From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 815E842AFA2 for ; Wed, 12 Aug 2026 10:53:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.41 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532008; cv=none; b=X8ph/SuUkBFrLv4FBF2+2zttseIsTogT+dxNlKtYnQ4oLyKbxKF1Yi24rncmpgBge4mLqHXfRjfIUtsIgh4RMG/3OixQew2INd4GuYJ/DogzCtt+G1hsQ5zbckOmJoIs8gg2AFZ5tGIXGjI/x+83x77F1Q4Lm34v8VnQoodp3bY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532008; c=relaxed/simple; bh=MZxpdQUH2WM18MmXTZCwsSq01qdcto9rE1WR/kLOhug=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gG0OpR9fXZINiMHJmZXqQroH8Pc00XAt9PrFGr5g/wauJ8MzZ0WR4ssL1ecInhuBcni4i/RUnJYG+jItcQc0ROC+/QOZyeJGYKaY5/tK7pFRp48jMqO4R9eSuU/OwdTAiGOC5m46kOPblfBFrr4SAJ0to8n088jaBa8qYVmIS6s= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=MHwbPIqW; arc=none smtp.client-ip=209.85.128.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="MHwbPIqW" Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-49553515a8bso11737505e9.1 for ; Wed, 12 Aug 2026 03:53:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786532005; x=1787136805; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zdWsixD11lZF8ErXsHx7xiySMr3/DkdbqSRJhXboNQ4=; b=MHwbPIqWWGEoreaXlyWsT9IeekHpcQfSXlYC7F+tbo7b1SeaNrR42Ist5UHdcam9rR gb49u0EFBdAhTrp8NxIek+DIHcG4STl0nzXGFWWkDUxuWNbTJbMyoS+V9VoIuUhcbmve FdkwPkm8ibo+pRXE9cShZzxSzymM7gyKPTsx6g9LTASnWowIe9X4AnC3wfiRcZCv+Uok 3CN8AdehsbIA29YVQ7Ip8eq6SnqoWSd37MqE7yzBj3ZMu+mKZjr0oAfnr6s1Q1cvTXRy WrsFMAdSMomXyGvzWf5DSkpW571MfVoIb7nNFM3WqoS+XZo1ycaVwB2FUZSrg0cGWwEm TPBQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786532005; x=1787136805; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=zdWsixD11lZF8ErXsHx7xiySMr3/DkdbqSRJhXboNQ4=; b=lKO3wikw40MqEezE0YO27SgRO57XQxeZY1+6vngJXM/6TdggUPzMsggyIec0fLYI1B MJZ9vdcehy/McC94R6AsXae0NqtY0LkiA4hbh0cH0z/L0ZuUDE1IfU2/2e4ASOqR8W3s R7pUENNoFOJ5WSMUohSVp1GBLxW9yA+CWaDFuvTqIWOccb3J1lT09OzO8Ss6di+2Xtt3 Ms7/ZhdfYa4tMIfQCLWVSkmirVjUQdLbdaAhk2gz/YxtBFy3auAfvtG6lCZXrsO9XiWN DPtMC5tc6M2qCA+0FtMVxgaCCCT9nL881zqJz+8vMmK+VLx39HKJhOlK/Y/wwzzLiXYt F0rw== X-Forwarded-Encrypted: i=1; AHgh+RoXwGkCuiRV3yzYrvStRXYBG8p/9jKDuFurBQHsZgRqjfPZ3RImuKfSa35tGbCbRN53KSrpUHSuJinLYPY=@vger.kernel.org X-Gm-Message-State: AOJu0YxFbhusv07uCXQfTe3KE/a8KMvx4ToLbVQJwnphnR1MLlQ08Bz2 PaQx/SrsT5ipvl9j/bAZgLx8TrbT0bLplGtBZ9nmjCy1lMibYUS6Vpvk X-Gm-Gg: AR+sD12snR66UQePVzHfoKcqIXJgezlyOWYDptlDuHvX9TF5zaYk0elQyNJhVa9NjK3 wQpKiLh/kjDPg0MNBkbVAH3jeq7jB5cHBTJoAX6M3EhZkBRy/mZmOttHJ/DbeaxVZXedbAklkt5 RDiZmAckGiSdUXAo+s7eIbbaX4WJr/IAzcJ2SRIUlL+IPYBWQ0mIOYdePAhEYROBCSBPIYRiBDB VwcqRlaASz6H+/IV1q4CyoYC1hElwVfpY+xtvm8CXuYhYu2Fn1kPCyfoOPdiOs0BDHvwoymIByx wXLYqby50/0I+7PkqhT2r4ATyO8O2bj0uJc454wGWuYOg4mV2YpsWjz3ylVShoXU/BtaoHKjxY9 CbwzX1DJiT0cR3CN2JESddXb5chu5BnqWN1Zfav3+Lh50FAscpC5ZnzSBpM1Ry6dsngRi3gswnM pX3IWwLcdFgmtqJstTsfC6AmaGwLpA2Jr1VCPfcvH1e5thISoOOyQJGYJgGC/HGMGzdDg/AR+CD QdLq9U92pP0QGCxWnL/orqlJqwfEfM8JPwbTa5tB+8eWA00JPBmZxkGFnuPSZq7S8ykg60Xz7y6 /457ZAbwmfjaKcQHNf01ZnsCo3E6uCk7ft9uiLPnBLq0xuJu9Ok2qVjp6kiMTf2XvcdDkEIaO1y YqQPVA9t5Icj2CQ6xQ7f6RvyojSVHUWyhPdambcU4kO56vw== X-Received: by 2002:a05:600c:c178:b0:499:60bf:c6f7 with SMTP id 5b1f17b1804b1-4997c1487e9mr47992325e9.13.1786532004701; Wed, 12 Aug 2026 03:53:24 -0700 (PDT) Received: from localhost.localdomain (host-213-45-168-79.pool21345.interbusiness.it. [213.45.168.79]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4997c939574sm37352315e9.1.2026.08.12.03.53.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 03:53:24 -0700 (PDT) From: Nicola Fiorillo To: linux-media@vger.kernel.org Cc: mchehab@kernel.org, sakari.ailus@linux.intel.com, bingbu.cao@intel.com, tian.shu.qiu@intel.com, linux-kernel@vger.kernel.org, Nicola Fiorillo Subject: [PATCH 1/3] media: ipu6: Check the remote pad before dereferencing it Date: Wed, 12 Aug 2026 12:53:03 +0200 Message-ID: <20260812105305.32447-2-nicfio@gmail.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260812105305.32447-1-nicfio@gmail.com> References: <20260812105305.32447-1-nicfio@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Unbinding a sensor driver while a capture is running oopses the kernel: BUG: kernel NULL pointer dereference, address: 0000000000000020 RIP: 0010:ipu6_isys_csi2_disable_streams+0x3c/0x70 [intel_ipu6_isys] Call Trace: v4l2_subdev_disable_streams+0x1b7/0x370 [videodev] ipu6_isys_video_set_streaming+0x20f/0x930 [intel_ipu6_isys] stop_streaming+0x102/0x110 [intel_ipu6_isys] __vb2_queue_cancel+0x2a/0x2d0 [videobuf2_common] vb2_core_queue_release+0x22/0x80 [videobuf2_common] _vb2_fop_release+0x58/0xb0 [videobuf2_v4l2] v4l2_release+0xbd/0xd0 [videodev] __fput+0xde/0x2a0 media_pad_remote_pad_first() returns NULL once the sensor is gone and the link with it, but both the enable and the disable path dereference the result unconditionally. The faulting address is the offset of the entity member in struct media_pad. Check it. On enable there is nothing to stream from, so refuse with -ENOLINK. On disable the receiver still has to be stopped, so stop it and skip only the call towards the sensor that is no longer there. Reproduced on a CHUWI Hi10 X1 (Alder Lake-N, IPU6) running 6.12.86, with the CSI-2 port of a sensor being unbound mid capture. The code is unchanged in 7.2-rc7. Fixes: 3a5c59ad926b ("media: ipu6: Rework CSI-2 sub-device streaming control") Signed-off-by: Nicola Fiorillo --- drivers/media/pci/intel/ipu6/ipu6-isys-csi2.c | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/drivers/media/pci/intel/ipu6/ipu6-isys-csi2.c b/drivers/media/pci/intel/ipu6/ipu6-isys-csi2.c index 7e539a0c6..c00a82eb8 100644 --- a/drivers/media/pci/intel/ipu6/ipu6-isys-csi2.c +++ b/drivers/media/pci/intel/ipu6/ipu6-isys-csi2.c @@ -356,6 +356,9 @@ static int ipu6_isys_csi2_enable_streams(struct v4l2_subdev *sd, int ret; remote_pad = media_pad_remote_pad_first(&sd->entity.pads[CSI2_PAD_SINK]); + if (!remote_pad) + return -ENOLINK; + remote_sd = media_entity_to_v4l2_subdev(remote_pad->entity); sink_streams = @@ -392,10 +395,17 @@ static int ipu6_isys_csi2_disable_streams(struct v4l2_subdev *sd, v4l2_subdev_state_xlate_streams(state, pad, CSI2_PAD_SINK, &streams_mask); + ipu6_isys_csi2_set_stream(sd, NULL, 0, false); + + /* + * The link is gone if the sensor driver was unbound while streaming. + * Stop the receiver anyway, there is just no one left to tell. + */ remote_pad = media_pad_remote_pad_first(&sd->entity.pads[CSI2_PAD_SINK]); - remote_sd = media_entity_to_v4l2_subdev(remote_pad->entity); + if (!remote_pad) + return 0; - ipu6_isys_csi2_set_stream(sd, NULL, 0, false); + remote_sd = media_entity_to_v4l2_subdev(remote_pad->entity); v4l2_subdev_disable_streams(remote_sd, remote_pad->index, sink_streams); -- 2.47.3