Re: [PATCH v7 2/2] ALSA: usb-audio: bind the Topping M62's vendor controls
From: Mikhail Gavrilov <hidden>
Date: 2026-09-30 22:50:01
Also in:
linux-sound, sashiko-reviews
On Wed, 30 Sep 2026 21:50:22 +0000, sashiko-bot@kernel.org wrote:
Does this lockless teardown open a time-of-check to time-of-use race window before the tm context is freed by devres?
No. The two paths are serialized by the usb_device lock, and on the M62 the path does not exist. The failed probe runs with the device locked. usb_bus_type sets need_parent_lock, so the driver core takes the parent's lock around an interface probe (__driver_attach(), device_driver_attach()), and at enumeration the interfaces are added by usb_set_configuration(), whose caller must own the device lock. really_probe() unwinds a failed probe with device_unbind_cleanup() inside that region, so topping_master_teardown() runs with the usb_device locked. The disconnect does too. usb_audio_disconnect() runs from usb_disconnect(), which holds usb_lock_device() across usb_disable_device(), or from an unbind through device_driver_detach(), which takes the same lock. A later snd_usb_mixer_free() finds mixer->disconnected set and returns before private_free. So cpu1 and cpu2 in the sequence above cannot overlap. As for the premise: on the M62 only the AudioControl interface goes through usb_audio_probe(); the streaming interfaces are claimed from its probe. If that probe fails, chip->num_interfaces is still 0 and usb_audio_probe() frees the card itself, which runs topping_private_free() before the driver core unwinds devres. -- Thanks, Mikhail.