From: Shuah Khan <shuahkh@osg.samsung.com>
To: linux-media@vger.kernel.org, mchehab@osg.samsung.com,
linux-kernel@vger.kernel.org,
Shuah Khan <shuahkh@osg.samsung.com>
Subject: Re: [PATCH 3/3] drivers/media/media-device: fix double free bug in _unregister()
Date: Wed, 15 Jun 2016 15:50:47 -0600 [thread overview]
Message-ID: <5761CDB7.9020001@osg.samsung.com> (raw)
In-Reply-To: <20160615203753.GA30666@swift.blarg.de>
On 06/15/2016 02:37 PM, Max Kellermann wrote:
> On 2016/06/15 22:32, Shuah Khan <shuahkh@osg.samsung.com> wrote:
>> This change introduces memory leaks, since drivers are relying on
>> media_device_unregister() to free interfaces.
>
> This is what I thought, too, until I checked the code paths. Who adds
> entries to that list? Only media_gobj_create() does, and only when
> type==MEDIA_GRAPH_INTF_DEVNODE. That is called via
> media_interface_init(), via media_devnode_create().
>
> In the whole kernel, there are two calls to media_devnode_create():
> one in dvbdev.c and another one in v4l2-dev.c. Both callers take care
> for freeing their interface. Both would crash if somebody else would
> free it for them before they get a chance to do it. Which is the very
> thing my patch addresses.
>
> Did I miss something?
>
Yes media_devnode_create() creates the interfaces links and these links
are deleted by media_devnode_remove(). media_device_unregister() still
needs to delete the interfaces links. The reason for that is the API
dynalic use-case.
Drivers (other than dvb-core and v4l2-core) can create and delete media
devnode interfaces during run-time, hence media_devnode_remove() has to
call media_remove_intf_links(). However, driver isn't required to call
media_devnode_remove() and media-core can't enforce that. So it is safe
for media_device_unregister() to remove interface links if the list isn't
empty. If driver does delete them, media_device_unregister() has nothing
to do since the list is going to be empty.
So removing kfree() from media_device_unregister() isn't the correct
fix.
I don't see the stack trace for the double free error you are seeing? Could
it be that there is a driver problem in the order in which it is calling
media_device_unregister()?
thanks,
-- Shuah
next prev parent reply other threads:[~2016-06-15 21:50 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-06-15 20:15 [PATCH 1/3] drivers/media/dvb-core/en50221: use kref to manage struct dvb_ca_private Max Kellermann
2016-06-15 20:15 ` [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in _destroy() Max Kellermann
2016-06-16 16:24 ` Shuah Khan
2016-06-16 18:43 ` Max Kellermann
2016-06-16 18:55 ` Shuah Khan
2016-06-17 12:53 ` Sakari Ailus
2016-06-17 13:04 ` Max Kellermann
2016-06-15 20:15 ` [PATCH 3/3] drivers/media/media-device: fix double free bug in _unregister() Max Kellermann
2016-06-15 20:32 ` Shuah Khan
2016-06-15 20:37 ` Max Kellermann
2016-06-15 21:50 ` Shuah Khan [this message]
2016-06-16 9:29 ` Max Kellermann
2016-06-16 13:40 ` Shuah Khan
2016-06-16 16:06 ` [PATCH 1/3] drivers/media/dvb-core/en50221: use kref to manage struct dvb_ca_private Shuah Khan
2016-06-16 18:37 ` Max Kellermann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5761CDB7.9020001@osg.samsung.com \
--to=shuahkh@osg.samsung.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@osg.samsung.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.