1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3 * Routines for driver control interface
4 * Copyright (c) by Jaroslav Kysela <perex@perex.cz>
5 */
6
7 #include <linux/threads.h>
8 #include <linux/interrupt.h>
9 #include <linux/module.h>
10 #include <linux/moduleparam.h>
11 #include <linux/slab.h>
12 #include <linux/vmalloc.h>
13 #include <linux/time.h>
14 #include <linux/mm.h>
15 #include <linux/math64.h>
16 #include <linux/sched/signal.h>
17 #include <sound/core.h>
18 #include <sound/minors.h>
19 #include <sound/info.h>
20 #include <sound/control.h>
21
22 #ifdef CONFIG_SND_CTL_DEBUG
23 #define CREATE_TRACE_POINTS
24 #include "control_trace.h"
25 #else
26 #define trace_snd_ctl_put(card, kctl, iname, expected, actual)
27 #endif
28
29 // Max allocation size for user controls.
30 static int max_user_ctl_alloc_size = 8 * 1024 * 1024;
31 module_param_named(max_user_ctl_alloc_size, max_user_ctl_alloc_size, int, 0444);
32 MODULE_PARM_DESC(max_user_ctl_alloc_size, "Max allocation size for user controls");
33
34 #define MAX_CONTROL_COUNT 1028
35
36 struct snd_kctl_ioctl {
37 struct list_head list; /* list of all ioctls */
38 snd_kctl_ioctl_func_t fioctl;
39 };
40
41 DECLARE_RWSEM(snd_ioctl_rwsem);
42 static DECLARE_RWSEM(snd_ctl_layer_rwsem);
43 static LIST_HEAD(snd_control_ioctls);
44 #ifdef CONFIG_COMPAT
45 static LIST_HEAD(snd_control_compat_ioctls);
46 #endif
47 static struct snd_ctl_layer_ops *snd_ctl_layer;
48
49 static int snd_ctl_remove_locked(struct snd_card *card,
50 struct snd_kcontrol *kcontrol);
51
snd_ctl_open(struct inode * inode,struct file * file)52 static int snd_ctl_open(struct inode *inode, struct file *file)
53 {
54 struct snd_card *card;
55 struct snd_ctl_file *ctl;
56 int i, err;
57
58 stream_open(inode, file);
59
60 card = snd_lookup_minor_data(iminor(inode), SNDRV_DEVICE_TYPE_CONTROL);
61 if (!card) {
62 err = -ENODEV;
63 goto __error1;
64 }
65 err = snd_card_file_add(card, file);
66 if (err < 0)
67 goto __error1;
68 if (!try_module_get(card->module)) {
69 err = -ENODEV;
70 goto __error2;
71 }
72 ctl = kzalloc_obj(*ctl);
73 if (ctl == NULL) {
74 err = -ENOMEM;
75 goto __error;
76 }
77 INIT_LIST_HEAD(&ctl->events);
78 init_waitqueue_head(&ctl->change_sleep);
79 spin_lock_init(&ctl->read_lock);
80 ctl->card = card;
81 for (i = 0; i < SND_CTL_SUBDEV_ITEMS; i++)
82 ctl->preferred_subdevice[i] = -1;
83 ctl->pid = get_pid(task_pid(current));
84 file->private_data = ctl;
85 scoped_guard(write_lock_irqsave, &card->controls_rwlock)
86 list_add_tail(&ctl->list, &card->ctl_files);
87 snd_card_unref(card);
88 return 0;
89
90 __error:
91 module_put(card->module);
92 __error2:
93 snd_card_file_remove(card, file);
94 __error1:
95 if (card)
96 snd_card_unref(card);
97 return err;
98 }
99
snd_ctl_empty_read_queue(struct snd_ctl_file * ctl)100 static void snd_ctl_empty_read_queue(struct snd_ctl_file * ctl)
101 {
102 struct snd_kctl_event *cread;
103
104 guard(spinlock_irqsave)(&ctl->read_lock);
105 while (!list_empty(&ctl->events)) {
106 cread = snd_kctl_event(ctl->events.next);
107 list_del(&cread->list);
108 kfree(cread);
109 }
110 }
111
snd_ctl_release(struct inode * inode,struct file * file)112 static int snd_ctl_release(struct inode *inode, struct file *file)
113 {
114 struct snd_card *card;
115 struct snd_ctl_file *ctl;
116 struct snd_kcontrol *control;
117 unsigned int idx;
118
119 ctl = file->private_data;
120 file->private_data = NULL;
121 card = ctl->card;
122
123 scoped_guard(write_lock_irqsave, &card->controls_rwlock)
124 list_del(&ctl->list);
125
126 scoped_guard(rwsem_write, &card->controls_rwsem) {
127 list_for_each_entry(control, &card->controls, list)
128 for (idx = 0; idx < control->count; idx++)
129 if (control->vd[idx].owner == ctl)
130 control->vd[idx].owner = NULL;
131 }
132
133 snd_fasync_free(ctl->fasync);
134 snd_ctl_empty_read_queue(ctl);
135 put_pid(ctl->pid);
136 kfree(ctl);
137 module_put(card->module);
138 snd_card_file_remove(card, file);
139 return 0;
140 }
141
142 /**
143 * snd_ctl_notify - Send notification to user-space for a control change
144 * @card: the card to send notification
145 * @mask: the event mask, SNDRV_CTL_EVENT_*
146 * @id: the ctl element id to send notification
147 *
148 * This function adds an event record with the given id and mask, appends
149 * to the list and wakes up the user-space for notification. This can be
150 * called in the atomic context.
151 */
snd_ctl_notify(struct snd_card * card,unsigned int mask,struct snd_ctl_elem_id * id)152 void snd_ctl_notify(struct snd_card *card, unsigned int mask,
153 struct snd_ctl_elem_id *id)
154 {
155 struct snd_ctl_file *ctl;
156 struct snd_kctl_event *ev;
157
158 if (snd_BUG_ON(!card || !id))
159 return;
160 if (card->shutdown)
161 return;
162
163 guard(read_lock_irqsave)(&card->controls_rwlock);
164 #if IS_ENABLED(CONFIG_SND_MIXER_OSS)
165 card->mixer_oss_change_count++;
166 #endif
167 list_for_each_entry(ctl, &card->ctl_files, list) {
168 if (!ctl->subscribed)
169 continue;
170 scoped_guard(spinlock, &ctl->read_lock) {
171 list_for_each_entry(ev, &ctl->events, list) {
172 if (ev->id.numid == id->numid) {
173 ev->mask |= mask;
174 goto _found;
175 }
176 }
177 ev = kzalloc_obj(*ev, GFP_ATOMIC);
178 if (ev) {
179 ev->id = *id;
180 ev->mask = mask;
181 list_add_tail(&ev->list, &ctl->events);
182 } else {
183 dev_err(card->dev, "No memory available to allocate event\n");
184 }
185 _found:
186 wake_up(&ctl->change_sleep);
187 }
188 snd_kill_fasync(ctl->fasync, SIGIO, POLL_IN);
189 }
190 }
191 EXPORT_SYMBOL(snd_ctl_notify);
192
193 /**
194 * snd_ctl_notify_one - Send notification to user-space for a control change
195 * @card: the card to send notification
196 * @mask: the event mask, SNDRV_CTL_EVENT_*
197 * @kctl: the pointer with the control instance
198 * @ioff: the additional offset to the control index
199 *
200 * This function calls snd_ctl_notify() and does additional jobs
201 * like LED state changes.
202 */
snd_ctl_notify_one(struct snd_card * card,unsigned int mask,struct snd_kcontrol * kctl,unsigned int ioff)203 void snd_ctl_notify_one(struct snd_card *card, unsigned int mask,
204 struct snd_kcontrol *kctl, unsigned int ioff)
205 {
206 struct snd_ctl_elem_id id = kctl->id;
207 struct snd_ctl_layer_ops *lops;
208
209 id.index += ioff;
210 id.numid += ioff;
211 snd_ctl_notify(card, mask, &id);
212 guard(rwsem_read)(&snd_ctl_layer_rwsem);
213 for (lops = snd_ctl_layer; lops; lops = lops->next)
214 lops->lnotify(card, mask, kctl, ioff);
215 }
216 EXPORT_SYMBOL(snd_ctl_notify_one);
217
218 /**
219 * snd_ctl_new - create a new control instance with some elements
220 * @kctl: the pointer to store new control instance
221 * @count: the number of elements in this control
222 * @access: the default access flags for elements in this control
223 * @file: given when locking these elements
224 *
225 * Allocates a memory object for a new control instance. The instance has
226 * elements as many as the given number (@count). Each element has given
227 * access permissions (@access). Each element is locked when @file is given.
228 *
229 * Return: 0 on success, error code on failure
230 */
snd_ctl_new(struct snd_kcontrol ** kctl,unsigned int count,unsigned int access,struct snd_ctl_file * file)231 static int snd_ctl_new(struct snd_kcontrol **kctl, unsigned int count,
232 unsigned int access, struct snd_ctl_file *file)
233 {
234 unsigned int idx;
235
236 if (count == 0 || count > MAX_CONTROL_COUNT)
237 return -EINVAL;
238
239 *kctl = kzalloc_flex(**kctl, vd, count);
240 if (!*kctl)
241 return -ENOMEM;
242
243 (*kctl)->count = count;
244 for (idx = 0; idx < count; idx++) {
245 (*kctl)->vd[idx].access = access;
246 (*kctl)->vd[idx].owner = file;
247 }
248
249 return 0;
250 }
251
252 /**
253 * snd_ctl_new1 - create a control instance from the template
254 * @ncontrol: the initialization record
255 * @private_data: the private data to set
256 *
257 * Allocates a new struct snd_kcontrol instance and initialize from the given
258 * template. When the access field of ncontrol is 0, it's assumed as
259 * READWRITE access. When the count field is 0, it's assumes as one.
260 *
261 * Return: The pointer of the newly generated instance, or %NULL on failure.
262 */
snd_ctl_new1(const struct snd_kcontrol_new * ncontrol,void * private_data)263 struct snd_kcontrol *snd_ctl_new1(const struct snd_kcontrol_new *ncontrol,
264 void *private_data)
265 {
266 struct snd_kcontrol *kctl;
267 unsigned int count;
268 unsigned int access;
269 int err;
270
271 if (snd_BUG_ON(!ncontrol || !ncontrol->info))
272 return NULL;
273
274 count = ncontrol->count;
275 if (count == 0)
276 count = 1;
277
278 access = ncontrol->access;
279 if (access == 0)
280 access = SNDRV_CTL_ELEM_ACCESS_READWRITE;
281 access &= (SNDRV_CTL_ELEM_ACCESS_READWRITE |
282 SNDRV_CTL_ELEM_ACCESS_VOLATILE |
283 SNDRV_CTL_ELEM_ACCESS_INACTIVE |
284 SNDRV_CTL_ELEM_ACCESS_TLV_READWRITE |
285 SNDRV_CTL_ELEM_ACCESS_TLV_COMMAND |
286 SNDRV_CTL_ELEM_ACCESS_TLV_CALLBACK |
287 SNDRV_CTL_ELEM_ACCESS_LED_MASK |
288 SNDRV_CTL_ELEM_ACCESS_SKIP_CHECK);
289
290 err = snd_ctl_new(&kctl, count, access, NULL);
291 if (err < 0)
292 return NULL;
293
294 /* The 'numid' member is decided when calling snd_ctl_add(). */
295 kctl->id.iface = ncontrol->iface;
296 kctl->id.device = ncontrol->device;
297 kctl->id.subdevice = ncontrol->subdevice;
298 if (ncontrol->name) {
299 strscpy(kctl->id.name, ncontrol->name, sizeof(kctl->id.name));
300 if (strcmp(ncontrol->name, kctl->id.name) != 0)
301 pr_warn("ALSA: Control name '%s' truncated to '%s'\n",
302 ncontrol->name, kctl->id.name);
303 }
304 kctl->id.index = ncontrol->index;
305
306 kctl->info = ncontrol->info;
307 kctl->get = ncontrol->get;
308 kctl->put = ncontrol->put;
309 kctl->tlv.p = ncontrol->tlv.p;
310
311 kctl->private_value = ncontrol->private_value;
312 kctl->private_data = private_data;
313
314 return kctl;
315 }
316 EXPORT_SYMBOL(snd_ctl_new1);
317
318 /**
319 * snd_ctl_free_one - release the control instance
320 * @kcontrol: the control instance
321 *
322 * Releases the control instance created via snd_ctl_new()
323 * or snd_ctl_new1().
324 * Don't call this after the control was added to the card.
325 */
snd_ctl_free_one(struct snd_kcontrol * kcontrol)326 void snd_ctl_free_one(struct snd_kcontrol *kcontrol)
327 {
328 if (kcontrol) {
329 if (kcontrol->private_free)
330 kcontrol->private_free(kcontrol);
331 kfree(kcontrol);
332 }
333 }
334 EXPORT_SYMBOL(snd_ctl_free_one);
335
snd_ctl_remove_numid_conflict(struct snd_card * card,unsigned int count)336 static bool snd_ctl_remove_numid_conflict(struct snd_card *card,
337 unsigned int count)
338 {
339 struct snd_kcontrol *kctl;
340
341 /* Make sure that the ids assigned to the control do not wrap around */
342 if (card->last_numid >= UINT_MAX - count)
343 card->last_numid = 0;
344
345 list_for_each_entry(kctl, &card->controls, list) {
346 if (kctl->id.numid < card->last_numid + 1 + count &&
347 kctl->id.numid + kctl->count > card->last_numid + 1) {
348 card->last_numid = kctl->id.numid + kctl->count - 1;
349 return true;
350 }
351 }
352 return false;
353 }
354
snd_ctl_find_hole(struct snd_card * card,unsigned int count)355 static int snd_ctl_find_hole(struct snd_card *card, unsigned int count)
356 {
357 unsigned int iter = 100000;
358
359 while (snd_ctl_remove_numid_conflict(card, count)) {
360 if (--iter == 0) {
361 /* this situation is very unlikely */
362 dev_err(card->dev, "unable to allocate new control numid\n");
363 return -ENOMEM;
364 }
365 }
366 return 0;
367 }
368
369 /* check whether the given id is contained in the given kctl */
elem_id_matches(const struct snd_kcontrol * kctl,const struct snd_ctl_elem_id * id)370 static bool elem_id_matches(const struct snd_kcontrol *kctl,
371 const struct snd_ctl_elem_id *id)
372 {
373 return kctl->id.iface == id->iface &&
374 kctl->id.device == id->device &&
375 kctl->id.subdevice == id->subdevice &&
376 !strncmp(kctl->id.name, id->name, sizeof(kctl->id.name)) &&
377 kctl->id.index <= id->index &&
378 kctl->id.index + kctl->count > id->index;
379 }
380
381 #ifdef CONFIG_SND_CTL_FAST_LOOKUP
382 /* Compute a hash key for the corresponding ctl id
383 * It's for the name lookup, hence the numid is excluded.
384 * The hash key is bound in LONG_MAX to be used for Xarray key.
385 */
386 #define MULTIPLIER 37
get_ctl_id_hash(const struct snd_ctl_elem_id * id)387 static unsigned long get_ctl_id_hash(const struct snd_ctl_elem_id *id)
388 {
389 int i;
390 unsigned long h;
391
392 h = id->iface;
393 h = MULTIPLIER * h + id->device;
394 h = MULTIPLIER * h + id->subdevice;
395 for (i = 0; i < SNDRV_CTL_ELEM_ID_NAME_MAXLEN && id->name[i]; i++)
396 h = MULTIPLIER * h + id->name[i];
397 h = MULTIPLIER * h + id->index;
398 h &= LONG_MAX;
399 return h;
400 }
401
402 /* add hash entries to numid and ctl xarray tables */
add_hash_entries(struct snd_card * card,struct snd_kcontrol * kcontrol)403 static void add_hash_entries(struct snd_card *card,
404 struct snd_kcontrol *kcontrol)
405 {
406 struct snd_ctl_elem_id id = kcontrol->id;
407 int i;
408
409 xa_store_range(&card->ctl_numids, kcontrol->id.numid,
410 kcontrol->id.numid + kcontrol->count - 1,
411 kcontrol, GFP_KERNEL);
412
413 for (i = 0; i < kcontrol->count; i++) {
414 id.index = kcontrol->id.index + i;
415 if (xa_insert(&card->ctl_hash, get_ctl_id_hash(&id),
416 kcontrol, GFP_KERNEL)) {
417 /* skip hash for this entry, noting we had collision */
418 card->ctl_hash_collision = true;
419 dev_dbg(card->dev, "ctl_hash collision %d:%s:%d\n",
420 id.iface, id.name, id.index);
421 }
422 }
423 }
424
425 /* remove hash entries that have been added */
remove_hash_entries(struct snd_card * card,struct snd_kcontrol * kcontrol)426 static void remove_hash_entries(struct snd_card *card,
427 struct snd_kcontrol *kcontrol)
428 {
429 struct snd_ctl_elem_id id = kcontrol->id;
430 struct snd_kcontrol *matched;
431 unsigned long h;
432 int i;
433
434 for (i = 0; i < kcontrol->count; i++) {
435 xa_erase(&card->ctl_numids, id.numid);
436 h = get_ctl_id_hash(&id);
437 matched = xa_load(&card->ctl_hash, h);
438 if (matched && (matched == kcontrol ||
439 elem_id_matches(matched, &id)))
440 xa_erase(&card->ctl_hash, h);
441 id.index++;
442 id.numid++;
443 }
444 }
445 #else /* CONFIG_SND_CTL_FAST_LOOKUP */
add_hash_entries(struct snd_card * card,struct snd_kcontrol * kcontrol)446 static inline void add_hash_entries(struct snd_card *card,
447 struct snd_kcontrol *kcontrol)
448 {
449 }
remove_hash_entries(struct snd_card * card,struct snd_kcontrol * kcontrol)450 static inline void remove_hash_entries(struct snd_card *card,
451 struct snd_kcontrol *kcontrol)
452 {
453 }
454 #endif /* CONFIG_SND_CTL_FAST_LOOKUP */
455
456 enum snd_ctl_add_mode {
457 CTL_ADD_EXCLUSIVE, CTL_REPLACE, CTL_ADD_ON_REPLACE,
458 };
459
460 /* add/replace a new kcontrol object; call with card->controls_rwsem locked */
__snd_ctl_add_replace(struct snd_card * card,struct snd_kcontrol * kcontrol,enum snd_ctl_add_mode mode)461 static int __snd_ctl_add_replace(struct snd_card *card,
462 struct snd_kcontrol *kcontrol,
463 enum snd_ctl_add_mode mode)
464 {
465 struct snd_ctl_elem_id id;
466 unsigned int idx;
467 struct snd_kcontrol *old;
468 int err;
469
470 lockdep_assert_held_write(&card->controls_rwsem);
471
472 id = kcontrol->id;
473 if (id.index > UINT_MAX - kcontrol->count)
474 return -EINVAL;
475
476 old = snd_ctl_find_id(card, &id);
477 if (!old) {
478 if (mode == CTL_REPLACE)
479 return -EINVAL;
480 } else {
481 if (mode == CTL_ADD_EXCLUSIVE) {
482 dev_err(card->dev,
483 "control %i:%i:%i:%s:%i is already present\n",
484 id.iface, id.device, id.subdevice, id.name,
485 id.index);
486 return -EBUSY;
487 }
488
489 err = snd_ctl_remove_locked(card, old);
490 if (err < 0)
491 return err;
492 }
493
494 if (snd_ctl_find_hole(card, kcontrol->count) < 0)
495 return -ENOMEM;
496
497 scoped_guard(write_lock_irq, &card->controls_rwlock) {
498 list_add_tail(&kcontrol->list, &card->controls);
499 card->controls_count += kcontrol->count;
500 kcontrol->id.numid = card->last_numid + 1;
501 card->last_numid += kcontrol->count;
502 }
503
504 add_hash_entries(card, kcontrol);
505
506 for (idx = 0; idx < kcontrol->count; idx++)
507 snd_ctl_notify_one(card, SNDRV_CTL_EVENT_MASK_ADD, kcontrol, idx);
508
509 return 0;
510 }
511
snd_ctl_add_replace(struct snd_card * card,struct snd_kcontrol * kcontrol,enum snd_ctl_add_mode mode)512 static int snd_ctl_add_replace(struct snd_card *card,
513 struct snd_kcontrol *kcontrol,
514 enum snd_ctl_add_mode mode)
515 {
516 int err = -EINVAL;
517
518 if (! kcontrol)
519 return err;
520 if (snd_BUG_ON(!card || !kcontrol->info))
521 goto error;
522
523 scoped_guard(rwsem_write, &card->controls_rwsem)
524 err = __snd_ctl_add_replace(card, kcontrol, mode);
525
526 if (err < 0)
527 goto error;
528 return 0;
529
530 error:
531 snd_ctl_free_one(kcontrol);
532 return err;
533 }
534
535 /**
536 * snd_ctl_add - add the control instance to the card
537 * @card: the card instance
538 * @kcontrol: the control instance to add
539 *
540 * Adds the control instance created via snd_ctl_new() or
541 * snd_ctl_new1() to the given card. Assigns also an unique
542 * numid used for fast search.
543 *
544 * It frees automatically the control which cannot be added.
545 *
546 * Return: Zero if successful, or a negative error code on failure.
547 *
548 */
snd_ctl_add(struct snd_card * card,struct snd_kcontrol * kcontrol)549 int snd_ctl_add(struct snd_card *card, struct snd_kcontrol *kcontrol)
550 {
551 return snd_ctl_add_replace(card, kcontrol, CTL_ADD_EXCLUSIVE);
552 }
553 EXPORT_SYMBOL(snd_ctl_add);
554
555 /**
556 * snd_ctl_replace - replace the control instance of the card
557 * @card: the card instance
558 * @kcontrol: the control instance to replace
559 * @add_on_replace: add the control if not already added
560 *
561 * Replaces the given control. If the given control does not exist
562 * and the add_on_replace flag is set, the control is added. If the
563 * control exists, it is destroyed first.
564 *
565 * It frees automatically the control which cannot be added or replaced.
566 *
567 * Return: Zero if successful, or a negative error code on failure.
568 */
snd_ctl_replace(struct snd_card * card,struct snd_kcontrol * kcontrol,bool add_on_replace)569 int snd_ctl_replace(struct snd_card *card, struct snd_kcontrol *kcontrol,
570 bool add_on_replace)
571 {
572 return snd_ctl_add_replace(card, kcontrol,
573 add_on_replace ? CTL_ADD_ON_REPLACE : CTL_REPLACE);
574 }
575 EXPORT_SYMBOL(snd_ctl_replace);
576
__snd_ctl_remove(struct snd_card * card,struct snd_kcontrol * kcontrol,bool remove_hash)577 static int __snd_ctl_remove(struct snd_card *card,
578 struct snd_kcontrol *kcontrol,
579 bool remove_hash)
580 {
581 unsigned int idx;
582
583 lockdep_assert_held_write(&card->controls_rwsem);
584
585 if (snd_BUG_ON(!card || !kcontrol))
586 return -EINVAL;
587
588 if (remove_hash)
589 remove_hash_entries(card, kcontrol);
590
591 scoped_guard(write_lock_irq, &card->controls_rwlock) {
592 list_del(&kcontrol->list);
593 card->controls_count -= kcontrol->count;
594 }
595
596 for (idx = 0; idx < kcontrol->count; idx++)
597 snd_ctl_notify_one(card, SNDRV_CTL_EVENT_MASK_REMOVE, kcontrol, idx);
598 snd_ctl_free_one(kcontrol);
599 return 0;
600 }
601
snd_ctl_remove_locked(struct snd_card * card,struct snd_kcontrol * kcontrol)602 static inline int snd_ctl_remove_locked(struct snd_card *card,
603 struct snd_kcontrol *kcontrol)
604 {
605 return __snd_ctl_remove(card, kcontrol, true);
606 }
607
608 /**
609 * snd_ctl_remove - remove the control from the card and release it
610 * @card: the card instance
611 * @kcontrol: the control instance to remove
612 *
613 * Removes the control from the card and then releases the instance.
614 * You don't need to call snd_ctl_free_one().
615 * Passing NULL to @kcontrol argument is allowed as noop.
616 *
617 * Return: 0 if successful, or a negative error code on failure.
618 *
619 * Note that this function takes card->controls_rwsem lock internally.
620 */
snd_ctl_remove(struct snd_card * card,struct snd_kcontrol * kcontrol)621 int snd_ctl_remove(struct snd_card *card, struct snd_kcontrol *kcontrol)
622 {
623 if (!kcontrol)
624 return 0;
625 guard(rwsem_write)(&card->controls_rwsem);
626 return snd_ctl_remove_locked(card, kcontrol);
627 }
628 EXPORT_SYMBOL(snd_ctl_remove);
629
630 /**
631 * snd_ctl_remove_id - remove the control of the given id and release it
632 * @card: the card instance
633 * @id: the control id to remove
634 *
635 * Finds the control instance with the given id, removes it from the
636 * card list and releases it.
637 *
638 * Return: 0 if successful, or a negative error code on failure.
639 */
snd_ctl_remove_id(struct snd_card * card,struct snd_ctl_elem_id * id)640 int snd_ctl_remove_id(struct snd_card *card, struct snd_ctl_elem_id *id)
641 {
642 struct snd_kcontrol *kctl;
643
644 guard(rwsem_write)(&card->controls_rwsem);
645 kctl = snd_ctl_find_id(card, id);
646 if (kctl == NULL)
647 return -ENOENT;
648 return snd_ctl_remove_locked(card, kctl);
649 }
650 EXPORT_SYMBOL(snd_ctl_remove_id);
651
652 /**
653 * snd_ctl_remove_user_ctl - remove and release the unlocked user control
654 * @file: active control handle
655 * @id: the control id to remove
656 *
657 * Finds the control instance with the given id, removes it from the
658 * card list and releases it.
659 *
660 * Return: 0 if successful, or a negative error code on failure.
661 */
snd_ctl_remove_user_ctl(struct snd_ctl_file * file,struct snd_ctl_elem_id * id)662 static int snd_ctl_remove_user_ctl(struct snd_ctl_file * file,
663 struct snd_ctl_elem_id *id)
664 {
665 struct snd_card *card = file->card;
666 struct snd_kcontrol *kctl;
667 int idx;
668
669 guard(rwsem_write)(&card->controls_rwsem);
670 kctl = snd_ctl_find_id(card, id);
671 if (kctl == NULL)
672 return -ENOENT;
673 if (!(kctl->vd[0].access & SNDRV_CTL_ELEM_ACCESS_USER))
674 return -EINVAL;
675 for (idx = 0; idx < kctl->count; idx++)
676 if (kctl->vd[idx].owner != NULL && kctl->vd[idx].owner != file)
677 return -EBUSY;
678 return snd_ctl_remove_locked(card, kctl);
679 }
680
681 /**
682 * snd_ctl_activate_id - activate/inactivate the control of the given id
683 * @card: the card instance
684 * @id: the control id to activate/inactivate
685 * @active: non-zero to activate
686 *
687 * Finds the control instance with the given id, and activate or
688 * inactivate the control together with notification, if changed.
689 * The given ID data is filled with full information.
690 *
691 * Return: 0 if unchanged, 1 if changed, or a negative error code on failure.
692 */
snd_ctl_activate_id(struct snd_card * card,struct snd_ctl_elem_id * id,int active)693 int snd_ctl_activate_id(struct snd_card *card, struct snd_ctl_elem_id *id,
694 int active)
695 {
696 struct snd_kcontrol *kctl;
697 struct snd_kcontrol_volatile *vd;
698 unsigned int index_offset;
699 int ret;
700
701 down_write(&card->controls_rwsem);
702 kctl = snd_ctl_find_id(card, id);
703 if (kctl == NULL) {
704 ret = -ENOENT;
705 goto unlock;
706 }
707 index_offset = snd_ctl_get_ioff(kctl, id);
708 vd = &kctl->vd[index_offset];
709 ret = 0;
710 if (active) {
711 if (!(vd->access & SNDRV_CTL_ELEM_ACCESS_INACTIVE))
712 goto unlock;
713 vd->access &= ~SNDRV_CTL_ELEM_ACCESS_INACTIVE;
714 } else {
715 if (vd->access & SNDRV_CTL_ELEM_ACCESS_INACTIVE)
716 goto unlock;
717 vd->access |= SNDRV_CTL_ELEM_ACCESS_INACTIVE;
718 }
719 snd_ctl_build_ioff(id, kctl, index_offset);
720 downgrade_write(&card->controls_rwsem);
721 snd_ctl_notify_one(card, SNDRV_CTL_EVENT_MASK_INFO, kctl, index_offset);
722 up_read(&card->controls_rwsem);
723 return 1;
724
725 unlock:
726 up_write(&card->controls_rwsem);
727 return ret;
728 }
729 EXPORT_SYMBOL_GPL(snd_ctl_activate_id);
730
731 /**
732 * snd_ctl_rename_id - replace the id of a control on the card
733 * @card: the card instance
734 * @src_id: the old id
735 * @dst_id: the new id
736 *
737 * Finds the control with the old id from the card, and replaces the
738 * id with the new one.
739 *
740 * The function tries to keep the already assigned numid while replacing
741 * the rest.
742 *
743 * Note that this function should be used only in the card initialization
744 * phase. Calling after the card instantiation may cause issues with
745 * user-space expecting persistent numids.
746 *
747 * Return: Zero if successful, or a negative error code on failure.
748 */
snd_ctl_rename_id(struct snd_card * card,struct snd_ctl_elem_id * src_id,struct snd_ctl_elem_id * dst_id)749 int snd_ctl_rename_id(struct snd_card *card, struct snd_ctl_elem_id *src_id,
750 struct snd_ctl_elem_id *dst_id)
751 {
752 struct snd_kcontrol *kctl;
753 int saved_numid;
754
755 guard(rwsem_write)(&card->controls_rwsem);
756 kctl = snd_ctl_find_id(card, src_id);
757 if (kctl == NULL)
758 return -ENOENT;
759 saved_numid = kctl->id.numid;
760 remove_hash_entries(card, kctl);
761 kctl->id = *dst_id;
762 kctl->id.numid = saved_numid;
763 add_hash_entries(card, kctl);
764 return 0;
765 }
766 EXPORT_SYMBOL(snd_ctl_rename_id);
767
768 /**
769 * snd_ctl_rename - rename the control on the card
770 * @card: the card instance
771 * @kctl: the control to rename
772 * @name: the new name
773 *
774 * Renames the specified control on the card to the new name.
775 *
776 * Note that this function takes card->controls_rwsem lock internally.
777 */
snd_ctl_rename(struct snd_card * card,struct snd_kcontrol * kctl,const char * name)778 void snd_ctl_rename(struct snd_card *card, struct snd_kcontrol *kctl,
779 const char *name)
780 {
781 guard(rwsem_write)(&card->controls_rwsem);
782 remove_hash_entries(card, kctl);
783
784 if (strscpy(kctl->id.name, name, sizeof(kctl->id.name)) < 0)
785 pr_warn("ALSA: Renamed control new name '%s' truncated to '%s'\n",
786 name, kctl->id.name);
787
788 add_hash_entries(card, kctl);
789 }
790 EXPORT_SYMBOL(snd_ctl_rename);
791
792 #ifndef CONFIG_SND_CTL_FAST_LOOKUP
793 static struct snd_kcontrol *
snd_ctl_find_numid_slow(struct snd_card * card,unsigned int numid)794 snd_ctl_find_numid_slow(struct snd_card *card, unsigned int numid)
795 {
796 struct snd_kcontrol *kctl;
797
798 guard(read_lock_irqsave)(&card->controls_rwlock);
799 list_for_each_entry(kctl, &card->controls, list) {
800 if (kctl->id.numid <= numid && kctl->id.numid + kctl->count > numid)
801 return kctl;
802 }
803 return NULL;
804 }
805 #endif /* !CONFIG_SND_CTL_FAST_LOOKUP */
806
807 /**
808 * snd_ctl_find_numid - find the control instance with the given number-id
809 * @card: the card instance
810 * @numid: the number-id to search
811 *
812 * Finds the control instance with the given number-id from the card.
813 *
814 * Return: The pointer of the instance if found, or %NULL if not.
815 *
816 * Note that this function takes card->controls_rwlock lock internally.
817 */
snd_ctl_find_numid(struct snd_card * card,unsigned int numid)818 struct snd_kcontrol *snd_ctl_find_numid(struct snd_card *card,
819 unsigned int numid)
820 {
821 if (snd_BUG_ON(!card || !numid))
822 return NULL;
823
824 #ifdef CONFIG_SND_CTL_FAST_LOOKUP
825 return xa_load(&card->ctl_numids, numid);
826 #else
827 return snd_ctl_find_numid_slow(card, numid);
828 #endif
829 }
830 EXPORT_SYMBOL(snd_ctl_find_numid);
831
832 /**
833 * snd_ctl_find_id - find the control instance with the given id
834 * @card: the card instance
835 * @id: the id to search
836 *
837 * Finds the control instance with the given id from the card.
838 *
839 * Return: The pointer of the instance if found, or %NULL if not.
840 *
841 * Note that this function takes card->controls_rwlock lock internally.
842 */
snd_ctl_find_id(struct snd_card * card,const struct snd_ctl_elem_id * id)843 struct snd_kcontrol *snd_ctl_find_id(struct snd_card *card,
844 const struct snd_ctl_elem_id *id)
845 {
846 struct snd_kcontrol *kctl;
847
848 if (snd_BUG_ON(!card || !id))
849 return NULL;
850
851 if (id->numid != 0)
852 return snd_ctl_find_numid(card, id->numid);
853 #ifdef CONFIG_SND_CTL_FAST_LOOKUP
854 kctl = xa_load(&card->ctl_hash, get_ctl_id_hash(id));
855 if (kctl && elem_id_matches(kctl, id))
856 return kctl;
857 if (!card->ctl_hash_collision)
858 return NULL; /* we can rely on only hash table */
859 #endif
860 /* no matching in hash table - try all as the last resort */
861 guard(read_lock_irqsave)(&card->controls_rwlock);
862 list_for_each_entry(kctl, &card->controls, list)
863 if (elem_id_matches(kctl, id))
864 return kctl;
865
866 return NULL;
867 }
868 EXPORT_SYMBOL(snd_ctl_find_id);
869
snd_ctl_card_info(struct snd_card * card,struct snd_ctl_file * ctl,unsigned int cmd,void __user * arg)870 static int snd_ctl_card_info(struct snd_card *card, struct snd_ctl_file * ctl,
871 unsigned int cmd, void __user *arg)
872 {
873 struct snd_ctl_card_info *info __free(kfree) =
874 kzalloc_obj(*info);
875 ssize_t n;
876
877 if (! info)
878 return -ENOMEM;
879
880 static_assert(sizeof(info->components) >= 2);
881
882 scoped_guard(rwsem_read, &snd_ioctl_rwsem) {
883 const char *components = card->components;
884
885 if (!components)
886 components = "";
887
888 info->card = card->number;
889 strscpy(info->id, card->id, sizeof(info->id));
890 strscpy(info->driver, card->driver, sizeof(info->driver));
891 strscpy(info->name, card->shortname, sizeof(info->name));
892 strscpy(info->longname, card->longname, sizeof(info->longname));
893 strscpy(info->mixername, card->mixername, sizeof(info->mixername));
894 n = strscpy(info->components, components, sizeof(info->components));
895 if (n < 0) // mark the truncation with '>' before NULL terminator
896 info->components[sizeof(info->components) - 2] = '>';
897 }
898 if (copy_to_user(arg, info, sizeof(struct snd_ctl_card_info)))
899 return -EFAULT;
900 return 0;
901 }
902
snd_ctl_card_bytes(struct snd_card * card,struct snd_ctl_card_bytes * info,unsigned int __user * data_len_out)903 static int snd_ctl_card_bytes(struct snd_card *card,
904 struct snd_ctl_card_bytes *info,
905 unsigned int __user *data_len_out)
906 {
907 unsigned int data_len;
908
909 switch (info->type) {
910 case SND_CTL_CARD_BTYPE_COMPONENTS:
911 scoped_guard(rwsem_read, &snd_ioctl_rwsem) {
912 const char *components = card->components;
913
914 if (!components)
915 components = "";
916
917 data_len = strlen(components) + 1;
918
919 if (!info->data || info->data_allocated == 0)
920 break;
921
922 if (info->data_allocated < data_len)
923 return -ENOMEM;
924
925 if (copy_to_user(u64_to_user_ptr(info->data), components, data_len))
926 return -EFAULT;
927 }
928 break;
929 default:
930 return -EINVAL;
931 }
932
933 if (put_user(data_len, data_len_out))
934 return -EFAULT;
935
936 return 0;
937 }
938
snd_ctl_card_bytes_user(struct snd_card * card,struct snd_ctl_card_bytes __user * _info)939 static int snd_ctl_card_bytes_user(struct snd_card *card,
940 struct snd_ctl_card_bytes __user *_info)
941 {
942 struct snd_ctl_card_bytes info;
943
944 if (copy_from_user(&info, _info, sizeof(info)))
945 return -EFAULT;
946
947 return snd_ctl_card_bytes(card, &info, &_info->data_len);
948 }
949
snd_ctl_elem_list(struct snd_card * card,struct snd_ctl_elem_list * list)950 static int snd_ctl_elem_list(struct snd_card *card,
951 struct snd_ctl_elem_list *list)
952 {
953 struct snd_kcontrol *kctl;
954 struct snd_ctl_elem_id id;
955 unsigned int offset, space, jidx;
956
957 offset = list->offset;
958 space = list->space;
959
960 guard(rwsem_read)(&card->controls_rwsem);
961 list->count = card->controls_count;
962 list->used = 0;
963 if (!space)
964 return 0;
965 list_for_each_entry(kctl, &card->controls, list) {
966 if (offset >= kctl->count) {
967 offset -= kctl->count;
968 continue;
969 }
970 for (jidx = offset; jidx < kctl->count; jidx++) {
971 snd_ctl_build_ioff(&id, kctl, jidx);
972 if (copy_to_user(list->pids + list->used, &id, sizeof(id)))
973 return -EFAULT;
974 list->used++;
975 if (!--space)
976 return 0;
977 }
978 offset = 0;
979 }
980 return 0;
981 }
982
snd_ctl_elem_list_user(struct snd_card * card,struct snd_ctl_elem_list __user * _list)983 static int snd_ctl_elem_list_user(struct snd_card *card,
984 struct snd_ctl_elem_list __user *_list)
985 {
986 struct snd_ctl_elem_list list;
987 int err;
988
989 if (copy_from_user(&list, _list, sizeof(list)))
990 return -EFAULT;
991 err = snd_ctl_elem_list(card, &list);
992 if (err)
993 return err;
994 if (copy_to_user(_list, &list, sizeof(list)))
995 return -EFAULT;
996
997 return 0;
998 }
999
1000 /* Check whether the given kctl info is valid */
snd_ctl_check_elem_info(struct snd_card * card,const struct snd_ctl_elem_info * info)1001 static int snd_ctl_check_elem_info(struct snd_card *card,
1002 const struct snd_ctl_elem_info *info)
1003 {
1004 static const unsigned int max_value_counts[] = {
1005 [SNDRV_CTL_ELEM_TYPE_BOOLEAN] = 128,
1006 [SNDRV_CTL_ELEM_TYPE_INTEGER] = 128,
1007 [SNDRV_CTL_ELEM_TYPE_ENUMERATED] = 128,
1008 [SNDRV_CTL_ELEM_TYPE_BYTES] = 512,
1009 [SNDRV_CTL_ELEM_TYPE_IEC958] = 1,
1010 [SNDRV_CTL_ELEM_TYPE_INTEGER64] = 64,
1011 };
1012
1013 if (info->type < SNDRV_CTL_ELEM_TYPE_BOOLEAN ||
1014 info->type > SNDRV_CTL_ELEM_TYPE_INTEGER64) {
1015 if (card)
1016 dev_err(card->dev,
1017 "control %i:%i:%i:%s:%i: invalid type %d\n",
1018 info->id.iface, info->id.device,
1019 info->id.subdevice, info->id.name,
1020 info->id.index, info->type);
1021 return -EINVAL;
1022 }
1023 if (info->type == SNDRV_CTL_ELEM_TYPE_ENUMERATED &&
1024 info->value.enumerated.items == 0) {
1025 if (card)
1026 dev_err(card->dev,
1027 "control %i:%i:%i:%s:%i: zero enum items\n",
1028 info->id.iface, info->id.device,
1029 info->id.subdevice, info->id.name,
1030 info->id.index);
1031 return -EINVAL;
1032 }
1033 if (info->count > max_value_counts[info->type]) {
1034 if (card)
1035 dev_err(card->dev,
1036 "control %i:%i:%i:%s:%i: invalid count %d\n",
1037 info->id.iface, info->id.device,
1038 info->id.subdevice, info->id.name,
1039 info->id.index, info->count);
1040 return -EINVAL;
1041 }
1042
1043 return 0;
1044 }
1045
1046 /* The capacity of struct snd_ctl_elem_value.value.*/
1047 static const unsigned int value_sizes[] = {
1048 [SNDRV_CTL_ELEM_TYPE_BOOLEAN] = sizeof(long),
1049 [SNDRV_CTL_ELEM_TYPE_INTEGER] = sizeof(long),
1050 [SNDRV_CTL_ELEM_TYPE_ENUMERATED] = sizeof(unsigned int),
1051 [SNDRV_CTL_ELEM_TYPE_BYTES] = sizeof(unsigned char),
1052 [SNDRV_CTL_ELEM_TYPE_IEC958] = sizeof(struct snd_aes_iec958),
1053 [SNDRV_CTL_ELEM_TYPE_INTEGER64] = sizeof(long long),
1054 };
1055
1056 /* fill the remaining snd_ctl_elem_value data with the given pattern */
fill_remaining_elem_value(struct snd_ctl_elem_value * control,struct snd_ctl_elem_info * info,u32 pattern)1057 static void fill_remaining_elem_value(struct snd_ctl_elem_value *control,
1058 struct snd_ctl_elem_info *info,
1059 u32 pattern)
1060 {
1061 size_t offset = value_sizes[info->type] * info->count;
1062
1063 offset = DIV_ROUND_UP(offset, sizeof(u32));
1064 memset32((u32 *)control->value.bytes.data + offset, pattern,
1065 sizeof(control->value) / sizeof(u32) - offset);
1066 }
1067
1068 /* check whether the given integer ctl value is valid */
sanity_check_int_value(struct snd_card * card,const struct snd_ctl_elem_value * control,const struct snd_ctl_elem_info * info,int i,bool print_error)1069 static int sanity_check_int_value(struct snd_card *card,
1070 const struct snd_ctl_elem_value *control,
1071 const struct snd_ctl_elem_info *info,
1072 int i, bool print_error)
1073 {
1074 long long lval, lmin, lmax, lstep;
1075 u64 rem;
1076
1077 switch (info->type) {
1078 default:
1079 case SNDRV_CTL_ELEM_TYPE_BOOLEAN:
1080 lval = control->value.integer.value[i];
1081 lmin = 0;
1082 lmax = 1;
1083 lstep = 0;
1084 break;
1085 case SNDRV_CTL_ELEM_TYPE_INTEGER:
1086 lval = control->value.integer.value[i];
1087 lmin = info->value.integer.min;
1088 lmax = info->value.integer.max;
1089 lstep = info->value.integer.step;
1090 break;
1091 case SNDRV_CTL_ELEM_TYPE_INTEGER64:
1092 lval = control->value.integer64.value[i];
1093 lmin = info->value.integer64.min;
1094 lmax = info->value.integer64.max;
1095 lstep = info->value.integer64.step;
1096 break;
1097 case SNDRV_CTL_ELEM_TYPE_ENUMERATED:
1098 lval = control->value.enumerated.item[i];
1099 lmin = 0;
1100 lmax = info->value.enumerated.items - 1;
1101 lstep = 0;
1102 break;
1103 }
1104
1105 if (lval < lmin || lval > lmax) {
1106 if (print_error)
1107 dev_err(card->dev,
1108 "control %i:%i:%i:%s:%i: value out of range %lld (%lld/%lld) at count %i\n",
1109 control->id.iface, control->id.device,
1110 control->id.subdevice, control->id.name,
1111 control->id.index, lval, lmin, lmax, i);
1112 return -EINVAL;
1113 }
1114 if (lstep) {
1115 div64_u64_rem(lval, lstep, &rem);
1116 if (rem) {
1117 if (print_error)
1118 dev_err(card->dev,
1119 "control %i:%i:%i:%s:%i: unaligned value %lld (step %lld) at count %i\n",
1120 control->id.iface, control->id.device,
1121 control->id.subdevice, control->id.name,
1122 control->id.index, lval, lstep, i);
1123 return -EINVAL;
1124 }
1125 }
1126
1127 return 0;
1128 }
1129
1130 /* check whether the all input values are valid for the given elem value */
sanity_check_input_values(struct snd_card * card,const struct snd_ctl_elem_value * control,const struct snd_ctl_elem_info * info,bool print_error)1131 static int sanity_check_input_values(struct snd_card *card,
1132 const struct snd_ctl_elem_value *control,
1133 const struct snd_ctl_elem_info *info,
1134 bool print_error)
1135 {
1136 int i, ret;
1137
1138 switch (info->type) {
1139 case SNDRV_CTL_ELEM_TYPE_BOOLEAN:
1140 case SNDRV_CTL_ELEM_TYPE_INTEGER:
1141 case SNDRV_CTL_ELEM_TYPE_INTEGER64:
1142 case SNDRV_CTL_ELEM_TYPE_ENUMERATED:
1143 for (i = 0; i < info->count; i++) {
1144 ret = sanity_check_int_value(card, control, info, i,
1145 print_error);
1146 if (ret < 0)
1147 return ret;
1148 }
1149 break;
1150 default:
1151 break;
1152 }
1153
1154 return 0;
1155 }
1156
1157 /* perform sanity checks to the given snd_ctl_elem_value object */
sanity_check_elem_value(struct snd_card * card,const struct snd_ctl_elem_value * control,const struct snd_ctl_elem_info * info,u32 pattern)1158 static int sanity_check_elem_value(struct snd_card *card,
1159 const struct snd_ctl_elem_value *control,
1160 const struct snd_ctl_elem_info *info,
1161 u32 pattern)
1162 {
1163 size_t offset;
1164 int ret;
1165 u32 *p;
1166
1167 ret = sanity_check_input_values(card, control, info, true);
1168 if (ret < 0)
1169 return ret;
1170
1171 /* check whether the remaining area kept untouched */
1172 offset = value_sizes[info->type] * info->count;
1173 offset = DIV_ROUND_UP(offset, sizeof(u32));
1174 p = (u32 *)control->value.bytes.data + offset;
1175 for (; offset < sizeof(control->value) / sizeof(u32); offset++, p++) {
1176 if (*p != pattern) {
1177 ret = -EINVAL;
1178 break;
1179 }
1180 *p = 0; /* clear the checked area */
1181 }
1182
1183 return ret;
1184 }
1185
__snd_ctl_elem_info(struct snd_card * card,struct snd_kcontrol * kctl,struct snd_ctl_elem_info * info,struct snd_ctl_file * ctl)1186 static int __snd_ctl_elem_info(struct snd_card *card,
1187 struct snd_kcontrol *kctl,
1188 struct snd_ctl_elem_info *info,
1189 struct snd_ctl_file *ctl)
1190 {
1191 struct snd_kcontrol_volatile *vd;
1192 unsigned int index_offset;
1193 int result;
1194
1195 #ifdef CONFIG_SND_DEBUG
1196 info->access = 0;
1197 #endif
1198 result = kctl->info(kctl, info);
1199 if (result >= 0) {
1200 snd_BUG_ON(info->access);
1201 index_offset = snd_ctl_get_ioff(kctl, &info->id);
1202 vd = &kctl->vd[index_offset];
1203 snd_ctl_build_ioff(&info->id, kctl, index_offset);
1204 info->access = vd->access;
1205 if (vd->owner) {
1206 info->access |= SNDRV_CTL_ELEM_ACCESS_LOCK;
1207 if (vd->owner == ctl)
1208 info->access |= SNDRV_CTL_ELEM_ACCESS_OWNER;
1209 info->owner = pid_vnr(vd->owner->pid);
1210 } else {
1211 info->owner = -1;
1212 }
1213 if (!snd_ctl_skip_validation(info) &&
1214 snd_ctl_check_elem_info(card, info) < 0)
1215 result = -EINVAL;
1216 }
1217 return result;
1218 }
1219
snd_ctl_elem_info(struct snd_ctl_file * ctl,struct snd_ctl_elem_info * info)1220 static int snd_ctl_elem_info(struct snd_ctl_file *ctl,
1221 struct snd_ctl_elem_info *info)
1222 {
1223 struct snd_card *card = ctl->card;
1224 struct snd_kcontrol *kctl;
1225
1226 guard(rwsem_read)(&card->controls_rwsem);
1227 kctl = snd_ctl_find_id(card, &info->id);
1228 if (!kctl)
1229 return -ENOENT;
1230 return __snd_ctl_elem_info(card, kctl, info, ctl);
1231 }
1232
snd_ctl_elem_info_user(struct snd_ctl_file * ctl,struct snd_ctl_elem_info __user * _info)1233 static int snd_ctl_elem_info_user(struct snd_ctl_file *ctl,
1234 struct snd_ctl_elem_info __user *_info)
1235 {
1236 struct snd_card *card = ctl->card;
1237 struct snd_ctl_elem_info info;
1238 int result;
1239
1240 if (copy_from_user(&info, _info, sizeof(info)))
1241 return -EFAULT;
1242 result = snd_power_ref_and_wait(card);
1243 if (result)
1244 return result;
1245 result = snd_ctl_elem_info(ctl, &info);
1246 snd_power_unref(card);
1247 if (result < 0)
1248 return result;
1249 /* drop internal access flags */
1250 info.access &= ~(SNDRV_CTL_ELEM_ACCESS_SKIP_CHECK|
1251 SNDRV_CTL_ELEM_ACCESS_LED_MASK);
1252 if (copy_to_user(_info, &info, sizeof(info)))
1253 return -EFAULT;
1254 return result;
1255 }
1256
snd_ctl_elem_read(struct snd_card * card,struct snd_ctl_elem_value * control)1257 static int snd_ctl_elem_read(struct snd_card *card,
1258 struct snd_ctl_elem_value *control)
1259 {
1260 struct snd_kcontrol *kctl;
1261 struct snd_kcontrol_volatile *vd;
1262 unsigned int index_offset;
1263 struct snd_ctl_elem_info info;
1264 const u32 pattern = 0xdeadbeef;
1265 int ret;
1266
1267 guard(rwsem_read)(&card->controls_rwsem);
1268 kctl = snd_ctl_find_id(card, &control->id);
1269 if (!kctl)
1270 return -ENOENT;
1271
1272 index_offset = snd_ctl_get_ioff(kctl, &control->id);
1273 vd = &kctl->vd[index_offset];
1274 if (!(vd->access & SNDRV_CTL_ELEM_ACCESS_READ) || !kctl->get)
1275 return -EPERM;
1276
1277 snd_ctl_build_ioff(&control->id, kctl, index_offset);
1278
1279 #ifdef CONFIG_SND_CTL_DEBUG
1280 /* info is needed only for validation */
1281 memset(&info, 0, sizeof(info));
1282 info.id = control->id;
1283 ret = __snd_ctl_elem_info(card, kctl, &info, NULL);
1284 if (ret < 0)
1285 return ret;
1286 #endif
1287
1288 if (!snd_ctl_skip_validation(&info))
1289 fill_remaining_elem_value(control, &info, pattern);
1290 ret = kctl->get(kctl, control);
1291 if (ret < 0)
1292 return ret;
1293 if (!snd_ctl_skip_validation(&info) &&
1294 sanity_check_elem_value(card, control, &info, pattern) < 0) {
1295 dev_err(card->dev,
1296 "control %i:%i:%i:%s:%i: access overflow\n",
1297 control->id.iface, control->id.device,
1298 control->id.subdevice, control->id.name,
1299 control->id.index);
1300 return -EINVAL;
1301 }
1302 return 0;
1303 }
1304
snd_ctl_elem_read_user(struct snd_card * card,struct snd_ctl_elem_value __user * _control)1305 static int snd_ctl_elem_read_user(struct snd_card *card,
1306 struct snd_ctl_elem_value __user *_control)
1307 {
1308 int result;
1309 struct snd_ctl_elem_value *control __free(kfree) =
1310 memdup_user(_control, sizeof(*control));
1311
1312 if (IS_ERR(control))
1313 return PTR_ERR(control);
1314
1315 result = snd_power_ref_and_wait(card);
1316 if (result)
1317 return result;
1318 result = snd_ctl_elem_read(card, control);
1319 snd_power_unref(card);
1320 if (result < 0)
1321 return result;
1322
1323 if (copy_to_user(_control, control, sizeof(*control)))
1324 return -EFAULT;
1325 return result;
1326 }
1327
1328 #if IS_ENABLED(CONFIG_SND_CTL_DEBUG)
1329
1330 static const char *const snd_ctl_elem_iface_names[] = {
1331 [SNDRV_CTL_ELEM_IFACE_CARD] = "CARD",
1332 [SNDRV_CTL_ELEM_IFACE_HWDEP] = "HWDEP",
1333 [SNDRV_CTL_ELEM_IFACE_MIXER] = "MIXER",
1334 [SNDRV_CTL_ELEM_IFACE_PCM] = "PCM",
1335 [SNDRV_CTL_ELEM_IFACE_RAWMIDI] = "RAWMIDI",
1336 [SNDRV_CTL_ELEM_IFACE_TIMER] = "TIMER",
1337 [SNDRV_CTL_ELEM_IFACE_SEQUENCER] = "SEQUENCER",
1338 };
1339
snd_ctl_put_verify(struct snd_card * card,struct snd_kcontrol * kctl,struct snd_ctl_elem_value * control)1340 static int snd_ctl_put_verify(struct snd_card *card, struct snd_kcontrol *kctl,
1341 struct snd_ctl_elem_value *control)
1342 {
1343 struct snd_ctl_elem_value *original = card->value_buf;
1344 struct snd_ctl_elem_info info;
1345 const char *iname;
1346 int ret, retcmp;
1347
1348 memset(original, 0, sizeof(*original));
1349 memset(&info, 0, sizeof(info));
1350
1351 ret = kctl->info(kctl, &info);
1352 if (ret)
1353 return ret;
1354
1355 ret = kctl->get(kctl, original);
1356 if (ret)
1357 return ret;
1358
1359 ret = kctl->put(kctl, control);
1360 if (ret < 0)
1361 return ret;
1362
1363 /* Sanitize the new value (control->value) before comparing. */
1364 fill_remaining_elem_value(control, &info, 0);
1365
1366 /* With known state for both new and original, do the comparison. */
1367 retcmp = memcmp(&original->value, &control->value, sizeof(original->value));
1368 if (retcmp)
1369 retcmp = 1;
1370
1371 iname = snd_ctl_elem_iface_names[kctl->id.iface];
1372 trace_snd_ctl_put(&kctl->id, iname, card->number, ret, retcmp);
1373
1374 return ret;
1375 }
1376
snd_ctl_put(struct snd_card * card,struct snd_kcontrol * kctl,struct snd_ctl_elem_value * control,unsigned int access)1377 static int snd_ctl_put(struct snd_card *card, struct snd_kcontrol *kctl,
1378 struct snd_ctl_elem_value *control, unsigned int access)
1379 {
1380 if ((access & SNDRV_CTL_ELEM_ACCESS_SKIP_CHECK) ||
1381 (access & SNDRV_CTL_ELEM_ACCESS_VOLATILE))
1382 return kctl->put(kctl, control);
1383
1384 return snd_ctl_put_verify(card, kctl, control);
1385 }
1386 #else
snd_ctl_put(struct snd_card * card,struct snd_kcontrol * kctl,struct snd_ctl_elem_value * control,unsigned int access)1387 static inline int snd_ctl_put(struct snd_card *card, struct snd_kcontrol *kctl,
1388 struct snd_ctl_elem_value *control, unsigned int access)
1389 {
1390 return kctl->put(kctl, control);
1391 }
1392 #endif
1393
snd_ctl_elem_write(struct snd_card * card,struct snd_ctl_file * file,struct snd_ctl_elem_value * control)1394 static int snd_ctl_elem_write(struct snd_card *card, struct snd_ctl_file *file,
1395 struct snd_ctl_elem_value *control)
1396 {
1397 struct snd_kcontrol *kctl;
1398 struct snd_kcontrol_volatile *vd;
1399 unsigned int index_offset;
1400 int result = 0;
1401
1402 down_write(&card->controls_rwsem);
1403 kctl = snd_ctl_find_id(card, &control->id);
1404 if (kctl == NULL) {
1405 up_write(&card->controls_rwsem);
1406 return -ENOENT;
1407 }
1408
1409 index_offset = snd_ctl_get_ioff(kctl, &control->id);
1410 vd = &kctl->vd[index_offset];
1411 if (!(vd->access & SNDRV_CTL_ELEM_ACCESS_WRITE) || kctl->put == NULL ||
1412 (file && vd->owner && vd->owner != file)) {
1413 up_write(&card->controls_rwsem);
1414 return -EPERM;
1415 }
1416
1417 snd_ctl_build_ioff(&control->id, kctl, index_offset);
1418 /* validate input values */
1419 if (IS_ENABLED(CONFIG_SND_CTL_INPUT_VALIDATION)) {
1420 struct snd_ctl_elem_info info;
1421
1422 memset(&info, 0, sizeof(info));
1423 info.id = control->id;
1424 result = __snd_ctl_elem_info(card, kctl, &info, NULL);
1425 if (!result)
1426 result = sanity_check_input_values(card, control, &info,
1427 false);
1428 }
1429 if (!result)
1430 result = snd_ctl_put(card, kctl, control, vd->access);
1431
1432 if (result < 0) {
1433 up_write(&card->controls_rwsem);
1434 return result;
1435 }
1436
1437 if (result > 0) {
1438 downgrade_write(&card->controls_rwsem);
1439 snd_ctl_notify_one(card, SNDRV_CTL_EVENT_MASK_VALUE, kctl, index_offset);
1440 up_read(&card->controls_rwsem);
1441 } else {
1442 up_write(&card->controls_rwsem);
1443 }
1444
1445 return 0;
1446 }
1447
snd_ctl_elem_write_user(struct snd_ctl_file * file,struct snd_ctl_elem_value __user * _control)1448 static int snd_ctl_elem_write_user(struct snd_ctl_file *file,
1449 struct snd_ctl_elem_value __user *_control)
1450 {
1451 struct snd_card *card;
1452 int result;
1453 struct snd_ctl_elem_value *control __free(kfree) =
1454 memdup_user(_control, sizeof(*control));
1455
1456 if (IS_ERR(control))
1457 return PTR_ERR(control);
1458
1459 card = file->card;
1460 result = snd_power_ref_and_wait(card);
1461 if (result < 0)
1462 return result;
1463 result = snd_ctl_elem_write(card, file, control);
1464 snd_power_unref(card);
1465 if (result < 0)
1466 return result;
1467
1468 if (copy_to_user(_control, control, sizeof(*control)))
1469 return -EFAULT;
1470 return result;
1471 }
1472
snd_ctl_elem_lock(struct snd_ctl_file * file,struct snd_ctl_elem_id __user * _id)1473 static int snd_ctl_elem_lock(struct snd_ctl_file *file,
1474 struct snd_ctl_elem_id __user *_id)
1475 {
1476 struct snd_card *card = file->card;
1477 struct snd_ctl_elem_id id;
1478 struct snd_kcontrol *kctl;
1479 struct snd_kcontrol_volatile *vd;
1480
1481 if (copy_from_user(&id, _id, sizeof(id)))
1482 return -EFAULT;
1483 guard(rwsem_write)(&card->controls_rwsem);
1484 kctl = snd_ctl_find_id(card, &id);
1485 if (!kctl)
1486 return -ENOENT;
1487 vd = &kctl->vd[snd_ctl_get_ioff(kctl, &id)];
1488 if (vd->owner)
1489 return -EBUSY;
1490 vd->owner = file;
1491 return 0;
1492 }
1493
snd_ctl_elem_unlock(struct snd_ctl_file * file,struct snd_ctl_elem_id __user * _id)1494 static int snd_ctl_elem_unlock(struct snd_ctl_file *file,
1495 struct snd_ctl_elem_id __user *_id)
1496 {
1497 struct snd_card *card = file->card;
1498 struct snd_ctl_elem_id id;
1499 struct snd_kcontrol *kctl;
1500 struct snd_kcontrol_volatile *vd;
1501
1502 if (copy_from_user(&id, _id, sizeof(id)))
1503 return -EFAULT;
1504 guard(rwsem_write)(&card->controls_rwsem);
1505 kctl = snd_ctl_find_id(card, &id);
1506 if (!kctl)
1507 return -ENOENT;
1508 vd = &kctl->vd[snd_ctl_get_ioff(kctl, &id)];
1509 if (!vd->owner)
1510 return -EINVAL;
1511 if (vd->owner != file)
1512 return -EPERM;
1513 vd->owner = NULL;
1514 return 0;
1515 }
1516
1517 struct user_element {
1518 struct snd_ctl_elem_info info;
1519 struct snd_card *card;
1520 char *elem_data; /* element data */
1521 unsigned long elem_data_size; /* size of element data in bytes */
1522 void *tlv_data; /* TLV data */
1523 unsigned long tlv_data_size; /* TLV data size */
1524 void *priv_data; /* private data (like strings for enumerated type) */
1525 };
1526
1527 // check whether the addition (in bytes) of user ctl element may overflow the limit.
check_user_elem_overflow(struct snd_card * card,ssize_t add)1528 static bool check_user_elem_overflow(struct snd_card *card, ssize_t add)
1529 {
1530 return (ssize_t)card->user_ctl_alloc_size + add > max_user_ctl_alloc_size;
1531 }
1532
snd_ctl_elem_user_info(struct snd_kcontrol * kcontrol,struct snd_ctl_elem_info * uinfo)1533 static int snd_ctl_elem_user_info(struct snd_kcontrol *kcontrol,
1534 struct snd_ctl_elem_info *uinfo)
1535 {
1536 struct user_element *ue = snd_kcontrol_chip(kcontrol);
1537 unsigned int offset;
1538
1539 offset = snd_ctl_get_ioff(kcontrol, &uinfo->id);
1540 *uinfo = ue->info;
1541 snd_ctl_build_ioff(&uinfo->id, kcontrol, offset);
1542
1543 return 0;
1544 }
1545
snd_ctl_elem_user_enum_info(struct snd_kcontrol * kcontrol,struct snd_ctl_elem_info * uinfo)1546 static int snd_ctl_elem_user_enum_info(struct snd_kcontrol *kcontrol,
1547 struct snd_ctl_elem_info *uinfo)
1548 {
1549 struct user_element *ue = snd_kcontrol_chip(kcontrol);
1550 const char *names;
1551 unsigned int item;
1552 unsigned int offset;
1553
1554 item = uinfo->value.enumerated.item;
1555
1556 offset = snd_ctl_get_ioff(kcontrol, &uinfo->id);
1557 *uinfo = ue->info;
1558 snd_ctl_build_ioff(&uinfo->id, kcontrol, offset);
1559
1560 item = min(item, uinfo->value.enumerated.items - 1);
1561 uinfo->value.enumerated.item = item;
1562
1563 names = ue->priv_data;
1564 for (; item > 0; --item)
1565 names += strlen(names) + 1;
1566 strscpy(uinfo->value.enumerated.name, names);
1567
1568 return 0;
1569 }
1570
snd_ctl_elem_user_get(struct snd_kcontrol * kcontrol,struct snd_ctl_elem_value * ucontrol)1571 static int snd_ctl_elem_user_get(struct snd_kcontrol *kcontrol,
1572 struct snd_ctl_elem_value *ucontrol)
1573 {
1574 struct user_element *ue = snd_kcontrol_chip(kcontrol);
1575 unsigned int size = ue->elem_data_size;
1576 char *src = ue->elem_data +
1577 snd_ctl_get_ioff(kcontrol, &ucontrol->id) * size;
1578
1579 memcpy(&ucontrol->value, src, size);
1580 return 0;
1581 }
1582
snd_ctl_elem_user_put(struct snd_kcontrol * kcontrol,struct snd_ctl_elem_value * ucontrol)1583 static int snd_ctl_elem_user_put(struct snd_kcontrol *kcontrol,
1584 struct snd_ctl_elem_value *ucontrol)
1585 {
1586 int err, change;
1587 struct user_element *ue = snd_kcontrol_chip(kcontrol);
1588 unsigned int size = ue->elem_data_size;
1589 char *dst = ue->elem_data +
1590 snd_ctl_get_ioff(kcontrol, &ucontrol->id) * size;
1591
1592 err = sanity_check_input_values(ue->card, ucontrol, &ue->info, false);
1593 if (err < 0)
1594 return err;
1595
1596 change = memcmp(&ucontrol->value, dst, size) != 0;
1597 if (change)
1598 memcpy(dst, &ucontrol->value, size);
1599 return change;
1600 }
1601
1602 /* called in controls_rwsem write lock */
replace_user_tlv(struct snd_kcontrol * kctl,unsigned int __user * buf,unsigned int size)1603 static int replace_user_tlv(struct snd_kcontrol *kctl, unsigned int __user *buf,
1604 unsigned int size)
1605 {
1606 struct user_element *ue = snd_kcontrol_chip(kctl);
1607 unsigned int mask = 0;
1608 int i;
1609 int change;
1610
1611 lockdep_assert_held_write(&ue->card->controls_rwsem);
1612
1613 if (size > 1024 * 128) /* sane value */
1614 return -EINVAL;
1615
1616 // does the TLV size change cause overflow?
1617 if (check_user_elem_overflow(ue->card, (ssize_t)(size - ue->tlv_data_size)))
1618 return -ENOMEM;
1619
1620 unsigned int *container __free(kvfree) = vmemdup_user(buf, size);
1621
1622 if (IS_ERR(container))
1623 return PTR_ERR(container);
1624
1625 change = ue->tlv_data_size != size;
1626 if (!change)
1627 change = memcmp(ue->tlv_data, container, size) != 0;
1628 if (!change)
1629 return 0;
1630
1631 if (ue->tlv_data == NULL) {
1632 /* Now TLV data is available. */
1633 for (i = 0; i < kctl->count; ++i)
1634 kctl->vd[i].access |= SNDRV_CTL_ELEM_ACCESS_TLV_READ;
1635 mask = SNDRV_CTL_EVENT_MASK_INFO;
1636 } else {
1637 ue->card->user_ctl_alloc_size -= ue->tlv_data_size;
1638 ue->tlv_data_size = 0;
1639 kvfree(ue->tlv_data);
1640 }
1641
1642 ue->tlv_data = no_free_ptr(container);
1643 ue->tlv_data_size = size;
1644 // decremented at private_free.
1645 ue->card->user_ctl_alloc_size += size;
1646
1647 mask |= SNDRV_CTL_EVENT_MASK_TLV;
1648 for (i = 0; i < kctl->count; ++i)
1649 snd_ctl_notify_one(ue->card, mask, kctl, i);
1650
1651 return change;
1652 }
1653
read_user_tlv(struct snd_kcontrol * kctl,unsigned int __user * buf,unsigned int size)1654 static int read_user_tlv(struct snd_kcontrol *kctl, unsigned int __user *buf,
1655 unsigned int size)
1656 {
1657 struct user_element *ue = snd_kcontrol_chip(kctl);
1658
1659 if (ue->tlv_data_size == 0 || ue->tlv_data == NULL)
1660 return -ENXIO;
1661
1662 if (size < ue->tlv_data_size)
1663 return -ENOSPC;
1664
1665 if (copy_to_user(buf, ue->tlv_data, ue->tlv_data_size))
1666 return -EFAULT;
1667
1668 return 0;
1669 }
1670
snd_ctl_elem_user_tlv(struct snd_kcontrol * kctl,int op_flag,unsigned int size,unsigned int __user * buf)1671 static int snd_ctl_elem_user_tlv(struct snd_kcontrol *kctl, int op_flag,
1672 unsigned int size, unsigned int __user *buf)
1673 {
1674 if (op_flag == SNDRV_CTL_TLV_OP_WRITE)
1675 return replace_user_tlv(kctl, buf, size);
1676 else
1677 return read_user_tlv(kctl, buf, size);
1678 }
1679
1680 /* called in controls_rwsem write lock */
snd_ctl_elem_init_enum_names(struct user_element * ue)1681 static int snd_ctl_elem_init_enum_names(struct user_element *ue)
1682 {
1683 size_t buf_len, name_len;
1684 unsigned int i;
1685 const uintptr_t user_ptrval = ue->info.value.enumerated.names_ptr;
1686
1687 lockdep_assert_held_write(&ue->card->controls_rwsem);
1688
1689 buf_len = ue->info.value.enumerated.names_length;
1690 if (buf_len > 64 * 1024)
1691 return -EINVAL;
1692
1693 if (check_user_elem_overflow(ue->card, buf_len))
1694 return -ENOMEM;
1695 char *names __free(kvfree) = vmemdup_user((const void __user *)user_ptrval,
1696 buf_len);
1697
1698 if (IS_ERR(names))
1699 return PTR_ERR(names);
1700
1701 /* check that there are enough valid names */
1702 char *p = names;
1703
1704 for (i = 0; i < ue->info.value.enumerated.items; ++i) {
1705 if (buf_len == 0)
1706 return -EINVAL;
1707
1708 name_len = strnlen(p, buf_len);
1709 if (name_len == 0 || name_len >= 64 || name_len == buf_len)
1710 return -EINVAL;
1711
1712 p += name_len + 1;
1713 buf_len -= name_len + 1;
1714 }
1715
1716 ue->priv_data = no_free_ptr(names);
1717 ue->info.value.enumerated.names_ptr = 0;
1718 // increment the allocation size; decremented again at private_free.
1719 ue->card->user_ctl_alloc_size += ue->info.value.enumerated.names_length;
1720
1721 return 0;
1722 }
1723
compute_user_elem_size(size_t size,unsigned int count)1724 static size_t compute_user_elem_size(size_t size, unsigned int count)
1725 {
1726 return sizeof(struct user_element) + size * count;
1727 }
1728
snd_ctl_elem_user_free(struct snd_kcontrol * kcontrol)1729 static void snd_ctl_elem_user_free(struct snd_kcontrol *kcontrol)
1730 {
1731 struct user_element *ue = snd_kcontrol_chip(kcontrol);
1732
1733 // decrement the allocation size.
1734 ue->card->user_ctl_alloc_size -= compute_user_elem_size(ue->elem_data_size, kcontrol->count);
1735 ue->card->user_ctl_alloc_size -= ue->tlv_data_size;
1736 if (ue->priv_data)
1737 ue->card->user_ctl_alloc_size -= ue->info.value.enumerated.names_length;
1738
1739 kvfree(ue->tlv_data);
1740 kvfree(ue->priv_data);
1741 kfree(ue);
1742 }
1743
snd_ctl_elem_add(struct snd_ctl_file * file,struct snd_ctl_elem_info * info,int replace)1744 static int snd_ctl_elem_add(struct snd_ctl_file *file,
1745 struct snd_ctl_elem_info *info, int replace)
1746 {
1747 struct snd_card *card = file->card;
1748 struct snd_kcontrol *kctl;
1749 unsigned int count;
1750 unsigned int access;
1751 long private_size;
1752 size_t alloc_size;
1753 struct user_element *ue;
1754 unsigned int offset;
1755 int err;
1756
1757 if (!*info->id.name)
1758 return -EINVAL;
1759 if (strnlen(info->id.name, sizeof(info->id.name)) >= sizeof(info->id.name))
1760 return -EINVAL;
1761
1762 /* Delete a control to replace them if needed. */
1763 if (replace) {
1764 info->id.numid = 0;
1765 err = snd_ctl_remove_user_ctl(file, &info->id);
1766 if (err)
1767 return err;
1768 }
1769
1770 /* Check the number of elements for this userspace control. */
1771 count = info->owner;
1772 if (count == 0)
1773 count = 1;
1774 if (count > MAX_CONTROL_COUNT)
1775 return -EINVAL;
1776
1777 /* Arrange access permissions if needed. */
1778 access = info->access;
1779 if (access == 0)
1780 access = SNDRV_CTL_ELEM_ACCESS_READWRITE;
1781 access &= (SNDRV_CTL_ELEM_ACCESS_READWRITE |
1782 SNDRV_CTL_ELEM_ACCESS_INACTIVE |
1783 SNDRV_CTL_ELEM_ACCESS_TLV_WRITE);
1784
1785 /* In initial state, nothing is available as TLV container. */
1786 if (access & SNDRV_CTL_ELEM_ACCESS_TLV_WRITE)
1787 access |= SNDRV_CTL_ELEM_ACCESS_TLV_CALLBACK;
1788 access |= SNDRV_CTL_ELEM_ACCESS_USER;
1789
1790 /*
1791 * Check information and calculate the size of data specific to
1792 * this userspace control.
1793 */
1794 /* pass NULL to card for suppressing error messages */
1795 err = snd_ctl_check_elem_info(NULL, info);
1796 if (err < 0)
1797 return err;
1798 /* user-space control doesn't allow zero-size data */
1799 if (info->count < 1)
1800 return -EINVAL;
1801 private_size = value_sizes[info->type] * info->count;
1802 alloc_size = compute_user_elem_size(private_size, count);
1803
1804 guard(rwsem_write)(&card->controls_rwsem);
1805 if (check_user_elem_overflow(card, alloc_size))
1806 return -ENOMEM;
1807
1808 /*
1809 * Keep memory object for this userspace control. After passing this
1810 * code block, the instance should be freed by snd_ctl_free_one().
1811 *
1812 * Note that these elements in this control are locked.
1813 */
1814 err = snd_ctl_new(&kctl, count, access, file);
1815 if (err < 0)
1816 return err;
1817 memcpy(&kctl->id, &info->id, sizeof(kctl->id));
1818 ue = kzalloc(alloc_size, GFP_KERNEL);
1819 if (!ue) {
1820 kfree(kctl);
1821 return -ENOMEM;
1822 }
1823 kctl->private_data = ue;
1824 kctl->private_free = snd_ctl_elem_user_free;
1825
1826 // increment the allocated size; decremented again at private_free.
1827 card->user_ctl_alloc_size += alloc_size;
1828
1829 /* Set private data for this userspace control. */
1830 ue->card = card;
1831 ue->info = *info;
1832 ue->info.access = 0;
1833 ue->elem_data = (char *)ue + sizeof(*ue);
1834 ue->elem_data_size = private_size;
1835 if (ue->info.type == SNDRV_CTL_ELEM_TYPE_ENUMERATED) {
1836 err = snd_ctl_elem_init_enum_names(ue);
1837 if (err < 0) {
1838 snd_ctl_free_one(kctl);
1839 return err;
1840 }
1841 }
1842
1843 /* Set callback functions. */
1844 if (info->type == SNDRV_CTL_ELEM_TYPE_ENUMERATED)
1845 kctl->info = snd_ctl_elem_user_enum_info;
1846 else
1847 kctl->info = snd_ctl_elem_user_info;
1848 if (access & SNDRV_CTL_ELEM_ACCESS_READ)
1849 kctl->get = snd_ctl_elem_user_get;
1850 if (access & SNDRV_CTL_ELEM_ACCESS_WRITE)
1851 kctl->put = snd_ctl_elem_user_put;
1852 if (access & SNDRV_CTL_ELEM_ACCESS_TLV_WRITE)
1853 kctl->tlv.c = snd_ctl_elem_user_tlv;
1854
1855 /* This function manage to free the instance on failure. */
1856 err = __snd_ctl_add_replace(card, kctl, CTL_ADD_EXCLUSIVE);
1857 if (err < 0) {
1858 snd_ctl_free_one(kctl);
1859 return err;
1860 }
1861 offset = snd_ctl_get_ioff(kctl, &info->id);
1862 snd_ctl_build_ioff(&info->id, kctl, offset);
1863 /*
1864 * Here we cannot fill any field for the number of elements added by
1865 * this operation because there're no specific fields. The usage of
1866 * 'owner' field for this purpose may cause any bugs to userspace
1867 * applications because the field originally means PID of a process
1868 * which locks the element.
1869 */
1870 return 0;
1871 }
1872
snd_ctl_elem_add_user(struct snd_ctl_file * file,struct snd_ctl_elem_info __user * _info,int replace)1873 static int snd_ctl_elem_add_user(struct snd_ctl_file *file,
1874 struct snd_ctl_elem_info __user *_info, int replace)
1875 {
1876 struct snd_ctl_elem_info info;
1877 int err;
1878
1879 if (copy_from_user(&info, _info, sizeof(info)))
1880 return -EFAULT;
1881 err = snd_ctl_elem_add(file, &info, replace);
1882 if (err < 0)
1883 return err;
1884 if (copy_to_user(_info, &info, sizeof(info))) {
1885 snd_ctl_remove_user_ctl(file, &info.id);
1886 return -EFAULT;
1887 }
1888
1889 return 0;
1890 }
1891
snd_ctl_elem_remove(struct snd_ctl_file * file,struct snd_ctl_elem_id __user * _id)1892 static int snd_ctl_elem_remove(struct snd_ctl_file *file,
1893 struct snd_ctl_elem_id __user *_id)
1894 {
1895 struct snd_ctl_elem_id id;
1896
1897 if (copy_from_user(&id, _id, sizeof(id)))
1898 return -EFAULT;
1899 return snd_ctl_remove_user_ctl(file, &id);
1900 }
1901
snd_ctl_subscribe_events(struct snd_ctl_file * file,int __user * ptr)1902 static int snd_ctl_subscribe_events(struct snd_ctl_file *file, int __user *ptr)
1903 {
1904 int subscribe;
1905 if (get_user(subscribe, ptr))
1906 return -EFAULT;
1907 if (subscribe < 0) {
1908 subscribe = file->subscribed;
1909 if (put_user(subscribe, ptr))
1910 return -EFAULT;
1911 return 0;
1912 }
1913 if (subscribe) {
1914 file->subscribed = 1;
1915 return 0;
1916 } else if (file->subscribed) {
1917 snd_ctl_empty_read_queue(file);
1918 file->subscribed = 0;
1919 }
1920 return 0;
1921 }
1922
call_tlv_handler(struct snd_ctl_file * file,int op_flag,struct snd_kcontrol * kctl,struct snd_ctl_elem_id * id,unsigned int __user * buf,unsigned int size)1923 static int call_tlv_handler(struct snd_ctl_file *file, int op_flag,
1924 struct snd_kcontrol *kctl,
1925 struct snd_ctl_elem_id *id,
1926 unsigned int __user *buf, unsigned int size)
1927 {
1928 static const struct {
1929 int op;
1930 int perm;
1931 } pairs[] = {
1932 {SNDRV_CTL_TLV_OP_READ, SNDRV_CTL_ELEM_ACCESS_TLV_READ},
1933 {SNDRV_CTL_TLV_OP_WRITE, SNDRV_CTL_ELEM_ACCESS_TLV_WRITE},
1934 {SNDRV_CTL_TLV_OP_CMD, SNDRV_CTL_ELEM_ACCESS_TLV_COMMAND},
1935 };
1936 struct snd_kcontrol_volatile *vd = &kctl->vd[snd_ctl_get_ioff(kctl, id)];
1937 int i;
1938
1939 /* Check support of the request for this element. */
1940 for (i = 0; i < ARRAY_SIZE(pairs); ++i) {
1941 if (op_flag == pairs[i].op && (vd->access & pairs[i].perm))
1942 break;
1943 }
1944 if (i == ARRAY_SIZE(pairs))
1945 return -ENXIO;
1946
1947 if (kctl->tlv.c == NULL)
1948 return -ENXIO;
1949
1950 /* Write and command operations are not allowed for locked element. */
1951 if (op_flag != SNDRV_CTL_TLV_OP_READ &&
1952 vd->owner != NULL && vd->owner != file)
1953 return -EPERM;
1954
1955 return kctl->tlv.c(kctl, op_flag, size, buf);
1956 }
1957
read_tlv_buf(struct snd_kcontrol * kctl,struct snd_ctl_elem_id * id,unsigned int __user * buf,unsigned int size)1958 static int read_tlv_buf(struct snd_kcontrol *kctl, struct snd_ctl_elem_id *id,
1959 unsigned int __user *buf, unsigned int size)
1960 {
1961 struct snd_kcontrol_volatile *vd = &kctl->vd[snd_ctl_get_ioff(kctl, id)];
1962 unsigned int len;
1963
1964 if (!(vd->access & SNDRV_CTL_ELEM_ACCESS_TLV_READ))
1965 return -ENXIO;
1966
1967 if (kctl->tlv.p == NULL)
1968 return -ENXIO;
1969
1970 len = sizeof(unsigned int) * 2 + kctl->tlv.p[1];
1971 if (size < len)
1972 return -ENOMEM;
1973
1974 if (copy_to_user(buf, kctl->tlv.p, len))
1975 return -EFAULT;
1976
1977 return 0;
1978 }
1979
snd_ctl_tlv_ioctl(struct snd_ctl_file * file,struct snd_ctl_tlv __user * buf,int op_flag)1980 static int snd_ctl_tlv_ioctl(struct snd_ctl_file *file,
1981 struct snd_ctl_tlv __user *buf,
1982 int op_flag)
1983 {
1984 struct snd_ctl_tlv header;
1985 unsigned int __user *container;
1986 unsigned int container_size;
1987 struct snd_kcontrol *kctl;
1988 struct snd_ctl_elem_id id;
1989 struct snd_kcontrol_volatile *vd;
1990
1991 lockdep_assert_held(&file->card->controls_rwsem);
1992
1993 if (copy_from_user(&header, buf, sizeof(header)))
1994 return -EFAULT;
1995
1996 /* In design of control core, numerical ID starts at 1. */
1997 if (header.numid == 0)
1998 return -EINVAL;
1999
2000 /* At least, container should include type and length fields. */
2001 if (header.length < sizeof(unsigned int) * 2)
2002 return -EINVAL;
2003 container_size = header.length;
2004 container = buf->tlv;
2005
2006 kctl = snd_ctl_find_numid(file->card, header.numid);
2007 if (kctl == NULL)
2008 return -ENOENT;
2009
2010 /* Calculate index of the element in this set. */
2011 id = kctl->id;
2012 snd_ctl_build_ioff(&id, kctl, header.numid - id.numid);
2013 vd = &kctl->vd[snd_ctl_get_ioff(kctl, &id)];
2014
2015 if (vd->access & SNDRV_CTL_ELEM_ACCESS_TLV_CALLBACK) {
2016 return call_tlv_handler(file, op_flag, kctl, &id, container,
2017 container_size);
2018 } else {
2019 if (op_flag == SNDRV_CTL_TLV_OP_READ) {
2020 return read_tlv_buf(kctl, &id, container,
2021 container_size);
2022 }
2023 }
2024
2025 /* Not supported. */
2026 return -ENXIO;
2027 }
2028
snd_ctl_ioctl(struct file * file,unsigned int cmd,unsigned long arg)2029 static long snd_ctl_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
2030 {
2031 struct snd_ctl_file *ctl;
2032 struct snd_card *card;
2033 struct snd_kctl_ioctl *p;
2034 void __user *argp = (void __user *)arg;
2035 int __user *ip = argp;
2036 int err;
2037
2038 ctl = file->private_data;
2039 card = ctl->card;
2040 if (snd_BUG_ON(!card))
2041 return -ENXIO;
2042 switch (cmd) {
2043 case SNDRV_CTL_IOCTL_PVERSION:
2044 return put_user(SNDRV_CTL_VERSION, ip) ? -EFAULT : 0;
2045 case SNDRV_CTL_IOCTL_CARD_INFO:
2046 return snd_ctl_card_info(card, ctl, cmd, argp);
2047 case SNDRV_CTL_IOCTL_CARD_BYTES:
2048 return snd_ctl_card_bytes_user(card, argp);
2049 case SNDRV_CTL_IOCTL_ELEM_LIST:
2050 return snd_ctl_elem_list_user(card, argp);
2051 case SNDRV_CTL_IOCTL_ELEM_INFO:
2052 return snd_ctl_elem_info_user(ctl, argp);
2053 case SNDRV_CTL_IOCTL_ELEM_READ:
2054 return snd_ctl_elem_read_user(card, argp);
2055 case SNDRV_CTL_IOCTL_ELEM_WRITE:
2056 return snd_ctl_elem_write_user(ctl, argp);
2057 case SNDRV_CTL_IOCTL_ELEM_LOCK:
2058 return snd_ctl_elem_lock(ctl, argp);
2059 case SNDRV_CTL_IOCTL_ELEM_UNLOCK:
2060 return snd_ctl_elem_unlock(ctl, argp);
2061 case SNDRV_CTL_IOCTL_ELEM_ADD:
2062 return snd_ctl_elem_add_user(ctl, argp, 0);
2063 case SNDRV_CTL_IOCTL_ELEM_REPLACE:
2064 return snd_ctl_elem_add_user(ctl, argp, 1);
2065 case SNDRV_CTL_IOCTL_ELEM_REMOVE:
2066 return snd_ctl_elem_remove(ctl, argp);
2067 case SNDRV_CTL_IOCTL_SUBSCRIBE_EVENTS:
2068 return snd_ctl_subscribe_events(ctl, ip);
2069 case SNDRV_CTL_IOCTL_TLV_READ:
2070 err = snd_power_ref_and_wait(card);
2071 if (err < 0)
2072 return err;
2073 scoped_guard(rwsem_read, &card->controls_rwsem)
2074 err = snd_ctl_tlv_ioctl(ctl, argp, SNDRV_CTL_TLV_OP_READ);
2075 snd_power_unref(card);
2076 return err;
2077 case SNDRV_CTL_IOCTL_TLV_WRITE:
2078 err = snd_power_ref_and_wait(card);
2079 if (err < 0)
2080 return err;
2081 scoped_guard(rwsem_write, &card->controls_rwsem)
2082 err = snd_ctl_tlv_ioctl(ctl, argp, SNDRV_CTL_TLV_OP_WRITE);
2083 snd_power_unref(card);
2084 return err;
2085 case SNDRV_CTL_IOCTL_TLV_COMMAND:
2086 err = snd_power_ref_and_wait(card);
2087 if (err < 0)
2088 return err;
2089 scoped_guard(rwsem_write, &card->controls_rwsem)
2090 err = snd_ctl_tlv_ioctl(ctl, argp, SNDRV_CTL_TLV_OP_CMD);
2091 snd_power_unref(card);
2092 return err;
2093 case SNDRV_CTL_IOCTL_POWER:
2094 return -ENOPROTOOPT;
2095 case SNDRV_CTL_IOCTL_POWER_STATE:
2096 return put_user(SNDRV_CTL_POWER_D0, ip) ? -EFAULT : 0;
2097 }
2098
2099 guard(rwsem_read)(&snd_ioctl_rwsem);
2100 list_for_each_entry(p, &snd_control_ioctls, list) {
2101 err = p->fioctl(card, ctl, cmd, arg);
2102 if (err != -ENOIOCTLCMD)
2103 return err;
2104 }
2105 dev_dbg(card->dev, "unknown ioctl = 0x%x\n", cmd);
2106 return -ENOTTY;
2107 }
2108
snd_ctl_read(struct file * file,char __user * buffer,size_t count,loff_t * offset)2109 static ssize_t snd_ctl_read(struct file *file, char __user *buffer,
2110 size_t count, loff_t * offset)
2111 {
2112 struct snd_ctl_file *ctl;
2113 int err = 0;
2114 ssize_t result = 0;
2115
2116 ctl = file->private_data;
2117 if (snd_BUG_ON(!ctl || !ctl->card))
2118 return -ENXIO;
2119 if (!ctl->subscribed)
2120 return -EBADFD;
2121 if (count < sizeof(struct snd_ctl_event))
2122 return -EINVAL;
2123 spin_lock_irq(&ctl->read_lock);
2124 while (count >= sizeof(struct snd_ctl_event)) {
2125 struct snd_ctl_event ev;
2126 struct snd_kctl_event *kev;
2127 while (list_empty(&ctl->events)) {
2128 wait_queue_entry_t wait;
2129 if ((file->f_flags & O_NONBLOCK) != 0 || result > 0) {
2130 err = -EAGAIN;
2131 goto __end_lock;
2132 }
2133 init_waitqueue_entry(&wait, current);
2134 add_wait_queue(&ctl->change_sleep, &wait);
2135 set_current_state(TASK_INTERRUPTIBLE);
2136 spin_unlock_irq(&ctl->read_lock);
2137 schedule();
2138 remove_wait_queue(&ctl->change_sleep, &wait);
2139 if (ctl->card->shutdown)
2140 return -ENODEV;
2141 if (signal_pending(current))
2142 return -ERESTARTSYS;
2143 spin_lock_irq(&ctl->read_lock);
2144 }
2145 kev = snd_kctl_event(ctl->events.next);
2146 ev.type = SNDRV_CTL_EVENT_ELEM;
2147 ev.data.elem.mask = kev->mask;
2148 ev.data.elem.id = kev->id;
2149 list_del(&kev->list);
2150 spin_unlock_irq(&ctl->read_lock);
2151 kfree(kev);
2152 if (copy_to_user(buffer, &ev, sizeof(struct snd_ctl_event))) {
2153 err = -EFAULT;
2154 goto __end;
2155 }
2156 spin_lock_irq(&ctl->read_lock);
2157 buffer += sizeof(struct snd_ctl_event);
2158 count -= sizeof(struct snd_ctl_event);
2159 result += sizeof(struct snd_ctl_event);
2160 }
2161 __end_lock:
2162 spin_unlock_irq(&ctl->read_lock);
2163 __end:
2164 return result > 0 ? result : err;
2165 }
2166
snd_ctl_poll(struct file * file,poll_table * wait)2167 static __poll_t snd_ctl_poll(struct file *file, poll_table * wait)
2168 {
2169 __poll_t mask;
2170 struct snd_ctl_file *ctl;
2171
2172 ctl = file->private_data;
2173 if (!ctl->subscribed)
2174 return 0;
2175 poll_wait(file, &ctl->change_sleep, wait);
2176
2177 mask = 0;
2178 if (!list_empty(&ctl->events))
2179 mask |= EPOLLIN | EPOLLRDNORM;
2180
2181 return mask;
2182 }
2183
2184 /*
2185 * register the device-specific control-ioctls.
2186 * called from each device manager like pcm.c, hwdep.c, etc.
2187 */
_snd_ctl_register_ioctl(snd_kctl_ioctl_func_t fcn,struct list_head * lists)2188 static int _snd_ctl_register_ioctl(snd_kctl_ioctl_func_t fcn, struct list_head *lists)
2189 {
2190 struct snd_kctl_ioctl *pn;
2191
2192 pn = kzalloc_obj(struct snd_kctl_ioctl);
2193 if (pn == NULL)
2194 return -ENOMEM;
2195 pn->fioctl = fcn;
2196 guard(rwsem_write)(&snd_ioctl_rwsem);
2197 list_add_tail(&pn->list, lists);
2198 return 0;
2199 }
2200
2201 /**
2202 * snd_ctl_register_ioctl - register the device-specific control-ioctls
2203 * @fcn: ioctl callback function
2204 *
2205 * called from each device manager like pcm.c, hwdep.c, etc.
2206 *
2207 * Return: zero if successful, or a negative error code
2208 */
snd_ctl_register_ioctl(snd_kctl_ioctl_func_t fcn)2209 int snd_ctl_register_ioctl(snd_kctl_ioctl_func_t fcn)
2210 {
2211 return _snd_ctl_register_ioctl(fcn, &snd_control_ioctls);
2212 }
2213 EXPORT_SYMBOL(snd_ctl_register_ioctl);
2214
2215 #ifdef CONFIG_COMPAT
2216 /**
2217 * snd_ctl_register_ioctl_compat - register the device-specific 32bit compat
2218 * control-ioctls
2219 * @fcn: ioctl callback function
2220 *
2221 * Return: zero if successful, or a negative error code
2222 */
snd_ctl_register_ioctl_compat(snd_kctl_ioctl_func_t fcn)2223 int snd_ctl_register_ioctl_compat(snd_kctl_ioctl_func_t fcn)
2224 {
2225 return _snd_ctl_register_ioctl(fcn, &snd_control_compat_ioctls);
2226 }
2227 EXPORT_SYMBOL(snd_ctl_register_ioctl_compat);
2228 #endif
2229
2230 /*
2231 * de-register the device-specific control-ioctls.
2232 */
_snd_ctl_unregister_ioctl(snd_kctl_ioctl_func_t fcn,struct list_head * lists)2233 static int _snd_ctl_unregister_ioctl(snd_kctl_ioctl_func_t fcn,
2234 struct list_head *lists)
2235 {
2236 struct snd_kctl_ioctl *p;
2237
2238 if (snd_BUG_ON(!fcn))
2239 return -EINVAL;
2240 guard(rwsem_write)(&snd_ioctl_rwsem);
2241 list_for_each_entry(p, lists, list) {
2242 if (p->fioctl == fcn) {
2243 list_del(&p->list);
2244 kfree(p);
2245 return 0;
2246 }
2247 }
2248 snd_BUG();
2249 return -EINVAL;
2250 }
2251
2252 /**
2253 * snd_ctl_unregister_ioctl - de-register the device-specific control-ioctls
2254 * @fcn: ioctl callback function to unregister
2255 *
2256 * Return: zero if successful, or a negative error code
2257 */
snd_ctl_unregister_ioctl(snd_kctl_ioctl_func_t fcn)2258 int snd_ctl_unregister_ioctl(snd_kctl_ioctl_func_t fcn)
2259 {
2260 return _snd_ctl_unregister_ioctl(fcn, &snd_control_ioctls);
2261 }
2262 EXPORT_SYMBOL(snd_ctl_unregister_ioctl);
2263
2264 #ifdef CONFIG_COMPAT
2265 /**
2266 * snd_ctl_unregister_ioctl_compat - de-register the device-specific compat
2267 * 32bit control-ioctls
2268 * @fcn: ioctl callback function to unregister
2269 *
2270 * Return: zero if successful, or a negative error code
2271 */
snd_ctl_unregister_ioctl_compat(snd_kctl_ioctl_func_t fcn)2272 int snd_ctl_unregister_ioctl_compat(snd_kctl_ioctl_func_t fcn)
2273 {
2274 return _snd_ctl_unregister_ioctl(fcn, &snd_control_compat_ioctls);
2275 }
2276 EXPORT_SYMBOL(snd_ctl_unregister_ioctl_compat);
2277 #endif
2278
snd_ctl_fasync(int fd,struct file * file,int on)2279 static int snd_ctl_fasync(int fd, struct file * file, int on)
2280 {
2281 struct snd_ctl_file *ctl;
2282
2283 ctl = file->private_data;
2284 return snd_fasync_helper(fd, file, on, &ctl->fasync);
2285 }
2286
2287 /* return the preferred subdevice number if already assigned;
2288 * otherwise return -1
2289 */
snd_ctl_get_preferred_subdevice(struct snd_card * card,int type)2290 int snd_ctl_get_preferred_subdevice(struct snd_card *card, int type)
2291 {
2292 struct snd_ctl_file *kctl;
2293 int subdevice = -1;
2294
2295 guard(read_lock_irqsave)(&card->controls_rwlock);
2296 list_for_each_entry(kctl, &card->ctl_files, list) {
2297 if (kctl->pid == task_pid(current)) {
2298 subdevice = kctl->preferred_subdevice[type];
2299 if (subdevice != -1)
2300 break;
2301 }
2302 }
2303 return subdevice;
2304 }
2305 EXPORT_SYMBOL_GPL(snd_ctl_get_preferred_subdevice);
2306
2307 /*
2308 * ioctl32 compat
2309 */
2310 #ifdef CONFIG_COMPAT
2311 #include "control_compat.c"
2312 #else
2313 #define snd_ctl_ioctl_compat NULL
2314 #endif
2315
2316 /*
2317 * control layers (audio LED etc.)
2318 */
2319
2320 /**
2321 * snd_ctl_request_layer - request to use the layer
2322 * @module_name: Name of the kernel module (NULL == build-in)
2323 *
2324 * Return: zero if successful, or an error code when the module cannot be loaded
2325 */
snd_ctl_request_layer(const char * module_name)2326 int snd_ctl_request_layer(const char *module_name)
2327 {
2328 struct snd_ctl_layer_ops *lops;
2329
2330 if (module_name == NULL)
2331 return 0;
2332 scoped_guard(rwsem_read, &snd_ctl_layer_rwsem) {
2333 for (lops = snd_ctl_layer; lops; lops = lops->next)
2334 if (strcmp(lops->module_name, module_name) == 0)
2335 return 0;
2336 }
2337 return request_module(module_name);
2338 }
2339 EXPORT_SYMBOL_GPL(snd_ctl_request_layer);
2340
2341 /**
2342 * snd_ctl_register_layer - register new control layer
2343 * @lops: operation structure
2344 *
2345 * The new layer can track all control elements and do additional
2346 * operations on top (like audio LED handling).
2347 */
snd_ctl_register_layer(struct snd_ctl_layer_ops * lops)2348 void snd_ctl_register_layer(struct snd_ctl_layer_ops *lops)
2349 {
2350 int card_number;
2351
2352 scoped_guard(rwsem_write, &snd_ctl_layer_rwsem) {
2353 lops->next = snd_ctl_layer;
2354 snd_ctl_layer = lops;
2355 }
2356 for (card_number = 0; card_number < SNDRV_CARDS; card_number++) {
2357 struct snd_card *card __free(snd_card_unref) =
2358 snd_card_ref(card_number);
2359
2360 if (card) {
2361 scoped_guard(rwsem_read, &card->controls_rwsem)
2362 lops->lregister(card);
2363 }
2364 }
2365 }
2366 EXPORT_SYMBOL_GPL(snd_ctl_register_layer);
2367
2368 /**
2369 * snd_ctl_disconnect_layer - disconnect control layer
2370 * @lops: operation structure
2371 *
2372 * It is expected that the information about tracked cards
2373 * is freed before this call (the disconnect callback is
2374 * not called here).
2375 */
snd_ctl_disconnect_layer(struct snd_ctl_layer_ops * lops)2376 void snd_ctl_disconnect_layer(struct snd_ctl_layer_ops *lops)
2377 {
2378 struct snd_ctl_layer_ops *lops2, *prev_lops2;
2379
2380 guard(rwsem_write)(&snd_ctl_layer_rwsem);
2381 for (lops2 = snd_ctl_layer, prev_lops2 = NULL; lops2; lops2 = lops2->next) {
2382 if (lops2 == lops) {
2383 if (!prev_lops2)
2384 snd_ctl_layer = lops->next;
2385 else
2386 prev_lops2->next = lops->next;
2387 break;
2388 }
2389 prev_lops2 = lops2;
2390 }
2391 }
2392 EXPORT_SYMBOL_GPL(snd_ctl_disconnect_layer);
2393
2394 /*
2395 * INIT PART
2396 */
2397
2398 static const struct file_operations snd_ctl_f_ops = {
2399 .owner = THIS_MODULE,
2400 .read = snd_ctl_read,
2401 .open = snd_ctl_open,
2402 .release = snd_ctl_release,
2403 .poll = snd_ctl_poll,
2404 .unlocked_ioctl = snd_ctl_ioctl,
2405 .compat_ioctl = snd_ctl_ioctl_compat,
2406 .fasync = snd_ctl_fasync,
2407 };
2408
2409 /* call lops under rwsems; called from snd_ctl_dev_*() below() */
2410 #define call_snd_ctl_lops(_card, _op) \
2411 do { \
2412 struct snd_ctl_layer_ops *lops; \
2413 guard(rwsem_read)(&(_card)->controls_rwsem); \
2414 guard(rwsem_read)(&snd_ctl_layer_rwsem); \
2415 for (lops = snd_ctl_layer; lops; lops = lops->next) \
2416 lops->_op(_card); \
2417 } while (0)
2418
2419 /*
2420 * registration of the control device
2421 */
snd_ctl_dev_register(struct snd_device * device)2422 static int snd_ctl_dev_register(struct snd_device *device)
2423 {
2424 struct snd_card *card = device->device_data;
2425 int err;
2426
2427 err = snd_register_device(SNDRV_DEVICE_TYPE_CONTROL, card, -1,
2428 &snd_ctl_f_ops, card, card->ctl_dev);
2429 if (err < 0)
2430 return err;
2431 call_snd_ctl_lops(card, lregister);
2432 return 0;
2433 }
2434
2435 /*
2436 * disconnection of the control device
2437 */
snd_ctl_dev_disconnect(struct snd_device * device)2438 static int snd_ctl_dev_disconnect(struct snd_device *device)
2439 {
2440 struct snd_card *card = device->device_data;
2441 struct snd_ctl_file *ctl;
2442
2443 scoped_guard(read_lock_irqsave, &card->controls_rwlock) {
2444 list_for_each_entry(ctl, &card->ctl_files, list) {
2445 wake_up(&ctl->change_sleep);
2446 snd_kill_fasync(ctl->fasync, SIGIO, POLL_ERR);
2447 }
2448 }
2449
2450 call_snd_ctl_lops(card, ldisconnect);
2451 return snd_unregister_device(card->ctl_dev);
2452 }
2453
2454 /*
2455 * free all controls
2456 */
snd_ctl_dev_free(struct snd_device * device)2457 static int snd_ctl_dev_free(struct snd_device *device)
2458 {
2459 struct snd_card *card = device->device_data;
2460 struct snd_kcontrol *control;
2461
2462 scoped_guard(rwsem_write, &card->controls_rwsem) {
2463 while (!list_empty(&card->controls)) {
2464 control = snd_kcontrol(card->controls.next);
2465 __snd_ctl_remove(card, control, false);
2466 }
2467
2468 #ifdef CONFIG_SND_CTL_FAST_LOOKUP
2469 xa_destroy(&card->ctl_numids);
2470 xa_destroy(&card->ctl_hash);
2471 #endif
2472 }
2473 put_device(card->ctl_dev);
2474 return 0;
2475 }
2476
2477 /*
2478 * create control core:
2479 * called from init.c
2480 */
snd_ctl_create(struct snd_card * card)2481 int snd_ctl_create(struct snd_card *card)
2482 {
2483 static const struct snd_device_ops ops = {
2484 .dev_free = snd_ctl_dev_free,
2485 .dev_register = snd_ctl_dev_register,
2486 .dev_disconnect = snd_ctl_dev_disconnect,
2487 };
2488 int err;
2489
2490 if (snd_BUG_ON(!card))
2491 return -ENXIO;
2492 if (snd_BUG_ON(card->number < 0 || card->number >= SNDRV_CARDS))
2493 return -ENXIO;
2494
2495 err = snd_device_alloc(&card->ctl_dev, card);
2496 if (err < 0)
2497 return err;
2498 dev_set_name(card->ctl_dev, "controlC%d", card->number);
2499
2500 err = snd_device_new(card, SNDRV_DEV_CONTROL, card, &ops);
2501 if (err < 0)
2502 put_device(card->ctl_dev);
2503 return err;
2504 }
2505
2506 /*
2507 * Frequently used control callbacks/helpers
2508 */
2509
2510 /**
2511 * snd_ctl_boolean_mono_info - Helper function for a standard boolean info
2512 * callback with a mono channel
2513 * @kcontrol: the kcontrol instance
2514 * @uinfo: info to store
2515 *
2516 * This is a function that can be used as info callback for a standard
2517 * boolean control with a single mono channel.
2518 *
2519 * Return: Zero (always successful)
2520 */
snd_ctl_boolean_mono_info(struct snd_kcontrol * kcontrol,struct snd_ctl_elem_info * uinfo)2521 int snd_ctl_boolean_mono_info(struct snd_kcontrol *kcontrol,
2522 struct snd_ctl_elem_info *uinfo)
2523 {
2524 uinfo->type = SNDRV_CTL_ELEM_TYPE_BOOLEAN;
2525 uinfo->count = 1;
2526 uinfo->value.integer.min = 0;
2527 uinfo->value.integer.max = 1;
2528 return 0;
2529 }
2530 EXPORT_SYMBOL(snd_ctl_boolean_mono_info);
2531
2532 /**
2533 * snd_ctl_boolean_stereo_info - Helper function for a standard boolean info
2534 * callback with stereo two channels
2535 * @kcontrol: the kcontrol instance
2536 * @uinfo: info to store
2537 *
2538 * This is a function that can be used as info callback for a standard
2539 * boolean control with stereo two channels.
2540 *
2541 * Return: Zero (always successful)
2542 */
snd_ctl_boolean_stereo_info(struct snd_kcontrol * kcontrol,struct snd_ctl_elem_info * uinfo)2543 int snd_ctl_boolean_stereo_info(struct snd_kcontrol *kcontrol,
2544 struct snd_ctl_elem_info *uinfo)
2545 {
2546 uinfo->type = SNDRV_CTL_ELEM_TYPE_BOOLEAN;
2547 uinfo->count = 2;
2548 uinfo->value.integer.min = 0;
2549 uinfo->value.integer.max = 1;
2550 return 0;
2551 }
2552 EXPORT_SYMBOL(snd_ctl_boolean_stereo_info);
2553
2554 /**
2555 * snd_ctl_enum_info - fills the info structure for an enumerated control
2556 * @info: the structure to be filled
2557 * @channels: the number of the control's channels; often one
2558 * @items: the number of control values; also the size of @names
2559 * @names: an array containing the names of all control values
2560 *
2561 * Sets all required fields in @info to their appropriate values.
2562 * If the control's accessibility is not the default (readable and writable),
2563 * the caller has to fill @info->access.
2564 *
2565 * Return: Zero (always successful)
2566 */
snd_ctl_enum_info(struct snd_ctl_elem_info * info,unsigned int channels,unsigned int items,const char * const names[])2567 int snd_ctl_enum_info(struct snd_ctl_elem_info *info, unsigned int channels,
2568 unsigned int items, const char *const names[])
2569 {
2570 info->type = SNDRV_CTL_ELEM_TYPE_ENUMERATED;
2571 info->count = channels;
2572 info->value.enumerated.items = items;
2573 if (!items)
2574 return 0;
2575 if (info->value.enumerated.item >= items)
2576 info->value.enumerated.item = items - 1;
2577 WARN(strlen(names[info->value.enumerated.item]) >= sizeof(info->value.enumerated.name),
2578 "ALSA: too long item name '%s'\n",
2579 names[info->value.enumerated.item]);
2580 strscpy(info->value.enumerated.name,
2581 names[info->value.enumerated.item],
2582 sizeof(info->value.enumerated.name));
2583 return 0;
2584 }
2585 EXPORT_SYMBOL(snd_ctl_enum_info);
2586