From: sashiko-bot@kernel.org
To: "Richard Leitner" <richard.leitner@linux.dev>
Cc: robh@kernel.org, devicetree@vger.kernel.org, conor+dt@kernel.org,
media-ci@linuxtv.org
Subject: Re: [PATCH 3/3] media: i2c: vc-mipi: add Vision Components MIPI Module Controller
Date: Tue, 15 Sep 2026 20:30:55 +0000 [thread overview]
Message-ID: <20260915203055.EB1A01F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260915-vc-mipi-ctrl-v1-3-8a42b693d889@linux.dev>
Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:
- [High] clk: UAF window in OF clock provider during device removal
- [Medium] of: memory leak of device_node due to double-increment and missing cleanup
- [Medium] clk: memory leak of clk_hw on probe error path
- [Low] pm: unconditional assignment of PM callbacks violates dev_pm_ops guidelines
--
commit d0204937d4a594ae9bcc6ff943f4549e7368e364
Author: Richard Leitner <richard.leitner@linux.dev>
media: i2c: vc-mipi: add Vision Components MIPI Module Controller
This commit adds a driver for the camera module controller found in the Vision
Components MIPI modules. It manages power sequencing, provides a fixed clock
output, and acts as an I2C tunnel to the camera sensor.
> diff --git a/drivers/media/i2c/vc-mipi.c b/drivers/media/i2c/vc-mipi.c
> new file mode 100644
> index 0000000000000..1ca7f94c17d3c
> --- /dev/null
> +++ b/drivers/media/i2c/vc-mipi.c
> @@ -0,0 +1,541 @@
[ ... ]
> +static int vc_mipi_clk_init(struct vc_mipi_ctrl *ctrl)
> +{
[ ... ]
> + ctrl->clk_hw = clk_hw_register_fixed_rate(ctrl->dev, name, NULL, 0,
> + freq);
> + if (IS_ERR(ctrl->clk_hw))
> + return PTR_ERR(ctrl->clk_hw);
> +
> + ret = devm_of_clk_add_hw_provider(ctrl->dev, of_clk_hw_simple_get,
> + ctrl->clk_hw);
[Severity: High]
Does this create a use-after-free window during device removal?
The clock hardware is registered manually with clk_hw_register_fixed_rate(),
while the OF provider is registered here with devm_of_clk_add_hw_provider().
Later in vc_mipi_i2c_remove(), vc_mipi_clk_cleanup() synchronously
unregisters and frees ctrl->clk_hw. Because the OF provider is devm-managed,
it remains active until devres cleanup, which happens after remove() returns.
Could concurrent OF clock lookups return a dangling pointer to freed memory
during this window?
> + if (ret < 0) {
> + clk_hw_unregister_fixed_rate(ctrl->clk_hw);
> + return ret;
> + }
> +
> + return 0;
> +}
[ ... ]
> +static struct device_node *vc_mipi_i2c_find_tunnel_bus(struct device *dev)
> +{
> + struct device_node *child;
> +
> + for_each_child_of_node(dev->of_node, child) {
> + u32 addr_cells, size_cells;
> +
> + if (of_property_read_u32(child, "#address-cells", &addr_cells))
> + continue;
> + if (of_property_read_u32(child, "#size-cells", &size_cells))
> + continue;
> + if (addr_cells != 1 || size_cells != 0)
> + continue;
> +
> + return of_node_get(child);
[Severity: Medium]
Does returning of_node_get(child) here cause a memory leak of the device_node?
The for_each_child_of_node macro automatically acquires a reference to the
matched child node. Exiting the loop early with of_node_get(child) incorrectly
adds a second reference, leaking the iterator's implicit reference.
> + }
> +
> + return NULL;
> +}
> +
> +static int vc_mipi_i2c_tunnel_add(struct i2c_client *i2c)
> +{
> + struct vc_mipi_ctrl *ctrl = i2c_get_clientdata(i2c);
> + struct i2c_adapter *i2c_adapter = &ctrl->i2c_tunnel;
> + struct device_node *bus_node;
> +
> + bus_node = vc_mipi_i2c_find_tunnel_bus(ctrl->dev);
> + if (!bus_node)
> + return -EINVAL;
> +
> + strscpy(i2c_adapter->name, "vc-mipi-i2c", sizeof(i2c_adapter->name));
> + i2c_adapter->owner = THIS_MODULE;
> + i2c_adapter->algo = &vc_mipi_i2c_tunnel_algorithm;
> + i2c_adapter->quirks = &vc_mipi_i2c_tunnel_quirks;
> + i2c_adapter->dev.parent = ctrl->dev;
> + i2c_adapter->dev.of_node = bus_node;
[Severity: Medium]
Is there a missing of_node_put() for this reference?
The explicitly acquired reference is assigned to i2c_adapter->dev.of_node
here, but it appears to never be released via of_node_put() in
vc_mipi_i2c_tunnel_del() nor on the i2c_add_adapter() failure path.
Will this cause a permanent memory leak?
> +
> + i2c_set_adapdata(i2c_adapter, i2c);
> + return i2c_add_adapter(&ctrl->i2c_tunnel);
> +}
[ ... ]
> +static int vc_mipi_i2c_probe(struct i2c_client *i2c)
> +{
[ ... ]
> + ret = vc_mipi_clk_init(ctrl);
> + if (ret < 0) {
> + dev_err(ctrl->dev, "Failed to register clock\n");
> + goto err_power;
> + }
> +
> + /* Enable runtime PM and turn off the device. */
> + pm_runtime_set_active(ctrl->dev);
> + pm_runtime_get_noresume(ctrl->dev);
> + pm_runtime_enable(ctrl->dev);
> + pm_runtime_set_autosuspend_delay(ctrl->dev, 1000);
> + pm_runtime_use_autosuspend(ctrl->dev);
> + pm_runtime_mark_last_busy(ctrl->dev);
> + pm_runtime_put_autosuspend(ctrl->dev);
> +
> + /* As a last step create the proxied downstream I2C adapter */
> + ret = vc_mipi_i2c_tunnel_add(i2c);
> + if (ret < 0) {
> + dev_err(ctrl->dev, "Failed to register i2c tunnel adapter: %d\n", ret);
> + goto err_power;
> + }
> +
> + return 0;
> +
> +err_power:
> + vc_mipi_power_off(ctrl->dev);
> + return ret;
[Severity: Medium]
Does this error path leak the clk_hw memory?
If vc_mipi_i2c_tunnel_add() fails during probe, the code jumps to err_power.
The error handler only powers off the device but fails to call
vc_mipi_clk_cleanup(). This permanently leaks the clk_fixed_rate memory and
leaves it registered in the clock subsystem.
> +}
[ ... ]
> +static struct i2c_driver vc_mipi_driver = {
> + .driver = {
> + .name = "vc-mipi",
> + .of_match_table = vc_mipi_dt_ids,
> + .pm = &vc_mipi_pm_ops,
[Severity: Low]
Should this use the pm_ptr() macro?
Subsystem guidelines require using the pm_ptr() wrapper macro for dev_pm_ops
assignments. Failing to use pm_ptr() causes the pointer to remain even when
CONFIG_PM is disabled, leaving a dead struct reference and generating
unnecessary object code.
> + },
> + .probe = vc_mipi_i2c_probe,
> + .remove = vc_mipi_i2c_remove,
> +};
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260915-vc-mipi-ctrl-v1-0-8a42b693d889@linux.dev?part=3
prev parent reply other threads:[~2026-09-15 20:30 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 20:20 [PATCH 0/3] Add Vision Components MIPI Camera Module support Richard Leitner
2026-09-15 20:20 ` [PATCH 1/3] dt-bindings: vendor-prefixes: add Vision Components GmbH Richard Leitner
2026-09-15 20:27 ` sashiko-bot
2026-09-15 20:20 ` [PATCH 2/3] dt-bindings: media: i2c: Add vision-components,mipi-module-controller Richard Leitner
2026-09-15 20:27 ` sashiko-bot
2026-09-15 21:57 ` Rob Herring (Arm)
2026-09-16 7:00 ` Krzysztof Kozlowski
2026-09-16 7:33 ` Richard Leitner
2026-09-16 7:45 ` Laurent Pinchart
2026-09-16 8:30 ` Krzysztof Kozlowski
2026-09-16 8:35 ` Krzysztof Kozlowski
2026-09-16 9:01 ` Richard Leitner
2026-09-16 13:41 ` Krzysztof Kozlowski
2026-09-16 14:57 ` Richard Leitner
2026-09-17 6:30 ` Krzysztof Kozlowski
2026-09-17 8:46 ` Laurent Pinchart
2026-09-28 9:30 ` Richard Leitner
2026-09-16 16:52 ` Laurent Pinchart
2026-09-17 6:18 ` Krzysztof Kozlowski
2026-09-17 7:55 ` Richard Leitner
2026-09-17 8:08 ` Krzysztof Kozlowski
2026-09-17 8:19 ` Laurent Pinchart
2026-09-17 8:28 ` Krzysztof Kozlowski
2026-09-17 8:17 ` Laurent Pinchart
2026-09-15 20:20 ` [PATCH 3/3] media: i2c: vc-mipi: add Vision Components MIPI Module Controller Richard Leitner
2026-09-15 20:30 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260915203055.EB1A01F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=media-ci@linuxtv.org \
--cc=richard.leitner@linux.dev \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox