From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f49.google.com (mail-qv1-f49.google.com [209.85.219.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DD9A03C8C49 for ; Sun, 14 Jun 2026 15:56:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781452581; cv=none; b=SteSQixi4Lta24pSL3Wp5/DTNGYncaUBFENhU1GbokkcpUFlIIo31t7E9iORNSm5ujvBBn1xHXuqgYyF92lVwvahJVhhkUKvGXUCtaJrnlvysVbneSBlcoq946U4dLErms253kY1083yoWeebd6a/tTYQvKgdBqUAUbgD98vs8Q= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781452581; c=relaxed/simple; bh=hmHOAPhRLoMfAfFhPoMmt5S6UD7EEY8vWV+vVjYiIbc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=icPZfk4ASIJ4JW3qLOLNEpl1F9xp7rnLiIFlKRDes/J9JfTY8CfdfL3Bq/N7B7oqHeM9HvO+ne7gTW2vGun90fElbTX7tnVCqZ7q9RjOk3zPcjU3t9/3gtEnWSRuRDVGx+WjA1dlNBIKiNfU4gn4ufvnaw0fTo4pX91Aw4BpIDs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Co6EB/vi; arc=none smtp.client-ip=209.85.219.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Co6EB/vi" Received: by mail-qv1-f49.google.com with SMTP id 6a1803df08f44-8cc0ef7c306so24123576d6.3 for ; Sun, 14 Jun 2026 08:56:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781452578; x=1782057378; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=T/sfSCxlJV21DnAv9Ka6YHdwihRoTK4jXXXiCxaH1uE=; b=Co6EB/viR2RZM6d9XVPJ1fUhm5NO0Ega/tMX26VO9fYj4JQz2JUCITegH1dYR+L/Mg YVTZpmbU7NygNh/nk2FpnlATW0QGPSn9mWS2DG6xqyHQodU7TRWJwzOStw7dor1SN67e pUiTxI16vyCCuH8+OXc1xKkPsZZrnxtEeIy0oiz79YkZ4Gr4iwg7D1vbgRl88o7UZCKm NJuXsW47di0neOr2rWUzBNptZyvMasQYyIC9S5vRCaLALn1ENTcIxu+AzcGUa2XdnVxV RiwwfVGhxHnzkkFjYJfPivM2ew1Q2UFs6n5lNck7hR30LeyyGBaCPIva9tIT1tq0h4xd wrLg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781452578; x=1782057378; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=T/sfSCxlJV21DnAv9Ka6YHdwihRoTK4jXXXiCxaH1uE=; b=WutvK2E1iSmKFVPNkYatEhrg6VSBsyfcDmqwQkd+4cD1vX97mnZP+Zsa2N3sO3jSf+ TwZZV/jrwf2D+Kc9Uqqj6h7hSkGoWScQU/hNXqti+8tDpdw1Op0Lah8hfioThcgV0llr hMloU0t2pLNhh//JsJBJQFCj5OTFdsUo89SnUYyUQi7FPeAneU045T9IWDB8bO+CvL82 Pan4c7rPaARM5VcA/DN5077OPe0l0q/xO/FYzs4VEW99Z4EGNAa4fA/iKcHhtJ21rmmk NtVmrKaTZGt3psCOsTpkXGSoDT2He5tEiqr6DZa6ZvadLWbPcdCbamNI/4G5J/4NrVou jTCg== X-Forwarded-Encrypted: i=1; AFNElJ/S94uqwAlw4wS9gg5NNRfqJoiWAlXmoefZn3dN1B21szuLxT5NU1a/81LZr9TyfLlmVyYWIK/quq560hU=@vger.kernel.org X-Gm-Message-State: AOJu0YwQBLFE/DBvgIk9SM0nSqTOD4N19WP0kX4LApFNTQkSwCaZBd3y CcPi4rsj+QiH8gxpBluPzhK+u2QGsEr3Vws5MEumjg57rCqppjF3cmzi X-Gm-Gg: Acq92OHDKbk9ZfpP7npFLVuts2CpCUnw1neKMw3O9KVi8OzG1x1/dJF5eqQX7jA60fN pH3Yss+LzNvUngdkC4MGQJzdjN7S/q9/DbM8E9ZJ4mK3xOI0GhUwAINOyeCp8yoxLu96qDQ11sD T8goPpuo0zZXoCZFkpy7Li877rGaSZySE51aBtvDS43nZmv/5BgHm/7ocyE7pXsdetuCnm6vVtM 3gCBRKXeRVa+Ni1ZYlVr4JPA5rzpZzHynRO/BAbIf853L7651VXZ1yTlGjmmyo6dcDSYKHTNzdA zZurDrsOa9ATMZpsE9NqsJWwh2TvzDrijAQEHbyZfckrd43ZaHjTj+qKwa4GN3bnQgr64OhxtCZ o/Y+EgucSGH1gQ1NishaCuDGORh2aXDqDGyHALFL24kXbq9W8MUt3RAAFx0+CPtwk59NENpJ5YG XdGPw3NhuWTTw352RhhNZW8T/VAqN9dpS3hv8qPdqq2MPZbQyeSdF5sv9SP4Kdab1uMxqhU8wwf Pe4aA+LMM7mOg1OOmSqn+je0erLvhZl0IoodYYyatg= X-Received: by 2002:ad4:5dc2:0:b0:8ce:d302:f069 with SMTP id 6a1803df08f44-8d32b47b28emr185934816d6.3.1781452577762; Sun, 14 Jun 2026 08:56:17 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8d30522cbeasm82008446d6.44.2026.06.14.08.56.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 14 Jun 2026 08:56:17 -0700 (PDT) From: Michael Bommarito To: Hans Verkuil , Mauro Carvalho Chehab , Sakari Ailus , Nicolas Dufresne Cc: Laurent Pinchart , Benjamin Gaignard , Detlev Casanova , Ezequiel Garcia , Yunfei Dong , Jonas Karlman , Heiko Stuebner , Kees Cook , linux-media@vger.kernel.org, linux-rockchip@lists.infradead.org, linux-mediatek@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH v2 3/6] media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity Date: Sun, 14 Jun 2026 11:56:05 -0400 Message-ID: <20260614155609.3107600-4-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260614155609.3107600-1-michael.bommarito@gmail.com> References: <20260614155609.3107600-1-michael.bommarito@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 7bit prepare_tile_info_buffer() writes one entry per tile into the tile_sizes DMA buffer, sized for a grid equal to the PPS uAPI array capacity. Bound the loop to that capacity so the writes stay inside the buffer. Fixes: cb5dd5a0fa51 ("media: hantro: Introduce G2/HEVC decoder") Signed-off-by: Michael Bommarito Assisted-by: Claude:claude-opus-4-8 --- drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c b/drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c index e8c2e83379def..94fbd79885aa5 100644 --- a/drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c +++ b/drivers/media/platform/verisilicon/hantro_g2_hevc_dec.c @@ -22,6 +22,12 @@ static void prepare_tile_info_buffer(struct hantro_ctx *ctx) bool tiles_enabled, uniform_spacing; u32 no_chroma = 0; + /* Bound the loops to the tile_sizes buffer capacity. */ + num_tile_cols = min_t(unsigned int, num_tile_cols, + ARRAY_SIZE(pps->column_width_minus1)); + num_tile_rows = min_t(unsigned int, num_tile_rows, + ARRAY_SIZE(pps->row_height_minus1)); + tiles_enabled = !!(pps->flags & V4L2_HEVC_PPS_FLAG_TILES_ENABLED); uniform_spacing = !!(pps->flags & V4L2_HEVC_PPS_FLAG_UNIFORM_SPACING); -- 2.53.0