From nobody Sat Jul 25 04:30:37 2026 Received: from mail-pj1-f41.google.com (mail-pj1-f41.google.com [209.85.216.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0ECDC33AD9A for ; Sat, 18 Jul 2026 13:03:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784379784; cv=none; b=cwLPQPs5GLuvEd92FUoozAbEBxo6ftnTN5DsIANTMvdbyFNTkhlNsEP3Bzx0ue6QObI5DaaG3X/JHRfei0PoSVh2TeBgeI0FMnWfdnjitNDKRXi/NchGE2xjpSD/FaPEtau7wCUjtDIp3sjlm6yK0HKO5jVtF2GIRnTAa5Wymdg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784379784; c=relaxed/simple; bh=+Grdugcauc4mZVTbOs5VT+LBzVeVXGJ51Rt+36hFDMM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=jYdbmzBnDwQQSZ/UpbVhUmIbLwCRVFDai/fbAyCVgK/1ICzVutYwjUtYYy9g/9Z5IA1TwRPTLy2853QoXgBX8yUi2ESntfZ156AliKpAmXd3KNONP3pD3TBXB84iIRa3cEAqtrSia1NMaB17f7mVnHv4+urnkKV1qni2HM9MbNg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=QUhkzExP; arc=none smtp.client-ip=209.85.216.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="QUhkzExP" Received: by mail-pj1-f41.google.com with SMTP id 98e67ed59e1d1-38e347638adso3694436a91.0 for ; Sat, 18 Jul 2026 06:03:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784379782; x=1784984582; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UGP+4K0uZcwD2O//SMtKKili1zVc41sNCrJ+p97Mo6w=; b=QUhkzExPQAkboYcdGo/qzGdaYT3v6QFOakvBNceSHlHVu9v2k2hcFbDgNZBWvgnKdc sGoYit0sf0QaYvGRB7kWevJOsEWX9AET6Oec4QiHNttl1mKSpExNnw84eqlWeKHL9w4W 27WWYLy1QB+wXH7rueRZLgF6VCjjuy0DE5bb4j6PfjDGgTmlGqSzn3sPVs3mKARTX45Y TVjKOiN+X7Li80IKXV7ZThq7ms42fbRkwqFj1btnj4Hz1PfFeCttHjqthVpHkFztR/T5 LdV3tAD85NN0kBBuBCtR8Nelnl4CtDGs6a+WmEt0NA7VQqwaLwpKIWhIDTcYZts6Bgjx 4KvQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784379782; x=1784984582; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=UGP+4K0uZcwD2O//SMtKKili1zVc41sNCrJ+p97Mo6w=; b=k9hCnvBtjGRZgHwgugRVl+CST3z1vg2fAwMDzRbbzvtDQ3OdJCC+ev+dVhT7/CiHfx txMXYxZWAbdtFQrsp6GlRUmCpOQTvCqfv1U6QhmCUZngpqPC3LhPwBCwe6q59GNd4ig7 Y4D7oqPViSTc4f2e2uxGcbHFWaWbGUiFzlQR44V3ijE4Gurj9V1dR9ZtQBXnjwKcE1lp 4p1ymq1N1jCfYWAYFzcc5NU4ZlMOOkj4qGH5+geJjttZ4CBHMQpycOsaQ80dFuY7ZiyN Q3w7IAVBG+uURV0WILWQWjYNrRr2nYYABMtI/pCfSQCVbh7B3Gs8RAmNrkxuEfckabQp 9W3w== X-Forwarded-Encrypted: i=1; AHgh+RqfV8NkzGzKQX45mZS/atkoLgsHkrUKAlGcKEf3eG0pAshdCF6k4gbn9r6nponUQQuBriwZampFG3nUjI0=@vger.kernel.org X-Gm-Message-State: AOJu0Yzz5bi2qPWwy+BTjNMklkPC1/tGPGouDGT+kHkprRIeF8OW3zTp YNxUW6XwV9Pl1VInccsIf4h4vjnJzsXCzMpcx/huxHmplsoM66X4ntGR X-Gm-Gg: AfdE7cmwUxMzWMJAFw4ozhZIc9iZcDWw6Jkbue0Va1MAif8HJYlboCUDOzO7m3aodnz YTITWL9iLgeyUQjjjkYQ6NW5nSPo/ZaGBfFQ3Dxry5UlG5Vatowfpg8vEdOYB7k3psgAYwO/A0U zp47X84UXQ7zMIN6AfUFqBx1nuB3gYGkmFwALtrDMbRlKqayzLa6RCiIbeYX9Yy9HzdPASoBgT6 ab42m4BhmAFUAkEU3te2X+hDAI4S2G4m2hY5G1lEB8cL7TStEwNy1GwycItpUvI2NZS/S8NQNYr +z2tahY6dtkc/j22ksedRs+YtXuyGXwIHEzA5Tz3Q/X02vGrZpfYIM5Oj3Qs/zyA3+LP6Su9gp5 TMMD9gH7f49/SZPReYLIo2LOJET7o6lBdMTuvFrEGmoBlWZ5ZyI7sX6ueCd9T X-Received: by 2002:a17:90b:1d10:b0:38e:659b:f366 with SMTP id 98e67ed59e1d1-38e659bf4d8mr1058381a91.0.1784379781912; Sat, 18 Jul 2026 06:03:01 -0700 (PDT) Received: from lgs.. ([2001:250:5800:1000::f280]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38e4aff383dsm2766845a91.8.2026.07.18.06.02.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 18 Jul 2026 06:03:01 -0700 (PDT) From: Guangshuo Li To: Nas Chung , Jackson Lee , Mauro Carvalho Chehab , Nicolas Dufresne , Hans Verkuil , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org Cc: Guangshuo Li Subject: [PATCH v2 1/2] media: chips-media: wave5: Check decoder qbuf runtime resume Date: Sat, 18 Jul 2026 21:00:36 +0800 Message-ID: <20260718130037.3306626-2-lgs201920130244@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260718130037.3306626-1-lgs201920130244@gmail.com> References: <20260718130037.3306626-1-lgs201920130244@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" wave5_vpu_dec_buf_queue_dst() resumes the VPU before it may clear a decoder display flag. This is needed because clearing the display flag accesses VPU registers. However, the return value from pm_runtime_resume_and_get() is ignored. If the resume fails, pm_runtime_resume_and_get() returns without holding a runtime PM usage reference. The unconditional pm_runtime_put_autosuspend() at the end of the function then drops an unmatched reference. The failed resume path can also continue into wave5_vpu_dec_clr_disp_flag() while the device is still suspended. Check the return value. If the resume fails, complete the queued buffer with an error and return without touching the hardware or dropping an unmatched runtime PM reference. Fixes: cbb9c0d50e47 ("media: chips-media: wave5: Fix SError of kernel panic= when closed") Signed-off-by: Guangshuo Li --- drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c b/dri= vers/media/platform/chips-media/wave5/wave5-vpu-dec.c index bb2ba9204a83..03d108b808ba 100644 --- a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c +++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c @@ -1290,8 +1290,14 @@ static void wave5_vpu_dec_buf_queue_dst(struct vb2_b= uffer *vb) struct vb2_v4l2_buffer *vbuf =3D to_vb2_v4l2_buffer(vb); struct vpu_instance *inst =3D vb2_get_drv_priv(vb->vb2_queue); struct v4l2_m2m_ctx *m2m_ctx =3D inst->v4l2_fh.m2m_ctx; + int ret; + + ret =3D pm_runtime_resume_and_get(inst->dev->dev); + if (ret < 0) { + vb2_buffer_done(vb, VB2_BUF_STATE_ERROR); + return; + } =20 - pm_runtime_resume_and_get(inst->dev->dev); vbuf->sequence =3D inst->queued_dst_buf_num++; =20 if (inst->state =3D=3D VPU_INST_STATE_PIC_RUN) { --=20 2.43.0 From nobody Sat Jul 25 04:30:37 2026 Received: from mail-pl1-f181.google.com (mail-pl1-f181.google.com [209.85.214.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D8FA934EF0E for ; Sat, 18 Jul 2026 13:03:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.181 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784379792; cv=none; b=j+HluVxlOnKxFEqhGA194uG7GbCohBzGjKociK0K5ia6u4S5+3wkBjyvUxS16mjoE4mQWyDkXMkTqiwp/PV1y6CdfaoEKMU64AOUrqt26wHkdq6IlH2eb5rvTxmZXDvs4CsK8VKpEZAasohkwPsvvplPjR8rnNgYlqnZfWavjtk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784379792; c=relaxed/simple; bh=HlHEfXFZJ5xtln/j37UOuB0TCVYBSKyfl8up/yiI9+I=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=m8m+vrmk5S0G9Xpo/teZA1M/E+g9r2Bd6gijojoGsgYC29GvgXrExRF82iczDQ9UK0O3z4csiN3D6BWks6sSPv8YZHEWpEobiGzYYmaVMO2nIOPgkv7M9oAWCIQ7ZrHU11thMJBanfB3qV3DerYNPWZ6gWzUIgCn2+wjMaCk1P4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=So0S9W0U; arc=none smtp.client-ip=209.85.214.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="So0S9W0U" Received: by mail-pl1-f181.google.com with SMTP id d9443c01a7336-2caea3f742bso106621435ad.0 for ; Sat, 18 Jul 2026 06:03:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784379789; x=1784984589; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jPoS/KPRuLJigSPtx3g2dwPFdKf+p/6hoW4Ckw2zIVg=; b=So0S9W0Uev/I3CNjPIlevzhMbRGGW5107rKfsN+lKn27Vwo1wNsNZ0i7psVnW5arRY OONwn81DCPmU6gTvWH0zJlfLd5mYPznsGjZMlZ0iPQhtXRYtl1qERUwW8d0yA97EXaAL 0oALfgwfcFlLjYle/V0qqFS3+y9CEBDlcU9wFEB40jVq1Fp6/B3LZ9fPNoowByElW6n+ ywGRISeybHTzRJ7PT+9edrwUDup2QfPIdqWjybtXgt3U8eSbMzSums1BstuBhtg3ckmb klUSG0Q/N4BSddhuu0qgI7gP5jgTD8tWMuU0Bfo1YgdL6avJRedvaRrCp01/dfz2BFQe mLAg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784379789; x=1784984589; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=jPoS/KPRuLJigSPtx3g2dwPFdKf+p/6hoW4Ckw2zIVg=; b=kT2x6U0/zJ7QNWEGw5cOGBNOenso6SbHkgy24V48ZUVEnZuEOXN2Pq6G7wzYCmkK2p k/WiodsvlnOfEYbf6ISgQ9xQ6JumQF6HlKRSpUW1Uq7c2Ig2klLCs4zHhIgBeHzjnH0C w3F/KWyoOuHpaWjygZRuMz0HytcPFQmFkNzWfpgLn4jzWSyxVxepzmNujxFMzmrD+KEz uFId7mpBd0Otq2L8NlXCTxFEx6rcXTxfSW5uT1Rsifqp51/iZkAF6FpvJmQobLvbn9Zi 5V4usSeULDNqkry8akIOcaDu3Xa3265WYxpCPvLwTSGx4tOB9+EmXxPca1ULhHw1SpiM EadQ== X-Forwarded-Encrypted: i=1; AHgh+RpPxeJi+C7H3WDFF2SFk/FDr/W7IqUEyF33mX/c0ltg/CLjmjrmCQBlJVd94hC3dgRmzRCAzE6/8hFTZqQ=@vger.kernel.org X-Gm-Message-State: AOJu0Ywdo3margVmQDN+a6BuouyWyYHlUhUNTrjObXiocjKUBPS8pNyA Q+ODRNnGMYameyaOuSQrXlpOIS/6ieLC8qM8yD+tci1bi8lWI9dELiaP X-Gm-Gg: AfdE7ckPJa52TwiYrEJ6TwKdXAr9sR3ARNDx3gquITQ0pgk6o7oGIKBPJIQGdVH4Bzg HKR5/JPvbBqJOJzh2JmCYk58L3doI8J/rQ/6X3U7gByxz74xuCmkueMUV8m8zmdr0K1X0cj/6Xc AAARBCOVL0aRAnBRxUlsi4uTvRdu5BBr0S1IyjM6CcNZvqL9S2iJ85wHh3QvL1KgDH8FFd7YdRw 9FKTS5jhj94kfJyxtgvKPJYfCtOJMuHbjjoDJ96RB+OfsqtxyOVwR7dFD3qWseoqCufUxkQywm2 /QO6f5zbQJCn6ZcAGxgJy1VWCep2iWD2ROfzAKa+PX8ocRhb3krqKIxmcg9uDXBrZj8uCBL/7PZ CU0ZHZIkcjecf54Mq8Xu2ohzLcHtc3O7/mJFbYur5GJoF2l9kxnKnKetfkCK9S8yGw26rU5k= X-Received: by 2002:a17:90b:2f85:b0:38e:1497:af5b with SMTP id 98e67ed59e1d1-38e4b3e1015mr6893997a91.1.1784379788951; Sat, 18 Jul 2026 06:03:08 -0700 (PDT) Received: from lgs.. ([2001:250:5800:1000::f280]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38e4aff383dsm2766845a91.8.2026.07.18.06.03.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 18 Jul 2026 06:03:08 -0700 (PDT) From: Guangshuo Li To: Nas Chung , Jackson Lee , Mauro Carvalho Chehab , Nicolas Dufresne , Hans Verkuil , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org Cc: Guangshuo Li Subject: [PATCH v2 2/2] media: chips-media: wave5: Check decoder runtime resume errors Date: Sat, 18 Jul 2026 21:00:37 +0800 Message-ID: <20260718130037.3306626-3-lgs201920130244@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260718130037.3306626-1-lgs201920130244@gmail.com> References: <20260718130037.3306626-1-lgs201920130244@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The decoder start_streaming, stop_streaming and device_run callbacks resume the VPU before accessing hardware, but do not check the return value from pm_runtime_resume_and_get(). If runtime resume fails, continuing can access the VPU while it remains suspended. Since pm_runtime_resume_and_get() does not retain a runtime PM usage reference on failure, the later unconditional pm_runtime_put_autosuspend() can also drop an unmatched reference. Check the return value in all three callbacks. Return queued buffers as required by vb2 when start_streaming fails, clean up buffers without touching hardware when stop_streaming fails, and finish the current mem2mem job when device_run cannot resume. Only call pm_runtime_put_autosuspend() after a successful runtime resume. Fixes: 2092b3833487 ("media: chips-media: wave5: Support runtime suspend/re= sume") Signed-off-by: Guangshuo Li --- .../chips-media/wave5/wave5-vpu-dec.c | 36 +++++++++++++++++-- 1 file changed, 33 insertions(+), 3 deletions(-) diff --git a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c b/dri= vers/media/platform/chips-media/wave5/wave5-vpu-dec.c index 03d108b808ba..bb59bc962603 100644 --- a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c +++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c @@ -1380,7 +1380,11 @@ static int wave5_vpu_dec_start_streaming(struct vb2_= queue *q, unsigned int count int ret =3D 0; =20 dev_dbg(inst->dev->dev, "%s: type: %u\n", __func__, q->type); - pm_runtime_resume_and_get(inst->dev->dev); + ret =3D pm_runtime_resume_and_get(inst->dev->dev); + if (ret < 0) { + wave5_return_bufs(q, VB2_BUF_STATE_QUEUED); + return ret; + } =20 v4l2_m2m_update_start_streaming_state(m2m_ctx, q); =20 @@ -1544,9 +1548,29 @@ static void wave5_vpu_dec_stop_streaming(struct vb2_= queue *q) struct v4l2_m2m_ctx *m2m_ctx =3D inst->v4l2_fh.m2m_ctx; =20 bool check_cmd =3D TRUE; + int ret; =20 dev_dbg(inst->dev->dev, "%s: type: %u\n", __func__, q->type); - pm_runtime_resume_and_get(inst->dev->dev); + ret =3D pm_runtime_resume_and_get(inst->dev->dev); + if (ret < 0) { + struct vpu_src_buffer *vpu_buf; + + v4l2_m2m_update_stop_streaming_state(m2m_ctx, q); + + if (q->type =3D=3D V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE) { + inst->retry =3D false; + inst->queuing_num =3D 0; + while ((vpu_buf =3D inst_src_buf_remove(inst)) !=3D NULL) + ; + inst->eos =3D false; + } + + wave5_return_bufs(q, VB2_BUF_STATE_ERROR); + inst->empty_queue =3D false; + inst->sent_eos =3D false; + return; + } + inst->empty_queue =3D true; while (check_cmd) { struct queue_status_info q_status; @@ -1659,7 +1683,13 @@ static void wave5_vpu_dec_device_run(void *priv) int ret =3D 0; =20 dev_dbg(inst->dev->dev, "%s: Fill the ring buffer with new bitstream data= ", __func__); - pm_runtime_resume_and_get(inst->dev->dev); + + ret =3D pm_runtime_resume_and_get(inst->dev->dev); + if (ret < 0) { + v4l2_m2m_job_finish(inst->v4l2_m2m_dev, m2m_ctx); + return; + } + if (!inst->retry) { ret =3D fill_ringbuffer(inst); if (ret < 0) { --=20 2.43.0