On Mon May 11 20:12:10 2026 +0300, Valery Borovsky wrote:
> The vb2 framework hands buffers to the driver via buf_queue() before
> calling start_streaming().  If start_streaming() returns an error
> without first returning those buffers via vb2_buffer_done(),
> vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
> buffers leak.
> 
> dcmipp_bytecap_start_streaming() returned -EINVAL when the source
> subdevice could not be resolved from the media graph, before
> pm_runtime_resume_and_get() and media_pipeline_start() had been called.
> The remaining error paths already converge on the err_buffer_done
> label, which calls dcmipp_bytecap_all_buffers_done(...,
> VB2_BUF_STATE_QUEUED).  Jump to that label directly: the intermediate
> err_pm_put / err_media_pipeline_stop labels are skipped, which is
> correct because nothing they would undo has happened yet.
> 
> This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
> Return queued buffers on start_streaming() failure").
> 
> Fixes: 28e0f3772296 ("media: stm32-dcmipp: STM32 DCMIPP camera interface 
> driver")
> Cc: [email protected]
> Signed-off-by: Valery Borovsky <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/platform/st/stm32/stm32-dcmipp/dcmipp-bytecap.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

---

diff --git a/drivers/media/platform/st/stm32/stm32-dcmipp/dcmipp-bytecap.c 
b/drivers/media/platform/st/stm32/stm32-dcmipp/dcmipp-bytecap.c
index a42f43d19f9e..f0e809458489 100644
--- a/drivers/media/platform/st/stm32/stm32-dcmipp/dcmipp-bytecap.c
+++ b/drivers/media/platform/st/stm32/stm32-dcmipp/dcmipp-bytecap.c
@@ -401,8 +401,10 @@ static int dcmipp_bytecap_start_streaming(struct vb2_queue 
*vq,
         */
        if (!vcap->s_subdev) {
                pad = media_pad_remote_pad_first(&vcap->vdev.entity.pads[0]);
-               if (!pad || !is_media_entity_v4l2_subdev(pad->entity))
-                       return -EINVAL;
+               if (!pad || !is_media_entity_v4l2_subdev(pad->entity)) {
+                       ret = -EINVAL;
+                       goto err_buffer_done;
+               }
                vcap->s_subdev = media_entity_to_v4l2_subdev(pad->entity);
                vcap->s_subdev_pad_nb = pad->index;
        }
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to