[PATCH] media: v4l2-async: avoid deleting unlinked ASC entry on link error

raoxu posted 1 patch 1 month, 2 weeks ago
drivers/media/v4l2-core/v4l2-async.c | 1 -
1 file changed, 1 deletion(-)
[PATCH] media: v4l2-async: avoid deleting unlinked ASC entry on link error
Posted by raoxu 1 month, 2 weeks ago
From: Xu Rao <raoxu@uniontech.com>

v4l2_async_match_notify() creates ancillary media links before adding
asc->asc_subdev_entry to sd->asc_list.

If ancillary link creation fails, the function jumps to
err_call_unbind while asc_subdev_entry has not been linked yet. Async
connections are zero-allocated, so the list entry still has NULL next
and prev pointers on this path. Calling list_del() on it can therefore
dereference NULL instead of returning the original link creation error.

Do not delete asc_subdev_entry from err_call_unbind. There is no list
insertion to undo on this path; the bound callback and sub-device
registration are the operations that need to be rolled back.

Fixes: 28a1295795d8 ("media: v4l: async: Allow multiple connections between entities")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
---
 drivers/media/v4l2-core/v4l2-async.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/drivers/media/v4l2-core/v4l2-async.c b/drivers/media/v4l2-core/v4l2-async.c
index 888a2e213b08..0aa4265a6782 100644
--- a/drivers/media/v4l2-core/v4l2-async.c
+++ b/drivers/media/v4l2-core/v4l2-async.c
@@ -392,7 +392,6 @@ static int v4l2_async_match_notify(struct v4l2_async_notifier *notifier,

 err_call_unbind:
 	v4l2_async_nf_call_unbind(notifier, sd, asc);
-	list_del(&asc->asc_subdev_entry);

 err_unregister_subdev:
 	if (registered)
--
2.50.1
Re: [PATCH] media: v4l2-async: avoid deleting unlinked ASC entry on link error
Posted by Sakari Ailus 1 month, 2 weeks ago
Hi Rao,

On Mon, Aug 10, 2026 at 05:50:12PM +0800, raoxu wrote:
> From: Xu Rao <raoxu@uniontech.com>
> 
> v4l2_async_match_notify() creates ancillary media links before adding
> asc->asc_subdev_entry to sd->asc_list.
> 
> If ancillary link creation fails, the function jumps to
> err_call_unbind while asc_subdev_entry has not been linked yet. Async
> connections are zero-allocated, so the list entry still has NULL next
> and prev pointers on this path. Calling list_del() on it can therefore
> dereference NULL instead of returning the original link creation error.
> 
> Do not delete asc_subdev_entry from err_call_unbind. There is no list
> insertion to undo on this path; the bound callback and sub-device
> registration are the operations that need to be rolled back.
> 
> Fixes: 28a1295795d8 ("media: v4l: async: Allow multiple connections between entities")
> Cc: stable@vger.kernel.org
> Signed-off-by: Xu Rao <raoxu@uniontech.com>

Can you resend this, please? Somehow Patchwork didn't pick it up.

-- 
Regards,

Sakari Ailus
Re: [PATCH] media: v4l2-async: avoid deleting unlinked ASC entry on link error
Posted by Sakari Ailus 1 month, 2 weeks ago
On Tue, Aug 11, 2026 at 09:21:07AM +0300, Sakari Ailus wrote:
> Can you resend this, please? Somehow Patchwork didn't pick it up.

Please ignore. There was an issue with Message-Id coding I suppose.

-- 
Sakari Ailus