From: sashiko-bot@kernel.org
To: "Kyrie Wu" <kyrie.wu@mediatek.com>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org,
media-ci@linuxtv.org, robh@kernel.org
Subject: Re: [PATCH v17 06/12] media: mediatek: jpeg: fix buffer state update timing
Date: Tue, 22 Sep 2026 09:31:50 +0000 [thread overview]
Message-ID: <20260922093150.C41351F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260922091530.241762-7-kyrie.wu@mediatek.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] media: mtk-jpeg: Use-After-Free in mtk_jpegdec_worker on timeout race
--
commit 44ce2c64fc6b5a268c3679b0da3fbbbb9bc8ce15
Author: Kyrie Wu <kyrie.wu@mediatek.com>
media: mediatek: jpeg: fix buffer state update timing
This commit delays the update of the destination buffer state until after the
decoder has selected a hardware core and resumed its runtime PM state. It also
protects the buffer state update with the hardware spinlock and stops walking
the done queue after completing the next expected frame.
> diff --git a/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c b/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
> index a5a1f6126af73..e152ebae0f219 100644
> --- a/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
> +++ b/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
[ ... ]
> @@ -1773,6 +1767,9 @@ static void mtk_jpegdec_worker(struct work_struct *work)
> msecs_to_jiffies(MTK_JPEG_HW_TIMEOUT_MSEC));
>
> spin_lock_irqsave(&comp_jpeg[hw_id]->hw_lock, flags);
> + jpeg_dst_buf = mtk_jpeg_vb2_to_srcbuf(&dst_buf->vb2_buf);
> + jpeg_dst_buf->curr_ctx = ctx;
> + jpeg_dst_buf->frame_num = ctx->total_frame_num;
[Severity: High]
If mtk_jpegdec_worker() is preempted immediately after schedule_delayed_work(),
but before acquiring the spinlock, could the timeout handler run?
If the timeout handler executes during this window, it could reset the hardware
state to idle and complete the buffers back to userspace (where they might
subsequently be freed).
When the worker thread resumes, would writing to jpeg_dst_buf->curr_ctx and
frame_num result in a use-after-free?
Could the hardware then be programmed to DMA into those potentially unowned
addresses?
> ctx->total_frame_num++;
> mtk_jpeg_dec_reset(comp_jpeg[hw_id]->reg_base);
> mtk_jpeg_dec_set_config(comp_jpeg[hw_id]->reg_base,
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922091530.241762-1-kyrie.wu@mediatek.com?part=6
next prev parent reply other threads:[~2026-09-22 9:31 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 9:15 [PATCH v17 00/12] Enable jpeg enc & dec multi-hardwares for MT8196 Kyrie Wu
2026-09-22 9:15 ` [PATCH v17 01/12] media: mediatek: jpeg: fix jpeg cores' amounts setting Kyrie Wu
2026-09-22 9:28 ` sashiko-bot
2026-09-22 9:15 ` [PATCH v17 02/12] media: mediatek: jpeg: fix jpeg buffer payload size setting Kyrie Wu
2026-09-22 9:27 ` sashiko-bot
2026-09-22 11:40 ` AngeloGioacchino Del Regno
2026-09-22 9:15 ` [PATCH v17 03/12] media: mediatek: jpeg: fix buffer structure size and layout Kyrie Wu
2026-09-22 11:40 ` AngeloGioacchino Del Regno
2026-09-22 9:15 ` [PATCH v17 04/12] media: mediatek: jpeg: Fix buffer completion on multi-core streaming stop Kyrie Wu
2026-09-22 9:27 ` sashiko-bot
2026-09-22 11:40 ` AngeloGioacchino Del Regno
2026-09-22 9:15 ` [PATCH v17 05/12] media: mediatek: jpeg: Fix multi-core clk suspend and resume setting Kyrie Wu
2026-09-22 9:26 ` sashiko-bot
2026-09-22 11:39 ` AngeloGioacchino Del Regno
2026-09-22 9:15 ` [PATCH v17 06/12] media: mediatek: jpeg: fix buffer state update timing Kyrie Wu
2026-09-22 9:31 ` sashiko-bot [this message]
2026-09-22 11:40 ` AngeloGioacchino Del Regno
2026-09-22 9:15 ` [PATCH v17 07/12] media: mediatek: jpeg: fix resolution change event handling in decoder Kyrie Wu
2026-09-22 9:29 ` sashiko-bot
2026-09-22 11:40 ` AngeloGioacchino Del Regno
2026-09-22 9:15 ` [PATCH v17 08/12] media: mediatek: jpeg: fix remove buffer removal timing for multi-core Kyrie Wu
2026-09-22 9:32 ` sashiko-bot
2026-09-22 11:39 ` AngeloGioacchino Del Regno
2026-09-22 9:15 ` [PATCH v17 09/12] media: dt-bindings: mediatek,jpeg: Add mediatek, mt8196-jpgdec compatible Kyrie Wu
2026-09-22 11:39 ` AngeloGioacchino Del Regno
2026-09-22 9:15 ` [PATCH v17 10/12] media: dt-bindings: mediatek,jpeg: Add mediatek, mt8196-jpgenc compatible Kyrie Wu
2026-09-22 11:39 ` AngeloGioacchino Del Regno
2026-09-22 9:15 ` [PATCH v17 11/12] media: mediatek: jpeg: add jpeg compatible Kyrie Wu
2026-09-22 11:39 ` AngeloGioacchino Del Regno
2026-09-22 9:15 ` [PATCH v17 12/12] media: mediatek: jpeg: add jpeg smmu sid setting Kyrie Wu
2026-09-22 9:34 ` sashiko-bot
2026-09-22 11:39 ` AngeloGioacchino Del Regno
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260922093150.C41351F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=kyrie.wu@mediatek.com \
--cc=media-ci@linuxtv.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox