[lvc-project] [RESEND PATCH 1/2] media: em28xx: adjust initialization order in em28xx_v4l2_init()
Hans Verkuil
hverkuil+cisco at kernel.org
Tue Sep 8 12:23:43 MSK 2026
On 07/09/2026 12:28, Dmitry Antipov wrote:
> In em28xx_v4l2_init(), call to vb2_video_unregister_device() during
> 'unregister_dev' cleanup assumes that queues of the corresponding 'struct
> video_device' instance (i.e. 'vdev' of 'struct em28xx_v4l2') are properly
> initialized, triggering an undefined behavior otherwise. So call
> em28xx_vb2_setup() immediately after video_register_device() and,
> since the former is actually non-void, do not ignore the value returned.
>
> Reported-by: syzbot+dd0f06181ab66b93dc00 at syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=dd0f06181ab66b93dc00
> Fixes: 37ecc7b1278f ("[media] em28xx: add media controller support")
> Signed-off-by: Dmitry Antipov <dmantipov at yandex.ru>
> ---
> drivers/media/usb/em28xx/em28xx-video.c | 11 +++++++----
> 1 file changed, 7 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/media/usb/em28xx/em28xx-video.c b/drivers/media/usb/em28xx/em28xx-video.c
> index c418add65bb5..324855ff5e86 100644
> --- a/drivers/media/usb/em28xx/em28xx-video.c
> +++ b/drivers/media/usb/em28xx/em28xx-video.c
> @@ -2992,13 +2992,19 @@ static int em28xx_v4l2_init(struct em28xx *dev)
> goto unregister_dev;
> }
>
> + v4l2->vb_vbiq.lock = &v4l2->vb_vbi_queue_lock;
> + ret = em28xx_vb2_setup(dev);
> + if (ret) {
> + dev_err(&dev->intf->dev, "unable to setup device queues, error %d\n", ret);
> + goto unregister_dev;
> + }
> +
> /* Allocate and fill vbi video_device struct */
> if (em28xx_vbi_supported(dev) == 1) {
> em28xx_vdev_init(dev, &v4l2->vbi_dev, &em28xx_video_template,
> "vbi");
>
> v4l2->vbi_dev.queue = &v4l2->vb_vbiq;
> - v4l2->vbi_dev.queue->lock = &v4l2->vb_vbi_queue_lock;
> v4l2->vbi_dev.device_caps = V4L2_CAP_STREAMING |
> V4L2_CAP_READWRITE | V4L2_CAP_VBI_CAPTURE;
> if ((v4l2->vdev.device_caps & V4L2_CAP_TUNER) == 0)
> @@ -3068,9 +3074,6 @@ static int em28xx_v4l2_init(struct em28xx *dev)
> /* Save some power by putting tuner to sleep */
> v4l2_device_call_all(&v4l2->v4l2_dev, 0, tuner, standby);
>
> - /* initialize videobuf2 stuff */
> - em28xx_vb2_setup(dev);
> -
> dev_info(&dev->intf->dev,
> "V4L2 extension successfully initialized\n");
>
I prefer this simpler patch:
https://patchwork.linuxtv.org/project/linux-media/patch/3e01154b-ab4d-4cb3-90d7-a5dce4e5b2c4@kernel.org/
Regards,
Hans
More information about the lvc-project
mailing list