Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Kyrie Wu" <kyrie.wu@mediatek.com>
Cc: media-ci@linuxtv.org, robh@kernel.org, conor+dt@kernel.org,
	devicetree@vger.kernel.org
Subject: Re: [PATCH v17 07/12] media: mediatek: jpeg: fix resolution change event handling in decoder
Date: Tue, 22 Sep 2026 09:29:23 +0000	[thread overview]
Message-ID: <20260922092924.011931F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260922091530.241762-8-kyrie.wu@mediatek.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] media: mediatek: jpeg: data race in mtk_jpegdec_worker() on format queues
--

commit 35ce87a0072442a39f5ea440c3ef1d674406f548
Author: Kyrie Wu <kyrie.wu@mediatek.com>

media: mediatek: jpeg: fix resolution change event handling in decoder

This commit refines the handling of resolution change events within the
JPEG decoder worker. It reorganizes operations to set up queue data before
signaling a source change and adds an early exit condition if the context is
already in the source change state.

> diff --git a/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c b/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
> index e152ebae0f219..edd9e2d0ab05f 100644
> --- a/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
> +++ b/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
> @@ -1738,11 +1738,15 @@ static void mtk_jpegdec_worker(struct work_struct *work)
>  
>  	if (mtk_jpeg_check_resolution_change(ctx,
>  					     &jpeg_src_buf->dec_param)) {
> -		mtk_jpeg_queue_src_chg_event(ctx);
> +		mtk_jpeg_set_queue_data(ctx, &jpeg_src_buf->dec_param);

[Severity: High]
Does this introduce a data race with concurrent V4L2 ioctl handlers?

The lockless worker thread mtk_jpegdec_worker() appears to be updating the
V4L2 context format queues (ctx->cap_q and ctx->out_q) asynchronously through
mtk_jpeg_set_queue_data() without holding the video device lock.

Concurrent ioctls such as VIDIOC_G_FMT read these queue structures under
the video device lock. For example, in mtk_jpeg_g_fmt_vid_mplane():

    pix_mp->pixelformat = q_data->fmt->fourcc;
    pix_mp->num_planes = q_data->fmt->colplanes;

Could a local userspace application streaming a JPEG that changes
resolution trigger this race while concurrently invoking format-querying
ioctls, potentially exposing inconsistent format fields (like width, height,
and bytesperline) to userspace?

>  		ctx->state = MTK_JPEG_SOURCE_CHANGE;
> +		mtk_jpeg_queue_src_chg_event(ctx);
>  		goto getbuf_fail;
>  	}
>  
> +	if (ctx->state == MTK_JPEG_SOURCE_CHANGE)
> +		goto getbuf_fail;
> +
>  	mtk_jpegdec_set_hw_param(ctx, hw_id, src_buf, dst_buf);
>  	ret = pm_runtime_resume_and_get(comp_jpeg[hw_id]->dev);
>  	if (ret < 0) {

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260922091530.241762-1-kyrie.wu@mediatek.com?part=7

  reply	other threads:[~2026-09-22  9:29 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22  9:15 [PATCH v17 00/12] Enable jpeg enc & dec multi-hardwares for MT8196 Kyrie Wu
2026-09-22  9:15 ` [PATCH v17 01/12] media: mediatek: jpeg: fix jpeg cores' amounts setting Kyrie Wu
2026-09-22  9:28   ` sashiko-bot
2026-09-22  9:15 ` [PATCH v17 02/12] media: mediatek: jpeg: fix jpeg buffer payload size setting Kyrie Wu
2026-09-22  9:27   ` sashiko-bot
2026-09-22 11:40   ` AngeloGioacchino Del Regno
2026-09-22  9:15 ` [PATCH v17 03/12] media: mediatek: jpeg: fix buffer structure size and layout Kyrie Wu
2026-09-22 11:40   ` AngeloGioacchino Del Regno
2026-09-22  9:15 ` [PATCH v17 04/12] media: mediatek: jpeg: Fix buffer completion on multi-core streaming stop Kyrie Wu
2026-09-22  9:27   ` sashiko-bot
2026-09-22 11:40   ` AngeloGioacchino Del Regno
2026-09-22  9:15 ` [PATCH v17 05/12] media: mediatek: jpeg: Fix multi-core clk suspend and resume setting Kyrie Wu
2026-09-22  9:26   ` sashiko-bot
2026-09-22 11:39   ` AngeloGioacchino Del Regno
2026-09-22  9:15 ` [PATCH v17 06/12] media: mediatek: jpeg: fix buffer state update timing Kyrie Wu
2026-09-22  9:31   ` sashiko-bot
2026-09-22 11:40   ` AngeloGioacchino Del Regno
2026-09-22  9:15 ` [PATCH v17 07/12] media: mediatek: jpeg: fix resolution change event handling in decoder Kyrie Wu
2026-09-22  9:29   ` sashiko-bot [this message]
2026-09-22 11:40   ` AngeloGioacchino Del Regno
2026-09-22  9:15 ` [PATCH v17 08/12] media: mediatek: jpeg: fix remove buffer removal timing for multi-core Kyrie Wu
2026-09-22  9:32   ` sashiko-bot
2026-09-22 11:39   ` AngeloGioacchino Del Regno
2026-09-22  9:15 ` [PATCH v17 09/12] media: dt-bindings: mediatek,jpeg: Add mediatek, mt8196-jpgdec compatible Kyrie Wu
2026-09-22 11:39   ` AngeloGioacchino Del Regno
2026-09-22  9:15 ` [PATCH v17 10/12] media: dt-bindings: mediatek,jpeg: Add mediatek, mt8196-jpgenc compatible Kyrie Wu
2026-09-22 11:39   ` AngeloGioacchino Del Regno
2026-09-22  9:15 ` [PATCH v17 11/12] media: mediatek: jpeg: add jpeg compatible Kyrie Wu
2026-09-22 11:39   ` AngeloGioacchino Del Regno
2026-09-22  9:15 ` [PATCH v17 12/12] media: mediatek: jpeg: add jpeg smmu sid setting Kyrie Wu
2026-09-22  9:34   ` sashiko-bot
2026-09-22 11:39   ` AngeloGioacchino Del Regno

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260922092924.011931F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=kyrie.wu@mediatek.com \
    --cc=media-ci@linuxtv.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox