Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/video-driver into android13-5.4-lahaina

LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/video-driver:
  msm: vidc: Fix use after free in driver
  msm: vidc: Enable hybrid mode only for HFR usecase

Change-Id: Ic2a5c64a04bcd2bed2c853f541255b7563d9b65c
This commit is contained in:
Michael Bestas 2026-04-30 21:20:07 +03:00
commit 77d305881e
No known key found for this signature in database
GPG key ID: CC95044519BE6669
2 changed files with 10 additions and 16 deletions

View file

@ -3710,6 +3710,9 @@ int msm_venc_enable_hybrid_hp(struct msm_vidc_inst *inst)
if (ctrl->val)
return 0;
if (msm_vidc_get_fps(inst) <= 60)
return 0;
ctrl = get_ctrl(inst,
V4L2_CID_MPEG_VIDC_VIDEO_HEVC_MAX_HIER_CODING_LAYER);
layer = get_ctrl(inst, V4L2_CID_MPEG_VIDEO_HEVC_HIER_CODING_LAYER);

View file

@ -1482,7 +1482,6 @@ static void close_helper(struct kref *kref)
{
struct msm_vidc_inst *inst = container_of(kref,
struct msm_vidc_inst, kref);
msm_vidc_destroy(inst);
}
@ -1497,19 +1496,19 @@ void *msm_vidc_open(int core_id, int session_type)
session_type >= MSM_VIDC_MAX_DEVICES) {
d_vpr_e("Invalid input, core_id = %d, session = %d\n",
core_id, session_type);
goto err_invalid_core;
return NULL;
}
core = get_vidc_core(core_id);
if (!core) {
d_vpr_e("Failed to find core for core_id = %d\n", core_id);
goto err_invalid_core;
return NULL;
}
inst = kzalloc(sizeof(*inst), GFP_KERNEL);
if (!inst) {
d_vpr_e("Failed to allocate memory\n");
rc = -ENOMEM;
goto err_invalid_core;
return NULL;
}
mutex_lock(&core->lock);
rc = get_sid(&inst->sid, session_type);
@ -1609,14 +1608,15 @@ void *msm_vidc_open(int core_id, int session_type)
s_vpr_e(inst->sid,
"Failed to move video instance to init state\n");
kref_put(&inst->kref, close_helper);
inst = NULL;
goto err_invalid_core;
return NULL;
}
if (msm_comm_check_for_inst_overload(core)) {
s_vpr_e(inst->sid,
"Instance count reached Max limit, rejecting session");
goto fail_init;
msm_comm_kill_session(inst);
kref_put(&inst->kref, close_helper);
return NULL;
}
msm_comm_scale_clocks_and_bus(inst, 1);
@ -1625,14 +1625,6 @@ void *msm_vidc_open(int core_id, int session_type)
msm_vidc_debugfs_init_inst(inst, core->debugfs_root);
return inst;
fail_init:
mutex_lock(&core->lock);
list_del(&inst->list);
mutex_unlock(&core->lock);
v4l2_fh_del(&inst->event_handler);
v4l2_fh_exit(&inst->event_handler);
vb2_queue_release(&inst->bufq[INPUT_PORT].vb2_bufq);
fail_bufq_output:
vb2_queue_release(&inst->bufq[OUTPUT_PORT].vb2_bufq);
fail_bufq_capture:
@ -1660,7 +1652,6 @@ err_invalid_sid:
put_sid(inst->sid);
kfree(inst);
inst = NULL;
err_invalid_core:
return inst;
}
EXPORT_SYMBOL(msm_vidc_open);