Linux kernel and device drivers for NXP i.MX platforms
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Xu Yang" <xu.yang_2@oss.nxp.com>
Cc: Frank.Li@kernel.org, imx@lists.linux.dev
Subject: Re: [PATCH v2 1/2] usb: gadget: uvc: replace mutex lock/unlock with scoped_guard in uvc_function_bind()
Date: Wed, 23 Sep 2026 10:45:02 +0000	[thread overview]
Message-ID: <20260923104502.7AAD41F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260923-usb-uvc-fixes-v2-1-844e04a4a4b7@nxp.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] usb: uvc: architectural violation by mixing goto with scoped_guard cleanup
--

commit 7b1d83604fdc69bbda123c4e57da835730d015cb
Author: Xu Yang <xu.yang_2@nxp.com>

usb: gadget: uvc: replace mutex lock/unlock with scoped_guard in uvc_function_bind()

This patch replaces manual mutex locking and unlocking with scoped_guard()
to resolve a label fallthrough bug on failure paths.

> diff --git a/drivers/usb/gadget/function/f_uvc.c b/drivers/usb/gadget/function/f_uvc.c
> index d1bf3ea751973..a4fb2790f4ffe 100644
> --- a/drivers/usb/gadget/function/f_uvc.c
> +++ b/drivers/usb/gadget/function/f_uvc.c
[ ... ]
> @@ -809,50 +803,50 @@ uvc_function_bind(struct usb_configuration *c, struct usb_function *f)
[ ... ]
>  	/* Copy descriptors */
> -	f->fs_descriptors = uvc_copy_descriptors(uvc, USB_SPEED_FULL);
> -	if (IS_ERR(f->fs_descriptors)) {
> -		ret = PTR_ERR(f->fs_descriptors);
> -		f->fs_descriptors = NULL;
> -		goto error_unlock;
> -	}
> +	scoped_guard(mutex, &opts->lock) {
> +		f->fs_descriptors = uvc_copy_descriptors(uvc, USB_SPEED_FULL);
> +		if (IS_ERR(f->fs_descriptors)) {
> +			ret = PTR_ERR(f->fs_descriptors);
> +			f->fs_descriptors = NULL;
> +			goto error;
> +		}

[Severity: Low]
Does this code violate the kernel cleanup subsystem guidelines?

The documentation in include/linux/cleanup.h explicitly states that usage
of "goto" and scope-based cleanup helpers should never be mixed in the same
function to avoid confusing ownership semantics.

Here we jump out of the scoped_guard block to the legacy error label. While
this correctly releases the mutex lock and doesn't appear to cause a
functional issue, would it be better to convert the rest of the resources
in uvc_function_bind() to scope-based cleanup, or use manual locking if
goto error handling must be retained?

[ ... ]
> @@ -884,8 +878,6 @@ uvc_function_bind(struct usb_configuration *c, struct usb_function *f)
>  
>  	return 0;
>  
> -error_unlock:
> -	mutex_unlock(&opts->lock);
>  v4l2_error:
>  	v4l2_device_unregister(&uvc->v4l2_dev);
>  error:

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-usb-uvc-fixes-v2-0-844e04a4a4b7@nxp.com?part=1

  reply	other threads:[~2026-09-23 10:45 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 10:39 [PATCH v2 0/2] usb: gadget: uvc: fix resource leak on video->async_wq and video->kworker Xu Yang
2026-09-23 10:39 ` [PATCH v2 1/2] usb: gadget: uvc: replace mutex lock/unlock with scoped_guard in uvc_function_bind() Xu Yang
2026-09-23 10:45   ` sashiko-bot [this message]
2026-09-23 10:39 ` [PATCH v2 2/2] usb: gadget: uvc: refactor video cleanup into uvcg_video_deinit() Xu Yang
2026-09-23 10:51   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923104502.7AAD41F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=imx@lists.linux.dev \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=xu.yang_2@oss.nxp.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox