From: Benjamin Gaignard <benjamin.gaignard@collabora.com>
To: Michael Bommarito <michael.bommarito@gmail.com>,
Hans Verkuil <hverkuil@kernel.org>,
Mauro Carvalho Chehab <mchehab@kernel.org>,
Sakari Ailus <sakari.ailus@linux.intel.com>,
Nicolas Dufresne <nicolas.dufresne@collabora.com>
Cc: Laurent Pinchart <laurent.pinchart@ideasonboard.com>,
Detlev Casanova <detlev.casanova@collabora.com>,
Ezequiel Garcia <ezequiel@vanguardiasur.com.ar>,
Yunfei Dong <yunfei.dong@mediatek.com>,
Jonas Karlman <jonas@kwiboo.se>, Heiko Stuebner <heiko@sntech.de>,
Kees Cook <kees@kernel.org>,
linux-media@vger.kernel.org, linux-rockchip@lists.infradead.org,
linux-mediatek@lists.infradead.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v3 6/9] media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer
Date: Thu, 3 Sep 2026 08:52:10 +0200 [thread overview]
Message-ID: <805fa7a9-bd32-4364-a228-5ff17f22ae56@collabora.com> (raw)
In-Reply-To: <20260617021906.2746743-7-michael.bommarito@gmail.com>
Le 17/06/2026 à 04:19, Michael Bommarito a écrit :
> rockchip_vpu981_av1_dec_set_tile_info() divides context_update_tile_id by
> tile_info->tile_cols and writes one descriptor per tile into the tile_info
> DMA buffer, which holds AV1_MAX_TILES entries; tile_cols and tile_rows
> come from the bitstream. Guard the division against a zero tile_cols by
> initialising the context-update values to zero and computing them only
> when tile_cols is non-zero, and stop the descriptor writes once the
> tile_info buffer is full. The tile geometry written to the hardware
> registers is left unmodified; the per-dimension and total tile bounds are
> enforced by the control validation.
>
> Fixes: 727a400686a2 ("media: verisilicon: Add Rockchip AV1 decoder")
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Benjamin Gaignard <benjamin.gaignard@collabora.com>
> ---
> .../verisilicon/rockchip_vpu981_hw_av1_dec.c | 32 +++++++++++++++----
> 1 file changed, 26 insertions(+), 6 deletions(-)
>
> diff --git a/drivers/media/platform/verisilicon/rockchip_vpu981_hw_av1_dec.c b/drivers/media/platform/verisilicon/rockchip_vpu981_hw_av1_dec.c
> index e4e21ad373233..fd00dbd79fe46 100644
> --- a/drivers/media/platform/verisilicon/rockchip_vpu981_hw_av1_dec.c
> +++ b/drivers/media/platform/verisilicon/rockchip_vpu981_hw_av1_dec.c
> @@ -578,16 +578,30 @@ static void rockchip_vpu981_av1_dec_set_tile_info(struct hantro_ctx *ctx)
> const struct v4l2_av1_tile_info *tile_info = &ctrls->frame->tile_info;
> const struct v4l2_ctrl_av1_tile_group_entry *group_entry =
> ctrls->tile_group_entry;
> - int context_update_y =
> - tile_info->context_update_tile_id / tile_info->tile_cols;
> - int context_update_x =
> - tile_info->context_update_tile_id % tile_info->tile_cols;
> - int context_update_tile_id =
> - context_update_x * tile_info->tile_rows + context_update_y;
> + int context_update_y = 0;
> + int context_update_x = 0;
> + int context_update_tile_id = 0;
> u8 *dst = av1_dec->tile_info.cpu;
> + u8 *dst_end = dst + av1_dec->tile_info.size;
> struct hantro_dev *vpu = ctx->dev;
> int tile0, tile1;
>
> + /*
> + * tile_cols and tile_rows are bounded by the V4L2 control validation
> + * (V4L2_AV1_MAX_TILE_{COLS,ROWS} and V4L2_AV1_MAX_TILE_COUNT). Guard
> + * the divisor here, and keep the descriptor writes within the
> + * AV1_MAX_TILES tile_info buffer below; the register values use the
> + * unmodified tile geometry.
> + */
> + if (tile_info->tile_cols) {
> + context_update_y =
> + tile_info->context_update_tile_id / tile_info->tile_cols;
> + context_update_x =
> + tile_info->context_update_tile_id % tile_info->tile_cols;
> + context_update_tile_id =
> + context_update_x * tile_info->tile_rows + context_update_y;
> + }
> +
> memset(dst, 0, av1_dec->tile_info.size);
>
> for (tile0 = 0; tile0 < tile_info->tile_cols; tile0++) {
> @@ -598,6 +612,10 @@ static void rockchip_vpu981_av1_dec_set_tile_info(struct hantro_ctx *ctx)
> tile_info->height_in_sbs_minus_1[tile1] + 1;
> u32 x0 = tile_info->width_in_sbs_minus_1[tile0] + 1;
>
> + /* Stop once the tile_info descriptor buffer is full. */
> + if (dst + 16 > dst_end)
> + break;
> +
> /* tile size in SB units (width,height) */
> *dst++ = x0;
> *dst++ = 0;
> @@ -622,6 +640,8 @@ static void rockchip_vpu981_av1_dec_set_tile_info(struct hantro_ctx *ctx)
> *dst++ = (end >> 16) & 255;
> *dst++ = (end >> 24) & 255;
> }
> + if (dst + 16 > dst_end)
> + break;
> }
>
> hantro_reg_write(vpu, &av1_multicore_expect_context_update, !!(context_update_x == 0));
_______________________________________________
Linux-rockchip mailing list
Linux-rockchip@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-rockchip
WARNING: multiple messages have this Message-ID (diff)
From: Benjamin Gaignard <benjamin.gaignard@collabora.com>
To: Michael Bommarito <michael.bommarito@gmail.com>,
Hans Verkuil <hverkuil@kernel.org>,
Mauro Carvalho Chehab <mchehab@kernel.org>,
Sakari Ailus <sakari.ailus@linux.intel.com>,
Nicolas Dufresne <nicolas.dufresne@collabora.com>
Cc: Laurent Pinchart <laurent.pinchart@ideasonboard.com>,
Detlev Casanova <detlev.casanova@collabora.com>,
Ezequiel Garcia <ezequiel@vanguardiasur.com.ar>,
Yunfei Dong <yunfei.dong@mediatek.com>,
Jonas Karlman <jonas@kwiboo.se>, Heiko Stuebner <heiko@sntech.de>,
Kees Cook <kees@kernel.org>,
linux-media@vger.kernel.org, linux-rockchip@lists.infradead.org,
linux-mediatek@lists.infradead.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v3 6/9] media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer
Date: Thu, 3 Sep 2026 08:52:10 +0200 [thread overview]
Message-ID: <805fa7a9-bd32-4364-a228-5ff17f22ae56@collabora.com> (raw)
In-Reply-To: <20260617021906.2746743-7-michael.bommarito@gmail.com>
Le 17/06/2026 à 04:19, Michael Bommarito a écrit :
> rockchip_vpu981_av1_dec_set_tile_info() divides context_update_tile_id by
> tile_info->tile_cols and writes one descriptor per tile into the tile_info
> DMA buffer, which holds AV1_MAX_TILES entries; tile_cols and tile_rows
> come from the bitstream. Guard the division against a zero tile_cols by
> initialising the context-update values to zero and computing them only
> when tile_cols is non-zero, and stop the descriptor writes once the
> tile_info buffer is full. The tile geometry written to the hardware
> registers is left unmodified; the per-dimension and total tile bounds are
> enforced by the control validation.
>
> Fixes: 727a400686a2 ("media: verisilicon: Add Rockchip AV1 decoder")
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Benjamin Gaignard <benjamin.gaignard@collabora.com>
> ---
> .../verisilicon/rockchip_vpu981_hw_av1_dec.c | 32 +++++++++++++++----
> 1 file changed, 26 insertions(+), 6 deletions(-)
>
> diff --git a/drivers/media/platform/verisilicon/rockchip_vpu981_hw_av1_dec.c b/drivers/media/platform/verisilicon/rockchip_vpu981_hw_av1_dec.c
> index e4e21ad373233..fd00dbd79fe46 100644
> --- a/drivers/media/platform/verisilicon/rockchip_vpu981_hw_av1_dec.c
> +++ b/drivers/media/platform/verisilicon/rockchip_vpu981_hw_av1_dec.c
> @@ -578,16 +578,30 @@ static void rockchip_vpu981_av1_dec_set_tile_info(struct hantro_ctx *ctx)
> const struct v4l2_av1_tile_info *tile_info = &ctrls->frame->tile_info;
> const struct v4l2_ctrl_av1_tile_group_entry *group_entry =
> ctrls->tile_group_entry;
> - int context_update_y =
> - tile_info->context_update_tile_id / tile_info->tile_cols;
> - int context_update_x =
> - tile_info->context_update_tile_id % tile_info->tile_cols;
> - int context_update_tile_id =
> - context_update_x * tile_info->tile_rows + context_update_y;
> + int context_update_y = 0;
> + int context_update_x = 0;
> + int context_update_tile_id = 0;
> u8 *dst = av1_dec->tile_info.cpu;
> + u8 *dst_end = dst + av1_dec->tile_info.size;
> struct hantro_dev *vpu = ctx->dev;
> int tile0, tile1;
>
> + /*
> + * tile_cols and tile_rows are bounded by the V4L2 control validation
> + * (V4L2_AV1_MAX_TILE_{COLS,ROWS} and V4L2_AV1_MAX_TILE_COUNT). Guard
> + * the divisor here, and keep the descriptor writes within the
> + * AV1_MAX_TILES tile_info buffer below; the register values use the
> + * unmodified tile geometry.
> + */
> + if (tile_info->tile_cols) {
> + context_update_y =
> + tile_info->context_update_tile_id / tile_info->tile_cols;
> + context_update_x =
> + tile_info->context_update_tile_id % tile_info->tile_cols;
> + context_update_tile_id =
> + context_update_x * tile_info->tile_rows + context_update_y;
> + }
> +
> memset(dst, 0, av1_dec->tile_info.size);
>
> for (tile0 = 0; tile0 < tile_info->tile_cols; tile0++) {
> @@ -598,6 +612,10 @@ static void rockchip_vpu981_av1_dec_set_tile_info(struct hantro_ctx *ctx)
> tile_info->height_in_sbs_minus_1[tile1] + 1;
> u32 x0 = tile_info->width_in_sbs_minus_1[tile0] + 1;
>
> + /* Stop once the tile_info descriptor buffer is full. */
> + if (dst + 16 > dst_end)
> + break;
> +
> /* tile size in SB units (width,height) */
> *dst++ = x0;
> *dst++ = 0;
> @@ -622,6 +640,8 @@ static void rockchip_vpu981_av1_dec_set_tile_info(struct hantro_ctx *ctx)
> *dst++ = (end >> 16) & 255;
> *dst++ = (end >> 24) & 255;
> }
> + if (dst + 16 > dst_end)
> + break;
> }
>
> hantro_reg_write(vpu, &av1_multicore_expect_context_update, !!(context_update_x == 0));
next prev parent reply other threads:[~2026-09-03 6:52 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-17 2:18 [PATCH v3 0/9] media: bound stateless HEVC/AV1 tile counts Michael Bommarito
2026-06-17 2:18 ` Michael Bommarito
2026-06-17 2:18 ` [PATCH v3 1/9] media: v4l2-ctrls: validate HEVC " Michael Bommarito
2026-06-17 2:18 ` Michael Bommarito
2026-09-03 6:50 ` Benjamin Gaignard
2026-09-03 6:50 ` Benjamin Gaignard
2026-06-17 2:18 ` [PATCH v3 2/9] media: v4l2-ctrls: validate AV1 " Michael Bommarito
2026-06-17 2:18 ` Michael Bommarito
2026-09-03 6:50 ` Benjamin Gaignard
2026-09-03 6:50 ` Benjamin Gaignard
2026-06-17 2:19 ` [PATCH v3 3/9] media: hevc: add bounded tile-count helpers Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-09-03 6:51 ` Benjamin Gaignard
2026-09-03 6:51 ` Benjamin Gaignard
2026-06-17 2:19 ` [PATCH v3 4/9] media: rkvdec: bound HEVC tile loops and PPS id to the array capacity Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-06-17 2:19 ` [PATCH v3 5/9] media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-09-03 6:51 ` Benjamin Gaignard
2026-09-03 6:51 ` Benjamin Gaignard
2026-06-17 2:19 ` [PATCH v3 6/9] media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-09-03 6:52 ` Benjamin Gaignard [this message]
2026-09-03 6:52 ` Benjamin Gaignard
2026-06-17 2:19 ` [PATCH v3 7/9] media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-09-03 6:53 ` Benjamin Gaignard
2026-09-03 6:53 ` Benjamin Gaignard
2026-06-17 2:19 ` [PATCH v3 8/9] media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-06-17 2:19 ` [PATCH v3 9/9] media: v4l2-ctrls: add KUnit tests for compound control tile validation Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-07-16 1:03 ` [PATCH v3 0/9] media: bound stateless HEVC/AV1 tile counts Nicolas Dufresne
2026-07-16 1:03 ` Nicolas Dufresne
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=805fa7a9-bd32-4364-a228-5ff17f22ae56@collabora.com \
--to=benjamin.gaignard@collabora.com \
--cc=detlev.casanova@collabora.com \
--cc=ezequiel@vanguardiasur.com.ar \
--cc=heiko@sntech.de \
--cc=hverkuil@kernel.org \
--cc=jonas@kwiboo.se \
--cc=kees@kernel.org \
--cc=laurent.pinchart@ideasonboard.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=linux-mediatek@lists.infradead.org \
--cc=linux-rockchip@lists.infradead.org \
--cc=mchehab@kernel.org \
--cc=michael.bommarito@gmail.com \
--cc=nicolas.dufresne@collabora.com \
--cc=sakari.ailus@linux.intel.com \
--cc=yunfei.dong@mediatek.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.