From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-5.2 required=3.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS, USER_AGENT_SANE_1 autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0CCE2C0007A for ; Thu, 3 Dec 2020 18:01:14 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id C40C420754 for ; Thu, 3 Dec 2020 18:01:13 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727726AbgLCSBF (ORCPT ); Thu, 3 Dec 2020 13:01:05 -0500 Received: from youngberry.canonical.com ([91.189.89.112]:33236 "EHLO youngberry.canonical.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1731413AbgLCSBE (ORCPT ); Thu, 3 Dec 2020 13:01:04 -0500 Received: from 1.general.cking.uk.vpn ([10.172.193.212]) by youngberry.canonical.com with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1kkstx-0005Pt-3z; Thu, 03 Dec 2020 18:00:21 +0000 To: Dongchun Zhu Cc: Andy Shevchenko , Sakari Ailus , Mauro Carvalho Chehab , Matthias Brugger , linux-media , "linux-arm-kernel@lists.infradead.org" , linux-mediatek@lists.infradead.org, "linux-kernel@vger.kernel.org" From: Colin Ian King Subject: re: media: i2c: add OV02A10 image sensor driver Message-ID: <9af089ea-2532-68ac-5d22-97a669ccec91@canonical.com> Date: Thu, 3 Dec 2020 18:00:20 +0000 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.5.0 MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit Precedence: bulk List-ID: X-Mailing-List: linux-media@vger.kernel.org Hi, Static analysis on linux-next with Coverity has detected an issue with the following commit: 529 static int ov02a10_s_stream(struct v4l2_subdev *sd, int on) 530 { 531 struct ov02a10 *ov02a10 = to_ov02a10(sd); 532 struct i2c_client *client = v4l2_get_subdevdata(&ov02a10->subdev); 1. var_decl: Declaring variable ret without initializer. 533 int ret; 534 535 mutex_lock(&ov02a10->mutex); 536 2. Condition ov02a10->streaming == on, taking true branch. 537 if (ov02a10->streaming == on) 3. Jumping to label unlock_and_return. 538 goto unlock_and_return; 539 540 if (on) { 541 ret = pm_runtime_get_sync(&client->dev); 542 if (ret < 0) { 543 pm_runtime_put_noidle(&client->dev); 544 goto unlock_and_return; 545 } 546 547 ret = __ov02a10_start_stream(ov02a10); 548 if (ret) { 549 __ov02a10_stop_stream(ov02a10); 550 ov02a10->streaming = !on; 551 goto err_rpm_put; 552 } 553 } else { 554 __ov02a10_stop_stream(ov02a10); 555 pm_runtime_put(&client->dev); 556 } 557 558 ov02a10->streaming = on; 559 mutex_unlock(&ov02a10->mutex); 560 561 return 0; 562 563 err_rpm_put: 564 pm_runtime_put(&client->dev); 565 unlock_and_return: 566 mutex_unlock(&ov02a10->mutex); 567 Uninitialized scalar variable (UNINIT) 4. uninit_use: Using uninitialized value ret. 568 return ret; 569 } Variable ret has not been initialized, so the error return value is a garbage value. It should be initialized with some appropriate negative error code, or ret could be removed and the return should return a literal value of a error code. I was unsure what value is appropriate to fix this, so instead I'm reporting this issue. Colin