On Mon Aug 10 05:51:28 2026 +0000, Fan Wu wrote:
> start_urb_transfer() arms dev->bulk_timeout, whose callback
> au0828_bulk_timeout() queues dev->restart_streaming; that work in turn
> calls start_urb_transfer() and re-arms the timer.
>
> au0828_dvb_unregister() cancels restart_streaming on disconnect but does
> not sync bulk_timeout. au0828_usb_release() then frees dev with kfree(),
> so a timer still armed or pending at that point can fire after the free
> and dereference dev through timer_container_of().
>
> Sync the timer with timer_shutdown_sync() before cancel_work_sync(). The
> timer callback queues the work, so the timer must be stopped first; the
> shutdown variant is needed because the work re-arms the timer through
> start_urb_transfer(). The dvb->frontend == NULL early return guards the
> register-failure path where the timer was never set up.
>
> This bug was found by static analysis.
>
> Fixes: 53460c53b761 ("[media] au0828: Add timer to restart TS stream if no
> data arrives on bulk endpoint")
> Cc: [email protected]
> Assisted-by: Codex:gpt-5.6
> Signed-off-by: Fan Wu <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/usb/au0828/au0828-dvb.c | 1 +
1 file changed, 1 insertion(+)
---
diff --git a/drivers/media/usb/au0828/au0828-dvb.c
b/drivers/media/usb/au0828/au0828-dvb.c
index 9c95b7ceaecd..d3fff47f0edf 100644
--- a/drivers/media/usb/au0828/au0828-dvb.c
+++ b/drivers/media/usb/au0828/au0828-dvb.c
@@ -537,6 +537,7 @@ void au0828_dvb_unregister(struct au0828_dev *dev)
if (dvb->frontend == NULL)
return;
+ timer_shutdown_sync(&dev->bulk_timeout);
cancel_work_sync(&dev->restart_streaming);
dvb_net_release(&dvb->net);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]