Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1424246
| From | Shuah Khan <shuahkh@osg.samsung.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in _destroy() |
| Date | 2016-06-16 18:30 +0200 |
| Message-ID | <rKIl3-2cb-7@gated-at.bofh.it> (permalink) |
| References | <rKpBL-7cb-7@gated-at.bofh.it> <rKpBM-7cb-27@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 06/15/2016 02:15 PM, Max Kellermann wrote:
> media_gobj_destroy() may be called twice on one instance - once by
> media_device_unregister() and again by dvb_media_device_free(). The
> function media_remove_intf_links() establishes and documents the
> convention that mdev==NULL means that the object is not registered,
> but nobody ever NULLs this variable. So this patch really implements
> this behavior, and adds another mdev==NULL check to
> media_gobj_destroy() to protect against double removal.
Are you seeing null pointer dereference on gobj->mdev? In any case,
we have to look at if there is a missing mutex hold that creates a
race between media_device_unregister() and dvb_media_device_free()
I don't this patch will solve the race condition.
thanks,
-- Shuah
>
> Signed-off-by: Max Kellermann <max@duempel.org>
> ---
> drivers/media/media-entity.c | 6 ++++++
> 1 file changed, 6 insertions(+)
>
> diff --git a/drivers/media/media-entity.c b/drivers/media/media-entity.c
> index d8a2299..9526338 100644
> --- a/drivers/media/media-entity.c
> +++ b/drivers/media/media-entity.c
> @@ -203,10 +203,16 @@ void media_gobj_destroy(struct media_gobj *gobj)
> {
> dev_dbg_obj(__func__, gobj);
>
> + /* Do nothing if the object is not linked. */
> + if (gobj->mdev == NULL)
> + return;
> +
> gobj->mdev->topology_version++;
>
> /* Remove the object from mdev list */
> list_del(&gobj->list);
> +
> + gobj->mdev = NULL;
> }
>
> int media_entity_pads_init(struct media_entity *entity, u16 num_pads,
>
> --
> To unsubscribe from this list: send the line "unsubscribe linux-media" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
>
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 1/3] drivers/media/dvb-core/en50221: use kref to manage struct dvb_ca_private Max Kellermann <max@duempel.org> - 2016-06-15 22:30 +0200
[PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in _destroy() Max Kellermann <max@duempel.org> - 2016-06-15 22:30 +0200
Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in _destroy() Shuah Khan <shuahkh@osg.samsung.com> - 2016-06-16 18:30 +0200
Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in _destroy() Max Kellermann <max@duempel.org> - 2016-06-16 20:50 +0200
Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in _destroy() Shuah Khan <shuahkh@osg.samsung.com> - 2016-06-16 21:00 +0200
Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in _destroy() Sakari Ailus <sakari.ailus@iki.fi> - 2016-06-17 15:00 +0200
Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in _destroy() Max Kellermann <max@duempel.org> - 2016-06-17 15:10 +0200
Re: [PATCH 1/3] drivers/media/dvb-core/en50221: use kref to manage struct dvb_ca_private Shuah Khan <shuahkh@osg.samsung.com> - 2016-06-16 18:10 +0200
Re: [PATCH 1/3] drivers/media/dvb-core/en50221: use kref to manage struct dvb_ca_private Max Kellermann <max@duempel.org> - 2016-06-16 20:40 +0200
csiph-web