From: Niklas Söderlund <[email protected]>

The call to v4l2_async_cleanup() will set sd->asd to NULL so passing it to
notifier->unbind() has no effect and leaves the notifier confused. Call
the unbind() callback prior to cleaning up the subdevice to avoid this.

Signed-off-by: Niklas Söderlund <[email protected]>
Signed-off-by: Sakari Ailus <[email protected]>
Reviewed-by: Sebastian Reichel <[email protected]>
Acked-by: Hans Verkuil <[email protected]>
---
 drivers/media/v4l2-core/v4l2-async.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/media/v4l2-core/v4l2-async.c 
b/drivers/media/v4l2-core/v4l2-async.c
index 21c748bf3a7b..ca281438a0ae 100644
--- a/drivers/media/v4l2-core/v4l2-async.c
+++ b/drivers/media/v4l2-core/v4l2-async.c
@@ -206,11 +206,11 @@ void v4l2_async_notifier_unregister(struct 
v4l2_async_notifier *notifier)
        list_del(&notifier->list);
 
        list_for_each_entry_safe(sd, tmp, &notifier->done, async_list) {
-               v4l2_async_cleanup(sd);
-
                if (notifier->unbind)
                        notifier->unbind(notifier, sd, sd->asd);
 
+               v4l2_async_cleanup(sd);
+
                list_move(&sd->async_list, &subdev_list);
        }
 
@@ -268,11 +268,11 @@ void v4l2_async_unregister_subdev(struct v4l2_subdev *sd)
 
        list_add(&sd->asd->list, &notifier->waiting);
 
-       v4l2_async_cleanup(sd);
-
        if (notifier->unbind)
                notifier->unbind(notifier, sd, sd->asd);
 
+       v4l2_async_cleanup(sd);
+
        mutex_unlock(&list_lock);
 }
 EXPORT_SYMBOL(v4l2_async_unregister_subdev);
-- 
2.11.0

Reply via email to