From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DB8CD42C4FF for ; Wed, 12 Aug 2026 10:53:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532010; cv=none; b=EoGlPslmMQimI7vlvVggnJg3qZ8TWewHmOFdAgJ8KnHUlSLYuMOh+4PoxvAif3pHVo2tWgSLWtkplQvOVK+PBDTyyzryj4TVp5EgGJ0krS+dbeHTzrCuVrtvXLVAOR+JbPbmKM/V0Py8OLqcwmblN44sGJ1fudXTzN9bpzRKrlk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532010; c=relaxed/simple; bh=3U8yTqWdcMedAAD5xD43DIh+6Q0rTvKIilQ/8WcxKkU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Pv7IXODHXQWvoO5O8pWs0yoZgTOaIKVyC0+i/aBcR1a21/nKnqhvTYzolkGg7j5cLZe+qwc09c/yor23ZtPw3pLuReyMDVlAglOJCBLaNMLRSbJoTnN20xI4bZ1XugRvr4rmDatUWKOtH+30dywq/QngQNoBORmikXzQXvGMI4A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=PCBlv+S5; arc=none smtp.client-ip=209.85.128.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="PCBlv+S5" Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-4954a2e73a9so4155075e9.3 for ; Wed, 12 Aug 2026 03:53:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786532007; x=1787136807; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5jgs5U43ai39YOGkWm4gKlSWagxfcI4VO/2d/d10obI=; b=PCBlv+S5FOSLRU5xEEOaFkB0btHalZykHD1VvV2qoYkPxoGFBPqU0iuHHFgxuVH2mp ZqM7lAGjCSJrCBu6XHLaiFgGLZtn8ky0WAB71WFNR5kbymzJ8Eh/UfWoVNA+u1JY8uc+ A5mhNBrDeO6SwqNU3S7aCwnt1fbcxBNK+1kLMIV82LVzM+zFg5c67cFwEy4La8tdAsiE YojGxzeErnnhIkrlT4aIl4uG/aWOpOdBc1jPJniTvTmgvD5Z+Sv33H78gw7ODkroC2n9 Jr74W2K9vzpJhp1dAXlUyfCiI/NTYfMgrjgLr1z/Wg5Du2yqMj9GOLMvQqqxP31iOqaN lBNA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786532007; x=1787136807; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=5jgs5U43ai39YOGkWm4gKlSWagxfcI4VO/2d/d10obI=; b=DQYP+Zfrj+lNOWdC/mNG6bViufhVqEt0IwA2b/q6NBY4Lj8/57VCJ8GkJnWbb6Gxas 7ObJiAyi3Hw58etihz+NeAhKN3sqHXfonISmVH2fXGkvOJyR0psrRMc0aqsdMG18WfA9 W+Dbb5q4YZk6mj4cNDw+q5sx1ZptVjuIJhkNAYzvPPeMyu/GZ9at0UQke8mSHudzBs/Z yfKvSyUMsXBfm56hnVpzz90y+t7upN9vdpOXXixVuMD2neBK050PKfdq6l+551jYPY2c atN6WTG6ce9LHnNU/vCgo2DotC42UUcRMCQYDg7l637qdD9ph0mASYj4z42qqeQxFSiP lj0A== X-Forwarded-Encrypted: i=1; AHgh+RpDepXrEzdN+Gt/GGT5tGBK4UUKGFYrAUen+RVbwxBDaiLLSkBS1rxU5PJso7RRwSQkRnCJeDkQTjxs97M=@vger.kernel.org X-Gm-Message-State: AOJu0YxwUxB3tky8G4E3Wb2MRgW9uQWUTEqlPMlrVW9qb/ESkRt9x9sk upZaaQ2TiGpJNhFYzngHvu5qw1TAzaPMZoSe9W1ui+OHX2lbRoo5iKnR X-Gm-Gg: AR+sD10QHyV2oUa+wDV5bKNB6pwrZw+XHUO+E7Gl1em3KD/EfbMNO9LjlMaq+EELZJZ egUaWgnXc3L4zehTWWgAK5CXKROh1G0ZbU7EPnSAeH4SogC12mvmlI+l5tcIZH1j3g6leQ5uiGm xNeRfb1b7tQ4nU/FGfwbTfzaf1XcKGX48oejBs92amOky6D/gV1SX6di8iP4j/WdBccJkzuuRRT E3X9CzC49tDrF5uJWmUlCmS/kEO0KCM+zOuesMdOXZ6GwNI5tkpMeRoPVxZl2CNMujLYwQh7+mL Tn+vBWtwaArNEVs0v3sYjSUZd0zSbUoNReNicn8iGZY2wBBWOBezPwSu4VWWueh9MQfmHEWl6vT LSkc+mShiKQrwYEjwdPguTdZ44okQ2uxHlTIxACNsn8VQMIiFItBZZmXCome+rd3kd4NT9ndb45 pU37CAd8u7brcBS4AnkOpUF65g8HXq8yeUeORrfCw7nKuIe71ZPa2t9ihEIHjB0CtOZeTu5ARj+ 2TSydEaKPpnf4TSYK0Hj1Ioj/4h5AXWMcmP/PU60//ljSj2flXXKltQwQLz1Q9pUU0uEZoDv3aF Uu3KGiRvEJ95Bc3zSv3CkQg43nXrVa1OUuFNfQnNLGMuvyfrLRgtV5M10HiP+vAYHoimDyAev3E nJjWqmwSQWwtDwTWhzvs/sqkJUo3ZUpJdYh3I1rt8Tbwb4w== X-Received: by 2002:a05:600c:8209:b0:496:bbce:fc with SMTP id 5b1f17b1804b1-4997c126dbemr59720255e9.12.1786532007084; Wed, 12 Aug 2026 03:53:27 -0700 (PDT) Received: from localhost.localdomain (host-213-45-168-79.pool21345.interbusiness.it. [213.45.168.79]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4997c939574sm37352315e9.1.2026.08.12.03.53.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 03:53:26 -0700 (PDT) From: Nicola Fiorillo To: linux-media@vger.kernel.org Cc: mchehab@kernel.org, sakari.ailus@linux.intel.com, bingbu.cao@intel.com, tian.shu.qiu@intel.com, linux-kernel@vger.kernel.org, Nicola Fiorillo Subject: [PATCH 3/3] media: ipu6: Signal the video queues when a sensor is unbound Date: Wed, 12 Aug 2026 12:53:05 +0200 Message-ID: <20260812105305.32447-4-nicfio@gmail.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260812105305.32447-1-nicfio@gmail.com> References: <20260812105305.32447-1-nicfio@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit isys_async_ops implements .bound() and .complete() but not .unbind(), so nothing tells the ISYS video nodes that the sensor feeding them has gone away. A capture that is streaming when the sensor is unbound stays blocked in vb2_core_dqbuf() forever, waiting for a frame that can no longer arrive: [<0>] vb2_core_dqbuf+0x362/0x1190 [videobuf2_common] [<0>] vb2_dqbuf+0xb4/0x210 [videobuf2_v4l2] [<0>] __video_do_ioctl+0x894/0xb30 [<0>] video_usercopy+0x479/0xde0 [<0>] v4l2_ioctl+0x198/0x220 [<0>] __x64_sys_ioctl+0x134/0x1c0 The wait in __vb2_wait_for_done_vb() ends on a new buffer, on !q->streaming, or on q->error. Tearing the sensor down sets none of the three. The sleep is interruptible, so DETECT_HUNG_TASK stays quiet as well and the process is simply stuck until something kills it. Add the missing .unbind() and mark the queues of the CSI-2 receiver the departing sensor was attached to, which is enough for DQBUF to return -EIO. Only streaming queues are flagged: q->error is cleared by __vb2_queue_cancel(), so flagging an idle queue would leave it in error until the next VIDIOC_STREAMOFF. Reproduced on a CHUWI Hi10 X1 (Alder Lake-N, IPU6) by unbinding the sensor while v4l2-ctl was streaming, with both sensors of the machine. Without this patch 3 attempts out of 3 hang; with it, 10 out of 10 wake up, report "VIDIOC_DQBUF: failed: Input/output error" and exit. The same run under KASAN reports nothing. Fixes: f50c4ca0a820 ("media: intel/ipu6: add the main input system driver") Signed-off-by: Nicola Fiorillo --- drivers/media/pci/intel/ipu6/ipu6-isys.c | 41 ++++++++++++++++++++++++ 1 file changed, 41 insertions(+) diff --git a/drivers/media/pci/intel/ipu6/ipu6-isys.c b/drivers/media/pci/intel/ipu6/ipu6-isys.c index c9cdeb705..8055ae169 100644 --- a/drivers/media/pci/intel/ipu6/ipu6-isys.c +++ b/drivers/media/pci/intel/ipu6/ipu6-isys.c @@ -31,6 +31,7 @@ #include #include #include +#include #include "ipu6-bus.h" #include "ipu6-cpd.h" @@ -700,6 +701,45 @@ static int isys_notifier_bound(struct v4l2_async_notifier *notifier, return v4l2_device_register_subdev_nodes(&isys->v4l2_dev); } +/* The .unbind() notifier callback when a sub-device goes away */ +static void isys_notifier_unbind(struct v4l2_async_notifier *notifier, + struct v4l2_subdev *sd, + struct v4l2_async_connection *asc) +{ + struct ipu6_isys *isys = + container_of(notifier, struct ipu6_isys, notifier); + struct sensor_async_sd *s_asd = + container_of(asc, struct sensor_async_sd, asc); + struct ipu6_isys_csi2 *csi2; + unsigned int i; + + if (s_asd->csi2.port >= isys->pdata->ipdata->csi2.nports) + return; + + /* + * The sensor is gone, so no more frames will ever arrive on the video + * nodes fed by it. Tell videobuf2, or a DQBUF already blocked in + * vb2_core_dqbuf() would sleep forever: nothing else in the teardown + * path wakes that queue up. + * + * Only queues that are actually streaming are marked. The error flag + * is only cleared by __vb2_queue_cancel(), so flagging an idle queue + * would leave it poisoned until the next STREAMOFF. + */ + csi2 = &isys->csi2[s_asd->csi2.port]; + for (i = 0; i < NR_OF_CSI2_SRC_PADS; i++) { + struct vb2_queue *q = &csi2->av[i].aq.vbq; + + if (!vb2_is_streaming(q)) + continue; + + dev_dbg(&isys->adev->auxdev.dev, + "%s went away while streaming on %s\n", sd->name, + csi2->av[i].vdev.name); + vb2_queue_error(q); + } +} + static int isys_notifier_complete(struct v4l2_async_notifier *notifier) { struct ipu6_isys *isys = @@ -710,6 +750,7 @@ static int isys_notifier_complete(struct v4l2_async_notifier *notifier) static const struct v4l2_async_notifier_operations isys_async_ops = { .bound = isys_notifier_bound, + .unbind = isys_notifier_unbind, .complete = isys_notifier_complete, }; -- 2.47.3