Skip to content

module: mux: fix dead source check in demux_process - #11284

Open
tmleman wants to merge 1 commit into
thesofproject:mainfrom
tmleman:topic/upstream/pr/audio/mux/fix/dead_null_check
Open

tmleman wants to merge 1 commit into
thesofproject:mainfrom
tmleman:topic/upstream/pr/audio/mux/fix/dead_null_check

Conversation

@tmleman

@tmleman tmleman commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

The guard read "sources == NULL && sources[0] == NULL". mod->sources is a fixed array inside struct processing_module, so the array argument decays to a non-NULL address and the first operand is always false. The condition is therefore tautologically false and the intended check never runs.

struct processing_module is memset to zero on allocation, so with no source bound sources[0] is NULL and the function falls through to source_get_data_frames_available(NULL).

Check num_of_sources instead of probing sources[0]. The count is the authoritative indication of whether a source is connected, whereas a NULL sources[0] only reflects the zeroed allocation. This also matches mux_process() in the same file and the guards used by copier, volume, rtnr and dts. The separate num_of_sinks test is folded into the same condition.

Note: clang-analyzer-core.NullDereference reported this as a deref of a NULL sources array; that path is unreachable because sources can never be NULL. The defect is the dead check, not the reported deref.

Assisted-by: Copilot:claude-opus-5 clang-tidy

Copilot AI balanced review requested due to automatic review settings October 8, 2026 09:43
@tmleman
tmleman requested a review from fkwasowi as a code owner October 8, 2026 09:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The corrected zero-source path lacks regression test coverage.

1 open finding
What changed in this PR

Fixes demux processing when no source is connected, preventing a null-source access.

Changes:

  • Uses source and sink counts as authoritative guards.
  • Consolidates the early-return conditions.
File Description
src/​audio/​mux/​mux.c Corrects the demux no-source guard.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread src/audio/mux/mux.c

if (sources == NULL && sources[0] == NULL) {
/* if there are no sources or sinks active, then there is nothing to do */
if (num_of_sources == 0 || num_of_sinks == 0) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cmocka being deprecated in favour of ztests so acceptable.

The guard read "sources == NULL && sources[0] == NULL". mod->sources is a
fixed array inside struct processing_module, so the array argument decays to
a non-NULL address and the first operand is always false. The condition is
therefore tautologically false and the intended check never runs.

struct processing_module is memset to zero on allocation, so with no source
bound sources[0] is NULL and the function falls through to
source_get_data_frames_available(NULL).

Check num_of_sources instead of probing sources[0]. The count is the
authoritative indication of whether a source is connected, whereas a NULL
sources[0] only reflects the zeroed allocation. This also matches
mux_process() in the same file and the guards used by copier, volume, rtnr
and dts. The separate num_of_sinks test is folded into the same condition.

Note: clang-analyzer-core.NullDereference reported this as a deref of a NULL
sources array; that path is unreachable because sources can never be NULL.
The defect is the dead check, not the reported deref.

Assisted-by: Copilot:claude-opus-5 clang-tidy
Signed-off-by: Tomasz Leman <tomasz.m.leman@intel.com>
@intel-sofci

intel-sofci commented Oct 8, 2026 •

Copy link
Copy Markdown

PR 11284: test results

Run date: 2026-10-08 13:31 UTC

Tested commit: b54c14934fe1e4528f44d44d29e1e76cd2293102

mtl pass rate lnl pass rate ptl pass rate wcl pass rate nvl pass rate

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants