From 7fda1d3cb8cefe62f3dd2baebfe7bbeb7822568b Mon Sep 17 00:00:00 2001 From: Tomasz Leman Date: Fri, 2 Oct 2026 15:53:27 +0200 Subject: [PATCH] ipc4: volume: probe: declare init payload structs 4-byte aligned struct ipc4_peak_volume_config, struct ipc4_peak_volume_module_cfg and struct ipc4_probe_module_cfg are declared __packed __aligned(8) and are dereferenced in place in the hostbox via mod->priv.cfg.init_data. The IPC4 INIT_MODULE_INSTANCE payload only guarantees 4-byte alignment: when the extension has extended_init set, the module config follows the 12-byte struct ipc4_module_init_ext_init (plus optional 4-byte-granular ext init objects), so it lands at a 4-byte aligned offset. The Linux driver uses extended init for DP modules, so this happens on real hardware, not only under native_sim. UBSan reports "member access within misaligned address ... which requires 8 byte alignment" in volume_init() and probe_mod_init(). Relax the declared alignment to 4 bytes, matching every other IPC4 payload struct. sizeof() and all member offsets are unchanged (24/40 and 48 bytes respectively), so the wire layout is untouched. Found by the IPC4 libFuzzer campaign with -fsanitize=undefined. Signed-off-by: Tomasz Leman --- src/audio/volume/peak_volume.h | 4 ++-- src/include/ipc4/probe.h | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/src/audio/volume/peak_volume.h b/src/audio/volume/peak_volume.h index 057db458277a..7639ef2def72 100644 --- a/src/audio/volume/peak_volume.h +++ b/src/audio/volume/peak_volume.h @@ -73,12 +73,12 @@ struct ipc4_peak_volume_config { * initialization. */ uint64_t curve_duration; -} __packed __aligned(8); +} __packed __aligned(4); struct ipc4_peak_volume_module_cfg { struct ipc4_base_module_cfg base_cfg; struct ipc4_peak_volume_config config[]; -} __packed __aligned(8); +} __packed __aligned(4); static inline enum sof_volume_ramp ipc4_curve_type_convert(enum ipc4_curve_type ipc4_type) { diff --git a/src/include/ipc4/probe.h b/src/include/ipc4/probe.h index 70b23632eecb..96efc1bb7acd 100644 --- a/src/include/ipc4/probe.h +++ b/src/include/ipc4/probe.h @@ -92,6 +92,6 @@ struct sof_ipc_probe_info_params { struct ipc4_probe_module_cfg { struct ipc4_base_module_cfg base_cfg; struct probe_dma gtw_cfg; -} __packed __aligned(8); +} __packed __aligned(4); #endif /* __SOF_IPC4_PROBE_H__ */