From 8a055950fd9a04db260d6b089d9e49b5c4a16cfb Mon Sep 17 00:00:00 2001 From: Agnimitra Sen Date: Thu, 10 Apr 2025 16:16:35 +0530 Subject: [PATCH 1/2] msm: vidc: Enable hybrid mode only for HFR usecase Dynamic properties such as IDR insertion is not supported when hybrid layers are enabled . Hybrid layers required only HFR usecase. Hence enabling hybrid only when VBR+noLTR+HFR use cases. Change-Id: I36e4ecb9c98135790cff0487a237a1a4fd33d241 --- msm/vidc/msm_venc.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/msm/vidc/msm_venc.c b/msm/vidc/msm_venc.c index 25a282e5aa4a..f95639e02465 100644 --- a/msm/vidc/msm_venc.c +++ b/msm/vidc/msm_venc.c @@ -3710,6 +3710,9 @@ int msm_venc_enable_hybrid_hp(struct msm_vidc_inst *inst) if (ctrl->val) return 0; + if (msm_vidc_get_fps(inst) <= 60) + return 0; + ctrl = get_ctrl(inst, V4L2_CID_MPEG_VIDC_VIDEO_HEVC_MAX_HIER_CODING_LAYER); layer = get_ctrl(inst, V4L2_CID_MPEG_VIDEO_HEVC_HIER_CODING_LAYER); From 3fedfd9225c35b50d8b48ab8ea31bbe26fd83713 Mon Sep 17 00:00:00 2001 From: Vasantha Balla Date: Fri, 28 Mar 2025 12:16:47 +0530 Subject: [PATCH 2/2] msm: vidc: Fix use after free in driver Use after free can happen in below scenario. [1] In msm_vidc_open, When instance count reaches max count or when open failed it waits for core lock before removing instance from instance list. [2] During this time backward thread can get invoked to handle firmware response for cmds, It increments reference count and gets instance. [3] If forward thread resumes after this, and frees intance, backward thread will end up using freed instance. [4] To address this, calling kref_put(&inst->kref) and freeing instance immediately if ref count is zero, if recount is not zero, backward thread frees instance memory in put_inst_helper. Change-Id: I58c81d4d9fda1523d0fa29ebdb33455db839d46f Signed-off-by: Vasantha Balla (cherry picked from commit ccddad0c4992ab7b4e3651e2c5c8df3e79bb7c43) (cherry picked from commit cc9f3cc50311796626b2c40b049daeef0a5719ea) --- msm/vidc/msm_vidc.c | 23 +++++++---------------- 1 file changed, 7 insertions(+), 16 deletions(-) diff --git a/msm/vidc/msm_vidc.c b/msm/vidc/msm_vidc.c index d848eb08976b..db0f6529abb8 100644 --- a/msm/vidc/msm_vidc.c +++ b/msm/vidc/msm_vidc.c @@ -1482,7 +1482,6 @@ static void close_helper(struct kref *kref) { struct msm_vidc_inst *inst = container_of(kref, struct msm_vidc_inst, kref); - msm_vidc_destroy(inst); } @@ -1497,19 +1496,19 @@ void *msm_vidc_open(int core_id, int session_type) session_type >= MSM_VIDC_MAX_DEVICES) { d_vpr_e("Invalid input, core_id = %d, session = %d\n", core_id, session_type); - goto err_invalid_core; + return NULL; } core = get_vidc_core(core_id); if (!core) { d_vpr_e("Failed to find core for core_id = %d\n", core_id); - goto err_invalid_core; + return NULL; } inst = kzalloc(sizeof(*inst), GFP_KERNEL); if (!inst) { d_vpr_e("Failed to allocate memory\n"); rc = -ENOMEM; - goto err_invalid_core; + return NULL; } mutex_lock(&core->lock); rc = get_sid(&inst->sid, session_type); @@ -1609,14 +1608,15 @@ void *msm_vidc_open(int core_id, int session_type) s_vpr_e(inst->sid, "Failed to move video instance to init state\n"); kref_put(&inst->kref, close_helper); - inst = NULL; - goto err_invalid_core; + return NULL; } if (msm_comm_check_for_inst_overload(core)) { s_vpr_e(inst->sid, "Instance count reached Max limit, rejecting session"); - goto fail_init; + msm_comm_kill_session(inst); + kref_put(&inst->kref, close_helper); + return NULL; } msm_comm_scale_clocks_and_bus(inst, 1); @@ -1625,14 +1625,6 @@ void *msm_vidc_open(int core_id, int session_type) msm_vidc_debugfs_init_inst(inst, core->debugfs_root); return inst; -fail_init: - mutex_lock(&core->lock); - list_del(&inst->list); - mutex_unlock(&core->lock); - - v4l2_fh_del(&inst->event_handler); - v4l2_fh_exit(&inst->event_handler); - vb2_queue_release(&inst->bufq[INPUT_PORT].vb2_bufq); fail_bufq_output: vb2_queue_release(&inst->bufq[OUTPUT_PORT].vb2_bufq); fail_bufq_capture: @@ -1660,7 +1652,6 @@ err_invalid_sid: put_sid(inst->sid); kfree(inst); inst = NULL; -err_invalid_core: return inst; } EXPORT_SYMBOL(msm_vidc_open);