From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f51.google.com (mail-pj1-f51.google.com [209.85.216.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A2B1D3E63BB for ; Mon, 25 May 2026 09:52:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.51 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779702769; cv=none; b=iWec0OaWqTY7raF9ucP7tVyZhbYGXD57rOmXvAICmvTLEVl/sBha7EqG5EEp0m5IS9qCmxiVWClKZJSZ4/kh1ETwqIVtYC/pYMLBQ8wxkz9Jpiz5Feexk3STtV1Gu1F8b+92dJ6JpbTVUYEDYZ2QV6crY2lLIln7U+c/QP9SbOw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779702769; c=relaxed/simple; bh=4B9KkP1btML4C6oNkrTHn+OUIMQeidMbAkDiIWR3XwY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=hjz3uii/EFDWajflzqUwEIOEkMywEyFQktHyjDx0poovr+rx5ikVVWN3oBUZfe2kMUcd1NmA0PZR8p+Y9teUJF+6uMZN7en1eiseyzurj2AkGWgiho0G2GU3KcOO3VeeJwHVITAhNuvlIubj6R2A/sVFALuCXlKqFf30GtcgqQk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=OXe63wV4; arc=none smtp.client-ip=209.85.216.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="OXe63wV4" Received: by mail-pj1-f51.google.com with SMTP id 98e67ed59e1d1-3684a6f3b0bso4656299a91.1 for ; Mon, 25 May 2026 02:52:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779702768; x=1780307568; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=oIFEnpVuawucZlIPGTpnFigTasBUEJzr8Hl8oaehmP4=; b=OXe63wV47PkWs03ZPySrt/2gPtLAHsNor9VUjIKALf3FkjA6cYDgOa0x/xOdhjrIq9 9/4nS71Ud18+q7jSmnX3qNwWtjo8bKyCcl0YRZdDo+1JpCJ9uX/zyQop8lqS+aNADYHm blBqlSguNEVntBR71ip6tthOLJajRioknYfAw2IYmGkdMrk7RnG4WSFCVjKBc4bt16lQ oY4xHEtPyjmFbmRKQhI3ENk+nwAWSeZd0UjIohGGbBO1VxPNJL44cP+4T3LMdqhxtLwj gUVtDRItqp48RB+ZvaYQt68BhIVyFOL2N1/bBxM8pGmZD1zs0Kk+5Ueq1YN5QT8DD6cO o8Rg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779702768; x=1780307568; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=oIFEnpVuawucZlIPGTpnFigTasBUEJzr8Hl8oaehmP4=; b=qGGfc+3IFggQM2Laf853e1sHcN+wCDxfr9niksYFZNd06JLFVPa0E1NKtLP2RO5Kap pR6AICnh9Nm/YTcA67tWHc278jRlcSHvrsrGqC8k5qH0klr0oh2pa/KcsTNOiqjYqmqe bzrJzPDknMLDk4GhRmIYHA0pI4KvBZUyq/rpdUQSutO7lmAcZVxhCuJ6UUOFMvf+vPNg /XGa4DfCuYNJEUq5EKSXB1ZGCZUWjDNsRxUOv6mmg430UM33rV6aGV8jZgNxxi5Np1nv aYRqXnnZCjZXaI3WjQlzDHY4kBr8IyBv/9sSWbgirOyAXCjFOnwCnol+kc9l95+gGKNB x2Kg== X-Forwarded-Encrypted: i=1; AFNElJ/c4vNObvvvVPDjDGrmV5J1qCBf1e5aWIEiKQGbLshJzcAN5Qyjpwpxyex4VJW9NFgWN0Wu3Ma6otvRkaw=@vger.kernel.org X-Gm-Message-State: AOJu0Yxpg+tDjwH841CLc5UcmoCfwhGefqtSVdIjJcExG9ptuBMJ2kcq iWv8bYgmsJl75CoNYGjZhPlmY7pRWqdR8tNlk5CJe7bsdAFqTz8ozgnI X-Gm-Gg: Acq92OFSbAOc5mgKNwECyaztO9XfsoIj/W/AcYTBPiwbJPmRu1vDOGdCWJFoaWJ1U/+ O6+1WAr/5CRb2Jg0TD8oD0PMiAqnLOLeXOkuaNiP3MdbCEVqFY6e91krclYOiQniFnm85N/Th/I oFMl6p7ZfwbiOl3oZnVR9iVcII/2OlEdX9ap05XnaKJOkrGay2uC6Ymyb+Bk+LNDVF8ZBM7uy2c s8nQO3OyMpAbcBnKuHD4EzabvD9Q1LVj2tUpHjXt3yH/PXTXG7hGRCwpzd10KxobcgmItHgpNnu mFGrj95BKpkLqbHsbldi1pFXs2mlfhoKssjNYdTlhjRfyO0d3Tl2R0IQK3A7sVcHPhl1AvpF9yW nTBpdcSE0QGtgFTXaQhhCjVVVSTp4SeBOzHQ4yULXNhzjbzkcF9yIDC+tStYhp0i2d2M/viB9LY pFsNvUPx43qkw/l6OXjqLd X-Received: by 2002:a17:902:f546:b0:2bc:8e7d:3dce with SMTP id d9443c01a7336-2bea23e2057mr157194235ad.27.1779702767866; Mon, 25 May 2026 02:52:47 -0700 (PDT) Received: from rockpi-5b ([45.112.0.230]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2beb58b2cd6sm92533615ad.52.2026.05.25.02.52.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 25 May 2026 02:52:47 -0700 (PDT) From: Anand Moon To: Neil Armstrong , Mauro Carvalho Chehab , Greg Kroah-Hartman , Kevin Hilman , Jerome Brunet , Martin Blumenstingl , Hans Verkuil , Maxime Jourdan , linux-media@vger.kernel.org (open list:MESON VIDEO DECODER DRIVER FOR AMLOGIC SOCS), linux-amlogic@lists.infradead.org (open list:MESON VIDEO DECODER DRIVER FOR AMLOGIC SOCS), linux-staging@lists.linux.dev (open list:STAGING SUBSYSTEM), linux-arm-kernel@lists.infradead.org (moderated list:ARM/Amlogic Meson SoC support), linux-kernel@vger.kernel.org (open list) Cc: Anand Moon , Nicolas Dufresne , Sashiko Subject: [PATCH v5 2/6] media: meson: vdec: Protect session exclusivity check with lock Date: Mon, 25 May 2026 15:21:50 +0530 Message-ID: <20260525095216.12078-3-linux.amoon@gmail.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260525095216.12078-1-linux.amoon@gmail.com> References: <20260525095216.12078-1-linux.amoon@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Add the check for an active hardware session is performed without holding the core->lock mutex. In multi-threaded environments, two concurrent STREAMON ioctls on different file descriptors can simultaneously find core->cur_sess to be NULL, bypass the check, and concurrently call vdec_poweron(), corrupting hardware state. Fix this by wrapping the session exclusivity check inside core->lock. Cc: Nicolas Dufresne Reported-by: Sashiko Closes: https://lore.kernel.org/all/20260521090944.F35401F00A3D@smtp.kernel.org/ Fixes: 3e7f51bd9607 ("media: meson: add v4l2 m2m video decoder driver") Signed-off-by: Anand Moon --- v5: New patch. [High] Concurrent sessions can bypass the hardware exclusivity check, leading to simultaneous hardware programming. --- drivers/staging/media/meson/vdec/vdec.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/staging/media/meson/vdec/vdec.c b/drivers/staging/media/meson/vdec/vdec.c index 18a22b79e835..e72f54af026e 100644 --- a/drivers/staging/media/meson/vdec/vdec.c +++ b/drivers/staging/media/meson/vdec/vdec.c @@ -286,10 +286,13 @@ static int vdec_start_streaming(struct vb2_queue *q, unsigned int count) struct vb2_v4l2_buffer *buf; int ret; + mutex_lock(&core->lock); if (core->cur_sess && core->cur_sess != sess) { + mutex_unlock(&core->lock); ret = -EBUSY; goto bufs_done; } + mutex_unlock(&core->lock); if (q->type == V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE) sess->streamon_out = 1; -- 2.50.1