from
its probe. If that probe fails, chip->num_interfaces is still 0 and
usb_audio_probe() frees the card itself, which runs
topping_private_free() before the driver core unwinds devres.

-- 
Thanks,
Mikhail.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help