From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4A2274E3230; Thu, 17 Sep 2026 15:54:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660453; cv=none; b=fFI0s295GxrQnNnjQBOyeeSfDvWPudsfOk60JMvC4czRZ3tOcxXbtV3HGXjG+uuz7aRpCH0mWeUZiNAK9bwXXYMRZi37yc/ICwvieKwXEdwvnvp/36V989U6TArISuwTLrBBZ10YDzGlDlQInzcEEkAKf1j+iti/ZuVg+WgstmM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660453; c=relaxed/simple; bh=KOu2Ne38jE4v2CbSU77D42NBWOWW3yOhCzcOUBAp7/o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=SMsC/iS81gFI5hqjnqVIeVAe5urMu6wSuN6AEozocJuGa5GMyTGPhdsYUeLqL3Jye5NSCKhhFlpzvY+yVeLkEGZY7u2+aXaIW2tjjm6c7a3zCeYuWZvtT7l9UDnhst3huoWdohU6YAjBQpQrGth3dGkbaFbGYMoRF+pcNoAzueQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=besGLjo+; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="besGLjo+" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8FE411F000FF; Thu, 17 Sep 2026 15:54:11 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789660452; bh=AtlrJaRM/VWuzysXBGCAyKEdbpP58zdX9QmioLnlOwE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=besGLjo+7mQE7pckzpGx95SPy1zMIcBHUbhu028cGVGzbzrdu60rvL3PqPvdcIY+N Wnr7ge9WVMJ5cd7+VI3ZkX02zoJ2jSw9A/8nRWBzRquMI44Z86j3TbS804sFWGQfbI OYzDpFXzjHgDVQycC0IM5blkvdJcfKh0NvxV6eDE= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Michael Bommarito , Benjamin Gaignard , Hans Verkuil Subject: [PATCH 7.2 597/733] media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity Date: Thu, 17 Sep 2026 16:15:05 +0100 Message-ID: <20260917151407.330461185@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151350.597953846@linuxfoundation.org> References: <20260917151350.597953846@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Michael Bommarito commit 06236b094c899c22c12ac5097935eb6719293de8 upstream. prepare_tile_info_buffer() writes one entry per tile into the tile_sizes DMA buffer, sized for a grid equal to the PPS uAPI array capacity. Use the bounded v4l2_hevc_pps_num_tile_columns() / v4l2_hevc_pps_num_tile_rows() helpers so the loops stay inside the buffer. Fixes: cb5dd5a0fa51 ("media: hantro: Introduce G2/HEVC decoder") Assisted-by: Claude:claude-opus-4-8 Cc: stable@vger.kernel.org Signed-off-by: Michael Bommarito Reviewed-by: Benjamin Gaignard Signed-off-by: Hans Verkuil Signed-off-by: Greg Kroah-Hartman --- drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) --- a/drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c +++ b/drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c @@ -5,6 +5,8 @@ * Copyright (C) 2020 Safran Passenger Innovations LLC */ +#include + #include "hantro_hw.h" #include "hantro_g2_regs.h" @@ -15,8 +17,8 @@ static void prepare_tile_info_buffer(str const struct v4l2_ctrl_hevc_pps *pps = ctrls->pps; const struct v4l2_ctrl_hevc_sps *sps = ctrls->sps; u16 *p = (u16 *)((u8 *)ctx->hevc_dec.tile_sizes.cpu); - unsigned int num_tile_rows = pps->num_tile_rows_minus1 + 1; - unsigned int num_tile_cols = pps->num_tile_columns_minus1 + 1; + unsigned int num_tile_rows = v4l2_hevc_pps_num_tile_rows(pps); + unsigned int num_tile_cols = v4l2_hevc_pps_num_tile_columns(pps); unsigned int pic_width_in_ctbs, pic_height_in_ctbs; unsigned int max_log2_ctb_size, ctb_size; bool tiles_enabled, uniform_spacing;