From: "Jackson.lee" <jackson.lee@chipsnmedia.com>
To: mchehab@kernel.org, hverkuil-cisco@xs4all.nl,
nicolas.dufresne@collabora.com, bob.beckett@collabora.com
Cc: linux-media@vger.kernel.org, linux-kernel@vger.kernel.org,
jackson.lee@chipsnmedia.com, lafley.kim@chipsnmedia.com,
b-brnich@ti.com, hverkuil@xs4all.nl, nas.chung@chipsnmedia.com,
stable@vger.kernel.org
Subject: [PATCH v1 1/9] media: chips-media: wave5: Ensure Atomic Access to src_buf list
Date: Wed, 7 Oct 2026 10:59:38 +0900 [thread overview]
Message-ID: <20261007015946.53-2-jackson.lee@chipsnmedia.com> (raw)
In-Reply-To: <20261007015946.53-1-jackson.lee@chipsnmedia.com>
From: Brandon Brnich <b-brnich@ti.com>
feed_lock was introduced in decoder performance improvements. This was
used to ensure atomic access to the driver's avail_src_buf list during
fill_ringbuffer, streamoff_output, and buf_queue. While this protected
the drivers available src bufs, the v4l2_m2m_src_bufs were not being
protected at driver level. Three separate threads have access to remove
buffers: start_decode fail path, streamoff_output, and finish_decode.
In streamoff_output(), replace the inst_src_buf_remove() loop with
list_for_each_entry_safe(). inst_src_buf_remove() takes feed_lock
itself, so calling it while streamoff_output() holds feed_lock would
take the same mutex twice and deadlock. Unlink each entry with
list_del_init() directly instead.
Fixes: a176ac5e701f ("media: chips-media: wave5: Improve performance of decoder")
Cc: stable@vger.kernel.org
Signed-off-by: Brandon Brnich <b-brnich@ti.com>
Signed-off-by: Jackson Lee <jackson.lee@chipsnmedia.com>
Signed-off-by: Nas Chung <nas.chung@chipsnmedia.com>
---
.../media/platform/chips-media/wave5/wave5-vpu-dec.c | 12 +++++++++---
1 file changed, 9 insertions(+), 3 deletions(-)
diff --git a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
index 6564cf3ec739..6af7d2e9a9f3 100644
--- a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
@@ -198,6 +198,7 @@ static void wave5_handle_src_buffer(struct vpu_instance *inst, dma_addr_t rd_ptr
dev_dbg(inst->dev->dev, "%s: %zu bytes of bitstream was consumed", __func__,
consumed_bytes);
+ mutex_lock(&inst->feed_lock);
v4l2_m2m_for_each_src_buf_safe(m2m_ctx, buf, n) {
struct vb2_v4l2_buffer *src_buf = &buf->vb;
size_t src_size = vb2_get_plane_payload(&src_buf->vb2_buf, 0);
@@ -224,6 +225,7 @@ static void wave5_handle_src_buffer(struct vpu_instance *inst, dma_addr_t rd_ptr
break;
}
}
+ mutex_unlock(&inst->feed_lock);
inst->remaining_consumed_bytes = consumed_bytes;
}
@@ -237,9 +239,11 @@ static int start_decode(struct vpu_instance *inst, u32 *fail_res)
if (ret) {
struct vb2_v4l2_buffer *src_buf;
+ mutex_lock(&inst->feed_lock);
src_buf = v4l2_m2m_src_buf_remove(m2m_ctx);
if (src_buf)
v4l2_m2m_buf_done(src_buf, VB2_BUF_STATE_ERROR);
+ mutex_unlock(&inst->feed_lock);
set_instance_state(inst, VPU_INST_STATE_STOP);
dev_dbg(inst->dev->dev, "%s: pic run failed / finish job", __func__);
@@ -1453,12 +1457,13 @@ static int streamoff_output(struct vb2_queue *q)
dma_addr_t new_rd_ptr;
struct dec_output_info dec_info;
unsigned int i;
- struct vpu_src_buffer *vpu_buf;
+ struct vpu_src_buffer *vpu_buf, *tmp;
inst->retry = false;
inst->queuing_num = 0;
- while ((vpu_buf = inst_src_buf_remove(inst)) != NULL)
- ;
+ mutex_lock(&inst->feed_lock);
+ list_for_each_entry_safe(vpu_buf, tmp, &inst->avail_src_bufs, list)
+ list_del_init(&vpu_buf->list);
for (i = 0; i < v4l2_m2m_num_dst_bufs_ready(m2m_ctx); i++) {
ret = wave5_vpu_dec_set_disp_flag(inst, i);
@@ -1473,6 +1478,7 @@ static int streamoff_output(struct vb2_queue *q)
__func__, buf->vb2_buf.type, buf->vb2_buf.index);
v4l2_m2m_buf_done(buf, VB2_BUF_STATE_ERROR);
}
+ mutex_unlock(&inst->feed_lock);
while (wave5_vpu_dec_get_output_info(inst, &dec_info) == 0) {
if (dec_info.index_frame_display >= 0)
--
2.43.0
next prev parent reply other threads:[~2026-10-07 2:00 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 1:59 [PATCH v1 0/9] fix decoder corruption, stalls and seek issues Jackson.lee
2026-10-07 1:59 ` Jackson.lee [this message]
2026-10-07 1:59 ` [PATCH v1 2/9] media: chips-media: wave5: drop the consumed-byte tally on OUTPUT streamoff Jackson.lee
2026-10-07 1:59 ` [PATCH v1 3/9] media: chips-media: wave5: wait before retrying a refused flush Jackson.lee
2026-10-07 1:59 ` [PATCH v1 4/9] media: chips-media: wave5: ack the interrupt after dispatching it Jackson.lee
2026-10-07 1:59 ` [PATCH v1 5/9] media: chips-media: wave5: finish a job only once Jackson.lee
2026-10-07 1:59 ` [PATCH v1 6/9] media: chips-media: wave5: decode only when the ring holds unclaimed bitstream Jackson.lee
2026-10-07 1:59 ` [PATCH v1 7/9] media: chips-media: wave5: stamp decoded pictures from a decode-order queue Jackson.lee
2026-10-07 1:59 ` [PATCH v1 8/9] media: chips-media: wave5: restore the display flags after a flush Jackson.lee
2026-10-07 1:59 ` [PATCH v1 9/9] media: chips-media: wave5: Stop FrameBuf Reset During Seek Jackson.lee
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007015946.53-2-jackson.lee@chipsnmedia.com \
--to=jackson.lee@chipsnmedia.com \
--cc=b-brnich@ti.com \
--cc=bob.beckett@collabora.com \
--cc=hverkuil-cisco@xs4all.nl \
--cc=hverkuil@xs4all.nl \
--cc=lafley.kim@chipsnmedia.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
--cc=nas.chung@chipsnmedia.com \
--cc=nicolas.dufresne@collabora.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®