Linux Media Controller development
 help / color / mirror / Atom feed
From: Hans Verkuil <hverkuil+cisco@kernel.org>
To: linux-media@vger.kernel.org
Cc: Mauricio Faria de Oliveira <mfo@igalia.com>,
	Sakari Ailus <sakari.ailus@linux.intel.com>
Subject: [PATCHv4 1/6] media: core: v4l2-async.c: unreg subdev if asc_list is, empty
Date: Tue, 30 Jun 2026 12:02:53 +0200	[thread overview]
Message-ID: <05d38e6d-5f18-4d70-983b-1a28ddd22535@kernel.org> (raw)
In-Reply-To: <2cf4473a9c16d0715aa081e234bb36c70fefce3c.1782716154.git.hverkuil+cisco@kernel.org>

When my em28xx USB device that uses the i2c tvp5150 driver is
disconnected, it crashes.

The cause is that the tvp5150 i2c module uses v4l2_async, but
the em28xx driver does not since it predates v4l2_async.

In that corner case sd->asc_list is empty, so
v4l2_async_unregister_subdev() never calls v4l2_device_unregister_subdev().

Modify the code so that, if sd->asc_list is empty,
v4l2_device_unregister_subdev() is still called.

Fixes: 28a1295795d8 ("media: v4l: async: Allow multiple connections between entities")
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
---
Changes since v3:
- updated commit message
- added comment to the code

Note: I did not post the other patches in this series, those are unchanged.
---
 drivers/media/v4l2-core/v4l2-async.c | 15 ++++++++++++---
 1 file changed, 12 insertions(+), 3 deletions(-)

diff --git a/drivers/media/v4l2-core/v4l2-async.c b/drivers/media/v4l2-core/v4l2-async.c
index 888a2e213b08..f36d60e6ff41 100644
--- a/drivers/media/v4l2-core/v4l2-async.c
+++ b/drivers/media/v4l2-core/v4l2-async.c
@@ -898,9 +898,18 @@ void v4l2_async_unregister_subdev(struct v4l2_subdev *sd)
 	sd->subdev_notifier = NULL;

 	if (sd->asc_list.next) {
-		list_for_each_entry_safe(asc, asc_tmp, &sd->asc_list,
-					 asc_subdev_entry) {
-			v4l2_async_unbind_subdev_one(asc->notifier, asc);
+		if (list_empty(&sd->asc_list)) {
+			/*
+			 * If the sub-device was registered through other means
+			 * than v4l2-async, there are no async connections but
+			 * the sub-device may still well be registered.
+			 * Unregister it now.
+			 */
+			v4l2_device_unregister_subdev(sd);
+		} else {
+			list_for_each_entry_safe(asc, asc_tmp, &sd->asc_list,
+						 asc_subdev_entry)
+				v4l2_async_unbind_subdev_one(asc->notifier, asc);
 		}
 	}

-- 
2.53.0



  parent reply	other threads:[~2026-06-30 10:02 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-29  6:55 [PATCHv3 0/6] media: em28xx: fix lifecycle issues Hans Verkuil
2026-06-29  6:55 ` [PATCHv3 1/6] media: core: v4l2-async.c: unreg subdev if asc_list is empty Hans Verkuil
2026-06-30  7:58   ` Sakari Ailus
2026-06-30  8:32     ` Hans Verkuil
2026-06-30  8:45       ` Sakari Ailus
2026-06-30  9:38         ` Hans Verkuil
2026-06-30 10:02   ` Hans Verkuil [this message]
2026-06-30 10:13     ` [PATCHv4 1/6] media: core: v4l2-async.c: unreg subdev if asc_list is, empty Sakari Ailus
2026-06-30 12:52       ` Hans Verkuil
2026-06-29  6:55 ` [PATCHv3 2/6] media: em28xx: use v4l2_device release callback Hans Verkuil
2026-06-29  6:55 ` [PATCHv3 3/6] media: em28xx: drop 'users' field Hans Verkuil
2026-06-29  6:55 ` [PATCHv3 4/6] media: em28xx: use vb2_video_unregister_device Hans Verkuil
2026-06-29  6:55 ` [PATCHv3 5/6] media: em28xx: dev_info->pr_info since dev has been freed Hans Verkuil
2026-06-30 12:57   ` Sakari Ailus
2026-06-29  6:55 ` [PATCHv3 6/6] media: em28xx: requeue buffers if start_streaming fails Hans Verkuil

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=05d38e6d-5f18-4d70-983b-1a28ddd22535@kernel.org \
    --to=hverkuil+cisco@kernel.org \
    --cc=linux-media@vger.kernel.org \
    --cc=mfo@igalia.com \
    --cc=sakari.ailus@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox