From: Benjamin Gaignard <benjamin.gaignard@collabora.com>
To: Michael Bommarito <michael.bommarito@gmail.com>,
Hans Verkuil <hverkuil@kernel.org>,
Mauro Carvalho Chehab <mchehab@kernel.org>,
Sakari Ailus <sakari.ailus@linux.intel.com>,
Nicolas Dufresne <nicolas.dufresne@collabora.com>
Cc: Laurent Pinchart <laurent.pinchart@ideasonboard.com>,
Detlev Casanova <detlev.casanova@collabora.com>,
Ezequiel Garcia <ezequiel@vanguardiasur.com.ar>,
Yunfei Dong <yunfei.dong@mediatek.com>,
Jonas Karlman <jonas@kwiboo.se>, Heiko Stuebner <heiko@sntech.de>,
Kees Cook <kees@kernel.org>,
linux-media@vger.kernel.org, linux-rockchip@lists.infradead.org,
linux-mediatek@lists.infradead.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v3 2/9] media: v4l2-ctrls: validate AV1 tile counts
Date: Thu, 3 Sep 2026 08:50:49 +0200 [thread overview]
Message-ID: <e56455f5-2213-49d5-9cd0-ab62f3b6edcc@collabora.com> (raw)
In-Reply-To: <20260617021906.2746743-3-michael.bommarito@gmail.com>
Le 17/06/2026 à 04:18, Michael Bommarito a écrit :
> The stateless AV1 decoders use tile_info.tile_cols and tile_rows as loop
> bounds and as indices into the mi_*_starts[] and *_in_sbs_minus_1[]
> arrays, as the divisor for context_update_tile_id, and their product
> bounds the per-tile descriptor buffers, but std_validate_compound() does
> not bound these u8 fields. Reject a V4L2_CTRL_TYPE_AV1_FRAME whose
> tile_cols or tile_rows exceeds V4L2_AV1_MAX_TILE_COLS / _ROWS, or whose
> product exceeds V4L2_AV1_MAX_TILE_COUNT. A zero tile count is left to the
> consuming driver so the zero-initialised control that existing userspace
> submits is still accepted.
>
> Fixes: 9de30f579980 ("media: Add AV1 uAPI")
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Benjamin Gaignard <benjamin.gaignard@collabora.com>
> ---
> drivers/media/v4l2-core/v4l2-ctrls-core.c | 20 ++++++++++++++++++++
> 1 file changed, 20 insertions(+)
>
> diff --git a/drivers/media/v4l2-core/v4l2-ctrls-core.c b/drivers/media/v4l2-core/v4l2-ctrls-core.c
> index 6d478e1a5ef22..fb20ad13dfec7 100644
> --- a/drivers/media/v4l2-core/v4l2-ctrls-core.c
> +++ b/drivers/media/v4l2-core/v4l2-ctrls-core.c
> @@ -790,10 +790,30 @@ static int validate_av1_film_grain(struct v4l2_ctrl_av1_film_grain *fg)
> return 0;
> }
>
> +static int validate_av1_tile_info(struct v4l2_av1_tile_info *t)
> +{
> + /*
> + * tile_cols and tile_rows index the per-tile descriptor arrays and
> + * bound the tile loops in the stateless AV1 drivers; the product
> + * bounds the total tile descriptor count.
> + */
> + if (t->tile_cols > V4L2_AV1_MAX_TILE_COLS ||
> + t->tile_rows > V4L2_AV1_MAX_TILE_ROWS)
> + return -EINVAL;
> +
> + if ((u32)t->tile_cols * t->tile_rows > V4L2_AV1_MAX_TILE_COUNT)
> + return -EINVAL;
> +
> + return 0;
> +}
> +
> static int validate_av1_frame(struct v4l2_ctrl_av1_frame *f)
> {
> int ret = 0;
>
> + ret = validate_av1_tile_info(&f->tile_info);
> + if (ret)
> + return ret;
> ret = validate_av1_quantization(&f->quantization);
> if (ret)
> return ret;
_______________________________________________
Linux-rockchip mailing list
Linux-rockchip@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-rockchip
WARNING: multiple messages have this Message-ID (diff)
From: Benjamin Gaignard <benjamin.gaignard@collabora.com>
To: Michael Bommarito <michael.bommarito@gmail.com>,
Hans Verkuil <hverkuil@kernel.org>,
Mauro Carvalho Chehab <mchehab@kernel.org>,
Sakari Ailus <sakari.ailus@linux.intel.com>,
Nicolas Dufresne <nicolas.dufresne@collabora.com>
Cc: Laurent Pinchart <laurent.pinchart@ideasonboard.com>,
Detlev Casanova <detlev.casanova@collabora.com>,
Ezequiel Garcia <ezequiel@vanguardiasur.com.ar>,
Yunfei Dong <yunfei.dong@mediatek.com>,
Jonas Karlman <jonas@kwiboo.se>, Heiko Stuebner <heiko@sntech.de>,
Kees Cook <kees@kernel.org>,
linux-media@vger.kernel.org, linux-rockchip@lists.infradead.org,
linux-mediatek@lists.infradead.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v3 2/9] media: v4l2-ctrls: validate AV1 tile counts
Date: Thu, 3 Sep 2026 08:50:49 +0200 [thread overview]
Message-ID: <e56455f5-2213-49d5-9cd0-ab62f3b6edcc@collabora.com> (raw)
In-Reply-To: <20260617021906.2746743-3-michael.bommarito@gmail.com>
Le 17/06/2026 à 04:18, Michael Bommarito a écrit :
> The stateless AV1 decoders use tile_info.tile_cols and tile_rows as loop
> bounds and as indices into the mi_*_starts[] and *_in_sbs_minus_1[]
> arrays, as the divisor for context_update_tile_id, and their product
> bounds the per-tile descriptor buffers, but std_validate_compound() does
> not bound these u8 fields. Reject a V4L2_CTRL_TYPE_AV1_FRAME whose
> tile_cols or tile_rows exceeds V4L2_AV1_MAX_TILE_COLS / _ROWS, or whose
> product exceeds V4L2_AV1_MAX_TILE_COUNT. A zero tile count is left to the
> consuming driver so the zero-initialised control that existing userspace
> submits is still accepted.
>
> Fixes: 9de30f579980 ("media: Add AV1 uAPI")
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Benjamin Gaignard <benjamin.gaignard@collabora.com>
> ---
> drivers/media/v4l2-core/v4l2-ctrls-core.c | 20 ++++++++++++++++++++
> 1 file changed, 20 insertions(+)
>
> diff --git a/drivers/media/v4l2-core/v4l2-ctrls-core.c b/drivers/media/v4l2-core/v4l2-ctrls-core.c
> index 6d478e1a5ef22..fb20ad13dfec7 100644
> --- a/drivers/media/v4l2-core/v4l2-ctrls-core.c
> +++ b/drivers/media/v4l2-core/v4l2-ctrls-core.c
> @@ -790,10 +790,30 @@ static int validate_av1_film_grain(struct v4l2_ctrl_av1_film_grain *fg)
> return 0;
> }
>
> +static int validate_av1_tile_info(struct v4l2_av1_tile_info *t)
> +{
> + /*
> + * tile_cols and tile_rows index the per-tile descriptor arrays and
> + * bound the tile loops in the stateless AV1 drivers; the product
> + * bounds the total tile descriptor count.
> + */
> + if (t->tile_cols > V4L2_AV1_MAX_TILE_COLS ||
> + t->tile_rows > V4L2_AV1_MAX_TILE_ROWS)
> + return -EINVAL;
> +
> + if ((u32)t->tile_cols * t->tile_rows > V4L2_AV1_MAX_TILE_COUNT)
> + return -EINVAL;
> +
> + return 0;
> +}
> +
> static int validate_av1_frame(struct v4l2_ctrl_av1_frame *f)
> {
> int ret = 0;
>
> + ret = validate_av1_tile_info(&f->tile_info);
> + if (ret)
> + return ret;
> ret = validate_av1_quantization(&f->quantization);
> if (ret)
> return ret;
next prev parent reply other threads:[~2026-09-03 6:51 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-17 2:18 [PATCH v3 0/9] media: bound stateless HEVC/AV1 tile counts Michael Bommarito
2026-06-17 2:18 ` Michael Bommarito
2026-06-17 2:18 ` [PATCH v3 1/9] media: v4l2-ctrls: validate HEVC " Michael Bommarito
2026-06-17 2:18 ` Michael Bommarito
2026-09-03 6:50 ` Benjamin Gaignard
2026-09-03 6:50 ` Benjamin Gaignard
2026-06-17 2:18 ` [PATCH v3 2/9] media: v4l2-ctrls: validate AV1 " Michael Bommarito
2026-06-17 2:18 ` Michael Bommarito
2026-09-03 6:50 ` Benjamin Gaignard [this message]
2026-09-03 6:50 ` Benjamin Gaignard
2026-06-17 2:19 ` [PATCH v3 3/9] media: hevc: add bounded tile-count helpers Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-09-03 6:51 ` Benjamin Gaignard
2026-09-03 6:51 ` Benjamin Gaignard
2026-06-17 2:19 ` [PATCH v3 4/9] media: rkvdec: bound HEVC tile loops and PPS id to the array capacity Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-06-17 2:19 ` [PATCH v3 5/9] media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-09-03 6:51 ` Benjamin Gaignard
2026-09-03 6:51 ` Benjamin Gaignard
2026-06-17 2:19 ` [PATCH v3 6/9] media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-09-03 6:52 ` Benjamin Gaignard
2026-09-03 6:52 ` Benjamin Gaignard
2026-06-17 2:19 ` [PATCH v3 7/9] media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-09-03 6:53 ` Benjamin Gaignard
2026-09-03 6:53 ` Benjamin Gaignard
2026-06-17 2:19 ` [PATCH v3 8/9] media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-06-17 2:19 ` [PATCH v3 9/9] media: v4l2-ctrls: add KUnit tests for compound control tile validation Michael Bommarito
2026-06-17 2:19 ` Michael Bommarito
2026-07-16 1:03 ` [PATCH v3 0/9] media: bound stateless HEVC/AV1 tile counts Nicolas Dufresne
2026-07-16 1:03 ` Nicolas Dufresne
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e56455f5-2213-49d5-9cd0-ab62f3b6edcc@collabora.com \
--to=benjamin.gaignard@collabora.com \
--cc=detlev.casanova@collabora.com \
--cc=ezequiel@vanguardiasur.com.ar \
--cc=heiko@sntech.de \
--cc=hverkuil@kernel.org \
--cc=jonas@kwiboo.se \
--cc=kees@kernel.org \
--cc=laurent.pinchart@ideasonboard.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=linux-mediatek@lists.infradead.org \
--cc=linux-rockchip@lists.infradead.org \
--cc=mchehab@kernel.org \
--cc=michael.bommarito@gmail.com \
--cc=nicolas.dufresne@collabora.com \
--cc=sakari.ailus@linux.intel.com \
--cc=yunfei.dong@mediatek.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.