Skip to content

android: synchronize AAudio routing state - #302

Closed
kumagi wants to merge 1 commit into
ebitengine:mainfrom
kumagi:audit/android-aaudio-routing-lock
Closed

kumagi wants to merge 1 commit into
ebitengine:mainfrom
kumagi:audit/android-aaudio-routing-lock

Conversation

@kumagi

@kumagi kumagi commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

What issue is this addressing?

No issue filed yet. Found during an audit of the vendored Oboe sources (Oboe 1.11.0).

What type of issue is this addressing?

bug

What this PR does | solves

In AudioStreamAAudio (internal/oboe/oboe_aaudio_AudioStreamAAudio_android.cpp), the double-buffered mUpdatedDeviceIds.deviceIds[] vectors are written by the AAudio routing-change callback while getDeviceId() / getDeviceIds() copy them on the calling thread — with no synchronization:

void AudioStreamAAudio::onRoutingChanged(std::vector<int32_t> deviceIds) {
    int nextIdx = mUpdatedDeviceIds.idx.load() ^ 1;
    mUpdatedDeviceIds.deviceIds[nextIdx] = deviceIds;   // vector assignment on callback thread
    mUpdatedDeviceIds.idx.store(nextIdx);
}

int32_t AudioStreamAAudio::getDeviceId() const {
    auto deviceIds = mUpdatedDeviceIds.deviceIds[mUpdatedDeviceIds.idx.load()];  // unsynchronized copy
    ...
}

The idx flip makes the read side pick the other slot, but a second routing change while getDeviceId()/getDeviceIds() is copying reuses the slot being read, so the std::vector assignment races with the copy — reallocation of the vector's heap buffer under a concurrent read is undefined behavior.

The fix

Add mUpdatedDeviceIdsLock (a std::mutex) and guard all three accesses — the two writes in onRoutingChanged/updateDeviceIds and the reads in getDeviceId/getDeviceIds. The critical sections are short (a vector assign/copy), so a plain mutex is sufficient.

Note: this file is vendored from Oboe 1.11.0 by internal/oboe/gen.go; the same fix would ideally be applied upstream in google/oboe as well.

@hajimehoshi

Copy link
Copy Markdown
Member

We cannot fix Oboe source code directly. If you need, report the issue to github.com/google/oboe

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants