Linux Media Controller development
 help / color / mirror / Atom feed
* [BUG] media: smipcie: panic on DVB feed restart
@ 2026-09-27 11:16 linux-media
  0 siblings, 0 replies; only message in thread
From: linux-media @ 2026-09-27 11:16 UTC (permalink / raw)
  To: linux-media; +Cc: mchehab, nibble.max

[-- Attachment #1: Type: text/plain, Size: 3286 bytes --]

Hi,

Restarting VDR 2.8.2 with two DVBSky S952 V3 cards (1ade:3038,
4254:0552) caused this panic on Debian 6.12.107-1, x86-64:

  #PF: supervisor read access in kernel mode
  RIP: dvb_dmx_swfilter_packets+0x5d/0x90 [dvb_core]
  Call Trace:
   smi_dma_xfer+0x154/0x210 [smipcie]
   process_one_work+0x177/0x330
   bh_worker+0x17b/0x1a0
  Kernel panic - not syncing: Fatal exception in interrupt

The kernel was not tainted; smipcie was unmodified. VDR has local
userspace changes. A redacted panic trace is attached. The diagnostic
restart script is
available on request; there is no standalone mainline reproducer.

In drivers/media/pci/smipcie/smipcie-main.c, smi_start_feed() queues
work with the previous _int_status. This may process a stale completion
on restart; the exact IRQ sequence was not captured. smi_dma_xfer()
also accepts lengths exceeding its 192,512-byte buffer. A zero length
register is interpreted as 4 MiB and passed to the demux unchecked.

The change below clears the saved status, enables work before IRQ/DMA,
and rejects oversized lengths. The same logic, built for the Debian
kernel, passed ten service restarts and a reboot. A stubbed function
test over all 22-bit lengths passed without oversized demux calls;
it does not test IRQ concurrency.

The diff is against mainline fd179f8a05be3ccae366b9b96e176b51fbe54aab,
where both paths remain. This mainline adaptation has not been built
or hardware-tested.

Assisted-by: LLM

diff --git a/drivers/media/pci/smipcie/smipcie-main.c
b/drivers/media/pci/smipcie/smipcie-main.c
--- a/drivers/media/pci/smipcie/smipcie-main.c
+++ b/drivers/media/pci/smipcie/smipcie-main.c
@@ -310,8 +310,15 @@
 				"DMA CH0 engine complete length mismatched,
finish data=%d !\n",
 				finishedData);
 		}
-		dvb_dmx_swfilter_packets(&port->demux,
-			port->cpu_addr[0], (finishedData / 188));
+		/* Reject lengths exceeding the DMA buffer. */
+		if (finishedData > SMI_TS_DMA_BUF_SIZE)
+			dev_warn_ratelimited(&dev->pci_dev->dev,
+					     "DMA CH0 invalid length %u,
dropping completion\n",
+					     finishedData);
+		else
+			dvb_dmx_swfilter_packets(&port->demux,
+						 port->cpu_addr[0],
+						 finishedData / 188);
 		/*dvb_dmx_swfilter(&port->demux,
 			port->cpu_addr[0], finishedData);*/
 	}
@@ -333,8 +340,15 @@
 				"DMA CH1 engine complete length mismatched,
finish data=%d !\n",
 				finishedData);
 		}
-		dvb_dmx_swfilter_packets(&port->demux,
-			port->cpu_addr[1], (finishedData / 188));
+		/* Reject lengths exceeding the DMA buffer. */
+		if (finishedData > SMI_TS_DMA_BUF_SIZE)
+			dev_warn_ratelimited(&dev->pci_dev->dev,
+					     "DMA CH1 invalid length %u,
dropping completion\n",
+					     finishedData);
+		else
+			dvb_dmx_swfilter_packets(&port->demux,
+						 port->cpu_addr[1],
+						 finishedData / 188);
 		/*dvb_dmx_swfilter(&port->demux,
 			port->cpu_addr[1], finishedData);*/
 	}
@@ -821,9 +835,11 @@
 	if (port->users++ == 0) {
 		dmaManagement = smi_config_DMA(port);
 		smi_port_clearInterrupt(port);
+		/* Clear stale status; let the IRQ queue work. */
+		port->_int_status = 0;
+		enable_work(&port->bh_work);
 		smi_port_enableInterrupt(port);
 		smi_write(port->DMA_MANAGEMENT, dmaManagement);
-		enable_and_queue_work(system_bh_wq, &port->bh_work);
 	}
 	return port->users;
 }

[-- Attachment #2: panic.txt --]
[-- Type: text/plain, Size: 4839 bytes --]

Redacted netconsole excerpt. Host model/BIOS, UID/PID and the
unrelated module inventory are omitted. Fault registers and trace
are preserved; the original capture is retained locally.

[   97.726900] VDR_DIAGNOSTIC_SERVICE_RESTART_BEGIN
[  101.991897] BUG: unable to handle page fault for address: ffffcbce408e4000
[  101.991940] #PF: supervisor read access in kernel mode
[  101.991955] #PF: error_code(0x0000) - not-present page
[  101.991968] PGD 100000067 P4D 100000067 PUD 1001f5067 PMD 107ec0067 PTE 0
[  101.991993] Oops: Oops: 0000 [#1] PREEMPT SMP PTI
[  101.992010] CPU: 3 UID: [omitted] PID: [omitted] Comm: vdr Not tainted 6.12.107+deb13-amd64 #1  Debian 6.12.107-1
[host model and BIOS omitted]
[  101.992046] RIP: 0010:dvb_dmx_swfilter_packets+0x5d/0x90 [dvb_core]
[  101.992089] Code: 49 8d 6d ff eb 24 66 66 2e 0f 1f 84 00 00 00 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 90 48 81 c3 bc 00 00 00 48 83 ed 01 72 1d <80> 3b 47 75 ee 48 89 de 4c 89 e7 48 81 c3 bc 00 00 00 e8 7c f9 ff
[  101.992110] RSP: 0018:ffffcbce401a0ea8 EFLAGS: 00010002
[  101.992125] RAX: ffff897c034505c8 RBX: ffffcbce408e4000 RCX: 0000000000000000
[  101.992139] RDX: ffff897c034505c8 RSI: ffffcbce408e3f44 RDI: ffff897c03450418
[  101.992152] RBP: 0000000000005325 R08: 0000000000000000 R09: 0000000000000000
[  101.992165] R10: 0000000000000001 R11: 0000000000000000 R12: ffff897c03450418
[  101.992178] R13: 0000000000005726 R14: 0000000000000246 R15: ffff897c034506c8
[  101.992192] FS:  00007fc3fe66bf40(0000) GS:ffff897d17b80000(0000) knlGS:0000000000000000
[  101.992207] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  101.992221] CR2: ffffcbce408e4000 CR3: 0000000106388003 CR4: 00000000001726f0
[  101.992236] Call Trace:
[  101.992250]  <IRQ>
[  101.992264]  smi_dma_xfer+0x154/0x210 [smipcie]
[  101.992283]  process_one_work+0x177/0x330
[  101.992308]  bh_worker+0x17b/0x1a0
[  101.992327]  tasklet_action+0x10/0x30
[  101.992343]  handle_softirqs+0xcf/0x280
[  101.992358]  ? __pfx_read_tsc+0x10/0x10
[  101.992373]  do_softirq.part.0+0x3b/0x60
[  101.992387]  </IRQ>
[  101.992396]  <TASK>
[  101.992405]  __local_bh_enable_ip+0x60/0x70
[  101.992420]  fpu_clone+0xf8/0x400
[  101.992440]  copy_thread+0x14d/0x2a0
[  101.992457]  copy_process+0x1c47/0x2740
[  101.992476]  ? __alloc_pages_noprof+0x16b/0x310
[  101.992494]  kernel_clone+0xbd/0x440
[  101.992511]  __do_sys_clone3+0xe4/0x130
[  101.992532]  do_syscall_64+0x87/0x1b0
[  101.992549]  ? handle_mm_fault+0x1bb/0x2c0
[  101.992566]  ? do_user_addr_fault+0x36c/0x620
[  101.992582]  ? arch_exit_to_user_mode_prepare.isra.0+0x16/0xa0
[  101.992598]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
[  101.992617] RIP: 0033:0x7fc3fe22c529
[  101.992654] Code: 90 b8 01 00 00 00 b9 01 00 00 00 eb ec 0f 1f 40 00 b8 ea ff ff ff 48 85 ff 74 28 48 85 d2 74 23 49 89 c8 b8 b3 01 00 00 0f 05 <48> 85 c0 7c 14 74 01 c3 31 ed 4c 89 c7 ff d2 48 89 c7 b8 3c 00 00
[  101.992674] RSP: 002b:00007ffeca7f25e8 EFLAGS: 00000202 ORIG_RAX: 00000000000001b3
[  101.992691] RAX: ffffffffffffffda RBX: 00007fc3fe1ae620 RCX: 00007fc3fe22c529
[  101.992705] RDX: 00007fc3fe1ae620 RSI: 0000000000000058 RDI: 00007ffeca7f2640
[  101.992717] RBP: 00007fc3d0ff96c0 R08: 00007fc3d0ff96c0 R09: 00007ffeca7f2737
[  101.992730] R10: 0000000000000008 R11: 0000000000000202 R12: fffffffffffffe90
[  101.992743] R13: 0000000000000000 R14: 00007ffeca7f2640 R15: 00007fc3d07f9000
[  101.992760]  </TASK>
[module inventory omitted]
[  101.993088] CR2: ffffcbce408e4000
[  101.993101] ---[ end trace 0000000000000000 ]---
[  101.993113] RIP: 0010:dvb_dmx_swfilter_packets+0x5d/0x90 [dvb_core]
[  101.993146] Code: 49 8d 6d ff eb 24 66 66 2e 0f 1f 84 00 00 00 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 90 48 81 c3 bc 00 00 00 48 83 ed 01 72 1d <80> 3b 47 75 ee 48 89 de 4c 89 e7 48 81 c3 bc 00 00 00 e8 7c f9 ff
[  101.993166] RSP: 0018:ffffcbce401a0ea8 EFLAGS: 00010002
[  101.993180] RAX: ffff897c034505c8 RBX: ffffcbce408e4000 RCX: 0000000000000000
[  101.993193] RDX: ffff897c034505c8 RSI: ffffcbce408e3f44 RDI: ffff897c03450418
[  101.993206] RBP: 0000000000005325 R08: 0000000000000000 R09: 0000000000000000
[  101.993219] R10: 0000000000000001 R11: 0000000000000000 R12: ffff897c03450418
[  101.993232] R13: 0000000000005726 R14: 0000000000000246 R15: ffff897c034506c8
[  101.993245] FS:  00007fc3fe66bf40(0000) GS:ffff897d17b80000(0000) knlGS:0000000000000000
[  101.993260] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  101.993272] CR2: ffffcbce408e4000 CR3: 0000000106388003 CR4: 00000000001726f0
[  101.993286] Kernel panic - not syncing: Fatal exception in interrupt
[  101.993374] Kernel Offset: 0x34400000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)
[  101.993395] Rebooting in 30 seconds..

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-27 11:23 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-27 11:16 [BUG] media: smipcie: panic on DVB feed restart linux-media

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox