Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1424246

Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in _destroy()

From Shuah Khan <shuahkh@osg.samsung.com>
Newsgroups linux.kernel
Subject Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in _destroy()
Date 2016-06-16 18:30 +0200
Message-ID <rKIl3-2cb-7@gated-at.bofh.it> (permalink)
References <rKpBL-7cb-7@gated-at.bofh.it> <rKpBM-7cb-27@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 06/15/2016 02:15 PM, Max Kellermann wrote:
> media_gobj_destroy() may be called twice on one instance - once by
> media_device_unregister() and again by dvb_media_device_free().  The
> function media_remove_intf_links() establishes and documents the
> convention that mdev==NULL means that the object is not registered,
> but nobody ever NULLs this variable.  So this patch really implements
> this behavior, and adds another mdev==NULL check to
> media_gobj_destroy() to protect against double removal.

Are you seeing null pointer dereference on gobj->mdev? In any case,
we have to look at if there is a missing mutex hold that creates a
race between media_device_unregister() and dvb_media_device_free()

I don't this patch will solve the race condition.

thanks,
-- Shuah


> 
> Signed-off-by: Max Kellermann <max@duempel.org>
> ---
>  drivers/media/media-entity.c |    6 ++++++
>  1 file changed, 6 insertions(+)
> 
> diff --git a/drivers/media/media-entity.c b/drivers/media/media-entity.c
> index d8a2299..9526338 100644
> --- a/drivers/media/media-entity.c
> +++ b/drivers/media/media-entity.c
> @@ -203,10 +203,16 @@ void media_gobj_destroy(struct media_gobj *gobj)
>  {
>  	dev_dbg_obj(__func__, gobj);
>  
> +	/* Do nothing if the object is not linked. */
> +	if (gobj->mdev == NULL)
> +		return;
> +
>  	gobj->mdev->topology_version++;
>  
>  	/* Remove the object from mdev list */
>  	list_del(&gobj->list);
> +
> +	gobj->mdev = NULL;
>  }
>  
>  int media_entity_pads_init(struct media_entity *entity, u16 num_pads,
> 
> --
> To unsubscribe from this list: send the line "unsubscribe linux-media" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> 

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 1/3] drivers/media/dvb-core/en50221: use kref to manage  struct dvb_ca_private Max Kellermann <max@duempel.org> - 2016-06-15 22:30 +0200
  [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in  _destroy() Max Kellermann <max@duempel.org> - 2016-06-15 22:30 +0200
    Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in  _destroy() Shuah Khan <shuahkh@osg.samsung.com> - 2016-06-16 18:30 +0200
      Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in  _destroy() Max Kellermann <max@duempel.org> - 2016-06-16 20:50 +0200
        Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in  _destroy() Shuah Khan <shuahkh@osg.samsung.com> - 2016-06-16 21:00 +0200
    Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in  _destroy() Sakari Ailus <sakari.ailus@iki.fi> - 2016-06-17 15:00 +0200
      Re: [PATCH 2/3] drivers/media/media-entity: clear media_gobj.mdev in  _destroy() Max Kellermann <max@duempel.org> - 2016-06-17 15:10 +0200
  Re: [PATCH 1/3] drivers/media/dvb-core/en50221: use kref to manage  struct dvb_ca_private Shuah Khan <shuahkh@osg.samsung.com> - 2016-06-16 18:10 +0200
    Re: [PATCH 1/3] drivers/media/dvb-core/en50221: use kref to manage  struct dvb_ca_private Max Kellermann <max@duempel.org> - 2016-06-16 20:40 +0200

csiph-web