From: Sakari Ailus <sakari.ailus@linux.intel.com>
To: linux-media@vger.kernel.org
Cc: hans@jjverkuil.nl, laurent.pinchart@ideasonboard.com,
Prabhakar <prabhakar.csengg@gmail.com>,
"Kate Hsuan" <hpa@redhat.com>,
"Dave Stevenson" <dave.stevenson@raspberrypi.com>,
"Tommaso Merciai" <tomm.merciai@gmail.com>,
"Benjamin Mugnier" <benjamin.mugnier@foss.st.com>,
"Sylvain Petinot" <sylvain.petinot@foss.st.com>,
"Christophe JAILLET" <christophe.jaillet@wanadoo.fr>,
"Julien Massot" <julien.massot@collabora.com>,
"Naushir Patuck" <naush@raspberrypi.com>,
"Yan, Dongcheng" <dongcheng.yan@intel.com>,
"Stefan Klug" <stefan.klug@ideasonboard.com>,
"Mirela Rabulea" <mirela.rabulea@nxp.com>,
"André Apitzsch" <git@apitzsch.eu>,
"Heimir Thor Sverrisson" <heimir.sverrisson@gmail.com>,
"Kieran Bingham" <kieran.bingham@ideasonboard.com>,
"Mehdi Djait" <mehdi.djait@linux.intel.com>,
"Ricardo Ribalda Delgado" <ribalda@kernel.org>,
"Hans de Goede" <hansg@kernel.org>,
"Jacopo Mondi" <jacopo.mondi@ideasonboard.com>,
"Tomi Valkeinen" <tomi.valkeinen@ideasonboard.com>,
"David Plowman" <david.plowman@raspberrypi.com>,
"Yu, Ong Hock" <ong.hock.yu@intel.com>,
"Ng, Khai Wen" <khai.wen.ng@intel.com>,
"Jai Luthra" <jai.luthra@ideasonboard.com>,
"Rishikesh Donadkar" <r-donadkar@ti.com>,
"Mattijs Korpershoek" <mkorpershoek@kernel.org>,
"Antti Laakso" <antti.laakso@linux.intel.com>
Subject: [PATCH v8 11/13] media: mt9m001: Pass sub-device state to set_selection() callback
Date: Mon, 14 Sep 2026 14:41:42 +0300 [thread overview]
Message-ID: <20260914114145.574791-12-sakari.ailus@linux.intel.com> (raw)
In-Reply-To: <20260914114145.574791-1-sakari.ailus@linux.intel.com>
When the set_selection() pad operation is called from mt9m001_s_fmt(),
it receives a NULL pointer for the state argument. As the function does
not use the state this does not cause any issue in practice, but it
could cause NULL pointer dereferences if the mt9m001_set_selection()
implementation is modified. Avoid future issues by passing the subdev
state.
Suggested-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
---
drivers/media/i2c/mt9m001.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/media/i2c/mt9m001.c b/drivers/media/i2c/mt9m001.c
index 0ade967b357b..d8fffed0818a 100644
--- a/drivers/media/i2c/mt9m001.c
+++ b/drivers/media/i2c/mt9m001.c
@@ -343,6 +343,7 @@ static int mt9m001_get_fmt(struct v4l2_subdev *sd,
}
static int mt9m001_s_fmt(struct v4l2_subdev *sd,
+ struct v4l2_subdev_state *state,
const struct mt9m001_datafmt *fmt,
struct v4l2_mbus_framefmt *mf)
{
@@ -359,7 +360,7 @@ static int mt9m001_s_fmt(struct v4l2_subdev *sd,
int ret;
/* No support for scaling so far, just crop. TODO: use skipping */
- ret = mt9m001_set_selection(sd, NULL, &sel);
+ ret = mt9m001_set_selection(sd, state, &sel);
if (!ret) {
mf->width = mt9m001->rect.width;
mf->height = mt9m001->rect.height;
@@ -404,7 +405,7 @@ static int mt9m001_set_fmt(struct v4l2_subdev *sd,
mf->xfer_func = V4L2_XFER_FUNC_DEFAULT;
if (format->which == V4L2_SUBDEV_FORMAT_ACTIVE)
- return mt9m001_s_fmt(sd, fmt, mf);
+ return mt9m001_s_fmt(sd, sd_state, fmt, mf);
*v4l2_subdev_state_get_format(sd_state, 0) = *mf;
return 0;
}
--
2.47.3
next prev parent reply other threads:[~2026-09-14 11:42 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 11:41 [PATCH v8 00/13] Metadata series preparation Sakari Ailus
2026-09-14 11:41 ` [PATCH v8 01/13] media: Documentation: Improve pixel rate calculation documentation Sakari Ailus
2026-09-14 11:41 ` [PATCH v8 02/13] media: imx219: Account rate_factor in setting upper exposure limit Sakari Ailus
2026-09-14 11:41 ` [PATCH v8 03/13] media: imx219: Account for rate_factor in control steps Sakari Ailus
2026-09-14 11:41 ` [PATCH v8 04/13] media: imx219: The horizontal blanking step is 8 Sakari Ailus
2026-09-14 11:41 ` [PATCH v8 05/13] media: imx219: Rename "binning" as "bin_hv" in imx219_set_pad_format Sakari Ailus
2026-09-14 11:41 ` [PATCH v8 06/13] media: Improve enable_streams and disable_streams documentation Sakari Ailus
2026-09-14 11:41 ` [PATCH v8 07/13] media: v4l2-subdev: Move subdev client capabilities into a new struct Sakari Ailus
2026-09-14 11:41 ` [PATCH v8 08/13] media: v4l2-subdev: Move op check to sub-device op wrappers Sakari Ailus
2026-09-14 11:41 ` [PATCH v8 09/13] media: v4l2-subdev: Always call get_fmt() if set_fmt() is unavailable Sakari Ailus
2026-09-14 11:41 ` [PATCH v8 10/13] media: v4l2-subdev: Don't assign set_fmt where it's equivalent to get_fmt Sakari Ailus
2026-09-14 11:41 ` Sakari Ailus [this message]
2026-09-14 11:41 ` [PATCH v8 12/13] media: cvs: Drop comments on sub-device operations Sakari Ailus
2026-09-14 11:41 ` [PATCH v8 13/13] media: v4l2-subdev: Add struct v4l2_subdev_client_info pointer to pad ops Sakari Ailus
2026-09-22 12:28 ` [PATCH v8 00/13] Metadata series preparation Yemike Abhilash Chandra
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260914114145.574791-12-sakari.ailus@linux.intel.com \
--to=sakari.ailus@linux.intel.com \
--cc=antti.laakso@linux.intel.com \
--cc=benjamin.mugnier@foss.st.com \
--cc=christophe.jaillet@wanadoo.fr \
--cc=dave.stevenson@raspberrypi.com \
--cc=david.plowman@raspberrypi.com \
--cc=dongcheng.yan@intel.com \
--cc=git@apitzsch.eu \
--cc=hans@jjverkuil.nl \
--cc=hansg@kernel.org \
--cc=heimir.sverrisson@gmail.com \
--cc=hpa@redhat.com \
--cc=jacopo.mondi@ideasonboard.com \
--cc=jai.luthra@ideasonboard.com \
--cc=julien.massot@collabora.com \
--cc=khai.wen.ng@intel.com \
--cc=kieran.bingham@ideasonboard.com \
--cc=laurent.pinchart@ideasonboard.com \
--cc=linux-media@vger.kernel.org \
--cc=mehdi.djait@linux.intel.com \
--cc=mirela.rabulea@nxp.com \
--cc=mkorpershoek@kernel.org \
--cc=naush@raspberrypi.com \
--cc=ong.hock.yu@intel.com \
--cc=prabhakar.csengg@gmail.com \
--cc=r-donadkar@ti.com \
--cc=ribalda@kernel.org \
--cc=stefan.klug@ideasonboard.com \
--cc=sylvain.petinot@foss.st.com \
--cc=tomi.valkeinen@ideasonboard.com \
--cc=tomm.merciai@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox