From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AD04C509EF1; Wed, 30 Sep 2026 16:25:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790785527; cv=none; b=lSzfhtGyIp/4S9QnydBDiMYQ4NIDQ/SJNlZLzBbhBhGMX9UBW6AbbvIUwaRYUy7AIiTht18Y6I2s/1vvOxitxv8WVYM3PFMKna5u/Apz6rkEvBAYIriK/8D4OKZ0jPr9HJdLGGM4qTfXEi0Ov9yZ9cW/QDe/O8H4iUw/4r9b3/Y= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790785527; c=relaxed/simple; bh=dDDJgg78NiP6GJne5/sJcIDkxTJxqdDwRjiOtneGlvc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=k+9rSdZ64tuex1THeouuJPuAYJh2dkNiXTa2jl4wdg0TMnssqpmQG1wGF2D0RpVbD8WWeGQib9dGN6aT9IwlsB2RThXFUS4Cowx4l8DWoa7htqmHTSOzEh3J/RuBP7KX5u69hFc93qnq7GSg4x/tnrE3jr1WHYRraXHGTBTAqCI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=qJ1fYZEt; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="qJ1fYZEt" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 368FB1F00893; Wed, 30 Sep 2026 16:25:17 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790785517; bh=irMTv3Ym7ayH3oUidtdza5cB2K0rIbON4iyodZ5I080=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=qJ1fYZEtZkF+Y7NTGlZtCNXFDfaeZut0qauLr+KhfgAdMjbqdHk1JRTACNhrfzGrh KAdayXaUVkp396iJ81yUnEUDlMWRFXH30olgiCBq4W1iVyPSTOTYTLLurE6BOJ39FX 3l7+HPNeN+9ng6iBTDTaK1d4MRFeK8OU5cmkO20Y= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Michael Bommarito , Benjamin Gaignard , Hans Verkuil Subject: [PATCH 6.1 535/982] media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity Date: Wed, 30 Sep 2026 17:21:11 +0200 Message-ID: <20260930152428.262470167@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152416.775402466@linuxfoundation.org> References: <20260930152416.775402466@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.1-stable review patch. If anyone has any objections, please let me know. ------------------ From: Michael Bommarito commit 06236b094c899c22c12ac5097935eb6719293de8 upstream. prepare_tile_info_buffer() writes one entry per tile into the tile_sizes DMA buffer, sized for a grid equal to the PPS uAPI array capacity. Use the bounded v4l2_hevc_pps_num_tile_columns() / v4l2_hevc_pps_num_tile_rows() helpers so the loops stay inside the buffer. Fixes: cb5dd5a0fa51 ("media: hantro: Introduce G2/HEVC decoder") Assisted-by: Claude:claude-opus-4-8 Cc: stable@vger.kernel.org Signed-off-by: Michael Bommarito Reviewed-by: Benjamin Gaignard Signed-off-by: Hans Verkuil Signed-off-by: Greg Kroah-Hartman --- drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) --- a/drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c +++ b/drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c @@ -5,6 +5,8 @@ * Copyright (C) 2020 Safran Passenger Innovations LLC */ +#include + #include "hantro_hw.h" #include "hantro_g2_regs.h" @@ -29,8 +31,8 @@ static void prepare_tile_info_buffer(str const struct v4l2_ctrl_hevc_pps *pps = ctrls->pps; const struct v4l2_ctrl_hevc_sps *sps = ctrls->sps; u16 *p = (u16 *)((u8 *)ctx->hevc_dec.tile_sizes.cpu); - unsigned int num_tile_rows = pps->num_tile_rows_minus1 + 1; - unsigned int num_tile_cols = pps->num_tile_columns_minus1 + 1; + unsigned int num_tile_rows = v4l2_hevc_pps_num_tile_rows(pps); + unsigned int num_tile_cols = v4l2_hevc_pps_num_tile_columns(pps); unsigned int pic_width_in_ctbs, pic_height_in_ctbs; unsigned int max_log2_ctb_size, ctb_size; bool tiles_enabled, uniform_spacing;