mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sasha Levin <sashal@kernel.org>
To: patches@lists.linux.dev, stable@vger.kernel.org
Cc: Nas Chung <nas.chung@chipsnmedia.com>,
	Sebastian Fricke <sebastian.fricke@collabora.com>,
	Hans Verkuil <hverkuil@xs4all.nl>,
	Sasha Levin <sashal@kernel.org>,
	mchehab@kernel.org, linux-media@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: [PATCH AUTOSEL 5.15 09/43] media: uapi: v4l: Fix V4L2_TYPE_IS_OUTPUT condition
Date: Sun,  1 Jun 2025 19:41:49 -0400	[thread overview]
Message-ID: <20250601234224.3517599-9-sashal@kernel.org> (raw)
In-Reply-To: <20250601234224.3517599-1-sashal@kernel.org>

From: Nas Chung <nas.chung@chipsnmedia.com>

[ Upstream commit f81f69a0e3da141bdd73a16b8676f4e542533d87 ]

V4L2_TYPE_IS_OUTPUT() returns true for V4L2_BUF_TYPE_VIDEO_OVERLAY
which definitely belongs to CAPTURE.

Signed-off-by: Nas Chung <nas.chung@chipsnmedia.com>
Signed-off-by: Sebastian Fricke <sebastian.fricke@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil@xs4all.nl>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---

**YES** This commit should be backported to stable kernel trees.
**Detailed Analysis:** **1. Nature of the Bug:** The commit fixes a
fundamental logic error in the `V4L2_TYPE_IS_OUTPUT` macro that has
existed since 2012 (commit 607ca46e97a1b). The macro incorrectly
classifies `V4L2_BUF_TYPE_VIDEO_OVERLAY` as an OUTPUT buffer type when
it should be classified as a CAPTURE type. This is a clear logical bug
in a core V4L2 API macro. **2. Code Impact Analysis:** The fix removes
this line from the macro: ```c || (type) == V4L2_BUF_TYPE_VIDEO_OVERLAY
``` My investigation shows the macro is used in critical V4L2 core
functions, particularly in: - **Crop/Selection handling**
(`drivers/media/v4l2-core/v4l2-ioctl.c:2517, 2547, 2597`): The macro
determines whether to use `V4L2_SEL_TGT_COMPOSE` (for output) vs
`V4L2_SEL_TGT_CROP` (for capture) targets - **Parameter handling**
(`drivers/media/v4l2-core/v4l2-ioctl.c:2269`): Affects how output vs
capture parameters are processed - **Buffer management** in videobuf2
framework: Affects buffer direction logic **3. User Impact:**
Applications using video overlay functionality have been subject to
incorrect behavior where: - Overlay buffers were processed with output
buffer logic instead of capture buffer logic - Wrong selection targets
were used for crop operations on overlay devices - Parameter handling
followed the wrong code paths **4. Risk Assessment:** - **Low regression
risk**: The fix corrects clearly wrong behavior - there's no valid use
case where VIDEO_OVERLAY should be treated as OUTPUT - **Contained
scope**: Only affects the classification logic for one specific buffer
type - **Clear correctness**: The fix aligns the code with the V4L2
specification and logical expectations **5. Comparison with Similar
Commits:** Looking at the historical commits provided, while they show
refactoring and API improvements that were not backported, this commit
fixes a fundamental logical bug in core API behavior, which is different
from cosmetic or enhancement changes. **6. Backport Suitability:** This
meets all stable backport criteria: - ✅ Fixes a clear bug affecting
users - ✅ Small, contained change with minimal risk - ✅ No new features
or architectural changes - ✅ Affects core V4L2 functionality that could
cause incorrect application behavior - ✅ Logic error that has persisted
for over a decade The fix should be backported to ensure VIDEO_OVERLAY
applications work correctly across all supported kernel versions.

 include/uapi/linux/videodev2.h | 1 -
 1 file changed, 1 deletion(-)

diff --git a/include/uapi/linux/videodev2.h b/include/uapi/linux/videodev2.h
index f5c6758464f25..4e305496edf27 100644
--- a/include/uapi/linux/videodev2.h
+++ b/include/uapi/linux/videodev2.h
@@ -164,7 +164,6 @@ enum v4l2_buf_type {
 #define V4L2_TYPE_IS_OUTPUT(type)				\
 	((type) == V4L2_BUF_TYPE_VIDEO_OUTPUT			\
 	 || (type) == V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE		\
-	 || (type) == V4L2_BUF_TYPE_VIDEO_OVERLAY		\
 	 || (type) == V4L2_BUF_TYPE_VIDEO_OUTPUT_OVERLAY	\
 	 || (type) == V4L2_BUF_TYPE_VBI_OUTPUT			\
 	 || (type) == V4L2_BUF_TYPE_SLICED_VBI_OUTPUT		\
-- 
2.39.5


  parent reply	other threads:[~2025-06-01 23:42 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-06-01 23:41 [PATCH AUTOSEL 5.15 01/43] drm/amdgpu/gfx6: fix CSIB handling Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 02/43] sunrpc: update nextcheck time when adding new cache entries Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 03/43] drm/bridge: analogix_dp: Add irq flag IRQF_NO_AUTOEN instead of calling disable_irq() Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 04/43] exfat: fix double free in delayed_free Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 05/43] arm64/cpuinfo: only show one cpu's info in c_show() Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 06/43] drm/bridge: anx7625: change the gpiod_set_value API Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 07/43] media: i2c: imx334: Enable runtime PM before sub-device registration Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 08/43] drm/msm/hdmi: add runtime PM calls to DDC transfer function Sasha Levin
2025-06-01 23:41 ` Sasha Levin [this message]
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 10/43] drm/amd/display: Add NULL pointer checks in dm_force_atomic_commit() Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 11/43] drm/msm/a6xx: Increase HFI response timeout Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 12/43] media: i2c: imx334: Fix runtime PM handling in remove function Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 13/43] drm/amdgpu/gfx10: fix CSIB handling Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 14/43] media: ccs-pll: Better validate VT PLL branch Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 15/43] media: uapi: v4l: Change V4L2_TYPE_IS_CAPTURE condition Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 16/43] drm/amdgpu/gfx7: fix CSIB handling Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 17/43] ext4: ext4: unify EXT4_EX_NOCACHE|NOFAIL flags in ext4_ext_remove_space() Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 18/43] jfs: fix array-index-out-of-bounds read in add_missing_indices Sasha Levin
2025-06-01 23:41 ` [PATCH AUTOSEL 5.15 19/43] media: ti: cal: Fix wrong goto on error path Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 20/43] media: rkvdec: h264: Use bytesperline and buffer height as virstride Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 21/43] media: rkvdec: Initialize the m2m context before the controls Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 22/43] sunrpc: fix race in cache cleanup causing stale nextcheck time Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 23/43] ext4: prevent stale extent cache entries caused by concurrent get es_cache Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 24/43] drm/amdgpu/gfx8: fix CSIB handling Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 25/43] drm/amdgpu/gfx9: " Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 26/43] jfs: Fix null-ptr-deref in jfs_ioc_trim Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 27/43] drm/msm/dpu: don't select single flush for active CTL blocks Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 28/43] drm/amdkfd: Set SDMA_RLCx_IB_CNTL/SWITCH_INSIDE_IB Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 29/43] media: tc358743: ignore video while HPD is low Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 30/43] media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 31/43] media: i2c: imx334: update mode_3840x2160_regs array Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 32/43] nios2: force update_mmu_cache on spurious tlb-permission--related pagefaults Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 33/43] ACPI: bus: Bail out if acpi_kobj registration fails Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 34/43] pmdomain: ti: Fix STANDBY handling of PER power domain Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 35/43] PM: runtime: fix denying of auto suspend in pm_suspend_timer_fn() Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 36/43] thermal/drivers/qcom/tsens: Update conditions to strictly evaluate for IP v2+ Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 37/43] clocksource: Fix the CPUs' choice in the watchdog per CPU verification Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 38/43] ACPICA: Avoid sequence overread in call to strncmp() Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 39/43] ACPICA: utilities: Fix overflow check in vsnprintf() Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 40/43] ALSA: seq: Remove unused snd_seq_queue_client_leave_cells Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 41/43] cpufreq: Force sync policy boost with global boost on sysfs update Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 42/43] power: supply: bq27xxx: Retrieve again when busy Sasha Levin
2025-06-01 23:42 ` [PATCH AUTOSEL 5.15 43/43] ASoC: tas2770: Power cycle amp on ISENSE/VSENSE change Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250601234224.3517599-9-sashal@kernel.org \
    --to=sashal@kernel.org \
    --cc=hverkuil@xs4all.nl \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-media@vger.kernel.org \
    --cc=mchehab@kernel.org \
    --cc=nas.chung@chipsnmedia.com \
    --cc=patches@lists.linux.dev \
    --cc=sebastian.fricke@collabora.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®