[PATCH v2] media: hackrf: defer v4l2_ctrl_auto_cluster() until after error check
From: Rokinthan p
Date: Thu Sep 10 2026 - 08:35:48 EST
In hackrf_probe(), v4l2_ctrl_auto_cluster() is called immediately after
allocating the auto and manual bandwidth controls for both the receiver
and transmitter.
If allocating the master control (dev->rx_bandwidth_auto or
dev->tx_bandwidth_auto) fails, e.g. due to memory allocation failure,
the pointer is NULL and the error is recorded in the control handler.
Calling v4l2_ctrl_auto_cluster() with a NULL master control causes
v4l2_ctrl_cluster() to trigger a WARNING:
ncontrols == 0 || controls[0] == NULL
WARNING: drivers/media/v4l2-core/v4l2-ctrls-core.c:2525 at
v4l2_ctrl_cluster
Fix this by moving the v4l2_ctrl_auto_cluster() invocations down after
checking dev->rx_ctrl_handler.error and dev->tx_ctrl_handler.error.
If control allocation fails, probe cleanly aborts with an error without
attempting to cluster NULL controls.
Fixes: 81774395a8d9 ("[media] hackrf: new driver")
Reported-by: syzbot+cf896de36144391bcde1@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=cf896de36144391bcde1
Signed-off-by: Rohinthan <rokinthanp03@xxxxxxxxx>
---
v1 -> v2: Fix email indentation and whitespace corruption from initial
submission.
drivers/media/usb/hackrf/hackrf.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/media/usb/hackrf/hackrf.c
b/drivers/media/usb/hackrf/hackrf.c
--- a/drivers/media/usb/hackrf/hackrf.c
+++ b/drivers/media/usb/hackrf/hackrf.c
@@ -1427,7 +1427,6 @@ static int hackrf_probe(struct usb_interface *intf,
dev->rx_bandwidth = v4l2_ctrl_new_std(&dev->rx_ctrl_handler,
&hackrf_ctrl_ops_rx, V4L2_CID_RF_TUNER_BANDWIDTH,
1750000, 28000000, 50000, 1750000);
- v4l2_ctrl_auto_cluster(2, &dev->rx_bandwidth_auto, 0, false);
dev->rx_rf_gain = v4l2_ctrl_new_std(&dev->rx_ctrl_handler,
&hackrf_ctrl_ops_rx, V4L2_CID_RF_TUNER_RF_GAIN, 0, 12,
12, 0);
dev->rx_lna_gain = v4l2_ctrl_new_std(&dev->rx_ctrl_handler,
@@ -1439,6 +1438,7 @@ static int hackrf_probe(struct usb_interface *intf,
dev_err(dev->dev, "Could not initialize controls\n");
goto err_v4l2_ctrl_handler_free_rx;
}
+ v4l2_ctrl_auto_cluster(2, &dev->rx_bandwidth_auto, 0, false);
v4l2_ctrl_grab(dev->rx_rf_gain, !hackrf_enable_rf_gain_ctrl);
v4l2_ctrl_handler_setup(&dev->rx_ctrl_handler);
@@ -1450,7 +1450,6 @@ static int hackrf_probe(struct usb_interface *intf,
dev->tx_bandwidth = v4l2_ctrl_new_std(&dev->tx_ctrl_handler,
&hackrf_ctrl_ops_tx, V4L2_CID_RF_TUNER_BANDWIDTH,
1750000, 28000000, 50000, 1750000);
- v4l2_ctrl_auto_cluster(2, &dev->tx_bandwidth_auto, 0, false);
dev->tx_lna_gain = v4l2_ctrl_new_std(&dev->tx_ctrl_handler,
&hackrf_ctrl_ops_tx, V4L2_CID_RF_TUNER_LNA_GAIN, 0, 47,
1, 0);
dev->tx_rf_gain = v4l2_ctrl_new_std(&dev->tx_ctrl_handler,
@@ -1460,6 +1459,7 @@ static int hackrf_probe(struct usb_interface *intf,
dev_err(dev->dev, "Could not initialize controls\n");
goto err_v4l2_ctrl_handler_free_tx;
}
+ v4l2_ctrl_auto_cluster(2, &dev->tx_bandwidth_auto, 0, false);
v4l2_ctrl_grab(dev->tx_rf_gain, !hackrf_enable_rf_gain_ctrl);
v4l2_ctrl_handler_setup(&dev->tx_ctrl_handler);
From: Rohinthan <rokinthanp03@xxxxxxxxx>
Subject: [PATCH v2] media: hackrf: defer v4l2_ctrl_auto_cluster() until after error check
Date: Thu, 10 Sep 2026 17:55:00 +0530
In hackrf_probe(), v4l2_ctrl_auto_cluster() is called immediately after
allocating the auto and manual bandwidth controls for both the receiver
and transmitter.
If allocating the master control (dev->rx_bandwidth_auto or
dev->tx_bandwidth_auto) fails, e.g. due to memory allocation failure,
the pointer is NULL and the error is recorded in the control handler.
Calling v4l2_ctrl_auto_cluster() with a NULL master control causes
v4l2_ctrl_cluster() to trigger a WARNING:
ncontrols == 0 || controls[0] == NULL
WARNING: drivers/media/v4l2-core/v4l2-ctrls-core.c:2525 at v4l2_ctrl_cluster
Fix this by moving the v4l2_ctrl_auto_cluster() invocations down after
checking dev->rx_ctrl_handler.error and dev->tx_ctrl_handler.error.
If control allocation fails, probe cleanly aborts with an error without
attempting to cluster NULL controls.
Fixes: 81774395a8d9 ("[media] hackrf: new driver")
Reported-by: syzbot+cf896de36144391bcde1@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=cf896de36144391bcde1
Signed-off-by: Rohinthan <rokinthanp03@xxxxxxxxx>
---
v1 -> v2: Fix email indentation and whitespace corruption from initial submission.
drivers/media/usb/hackrf/hackrf.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/media/usb/hackrf/hackrf.c b/drivers/media/usb/hackrf/hackrf.c
--- a/drivers/media/usb/hackrf/hackrf.c
+++ b/drivers/media/usb/hackrf/hackrf.c
@@ -1427,7 +1427,6 @@ static int hackrf_probe(struct usb_interface *intf,
dev->rx_bandwidth = v4l2_ctrl_new_std(&dev->rx_ctrl_handler,
&hackrf_ctrl_ops_rx, V4L2_CID_RF_TUNER_BANDWIDTH,
1750000, 28000000, 50000, 1750000);
- v4l2_ctrl_auto_cluster(2, &dev->rx_bandwidth_auto, 0, false);
dev->rx_rf_gain = v4l2_ctrl_new_std(&dev->rx_ctrl_handler,
&hackrf_ctrl_ops_rx, V4L2_CID_RF_TUNER_RF_GAIN, 0, 12, 12, 0);
dev->rx_lna_gain = v4l2_ctrl_new_std(&dev->rx_ctrl_handler,
@@ -1439,6 +1438,7 @@ static int hackrf_probe(struct usb_interface *intf,
dev_err(dev->dev, "Could not initialize controls\n");
goto err_v4l2_ctrl_handler_free_rx;
}
+ v4l2_ctrl_auto_cluster(2, &dev->rx_bandwidth_auto, 0, false);
v4l2_ctrl_grab(dev->rx_rf_gain, !hackrf_enable_rf_gain_ctrl);
v4l2_ctrl_handler_setup(&dev->rx_ctrl_handler);
@@ -1450,7 +1450,6 @@ static int hackrf_probe(struct usb_interface *intf,
dev->tx_bandwidth = v4l2_ctrl_new_std(&dev->tx_ctrl_handler,
&hackrf_ctrl_ops_tx, V4L2_CID_RF_TUNER_BANDWIDTH,
1750000, 28000000, 50000, 1750000);
- v4l2_ctrl_auto_cluster(2, &dev->tx_bandwidth_auto, 0, false);
dev->tx_lna_gain = v4l2_ctrl_new_std(&dev->tx_ctrl_handler,
&hackrf_ctrl_ops_tx, V4L2_CID_RF_TUNER_LNA_GAIN, 0, 47, 1, 0);
dev->tx_rf_gain = v4l2_ctrl_new_std(&dev->tx_ctrl_handler,
@@ -1460,6 +1459,7 @@ static int hackrf_probe(struct usb_interface *intf,
dev_err(dev->dev, "Could not initialize controls\n");
goto err_v4l2_ctrl_handler_free_tx;
}
+ v4l2_ctrl_auto_cluster(2, &dev->tx_bandwidth_auto, 0, false);
v4l2_ctrl_grab(dev->tx_rf_gain, !hackrf_enable_rf_gain_ctrl);
v4l2_ctrl_handler_setup(&dev->tx_ctrl_handler);
--