On Sat Aug 8 16:10:02 2026 +0700, Cong Nguyen wrote:
> isys_notifier_init() calls v4l2_async_nf_init() and then adds fwnode
> remote subdevs in a loop with v4l2_async_nf_add_fwnode_remote(). If an
> endpoint parse or add fails partway through the loop, it jumps to
> err_parse and returns without calling v4l2_async_nf_cleanup(), leaking
> every v4l2_async_connection already added to the notifier's waiting
> list.
> 
> The register-failure path just below already cleans up correctly, and
> the caller only tears the notifier down (isys_notifier_cleanup()) once
> isys_notifier_init() has returned success. Clean up the notifier on the
> parse error path too.
> 
> Fixes: f50c4ca0a820 ("media: intel/ipu6: add the main input system driver")
> Cc: [email protected]
> Assisted-by: Claude:claude-opus-4
> Signed-off-by: Cong Nguyen <[email protected]>
> Signed-off-by: Sakari Ailus <[email protected]>

Patch committed.

Thanks,
Sakari Ailus

 drivers/media/pci/intel/ipu6/ipu6-isys.c | 1 +
 1 file changed, 1 insertion(+)

---

diff --git a/drivers/media/pci/intel/ipu6/ipu6-isys.c 
b/drivers/media/pci/intel/ipu6/ipu6-isys.c
index c9cdeb7054d7..24db2763de54 100644
--- a/drivers/media/pci/intel/ipu6/ipu6-isys.c
+++ b/drivers/media/pci/intel/ipu6/ipu6-isys.c
@@ -761,6 +761,7 @@ static int isys_notifier_init(struct ipu6_isys *isys)
 
 err_parse:
                fwnode_handle_put(ep);
+               v4l2_async_nf_cleanup(&isys->notifier);
                return ret;
        }
 
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to