On Mon Jul 27 17:49:27 2026 +0700, Cong Nguyen wrote:
> device_run() allocates an ipu_image_convert_run object and, on the
> success path, hands it to the IPU image conversion core via
> ipu_image_convert_queue(); the run object is then freed asynchronously
> by the completion callback ipu_ic_pp_complete().
>
> However, if ipu_image_convert_queue() fails, the core never takes
> ownership of the run object and the completion callback is never
> invoked. The "err" label finishes the mem2mem job and reports the
> buffers as errored, but never frees the run object that was just
> allocated, leaking it on every queue failure.
>
> Free the run object in the error path. There is no risk of a double
> free: the completion callback only runs after the object was
> successfully queued, which is mutually exclusive with reaching the
> error path. It is also safe for the earlier "goto err" on allocation
> failure, since run is NULL there and kfree(NULL) is a no-op.
>
> Fixes: a8ef0488cc59 ("media: imx: add csc/scaler mem2mem device")
> Cc: [email protected]
> Signed-off-by: Cong Nguyen <[email protected]>
> Signed-off-by: Frank Li <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/staging/media/imx/imx-media-csc-scaler.c | 1 +
1 file changed, 1 insertion(+)
---
diff --git a/drivers/staging/media/imx/imx-media-csc-scaler.c
b/drivers/staging/media/imx/imx-media-csc-scaler.c
index 00fcdd4d0487..359d973d297f 100644
--- a/drivers/staging/media/imx/imx-media-csc-scaler.c
+++ b/drivers/staging/media/imx/imx-media-csc-scaler.c
@@ -147,6 +147,7 @@ err:
v4l2_m2m_buf_done(src_buf, VB2_BUF_STATE_ERROR);
v4l2_m2m_buf_done(dst_buf, VB2_BUF_STATE_ERROR);
v4l2_m2m_job_finish(priv->m2m_dev, ctx->fh.m2m_ctx);
+ kfree(run);
}
/*
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]