All of lore.kernel.org
 help / color / mirror / Atom feed
From: Nicola Fiorillo <nicfio@gmail.com>
To: Sakari Ailus <sakari.ailus@linux.intel.com>
Cc: linux-media@vger.kernel.org, mchehab@kernel.org,
	hverkuil@kernel.org, antti.laakso@linux.intel.com,
	linux-kernel@vger.kernel.org, nicfio@gmail.com
Subject: Re: [PATCH v2 0/3] media: Two oopses and a hang when unbinding a streaming sensor
Date: Thu, 01 Oct 2026 19:27:42 +0200	[thread overview]
Message-ID: <179087566277.2226896.14093541499965645@gmail.com> (raw)
In-Reply-To: <178921203630.98144.13238972861597227362@gmail.com>

Hi Sakari,

On 18 September you mentioned you would reply to the framework patch
(2/3 of this series) separately. Before you spend time on it: I have
reworked it, and I would rather you look at the new version than at
this one.

The v2 patch only checked the two pointers in subdev_open(), which
narrows the race but does not close it. The rework stops reading the
sub-device's registration state in the file operations altogether and
uses the node's own vdev->v4l2_dev, which unregistration never clears.
Reading the code further, the same sd->v4l2_dev dereference is also in
the EXT_CTRLS ioctls, so it is now a two-patch series touching only
v4l2-subdev.c.

I tested it in QEMU with KASAN and vimc, unbinding and rebinding vimc
in a loop while 16 threads open the sub-device nodes or issue EXT_CTRLS
ioctls. On media next every run oopsed in subdev_open(); with the first
patch only, every EXT_CTRLS run oopsed in subdev_do_ioctl(); with both,
there was no oops or KASAN report at all. It does not address the
lifetime limitation you described on v2, and the commit messages say
so.

Shall I post it as v3, or would you prefer to comment on the v2 patch
first?

Thanks,
Nicola

      reply	other threads:[~2026-10-01 17:27 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-11 19:48 [PATCH v2 0/3] media: Two oopses and a hang when unbinding a streaming sensor Nicola Fiorillo
2026-09-11 19:48 ` [PATCH v2 1/3] media: ipu6: Check the remote pad before dereferencing it Nicola Fiorillo
2026-09-11 19:48 ` [PATCH v2 2/3] media: v4l2-subdev: Check v4l2_dev before dereferencing it in open() Nicola Fiorillo
2026-09-11 19:48 ` [PATCH v2 3/3] media: ipu6: Signal the video queues when a sensor is unbound Nicola Fiorillo
2026-09-12 10:23 ` [PATCH v2 0/3] media: Two oopses and a hang when unbinding a streaming sensor Sakari Ailus
2026-09-12 11:20   ` Nicola Fiorillo
2026-10-01 17:27     ` Nicola Fiorillo [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=179087566277.2226896.14093541499965645@gmail.com \
    --to=nicfio@gmail.com \
    --cc=antti.laakso@linux.intel.com \
    --cc=hverkuil@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-media@vger.kernel.org \
    --cc=mchehab@kernel.org \
    --cc=sakari.ailus@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.