From: Sakari Ailus <sakari.ailus@linux.intel.com>
To: Linus Walleij <linusw@kernel.org>
Cc: linux-media@vger.kernel.org, laurent.pinchart@ideasonboard.com,
Dave Stevenson <dave.stevenson@raspberrypi.com>,
Jacopo Mondi <jacopo.mondi@ideasonboard.com>,
Tomi Valkeinen <tomi.valkeinen@ideasonboard.com>,
Jai Luthra <jai.luthra@ideasonboard.com>,
Mehdi Djait <mehdi.djait@linux.intel.com>,
Mattijs Korpershoek <mkorpershoek@kernel.org>
Subject: Re: [PATCH v3 05/29] media: v4l2-subdev: Allow allocating frame descriptors based on the need
Date: Wed, 23 Sep 2026 15:11:59 +0300 [thread overview]
Message-ID: <arPCD2WzFyT0GSNx@kekkonen.localdomain> (raw)
In-Reply-To: <CAD++jLnruxXqtgm2ckQQhKvuNQvawH0xZpq8ipYSjFLKDbpnyQ@mail.gmail.com>
Hej Linus,
On Mon, Aug 31, 2026 at 03:18:50PM +0200, Linus Walleij wrote:
> Hi Sakari,
>
> thanks for your patch!
Tack för kritiken!
>
> On Mon, Aug 24, 2026 at 2:14 PM Sakari Ailus
> <sakari.ailus@linux.intel.com> wrote:
>
> > Frame descriptors entries require a small amount of memory per entry (20
> > bytes), but if the number of entries in a frame descriptor is large, an
> > unreasonably large amount of memory would need to be allocated in the
> > stack. Therefore the number of entries has been limited to 8.
> >
> > Support larger frame descriptors by making the entry field a pointer that
> > by default points to a pre-allocated array while the get_frame_desc() pad
> > o may allocate as much memory as required, up to V4L2_FRAME_DESC_ENTRY_MAX
> > which is changed to 64.
> >
> > The caller is also responsible for releasing the allocated memory by
> > calling v4l2_subdev_free_frame_desc().
> >
> > Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
> > Reviewed-by: Frank Li <Frank.Li@nxp.com>
> (...)
>
> > @@ -63,10 +63,6 @@ static bool v4l2_subdev_enable_streams_api;
> > /*
> > * Maximum stream ID is 63 for now, as we use u64 bitmask to represent a set
> > * of streams.
> > - *
> > - * Note that V4L2_FRAME_DESC_ENTRY_MAX is related: V4L2_FRAME_DESC_ENTRY_MAX
> > - * restricts the total number of streams in a pad, although the stream ID is
> > - * not restricted.
> > */
> > #define V4L2_SUBDEV_MAX_STREAM_ID 63
> >
> > @@ -354,6 +350,7 @@ static int call_set_frame_interval(struct v4l2_subdev *sd,
> > static int call_get_frame_desc(struct v4l2_subdev *sd, unsigned int pad,
> > struct v4l2_mbus_frame_desc *fd)
> > {
> > + unsigned int type;
>
> This is again an enum, right?
Yes, seems so...
>
> > @@ -362,16 +359,26 @@ static int call_get_frame_desc(struct v4l2_subdev *sd, unsigned int pad,
> > return -EOPNOTSUPP;
> > #endif
> >
> > - memset(fd, 0, sizeof(*fd));
>
> So passing an unititialized or re-used struct v4l2_mbus_frame_desc foo
> used to be fine...
>
> > + type = fd->type;
> > + memset_after(fd, 0, type);
>
> ...and is not fine anymore.
>
> I guess later patches in this series fixes up all users so no-one
> passes in some garbage here?
After the set, we have all drivers converted to use
v4l2_subdev_get_frame_desc(), so this means some amount of inter-set
breakage. I wouldn't see this as a serious issue but if someone thinks so,
then we may need to introduce an intermediate wrapper that sets the type
for this.
I'll also include patches for the recently merged drivers calling
get_frame_desc() in v4.
>
> > + if (desc->num_entries > desc->len_entries) {
> > + dev_dbg(sd->dev,
>
> When you get to this check, isn't that after this loop:
>
> for (i = 0; i < fd->num_entries; i++) { (...)
>
> so you should check num_entries agains len_entries before this
> loop?
>
> (I might be misreading the patch, maybe I should actually apply
> it and inspect the result.)
The earlier arrangement was that the caller made the allocation but that's
no longer the case, so this is a fatal error now. Still, if num_entries
exceeds len_entries, the access of unallocated memory has probably already
been committed, so this check would still take effect retrospectively even
if moved to call_get_frame_desc(). I'll do that now in any case, the other
sensible option would be just removing it.
--
Med trevliga hälsningar,
Sakari Ailus
next prev parent reply other threads:[~2026-09-23 12:12 UTC|newest]
Thread overview: 119+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 12:14 [PATCH v3 00/29] Rework frame descriptors Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 01/29] media: v4l2-common: Add helper function media_bus_fmt_to_csi2_(bpp|dt)() Sakari Ailus
2026-08-26 13:18 ` Linus Walleij
2026-08-27 7:45 ` Linus Walleij
2026-08-27 8:50 ` Sakari Ailus
2026-08-27 9:34 ` Sakari Ailus
2026-08-27 22:29 ` Linus Walleij
2026-09-23 11:27 ` Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 02/29] media: v4l2-subdev: Align frame descriptor error codes with routing Sakari Ailus
2026-08-27 7:46 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 03/29] media: v4l2-subdev: Prepare for changes in getting frame descriptors Sakari Ailus
2026-08-31 12:43 ` Linus Walleij
2026-09-02 11:55 ` Sakari Ailus
2026-08-31 12:44 ` Linus Walleij
2026-09-02 12:00 ` Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 04/29] media: v4l2-subdev: Allow releasing frame descriptors on return Sakari Ailus
2026-08-24 20:34 ` Frank Li
2026-08-31 12:54 ` Linus Walleij
2026-09-02 11:23 ` Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 05/29] media: v4l2-subdev: Allow allocating frame descriptors based on the need Sakari Ailus
2026-08-31 13:18 ` Linus Walleij
2026-09-01 12:30 ` Linus Walleij
2026-09-23 12:11 ` Sakari Ailus [this message]
2026-08-24 12:14 ` [PATCH v3 06/29] media: v4l2-subdev: Change the maximum number of routes Sakari Ailus
2026-09-01 12:31 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 07/29] media: v4l2-subdev: Add frame descriptor passthrough for CSI-2 and DVP Sakari Ailus
2026-08-24 20:43 ` Frank Li
2026-09-01 13:01 ` Linus Walleij
2026-09-02 12:02 ` Sakari Ailus
2026-09-02 13:04 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 08/29] media: ds90ub913: Use v4l2_subdev_get_frame_desc_passthrough_csi2() Sakari Ailus
2026-08-24 20:44 ` Frank Li
2026-09-01 13:12 ` Linus Walleij
2026-09-02 12:05 ` Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 09/29] media: ds90ub953: " Sakari Ailus
2026-08-24 20:44 ` Frank Li
2026-09-01 13:17 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 10/29] media: nxp: imx8-isi: " Sakari Ailus
2026-08-24 20:44 ` Frank Li
2026-09-01 13:30 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 11/29] media: rzg2l-cru: " Sakari Ailus
2026-08-24 20:45 ` Frank Li
2026-09-01 21:18 ` Linus Walleij
2026-09-02 12:22 ` Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 12/29] media: dw-mipi-csi2rx: " Sakari Ailus
2026-08-24 20:46 ` Frank Li
2026-09-01 21:22 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 13/29] media: cdn-csi2rc: media: " Sakari Ailus
2026-08-24 20:47 ` Frank Li
2026-08-26 6:41 ` Jai Luthra
2026-09-01 21:43 ` Linus Walleij
2026-09-09 8:39 ` Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 14/29] media: v4l2-subdev: Make v4l2_subdev_get_frame_desc_passthrough() static Sakari Ailus
2026-08-24 20:48 ` Frank Li
2026-09-01 22:16 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 15/29] media: v4l2-subdev: Return dynamically allocated pass-through routes Sakari Ailus
2026-08-24 21:00 ` Frank Li
2026-08-25 7:36 ` Sakari Ailus
2026-09-02 5:44 ` Linus Walleij
2026-09-02 9:34 ` Linus Walleij
2026-09-09 9:12 ` Sakari Ailus
2026-09-09 9:10 ` Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 16/29] media: v4l2-subdev: Always return at least one frame descriptor Sakari Ailus
2026-09-04 10:27 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 17/29] media: bcm2835-unicam: Use v4l2_subdev_get_frame_desc() Sakari Ailus
2026-08-24 21:07 ` Frank Li
2026-08-25 7:40 ` Sakari Ailus
2026-09-04 10:32 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 18/29] media: bcm2835-unicam: Remove frame descriptor workaround Sakari Ailus
2026-08-24 21:10 ` Frank Li
2026-08-26 12:09 ` Sakari Ailus
2026-09-04 10:43 ` Linus Walleij
2026-09-09 9:26 ` Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 19/29] media: nxp: imx8-isi: Use v4l2_subdev_get_frame_desc() Sakari Ailus
2026-09-04 12:44 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 20/29] media: raspberrypi: cfe: " Sakari Ailus
2026-08-24 21:11 ` Frank Li
2026-09-04 12:51 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 21/29] media: rzg2l-cru: " Sakari Ailus
2026-08-24 21:13 ` Frank Li
2026-09-04 12:57 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 22/29] media: rkisp1: " Sakari Ailus
2026-08-24 21:13 ` Frank Li
2026-09-04 13:12 ` Linus Walleij
2026-09-09 10:06 ` Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 23/29] media: exynos4-is: " Sakari Ailus
2026-08-24 21:22 ` Frank Li
2026-09-04 13:35 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 24/29] media: ti: cal: " Sakari Ailus
2026-08-24 21:26 ` Frank Li
2026-08-25 8:05 ` Sakari Ailus
2026-09-04 13:38 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 25/29] media: ipu6: " Sakari Ailus
2026-08-24 21:26 ` Frank Li
2026-09-04 20:21 ` Linus Walleij
2026-09-16 8:09 ` Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 26/29] staging: media: ipu7: " Sakari Ailus
2026-08-24 21:27 ` Frank Li
2026-09-04 20:25 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 27/29] media: cdns-csi2rc: " Sakari Ailus
2026-08-24 21:29 ` Frank Li
2026-08-26 6:39 ` Jai Luthra
2026-09-04 20:27 ` Linus Walleij
2026-09-16 8:12 ` Sakari Ailus
2026-08-24 12:14 ` [PATCH v3 28/29] media: v4l2-subdev: Use v4l2_subdev_get_frame_desc() for passthrough Sakari Ailus
2026-08-24 21:37 ` Frank Li
2026-08-25 7:34 ` Sakari Ailus
2026-09-04 20:38 ` Linus Walleij
2026-09-16 8:22 ` Sakari Ailus
2026-09-04 20:45 ` Linus Walleij
2026-08-24 12:14 ` [PATCH v3 29/29] media: j721e-csi2rx: Use v4l2_subdev_get_frame_desc() Sakari Ailus
2026-08-24 21:38 ` Frank Li
2026-08-26 6:36 ` Jai Luthra
2026-09-04 20:54 ` Linus Walleij
2026-09-16 8:32 ` Sakari Ailus
2026-09-16 12:48 ` Jai Luthra
2026-08-26 9:58 ` [PATCH v3 00/29] Rework frame descriptors Mattijs Korpershoek
2026-09-17 8:04 ` Tomi Valkeinen
2026-09-21 8:22 ` Mattijs Korpershoek
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arPCD2WzFyT0GSNx@kekkonen.localdomain \
--to=sakari.ailus@linux.intel.com \
--cc=dave.stevenson@raspberrypi.com \
--cc=jacopo.mondi@ideasonboard.com \
--cc=jai.luthra@ideasonboard.com \
--cc=laurent.pinchart@ideasonboard.com \
--cc=linusw@kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mehdi.djait@linux.intel.com \
--cc=mkorpershoek@kernel.org \
--cc=tomi.valkeinen@ideasonboard.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox