mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Hans Verkuil <hverkuil+cisco@kernel.org>
To: Valery Borovsky <vebohr@gmail.com>,
	mchehab@kernel.org, crope@iki.fi, linux-media@vger.kernel.org
Cc: stable@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure
Date: Wed, 20 May 2026 08:34:58 +0200	[thread overview]
Message-ID: <936ca84b-3c4f-4415-8389-7d065cf18feb@kernel.org> (raw)
In-Reply-To: <20260513055733.146905-1-vebohr@gmail.com>

On 13/05/2026 07:57, Valery Borovsky wrote:
> rtl2832_sdr_start_streaming() calls rtl2832_sdr_alloc_stream_bufs(),
> rtl2832_sdr_alloc_urbs() and rtl2832_sdr_submit_urbs() in sequence and
> shares a single err: label that only unlocks the mutex and returns.
> When alloc_urbs() succeeds but submit_urbs() fails, or when alloc_urbs()
> itself returns -ENOMEM after alloc_stream_bufs() has already succeeded,
> the URBs and/or the coherent DMA stream buffers stay allocated while
> streaming reports failure to vb2. Two latent defects follow on the next
> VIDIOC_STREAMON:
> 
> 1) rtl2832_sdr_alloc_stream_bufs() unconditionally resets dev->buf_num
>    to 0 and overwrites dev->buf_list[]/dev->dma_addr[], permanently
>    leaking the coherent DMA memory allocated by the previous attempt.
> 
> 2) rtl2832_sdr_alloc_urbs() never resets dev->urbs_initialized and only
>    increments it. After a second successful pass urbs_initialized can
>    exceed MAX_BULK_BUFS, so the subsequent rtl2832_sdr_free_urbs() walks
>    from urbs_initialized - 1 down to 0 and reads past the end of
>    dev->urb_list[], passing garbage pointers to usb_free_urb().
> 
> Mirror the teardown that stop_streaming() already performs: on the error
> path call rtl2832_sdr_free_urbs() and rtl2832_sdr_free_stream_bufs()
> before unlocking. Both helpers are idempotent (free_urbs kills and zeros
> urbs_initialized; free_stream_bufs is gated on URB_BUF and clears the
> buf_num counter), so partial-failure paths and the no-allocation paths
> remain safe.
> 
> Issue identified by automated review of the INV-003 series at
> https://sashiko.dev/
> 
> Fixes: 771138920eaf ("[media] rtl2832_sdr: Realtek RTL2832 SDR driver module")
> Cc: stable@vger.kernel.org
> Signed-off-by: Valery Borovsky <vebohr@gmail.com>
> ---
>  drivers/media/dvb-frontends/rtl2832_sdr.c | 6 ++++++
>  1 file changed, 6 insertions(+)
> 
> diff --git a/drivers/media/dvb-frontends/rtl2832_sdr.c b/drivers/media/dvb-frontends/rtl2832_sdr.c
> index 422d1a7b5456..efcef1317cf9 100644
> --- a/drivers/media/dvb-frontends/rtl2832_sdr.c
> +++ b/drivers/media/dvb-frontends/rtl2832_sdr.c
> @@ -900,7 +900,13 @@ static int rtl2832_sdr_start_streaming(struct vb2_queue *vq, unsigned int count)
>  	if (ret)
>  		goto err;
>  
> +	mutex_unlock(&dev->v4l2_lock);
> +
> +	return 0;
> +
>  err:
> +	rtl2832_sdr_free_urbs(dev);
> +	rtl2832_sdr_free_stream_bufs(dev);
>  	mutex_unlock(&dev->v4l2_lock);
>  
>  	return ret;

This patch no longer applies to the next branch of
https://gitlab.freedesktop.org/linux-media/media-committers/

Please rebase and repost.

Regards,

	Hans

  reply	other threads:[~2026-05-20  6:35 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-13  5:57 Valery Borovsky
2026-05-20  6:34 ` Hans Verkuil [this message]
2026-05-23 16:53 ` [PATCH v2] " Valery Borovsky

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=936ca84b-3c4f-4415-8389-7d065cf18feb@kernel.org \
    --to=hverkuil+cisco@kernel.org \
    --cc=crope@iki.fi \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-media@vger.kernel.org \
    --cc=mchehab@kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=vebohr@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®