On Mon May 11 20:12:11 2026 +0300, Valery Borovsky wrote:
> The vb2 framework hands buffers to the driver via buf_queue() before
> calling start_streaming().  If start_streaming() returns an error
> without first returning those buffers via vb2_buffer_done(),
> vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued
> buffers leak.
> 
> sun4i_csi_start_streaming() returned -EINVAL when no matching CSI
> format could be found, before any setup (scratch buffer allocation,
> pipeline start) had been performed.  The remaining error paths already
> converge on the err_clear_dma_queue label, which calls
> return_all_buffers(..., VB2_BUF_STATE_QUEUED) under csi->qlock.  Jump
> to that label directly: the intermediate err_disable_device /
> err_disable_pipeline / err_free_scratch_buffer labels are skipped,
> which is correct because nothing they would undo has happened yet.
> 
> This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo:
> Return queued buffers on start_streaming() failure").
> 
> Fixes: 577bbf23b758 ("media: sunxi: Add A10 CSI driver")
> Cc: [email protected]
> Signed-off-by: Valery Borovsky <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

---

diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c 
b/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c
index e911c7f7acc5..4781db21c205 100644
--- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c
+++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c
@@ -234,8 +234,10 @@ static int sun4i_csi_start_streaming(struct vb2_queue *vq, 
unsigned int count)
        int ret;
 
        csi_fmt = sun4i_csi_find_format(&csi->fmt.pixelformat, NULL);
-       if (!csi_fmt)
-               return -EINVAL;
+       if (!csi_fmt) {
+               ret = -EINVAL;
+               goto err_clear_dma_queue;
+       }
 
        dev_dbg(csi->dev, "Starting capture\n");
 
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to