On Thu Jan 15 11:22:35 2026 +0200, Tomi Valkeinen wrote:
> When unloading the module on gen 4, we hit a NULL pointer dereference.
> This is caused by the cleanup code calling vsp1_drm_cleanup() where it
> should be calling vsp1_vspx_cleanup().
> 
> Fix this by checking the IP version and calling the drm or vspx function
> accordingly, the same way as the init code does.
> 
> Fixes: d06c1a9f348d ("media: vsp1: Add VSPX support")
> Cc: [email protected]
> Signed-off-by: Tomi Valkeinen <[email protected]>
> Reviewed-by: Kieran Bingham <[email protected]>
> Reviewed-by: Jacopo Mondi <[email protected]>
> Signed-off-by: Sakari Ailus <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/platform/renesas/vsp1/vsp1_drv.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

---

diff --git a/drivers/media/platform/renesas/vsp1/vsp1_drv.c 
b/drivers/media/platform/renesas/vsp1/vsp1_drv.c
index 2de515c497eb..627b5046fa80 100644
--- a/drivers/media/platform/renesas/vsp1/vsp1_drv.c
+++ b/drivers/media/platform/renesas/vsp1/vsp1_drv.c
@@ -240,8 +240,12 @@ static void vsp1_destroy_entities(struct vsp1_device *vsp1)
                media_device_unregister(&vsp1->media_dev);
        media_device_cleanup(&vsp1->media_dev);
 
-       if (!vsp1->info->uapi)
-               vsp1_drm_cleanup(vsp1);
+       if (!vsp1->info->uapi) {
+               if (vsp1->info->version == VI6_IP_VERSION_MODEL_VSPX_GEN4)
+                       vsp1_vspx_cleanup(vsp1);
+               else
+                       vsp1_drm_cleanup(vsp1);
+       }
 }
 
 static int vsp1_create_entities(struct vsp1_device *vsp1)
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to