diff options
| author | Cássio Gabriel <cassiogabrielcontato@gmail.com> | 2026-05-31 20:41:41 -0300 |
|---|---|---|
| committer | Takashi Iwai <tiwai@suse.de> | 2026-06-01 11:28:32 +0200 |
| commit | 8a2d0b5496850403d1105efbbe54aa8fc68cae6f (patch) | |
| tree | 47c0e38d39234ad8f6eb3ac8303ed78a06d19dde /sound/core | |
| parent | 635b5c6622f317a06c11ee050c2665c1085b68a0 (diff) | |
ALSA: seq: Use flexible array for device arguments
snd_seq_device_new() allocates struct snd_seq_device together with a
caller-specific argument area. SNDRV_SEQ_DEVICE_ARGPTR() reaches that
area by adding sizeof(struct snd_seq_device) to the object pointer.
Make the trailing storage explicit with a flexible array and allocate it
with kzalloc_flex(). This makes the object layout self-describing and
avoids open-coded size arithmetic in the allocation and accessor.
Reject negative argsize values before calculating the allocation size.
Current in-tree callers pass either zero or sizeof() values, but the
function takes an int size argument and should not let a negative value
flow into unsigned allocation arithmetic.
Signed-off-by: Cássio Gabriel <cassiogabrielcontato@gmail.com>
Link: https://patch.msgid.link/20260531-alsa-seq-flex-args-v2-1-6e068d4ed9b0@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Diffstat (limited to 'sound/core')
| -rw-r--r-- | sound/core/seq_device.c | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/sound/core/seq_device.c b/sound/core/seq_device.c index 1b062d6b17ea..8be1f3ab5b63 100644 --- a/sound/core/seq_device.c +++ b/sound/core/seq_device.c @@ -234,7 +234,10 @@ int snd_seq_device_new(struct snd_card *card, int device, const char *id, if (snd_BUG_ON(!id)) return -EINVAL; - dev = kzalloc(sizeof(*dev) + argsize, GFP_KERNEL); + if (argsize < 0) + return -EINVAL; + + dev = kzalloc_flex(*dev, args, argsize); if (!dev) return -ENOMEM; |
