From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f172.google.com (mail-pg1-f172.google.com [209.85.215.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0BBA73D16E2 for ; Sat, 8 Aug 2026 11:17:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187845; cv=none; b=kdo2mPCiljLrdFOjcNwzvGLOrqZdqAfNEDrCZ7WbjV+M169Hl76npmFdtaFRiHFZlUSBDQgMDCaPtig0Bd10U/8dG2HjpPyZNZHSARyjjpjHnSvUzmoN/FLbE/I72kJ3PQxBGM15NYKk8igrfV19pRSCFNW3rmkJUvlIJszBiz0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187845; c=relaxed/simple; bh=/o1udNNLV+FNe1R9p8BzEoEJfIqD9mThtLK2mmEohxQ=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Ud8SwCFFLhPeO0fKnG0mXYIsb0aU5/THbHiq71J4iII0Jn8yO8aD0rXoJL5AxeM+yRnFBtnAa6ea1iNO05cHwqU731/FX2SnTNzOBOgQh9pl4MJIFLjCOBsOHdZ02WxQTxs7aiGrB4GIgI4LUa7gZC2/J+/fUvYWTy5RLfz9TY8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=M0ReT1tr; arc=none smtp.client-ip=209.85.215.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="M0ReT1tr" Received: by mail-pg1-f172.google.com with SMTP id 41be03b00d2f7-ca80d708489so218538a12.1 for ; Sat, 08 Aug 2026 04:17:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786187840; x=1786792640; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VegdV0CGVtEAsdoGYq2fWs6TLBlXPmk2Egy9/veY9KE=; b=M0ReT1trpbHUGbvE6ipiIDdU4zdS3ysLx4hoMj5chMA28BJnjH5UFJcKzTUIIXkruZ /CJqS0VEOP5bh0SectkjAbRacELSDSQ8U+SJC0sLbiRgZk9PRxAbtA5V0BwBLguh9XUV Lct2voctfZD/31GGGfm87iXK5wKg7/RdsnCbyfh4EkTNAu8xpfayoS0qAPeKiR2U4ffX CWhcLdwm0UH7LrbFUMsHBn8ntP3qWzbTXKLO2Unv4MmRFxVR0JM3o2kgdeZZ464yKbX2 2qXVNnYqz36WX0qCN0L/mm5EK3aABVBj8s4aPSAwXYIz4bCiDZ/CMUaLlcxer29uYBxH YNyw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786187840; x=1786792640; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VegdV0CGVtEAsdoGYq2fWs6TLBlXPmk2Egy9/veY9KE=; b=k0j2mqpRA60yzYEnxjZdqukRHB1q5WWyD+iT2TuMbzu2muH24Lt3fJbHY+AxM8YvOn q78DSF3krS0yT0jplZgmcFRw7pjKJZG7vmsEmDN8D3Hlryn/FowyNULmR3rux/Jex444 3pYthvjMCtQ+B3/5r2TyIXcG0PStfzovoGrbuzhHER7JGkdfhGhN9KKXbsGAcDnDuoRh icIONn1qAL3XUBssce1aJ6DqPbxzpLyT5iJOR+tyHPe5h4f767EHodPI/TcKCe1/mvMA b6V8+LbZc6CjlXX11h7zqK4I09N2TlUkE91/puaO8B6NjjlQjKt16a5BMCTrFwQcZB6g 9vwA== X-Forwarded-Encrypted: i=1; AHgh+RpZryVCF5NRi/WISS0LcXlTcXqAgFUBb5G6G21zdJktoJRVbdF7DGLMRoyG5YO0N+5KcydvNRKBaoOGCdw=@vger.kernel.org X-Gm-Message-State: AOJu0YwyBnaBJU2kZzP9pmCmjAlhB3m0iONbEsI+i6wMSMgDuby/wzGw hOkKeNoMbM1Sj4NKMOg6La4IYQPfIT0BlSKjyJInWy97onsAhX73lRwK X-Gm-Gg: AR+sD13gfbqVfzqrvGpJ5mAncp+gRr6T6/2nwUzruVV0UBeN7XVtqDrlKN8EZRyMziR hOvL/xESsnhV8n40Mtl1dcOtqdVVhvXPC1jFOL4WMJcNAssg1LYU/qpW0nIw3LmiAvdZGS/t9/0 /UYjUD0leNP9bLBkiV3z/JIF9m6ayKgpYetzTVAeSJrEvRRQkJpCA9+vMOaFY5AKPKjatOhkcfM pncVhuhD7h3AUAlLeQq05F4DA9GfGAQeVNASXzNkMztHgkCNGeHynu/bQabKib6052wpgIualqR jofHDi7BKHlBPtFjbzdUh8ABzqQpApfD6uLBwJjvOmJj3SNTf0Q3zKOmUJuutcNgMHoOAKiEqKZ o1BpLwFfiD1z4bTx7mwxFWKbdTgnpuaQhU4+OmzBTa+ir3E7vBWMRDwXGpn/oOWrsfrxGnHnYli Gxpo2EiWt8W9Khd5QNc2gc0HJAlWYk2hKsj6KGmXvwOjewO01FPW0ceXWyc16XVpkgj/7WwOTrX h2QZA== X-Received: by 2002:a05:6300:141:b0:3c3:750f:3cf9 with SMTP id adf61e73a8af0-3cbd3ac3fbemr6024104637.11.1786187840297; Sat, 08 Aug 2026 04:17:20 -0700 (PDT) Received: from SGN-LDSENG.tasernet.com ([2405:4800:5cc3:11a:1ac0:4dff:fe8b:4a69]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315bebdf796sm17179976eec.22.2026.08.08.04.17.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 04:17:19 -0700 (PDT) From: Cong Nguyen To: Maxime Ripard , Mauro Carvalho Chehab , linux-media@vger.kernel.org Cc: Chen-Yu Tsai , Jernej Skrabec , Samuel Holland , Sakari Ailus , linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, Cong Nguyen , stable@vger.kernel.org Subject: [PATCH v1 2/3] media: sun4i-csi: disable interrupts when stopping streaming Date: Sat, 8 Aug 2026 18:17:09 +0700 Message-Id: X-Mailer: git-send-email 2.25.1 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit sun4i_csi_start_streaming() enables the frame-done interrupt in CSI_INT_EN_REG, but sun4i_csi_stop_streaming() only stops the capture engine (CSI_CPT_CTRL_REG) via sun4i_csi_capture_stop(). It never disables the interrupt source nor synchronizes with the handler. Capture stops at the end of the current frame, so a frame-done interrupt can still fire shortly after stop_streaming() returns. If userspace then closes the device, sun4i_csi_release() calls pm_runtime_put() and the CSI block is powered down (clocks gated, reset asserted). A delayed interrupt handler would then read/write CSI registers on the gated block, which can hang or crash the system. Clear CSI_INT_EN_REG and call synchronize_irq() in stop_streaming(), before returning the active buffers and freeing the scratch buffer, so no handler can run past this point. Store the IRQ number in struct sun4i_csi so it is available here. Fixes: 577bbf23b758 ("media: sunxi: Add A10 CSI driver") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4 Signed-off-by: Cong Nguyen --- drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h | 1 + drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c | 11 +++++++++++ 2 files changed, 12 insertions(+) diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h b/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h index 4e0c2df45d4d..51173faea871 100644 --- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h +++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h @@ -112,6 +112,7 @@ struct sun4i_csi { const struct sun4i_csi_traits *traits; void __iomem *regs; + int irq; struct clk *bus_clk; struct clk *isp_clk; struct clk *ram_clk; diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c b/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c index e911c7f7acc5..da697f39f2bc 100644 --- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c +++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c @@ -354,6 +354,16 @@ static void sun4i_csi_stop_streaming(struct vb2_queue *vq) v4l2_subdev_call(csi->src_subdev, video, s_stream, 0); sun4i_csi_capture_stop(csi); + /* + * Disable the frame done interrupt and wait for the handler to + * finish. A frame may complete right as capture is stopped, so an + * interrupt can still be pending here; without this the handler could + * run after the device is powered down (pm_runtime_put() on release) + * and access registers on a gated block. + */ + writel(0, csi->regs + CSI_INT_EN_REG); + synchronize_irq(csi->irq); + /* Release all active buffers */ spin_lock_irqsave(&csi->qlock, flags); return_all_buffers(csi, VB2_BUF_STATE_ERROR); @@ -438,6 +448,7 @@ int sun4i_csi_dma_register(struct sun4i_csi *csi, int irq) dev_err(csi->dev, "Couldn't register our interrupt\n"); goto err_unregister_device; } + csi->irq = irq; return 0; -- 2.25.1