On Mon Jul 6 20:58:33 2026 +0530, Uday Khare wrote:
> kthread_run() returns an ERR_PTR on failure, not NULL.
> When start_streaming() fails, data->kthread_vid_cap is left holding
> this error pointer instead of being cleared.
>
> This causes two subsequent bugs:
> 1. A future call to start_streaming() sees a non-NULL kthread_vid_cap
> and returns 0 (success) immediately, without actually starting the
> capture thread.
> 2. A call to stop_streaming() checks 'kthread_vid_cap == NULL' which
> is false for an error pointer, and proceeds to call kthread_stop()
> on the error pointer, leading to a kernel crash.
>
> Fix this by resetting kthread_vid_cap to NULL on failure before
> jumping to the error path.
>
> Fixes: 5cebaac60974 ("media: video-i2c: add video-i2c driver")
> Cc: [email protected]
> Signed-off-by: Uday Khare <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/i2c/video-i2c.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
---
diff --git a/drivers/media/i2c/video-i2c.c b/drivers/media/i2c/video-i2c.c
index 56b99eea54a1..7f971645c0b5 100644
--- a/drivers/media/i2c/video-i2c.c
+++ b/drivers/media/i2c/video-i2c.c
@@ -523,8 +523,12 @@ static int start_streaming(struct vb2_queue *vq, unsigned
int count)
data->kthread_vid_cap = kthread_run(video_i2c_thread_vid_cap, data,
"%s-vid-cap", data->v4l2_dev.name);
ret = PTR_ERR_OR_ZERO(data->kthread_vid_cap);
- if (!ret)
- return 0;
+ if (ret) {
+ data->kthread_vid_cap = NULL;
+ goto error_rpm_put;
+ }
+
+ return 0;
error_rpm_put:
pm_runtime_put_autosuspend(dev);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]