We are losing the reference to an allocated memory if try. Change the
order of the check to avoid that.
Cc: stable@vger.kernel.org
Fixes: 6d5f26f2e045 ("media: staging/intel-ipu3-v4l: reduce kernel stack usage")
Signed-off-by: Ricardo Ribalda <redacted>
---
drivers/staging/media/ipu3/ipu3-v4l2.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
@@ -693,6 +693,13 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,if(inode==IMGU_NODE_STAT_3A||inode==IMGU_NODE_PARAMS)continue;+/* CSS expects some format on OUT queue */+if(i!=IPU3_CSS_QUEUE_OUT&&+!imgu_pipe->nodes[inode].enabled){+fmts[i]=NULL;+continue;+}+if(try){fmts[i]=kmemdup(&imgu_pipe->nodes[inode].vdev_fmt.fmt.pix_mp,sizeof(structv4l2_pix_format_mplane),
@@ -705,10 +712,6 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,fmts[i]=&imgu_pipe->nodes[inode].vdev_fmt.fmt.pix_mp;}-/* CSS expects some format on OUT queue */-if(i!=IPU3_CSS_QUEUE_OUT&&-!imgu_pipe->nodes[inode].enabled)-fmts[i]=NULL;}if(!try){
If there in an error during a set_fmt, do not overwrite the previous
sizes with the invalid config.
[ 38.662975] ipu3-imgu 0000:00:05.0: swiotlb buffer is full (sz: 4096 bytes)
[ 38.662980] DMA: Out of SW-IOMMU space for 4096 bytes at device 0000:00:05.0
[ 38.663010] general protection fault: 0000 [#1] PREEMPT SMP
Cc: stable@vger.kernel.org
Fixes: 6d5f26f2e045 ("media: staging/intel-ipu3-v4l: reduce kernel stack usage")
Signed-off-by: Ricardo Ribalda <redacted>
---
drivers/staging/media/ipu3/ipu3-v4l2.c | 25 ++++++++++++++-----------
1 file changed, 14 insertions(+), 11 deletions(-)
@@ -686,6 +686,7 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,dev_dbg(dev,"IPU3 pipe %u pipe_id = %u",pipe,css_pipe->pipe_id);+css_q=imgu_node_to_queue(node);for(i=0;i<IPU3_CSS_QUEUES;i++){unsignedintinode=imgu_map_node(imgu,i);
@@ -700,6 +701,11 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,continue;}+if(i==css_q){+fmts[i]=&f->fmt.pix_mp;+continue;+}+if(try){fmts[i]=kmemdup(&imgu_pipe->nodes[inode].vdev_fmt.fmt.pix_mp,sizeof(structv4l2_pix_format_mplane),
@@ -728,16 +734,10 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,rects[IPU3_CSS_RECT_GDC]->height=pad_fmt.height;}-/*-*imgudoesn'tsetthenodetothevaluegivenbyuser-*beforewereturnsuccessfromthisfunction,sosetithere.-*/-css_q=imgu_node_to_queue(node);if(!fmts[css_q]){ret=-EINVAL;gotoout;}-*fmts[css_q]=f->fmt.pix_mp;if(try)ret=imgu_css_fmt_try(&imgu->css,fmts,rects,pipe);
@@ -748,15 +748,18 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,if(ret<0)gotoout;-if(try)-f->fmt.pix_mp=*fmts[css_q];-else-f->fmt=imgu_pipe->nodes[node].vdev_fmt.fmt;+/*+*imgudoesn'tsetthenodetothevaluegivenbyuser+*beforewereturnsuccessfromthisfunction,sosetithere.+*/+if(!try)+imgu_pipe->nodes[node].vdev_fmt.fmt.pix_mp=f->fmt.pix_mp;out:if(try){for(i=0;i<IPU3_CSS_QUEUES;i++)-kfree(fmts[i]);+if(i!=css_q)+kfree(fmts[i]);}returnret;
From: Bingbu Cao <hidden> Date: 2021-03-16 11:29:58
Hi, Ricardo
Thanks for your patch.
It looks fine for me, do you mind squash 2 patchsets into 1 commit?
On 3/15/21 8:34 PM, Ricardo Ribalda wrote:
quoted hunk
We are losing the reference to an allocated memory if try. Change the
order of the check to avoid that.
Cc: stable@vger.kernel.org
Fixes: 6d5f26f2e045 ("media: staging/intel-ipu3-v4l: reduce kernel stack usage")
Signed-off-by: Ricardo Ribalda <redacted>
---
drivers/staging/media/ipu3/ipu3-v4l2.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
@@ -693,6 +693,13 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,if(inode==IMGU_NODE_STAT_3A||inode==IMGU_NODE_PARAMS)continue;+/* CSS expects some format on OUT queue */+if(i!=IPU3_CSS_QUEUE_OUT&&+!imgu_pipe->nodes[inode].enabled){+fmts[i]=NULL;+continue;+}+if(try){fmts[i]=kmemdup(&imgu_pipe->nodes[inode].vdev_fmt.fmt.pix_mp,sizeof(structv4l2_pix_format_mplane),
@@ -705,10 +712,6 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,fmts[i]=&imgu_pipe->nodes[inode].vdev_fmt.fmt.pix_mp;}-/* CSS expects some format on OUT queue */-if(i!=IPU3_CSS_QUEUE_OUT&&-!imgu_pipe->nodes[inode].enabled)-fmts[i]=NULL;}if(!try){
Hi Bingbu
Thanks for your review
On Tue, Mar 16, 2021 at 12:29 PM Bingbu Cao [off-list ref] wrote:
Hi, Ricardo
Thanks for your patch.
It looks fine for me, do you mind squash 2 patchsets into 1 commit?
Are you sure? There are two different issues that we are solving.
Best regards!
On 3/15/21 8:34 PM, Ricardo Ribalda wrote:
quoted
We are losing the reference to an allocated memory if try. Change the
order of the check to avoid that.
Cc: stable@vger.kernel.org
Fixes: 6d5f26f2e045 ("media: staging/intel-ipu3-v4l: reduce kernel stack usage")
Signed-off-by: Ricardo Ribalda <redacted>
---
drivers/staging/media/ipu3/ipu3-v4l2.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
@@ -693,6 +693,13 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,if(inode==IMGU_NODE_STAT_3A||inode==IMGU_NODE_PARAMS)continue;+/* CSS expects some format on OUT queue */+if(i!=IPU3_CSS_QUEUE_OUT&&+!imgu_pipe->nodes[inode].enabled){+fmts[i]=NULL;+continue;+}+if(try){fmts[i]=kmemdup(&imgu_pipe->nodes[inode].vdev_fmt.fmt.pix_mp,sizeof(structv4l2_pix_format_mplane),
@@ -705,10 +712,6 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,fmts[i]=&imgu_pipe->nodes[inode].vdev_fmt.fmt.pix_mp;}-/* CSS expects some format on OUT queue */-if(i!=IPU3_CSS_QUEUE_OUT&&-!imgu_pipe->nodes[inode].enabled)-fmts[i]=NULL;}if(!try){
From: Bingbu Cao <hidden> Date: 2021-03-17 06:49:51
On 3/17/21 1:50 AM, Ricardo Ribalda wrote:
Hi Bingbu
Thanks for your review
On Tue, Mar 16, 2021 at 12:29 PM Bingbu Cao [off-list ref] wrote:
quoted
Hi, Ricardo
Thanks for your patch.
It looks fine for me, do you mind squash 2 patchsets into 1 commit?
Are you sure? There are two different issues that we are solving.
Oh, I see. I thought you were fixing 1 issue here.
Thanks!
Best regards!
quoted
On 3/15/21 8:34 PM, Ricardo Ribalda wrote:
quoted
We are losing the reference to an allocated memory if try. Change the
order of the check to avoid that.
Cc: stable@vger.kernel.org
Fixes: 6d5f26f2e045 ("media: staging/intel-ipu3-v4l: reduce kernel stack usage")
Signed-off-by: Ricardo Ribalda <redacted>
---
drivers/staging/media/ipu3/ipu3-v4l2.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
@@ -693,6 +693,13 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,if(inode==IMGU_NODE_STAT_3A||inode==IMGU_NODE_PARAMS)continue;+/* CSS expects some format on OUT queue */+if(i!=IPU3_CSS_QUEUE_OUT&&+!imgu_pipe->nodes[inode].enabled){+fmts[i]=NULL;+continue;+}+if(try){fmts[i]=kmemdup(&imgu_pipe->nodes[inode].vdev_fmt.fmt.pix_mp,sizeof(structv4l2_pix_format_mplane),
@@ -705,10 +712,6 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,fmts[i]=&imgu_pipe->nodes[inode].vdev_fmt.fmt.pix_mp;}-/* CSS expects some format on OUT queue */-if(i!=IPU3_CSS_QUEUE_OUT&&-!imgu_pipe->nodes[inode].enabled)-fmts[i]=NULL;}if(!try){
Hi Bingbu
Maybe you want to add your Reviewed-by ? ;)
Thanks!
On Wed, Mar 17, 2021 at 7:48 AM Bingbu Cao [off-list ref] wrote:
On 3/17/21 1:50 AM, Ricardo Ribalda wrote:
quoted
Hi Bingbu
Thanks for your review
On Tue, Mar 16, 2021 at 12:29 PM Bingbu Cao [off-list ref] wrote:
quoted
Hi, Ricardo
Thanks for your patch.
It looks fine for me, do you mind squash 2 patchsets into 1 commit?
Are you sure? There are two different issues that we are solving.
Oh, I see. I thought you were fixing 1 issue here.
Thanks!
quoted
Best regards!
quoted
On 3/15/21 8:34 PM, Ricardo Ribalda wrote:
quoted
We are losing the reference to an allocated memory if try. Change the
order of the check to avoid that.
Cc: stable@vger.kernel.org
Fixes: 6d5f26f2e045 ("media: staging/intel-ipu3-v4l: reduce kernel stack usage")
Signed-off-by: Ricardo Ribalda <redacted>
---
drivers/staging/media/ipu3/ipu3-v4l2.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
@@ -693,6 +693,13 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,if(inode==IMGU_NODE_STAT_3A||inode==IMGU_NODE_PARAMS)continue;+/* CSS expects some format on OUT queue */+if(i!=IPU3_CSS_QUEUE_OUT&&+!imgu_pipe->nodes[inode].enabled){+fmts[i]=NULL;+continue;+}+if(try){fmts[i]=kmemdup(&imgu_pipe->nodes[inode].vdev_fmt.fmt.pix_mp,sizeof(structv4l2_pix_format_mplane),
@@ -705,10 +712,6 @@ static int imgu_fmt(struct imgu_device *imgu, unsigned int pipe, int node,fmts[i]=&imgu_pipe->nodes[inode].vdev_fmt.fmt.pix_mp;}-/* CSS expects some format on OUT queue */-if(i!=IPU3_CSS_QUEUE_OUT&&-!imgu_pipe->nodes[inode].enabled)-fmts[i]=NULL;}if(!try){
From: Tomasz Figa <tfiga@chromium.org> Date: 2021-04-09 04:17:03
On Mon, Mar 15, 2021 at 01:34:06PM +0100, Ricardo Ribalda wrote:
If there in an error during a set_fmt, do not overwrite the previous
sizes with the invalid config.
[ 38.662975] ipu3-imgu 0000:00:05.0: swiotlb buffer is full (sz: 4096 bytes)
[ 38.662980] DMA: Out of SW-IOMMU space for 4096 bytes at device 0000:00:05.0
[ 38.663010] general protection fault: 0000 [#1] PREEMPT SMP
Cc: stable@vger.kernel.org
Fixes: 6d5f26f2e045 ("media: staging/intel-ipu3-v4l: reduce kernel stack usage")
Signed-off-by: Ricardo Ribalda <redacted>
---
drivers/staging/media/ipu3/ipu3-v4l2.c | 25 ++++++++++++++-----------
1 file changed, 14 insertions(+), 11 deletions(-)
Reviewed-by: Tomasz Figa <tfiga@chromium.org>
Best regards,
Tomasz