mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 04:12:04 -04:00
media: lirc: Fix error handling in lirc_register()
[ Upstream commit 4f4098c57e139ad972154077fb45c3e3141555dd ]
When cdev_device_add() failed, calling put_device() to explicitly
release dev->lirc_dev. Otherwise, it could cause the fault of the
reference count.
Found by code review.
Cc: stable@vger.kernel.org
Fixes: a6ddd4fecb ("media: lirc: remove last remnants of lirc kapi")
Signed-off-by: Ma Ke <make24@iscas.ac.cn>
Signed-off-by: Sean Young <sean@mess.org>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
bc35a8cc8a
commit
83fc1f68fb
1 changed files with 5 additions and 4 deletions
|
|
@ -762,11 +762,11 @@ int ir_lirc_register(struct rc_dev *dev)
|
|||
|
||||
cdev_init(&dev->lirc_cdev, &lirc_fops);
|
||||
|
||||
get_device(&dev->dev);
|
||||
|
||||
err = cdev_device_add(&dev->lirc_cdev, &dev->lirc_dev);
|
||||
if (err)
|
||||
goto out_ida;
|
||||
|
||||
get_device(&dev->dev);
|
||||
goto out_put_device;
|
||||
|
||||
switch (dev->driver_type) {
|
||||
case RC_DRIVER_SCANCODE:
|
||||
|
|
@ -790,7 +790,8 @@ int ir_lirc_register(struct rc_dev *dev)
|
|||
|
||||
return 0;
|
||||
|
||||
out_ida:
|
||||
out_put_device:
|
||||
put_device(&dev->lirc_dev);
|
||||
ida_free(&lirc_ida, minor);
|
||||
return err;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue