From: "D. Manresa" <dmanresa@gmail.com>
To: Sakari Ailus <sakari.ailus@linux.intel.com>,
Hans de Goede <johannes.goede@oss.qualcomm.com>,
Daniel Scally <dan.scally@ideasonboard.com>
Cc: Mauro Carvalho Chehab <mchehab@kernel.org>,
Fernando Rimoli <fernandorimoli11@gmail.com>,
linux-media@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH v4 1/2] media: ipu-bridge: don't reference the module image from software nodes
Date: Sat, 10 Oct 2026 17:56:25 +0200 [thread overview]
Message-ID: <20261010155626.2766298-2-dmanresa@gmail.com> (raw)
In-Reply-To: <20261010155626.2766298-1-dmanresa@gmail.com>
The software nodes the bridge registers are deliberately never
unregistered, so that a later rebind can reuse them. Nothing reachable
from them may therefore point into the module image, but two properties
still do: the "link-frequencies" values point at cfg->link_freqs in
ipu_supported_sensors[], and the "lens-focus" property name is a string
literal.
Both dangle once the module is unloaded. Re-probing sensor drivers then
read poisoned link frequencies from the surviving nodes and fail:
ov5693: supported link freq 419200000 not found
Copy both into struct ipu_sensor, where the other property names and
values already live.
Assisted-by: LLM
Fixes: 803abec64ef9 ("media: ipu3-cio2: Add cio2-bridge to ipu3-cio2 driver")
Fixes: 68b9bcc8a534 ("media: ipu3-cio2: Add support for instantiating i2c-clients for VCMs")
Signed-off-by: D. Manresa <dmanresa@gmail.com>
---
drivers/media/pci/intel/ipu-bridge.c | 12 +++++++++---
include/media/ipu-bridge.h | 6 ++++++
2 files changed, 15 insertions(+), 3 deletions(-)
diff --git a/drivers/media/pci/intel/ipu-bridge.c b/drivers/media/pci/intel/ipu-bridge.c
index 3739c4a..aea4699 100644
--- a/drivers/media/pci/intel/ipu-bridge.c
+++ b/drivers/media/pci/intel/ipu-bridge.c
@@ -290,6 +290,7 @@ static const struct ipu_property_names prop_names = {
.remote_endpoint = "remote-endpoint",
.link_frequencies = "link-frequencies",
.clock_noncontinuous = "clock-noncontinuous",
+ .lens_focus = "lens-focus",
};
static const char * const ipu_vcm_types[] = {
@@ -623,7 +624,8 @@ static void ipu_bridge_create_fwnode_properties(
sensor->vcm_ref[0] =
SOFTWARE_NODE_REFERENCE(&sensor->swnodes[SWNODE_VCM]);
sensor->dev_properties[3] =
- PROPERTY_ENTRY_REF_ARRAY("lens-focus", sensor->vcm_ref);
+ PROPERTY_ENTRY_REF_ARRAY(names->lens_focus,
+ sensor->vcm_ref);
}
sensor->ep_properties[IPU_BRIDGE_NEXT_PROPERTY(i, EP_BUS_TYPE)] =
@@ -636,11 +638,15 @@ static void ipu_bridge_create_fwnode_properties(
PROPERTY_ENTRY_REF_ARRAY(names->remote_endpoint,
sensor->local_ref);
- if (cfg->nr_link_freqs > 0)
+ if (cfg->nr_link_freqs > 0) {
+ memcpy(sensor->link_freqs, cfg->link_freqs,
+ cfg->nr_link_freqs * sizeof(*sensor->link_freqs));
+
sensor->ep_properties[IPU_BRIDGE_NEXT_PROPERTY(i, EP_LINK_FREQUENCIES)] =
PROPERTY_ENTRY_U64_ARRAY_LEN(names->link_frequencies,
- cfg->link_freqs,
+ sensor->link_freqs,
cfg->nr_link_freqs);
+ }
if (cfg->flags & IPU_BR_FL_CSI2_CLK_NONCONTINUOUS)
sensor->ep_properties[IPU_BRIDGE_NEXT_PROPERTY(i, EP_CLOCK_NONCONTINUOUS)] =
diff --git a/include/media/ipu-bridge.h b/include/media/ipu-bridge.h
index 3ef94c2..7c89fb6 100644
--- a/include/media/ipu-bridge.h
+++ b/include/media/ipu-bridge.h
@@ -136,6 +136,7 @@ struct ipu_property_names {
char remote_endpoint[16];
char link_frequencies[17];
char clock_noncontinuous[20];
+ char lens_focus[11];
};
struct ipu_node_names {
@@ -178,6 +179,11 @@ struct ipu_sensor {
const char *vcm_type;
struct ipu_property_names prop_names;
+ /*
+ * The registered software nodes outlive the module, so the property
+ * values they point at must not live in it.
+ */
+ u64 link_freqs[MAX_NUM_LINK_FREQS];
struct property_entry ep_properties[IPU_BRIDGE_EP_NUM_ENTRIES];
struct property_entry dev_properties[5];
struct property_entry ipu_properties[3];
--
2.43.0
next prev parent reply other threads:[~2026-10-10 15:56 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-10 15:56 [PATCH v4 0/2] media: ipu-bridge: survive module unload and reuse the software nodes on rebind D. Manresa
2026-10-10 15:56 ` D. Manresa [this message]
2026-10-10 15:56 ` [PATCH v4 2/2] media: ipu-bridge: " D. Manresa
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261010155626.2766298-2-dmanresa@gmail.com \
--to=dmanresa@gmail.com \
--cc=dan.scally@ideasonboard.com \
--cc=fernandorimoli11@gmail.com \
--cc=johannes.goede@oss.qualcomm.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
--cc=sakari.ailus@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®