From nobody Tue Sep 29 04:13:42 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E3A893515EA for ; Wed, 12 Aug 2026 20:01:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564896; cv=none; b=tf6pqZESKLuJGdbVCrGyhCkFKVfLgI1jgFzTnJ8XiLgHmaH2f+eFQue2APOWRgwDLkWQXPEt0nHqwu8Ze9PMReTdy08SDA+V6kfcG268Y/Z+VIPyDOaQYkfN2bxo1K8oCL8IsCzXcGF1LM99DrhCNYeRA7LTtvUnK8yccAThd6Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564896; c=relaxed/simple; bh=Srv7YZwRGZt3x26M6QPq4Hp84wa5hDmKkBrQtVxPXa8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=XaH0firX+USXHDzgSinTWBnNdu5UeU/OCuDuz2JhIKVDQGRQgRWNvxY34v5hFAiZsALx5qCaEDEiDUkYe1jb8yep9MQ29xMBk95NJi8ESnOZ5sO2zkvH1Eh71kV8cpv0pNP5fsWCSzXuJFDepeKnjW2jL2X5CMFXw0SGy07Fu+0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=QkJi4OrW; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=YVz1Lw57; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="QkJi4OrW"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="YVz1Lw57" Received: from pps.filterd (m0279864.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CI8gTq3792225 for ; Wed, 12 Aug 2026 20:01:34 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= Diq1tG25o0LV+02xuOMc5mc02Aof/vsh4RWwsT6di8s=; b=QkJi4OrW9Rvu7e5D OGEfkYEXMiWReMJdvkyWyd8c/C2mZUJIKAwOpSYIJTQ7sVALhevGFaYR7yX1tVF/ 92PsTzQbKdfkc9YnvKNw3lVPdzT/jnA1oO8NQBusOFN5YB6S7CGO0IMRMmr86Ctd VKWJg7lAhAdZqg858KhSLiQm3npKbCEKpf9NWz0wNiprl1ABmQd//G4aMhVRy2tQ lakLSsQBCEuWdKesLDLhKoaJRX8ZHAxJ6M7Uf2/hXn00DOLkP9TTbZsFR0Bq4A5w dP4vca7BzxA3BorlDt1ilCreSt9IwGaCYDuOO/r6P/rWFRl7TWlgiq4ei/KaQgHj KBvTIw== Received: from mail-qk1-f198.google.com (mail-qk1-f198.google.com [209.85.222.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4g0mndb6g7-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 12 Aug 2026 20:01:34 +0000 (GMT) Received: by mail-qk1-f198.google.com with SMTP id af79cd13be357-930edb4362dso149699985a.3 for ; Wed, 12 Aug 2026 13:01:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1786564893; x=1787169693; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Diq1tG25o0LV+02xuOMc5mc02Aof/vsh4RWwsT6di8s=; b=YVz1Lw574kOUUHOM8hMP7NrZHLngaepk4/3qkJeKWk3cc6iDAPDmSMdVQCNPQyUBEt gqtTsY4hDCFpAQqiZda/LV49XS7M7y/crxApHJIdllbU+bcx0klbvStT55fRSAYmQHb0 KVK55j0610jnCgS7A/vPFaxyzoh9sCU9NX+USyy7YzxbGHr+Q4mrn/UisXVqNRiLYySN NlWEYFTkZqZIz5d0wznBdd+05YXwtl88v2lkC2enHdGpiqyXM9N+ce6NZdsmQ9ZxGjkp svSAVITwlDZV1oUrcrvZk5x5QwdlzGXOK9MBffd8nPYhyKpn8RWfzEoZqlN/U5Id7jUw gUXA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786564893; x=1787169693; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Diq1tG25o0LV+02xuOMc5mc02Aof/vsh4RWwsT6di8s=; b=N2WtJC1YR0GxoPS202LqA3RWviS1Sk7yW1JZlitEDEjZm8XhvapHH2ylMwzJC8KeMm AjkEMR9mdrCp8fWMk/jwQgqZeaKB5si9Yx7Vvc01i85ihkRiJpr1qVtMFfm3wHr1tKJX rvkOFe9/+EHaOn5QrxOpELbCb/ZZPu9weKd6Ov0VJulgPZiRIdO49TK/FyqZwFYcMKs2 7MbMN/XYNzl9m4UqArMogQastlXyluLwPkafv3CNj7/QaGVKf2L5/e4lVYdCE6Q5paq7 5u6pB7m7Q7DCrkkpGKt85nHuAEOzC/YB9lpl9GWcm4V36ood2Oa0ytMJm3EYnx8/p0Ly 4JAw== X-Forwarded-Encrypted: i=1; AHgh+Rryt2/oXiqSWR1yfV//G75fF2E6EkOMFRFRVH5B7BquT2vGaikXIUcNVgQcasbcNoNg7auT0hxt9reWoAs=@vger.kernel.org X-Gm-Message-State: AOJu0Yw7+RwVt30RuvZqtbhfiOt/aMWetL7pgb187ogZ6x4Zifaqhq5t aSs7kspX+vOg2Hc8BmzO+k8YpJq6LAvL8ECgY69Q1kfW9YiuPqX+OH/TXNQe/RvthpTKQIMmZkI d9hxIlpewh7UTD2A2psfdX36Chx1Smncit12VmXGk6cMkte4ec8NHhy7PABXCYaDWZFY= X-Gm-Gg: AR+sD12qH66880we3FJat4KShpRuBI3LZJmiRQzJFGhDnagB2Lq/4m1rL+LI8xan9We CySYCvlEZoufXs3murvq+XnDI+RC9AZnKeGklSruIW1/SqhQiWeQvVY64eeZkooBgWg/LJKIJjP 7Qi+b85NdAJlLUAoBELXepJKPM06402T4PEbjDAM6OJxqho6bF8qGsjnxCuosP4dXTDfFzNNnxu qdCbdpcUEQTQ1ViRe3ywfzjENJE8gM6wDhJcl+zk0kn20OhqutiX40MS35dCA4YFe+fCwcPjFIW Z3diD6fmDdz12/pGyJ9igc8r5D+A1wtfrErEHXRXzVqCnzE7Z/YYdSKm9oJG7Sx6VYv3FvYmaAl vvLJFY/9eNvPT5r+BeLaGseSWYAF8RujMM2A9y8UBc1xEMX8hyr8V2ClzQsYDFHRLFoiZNv1ddE FpmHa0AcI+2345 X-Received: by 2002:a05:622a:2506:b0:51c:52a:8e70 with SMTP id d75a77b69052e-52d73c274b6mr8194661cf.2.1786564892766; Wed, 12 Aug 2026 13:01:32 -0700 (PDT) X-Received: by 2002:a05:622a:2506:b0:51c:52a:8e70 with SMTP id d75a77b69052e-52d73c274b6mr8193411cf.2.1786564892161; Wed, 12 Aug 2026 13:01:32 -0700 (PDT) Received: from umbar.lan (2001-14ba-a073-af00-264b-feff-fe8b-be8a.rev.dnainternet.fi. [2001:14ba:a073:af00:264b:feff:fe8b:be8a]) by smtp.gmail.com with ESMTPSA id 38308e7fff4ca-3a11b2acb0fsm354561fa.12.2026.08.12.13.01.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 13:01:30 -0700 (PDT) From: Dmitry Baryshkov Date: Wed, 12 Aug 2026 23:01:23 +0300 Subject: [PATCH 1/3] media: venus: hfi_parser: account for all capabilities when skipping a property Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260812-venus-8996-v1-1-6615f82a63b8@oss.qualcomm.com> References: <20260812-venus-8996-v1-0-6615f82a63b8@oss.qualcomm.com> In-Reply-To: <20260812-venus-8996-v1-0-6615f82a63b8@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Bryan O'Donoghue , Mauro Carvalho Chehab , Stanimir Varbanov , Hans Verkuil , Tomasz Figa Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, Mauro Carvalho Chehab X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=2126; i=dmitry.baryshkov@oss.qualcomm.com; h=from:subject:message-id; bh=Srv7YZwRGZt3x26M6QPq4Hp84wa5hDmKkBrQtVxPXa8=; b=owEBbQGS/pANAwAKAYs8ij4CKSjVAcsmYgBqfNEWqA3ie8cFiAO1nWypjTLI4TmhEdKGHed/Q 3uVr81Y3SWJATMEAAEKAB0WIQRMcISVXLJjVvC4lX+LPIo+Aiko1QUCanzRFgAKCRCLPIo+Aiko 1W4ZCACD/Qht2Hzl2eNlq5y+emPJoSGrOe2OtseIwvVh1pe762IpqRzANftw5A3/GYSf6wmEZAJ Rvn4nnRPZLnccr62udjtEO8NTZWhPE59Xzv/5/0kgPUsa5ZLEyfX6sLJ6iDjWdAEAENFFxJsEm+ rQYYWSKxYmSLInjl9RxO6ROTLt+CViTsvOQojcoRjElioPK3hYO5ECeUUCDoP7fr09cRFxk/4my zLlLBLHEQyR9ie40B6dnhL69zyronnfc1dHzcBBoFD+ZjplWWtpBlQ+I5EQRFCQjy8pCFS9wPLF Pzli7Np0pTDgnVt8ChXD7tFFcoEypJZAcqy5UxTtT9F3Y+QH X-Developer-Key: i=dmitry.baryshkov@oss.qualcomm.com; a=openpgp; fpr=8F88381DD5C873E4AE487DA5199BF1243632046A X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MCBTYWx0ZWRfXz1e8SIz3OmoV g4omMMT86jP9AnvPenS7askdF4ZnrQoBrD7yDnLfFAgenWKxIgSBhXNSF0nEC2JqcFKo+wrGjn4 LKa2oo5P4/D7NHQnceZbW9jj3ZIV3oQ= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MCBTYWx0ZWRfXxCK2n/S4tuJO pZD/UIOGhDAFnhg4gJh+Jyw8rmIzRbTzMaasheModP4BEOScZS10BF6O/ayEyOMaE+ACcaeXVa4 T6NBxQj2U334e5SNioBKcRUD0i6+Fa0n4gVhWpZvIjMY+Qr8OIdDGL1yirSb1ZT1dG/PrIHMiYi mgELO4ct0GAR/nK6dPFF2Vcw1l5tffwSwJkhrH4I3zRA7m75cvBrKsS581VAP35Xvg5+DT1vDio Vonqea+xUXCsmiych3VoIVYHaVlbiLMRebsscTRVBSbrteRwPQW5Y57uZcUJE362dMtfge1/th4 2bcXB2/VURmhDgulm+pkPL7hmbeviz92rvMHceQBlcEKs8JyBcC5R5m4fwh25HF65CYR3gn2Lrg Wyc+o+fu4EfLJ6v1lqT0r2ubTdyZlWua16wA4LjEdk6chaajlhmeAVLCqUtGcJb/C1ZkDYoT2Z/ HJ8mYx9bCW0EbpsM5Hg== X-Proofpoint-GUID: LBTJft5xudXWWECjY-QLwBmyjnXfxtVy X-Authority-Analysis: v=2.4 cv=C87ZDwP+ c=1 sm=1 tr=0 ts=6a7cd11e cx=c_pps a=qKBjSQ1v91RyAK45QCPf5w==:117 a=xqWC_Br6kY4A:10 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=DJpcGTmdVt4CTyJn9g5Z:22 a=EUspDBNiAAAA:8 a=cdMpqBep0YYzfnNq6hAA:9 a=QEXdDO2ut3YA:10 a=NFOGd7dJGGMPyQGDc5-O:22 X-Proofpoint-ORIG-GUID: LBTJft5xudXWWECjY-QLwBmyjnXfxtVy X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 suspectscore=0 phishscore=0 lowpriorityscore=0 spamscore=0 clxscore=1015 priorityscore=1501 bulkscore=0 adultscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120160 hfi_parser() walks the property list of the message it is given by advancing over each property by the length its handler returns. parse_caps() returns a fixed sizeof(*caps), which only covers the num_capabilities field and, at the time the code was written, the single struct hfi_capability that struct hfi_capabilities then declared. A property carrying N capabilities is therefore under-skipped by N-1 entries, and struct hfi_capabilities has since become a flexible array member, so today the whole capability array is left behind. The parser recovers from this because unrecognized words are skipped one at a time and capability types, limits and step sizes do not collide with the HFI property identifiers, but nothing guarantees that: any capability value that happens to equal a property ID is parsed as a property, at an offset that is not a property boundary. Return the length the payload actually has. Like the other handlers this leaves the property identifier itself unaccounted for, so the walk resumes on the last word of the payload rather than on the next property, and relies on that word being skipped as unrecognized on the following iteration. Fixes: 09c2845e8fe4 ("[media] media: venus: hfi: add Host Firmware Interfac= e (HFI)") Assisted-by: Claude:claude-opus-5 Signed-off-by: Dmitry Baryshkov --- drivers/media/platform/qcom/venus/hfi_parser.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/media/platform/qcom/venus/hfi_parser.c b/drivers/media= /platform/qcom/venus/hfi_parser.c index b1657443f23f..3413b91b0b7e 100644 --- a/drivers/media/platform/qcom/venus/hfi_parser.c +++ b/drivers/media/platform/qcom/venus/hfi_parser.c @@ -146,7 +146,7 @@ parse_caps(struct venus_core *core, u32 codecs, u32 dom= ain, void *data) for_each_codec(core->caps, ARRAY_SIZE(core->caps), codecs, domain, fill_caps, caps_arr, num_caps); =20 - return sizeof(*caps); + return struct_size(caps, data, num_caps); } =20 static void fill_raw_fmts(struct hfi_plat_caps *cap, const void *fmts, --=20 2.47.3 From nobody Tue Sep 29 04:13:42 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0171F1F4631 for ; Wed, 12 Aug 2026 20:01:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564901; cv=none; b=nLTAC89bmdpZibtOz+OQ7dkI/p6usgEmZnqHbatbPO3JyaAQxiPIzqUiG1fdFe8JVjawXJbuuicxv7w11yE/RVmsMaH06ms03Q7Vqb+X/otp8UmjIzgjlUj8LMs7dx+ao9KDA+Gvuw5C1ThAvwBTBBKkcA9SmSQLLe+Ky3Qun94= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564901; c=relaxed/simple; bh=sBVU1vPwdqmVJbT5lEmy2hLjCPRTfUjf3ue9MRRCoO8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=sB9dVkYZ6dLHeYivFln/Wf8B17D+RJLN1oipRzU1+ejundypvJ/qlKloGp2mXSHeEGi7VWYZgvdLec4y33UdzFhnDicwkmfsP+qbgABId1layvRBSZlcAuclzUeC5JmC96ji8/y5V4bzzG+LvqG7TIWkm8smRcpkIB3CtfavLd8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=ewJlTjoP; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=NsIughTJ; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="ewJlTjoP"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="NsIughTJ" Received: from pps.filterd (m0279865.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CI8gST918308 for ; Wed, 12 Aug 2026 20:01:39 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= LtHg0f0ys0fkjSOy8XnEbykJPJwUG/MtK+n1p9jWvGE=; b=ewJlTjoPPZPEpxQH tRrsAV1Cloe/xAwQ4gnVmyOeAQy3L9hsbEfcEMTamRn8inpmJQAbshvHDlLj5/3J AMhsUkPcQaClG7zINsQTWzqEv4VvpeoDVihOzjN2Ir6Gb7bRYlUrMP3AYYYeJI4h aFV/CTcXWoN7n5ZjXIkDOYqvH7SCAba73mferqQL0e3SYBWhyKmSQD2irs46xhQw sUcZ9fazXppvEFBLbNOs87M5ZdGZQHsIOLZnmz5BVVbIYLqOL5uytjujKxZGMZ4S s1D87hKCAtXWjZgmlGq4u75fZezQApmISdicz0kooV/7fHjro8oKTjImWl62uLN5 xzgHsQ== Received: from mail-qt1-f197.google.com (mail-qt1-f197.google.com [209.85.160.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4g0sk41xne-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 12 Aug 2026 20:01:38 +0000 (GMT) Received: by mail-qt1-f197.google.com with SMTP id d75a77b69052e-5283fa0656dso3314481cf.1 for ; Wed, 12 Aug 2026 13:01:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1786564897; x=1787169697; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=LtHg0f0ys0fkjSOy8XnEbykJPJwUG/MtK+n1p9jWvGE=; b=NsIughTJgAERQTE8QPGrY2HsY6Xa0u1/z2KoYd2ovr5LXnXw8q9seTNZdx/SXDk+Mx /nj4bKS7hSWKMA3goOQfqlDMew9/TSwJQHo6eIE+hVwF1yaKLqONyUS0dA5X6xtyM3CG ZKuA9f0ya4ye6S2Yqa0F8JipoH5guOYdOTfe1aSY7P/shI9W7M5iHliV1Fyw+rkIGxuM Q6UbuXQyTLSLsIXodsQBtu6FnUqn1f1z2uGGbHBxbXWxje3EbRVPBEHS7WWQXkMllBgP 6pJrgCWqqAtfFFreSbvoEfK7O+c8l2Ja4ic+GtSou0V/4qhQxZ+Vay8JnQnMNoW0PYUo Xmgw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786564897; x=1787169697; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=LtHg0f0ys0fkjSOy8XnEbykJPJwUG/MtK+n1p9jWvGE=; b=ToJb2PZL2YUF9xBsdBcYVr1zeBmfj/NI2ynMsfIDZ/2j2fE8QFXca/ehwatPelCmuG tD59XtZXLM4P2YqHaipLcVIrZ0OWqH8yWfloKjlMhWPu6vIZ1u80hnsX7tZ+mB0loWXx gZoVNgFNtMLNfVBs0TA2Tm528cbltOCMKm0L8afhvh009kY99wHh6kZzQqcuZCWA5uqw YqSnB3M0mUBhTnbrcOsziXzlBiimjp8bnTfqWnAkBQHiMJjitBe7YgiglERg46ggxmIU j2B2VIdQt+azer9WMjvbmVqZxJYEFDEIpM5/7ijPIbEoi7i65/STBhY/35gWZ7FkV9/d snLA== X-Forwarded-Encrypted: i=1; AHgh+Rpynb3iPqn9K+3ta8MK7f9AHJglOmkww8MhmM4FSlpBVnv8qu7AYrcYFcMlz5hxGZqODjiCs3BQw/doFu4=@vger.kernel.org X-Gm-Message-State: AOJu0YyE1PT67HL7kXftmci3QwyIY5hay7LfFePW4daSzKlNrywAx8QP a5qnsZETyfIKxNlWAXbA+eTqn/5HjkmrL+StIzsKiBU+aOFcz0WJP6bY/0Em6rubxTwj1z/WXJc jMR+wN+y0DnYpArk6+JWwJf9zIQLF954Ug2WKFkMHtL8lTtblE/wqu6/42RkJXgs3A5s= X-Gm-Gg: AR+sD112CCV0WhdGj+HCDO/bYT8Y/1KGlr22aok2Ba4dzs2sCEkJ8OJzRTeKg/YO0I0 kHL3LPP2XqBUQjxNXehvAY0Z+N13UHFORXVfwMRVfFM+joKUUII1moPM5Kq17PBaVGBV10vqLr5 jHeCBBZlnoZLAOlTJt+kEmD7WfDPSf63/6CBko5MZYdVlW0GJTfGIMThv4uAFy6v2n871HTFwy/ PmTBf/pR67pAePqxAbkxEGWw+CZTfTkChY/pebE/ykyRDsJhdE8439LZY2w9doikGZFEKSettEy E3QEl0XeK/uRbKoWs+KUb11LSwJHtisfwnnNg4KYDmdZy4/eyTQkd1PrnzvTSB7Llk6yKgURapf LkTEGGtVruTS6B0HYxReN4jsmiX3aEYeXvrOnT5tYRLMbvhx8PDfAFcB/B+ZXNdODo9BX1i+ozV a0EHRRH5yQPpya X-Received: by 2002:a05:622a:110a:b0:50e:474a:47e1 with SMTP id d75a77b69052e-52d74b47156mr1266911cf.10.1786564897457; Wed, 12 Aug 2026 13:01:37 -0700 (PDT) X-Received: by 2002:a05:622a:110a:b0:50e:474a:47e1 with SMTP id d75a77b69052e-52d74b47156mr1266161cf.10.1786564896922; Wed, 12 Aug 2026 13:01:36 -0700 (PDT) Received: from umbar.lan (2001-14ba-a073-af00-264b-feff-fe8b-be8a.rev.dnainternet.fi. [2001:14ba:a073:af00:264b:feff:fe8b:be8a]) by smtp.gmail.com with ESMTPSA id 38308e7fff4ca-3a11b2acb0fsm354561fa.12.2026.08.12.13.01.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 13:01:33 -0700 (PDT) From: Dmitry Baryshkov Date: Wed, 12 Aug 2026 23:01:24 +0300 Subject: [PATCH 2/3] media: venus: hfi_parser: size a raw format property by its own entries Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260812-venus-8996-v1-2-6615f82a63b8@oss.qualcomm.com> References: <20260812-venus-8996-v1-0-6615f82a63b8@oss.qualcomm.com> In-Reply-To: <20260812-venus-8996-v1-0-6615f82a63b8@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Bryan O'Donoghue , Mauro Carvalho Chehab , Stanimir Varbanov , Hans Verkuil , Tomasz Figa Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, Mauro Carvalho Chehab X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=3671; i=dmitry.baryshkov@oss.qualcomm.com; h=from:subject:message-id; bh=sBVU1vPwdqmVJbT5lEmy2hLjCPRTfUjf3ue9MRRCoO8=; b=owEBbQGS/pANAwAKAYs8ij4CKSjVAcsmYgBqfNEWZMXyMjow2pbuu3jtP6gpQcK6WuPwR2/ah kCfGu/BS+yJATMEAAEKAB0WIQRMcISVXLJjVvC4lX+LPIo+Aiko1QUCanzRFgAKCRCLPIo+Aiko 1Xd4B/9rNwKPqtpf4P8m6h42ck8yx+Gndg3jB+SNUc2bYsKYbE+OL4B2+cQ7edv+J/1doXwxZes jg80RAfi2uV8Fts2u0EDzloYBhAILcls3I5DyAXYjjzS5nUyeh7OKLFlfIEiWl33RsS1SocKhW2 o6d2P8XtdtHZKBK4nwP2VuLMvxZPNvREdIoExZORm9B8+wugVq5tMogf5atwy+irfQZ4Hnwdabu 7Aqs0vAq9ZC3g2GIhYE0/Kv1yYFwbgiNh1V6p2vIpEwKjCcSU4+w5FtMonBOj8P4Ok7CJ4YOZc0 C7EyZSll+Ir6JFYPIkPDtKo4xik/ZjUKNYP52fmtMSgH+AJe X-Developer-Key: i=dmitry.baryshkov@oss.qualcomm.com; a=openpgp; fpr=8F88381DD5C873E4AE487DA5199BF1243632046A X-Proofpoint-GUID: Jj67De_zW70JvmzANl2q5W6f1__t_293 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MCBTYWx0ZWRfX+ANfZ9aVd37/ MzSskJYjeBgzQA4YmGGBiPdrKIsA9CEOVOnbovtrFxv580BUVghCwY1C3nPlmDQeHLs0ZWPwCOO bWGcQ5s59AIs4l2f40yqWDM7DQIkxX7RQiIqF8Hm+7WnivtCitbk7p11dyQen3Bc67IRwzXDqg9 qO6ow1DKoaCYAlYD2GhxmWsp6ot78XEL47aiuuxOGZwDaziIZJetS1+UnXCbbH5yLnqsy9gJmj3 rSDfxcqh9BCHfZ3qYvA1cCK5HMN1z2Q7SEnmmVXX84dWgOLeLrcxFopVwRhb6ApNgaU2grklYy1 BwbqdMsmf2jr/AwBs1Kf4LR5RNi61pi8HPZnYz19747pbQEP/vgVzibO8mDZXFYUYW0eG4ktsTK EzUnt9o7E216Kb8ncTrVHV/tUL39q0KRxMiQF8F9Jn5MULzSOfhBAuX6XdlctganrLtjxxYZcDS hd5L5o7HVdj0+U2lkJQ== X-Authority-Analysis: v=2.4 cv=E8n9Y6dl c=1 sm=1 tr=0 ts=6a7cd122 cx=c_pps a=EVbN6Ke/fEF3bsl7X48z0g==:117 a=xqWC_Br6kY4A:10 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=Um2Pa8k9VHT-vaBCBUpS:22 a=EUspDBNiAAAA:8 a=cOiMibB1P2E-5jhLw68A:9 a=QEXdDO2ut3YA:10 a=a_PwQJl-kcHnX1M80qC6:22 X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MCBTYWx0ZWRfX89sNe7HtOTTf IMKo7gckPna0Nq/Uu1GJxa3Ylro81Wuy2VdX7SMelceGOhmUfA/NxjWYoIZ1lZtjn6P1M8BIk9e U/ypTkBu2bSKqYPbUljf+UbbhBHyUn4= X-Proofpoint-ORIG-GUID: Jj67De_zW70JvmzANl2q5W6f1__t_293 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 malwarescore=0 lowpriorityscore=0 adultscore=0 bulkscore=0 clxscore=1015 impostorscore=0 spamscore=0 phishscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120160 parse_raw_formats() walks the format entries one at a time, each of which is as long as its own plane count makes it, but then computes the length of the whole property as if every entry had as many planes as the last one it looked at. The result is only correct when all the entries agree, and there is nothing in the interface that says they must. On MSM8996 they do not, and the parser walks off into the middle of the message as a result. The raw format property of the HEVC decoder is 120 bytes long and the walk claims 152, so hfi_parser() resumes 28 bytes past the end of it, skipping the codec mask that follows and landing inside the property after that. It resynchronises eventually, because an unrecognized word is skipped one at a time, but everything it jumped over is lost. What is lost matters: the property skipped that way is the capability set of the codec mask 0x7002, which is to say the frame size, macroblock and frame rate limits of H.264, VP8, VP9 and HEVC decoding, all four of them described in one block. Those decoders end up holding a bitrate and nothing else, so frame_width_min() and friends return zero and VIDIOC_ENUM_FRAMESIZES advertises a stepwise range of 0x0 to 0x0 with a step of 0. Userspace cannot negotiate against that. GStreamer builds the sink caps of its V4L2 decoders from the enumerated frame sizes, an empty integer range collapses them to EMPTY, and no pad is found to be compatible with the parser feeding the decoder, so a pipeline as simple as filesrc ! parsebin ! v4l2vp9dec ! videoconvert ! fakesink fails to link and the stream stops with "not-linked" before a single buffer is queued. Hardware decoding is unavailable on the board for every codec in that block. An earlier overshoot loses a raw format property too, leaving the decoders with two of the five formats the firmware describes and HEVC with four of seven. Accumulate the length of the entries as they are walked, the way the downstream driver does, rather than extrapolating from the last one. Fixes: 1a73374a04e5 ("media: venus: hfi_parser: add common capability parse= r") Assisted-by: Claude:claude-opus-5 Signed-off-by: Dmitry Baryshkov --- drivers/media/platform/qcom/venus/hfi_parser.c | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/drivers/media/platform/qcom/venus/hfi_parser.c b/drivers/media= /platform/qcom/venus/hfi_parser.c index 3413b91b0b7e..f79c368647d7 100644 --- a/drivers/media/platform/qcom/venus/hfi_parser.c +++ b/drivers/media/platform/qcom/venus/hfi_parser.c @@ -171,7 +171,7 @@ parse_raw_formats(struct venus_core *core, u32 codecs, = u32 domain, void *data) u32 entries =3D fmt->format_entries; unsigned int i =3D 0; u32 num_planes =3D 0; - u32 size; + u32 size =3D 2 * sizeof(u32); =20 while (entries) { num_planes =3D pinfo->num_planes; @@ -183,9 +183,10 @@ parse_raw_formats(struct venus_core *core, u32 codecs,= u32 domain, void *data) if (i >=3D MAX_FMT_ENTRIES) return -EINVAL; =20 - if (pinfo->num_planes > MAX_PLANES) + if (num_planes > MAX_PLANES) break; =20 + size +=3D sizeof(*constr) * num_planes + 2 * sizeof(u32); pinfo =3D (void *)pinfo + sizeof(*constr) * num_planes + 2 * sizeof(u32); entries--; @@ -193,8 +194,6 @@ parse_raw_formats(struct venus_core *core, u32 codecs, = u32 domain, void *data) =20 for_each_codec(core->caps, ARRAY_SIZE(core->caps), codecs, domain, fill_raw_fmts, rawfmts, i); - size =3D fmt->format_entries * (sizeof(*constr) * num_planes + 2 * sizeof= (u32)) - + 2 * sizeof(u32); =20 return size; } --=20 2.47.3 From nobody Tue Sep 29 04:13:42 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 06360349CE4 for ; Wed, 12 Aug 2026 20:01:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564906; cv=none; b=szvdC58BimHjFRQOEbxz7vKIt4bqhiuZ5iA5Hr+fx0UuKOQg6vBK32NXA1gqY2f0jBwnAxnU5HBeYlagybC1L3X8+7qEqnnhj2ECOsL7nychDYw/crsIc5P/E54h9QS+dQIfOkqITezGWmB2znNBhlO6DM5+0HwiGLz+jii0zMk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786564906; c=relaxed/simple; bh=5TydX6YikVp1Sc2sSWcsXlwWC7g4cca4nfCeQ4bD1Rc=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=u0rcmZLkLg//WwM5EB2SLBWc1F674vusCyV4EaPBzzLdBpSDB1qKoxu1j2uadogNxvnuY+XlwxVpfh+xO6mIzgOkx2XhLJejwgjdD7nKgO+XZlPUd2t6gE9JsEyquXV8mxXoXadXi+nhJKQqtRFzv6i9OHfg11vDy7ozZLoGu5E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=ejK8hlVI; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=K1z9d6pz; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="ejK8hlVI"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="K1z9d6pz" Received: from pps.filterd (m0279862.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67CI9Fdn057210 for ; Wed, 12 Aug 2026 20:01:44 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= NAAK+dVxkbm/up/widEbGwaEg5Z5O0NAGPsT/Irywtw=; b=ejK8hlVInCwO3kMX OwlsGhri9rkwqmiHE+Vkh25HTmyAX/jHtzDq5wEzg8Dds/MIjKq/2s744Iqcvcq5 d3IG4uWtAVIq8d/iBIWTaNqZZHtFWVPcU3HfuODwE/TNz0bvmXmdFGXsqVFWcIF3 vVLHZS9cL8YBCmP30pBtzEypC1MNmEUQYnx9gnMsRkg86YAJLrmVdO153/oXLHSd a/T41alC/t1tlkXVZlfKc+/fDsARzmRRQHAl8kRI+KwUrexK5nUZdMQfNTrM0v13 y5j0aOLMeJD4YWj7opoGw58ZlEkcihxo/jhUznK6HZD+7L0Y3o1DWYz78iW1kqYq 3mopFg== Received: from mail-qt1-f198.google.com (mail-qt1-f198.google.com [209.85.160.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4g0pmytnaj-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 12 Aug 2026 20:01:43 +0000 (GMT) Received: by mail-qt1-f198.google.com with SMTP id d75a77b69052e-52ce3c7cb2eso23813521cf.3 for ; Wed, 12 Aug 2026 13:01:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1786564902; x=1787169702; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=NAAK+dVxkbm/up/widEbGwaEg5Z5O0NAGPsT/Irywtw=; b=K1z9d6pzQRin2UaEi6FhfsGih4Y98BE3Hspm4eRlYortKSrBBWVuCWqbpIa/l3TYmu W+scRs8oxDoZcqKUeydfnkZrAvROy6FpLTIyms7j8Fz1gD6m6ZHHF9jgQ1Cr/Q/y6FKg vFk2XMu8OM8NEkV+BGJdOQfUx63D6WSOeQooXWxJkRbfVOzKYTJxpjQpSzOr+TZp8dJ1 Oo6UfogvqFeMgikgRk53YoRNBM7TtPGs3rqvBBw8TqeRlp0gkHjCAXPvxFu6DbTxH+9r oEtDdWzJz/6Jo1ZLFz/JjCEYwLhRHSyDUWUhKNzQaYmcN8+1P19fRwVed8u/epkQh59P SVJw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786564903; x=1787169703; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=NAAK+dVxkbm/up/widEbGwaEg5Z5O0NAGPsT/Irywtw=; b=gu1e4Q4HCOt2WS4cQ9IkGmB1PGcIOKTUZ1l2NPMKKp9JlX6RS6k1bJIDyBuUhubzHm mhtc0ApmurP66U4r6b2/DuJGjMqIYytA9xG7sKNkYkXFO6pmXNEezwIQmayp0lrLprgC CqM6cFStxUadhs7TruDNLA0imoYHXIuDStruAiiIOaqL8yUzHCLT64ioRdB5FKFUmFkj 70nIgJRkmgmmqIKzpb4YlmWf5V7zVtaedD3iGNwuZ2w9JDH5kD20n3kJpMH88zZKqxty DDtKoklHBt3pXfDRRP6lO96ljGZQ+ZNS3m9q1M2iPOEnI7NiVr6beCzcrbPuQOJt0v0D FO1g== X-Forwarded-Encrypted: i=1; AHgh+Rrjodp8hHLQcftQJiYC5XYv/fryOz9BqT/VTEd3MUJ8eRNva0N/z55ROIYPIu3ocjbqlwmsmYzOd7MWNlg=@vger.kernel.org X-Gm-Message-State: AOJu0YxMaGMEAK+hgXGwKjAnlzbdrDlDZXnMMmIOux3AlqHhHpmtgpSu TfuYp6ZuDlkXRFn+wu4Fy3YRD0zS1efV+g722arhwoAtAcG+K38loaHTuvXVbWulsOA8DOHeEQO OvVB/IwnGCt4rZYQTYqs8PbSyrawTCnDW1lVTjLSUHGguvf7mi2aoLvuZYGV+9TxDf7E= X-Gm-Gg: AR+sD12KUyGGbsmY/GW3ESAbCvZmeTusbqCKYgglqD7orOmO22J6BZh5zRhcZrK/BjJ MVL+xowXsqGuG7wFYEyWG19fXr+0JdrH3RJ9IpteBdkBXNdKK87dT/GglJ70B6raEPA1FwdLK5Z TGAjFMqKmx6ON55WJjZiAd0IdzqSyj9+NsUBFv06GGsZNWn4z/G4MpsTeCQJ6RSmFIywLSLD7Yf 0l4QcK7KgKDtGxo7I8Jkaw581cqfOzht3N+8gmp8MVZbW2qKzK6vq+AJsy7INtBn4sDYD8qgCCS 4/Z5XLj5fuRN/HXOlqhjBw/nZ5p7+FkdTdNEBPXfpdR+6Pe/DGibxpwHXj5x9c/x/ekO0+D6+ww DBTL9DzpOA8SM1lyScg4G8d4BhDTuoX3esaI6CnWAtpDrnkbFWcrQR6rSMSHcbNkhCR/rblOPIh 1hT651FAzFuqjI X-Received: by 2002:ac8:5dc9:0:b0:527:7842:72cc with SMTP id d75a77b69052e-52d73dee51cmr5591421cf.39.1786564901792; Wed, 12 Aug 2026 13:01:41 -0700 (PDT) X-Received: by 2002:ac8:5dc9:0:b0:527:7842:72cc with SMTP id d75a77b69052e-52d73dee51cmr5589561cf.39.1786564900440; Wed, 12 Aug 2026 13:01:40 -0700 (PDT) Received: from umbar.lan (2001-14ba-a073-af00-264b-feff-fe8b-be8a.rev.dnainternet.fi. [2001:14ba:a073:af00:264b:feff:fe8b:be8a]) by smtp.gmail.com with ESMTPSA id 38308e7fff4ca-3a11b2acb0fsm354561fa.12.2026.08.12.13.01.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 13:01:37 -0700 (PDT) From: Dmitry Baryshkov Date: Wed, 12 Aug 2026 23:01:25 +0300 Subject: [PATCH 3/3] media: venus: report the frame size of the codec being enumerated Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260812-venus-8996-v1-3-6615f82a63b8@oss.qualcomm.com> References: <20260812-venus-8996-v1-0-6615f82a63b8@oss.qualcomm.com> In-Reply-To: <20260812-venus-8996-v1-0-6615f82a63b8@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Bryan O'Donoghue , Mauro Carvalho Chehab , Stanimir Varbanov , Hans Verkuil , Tomasz Figa Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, Mauro Carvalho Chehab X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=8427; i=dmitry.baryshkov@oss.qualcomm.com; h=from:subject:message-id; bh=5TydX6YikVp1Sc2sSWcsXlwWC7g4cca4nfCeQ4bD1Rc=; b=kA0DAAoBizyKPgIpKNUByyZiAGp80RbIJFmZPxfq+64dIRgRSIMojefUFZVzmLmlOa3N7HE4v YkBMwQAAQoAHRYhBExwhJVcsmNW8LiVf4s8ij4CKSjVBQJqfNEWAAoJEIs8ij4CKSjVjEsH/R1X 6wClTtjkrFSys/pP4seh5XFIWo4p8E2MA70s8hV0PkDjMdln7WZkKb/l1CWkBEuw/GghEAAkQ3x ml+pr1VmRipzqTmYyDBhFQ6NP5+yDzgQTxX0iSg3DxLMDfPXSPqrLgzZTsjEcq8XGpk7JGVok+R D4kiJLhXo90DATMi6PfCFTsmXqED8Ufka0nEduSV3XgglDWiRYTLoTREoyP9v5vZExak2D0XQHi tS3956SPQ83xGM3e67xvLbfXijzw5Z6KYWzGz+U1xZ3OXVXoSVsGtsZ3XfQp51xeH366d725i/i RaBisAx263SE1yfRkWn+mfjzRftxX1XUIOUUvJ8= X-Developer-Key: i=dmitry.baryshkov@oss.qualcomm.com; a=openpgp; fpr=8F88381DD5C873E4AE487DA5199BF1243632046A X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDE2MCBTYWx0ZWRfX+JcR+tyarrAy auz/Z36bb0QFdr1Qwm/if/H0xP0QuYzIVVMIi0pdz/rOmt4V9jIeeQQHZurH40fvgN5c5P88+qx Ju1WGf9k7NF95RorLN7eBYB0X7FQ5Qg= X-Proofpoint-ORIG-GUID: ApGsZEPiSw4iB7rzsR_FgMQNjyJa8PH0 X-Authority-Analysis: v=2.4 cv=C/fZDwP+ c=1 sm=1 tr=0 ts=6a7cd127 cx=c_pps a=mPf7EqFMSY9/WdsSgAYMbA==:117 a=xqWC_Br6kY4A:10 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_K5XuSEh1TEqbUxoQ0s3:22 a=EUspDBNiAAAA:8 a=BhK9gz1YmpFySvrNxgUA:9 a=QEXdDO2ut3YA:10 a=dawVfQjAaf238kedN5IG:22 X-Proofpoint-GUID: ApGsZEPiSw4iB7rzsR_FgMQNjyJa8PH0 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDE2MCBTYWx0ZWRfX0pgccsYgrP3h 7M/oChlDEkmVegkCW11mlzlJNT0otDvLfl8ce5Dd4V/jT2sHFkMUv0pWgqtlGgFaNQn8n4vRfB5 zQJEIqtf2UM5O2NhFn35a64r6M+VKT4ujRvWPh6JreYPVI+tdmLp9psmi+HpkSDFCU6uZ/EWrC2 jozXr+WwoGK6YodLTavcuFh3puSKpJl42Z3fwzG5aZJ8luSffonBokZsA4Sh1umhZVUaQ7FeG1w S3U7lM4xpbfPltY1pdLulEUFYAMomaO/SIvF/gO6TEsUV/b8lXzz6jLOPP+zsywmObNs87Al05F xtdbm+e5yfadk4o+B0vUrHvXa7BwhFSt6zY0y+cdJguAZ9Tuo7zmJDiRbuySKZnhuKbuLG1X6Nq WuXeie/07PjM8vtsb2PLVqItX4987kYtJNhagxBviN6F1Q/2PXE2Z14WKGi9EzVXxyZIU5CGSEH o7HmtGSyCo3Qyp3cvFQ== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_05,2026-08-12_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 clxscore=1015 phishscore=0 spamscore=0 malwarescore=0 adultscore=0 suspectscore=0 lowpriorityscore=0 priorityscore=1501 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120160 VIDIOC_ENUM_FRAMESIZES takes the pixel format to describe from userspace, but both vdec and venc answer it out of frame_width_min() and friends, which resolve the capabilities through inst->hfi_codec, the codec the instance is currently set to. Enumerating any format other than that one therefore returns the limits of an unrelated codec: on a freshly opened decoder, which starts out as H.264, asking about MPEG-2 on MSM8996 reports the H.264 limits where the firmware describes MPEG-2 as 16x16 to 1920x1920. Resolve the capabilities through the format being enumerated instead, falling back to the codec in use for the raw formats, which have no codec of their own. Both drivers now share one helper, alongside the pixel format to codec mapping that venus_helper_check_codec() already carried. Assisted-by: Claude:claude-opus-5 Signed-off-by: Dmitry Baryshkov --- drivers/media/platform/qcom/venus/helpers.c | 75 +++++++++++++++++-----= ---- drivers/media/platform/qcom/venus/helpers.h | 2 + drivers/media/platform/qcom/venus/hfi_parser.h | 12 +++-- drivers/media/platform/qcom/venus/vdec.c | 7 +-- drivers/media/platform/qcom/venus/venc.c | 7 +-- 5 files changed, 62 insertions(+), 41 deletions(-) diff --git a/drivers/media/platform/qcom/venus/helpers.c b/drivers/media/pl= atform/qcom/venus/helpers.c index 59eee3dd9e06..17415d0cdf8e 100644 --- a/drivers/media/platform/qcom/venus/helpers.c +++ b/drivers/media/platform/qcom/venus/helpers.c @@ -38,47 +38,43 @@ struct intbuf { u32 dpb_out_tag; }; =20 -bool venus_helper_check_codec(struct venus_inst *inst, u32 v4l2_pixfmt) +static u32 venus_pixfmt_to_hfi_codec(u32 v4l2_pixfmt) { - struct venus_core *core =3D inst->core; - u32 session_type =3D inst->session_type; - u32 codec; - switch (v4l2_pixfmt) { case V4L2_PIX_FMT_H264: - codec =3D HFI_VIDEO_CODEC_H264; - break; + return HFI_VIDEO_CODEC_H264; case V4L2_PIX_FMT_H263: - codec =3D HFI_VIDEO_CODEC_H263; - break; + return HFI_VIDEO_CODEC_H263; case V4L2_PIX_FMT_MPEG1: - codec =3D HFI_VIDEO_CODEC_MPEG1; - break; + return HFI_VIDEO_CODEC_MPEG1; case V4L2_PIX_FMT_MPEG2: - codec =3D HFI_VIDEO_CODEC_MPEG2; - break; + return HFI_VIDEO_CODEC_MPEG2; case V4L2_PIX_FMT_MPEG4: - codec =3D HFI_VIDEO_CODEC_MPEG4; - break; + return HFI_VIDEO_CODEC_MPEG4; case V4L2_PIX_FMT_VC1_ANNEX_G: case V4L2_PIX_FMT_VC1_ANNEX_L: - codec =3D HFI_VIDEO_CODEC_VC1; - break; + return HFI_VIDEO_CODEC_VC1; case V4L2_PIX_FMT_VP8: - codec =3D HFI_VIDEO_CODEC_VP8; - break; + return HFI_VIDEO_CODEC_VP8; case V4L2_PIX_FMT_VP9: - codec =3D HFI_VIDEO_CODEC_VP9; - break; + return HFI_VIDEO_CODEC_VP9; case V4L2_PIX_FMT_XVID: - codec =3D HFI_VIDEO_CODEC_DIVX; - break; + return HFI_VIDEO_CODEC_DIVX; case V4L2_PIX_FMT_HEVC: - codec =3D HFI_VIDEO_CODEC_HEVC; - break; + return HFI_VIDEO_CODEC_HEVC; default: - return false; + return 0; } +} + +bool venus_helper_check_codec(struct venus_inst *inst, u32 v4l2_pixfmt) +{ + struct venus_core *core =3D inst->core; + u32 session_type =3D inst->session_type; + u32 codec =3D venus_pixfmt_to_hfi_codec(v4l2_pixfmt); + + if (!codec) + return false; =20 if (session_type =3D=3D VIDC_SESSION_TYPE_ENC && core->enc_codecs & codec) return true; @@ -90,6 +86,33 @@ bool venus_helper_check_codec(struct venus_inst *inst, u= 32 v4l2_pixfmt) } EXPORT_SYMBOL_GPL(venus_helper_check_codec); =20 +/* + * Report the frame size of the codec being enumerated, which is not + * necessarily the one the instance is currently set to. A raw format map= s to + * no codec of its own and is described by the coded format in use. + */ +void venus_helper_get_frame_sizes(struct venus_inst *inst, u32 v4l2_pixfmt, + struct v4l2_frmsize_stepwise *fsize) +{ + struct venus_core *core =3D inst->core; + u32 dom =3D inst->session_type; + u32 codec =3D venus_pixfmt_to_hfi_codec(v4l2_pixfmt) ?: inst->hfi_codec; + + fsize->min_width =3D get_codec_cap(core, codec, dom, + HFI_CAPABILITY_FRAME_WIDTH, WHICH_CAP_MIN); + fsize->max_width =3D get_codec_cap(core, codec, dom, + HFI_CAPABILITY_FRAME_WIDTH, WHICH_CAP_MAX); + fsize->step_width =3D get_codec_cap(core, codec, dom, + HFI_CAPABILITY_FRAME_WIDTH, WHICH_CAP_STEP); + fsize->min_height =3D get_codec_cap(core, codec, dom, + HFI_CAPABILITY_FRAME_HEIGHT, WHICH_CAP_MIN); + fsize->max_height =3D get_codec_cap(core, codec, dom, + HFI_CAPABILITY_FRAME_HEIGHT, WHICH_CAP_MAX); + fsize->step_height =3D get_codec_cap(core, codec, dom, + HFI_CAPABILITY_FRAME_HEIGHT, WHICH_CAP_STEP); +} +EXPORT_SYMBOL_GPL(venus_helper_get_frame_sizes); + static void free_dpb_buf(struct venus_inst *inst, struct intbuf *buf) { ida_free(&inst->dpb_ids, buf->dpb_out_tag); diff --git a/drivers/media/platform/qcom/venus/helpers.h b/drivers/media/pl= atform/qcom/venus/helpers.h index 358e4f39c9c0..80d623db106c 100644 --- a/drivers/media/platform/qcom/venus/helpers.h +++ b/drivers/media/platform/qcom/venus/helpers.h @@ -12,6 +12,8 @@ struct venus_inst; struct venus_core; =20 bool venus_helper_check_codec(struct venus_inst *inst, u32 v4l2_pixfmt); +void venus_helper_get_frame_sizes(struct venus_inst *inst, u32 v4l2_pixfmt, + struct v4l2_frmsize_stepwise *fsize); struct vb2_v4l2_buffer *venus_helper_find_buf(struct venus_inst *inst, unsigned int type, u32 idx); void venus_helper_change_dpb_owner(struct venus_inst *inst, diff --git a/drivers/media/platform/qcom/venus/hfi_parser.h b/drivers/media= /platform/qcom/venus/hfi_parser.h index 5751d0140700..bcd11e7a9c1c 100644 --- a/drivers/media/platform/qcom/venus/hfi_parser.h +++ b/drivers/media/platform/qcom/venus/hfi_parser.h @@ -12,14 +12,14 @@ u32 hfi_parser(struct venus_core *core, struct venus_in= st *inst, #define WHICH_CAP_MAX 1 #define WHICH_CAP_STEP 2 =20 -static inline u32 get_cap(struct venus_inst *inst, u32 type, u32 which) +static inline u32 get_codec_cap(struct venus_core *core, u32 codec, u32 do= main, + u32 type, u32 which) { - struct venus_core *core =3D inst->core; struct hfi_capability *cap =3D NULL; struct hfi_plat_caps *caps; unsigned int i; =20 - caps =3D venus_caps_by_codec(core, inst->hfi_codec, inst->session_type); + caps =3D venus_caps_by_codec(core, codec, domain); if (!caps) return 0; =20 @@ -47,6 +47,12 @@ static inline u32 get_cap(struct venus_inst *inst, u32 t= ype, u32 which) return 0; } =20 +static inline u32 get_cap(struct venus_inst *inst, u32 type, u32 which) +{ + return get_codec_cap(inst->core, inst->hfi_codec, inst->session_type, + type, which); +} + static inline u32 cap_min(struct venus_inst *inst, u32 type) { return get_cap(inst, type, WHICH_CAP_MIN); diff --git a/drivers/media/platform/qcom/venus/vdec.c b/drivers/media/platf= orm/qcom/venus/vdec.c index 6a43ea191da1..0f62931eea4c 100644 --- a/drivers/media/platform/qcom/venus/vdec.c +++ b/drivers/media/platform/qcom/venus/vdec.c @@ -512,12 +512,7 @@ static int vdec_enum_framesizes(struct file *file, voi= d *fh, =20 fsize->type =3D V4L2_FRMSIZE_TYPE_STEPWISE; =20 - fsize->stepwise.min_width =3D frame_width_min(inst); - fsize->stepwise.max_width =3D frame_width_max(inst); - fsize->stepwise.step_width =3D frame_width_step(inst); - fsize->stepwise.min_height =3D frame_height_min(inst); - fsize->stepwise.max_height =3D frame_height_max(inst); - fsize->stepwise.step_height =3D frame_height_step(inst); + venus_helper_get_frame_sizes(inst, fsize->pixel_format, &fsize->stepwise); =20 return 0; } diff --git a/drivers/media/platform/qcom/venus/venc.c b/drivers/media/platf= orm/qcom/venus/venc.c index 79acf7c1ec9a..e0f7b9817ccf 100644 --- a/drivers/media/platform/qcom/venus/venc.c +++ b/drivers/media/platform/qcom/venus/venc.c @@ -456,12 +456,7 @@ static int venc_enum_framesizes(struct file *file, voi= d *fh, if (fsize->index) return -EINVAL; =20 - fsize->stepwise.min_width =3D frame_width_min(inst); - fsize->stepwise.max_width =3D frame_width_max(inst); - fsize->stepwise.step_width =3D frame_width_step(inst); - fsize->stepwise.min_height =3D frame_height_min(inst); - fsize->stepwise.max_height =3D frame_height_max(inst); - fsize->stepwise.step_height =3D frame_height_step(inst); + venus_helper_get_frame_sizes(inst, fsize->pixel_format, &fsize->stepwise); =20 return 0; } --=20 2.47.3