From: sashiko-bot@kernel.org
To: "Kyrie Wu" <kyrie.wu@mediatek.com>
Cc: media-ci@linuxtv.org, conor+dt@kernel.org, robh@kernel.org,
devicetree@vger.kernel.org
Subject: Re: [PATCH v8 14/14] media: mediatek: decoder: support av1 extend vsi
Date: Sat, 10 Oct 2026 08:51:31 +0000 [thread overview]
Message-ID: <sashiko-outbox-166378@kernel.org> (raw)
In-Reply-To: <1ed11835bd1833066e162035a2529eda1304edcd.1791619743.git.kyrie.wu@mediatek.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] media: Out-of-bounds write to VPU firmware memory due to oversized memcpy
--
commit 482da53176ed6a6bd943ba24dd065fc679bf7158
Author: Kyrie Wu <kyrie.wu@mediatek.com>
media: mediatek: decoder: support av1 extend vsi
The patch expands the AV1 VSI state structure to include tile group
information to support the extended architecture. It also updates the
initialization routine to allow smaller shared memory buffers when
running on non-extended firmware.
> diff --git a/drivers/media/platform/mediatek/vcodec/decoder/vdec/vdec_av1_req_lat_if.c b/drivers/media/platform/mediatek/vcodec/decoder/vdec/vdec_av1_req_lat_if.c
> index 14639098fd463..1ef561dae18c7 100644
> --- a/drivers/media/platform/mediatek/vcodec/decoder/vdec/vdec_av1_req_lat_if.c
> +++ b/drivers/media/platform/mediatek/vcodec/decoder/vdec/vdec_av1_req_lat_if.c
> @@ -665,6 +670,8 @@ struct vdec_av1_slice_vsi {
> struct vdec_av1_slice_frame frame;
> struct vdec_av1_slice_state state;
> u32 cur_lst_tile_id;
> + struct vdec_av1_slice_tile_group tile_group;
> + unsigned int reserved[4];
> };
[ ... ]
> @@ -1942,9 +1978,18 @@ static int vdec_av1_slice_init(struct mtk_vcodec_dec_ctx *ctx)
> goto error_vsi;
> }
>
> - if (vsi->vsi_size != sizeof(struct vdec_av1_slice_vsi))
> - mtk_vdec_err(ctx, "remote vsi size 0x%x mismatch! expected: 0x%zx\n",
> - vsi->vsi_size, sizeof(struct vdec_av1_slice_vsi));
> + if (IS_VDEC_SUPPORT_EXT(ctx->dev->dec_capability)) {
> + vsi_size = sizeof(struct vdec_av1_slice_vsi);
> + vsi->iq_table_size = AV1_IQ_TABLE_SIZE;
> + vsi->cdf_table_size = AV1_CDF_SIZE;
> + }
> +
> + if (vsi->vsi_size != vsi_size) {
> + mtk_vdec_err(ctx, "remote vsi size 0x%x mismatch! expected: 0x%x\n",
> + vsi->vsi_size, vsi_size);
> + ret = -EINVAL;
> + goto error_vsi;
> + }
[Severity: Critical]
This correctly enforces that older firmware provides a 0xD50-byte buffer for
the non-extended architecture.
However, since struct vdec_av1_slice_vsi was expanded with tile_group,
does vdec_av1_slice_vsi_to_remote() now copy too much data?
vdec_av1_slice_vsi_to_remote() {
memcpy(remote_vsi, vsi, sizeof(*vsi));
}
Since sizeof(*vsi) evaluates to the new, enlarged compile-time size of the
struct, will this unconditionally write ~7.5KB of data into the 0xD50
(3.4KB) firmware buffer when decoding on non-extended hardware?
Could this out-of-bounds write corrupt adjacent data in the VPU shared
memory or firmware SRAM?
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1791619742.git.kyrie.wu@mediatek.com?part=14
prev parent reply other threads:[~2026-10-10 8:51 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-10 8:35 [PATCH v8 00/14] media: mediatek: vcodec: support video decoder in mt8196 Kyrie Wu
2026-10-10 8:36 ` [PATCH v8 01/14] media: mediatek: vcodec: support vcp architecture Kyrie Wu
2026-10-10 8:36 ` [PATCH v8 02/14] media: mediatek: vcodec: add driver to support vcp Kyrie Wu
2026-10-10 8:53 ` sashiko-bot
2026-10-10 8:36 ` [PATCH v8 03/14] media: mediatek: vcodec: add driver to support vcp encoder Kyrie Wu
2026-10-10 8:59 ` sashiko-bot
2026-10-10 8:36 ` [PATCH v8 04/14] media: mediatek: vcodec: get different firmware ipi id Kyrie Wu
2026-10-10 8:56 ` sashiko-bot
2026-10-10 8:36 ` [PATCH v8 05/14] media: mediatek: vcodec: get share memory address Kyrie Wu
2026-10-10 8:56 ` sashiko-bot
2026-10-10 8:36 ` [PATCH v8 06/14] media: mediatek: vcodec: add debug information Kyrie Wu
2026-10-10 8:48 ` sashiko-bot
2026-10-10 8:36 ` [PATCH v8 07/14] media: mediatek: vcodec: send share memory address to vcp Kyrie Wu
2026-10-10 8:46 ` sashiko-bot
2026-10-10 8:36 ` [PATCH v8 08/14] dt-bindings: media: mediatek,vcodec-subdev-decoder: Add MT8196 Kyrie Wu
2026-10-10 8:36 ` [PATCH v8 09/14] media: mediatek: vcodec: add decoder compatible to support mt8196 Kyrie Wu
2026-10-10 8:36 ` [PATCH v8 10/14] media: mediatek: vcodec: define MT8196 vcodec levels Kyrie Wu
2026-10-10 8:36 ` [PATCH v8 11/14] media: mediatek: vcodec: support 36bit iova address Kyrie Wu
2026-10-10 8:36 ` [PATCH v8 12/14] media: mediatek: vcodec: clean xpc status Kyrie Wu
2026-10-10 8:50 ` sashiko-bot
2026-10-10 8:36 ` [PATCH v8 13/14] media: mediatek: decoder: fill av1 buffer size with picinfo Kyrie Wu
2026-10-10 8:57 ` sashiko-bot
2026-10-10 8:36 ` [PATCH v8 14/14] media: mediatek: decoder: support av1 extend vsi Kyrie Wu
2026-10-10 8:51 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-166378@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=kyrie.wu@mediatek.com \
--cc=media-ci@linuxtv.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox