From nobody Tue Sep 29 04:39:03 2026 Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 815E842AFA2 for ; Wed, 12 Aug 2026 10:53:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532008; cv=none; b=X8ph/SuUkBFrLv4FBF2+2zttseIsTogT+dxNlKtYnQ4oLyKbxKF1Yi24rncmpgBge4mLqHXfRjfIUtsIgh4RMG/3OixQew2INd4GuYJ/DogzCtt+G1hsQ5zbckOmJoIs8gg2AFZ5tGIXGjI/x+83x77F1Q4Lm34v8VnQoodp3bY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532008; c=relaxed/simple; bh=MZxpdQUH2WM18MmXTZCwsSq01qdcto9rE1WR/kLOhug=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gG0OpR9fXZINiMHJmZXqQroH8Pc00XAt9PrFGr5g/wauJ8MzZ0WR4ssL1ecInhuBcni4i/RUnJYG+jItcQc0ROC+/QOZyeJGYKaY5/tK7pFRp48jMqO4R9eSuU/OwdTAiGOC5m46kOPblfBFrr4SAJ0to8n088jaBa8qYVmIS6s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=MHwbPIqW; arc=none smtp.client-ip=209.85.128.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="MHwbPIqW" Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-49553515a8bso11737505e9.1 for ; Wed, 12 Aug 2026 03:53:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786532005; x=1787136805; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zdWsixD11lZF8ErXsHx7xiySMr3/DkdbqSRJhXboNQ4=; b=MHwbPIqWWGEoreaXlyWsT9IeekHpcQfSXlYC7F+tbo7b1SeaNrR42Ist5UHdcam9rR gb49u0EFBdAhTrp8NxIek+DIHcG4STl0nzXGFWWkDUxuWNbTJbMyoS+V9VoIuUhcbmve FdkwPkm8ibo+pRXE9cShZzxSzymM7gyKPTsx6g9LTASnWowIe9X4AnC3wfiRcZCv+Uok 3CN8AdehsbIA29YVQ7Ip8eq6SnqoWSd37MqE7yzBj3ZMu+mKZjr0oAfnr6s1Q1cvTXRy WrsFMAdSMomXyGvzWf5DSkpW571MfVoIb7nNFM3WqoS+XZo1ycaVwB2FUZSrg0cGWwEm TPBQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786532005; x=1787136805; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=zdWsixD11lZF8ErXsHx7xiySMr3/DkdbqSRJhXboNQ4=; b=lKO3wikw40MqEezE0YO27SgRO57XQxeZY1+6vngJXM/6TdggUPzMsggyIec0fLYI1B MJZ9vdcehy/McC94R6AsXae0NqtY0LkiA4hbh0cH0z/L0ZuUDE1IfU2/2e4ASOqR8W3s R7pUENNoFOJ5WSMUohSVp1GBLxW9yA+CWaDFuvTqIWOccb3J1lT09OzO8Ss6di+2Xtt3 Ms7/ZhdfYa4tMIfQCLWVSkmirVjUQdLbdaAhk2gz/YxtBFy3auAfvtG6lCZXrsO9XiWN DPtMC5tc6M2qCA+0FtMVxgaCCCT9nL881zqJz+8vMmK+VLx39HKJhOlK/Y/wwzzLiXYt F0rw== X-Forwarded-Encrypted: i=1; AHgh+RoXwGkCuiRV3yzYrvStRXYBG8p/9jKDuFurBQHsZgRqjfPZ3RImuKfSa35tGbCbRN53KSrpUHSuJinLYPY=@vger.kernel.org X-Gm-Message-State: AOJu0YxFbhusv07uCXQfTe3KE/a8KMvx4ToLbVQJwnphnR1MLlQ08Bz2 PaQx/SrsT5ipvl9j/bAZgLx8TrbT0bLplGtBZ9nmjCy1lMibYUS6Vpvk X-Gm-Gg: AR+sD12snR66UQePVzHfoKcqIXJgezlyOWYDptlDuHvX9TF5zaYk0elQyNJhVa9NjK3 wQpKiLh/kjDPg0MNBkbVAH3jeq7jB5cHBTJoAX6M3EhZkBRy/mZmOttHJ/DbeaxVZXedbAklkt5 RDiZmAckGiSdUXAo+s7eIbbaX4WJr/IAzcJ2SRIUlL+IPYBWQ0mIOYdePAhEYROBCSBPIYRiBDB VwcqRlaASz6H+/IV1q4CyoYC1hElwVfpY+xtvm8CXuYhYu2Fn1kPCyfoOPdiOs0BDHvwoymIByx wXLYqby50/0I+7PkqhT2r4ATyO8O2bj0uJc454wGWuYOg4mV2YpsWjz3ylVShoXU/BtaoHKjxY9 CbwzX1DJiT0cR3CN2JESddXb5chu5BnqWN1Zfav3+Lh50FAscpC5ZnzSBpM1Ry6dsngRi3gswnM pX3IWwLcdFgmtqJstTsfC6AmaGwLpA2Jr1VCPfcvH1e5thISoOOyQJGYJgGC/HGMGzdDg/AR+CD QdLq9U92pP0QGCxWnL/orqlJqwfEfM8JPwbTa5tB+8eWA00JPBmZxkGFnuPSZq7S8ykg60Xz7y6 /457ZAbwmfjaKcQHNf01ZnsCo3E6uCk7ft9uiLPnBLq0xuJu9Ok2qVjp6kiMTf2XvcdDkEIaO1y YqQPVA9t5Icj2CQ6xQ7f6RvyojSVHUWyhPdambcU4kO56vw== X-Received: by 2002:a05:600c:c178:b0:499:60bf:c6f7 with SMTP id 5b1f17b1804b1-4997c1487e9mr47992325e9.13.1786532004701; Wed, 12 Aug 2026 03:53:24 -0700 (PDT) Received: from localhost.localdomain (host-213-45-168-79.pool21345.interbusiness.it. [213.45.168.79]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4997c939574sm37352315e9.1.2026.08.12.03.53.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 03:53:24 -0700 (PDT) From: Nicola Fiorillo To: linux-media@vger.kernel.org Cc: mchehab@kernel.org, sakari.ailus@linux.intel.com, bingbu.cao@intel.com, tian.shu.qiu@intel.com, linux-kernel@vger.kernel.org, Nicola Fiorillo Subject: [PATCH 1/3] media: ipu6: Check the remote pad before dereferencing it Date: Wed, 12 Aug 2026 12:53:03 +0200 Message-ID: <20260812105305.32447-2-nicfio@gmail.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260812105305.32447-1-nicfio@gmail.com> References: <20260812105305.32447-1-nicfio@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Unbinding a sensor driver while a capture is running oopses the kernel: BUG: kernel NULL pointer dereference, address: 0000000000000020 RIP: 0010:ipu6_isys_csi2_disable_streams+0x3c/0x70 [intel_ipu6_isys] Call Trace: v4l2_subdev_disable_streams+0x1b7/0x370 [videodev] ipu6_isys_video_set_streaming+0x20f/0x930 [intel_ipu6_isys] stop_streaming+0x102/0x110 [intel_ipu6_isys] __vb2_queue_cancel+0x2a/0x2d0 [videobuf2_common] vb2_core_queue_release+0x22/0x80 [videobuf2_common] _vb2_fop_release+0x58/0xb0 [videobuf2_v4l2] v4l2_release+0xbd/0xd0 [videodev] __fput+0xde/0x2a0 media_pad_remote_pad_first() returns NULL once the sensor is gone and the link with it, but both the enable and the disable path dereference the result unconditionally. The faulting address is the offset of the entity member in struct media_pad. Check it. On enable there is nothing to stream from, so refuse with -ENOLINK. On disable the receiver still has to be stopped, so stop it and skip only the call towards the sensor that is no longer there. Reproduced on a CHUWI Hi10 X1 (Alder Lake-N, IPU6) running 6.12.86, with the CSI-2 port of a sensor being unbound mid capture. The code is unchanged in 7.2-rc7. Fixes: 3a5c59ad926b ("media: ipu6: Rework CSI-2 sub-device streaming contro= l") Signed-off-by: Nicola Fiorillo --- drivers/media/pci/intel/ipu6/ipu6-isys-csi2.c | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/drivers/media/pci/intel/ipu6/ipu6-isys-csi2.c b/drivers/media/= pci/intel/ipu6/ipu6-isys-csi2.c index 7e539a0c6..c00a82eb8 100644 --- a/drivers/media/pci/intel/ipu6/ipu6-isys-csi2.c +++ b/drivers/media/pci/intel/ipu6/ipu6-isys-csi2.c @@ -356,6 +356,9 @@ static int ipu6_isys_csi2_enable_streams(struct v4l2_su= bdev *sd, int ret; =20 remote_pad =3D media_pad_remote_pad_first(&sd->entity.pads[CSI2_PAD_SINK]= ); + if (!remote_pad) + return -ENOLINK; + remote_sd =3D media_entity_to_v4l2_subdev(remote_pad->entity); =20 sink_streams =3D @@ -392,10 +395,17 @@ static int ipu6_isys_csi2_disable_streams(struct v4l2= _subdev *sd, v4l2_subdev_state_xlate_streams(state, pad, CSI2_PAD_SINK, &streams_mask); =20 + ipu6_isys_csi2_set_stream(sd, NULL, 0, false); + + /* + * The link is gone if the sensor driver was unbound while streaming. + * Stop the receiver anyway, there is just no one left to tell. + */ remote_pad =3D media_pad_remote_pad_first(&sd->entity.pads[CSI2_PAD_SINK]= ); - remote_sd =3D media_entity_to_v4l2_subdev(remote_pad->entity); + if (!remote_pad) + return 0; =20 - ipu6_isys_csi2_set_stream(sd, NULL, 0, false); + remote_sd =3D media_entity_to_v4l2_subdev(remote_pad->entity); =20 v4l2_subdev_disable_streams(remote_sd, remote_pad->index, sink_streams); =20 --=20 2.47.3 From nobody Tue Sep 29 04:39:03 2026 Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EB8EC42BC31 for ; Wed, 12 Aug 2026 10:53:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532009; cv=none; b=J5pMc/sJFxqwg+WvEeQ7atXvAP86tXz/o18KcnnyXz7o2d+gxivWDJjZa0uXeI6eg5/mnheQt6D/4QDvILZoQdgFdXfJjqaetUeD5UMmpQFPaRJJebzFn2xgvEL7D6uBghuMHOLW6pg79BhBbHq4xhaBta9G37UTIvnE93/SMmQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532009; c=relaxed/simple; bh=Vk850nZ6nsG45RIDn4Sgo92jf2NilX70CluYj/q9p4w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=E7vOxL01El96qA3rEfv84ucJUHWvX2iarmP1+BhgdNvI65vEsRMWwCAy56nvGVaNReFUIlAGQ+y/llohWU0x/gZCZbW5Kvoi5xMhSX1nlwunaug0JZsPCpXVa8hBUiDCNMtt8TR3eJujesXHj8b37TkaJbMDqJvImEltF8JLhkU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=AnRUIUnS; arc=none smtp.client-ip=209.85.128.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="AnRUIUnS" Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-49556f97a9dso4505125e9.1 for ; Wed, 12 Aug 2026 03:53:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786532006; x=1787136806; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ZepWu022dhLaFNiqakPl4fWF3YzvM+iZ8Tl88qOlm90=; b=AnRUIUnScwNDqTYPhGdC20Y82gHBBRW7quVzN/sPjQkStkfvCseW3wNy8/9SJLIZNC a2EMWy8XsolgVgZvW9pR4rZl4RyHencHPH8yT8ybEvFZ+SzHfB8rUBAD5LfgU5YNqk3L eV5COANTYIkO3wawMiNJwk4pAf/T0ACnxwJdBZvTdHDchz6cS3mzn3Dc26hDxrS8l53S hQB3Spvcz9dDwLoHjedV92TU3yN3A3HD+VFVxgyuWYU5KuXDoWlJnS/ytDprH/dBuIqM AHzJ5f/FB+c/bLZbRYA798ZVzIZLjoBCGV7kpbdHShvxJl/XmzQN6hAIMi26opbCfKXL phbA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786532006; x=1787136806; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ZepWu022dhLaFNiqakPl4fWF3YzvM+iZ8Tl88qOlm90=; b=LEfaNlmqCXd3UIENHMqBZBVFYhUv+20857yv/lJIb35b8RqXjbQIDYgNnu7z7Afh3k SXiZaR5gQlB+QYdBeuUfalOZaBxx1rF1l8VRlgbdd5mMDojmdDX/wDISrIn3XX9fvRxc LfVAMoXLS72ZDv/7q3rgV3GncCf7NeWYXjbqrFiMML497p6wOzCryGOs8PRZqWk+3ktt u61RtsRRepLCJ6WH4FofruuBIfuimKXjPNPfQXLRDLXpc5GpKuMIju6PXGgbIDjn6P1H TkEYfwXT8f0bwFe1j9lqPQHQDissWqw1Odw78iqOOfZJ+2fv9R0ZhIcWoTW3R5Wbbale /7SQ== X-Forwarded-Encrypted: i=1; AHgh+RrllmlW4WLSlhkv1ItG27lB2eOQzhW5ax0x1mTRTUjIwzGkL8FE2nRKgrGJO1ziFn9nrjMTHO6p5yWayAM=@vger.kernel.org X-Gm-Message-State: AOJu0YwONYYO8ERSO2Y8L6ZI+ehQ5DVZJLG57ru73CvVp3CHeNyYeikY J9GtlC4ft0BLAvEMm0+jSkQI1/VIt9G1h/NIPs4k0NBPeZU/udmPuqjS X-Gm-Gg: AR+sD13BX25bLMetFu3aDw6PbqlR73bGa3LKpJqi1XAma1PhYGAAupH57tjhlX7a3Vp 7zEw2WMaEVUaA4R2rGEvKRpMLLUAFptUZwuml1qDFhbrJ4krN8L3gTAwV6Sn7Ss7PQgG7PebMsy Mdsvi47DMle6ZiW8L/iTg6Scplm+REEGwfHEtz6bOCQoeblZ4HW2aqTWLzi47W2a/V8/ANRlKsw SdWCKCjVZG3FFsow5ZlPnQGkx0Jfx+hyE1YiB0i7/RlZ9Rnpjmjun8zQgW31OSnufBM7z29G+xC bS38i0MNA80XLptq2bVfpneeqJrh5ghdXjucaGKVe97rSp3k3gJWeQq6sRY/nHkS7CTgSQkFrK/ agKCIkgx/3Pg17cLDqXTrx03usmkKp1Bb7fu12G+hz0UkwVoFFfTLBIH04r0ErhFSD9pZWs9+/S QnonvODd+K/E1V1/rHkDV+Tn+6etf2G9+ct9UUwhEZ51x7SQ8gQ9Uth96V1ErcjoV7ODhmjD9B4 IFfaO4+91ZKIWkUhqxNcSVUJE2kvEHunvCTQ4Cl5mmTXMoupEFWqMvhDCGT9guCY1CHb2TfAJ2/ qFvn/XYawFM5FcQ5rvS4aUf5+1+ZjwTHJy9sSXXa9DxMbZfHPkRtvZj4lRbHzC3jHgSUH5n6Nrg sSQcKX884aIteD2wZs1Jim/nMibVhHjYGcbvysdyLuoJVPQ== X-Received: by 2002:a05:600c:4e90:b0:495:6a50:3fb8 with SMTP id 5b1f17b1804b1-4997c0e3721mr41283045e9.1.1786532005885; Wed, 12 Aug 2026 03:53:25 -0700 (PDT) Received: from localhost.localdomain (host-213-45-168-79.pool21345.interbusiness.it. [213.45.168.79]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4997c939574sm37352315e9.1.2026.08.12.03.53.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 03:53:25 -0700 (PDT) From: Nicola Fiorillo To: linux-media@vger.kernel.org Cc: mchehab@kernel.org, sakari.ailus@linux.intel.com, bingbu.cao@intel.com, tian.shu.qiu@intel.com, linux-kernel@vger.kernel.org, Nicola Fiorillo Subject: [PATCH 2/3] media: v4l2-subdev: Check v4l2_dev before dereferencing it in open() Date: Wed, 12 Aug 2026 12:53:04 +0200 Message-ID: <20260812105305.32447-3-nicfio@gmail.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260812105305.32447-1-nicfio@gmail.com> References: <20260812105305.32447-1-nicfio@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Unbinding a sensor driver while something opens its /dev/v4l-subdevN node oopses the kernel: BUG: kernel NULL pointer dereference, address: 0000000000000008 RIP: 0010:subdev_open+0x8a/0x190 [videodev] Call Trace: v4l2_open+0xa9/0x100 [videodev] chrdev_open+0xb2/0x230 do_dentry_open+0x14c/0x440 vfs_open+0x2e/0xe0 path_openat+0x82e/0x12d0 do_filp_open+0xc4/0x170 do_sys_openat2+0xae/0xe0 __x64_sys_openat+0x55/0xa0 v4l2_device_unregister_subdev() clears sd->v4l2_dev, then unregisters the media entity, and only then unregisters the device node. Until the node is gone userspace can still open it, and subdev_open() dereferences sd->v4l2_dev unconditionally. The faulting address is the offset of the mdev member in struct v4l2_device. The window is not a narrow one: media_device_unregister_entity() sleeps, and the first oops seen here was not provoked at all, it was hit by v4l_id, run by udev on the very node that was appearing and disappearing. The same window leaves sd->entity.graph_obj.mdev NULL while sd->v4l2_dev->mdev is not, and the second dereference on that line goes through it. That one was found by reading the teardown path, not by crashing on it; it arrived later, with commit 218bf10e39ed ("media: v4l2-subdev: handle module refcounting here"). Unregistering the device node before clearing the pointers would narrow the window but not close it, because v4l2_open() drops videodev_lock before it calls fops->open() and the whole of v4l2_device_unregister_subdev() can run in between. Check the pointers in subdev_open() instead. Reproduced on a CHUWI Hi10 X1 (Alder Lake-N, IPU6) running 6.12.86, at cycle 7 of a loop unbinding and rebinding a sensor while four processes opened every /dev/v4l-subdev*. The code is unchanged in 7.2-rc7. Fixes: 61f5db549dde ("[media] v4l: Make v4l2_subdev inherit from media_enti= ty") Signed-off-by: Nicola Fiorillo --- drivers/media/v4l2-core/v4l2-subdev.c | 31 +++++++++++++++++++++------ 1 file changed, 25 insertions(+), 6 deletions(-) diff --git a/drivers/media/v4l2-core/v4l2-subdev.c b/drivers/media/v4l2-cor= e/v4l2-subdev.c index e9f81b9be..2a47b9730 100644 --- a/drivers/media/v4l2-core/v4l2-subdev.c +++ b/drivers/media/v4l2-core/v4l2-subdev.c @@ -97,8 +97,19 @@ static int subdev_open(struct file *file) struct video_device *vdev =3D video_devdata(file); struct v4l2_subdev *sd =3D vdev_to_v4l2_subdev(vdev); struct v4l2_subdev_fh *subdev_fh; + struct v4l2_device *v4l2_dev; int ret; =20 + /* + * v4l2_device_unregister_subdev() clears sd->v4l2_dev and unregisters + * the entity before it unregisters the device node, so an open() that + * races with the sub-device going away lands here with those pointers + * already gone. + */ + v4l2_dev =3D READ_ONCE(sd->v4l2_dev); + if (!v4l2_dev) + return -ENODEV; + subdev_fh =3D kzalloc_obj(*subdev_fh); if (subdev_fh =3D=3D NULL) return -ENOMEM; @@ -112,15 +123,23 @@ static int subdev_open(struct file *file) v4l2_fh_init(&subdev_fh->vfh, vdev); v4l2_fh_add(&subdev_fh->vfh, file); =20 - if (sd->v4l2_dev->mdev && sd->entity.graph_obj.mdev->dev) { - struct module *owner; + if (v4l2_dev->mdev) { + struct media_device *mdev =3D READ_ONCE(sd->entity.graph_obj.mdev); =20 - owner =3D sd->entity.graph_obj.mdev->dev->driver->owner; - if (!try_module_get(owner)) { - ret =3D -EBUSY; + if (!mdev) { + ret =3D -ENODEV; goto err; } - subdev_fh->owner =3D owner; + + if (mdev->dev) { + struct module *owner =3D mdev->dev->driver->owner; + + if (!try_module_get(owner)) { + ret =3D -EBUSY; + goto err; + } + subdev_fh->owner =3D owner; + } } =20 if (sd->internal_ops && sd->internal_ops->open) { --=20 2.47.3 From nobody Tue Sep 29 04:39:03 2026 Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DB8CD42C4FF for ; Wed, 12 Aug 2026 10:53:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532010; cv=none; b=EoGlPslmMQimI7vlvVggnJg3qZ8TWewHmOFdAgJ8KnHUlSLYuMOh+4PoxvAif3pHVo2tWgSLWtkplQvOVK+PBDTyyzryj4TVp5EgGJ0krS+dbeHTzrCuVrtvXLVAOR+JbPbmKM/V0Py8OLqcwmblN44sGJ1fudXTzN9bpzRKrlk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532010; c=relaxed/simple; bh=3U8yTqWdcMedAAD5xD43DIh+6Q0rTvKIilQ/8WcxKkU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Pv7IXODHXQWvoO5O8pWs0yoZgTOaIKVyC0+i/aBcR1a21/nKnqhvTYzolkGg7j5cLZe+qwc09c/yor23ZtPw3pLuReyMDVlAglOJCBLaNMLRSbJoTnN20xI4bZ1XugRvr4rmDatUWKOtH+30dywq/QngQNoBORmikXzQXvGMI4A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=PCBlv+S5; arc=none smtp.client-ip=209.85.128.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="PCBlv+S5" Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-4954a2e73a9so4155075e9.3 for ; Wed, 12 Aug 2026 03:53:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786532007; x=1787136807; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5jgs5U43ai39YOGkWm4gKlSWagxfcI4VO/2d/d10obI=; b=PCBlv+S5FOSLRU5xEEOaFkB0btHalZykHD1VvV2qoYkPxoGFBPqU0iuHHFgxuVH2mp ZqM7lAGjCSJrCBu6XHLaiFgGLZtn8ky0WAB71WFNR5kbymzJ8Eh/UfWoVNA+u1JY8uc+ A5mhNBrDeO6SwqNU3S7aCwnt1fbcxBNK+1kLMIV82LVzM+zFg5c67cFwEy4La8tdAsiE YojGxzeErnnhIkrlT4aIl4uG/aWOpOdBc1jPJniTvTmgvD5Z+Sv33H78gw7ODkroC2n9 Jr74W2K9vzpJhp1dAXlUyfCiI/NTYfMgrjgLr1z/Wg5Du2yqMj9GOLMvQqqxP31iOqaN lBNA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786532007; x=1787136807; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=5jgs5U43ai39YOGkWm4gKlSWagxfcI4VO/2d/d10obI=; b=DQYP+Zfrj+lNOWdC/mNG6bViufhVqEt0IwA2b/q6NBY4Lj8/57VCJ8GkJnWbb6Gxas 7ObJiAyi3Hw58etihz+NeAhKN3sqHXfonISmVH2fXGkvOJyR0psrRMc0aqsdMG18WfA9 W+Dbb5q4YZk6mj4cNDw+q5sx1ZptVjuIJhkNAYzvPPeMyu/GZ9at0UQke8mSHudzBs/Z yfKvSyUMsXBfm56hnVpzz90y+t7upN9vdpOXXixVuMD2neBK050PKfdq6l+551jYPY2c atN6WTG6ce9LHnNU/vCgo2DotC42UUcRMCQYDg7l637qdD9ph0mASYj4z42qqeQxFSiP lj0A== X-Forwarded-Encrypted: i=1; AHgh+RpDepXrEzdN+Gt/GGT5tGBK4UUKGFYrAUen+RVbwxBDaiLLSkBS1rxU5PJso7RRwSQkRnCJeDkQTjxs97M=@vger.kernel.org X-Gm-Message-State: AOJu0YxwUxB3tky8G4E3Wb2MRgW9uQWUTEqlPMlrVW9qb/ESkRt9x9sk upZaaQ2TiGpJNhFYzngHvu5qw1TAzaPMZoSe9W1ui+OHX2lbRoo5iKnR X-Gm-Gg: AR+sD10QHyV2oUa+wDV5bKNB6pwrZw+XHUO+E7Gl1em3KD/EfbMNO9LjlMaq+EELZJZ egUaWgnXc3L4zehTWWgAK5CXKROh1G0ZbU7EPnSAeH4SogC12mvmlI+l5tcIZH1j3g6leQ5uiGm xNeRfb1b7tQ4nU/FGfwbTfzaf1XcKGX48oejBs92amOky6D/gV1SX6di8iP4j/WdBccJkzuuRRT E3X9CzC49tDrF5uJWmUlCmS/kEO0KCM+zOuesMdOXZ6GwNI5tkpMeRoPVxZl2CNMujLYwQh7+mL Tn+vBWtwaArNEVs0v3sYjSUZd0zSbUoNReNicn8iGZY2wBBWOBezPwSu4VWWueh9MQfmHEWl6vT LSkc+mShiKQrwYEjwdPguTdZ44okQ2uxHlTIxACNsn8VQMIiFItBZZmXCome+rd3kd4NT9ndb45 pU37CAd8u7brcBS4AnkOpUF65g8HXq8yeUeORrfCw7nKuIe71ZPa2t9ihEIHjB0CtOZeTu5ARj+ 2TSydEaKPpnf4TSYK0Hj1Ioj/4h5AXWMcmP/PU60//ljSj2flXXKltQwQLz1Q9pUU0uEZoDv3aF Uu3KGiRvEJ95Bc3zSv3CkQg43nXrVa1OUuFNfQnNLGMuvyfrLRgtV5M10HiP+vAYHoimDyAev3E nJjWqmwSQWwtDwTWhzvs/sqkJUo3ZUpJdYh3I1rt8Tbwb4w== X-Received: by 2002:a05:600c:8209:b0:496:bbce:fc with SMTP id 5b1f17b1804b1-4997c126dbemr59720255e9.12.1786532007084; Wed, 12 Aug 2026 03:53:27 -0700 (PDT) Received: from localhost.localdomain (host-213-45-168-79.pool21345.interbusiness.it. [213.45.168.79]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4997c939574sm37352315e9.1.2026.08.12.03.53.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 03:53:26 -0700 (PDT) From: Nicola Fiorillo To: linux-media@vger.kernel.org Cc: mchehab@kernel.org, sakari.ailus@linux.intel.com, bingbu.cao@intel.com, tian.shu.qiu@intel.com, linux-kernel@vger.kernel.org, Nicola Fiorillo Subject: [PATCH 3/3] media: ipu6: Signal the video queues when a sensor is unbound Date: Wed, 12 Aug 2026 12:53:05 +0200 Message-ID: <20260812105305.32447-4-nicfio@gmail.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260812105305.32447-1-nicfio@gmail.com> References: <20260812105305.32447-1-nicfio@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" isys_async_ops implements .bound() and .complete() but not .unbind(), so nothing tells the ISYS video nodes that the sensor feeding them has gone away. A capture that is streaming when the sensor is unbound stays blocked in vb2_core_dqbuf() forever, waiting for a frame that can no longer arrive: [<0>] vb2_core_dqbuf+0x362/0x1190 [videobuf2_common] [<0>] vb2_dqbuf+0xb4/0x210 [videobuf2_v4l2] [<0>] __video_do_ioctl+0x894/0xb30 [<0>] video_usercopy+0x479/0xde0 [<0>] v4l2_ioctl+0x198/0x220 [<0>] __x64_sys_ioctl+0x134/0x1c0 The wait in __vb2_wait_for_done_vb() ends on a new buffer, on !q->streaming, or on q->error. Tearing the sensor down sets none of the three. The sleep is interruptible, so DETECT_HUNG_TASK stays quiet as well and the process is simply stuck until something kills it. Add the missing .unbind() and mark the queues of the CSI-2 receiver the departing sensor was attached to, which is enough for DQBUF to return -EIO. Only streaming queues are flagged: q->error is cleared by __vb2_queue_cancel(), so flagging an idle queue would leave it in error until the next VIDIOC_STREAMOFF. Reproduced on a CHUWI Hi10 X1 (Alder Lake-N, IPU6) by unbinding the sensor while v4l2-ctl was streaming, with both sensors of the machine. Without this patch 3 attempts out of 3 hang; with it, 10 out of 10 wake up, report "VIDIOC_DQBUF: failed: Input/output error" and exit. The same run under KASAN reports nothing. Fixes: f50c4ca0a820 ("media: intel/ipu6: add the main input system driver") Signed-off-by: Nicola Fiorillo --- drivers/media/pci/intel/ipu6/ipu6-isys.c | 41 ++++++++++++++++++++++++ 1 file changed, 41 insertions(+) diff --git a/drivers/media/pci/intel/ipu6/ipu6-isys.c b/drivers/media/pci/i= ntel/ipu6/ipu6-isys.c index c9cdeb705..8055ae169 100644 --- a/drivers/media/pci/intel/ipu6/ipu6-isys.c +++ b/drivers/media/pci/intel/ipu6/ipu6-isys.c @@ -31,6 +31,7 @@ #include #include #include +#include =20 #include "ipu6-bus.h" #include "ipu6-cpd.h" @@ -700,6 +701,45 @@ static int isys_notifier_bound(struct v4l2_async_notif= ier *notifier, return v4l2_device_register_subdev_nodes(&isys->v4l2_dev); } =20 +/* The .unbind() notifier callback when a sub-device goes away */ +static void isys_notifier_unbind(struct v4l2_async_notifier *notifier, + struct v4l2_subdev *sd, + struct v4l2_async_connection *asc) +{ + struct ipu6_isys *isys =3D + container_of(notifier, struct ipu6_isys, notifier); + struct sensor_async_sd *s_asd =3D + container_of(asc, struct sensor_async_sd, asc); + struct ipu6_isys_csi2 *csi2; + unsigned int i; + + if (s_asd->csi2.port >=3D isys->pdata->ipdata->csi2.nports) + return; + + /* + * The sensor is gone, so no more frames will ever arrive on the video + * nodes fed by it. Tell videobuf2, or a DQBUF already blocked in + * vb2_core_dqbuf() would sleep forever: nothing else in the teardown + * path wakes that queue up. + * + * Only queues that are actually streaming are marked. The error flag + * is only cleared by __vb2_queue_cancel(), so flagging an idle queue + * would leave it poisoned until the next STREAMOFF. + */ + csi2 =3D &isys->csi2[s_asd->csi2.port]; + for (i =3D 0; i < NR_OF_CSI2_SRC_PADS; i++) { + struct vb2_queue *q =3D &csi2->av[i].aq.vbq; + + if (!vb2_is_streaming(q)) + continue; + + dev_dbg(&isys->adev->auxdev.dev, + "%s went away while streaming on %s\n", sd->name, + csi2->av[i].vdev.name); + vb2_queue_error(q); + } +} + static int isys_notifier_complete(struct v4l2_async_notifier *notifier) { struct ipu6_isys *isys =3D @@ -710,6 +750,7 @@ static int isys_notifier_complete(struct v4l2_async_not= ifier *notifier) =20 static const struct v4l2_async_notifier_operations isys_async_ops =3D { .bound =3D isys_notifier_bound, + .unbind =3D isys_notifier_unbind, .complete =3D isys_notifier_complete, }; =20 --=20 2.47.3