On Tue Mar 17 15:20:20 2026 +0800, Chen Ni wrote:
> Use IS_ERR() and PTR_ERR() to properly handle the error return from
> media_pad_remote_pad_unique(), which returns ERR_PTR() on failure but
> never NULL. The previous code only checked for NULL, leading to invalid
> pointer dereference.
> 
> Detected by Smatch:
> drivers/media/v4l2-core/v4l2-subdev.c:2588 
> v4l2_subdev_get_frame_desc_passthrough() warn:
> 'remote_source_pad' is an error pointer or valid
> 
> drivers/media/v4l2-core/v4l2-subdev.c:2595 
> v4l2_subdev_get_frame_desc_passthrough() error:
> 'remote_source_pad' dereferencing possible ERR_PTR()
> 
> Fixes: a564839e630c ("media: subdev: Add 
> v4l2_subdev_get_frame_desc_passthrough helper")
> Reviewed-by: Jacopo Mondi <[email protected]>
> Reviewed-by: Tomi Valkeinen <[email protected]>
> Signed-off-by: Chen Ni <[email protected]>
> Signed-off-by: Sakari Ailus <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/v4l2-core/v4l2-subdev.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

---

diff --git a/drivers/media/v4l2-core/v4l2-subdev.c 
b/drivers/media/v4l2-core/v4l2-subdev.c
index 9efd14d4026f..7cb17e0a5617 100644
--- a/drivers/media/v4l2-core/v4l2-subdev.c
+++ b/drivers/media/v4l2-core/v4l2-subdev.c
@@ -2585,10 +2585,10 @@ int v4l2_subdev_get_frame_desc_passthrough(struct 
v4l2_subdev *sd,
 
                        if (!have_source_fd) {
                                remote_source_pad = 
media_pad_remote_pad_unique(local_sink_pad);
-                               if (!remote_source_pad) {
+                               if (IS_ERR(remote_source_pad)) {
                                        dev_dbg(dev, "Failed to find remote pad 
for sink pad %u\n",
                                                local_sink_pad->index);
-                                       ret = -EINVAL;
+                                       ret = PTR_ERR(remote_source_pad);
                                        goto out_unlock;
                                }
 
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to