From: sashiko-bot@kernel.org
To: "Armandas Kvietkus" <armandas.kvietkus@proton.me>
Cc: devicetree@vger.kernel.org, robh@kernel.org,
media-ci@linuxtv.org, conor+dt@kernel.org
Subject: Re: [PATCH 2/2] media: i2c: Add Samsung S5K3T2 image sensor driver
Date: Sun, 20 Sep 2026 15:10:46 +0000 [thread overview]
Message-ID: <20260920151046.B3EBD1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260920-upstream-s5k3t2-v1-2-d640740f4013@proton.me>
Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:
- [High] media: s5k3t2: stale mode pointer used in synchronous control updates
- [High] pm: pm_runtime_get_if_active() error bypassed causing usage count unbalance
- [Medium] media: v4l2: format not updated when layout-modifying controls change
- [Low] pm: unconditionally assigned dev_pm_ops causes dead code
--
commit 4a653d96a1e95b8288d1057ab3b4c96de4ec5282
Author: Armandas Kvietkus <armandas.kvietkus@proton.me>
Subject: media: i2c: Add Samsung S5K3T2 image sensor driver
Add a driver for the Samsung S5K3T2 20 Mpixel CMOS image sensor. This
driver supports three RAW10 modes over four D-PHY lanes. The pixel clock
remains constant, while runtime PM manages power through autosuspend.
> diff --git a/drivers/media/i2c/s5k3t2.c b/drivers/media/i2c/s5k3t2.c
> new file mode 100644
> index 0000000000000..4ca44d86d2638
> --- /dev/null
> +++ b/drivers/media/i2c/s5k3t2.c
[ ... ]
> +static int s5k3t2_set_ctrl(struct v4l2_ctrl *ctrl)
> +{
> + struct s5k3t2 *s5k3t2 = container_of(ctrl->handler, struct s5k3t2,
> + ctrl_handler);
> + const struct s5k3t2_mode *mode = s5k3t2->mode;
> + s64 exposure_max;
> + int ret;
> +
> + switch (ctrl->id) {
> + case V4L2_CID_HFLIP:
> + case V4L2_CID_VFLIP:
> + case V4L2_CID_LINK_FREQ:
> + case V4L2_CID_PIXEL_RATE:
> + case V4L2_CID_HBLANK:
> + return 0;
[Severity: Medium]
Can a user query a stale bus format code after layout-modifying controls
(like flips) are changed?
The driver correctly sets V4L2_CTRL_FLAG_MODIFY_LAYOUT in
s5k3t2_init_controls(), but this function returns 0 without updating the
active subdevice state using v4l2_subdev_get_locked_active_state().
> + case V4L2_CID_VBLANK:
> + exposure_max = mode->height + ctrl->val - S5K3T2_EXPOSURE_MARGIN;
> + __v4l2_ctrl_modify_range(s5k3t2->exposure,
> + s5k3t2->exposure->minimum,
> + exposure_max,
> + s5k3t2->exposure->step,
> + s5k3t2->exposure->default_value);
> + break;
> + }
> +
> + if (!pm_runtime_get_if_active(s5k3t2->dev))
> + return 0;
[Severity: High]
Does this bypass negative error returns from pm_runtime_get_if_active()?
If pm_runtime_get_if_active() returns a negative error (for example, -EINVAL
when Runtime PM is disabled), this negation evaluates to false.
This allows execution to proceed with I2C hardware accesses and eventually
reaches an unbalanced pm_runtime_put(). Callers must check if the return
value is <= 0.
[ ... ]
> +static int s5k3t2_set_pad_format(struct v4l2_subdev *sd,
> + struct v4l2_subdev_state *state,
> + struct v4l2_subdev_format *fmt)
> +{
[ ... ]
> + exposure_max = mode->vts - S5K3T2_EXPOSURE_MARGIN;
> + __v4l2_ctrl_modify_range(s5k3t2->exposure, S5K3T2_EXPOSURE_MIN,
> + exposure_max, S5K3T2_EXPOSURE_STEP,
> + mode->exposure);
> + __v4l2_ctrl_s_ctrl(s5k3t2->exposure, mode->exposure);
> +
> + if (s5k3t2->sd.ctrl_handler->error)
> + return s5k3t2->sd.ctrl_handler->error;
> +
> + s5k3t2->mode = mode;
[Severity: High]
Does this sequence trigger synchronous control updates via
__v4l2_ctrl_s_ctrl() before the s5k3t2->mode pointer is updated?
When VIDIOC_SUBDEV_S_FMT changes the resolution, the control updates are
dispatched while s5k3t2->mode still points to the old active mode.
In s5k3t2_set_ctrl(), this causes the handler to read the old mode->height
and apply it with the new vblank to the hardware VTS register:
case V4L2_CID_VBLANK:
ret = cci_write(s5k3t2->regmap, S5K3T2_REG_VTS,
ctrl->val + mode->height, NULL);
break;
This misconfigures the frame's vertical total size.
[ ... ]
> +static struct i2c_driver s5k3t2_i2c_driver = {
> + .driver = {
> + .name = "s5k3t2",
> + .pm = &s5k3t2_pm_ops,
[Severity: Low]
Is this unconditionally assigned dev_pm_ops structure preventing dead code
elimination when CONFIG_PM is disabled?
The PM subsystem guide mandates that dev_pm_ops assignments use pm_ptr()
to ensure unused functions are discarded.
> + .of_match_table = s5k3t2_of_match,
> + },
> + .probe = s5k3t2_probe,
> + .remove = s5k3t2_remove,
> +};
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260920-upstream-s5k3t2-v1-0-d640740f4013@proton.me?part=2
prev parent reply other threads:[~2026-09-20 15:10 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-20 14:58 [PATCH 0/2] media: i2c: Samsung S5K3T2 image sensor Armandas Kvietkus via B4 Relay
2026-09-20 14:58 ` [PATCH 1/2] dt-bindings: media: i2c: Add " Armandas Kvietkus via B4 Relay
2026-09-20 14:58 ` [PATCH 2/2] media: i2c: Add Samsung S5K3T2 image sensor driver Armandas Kvietkus via B4 Relay
2026-09-20 15:10 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260920151046.B3EBD1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=armandas.kvietkus@proton.me \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=media-ci@linuxtv.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox