From nobody Fri Oct 2 14:02:43 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 33F962192FA for ; Fri, 31 Jul 2026 00:32:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785457926; cv=none; b=c5n2BqtiMVfi07F4//aJE5fzaqwPNDyinNOe69KbnlJ/NQtxIHwwaBAyVwTNrSp2pWPWvyM+yR9gXu0w+vxNiiJS/AgIliBLROKT2fJTKkvO+7L7eV4RyYvqftbrOpOirJ8rvgWo9KnS/HMyaOFzOE5M0rgE5Jtbj4BFrXxFMZE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785457926; c=relaxed/simple; bh=zgD959mMF/8ySbeK+HmCfcXDYm53NBUcMxUwd7KZ7mw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=hyYyQdWbMiJu/5nKZFMTju8fl+1AwPi/NTvnJid48YUL+lVVOSjoeEHQMmw3mrWR0kTv5aACUWt1tR+o+/HY5zzEWz2S4EdkgQcbrrZyh+yVkku5MszObro28GJRzTufEadPjWsgiWN2qQRzoiWx2EkHq4MrJZJNpyG7Yugr2ns= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=IEJsOyxU; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=KpY6g7df; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="IEJsOyxU"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="KpY6g7df" Received: from pps.filterd (m0279866.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66UMr9FB2008212 for ; Fri, 31 Jul 2026 00:32:03 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= hgdfzEGCpIZsxITOSxtWVRvSfeRmupU6X1LTU4J1VNs=; b=IEJsOyxUbmNiStSv W9s9IysgKx9DAFOW6QJNgVpJNb5hoqfWGN2DCdNTd8daHE0nETo/i1p0+wku0vld VjpqHcKo1rK80GouOLXSrg3HmCKFdJbUlsFJd89a+G4FklE//Y+XIbKV3O0OGGFK 2mKkdZ+ZUK4AhOsYYjlRCNRDH4OMrVYFN26PjAI8erli6nxgNokV+9iYOpKfUo2q Es3UMNiWLYroXBALy90EZYPIbNFeHVZXZrCxDCMANlGjCDHicS/3UcYKUt1BBGtG nYvDhB/YbnQX3HKudF7ChqjjmCxaXeiynW5HfdhRDSIO2KjvfUDGfoGRYFMu/RlL h6Kl6Q== Received: from mail-qt1-f198.google.com (mail-qt1-f198.google.com [209.85.160.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4frfmh091c-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 31 Jul 2026 00:32:03 +0000 (GMT) Received: by mail-qt1-f198.google.com with SMTP id d75a77b69052e-51c21c01cf3so6744971cf.2 for ; Thu, 30 Jul 2026 17:32:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1785457922; x=1786062722; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hgdfzEGCpIZsxITOSxtWVRvSfeRmupU6X1LTU4J1VNs=; b=KpY6g7df7vKe8D7mqyad7wmQm0liiF7sIzaz5DGfkBA5v1GqDKn324S3oK3BW5r3nI 6TrAbphdrasV/gYJjvUxRBLUMuQcA9ObVJ3IEpoZfXcaD/tsNID7eocCnpBrgY0YmQM0 Yqv5RjUxU7VA/i1MtDFc+daxWQURuCFPDQVdIqFv/KKQYqOxz1NIHO6QDwb5tIuTlRkZ XKAjTGuP8NEBFEJwFgxwdHl/VwMiHwQDb5bvj1TUhrqc4S5UhJ5OVKIPPIeAQ2AdU/cU MoXXnZvcX6ZOuvrumwtmPdhJfzMwKe9HJi6cG7enzlWFH3CENtyKlSK4QNTYBaWfzCPh Kl2w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785457922; x=1786062722; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=hgdfzEGCpIZsxITOSxtWVRvSfeRmupU6X1LTU4J1VNs=; b=IWYUBpumfiQtHHpb/to3bPuxk0h7Y/1ZLzE0ZrZY1EcgzMg1cTBj0HslLQdcONiWMQ W8FmhreTS5KfHpItUXCQREFts5Yh+INP7bgIihLndMh+u0Vr5P0ARD7JXmRjmpDrC2U7 XbRTaHg7jW9fpDop1OJvAKnH8yGEEmjl3dptitGM0pbesZF3RjP1LzmlW6X5wy7ZSkz1 Sh7YXedn0dpSy8ourJCWJZiZrWP0LfCTuaeIQXi5ov8Cp0tvzPiVh/321OUPsaL6Fp/4 AV4Ag/GOAtCMHowGFdrMIAIRby8vRsFz86yqumqhizixg3RmN52BtFMiaJqUahAUt7ar UJwA== X-Forwarded-Encrypted: i=1; AHgh+RohNJVzQlk7+E6IFF6wd7O//G0uYPXAGoQg6oVN01LUY6NbUEa79HBqRFU8UMkb0cJtCCUkVTOwDzN3LHk=@vger.kernel.org X-Gm-Message-State: AOJu0Yx1n9QHNj7h+deUBe/5+l/hj1oHlmEo3jV42y7B6r0OSn4mwJ63 y3xfPyZg0LbyxfWsrz3MAr87808Lrk+3F90ddniTOFmA/Whb3ii5NmlUzK9bJ0+yb960uFa9Tei /it2HQSvgxs/xMiPASu0x0ythzgavuWJc2Feh1hEvfBm93tbxAy7QETBDv8rKey4aZMk= X-Gm-Gg: AR+sD13T9fTUjea4fBslByfaqk8x8iJVD4n3FNTBQIMvuaEOPLZdOGXOE/w9CbE7J1C YZgIumZBTvyL0FP4WN4rfKrpVCeM1HBrDMqOruEhpuV2pzYPivYk0+NP39NC89entFNrmuTftSn x38uMb1t8N32mC1MdroyAhHEsKBWgcp7LlaVCEH3rPJB5t5DZWlfpWVL8hdcMXtMf+sjcEi9gMY lCeIiccO+ZwEnDI43dcLt4qXp8Nb/xRO1yegL5vh64Ai+QziAHJW5tIdHBxiCNJu6FFxQJDbFT6 DhaQ0fe9NgIVH/FiuJEN8xUDYWFWO/qxKc8f9SUhwzzI2dD+4GBGXH1Q/TGoZmJZL9pzOvWKh+S FHw1lqXPyMIltSKsKaqCQtYV1L6AftLbtXSawXlgdhyrcVuPUoXvuyYGwbXfxTwnm/GMzbRNbDW Z8AogI0aql2FSCdg== X-Received: by 2002:a05:622a:1249:b0:516:ed02:c85d with SMTP id d75a77b69052e-52b4af3e4d3mr1379691cf.3.1785457922347; Thu, 30 Jul 2026 17:32:02 -0700 (PDT) X-Received: by 2002:a05:622a:1249:b0:516:ed02:c85d with SMTP id d75a77b69052e-52b4af3e4d3mr1379401cf.3.1785457921908; Thu, 30 Jul 2026 17:32:01 -0700 (PDT) Received: from umbar.lan (2001-14ba-a073-af00-264b-feff-fe8b-be8a.rev.dnainternet.fi. [2001:14ba:a073:af00:264b:feff:fe8b:be8a]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-5b2db9d2688sm620538e87.57.2026.07.30.17.31.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 17:31:59 -0700 (PDT) From: Dmitry Baryshkov Date: Fri, 31 Jul 2026 03:31:40 +0300 Subject: [PATCH v2 1/5] media: iris: fail firmware boot on invalid uc_region Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260731-iris-fixes-v2-1-94c002016a09@oss.qualcomm.com> References: <20260731-iris-fixes-v2-0-94c002016a09@oss.qualcomm.com> In-Reply-To: <20260731-iris-fixes-v2-0-94c002016a09@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Abhinav Kumar , Bryan O'Donoghue , Mauro Carvalho Chehab , Hans Verkuil , Stefan Schmidt , Vedang Nagar Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=1528; i=dmitry.baryshkov@oss.qualcomm.com; h=from:subject:message-id; bh=zgD959mMF/8ySbeK+HmCfcXDYm53NBUcMxUwd7KZ7mw=; b=owGbwMvMwMXYbdNlx6SpcZXxtFoSQ1b2m995a5lVprBelxTwCNrQvsHY9b672R5p6+dnXPuT9 od5/trUyWjMwsDIxSArpsjiU9AyNWZTctiHHVPrYQaxMoFMYeDiFICJlJxn/8PP1PHHpVNum2Fx efevv+VXVm54byD9ysE8XsLu7TLh1wEZW+KniaYwlfE/N7cT3LhmV7HT+w8NF5mX5thu9E/Kfvy /+tHB7/bs668oRrrYPoi44iG6K01zdR0n2/rft6VjuI9/ViiuTZKcmLBx7aV993gK+cMfvguczV g1yfGB8Mk7uhfzzzq0Gf/hOTHJJKBeII4zpEqFgVN8Ftt1ucK5ya8WaGb8n650fmnXnd1T30oKp S+/5GvNdF994uSrXKF5TytjYycnaWprSfgpsnzWS+oqfhKwL0392/YNXJtLHKWLt+r4TN/pHLRt 0u9uCQ+Rt++rPH1Wpqid1+79zfjibui+fue9HnaecXsSAA== X-Developer-Key: i=dmitry.baryshkov@oss.qualcomm.com; a=openpgp; fpr=8F88381DD5C873E4AE487DA5199BF1243632046A X-Proofpoint-Spam-Info: AW1haW4tMjYwNzMxMDAwMiBTYWx0ZWRfX+ZjWmKlhqfy2 G1Fac1htNEng0+kh+HO2S+CJumXL35tQzAhvriJoflQ+C32WUBhc+eKX1sUNkdPNz3BJ/oCFEmP WrFPyXS6RtgXBRqPMjYa0hF1E6uVb70= X-Authority-Analysis: v=2.4 cv=evjvCIpX c=1 sm=1 tr=0 ts=6a6bed03 cx=c_pps a=mPf7EqFMSY9/WdsSgAYMbA==:117 a=xqWC_Br6kY4A:10 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=YMgV9FUhrdKAYTUUvYB2:22 a=EUspDBNiAAAA:8 a=bM5zmIW2MuzvGEp2F_gA:9 a=QEXdDO2ut3YA:10 a=dawVfQjAaf238kedN5IG:22 X-Proofpoint-GUID: k_NUxSi7nRotcUxz5itD6elC-Gq4h6XR X-Proofpoint-ORIG-GUID: k_NUxSi7nRotcUxz5itD6elC-Gq4h6XR X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzMxMDAwMiBTYWx0ZWRfXzqAaMQcM256z P9KTAPVazn8IXqQg1i7EQDSaaNYgvJdsjlpYnSb8lTNQsdqd04b+SjjwmROW6xas9czwCzofhq7 980DeNglZ8LaWEN6WRg2H5wBaVQMTgWF0JPfxcpRQz1KQiVEAVgxvAHfmTU4N76XKTpRoqT8SGv lTNy8bLqowv67TJKcOIIcqW9sDvQVypMRjMf+An5MU1NLLhqq4vAb6YQi9dVVC5sGMroV9EClyz meZ+2ljCQ2r9dILvjbjf4dX3HoNYEZdWA64hfuQWjE2lnM0UO/baDNqiTa8b7xH7eUvMxvB12Q6 oYaG3/8IXRBv4cacoGNYQ8ub3Rfkvl2qn0VplME7jxyz1p5rRlIdW1ItAAdMbGDaaH2URoDqmPn 0YmjpNGlHgKW4t4WNNo9WFIu/17MUiRdhWp7IPrQjdJrkNhpMMUWg+313no3kZaMDFd6M51BtS8 4xSSa+Phw5rYq+jfkLw== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-30_07,2026-07-30_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 spamscore=0 clxscore=1015 adultscore=0 suspectscore=0 bulkscore=0 impostorscore=0 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607310002 iris_vpu_boot_firmware() polls CTRL_STATUS while the firmware boots. When the hardware reports an invalid uc_region setting, the poll loop breaks early with count still below max_tries. The following timeout check (count >=3D max_tries) is therefore false, so the function skips the error return and falls through to return 0, reporting a successful boot. The caller then enables host interrupts and proceeds to use firmware that never came up, which can lead to unhandled timeouts or hardware hangs. Return an error directly from the uc_region error path instead of breaking out of the loop and reporting success. Fixes: abf5bac63f68 ("media: iris: implement the boot sequence of the firmw= are") Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Dmitry Baryshkov Reviewed-by: Konrad Dybcio --- drivers/media/platform/qcom/iris/iris_vpu_common.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/media/platform/qcom/iris/iris_vpu_common.c b/drivers/m= edia/platform/qcom/iris/iris_vpu_common.c index e4847c107709..819db7569524 100644 --- a/drivers/media/platform/qcom/iris/iris_vpu_common.c +++ b/drivers/media/platform/qcom/iris/iris_vpu_common.c @@ -84,7 +84,7 @@ int iris_vpu_boot_firmware(struct iris_core *core) ctrl_status =3D readl(core->reg_base + CTRL_STATUS); if ((ctrl_status & CTRL_ERROR_STATUS__M) =3D=3D 0x4) { dev_err(core->dev, "invalid setting for uc_region\n"); - break; + return -EINVAL; } =20 usleep_range(50, 100); --=20 2.47.3 From nobody Fri Oct 2 14:02:43 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3BB5D28B7EA for ; Fri, 31 Jul 2026 00:32:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785457928; cv=none; b=InIDpNXFzLfxH39h7vheTfgsJ9rp4i4vzeaovG3NyzfkE1LNwkZX1eocMjEluslM7ClfNTys4Qi3xYsGVg31VCbvFi5UrRss6uCnUGlJZ2fS1IU2y4pLdV36cIM0OH58XXp0cCq7Lslsg7JyVs6avsSxePU79DD133Acz/9X814= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785457928; c=relaxed/simple; bh=GJ+ySrymWuLsSpYJsvPcJ14/uEgMN/mxqNxIVXzl7aw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=KO0KbRVUmAa6I3fap70SP9adQqW1bT/SHjhp/azpnt7MN8PIkLVmra9lGwAcUFlYhlMaXkMbGWHmTKczq4wDgP8tRvca4FgnEWO+oW2XuWVYnrJ7ZGx8KDS5XOCizUG0yNfYB/0tmSDwSx32IkB070mazepbGmuGeBcaMQ2tQx4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=nwKydO0m; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=hfmOj0tQ; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="nwKydO0m"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="hfmOj0tQ" Received: from pps.filterd (m0279866.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66UMrKKY2011184 for ; Fri, 31 Jul 2026 00:32:05 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= 6zRicdP7MxQ+tTXunDsN7IaxIFcAVLbO4TxnDJ5/5TY=; b=nwKydO0mwX5CsyAC AfBQYKdaIIqf8fYMlx1ZTFu4Nf1qqGZfFHS4WBojRTejnax5qt/cJTVLvFX/GEup wIaxXEUQwqxZeMpHm0EH7nFFUPcQnIDjugongZVWzZZEBNJs6nctO7nUZham8E1V 2RR5WVC6PkimQD9fZsIEwlwb3qhGAVf3yHuOQmedrmCThIgBvYz94HRrzOZkktOi yUzUJuFWZhJnlSzH00gNYvKsEbPMySYtY55ltgjITgCH+ebuNTpqbbFQRk++Txc7 IE/z7t1f1yu772ru50W4gnPN7sWsGbi57W4d/w8D9W6t8Ksbjb/tGMCeGEddmiC4 DEyfEQ== Received: from mail-qt1-f200.google.com (mail-qt1-f200.google.com [209.85.160.200]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4frfmh091g-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 31 Jul 2026 00:32:05 +0000 (GMT) Received: by mail-qt1-f200.google.com with SMTP id d75a77b69052e-51c01ff996dso3582891cf.2 for ; Thu, 30 Jul 2026 17:32:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1785457924; x=1786062724; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6zRicdP7MxQ+tTXunDsN7IaxIFcAVLbO4TxnDJ5/5TY=; b=hfmOj0tQdUrrfAFnaBvg/dojWshgENwCZ16m77trjShPebSfrGzT7MnnZvrCLCU0H0 BovkWeTNXZtHJMv9TGYda1zxMoFX2Himp6nJNOZdNXoqTmEio4/a0I8Ff5PedHq2JCIq ZFVMrwjAWOaAu5mBe2VId0mOUIImuMGlda7ypZbxq/CixnWou+NqjaPkCIQjY0dEA61i w06m3wdFEtYv9DShwtLU6d1PDh1InzFKYnBQGvR6saSjhfx9f3JyGZzgOLaK693IHKvf PC8RgGd9bibsniqEk0lJq+AQ6rolln+huaXA4FDRr0CKyQlO+olfiVc3YmD5ef6NfsPX 4Tzw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785457924; x=1786062724; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=6zRicdP7MxQ+tTXunDsN7IaxIFcAVLbO4TxnDJ5/5TY=; b=Dhz1de+125Jg6j1iHZyk4IhOJSZ7opdwVfvZucxRazfXH2AEMRyK27WCGO3SuGoSQG 6cwEGFkPyTTl9m6PIA2W8X3lOSC+xkSdpjd8b2UsMbdXrQtmQzzmfRRgeoo6pYm2yWNq TzpnIhQX6zKFPTone0vDBk0FhZJ7xB9WJLsbsnaZAESX963tffkHNDMh5lKxkPhsnWlj QCG4bINZbQrCpE3fQ+se5MCG8x6jPe+MYFJcshZEEAuTCoOne8XeZYu0pt6/DhPExr46 4KgMG+cxkjb9SjohfvNpZgdLnWGTBQXXJK5+u5Sdmhu9A/PKEIWLyzS1si/D2e8KvTd/ S93A== X-Forwarded-Encrypted: i=1; AHgh+RqTGaWednog7kTM3QU/gCaA81dQ++JuxugyVx6oqC4jirgNXKRz/M0fxSM06VBlrJmMruijWfEkPBvWj3E=@vger.kernel.org X-Gm-Message-State: AOJu0YwT5In2BFPLjdMzh6NswcoGJW2Qr22MT275uFEIQH+jFzzurc1K CZrKMGeqQyFlWxVJ9/KjuQmannZRavGy8hyqlf2GWRiJkh7tzoJlWxajo1BjKH1yuBvwfBsof92 Lu8udwTpgQUVlPL+dNHG9tfflLHW+nB5+U4CicbXWpNBbmppxG/DXAVZjCZUOpPyRHC4= X-Gm-Gg: AR+sD12mGHyYrKdkEsJxC4wdhFiX1VcPvfy26K5m9eYkZ6LCGwt8PfGB+XcdbGyRn+J kPgKKRmL15h18ZPdzgeUwhjzwZFbMqo3swrPDpsx8Ui9aiOMs/Y3GlU8vA6E569XVqHYN8RefuM 7/jcNFTwUAXKrzs7L7YDvi/H1bImiOF2Jy8NPjpvR0+lzFcgm3u1uKXC9ZsH43DbEfzu5shmyOi L4lviSTYGeE+JnRQRa+56bjVlL8i8Psdx0dxWrIpEqwfh1oMFF+KfiFENE3xWqjOADeX0A9PEHF 6VBaYeg3UtvKB68HrBd33YeyhqfuuK+83qJlskjusNwLNAfiwki/BeR6A+DWGqVpGkP/AxNbfxE Ye5e0DkVXhw96HAMwNTxSkRIN6ob4FpRpkEbRujZx98Alr6JRFjBGixvTPnFbel8KXW6h0AwH5S 7evBGMh38aFwoXOg== X-Received: by 2002:a05:6214:419b:b0:8f3:f17a:a3f with SMTP id 6a1803df08f44-9084218f8bemr1689006d6.3.1785457924511; Thu, 30 Jul 2026 17:32:04 -0700 (PDT) X-Received: by 2002:a05:6214:419b:b0:8f3:f17a:a3f with SMTP id 6a1803df08f44-9084218f8bemr1688476d6.3.1785457923900; Thu, 30 Jul 2026 17:32:03 -0700 (PDT) Received: from umbar.lan (2001-14ba-a073-af00-264b-feff-fe8b-be8a.rev.dnainternet.fi. [2001:14ba:a073:af00:264b:feff:fe8b:be8a]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-5b2db9d2688sm620538e87.57.2026.07.30.17.32.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 17:32:02 -0700 (PDT) From: Dmitry Baryshkov Date: Fri, 31 Jul 2026 03:31:41 +0300 Subject: [PATCH v2 2/5] media: iris: take core lock when scanning the instance list Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260731-iris-fixes-v2-2-94c002016a09@oss.qualcomm.com> References: <20260731-iris-fixes-v2-0-94c002016a09@oss.qualcomm.com> In-Reply-To: <20260731-iris-fixes-v2-0-94c002016a09@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Abhinav Kumar , Bryan O'Donoghue , Mauro Carvalho Chehab , Hans Verkuil , Stefan Schmidt , Vedang Nagar Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=1561; i=dmitry.baryshkov@oss.qualcomm.com; h=from:subject:message-id; bh=GJ+ySrymWuLsSpYJsvPcJ14/uEgMN/mxqNxIVXzl7aw=; b=owEBbQGS/pANAwAKAYs8ij4CKSjVAcsmYgBqa+z8MQFsNBb3TBsAfK8BUIfgXStvOqqp1Z6iw lcmLnE9gI6JATMEAAEKAB0WIQRMcISVXLJjVvC4lX+LPIo+Aiko1QUCamvs/AAKCRCLPIo+Aiko 1elZCAClq7OZugFOwpA/5R6/SUxPPk8GxXUGQdoEOcprMHOHoyk6dsBqIrqspVjlaM2AWyHdUsB KxtKosGjTAv2s0whbOjZDTo0uExwW32+e41pZYX244DprxHGcumdl4b2JE1iMFG8TxZLEGwyclW SGGLdZr5/ynMED94pr2wdO+ngcenOgY1RjAiwcADE6dZfei7X2MwPlDt7GifvXQgXH61/NsrXQt VnekzUYVsK0caDfAYGxTfAhhoEq+Cm9cMnYAZ6+WPYWqg8HwwBpo0WazvU0cz00+QCVUy5PfvBx Tqofi9pAQa/RETvcBr6hkSHo3zie44oDsBO1SmazHHACXep0 X-Developer-Key: i=dmitry.baryshkov@oss.qualcomm.com; a=openpgp; fpr=8F88381DD5C873E4AE487DA5199BF1243632046A X-Proofpoint-Spam-Info: AW1haW4tMjYwNzMxMDAwMiBTYWx0ZWRfX6LIi71IBxyO3 Rkqw5US/mcIBS7J1YBzXLOJ4AEFnv5M7kwPQ8x4Vu4BaNz1Ok598nfOP3dz/iMlzBc6Su3YRn4m lCHX+5OD9iczF9WfkLEo+C8kgNsQBBc= X-Authority-Analysis: v=2.4 cv=evjvCIpX c=1 sm=1 tr=0 ts=6a6bed05 cx=c_pps a=JbAStetqSzwMeJznSMzCyw==:117 a=xqWC_Br6kY4A:10 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=YMgV9FUhrdKAYTUUvYB2:22 a=EUspDBNiAAAA:8 a=ArhRcrGwThaRUb-MlkEA:9 a=QEXdDO2ut3YA:10 a=uxP6HrT_eTzRwkO_Te1X:22 X-Proofpoint-GUID: DUnpW1ezKqvxuwWXi-FNrVQ06R_XDMCB X-Proofpoint-ORIG-GUID: DUnpW1ezKqvxuwWXi-FNrVQ06R_XDMCB X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzMxMDAwMiBTYWx0ZWRfXwONEqXZK3/u3 e69p6z86Fa2imSCxupPOk7RGaubjIyvsBRA5dEC7IGTsFh1BqtAaIRCULy+vLEms3qMWPKpM47S 7lgdUDydo/A9M2Tv6yugVzcuS31hs2X761sQq4HIcYJQEalm7p+G2HTaW++WfCde6pPKUcOwJyJ aZCQIx1TQg4CIwk36Bece1lPSNZDlqH2N9x6ogXyRFET/ySWBDf4y0/MUoMLsnzt6ruNXOQxiam rvZfRte4DLfXCmCvS29sdDQi9zRg283Rb2uhYhfxbctnWaUn0ZeoCOAT1u3eN4Q/Tt8Gcmvd89s nHZziMWQraTnIDOkrkmjK/+Zyj5OaEYuE12jnb1xmlZd2q/oJ58DQEOKkKHMFs/s+ZInv9sX/H6 r7o9HdxhNT7jVYL5NGMGRPeI7TSnlInQsqvn++upEa3USfjiXdATVruOIfExSYepKrXi0v/rZgq GOhwbQGbaZUmAPWjFsg== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-30_07,2026-07-30_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 spamscore=0 clxscore=1015 adultscore=0 suspectscore=0 bulkscore=0 impostorscore=0 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607310002 iris_check_session_supported() walks core->instances to confirm the current instance is registered, but does so without holding core->lock. A concurrent iris_close() takes core->lock and removes a (possibly different) instance from the list via list_del_init() before freeing it, so the lockless traversal can follow a freed pointer and dereference it, resulting in a use-after-free. Hold core->lock across the list traversal, matching the other iterators over core->instances such as iris_check_core_mbpf(). The lock is dropped before iris_check_core_mbpf() is called so the nesting is unchanged. Fixes: bdbe1cac0c10 ("media: iris: add check whether the video session is s= upported or not") Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Dmitry Baryshkov Reviewed-by: Konrad Dybcio --- drivers/media/platform/qcom/iris/iris_vb2.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/drivers/media/platform/qcom/iris/iris_vb2.c b/drivers/media/pl= atform/qcom/iris/iris_vb2.c index a2ea2d67f60d..8faf709c26c1 100644 --- a/drivers/media/platform/qcom/iris/iris_vb2.c +++ b/drivers/media/platform/qcom/iris/iris_vb2.c @@ -56,10 +56,14 @@ static int iris_check_session_supported(struct iris_ins= t *inst) bool found =3D false; int ret; =20 + mutex_lock(&core->lock); list_for_each_entry(instance, &core->instances, list) { - if (instance =3D=3D inst) + if (instance =3D=3D inst) { found =3D true; + break; + } } + mutex_unlock(&core->lock); =20 if (!found) { ret =3D -EINVAL; --=20 2.47.3 From nobody Fri Oct 2 14:02:43 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1E26C286D56 for ; Fri, 31 Jul 2026 00:32:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785457933; cv=none; b=NvOocb2v1th4u1XqddcczpfgJXqcQC3NYy//9JRU6BdCDvgP5CSzDmWbb9yHven1kkwx6sIMebt/ivcmsXrJRGZq4fSKQD1S94ywdZVjQbRNJkdYSpWmtc/huKAx8wefDsbFxPUcV7717UoMRlTOMaxJXrpANctgdyOM+LQVTPQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785457933; c=relaxed/simple; bh=88z5nx8vnFxzRCkkWynqATznmifWM76c1v/eINoop54=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=CGoprhugFZaBLgETHW2Ku/fv8dSmA/cg1fW1+a+JEXpxkqf1l8nurGTphXm8Sy4ajVFGZKyx5lMz4DJONVcWuPmreWcRMFQTODL0wywF30StI6vMAj4MXYUE7WWUptCAiKf1jEP77a8LFCZEIpLU2Knqa0UDZn9x2gZr4/a/o6c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=ZQso/E3L; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=P/h/A0h1; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="ZQso/E3L"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="P/h/A0h1" Received: from pps.filterd (m0279862.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66V0Lrpa2306153 for ; Fri, 31 Jul 2026 00:32:11 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= L/TwLWtG06x2BbiNOlF/3UZu3lQuv4b0JIWImEHpR30=; b=ZQso/E3LBPr1ONYa 0OYbuXaRY1oXoWNZj082/SsYCp8oCqP5lmiqFnqIqZ4W4sTobc/oM3y4gvWmpxTw qgf7rsLPbZNrhG50yTl7C40NWQSM9hKFcZXnD0hPbrsvILhA9k46PIG4DwXAkvrI XSJbdgD0B+gf9w5ZYZLQJ8aMRHgO4wgPRekY+LA450sDd8M/IctKxhqlNPlW+7pH TVnPk3+juyDuk7qLAHPWBfOKHYr8lDnyrtP8voCuoIk/xQniLNzsF53PaHeZc2KY hd9j1WPFsfoHOPBjaDOs19838d1ILt7emHWvj6d8b1p0hqtlu8xgOpOfMQEOjdKE XcgOPQ== Received: from mail-qt1-f197.google.com (mail-qt1-f197.google.com [209.85.160.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4frh3nr0u7-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 31 Jul 2026 00:32:11 +0000 (GMT) Received: by mail-qt1-f197.google.com with SMTP id d75a77b69052e-5283df62d68so3750291cf.0 for ; Thu, 30 Jul 2026 17:32:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1785457930; x=1786062730; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=L/TwLWtG06x2BbiNOlF/3UZu3lQuv4b0JIWImEHpR30=; b=P/h/A0h1XA8wjRv7mnHvxUoY1xQQznz48b7rHnNEOj6yXMNhfcG34rpEyz31y9u8RC LK1ZXazfMbYUXa/bBPcE/XAHhfuH12S3SwHqlmvbAFvSavc2+WE3X/O+aPtWcq1qkkA+ eu77VOpSM1RpKI5EKBVhEbo0/E4KmC2QRTJqSbY+qKqJmQf4K9hF/xaPDgxeDVtOQu5D qYlFdGnQkKp99+mdYioHdGKSRZQS7VaByX7D34htjGlWrlvSQpqyZo4fjQTFCg6hmDGL WFqf9Yrhbikga9HfnqGQOAa2ApYlNFtC0hoXpqyUOcJ7RhWSzltFFhfVHPuTyHaqVxpF DIjg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785457930; x=1786062730; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=L/TwLWtG06x2BbiNOlF/3UZu3lQuv4b0JIWImEHpR30=; b=sVBD4J2JjyvkTOaKNooG6r+hkjbLPYBWo5pS03cLQyYg+TVFHvv5osIcRUm2DyK3qD oy+G6U5fcIvi1ZXS3rDD8b6WGsWpzmwqwpBbtzIyVB/OpdRn5wH0Q0QQGJBw259Dc6Fx e+OpGvoXGeHsmj8DLo4O/Z0ZtHpvDrCnQuzlq7zZZS92JsP5ULvSwwEh+7Yp1A75f/5a KW2XVN4ssz+Ywy01RR/ggMoiyI2ciWcDTjgmHRoo5YbsJy9w9SBbhFD+GHstgz1d+kZx S6hpLTkpHN0w7GxE3WoMqft1ja4V/cwn7bxYdpPmNKXiAwz0m9rnSPE5W71JhtfqjQWT YFYQ== X-Forwarded-Encrypted: i=1; AHgh+RogieWDrL09TFlgOf6FTcqEQ0g1m8lQJ/vJ9dW6qPXgRWNgFl3NI2rmr5RtkFK8u0LzanVuThQRdIwjvsI=@vger.kernel.org X-Gm-Message-State: AOJu0Yzo8BC0gtTR8+PG5AphYk4erfGbsO33qPLrB3Gvo8RHdKnppHgU 0ZeD5rJqIAnGu3z19Rvosce/nhHCJTFVlTWP0laHApV2i8cW2X+gPMqeNji/ajA9+xSEuNsKutw mDZhYDq8txV5ljt37nIUrmgAVK5HVo6AGM4AORh4XV1hgZmqTYbIkT//04Mv8pjbO60Y= X-Gm-Gg: AR+sD11V/5QgtB/Pj73JdXod1QJzYStl1+Swg/twVJ7RApRSy/ZzewmHHsoIRgnE57q E6eqiYsFgLo2t/9GtSbvlcx+oWI3p0GGbgcPM6ZV4fOYGcC05J6+P7hlwE4NOXMcAydQwDmkrPB excpmoW2Thw7CpvxWUn0fXGFt+fQeDMqSreaUF4lobOE80G9MZI+EZdhCNjBJHHTuDlr6iwes2o +ZHhJ2ciVRXe7PFxTOPqJ0154a/5IhCNlZBNX9PWqnc8RnPvU/kpoXQv2PS7oQuFm6qOF2ph8zG CkbwMP9c5hnvHhV0bsB5Ju6OuykpsaasA44lHYpn7DOZhLbwri1cJKj4uAn0TaeotSxv6ITy64v Q1u4DY+72KTW8eCqLRo9NG1dqw4pi/N8wPqw4gGfCZWCL5zTWsVnKKNJbxaMAxvc4MZcyxE0ATn Q/WbaI1X6Mle12QQ== X-Received: by 2002:ac8:5aca:0:b0:517:9095:c329 with SMTP id d75a77b69052e-52b4b04ec02mr861591cf.45.1785457930158; Thu, 30 Jul 2026 17:32:10 -0700 (PDT) X-Received: by 2002:ac8:5aca:0:b0:517:9095:c329 with SMTP id d75a77b69052e-52b4b04ec02mr861191cf.45.1785457929603; Thu, 30 Jul 2026 17:32:09 -0700 (PDT) Received: from umbar.lan (2001-14ba-a073-af00-264b-feff-fe8b-be8a.rev.dnainternet.fi. [2001:14ba:a073:af00:264b:feff:fe8b:be8a]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-5b2db9d2688sm620538e87.57.2026.07.30.17.32.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 17:32:04 -0700 (PDT) From: Dmitry Baryshkov Date: Fri, 31 Jul 2026 03:31:42 +0300 Subject: [PATCH v2 3/5] media: iris: guard against a NULL hfi_sys_ops in the interrupt handler Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260731-iris-fixes-v2-3-94c002016a09@oss.qualcomm.com> References: <20260731-iris-fixes-v2-0-94c002016a09@oss.qualcomm.com> In-Reply-To: <20260731-iris-fixes-v2-0-94c002016a09@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Abhinav Kumar , Bryan O'Donoghue , Mauro Carvalho Chehab , Hans Verkuil , Stefan Schmidt , Vedang Nagar Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, Konrad Dybcio X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=1484; i=dmitry.baryshkov@oss.qualcomm.com; h=from:subject:message-id; bh=88z5nx8vnFxzRCkkWynqATznmifWM76c1v/eINoop54=; b=owEBbQGS/pANAwAKAYs8ij4CKSjVAcsmYgBqa+z80NSccOHSvCFa+lWguNSgcv7XcJiPt2XHi 8+ptf8lnSGJATMEAAEKAB0WIQRMcISVXLJjVvC4lX+LPIo+Aiko1QUCamvs/AAKCRCLPIo+Aiko 1cIcCACVPeNiauf0KRevIRsTh3xRlagTJP0YxD5EUkQodHPaBAUo1Fbm1F+h0k4nBjV0ThdUlcX +BMtn2YK2d8poz9FDCvE6h22DlRmvk2GGjYP1/WIab64IH1p4djcQgFcGsXpdTs2kFgycmSJwoU mO3WjZFpWELBNpc7Wgj1b93C1J/YGwJHtyS7ipDqogTvRm6pt6tT6eS4S0K/neGVuDE4vmyV1TL 9sMO37hJXXHLtyRcwqunpyq10yFZULeXSZAezXv7OkoLNlz88iQoiLPn4YJcjJxpNU68WWU+1G7 feFFoEq54cnTI7wd6/Iq6u/a5RqdBv48MNm2wVhd5perQv+d X-Developer-Key: i=dmitry.baryshkov@oss.qualcomm.com; a=openpgp; fpr=8F88381DD5C873E4AE487DA5199BF1243632046A X-Proofpoint-Spam-Info: AW1haW4tMjYwNzMxMDAwMiBTYWx0ZWRfXx0SGlR7bG4nc tBjy7hxnxhuRxPudhjLcEIM5ZkCkZYa51uyFodVjlhsaIGjMzdxxkaQyQbMdtgnqa00RcTcyrFi Z4CSLVq8ITM8stUijpWPAmhcYriH1pE= X-Proofpoint-GUID: xTLg3wmFwveZHHbUHrfBKV5hvGJFfwe3 X-Proofpoint-ORIG-GUID: xTLg3wmFwveZHHbUHrfBKV5hvGJFfwe3 X-Authority-Analysis: v=2.4 cv=W8UIkxWk c=1 sm=1 tr=0 ts=6a6bed0b cx=c_pps a=EVbN6Ke/fEF3bsl7X48z0g==:117 a=xqWC_Br6kY4A:10 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_K5XuSEh1TEqbUxoQ0s3:22 a=EUspDBNiAAAA:8 a=gNVOA7K2X4zeF1vqfc8A:9 a=QEXdDO2ut3YA:10 a=a_PwQJl-kcHnX1M80qC6:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzMxMDAwMiBTYWx0ZWRfXzkQGQldm41LU fLWjt+W8lu15w+jIJhD22yUqnW97XZlVouxNJh950mzMGAIe5BmSGy1zNIAVQltHJE96+y0Ebns KLMXXQ453/dfYN/ExnIcVn5vJeY02sth5aZOOo8BNspJKZCCwPZdKvdaSBk+7wX3kFQDMPYAKTB REeEtm5qu6pjttNp2I2IW++6KUVXqxC0qp8tEqO06bbxXfbfLhBF10i3yb0+7ZWAecy9luVFmvj kfvDUo6VY1ytA+WQmhjvBPqSU6L4c0SzeH1z2tUOjFi11ZL227rjDIplNhVlD9KICj/ctJueKti JS5JY1UYH6csNB2abpx65vAjHzcxlDVcXl30S3hvyZ9Kxv2/OwzNL++yrfBKqfIhgTXsSR5Rn6G yy3XRReWiI0CVjrXn4PG4km6k7eOxOeM6mbrYLXJKz9lSFknjNROTrgtqZFkdg+H3PnpXj3/eHI LG7cBkhWxw5MZCMTOyw== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-30_07,2026-07-30_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 suspectscore=0 priorityscore=1501 phishscore=0 impostorscore=0 malwarescore=0 lowpriorityscore=0 clxscore=1015 spamscore=0 adultscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607310002 core->hfi_sys_ops is populated only during core bring-up, once the firmware generation has been detected. iris_vpu_power_on() enables interrupts earlier than that, so an interrupt (for instance a spurious one) that fires in this window makes iris_hfi_isr_handler() unconditionally dereference a NULL core->hfi_sys_ops and panic. Skip the response handler when hfi_sys_ops has not been set up yet; the interrupt is still acknowledged and the line re-enabled. Fixes: d8a6a63372b8 ("media: qcom: iris: merge hfi_response_ops and hfi_com= mand_ops") Assisted-by: Claude:claude-opus-4-8 Reviewed-by: Konrad Dybcio Signed-off-by: Dmitry Baryshkov --- drivers/media/platform/qcom/iris/iris_hfi_common.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/media/platform/qcom/iris/iris_hfi_common.c b/drivers/m= edia/platform/qcom/iris/iris_hfi_common.c index 8769ec61f117..42fc854d4c05 100644 --- a/drivers/media/platform/qcom/iris/iris_hfi_common.c +++ b/drivers/media/platform/qcom/iris/iris_hfi_common.c @@ -109,7 +109,8 @@ irqreturn_t iris_hfi_isr_handler(int irq, void *data) iris_vpu_clear_interrupt(core); mutex_unlock(&core->lock); =20 - core->hfi_sys_ops->sys_hfi_response_handler(core); + if (core->hfi_sys_ops) + core->hfi_sys_ops->sys_hfi_response_handler(core); =20 if (!iris_vpu_watchdog(core, core->intr_status)) enable_irq(irq); --=20 2.47.3 From nobody Fri Oct 2 14:02:43 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 944F02BE05A for ; Fri, 31 Jul 2026 00:32:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785457936; cv=none; b=HNnLsuvt4L15E49N11W5B7VBoO4IeXm/U4mjr+pMcargDa+iidFZJSsjT4WA8U74V3/e99vGO7UJx+tcq/GAF0Qgl7nOdkG0yzNsOrcWzCqi+aUXS5/I98EMEup7UHvrOYhfb0JLv8fDYzI1s75yWfsbfCdTdbYFTVclYW+I8iY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785457936; c=relaxed/simple; bh=UTnwS/2KKMHvEnj1G5hWv78QxtNSfDbjsv+TIRCZ8q0=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=ekM1Dp79Q7H0X19omGWZEHAPTLGxhF+Bs0HXA/Xo5o6icY4LJjR1sww+b8U6bjrw5Ow7+0MbP6ee3W7BhJJNeJwd6tELp8gQWKYfZkQHZgI2KBhTvqxllOpk5jgpCQaByIWxr5hbZ8RinrJv/hS113tdGVASHC0QYIVd0xUqsdE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=WmAOihVd; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=Ku85ieRN; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="WmAOihVd"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="Ku85ieRN" Received: from pps.filterd (m0279865.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66UMxkC42683587 for ; Fri, 31 Jul 2026 00:32:13 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= IVKIsROaFLrBTWGGnB2cmBVxI+DUX5fudtaQeIbEl+s=; b=WmAOihVd/qdE7Me5 pjnb+kgRM1KpWULzNSUdQCU9bbnkeUFpV8i6X34noTvjsn5BGYyaVEJf+q2+ZWUr l7C7GuS/DlkebekZ6NC3R/Wlhg2RLpQw/3r7Ocn+Qi8oYSSMebOfwBooGIaJkWx/ 9MnvCvgEizR7bFvCqEzPh3Du0Y73ErCXWJ7mMX5BeW9PH0jX+pCi7hiy0v9Lw6OZ RHzYOFR3JJikFsRn7ShOx0ouoHY7DEbzmCFbwwb479joUOAehlJIQjnao/RDeUfR DVwaml4lUqI4o3aTLNbREHrduTlsaYnpSHbaQgQk/WFEGNroHMhmfXTYBB6I5VMM fmGq5g== Received: from mail-qt1-f198.google.com (mail-qt1-f198.google.com [209.85.160.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4frfw5r7ns-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 31 Jul 2026 00:32:13 +0000 (GMT) Received: by mail-qt1-f198.google.com with SMTP id d75a77b69052e-51ebdfceddcso3431631cf.3 for ; Thu, 30 Jul 2026 17:32:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1785457932; x=1786062732; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=IVKIsROaFLrBTWGGnB2cmBVxI+DUX5fudtaQeIbEl+s=; b=Ku85ieRNk1gI57h7boe5FGbD26zTcglsakeM82EX0pS6JgETijAwDMvoQdPvcJ0o+M DaJf42sA0Y8KsiMDyv/g/innahpW6Sb6Kx/ZsOSYCO40GkRPLdPIWChRDqvY8TlYgC5B zYRKZeohnQlXeHhh9EBpaEAbw3JBtgwDoO7Nk90uzYDXCa6+cL8MEZppwB+APIIVHbb/ yCqwv7FdaxRgyev/Vgu6Ruo/4V7nbzQq/8uu9dYuUwEr1oKZjYOE1TZ2TOQmwwcMuZ4o jWMLa0jiFCTSlAzMngt9Jvsmq/j8OGYJ2RBum6ES719w1NvO/R4mD+Zkb2KY+WsFog7C DUgA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785457932; x=1786062732; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=IVKIsROaFLrBTWGGnB2cmBVxI+DUX5fudtaQeIbEl+s=; b=pHCcyelzRgliyGu7Qd+q7x85QTh3KM4fDnLncFys+zIw0vasseM8J3QvRgpQTd1XK1 27vdTtM+PVDhkdDAB2XX7wq9O7I7TeODQbU8UM5maB8l3xuIIlEvT6sX47g14/JG8pvA tnXOWol+pZLiA8XLueOzRc1NvXg/dCW/xmSMvIS9UV43ynsRS77ZtRvtx/zVGwhhXUK9 nfdp9diqU04d/sWRuSBDo74jZmspKWfzTfQl57ZzWqHGy+/xTE7ozkWBgN9PR9NiDwpL IAuRq4xYEOhtX2Mgk1VsWE2/of8R+gs11GW10C7ru7yzBQ03ayQlg7KZN5LqcSEJqcN9 6DDw== X-Forwarded-Encrypted: i=1; AHgh+RpI+a/ydj3ba6QxfH5ItmJGyce8yyE2dZNTbtiIe1pZgoc1brPkQ+dCtiEC72GkeQI4FvS1N6fsr4v4xJc=@vger.kernel.org X-Gm-Message-State: AOJu0YzhQb1NWTr4qT/WrG/Jttx58qNeEBlogDASyiOze67orOwpQTVi UpsFeRRLr42aKqEJUkvIdBOEBhZEnO/W2TGF5OaDIbQgoTrIwpnDDnwVVXglYeBVnhL5b2geQzv UYV2WlYI6mZ1JaZSqKfkjvnBtgr/ugEBu0skuGzdaHvbs5dxLD9yrGENBiuKIUc1ZuLg= X-Gm-Gg: AR+sD11SzPibufrUhNHmJYjk69/sfVPjXFI5AtCH+tU0hxY29GWIZflHHFF/j0Q9M5s EAWjR8o5Ceu1IuTGbm4mDo2GQ9++EoTjMPuGJUmORHy7Kn4sV7iZS9BNTxwHb0/iC7apH/LHjJf vC/CWSKCh26CHOoVGIGvUcpPiv6qEvwNHkiqulENvsJhpuh1S77YixMcJ72uRuBU6e3Y2IWqHLm j/f/QLbVq4zqhLqeKzEEx7VwEPtP+aZ/bxmCsaRaryDpO5SRwUwwtZlE/1GPR4DQyvlZkbkVFSL Z+N/WwncxfsXEe2nKWJyZVV6ryWKnKsNBehc2U0YE2VDgPgRbfxMQHxZxS4wslIh2r+V2HlVN3t ZAAkSm8jzBFt1AJ+utC9hV6wGHxWg/EbZPMrlDNIEzqjMdIGAECi4YPNWDi55g/+mbgNKc5aXZs qjx0wi1wdTVvWngw== X-Received: by 2002:a05:622a:2509:b0:51a:8c97:9383 with SMTP id d75a77b69052e-52b4b07c9c0mr964381cf.58.1785457932284; Thu, 30 Jul 2026 17:32:12 -0700 (PDT) X-Received: by 2002:a05:622a:2509:b0:51a:8c97:9383 with SMTP id d75a77b69052e-52b4b07c9c0mr964171cf.58.1785457931876; Thu, 30 Jul 2026 17:32:11 -0700 (PDT) Received: from umbar.lan (2001-14ba-a073-af00-264b-feff-fe8b-be8a.rev.dnainternet.fi. [2001:14ba:a073:af00:264b:feff:fe8b:be8a]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-5b2db9d2688sm620538e87.57.2026.07.30.17.32.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 17:32:10 -0700 (PDT) From: Dmitry Baryshkov Date: Fri, 31 Jul 2026 03:31:43 +0300 Subject: [PATCH v2 4/5] media: iris: reject open() when the session limit is reached Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260731-iris-fixes-v2-4-94c002016a09@oss.qualcomm.com> References: <20260731-iris-fixes-v2-0-94c002016a09@oss.qualcomm.com> In-Reply-To: <20260731-iris-fixes-v2-0-94c002016a09@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Abhinav Kumar , Bryan O'Donoghue , Mauro Carvalho Chehab , Hans Verkuil , Stefan Schmidt , Vedang Nagar Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=2304; i=dmitry.baryshkov@oss.qualcomm.com; h=from:subject:message-id; bh=UTnwS/2KKMHvEnj1G5hWv78QxtNSfDbjsv+TIRCZ8q0=; b=owEBbQGS/pANAwAKAYs8ij4CKSjVAcsmYgBqa+z8pcYXFxCxQYZ5HVdyRAo+4mAppT+Dx+uFq z+/3vsTq3GJATMEAAEKAB0WIQRMcISVXLJjVvC4lX+LPIo+Aiko1QUCamvs/AAKCRCLPIo+Aiko 1RbUB/96EDm0/+sFBiakv8N/d/MwqjNAj3xbQZgcnod2Mz46RHG23UrI9zlAotJhcq7K9JxEoNQ W8xVZLXCcuMFnXEzyeKDHZXpNF2VSlfP/jQlhv7v1MTuNedpnI5jr+qniO2/prGams3F/LJep0g 7NvCfxRK6qFXdOXDWqx5PCa3Pi5/HIBCU5IlFMIOUwRdgCsCNCTogvH5qjWkmEUPsZonZxPXJEm zlMAbItBMOZTtJW0AepRvuxRXcWtRpfhunZvZiKRMfkfQYMUIV+38KT1Hz9GORoyWREWdUyiuqA fRTserw2he5KlEhODQhvZdZKJH9nVPiGJ1qQ0OWJUlOby35F X-Developer-Key: i=dmitry.baryshkov@oss.qualcomm.com; a=openpgp; fpr=8F88381DD5C873E4AE487DA5199BF1243632046A X-Proofpoint-GUID: BNnCB1tT2dkkskt_8oxe2Nc6JRnbDyZZ X-Proofpoint-Spam-Info: AW1haW4tMjYwNzMxMDAwMiBTYWx0ZWRfX9ypRAHs4LoWE 6NBAheWkukX7X/rw3lMlLbBUXEjGTtRtTuRGc8jhrFy7S0esmrLy9CGTB6hYQ3BwQFD1ai2dMpa Q7E90TniSHpYmu9vWy7qmrhrOLG2B9g= X-Proofpoint-ORIG-GUID: BNnCB1tT2dkkskt_8oxe2Nc6JRnbDyZZ X-Authority-Analysis: v=2.4 cv=DconbPtW c=1 sm=1 tr=0 ts=6a6bed0d cx=c_pps a=mPf7EqFMSY9/WdsSgAYMbA==:117 a=xqWC_Br6kY4A:10 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=Um2Pa8k9VHT-vaBCBUpS:22 a=EUspDBNiAAAA:8 a=8bbKkYRu5Ug-Ka50F9MA:9 a=QEXdDO2ut3YA:10 a=dawVfQjAaf238kedN5IG:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzMxMDAwMiBTYWx0ZWRfX5UAmR/zGAAsi tlKEnsr4ePhwc8gS3Xa8AxQfdAncyZocFbR985tZevoQ4CAqojRJq3KM7a7aaDWh6qOdWYATwmb X54M0YA22sUAZ0BdZSA94D2tiXYaadp8fjjb39NAlqq7RtQo9K92OkdNm3Eu6kv9SPFwyQf1WOe 4XAMe6vtK9BzqwKQalAEut8newRCVx9j0/FTBlP/2Tqv6L5CZASp+1IOlXEwakFezHWtBtuy2bW 9UmghAeiblkbUjtmNNby+Kdi4UohrHpb/nmo8jjO/HMgcD1elAedh+yeNHymcG/fCZwnYpLJJHS wW1ZNwCpdm221Bv9a9tQb+6myjMwwnTQB1fJS1zqkS5QimdbMqQr82W7541agaGmTITLpWcMVUE UnMQyBAiH0lmeNVRm4d2L5ypeDbczxLZzeXjV+WbiI3ERF5a+zHdpM2ykVYBJVN//9x8gXHHYw/ 75COz4y5a92GHTc9vCQ== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-30_07,2026-07-30_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 adultscore=0 phishscore=0 priorityscore=1501 clxscore=1015 bulkscore=0 impostorscore=0 suspectscore=0 lowpriorityscore=0 spamscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607310002 iris_add_session() silently skips adding the instance to core->instances once max_session_count is reached, but returns void, so iris_open() continues as if it succeeded and hands a file descriptor back to userspace. As the instance is not on core->instances, firmware responses for it are dropped and every subsequent ioctl times out. Make iris_add_session() return an error when the limit is reached and fail iris_open() accordingly, freeing the partially initialised instance. Fixes: 38fc8beaba55 ("media: iris: implement reqbuf ioctl with vb2_queue_se= tup") Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Dmitry Baryshkov Reviewed-by: Konrad Dybcio --- drivers/media/platform/qcom/iris/iris_vidc.c | 19 +++++++++++++------ 1 file changed, 13 insertions(+), 6 deletions(-) diff --git a/drivers/media/platform/qcom/iris/iris_vidc.c b/drivers/media/p= latform/qcom/iris/iris_vidc.c index fcbc60016bee..4ca9185b3d2b 100644 --- a/drivers/media/platform/qcom/iris/iris_vidc.c +++ b/drivers/media/platform/qcom/iris/iris_vidc.c @@ -40,21 +40,23 @@ static void iris_v4l2_fh_deinit(struct iris_inst *inst,= struct file *filp) v4l2_fh_exit(&inst->fh); } =20 -static void iris_add_session(struct iris_inst *inst) +static int iris_add_session(struct iris_inst *inst) { struct iris_core *core =3D inst->core; struct iris_inst *iter; u32 count =3D 0; =20 - mutex_lock(&core->lock); + guard(mutex)(&core->lock); =20 list_for_each_entry(iter, &core->instances, list) count++; =20 - if (count < core->iris_platform_data->max_session_count) - list_add_tail(&inst->list, &core->instances); + if (count >=3D core->iris_platform_data->max_session_count) + return -EBUSY; =20 - mutex_unlock(&core->lock); + list_add_tail(&inst->list, &core->instances); + + return 0; } =20 static void iris_remove_session(struct iris_inst *inst) @@ -206,12 +208,17 @@ int iris_open(struct file *filp) if (ret) goto fail_m2m_ctx_release; =20 - iris_add_session(inst); + ret =3D iris_add_session(inst); + if (ret) + goto fail_inst_deinit; =20 inst->fh.m2m_ctx =3D inst->m2m_ctx; =20 return 0; =20 +fail_inst_deinit: + kfree(inst->fmt_src); + kfree(inst->fmt_dst); fail_m2m_ctx_release: v4l2_m2m_ctx_release(inst->m2m_ctx); fail_m2m_release: --=20 2.47.3 From nobody Fri Oct 2 14:02:43 2026 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A6E06284662 for ; Fri, 31 Jul 2026 00:32:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785457939; cv=none; b=jjY4LhIKtVOD1Udl/HOalLtU2nJd9DCondHnAT8xNspXZzUlATQ/9EJf3EWDuY1J7kxs+AX1ZVnvibsGwPUY+TPXMeTiYy8Daek4jzKySZQxRHHyj5TF0Orz+C499lpKGDHlYYSA78bl26652MNHY8TMXeIxd07V8ECuEXTJSGc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785457939; c=relaxed/simple; bh=AtlBxAnhMsZ5O/g9dbEU81FBTz82waEQwGjM5JZ7NJs=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=oy3/nj5YfVGi7QWqAD8zHwlMPBhxIud2QC2vCD77IJd9av0bQIUwNSN19EIR3uiLmI6cBjO6DSr6yCX4Ncw9umYmRtuhbb9OqgxZpXZ8lsdmE2ACwAjS4bK8lyQu72iaeFBSO8lzfDkNqhct2i8hqaqmfGMoq5Er0CPFWf53CV0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=EpDTKrtx; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=PE3whfVC; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="EpDTKrtx"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="PE3whfVC" Received: from pps.filterd (m0279868.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 66V07qLI2359385 for ; Fri, 31 Jul 2026 00:32:15 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= A7RLFBUQEX78LH/H+CTPwK5+ik3e+0QJasHFVlabl/k=; b=EpDTKrtxYhp22C4Y Lc9v7in4NGRF+4cuSgBOgqQuiPbmc45MgoAYqpufLxIls3eTotLuMGY2wSF/vqUE bNUxzmcwJ4QOTSOGMlQQ9V+Zum21zEkCCxhN2pmyT5C+lTunTqPDKOgINKcq/w0r k+nK8r8LUrsnCJG/Zp70l4pl9QOAkWAhManfzWcob5SfSQ5glR4t1Qgr+2UXCZon BmzXPzZAvMMCPJoszn+wTSwZs88M7gQp6xPYTyf17G2K8dsHzlZYCkd2mINVW6n4 iG+VXvpXD3nyHXp18YBcbqpRKqKNMALPfKua4iavhsOplLQWE+SVfQUbjz/zGyDN YjtT4g== Received: from mail-qv1-f72.google.com (mail-qv1-f72.google.com [209.85.219.72]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4frgvyg1u1-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 31 Jul 2026 00:32:15 +0000 (GMT) Received: by mail-qv1-f72.google.com with SMTP id 6a1803df08f44-8f1e4e0eac1so5798346d6.1 for ; Thu, 30 Jul 2026 17:32:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1785457935; x=1786062735; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=A7RLFBUQEX78LH/H+CTPwK5+ik3e+0QJasHFVlabl/k=; b=PE3whfVChfBywjfu26npO/MciLunHZA57H2zwD+nBBAxTImaXVlvQu7sfVXcDiEQEz Pmqmb3zHUqmPnhjdA9p9jgowcnH7fvveGxrxzFNFQBztoV3eQJV7LWrIGwrtO+xJEYiE 01KK79whrwZipmx3izQaClPWV/XbuvEj2Zp3C5U+oSXLwgL+d/x7TsE5QaBfu7SHuVlr tvrbKgPfX88iVBVvdjdF7/zejVJS+0lAiLsf9cQNglSkzUTcvS6VpCQw3Gk9wtKmhqjl adi8IxOhHDgPZcNpub5tZqRTlr30czthRpMliW1XXrLJjIRrDMtcBSxtyQlHJn+wb17E ScEA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785457935; x=1786062735; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=A7RLFBUQEX78LH/H+CTPwK5+ik3e+0QJasHFVlabl/k=; b=Ezi6M1xrg5OX+uJ+RASlWGlx/Lx2PyqBIrG91EAzE7ZiGCG37hUY5YPuHdZgd4CVBr nfYjmiKLTBLYX2Z8rxIIuyhPPLiB91CmUU38YB2ccoZqMLHM81lnBOqIXuPcLhFDWmIM CrranTvrCfMjEePcqCmTSj3KtBEEqsKG/Br0/l7yKs7H+r0NI+R+fLpIsKGELiyZ4ske PrpjZKQjE45Shhht+SWXk56wP3GkiUraCGyaEk2+Fnv9i7CXr52lJxMjTZSkIw6csHLI OqfWfWY2THJW1A2ExDUpFZj3/6nz4tY/6YIGN3V/nR5Df6ZLI6bVTJWzOe6KlKkUPF6p qJ7w== X-Forwarded-Encrypted: i=1; AHgh+Rq0BbOVuBZ0hylb3jWnim+Gu8A7hh9HKZRC//oAg2AijgcQrYZhINX1EHLJVNoI9INqDPQTXafG6+Byvlc=@vger.kernel.org X-Gm-Message-State: AOJu0YwG0l7vZ9JbnI237z91TpXCqVCRsMPysA2EEh6Kp3z2qQb2Usmq xYVY59YEZSnDzCqas/6nlXnkCdWehkifPK4HE+c3IYetPUZ6jw9sXcfU245juSBi84w8QWKXRf0 nUXTUEHb5AseHmOV8PRxCy8QAI1Xp4imW7Ls4nWIu/XaO+1YVYKBCmHUXj3P4F9+3Xlw= X-Gm-Gg: AR+sD12ee6J85i92WUGjKSf0bq60GzAaL1RVjroTR80XR2aouUZmHV1qlPyqT95tay/ eJPSZJ6cB5hUVFog7UqmAhcajmrraUprCerPxgPFB4Vx7inhcK6I7hbHYHLbG5c611U3y5cVlkl FWpVqYl7SlgkAeljYc0WdbLGvWwJ9tHWCpPGsJnyx+a3zUxtVQ0TjG5ZJ6l/NIl2/QiwNWr0AG0 saMMFc+YYRfNN0dv7Mu5zpIU9Hj+avkJOGiWdo29XkumaPUo8WMO1VPo6cCyhmAn0V/VFsC48yI rY3clFSbIy5rxKx/qx5EVqiB926I748ebmLOs7z0DV88dOSbY5BXM4SkJKaU3CTSwnKN/KoYNY1 22RDfBAdbsRoD5oLULe61FG3sXeziLVKF0TNCOQMErrkwzM+/S3Unjb2e5ZUvZ2JO7nw+e8nGF2 7662o+Y6TYEqJfYg== X-Received: by 2002:a05:622a:138b:b0:529:a553:9d6a with SMTP id d75a77b69052e-52b4b1d6ee3mr621781cf.63.1785457934789; Thu, 30 Jul 2026 17:32:14 -0700 (PDT) X-Received: by 2002:a05:622a:138b:b0:529:a553:9d6a with SMTP id d75a77b69052e-52b4b1d6ee3mr621491cf.63.1785457934325; Thu, 30 Jul 2026 17:32:14 -0700 (PDT) Received: from umbar.lan (2001-14ba-a073-af00-264b-feff-fe8b-be8a.rev.dnainternet.fi. [2001:14ba:a073:af00:264b:feff:fe8b:be8a]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-5b2db9d2688sm620538e87.57.2026.07.30.17.32.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 17:32:12 -0700 (PDT) From: Dmitry Baryshkov Date: Fri, 31 Jul 2026 03:31:44 +0300 Subject: [PATCH v2 5/5] media: iris: reference count video instances Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260731-iris-fixes-v2-5-94c002016a09@oss.qualcomm.com> References: <20260731-iris-fixes-v2-0-94c002016a09@oss.qualcomm.com> In-Reply-To: <20260731-iris-fixes-v2-0-94c002016a09@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Abhinav Kumar , Bryan O'Donoghue , Mauro Carvalho Chehab , Hans Verkuil , Stefan Schmidt , Vedang Nagar Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=6840; i=dmitry.baryshkov@oss.qualcomm.com; h=from:subject:message-id; bh=AtlBxAnhMsZ5O/g9dbEU81FBTz82waEQwGjM5JZ7NJs=; b=owEBbQGS/pANAwAKAYs8ij4CKSjVAcsmYgBqa+z8G+KJsJaJZA+Z/kLUlMNwZgz5wI+sRhn8q X92vfrDnvmJATMEAAEKAB0WIQRMcISVXLJjVvC4lX+LPIo+Aiko1QUCamvs/AAKCRCLPIo+Aiko 1dlvB/4roW4ncetMvD7EQPWle46DiMNURUIjHRBA/RJKp25IGfZE7vktYJj3lil7KNctMGFgx+S M2M/P4Cn7GpG0NyPrSIsrpHXE1xZxGbkrh57LpxBA+9xHZfngAog2Lm6/rc+jk+kYPhaV4Iv1rC pfXxoV4wx0ntye0PUq2wyLhk+FqrAng7u97odCWOgFzGmnPTS5BO6lOrpqUPFMPWh7zV26GDrNj um0zysnmOCE44ZBnAxiXCEsF21p4OQpM/cefYSZSivx7aTjKuJrSF7IwZiEhGFFAr3mipJeXLZX b3l42eXFzvo26yFMs1+G/2JwiCy8hUb22ksDqJ3Muq/kyR81 X-Developer-Key: i=dmitry.baryshkov@oss.qualcomm.com; a=openpgp; fpr=8F88381DD5C873E4AE487DA5199BF1243632046A X-Authority-Analysis: v=2.4 cv=BtqtB4X5 c=1 sm=1 tr=0 ts=6a6bed0f cx=c_pps a=7E5Bxpl4vBhpaufnMqZlrw==:117 a=xqWC_Br6kY4A:10 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=ZpdpYltYx_vBUK5n70dp:22 a=EUspDBNiAAAA:8 a=D3wWFwynQU2KHtTvd0MA:9 a=QEXdDO2ut3YA:10 a=pJ04lnu7RYOZP9TFuWaZ:22 X-Proofpoint-GUID: HSwQmPemMIs4_QlsiXGz0pDUJs5pWTZz X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzMxMDAwMiBTYWx0ZWRfX4jeIH9UaszLn 0amhA+SLrLFgL6RcRTZhPias3EcjplYSC3hSqmIC++A95RukREIvb+i6G2RCCkiHQ7RSKKcfUw+ k2HM/M+Es6IAbkwzakoMwqaxWLpY7sJ5mhqO9DQlb8IDvfr+iQst4TEVz928uh22FF5foMs01eH 5w1ssMGt5g580TtS8Bm2piR3Vq7l/6gELsk9VvyfwMD8xXM/zNnIrJdkRm1dKryaPi6QeHVvb1Q uzSMyLwGyiu6vRVD0qKektLE0urns3uJXfiacODavRE3PwTrlFQ9tc8u5kUZ9ETdlf9cgDuOOpR JOSwXS1WTpCG/dVXq18fFXm2v9oAI1UPHtUNwCIjDalsz4Oo6ob8CrJb5uMLnjQ5fkGv6QlR2VW xvTtj4bvL8vDEwoOoZQwNZ3QCW75a0pvLItcbxuQN1c2wQwVTL6xhgd5jjUxv1Sf5TpeIfL9eRg /J99lVxz6dGmY2sqmbw== X-Proofpoint-Spam-Info: AW1haW4tMjYwNzMxMDAwMiBTYWx0ZWRfX2fESUtW0UZH7 lUVB9QoXnn2gDBne8QL5ovLUn7cWRo/BIFW98ylLU4v2Y6JF5+0/70CWli7cj60bLTATdTiisqh uA2cmIRMedQNq0fNgSB41My0RaZGYBs= X-Proofpoint-ORIG-GUID: HSwQmPemMIs4_QlsiXGz0pDUJs5pWTZz X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-07-30_07,2026-07-30_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 bulkscore=0 adultscore=0 clxscore=1015 lowpriorityscore=0 impostorscore=0 suspectscore=0 spamscore=0 malwarescore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607310002 iris_get_instance() looks up an instance on core->instances and returns it after dropping core->lock, without taking any reference. The threaded interrupt handler uses this to find the instance a firmware response belongs to and then takes inst->lock. Meanwhile userspace may close the same file descriptor: iris_close() removes the instance from the list, destroys inst->lock and frees the instance. The interrupt handler then operates on freed memory and a destroyed mutex, a use-after-free. Add a kref to struct iris_inst. iris_get_instance() takes a reference under core->lock, so an instance it returns cannot be freed until the caller drops that reference with iris_inst_put(). The instance is released (mutexes destroyed, memory freed) only when the last reference goes away, whether that is held by the closing thread or the interrupt handler. Fixes: 38fc8beaba55 ("media: iris: implement reqbuf ioctl with vb2_queue_se= tup") Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Dmitry Baryshkov --- .../platform/qcom/iris/iris_hfi_gen1_response.c | 2 ++ .../platform/qcom/iris/iris_hfi_gen2_response.c | 1 + drivers/media/platform/qcom/iris/iris_instance.h | 4 ++++ drivers/media/platform/qcom/iris/iris_utils.c | 6 ++++++ drivers/media/platform/qcom/iris/iris_utils.h | 1 + drivers/media/platform/qcom/iris/iris_vidc.c | 23 +++++++++++++++++-= ---- 6 files changed, 32 insertions(+), 5 deletions(-) diff --git a/drivers/media/platform/qcom/iris/iris_hfi_gen1_response.c b/dr= ivers/media/platform/qcom/iris/iris_hfi_gen1_response.c index bfd7495bf44f..e2b95c22f4d1 100644 --- a/drivers/media/platform/qcom/iris/iris_hfi_gen1_response.c +++ b/drivers/media/platform/qcom/iris/iris_hfi_gen1_response.c @@ -632,6 +632,7 @@ static void iris_hfi_gen1_handle_response(struct iris_c= ore *core, void *response mutex_lock(&inst->lock); iris_hfi_gen1_session_event_notify(inst, hdr); mutex_unlock(&inst->lock); + iris_inst_put(inst); } else { iris_hfi_gen1_sys_event_notify(core, hdr); } @@ -667,6 +668,7 @@ static void iris_hfi_gen1_handle_response(struct iris_c= ore *core, void *response } } mutex_unlock(&inst->lock); + iris_inst_put(inst); =20 break; } diff --git a/drivers/media/platform/qcom/iris/iris_hfi_gen2_response.c b/dr= ivers/media/platform/qcom/iris/iris_hfi_gen2_response.c index 8c2644c7f6e8..f0782c4b1e6e 100644 --- a/drivers/media/platform/qcom/iris/iris_hfi_gen2_response.c +++ b/drivers/media/platform/qcom/iris/iris_hfi_gen2_response.c @@ -969,6 +969,7 @@ static int iris_hfi_gen2_handle_session_response(struct= iris_core *core, iris_hfi_gen2_handle_dequeue_buffers(inst); =20 mutex_unlock(&inst->lock); + iris_inst_put(inst); =20 return ret; } diff --git a/drivers/media/platform/qcom/iris/iris_instance.h b/drivers/med= ia/platform/qcom/iris/iris_instance.h index a770331d1675..dde5d0b8a83b 100644 --- a/drivers/media/platform/qcom/iris/iris_instance.h +++ b/drivers/media/platform/qcom/iris/iris_instance.h @@ -6,6 +6,8 @@ #ifndef __IRIS_INSTANCE_H__ #define __IRIS_INSTANCE_H__ =20 +#include + #include =20 #include "iris_buffer.h" @@ -35,6 +37,7 @@ enum iris_fmt_type_cap { * struct iris_inst - holds per video instance parameters * * @list: used for attach an instance to the core + * @kref: reference count, keeps the instance alive while the IRQ thread u= ses it * @core: pointer to core structure * @session_id: id of current video session * @hfi_session_ops: iris HFI session ops @@ -82,6 +85,7 @@ enum iris_fmt_type_cap { =20 struct iris_inst { struct list_head list; + struct kref kref; struct iris_core *core; u32 session_id; const struct iris_hfi_session_ops *hfi_session_ops; diff --git a/drivers/media/platform/qcom/iris/iris_utils.c b/drivers/media/= platform/qcom/iris/iris_utils.c index ba5c8dc1280c..1096cc4b01c3 100644 --- a/drivers/media/platform/qcom/iris/iris_utils.c +++ b/drivers/media/platform/qcom/iris/iris_utils.c @@ -92,6 +92,12 @@ struct iris_inst *iris_get_instance(struct iris_core *co= re, u32 session_id) mutex_lock(&core->lock); list_for_each_entry(inst, &core->instances, list) { if (inst->session_id =3D=3D session_id) { + /* + * Take a reference under core->lock, paired with + * iris_inst_put() once the caller is done, so the + * instance cannot be freed by a concurrent close(). + */ + kref_get(&inst->kref); mutex_unlock(&core->lock); return inst; } diff --git a/drivers/media/platform/qcom/iris/iris_utils.h b/drivers/media/= platform/qcom/iris/iris_utils.h index 228a5f963812..be23acc0e848 100644 --- a/drivers/media/platform/qcom/iris/iris_utils.h +++ b/drivers/media/platform/qcom/iris/iris_utils.h @@ -48,6 +48,7 @@ bool iris_split_mode_enabled(struct iris_inst *inst); bool iris_fmt_is_8bit(u32 pixelformat); bool iris_fmt_is_10bit(u32 pixelformat); struct iris_inst *iris_get_instance(struct iris_core *core, u32 session_id= ); +void iris_inst_put(struct iris_inst *inst); void iris_helper_buffers_done(struct iris_inst *inst, unsigned int type, enum vb2_buffer_state state); int iris_wait_for_session_response(struct iris_inst *inst, bool is_flush); diff --git a/drivers/media/platform/qcom/iris/iris_vidc.c b/drivers/media/p= latform/qcom/iris/iris_vidc.c index 4ca9185b3d2b..56c6c1b0ac16 100644 --- a/drivers/media/platform/qcom/iris/iris_vidc.c +++ b/drivers/media/platform/qcom/iris/iris_vidc.c @@ -40,6 +40,22 @@ static void iris_v4l2_fh_deinit(struct iris_inst *inst, = struct file *filp) v4l2_fh_exit(&inst->fh); } =20 +static void iris_inst_release(struct kref *kref) +{ + struct iris_inst *inst =3D container_of(kref, struct iris_inst, kref); + + mutex_destroy(&inst->ctx_q_lock); + mutex_destroy(&inst->lock); + kfree(inst->fmt_src); + kfree(inst->fmt_dst); + kfree(inst); +} + +void iris_inst_put(struct iris_inst *inst) +{ + kref_put(&inst->kref, iris_inst_release); +} + static int iris_add_session(struct iris_inst *inst) { struct iris_core *core =3D inst->core; @@ -167,6 +183,7 @@ int iris_open(struct file *filp) inst->domain =3D session_type; inst->session_id =3D hash32_ptr(inst); inst->state =3D IRIS_INST_DEINIT; + kref_init(&inst->kref); =20 mutex_init(&inst->lock); mutex_init(&inst->ctx_q_lock); @@ -308,11 +325,7 @@ int iris_close(struct file *filp) iris_check_num_queued_internal_buffers(inst, V4L2_BUF_TYPE_VIDEO_CAPTURE_= MPLANE); iris_remove_session(inst); mutex_unlock(&inst->lock); - mutex_destroy(&inst->ctx_q_lock); - mutex_destroy(&inst->lock); - kfree(inst->fmt_src); - kfree(inst->fmt_dst); - kfree(inst); + iris_inst_put(inst); =20 return 0; } --=20 2.47.3