On Wed Apr 15 14:49:09 2026 +0000, Zhaoyang Yu wrote:
> The return value of dm1105_dma_map(), which handles DMA memory allocation,
> is ignored in dm1105_hw_init(). If dma_alloc_coherent() fails, the driver
> will proceed using a NULL pointer for DMA transfers, leading to a kernel
> oops or invalid hardware access.
> 
> Fix this by checking the return value and propagating -ENOMEM on failure.
> 
> Signed-off-by: Zhaoyang Yu <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/pci/dm1105/dm1105.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

---

diff --git a/drivers/media/pci/dm1105/dm1105.c 
b/drivers/media/pci/dm1105/dm1105.c
index bbd24769ae56..c33d811cbafa 100644
--- a/drivers/media/pci/dm1105/dm1105.c
+++ b/drivers/media/pci/dm1105/dm1105.c
@@ -768,6 +768,8 @@ static void dm1105_ir_exit(struct dm1105_dev *dm1105)
 
 static int dm1105_hw_init(struct dm1105_dev *dev)
 {
+       int ret;
+
        dm1105_disable_irqs(dev);
 
        dm_writeb(DM1105_HOST_CTR, 0);
@@ -778,7 +780,10 @@ static int dm1105_hw_init(struct dm1105_dev *dev)
        dm_writew(DM1105_TSCTR, 0xc10a);
 
        /* map DMA and set address */
-       dm1105_dma_map(dev);
+       ret = dm1105_dma_map(dev);
+       if (ret)
+               return -ENOMEM;
+
        dm1105_set_dma_addr(dev);
        /* big buffer */
        dm_writel(DM1105_RLEN, 5 * DM1105_DMA_BYTES);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to