From: sashiko-bot@kernel.org
To: "Wenmeng Liu" <wenmeng.liu@oss.qualcomm.com>
Cc: devicetree@vger.kernel.org, media-ci@linuxtv.org,
conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH v6 2/2] media: i2c: Add Samsung S5KJN5 image sensor driver
Date: Wed, 30 Sep 2026 08:23:37 +0000 [thread overview]
Message-ID: <20260930082337.A49931F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260930-sk5jn5-v6-2-517c9b34008a@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] pm: Refcount underflow in s5kjn5_s_ctrl() due to mishandled pm_runtime_get_if_active() error
- [Medium] media: i2c: s5kjn5: Incorrect clock and reset sequencing
--
commit 3459a342207994da314f1844556c8af1fbac48b5
Author: Wenmeng Liu <wenmeng.liu@oss.qualcomm.com>
media: i2c: Add Samsung S5KJN5 image sensor driver
Add a V4L2 sub-device driver for the Samsung S5KJN5, a 50 MP 10-bit
RAW MIPI CSI-2 image sensor.
> diff --git a/drivers/media/i2c/s5kjn5.c b/drivers/media/i2c/s5kjn5.c
> new file mode 100644
> --- /dev/null
> +++ b/drivers/media/i2c/s5kjn5.c
[ ... ]
> +static int s5kjn5_power_on(struct device *dev)
> +{
> + struct v4l2_subdev *sd = dev_get_drvdata(dev);
> + struct s5kjn5 *s5kjn5 = sd_to_s5kjn5(sd);
> + int ret;
> +
> + ret = regulator_bulk_enable(ARRAY_SIZE(s5kjn5_supply_names),
> + s5kjn5->supplies);
> + if (ret) {
> + dev_err(dev, "failed to enable regulators: %d\n", ret);
> + return ret;
> + }
> +
> + gpiod_set_value_cansleep(s5kjn5->reset_gpio, 0);
> + usleep_range(8000, 10000);
> +
> + ret = clk_prepare_enable(s5kjn5->inclk);
[Severity: Medium]
Does releasing the reset line before providing a stable clock put the
sensor in an indeterminate state? Many camera sensors require the clock
to be active before de-asserting reset to ensure a correct transition.
> + if (ret) {
> + dev_err(dev, "failed to enable clock: %d\n", ret);
> + gpiod_set_value_cansleep(s5kjn5->reset_gpio, 1);
> + regulator_bulk_disable(ARRAY_SIZE(s5kjn5_supply_names),
> + s5kjn5->supplies);
> + return ret;
> + }
> +
> + usleep_range(10000, 12000);
> +
> + return 0;
> +}
> +
> +static int s5kjn5_power_off(struct device *dev)
> +{
> + struct v4l2_subdev *sd = dev_get_drvdata(dev);
> + struct s5kjn5 *s5kjn5 = sd_to_s5kjn5(sd);
> +
> + clk_disable_unprepare(s5kjn5->inclk);
> + gpiod_set_value_cansleep(s5kjn5->reset_gpio, 1);
[Severity: Medium]
Could this also leave the hardware in a bad state? The clock is being
disabled here before the sensor is safely put back into reset.
> + regulator_bulk_disable(ARRAY_SIZE(s5kjn5_supply_names),
> + s5kjn5->supplies);
> +
> + return 0;
> +}
[ ... ]
> +static int s5kjn5_s_ctrl(struct v4l2_ctrl *ctrl)
> +{
> + struct s5kjn5 *s5kjn5 =
> + container_of(ctrl->handler, struct s5kjn5, ctrl_handler);
> + struct device *dev = s5kjn5->sd.dev;
> + const struct s5kjn5_mode *mode = &s5kjn5_modes[0];
> + u32 exposure_max;
> + int ret;
> +
> + if (ctrl->id == V4L2_CID_VBLANK) {
> + exposure_max = mode->height + ctrl->val - mode->exposure_margin;
> + ret = __v4l2_ctrl_modify_range(s5kjn5->exposure,
> + s5kjn5->exposure->minimum,
> + exposure_max,
> + s5kjn5->exposure->step,
> + s5kjn5->exposure->default_value);
> + if (ret)
> + return ret;
> + }
> +
> + if (!pm_runtime_get_if_active(dev))
> + return 0;
[Severity: High]
Can this lead to a reference count underflow if the device's runtime PM
is disabled?
If pm_runtime_get_if_active() returns a negative error code (like
-EINVAL), the boolean check evaluates to false, allowing execution to
continue down to the hardware access path.
> +
> + switch (ctrl->id) {
> + case V4L2_CID_EXPOSURE:
> + ret = cci_write(s5kjn5->regmap, S5KJN5_REG_EXPOSURE,
> + ctrl->val, NULL);
> + break;
[ ... ]
> + case V4L2_CID_TEST_PATTERN:
> + ret = cci_write(s5kjn5->regmap, S5KJN5_REG_TEST_PATTERN,
> + ctrl->val, NULL);
> + break;
> +
> + default:
> + ret = -EINVAL;
> + break;
> + }
> +
> + pm_runtime_put_autosuspend(dev);
[Severity: High]
Since the getter didn't actually increment the usage counter on a
negative error return, won't this put operation unconditionally
decrement it and trigger an underflow?
> +
> + return ret;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260930-sk5jn5-v6-0-517c9b34008a@oss.qualcomm.com?part=2
prev parent reply other threads:[~2026-09-30 8:23 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 8:08 [PATCH v6 0/2] media: i2c: Add Samsung S5KJN5 image sensor Wenmeng Liu
2026-09-30 8:08 ` [PATCH v6 1/2] dt-bindings: " Wenmeng Liu
2026-09-30 8:13 ` sashiko-bot
2026-09-30 8:08 ` [PATCH v6 2/2] media: i2c: Add Samsung S5KJN5 image sensor driver Wenmeng Liu
2026-09-30 8:23 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930082337.A49931F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=media-ci@linuxtv.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=wenmeng.liu@oss.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox