On Fri Jun 26 10:22:26 2026 +0900, Jackson Lee wrote:
> When CAPTURE STREAMON is called before the VPU has completed sequence
> initialization (initial_info_obtained == false), the initial_info fields
> contain uninitialized data. The driver checks
> luma_bitdepth and rejects anything other than 8-bit, so garbage values
> (e.g. 15) cause STREAMON to fail spuriously.
> 
> This is reproducible with the following multi-threaded test scenario:
>   1. Allocate 2 CAPTURE buffers.
>   2. Call STREAMON on the CAPTURE queue.
>   3. Call DQBUF, which blocks waiting for a decoded frame.
>   4. A second thread calls STREAMOFF on the CAPTURE queue.
>   5. The blocked DQBUF should be released, allowing graceful termination.
> 
> At step 2, STREAMON reads uninitialized luma_bitdepth and rejects the
> stream, causing the test to fail.
> 
> Fix this by checking initial_info_obtained before accessing the bit
> depth fields, so the validation is only performed when the sequence
> info has actually been parsed by the VPU.
> 
> Fixes: 035371c9e509 ("media: chips-media: wave5: Fix timeout while testing 
> 10bit hevc fluster")
> Cc: [email protected]
> Signed-off-by: Jackson Lee <[email protected]>
> Signed-off-by: Nas Chung <[email protected]>
> Reviewed-by: Nicolas Dufresne <[email protected]>
> Signed-off-by: Nicolas Dufresne <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

---

diff --git a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c 
b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
index bb2ba9204a83..01d1368b2965 100644
--- a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
@@ -1403,6 +1403,7 @@ static int wave5_vpu_dec_start_streaming(struct vb2_queue 
*q, unsigned int count
        } else if (q->type == V4L2_BUF_TYPE_VIDEO_CAPTURE_MPLANE) {
                struct dec_initial_info *initial_info =
                        &inst->codec_info->dec_info.initial_info;
+               struct dec_info *p_dec_info = &inst->codec_info->dec_info;
 
                if (inst->state == VPU_INST_STATE_STOP)
                        ret = switch_state(inst, VPU_INST_STATE_INIT_SEQ);
@@ -1410,6 +1411,7 @@ static int wave5_vpu_dec_start_streaming(struct vb2_queue 
*q, unsigned int count
                        goto return_buffers;
 
                if (inst->state == VPU_INST_STATE_INIT_SEQ &&
+                   p_dec_info->initial_info_obtained &&
                    inst->dev->product_code == WAVE521C_CODE) {
                        if (initial_info->luma_bitdepth != 8) {
                                dev_info(inst->dev->dev, "%s: no support for %d 
bit depth",
@@ -1418,7 +1420,6 @@ static int wave5_vpu_dec_start_streaming(struct vb2_queue 
*q, unsigned int count
                                goto return_buffers;
                        }
                }
-
        }
        pm_runtime_put_autosuspend(inst->dev->dev);
        return ret;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to