On Sat Aug 15 22:56:36 2026 +0800, Junrui Luo wrote:
> A capture format whose width or height is one more than a multiple of 16
> makes the FWHT codec write one 8x8 block row, or column, past the end of
> the capture plane, and read the same block out of the reference frame for
> P-coded frames.
>
> vic_round_dim() is documented to round a frame dimension up so that both
> the luma and the chroma plane end up a multiple of 8, but it only rounds
> the chroma plane:
>
> round_up((dim) / (div), 8) * (div)
>
> For div == 2 the result is a multiple of 16 in every case but one: when
> dim % 16 == 1, dim / div is already a multiple of 8 and the macro returns
> dim - 1. encode_plane() and decode_plane() round the same dimension with
> round_up(dim, 8), which yields dim + 7 -- one block more than the coded
> dimension that sized the buffer.
>
> On a KASAN-enabled kernel, a 641x360 YUYV P-frame triggers:
>
> BUG: KASAN: slab-out-of-bounds in add_deltas+0x450/0xcc0
> Read of size 1 at addr ffff888009070800 by task trigger_bin/70
>
> Call Trace:
> add_deltas+0x450/0xcc0
> decode_plane+0x1916/0x3390
> fwht_decode_frame+0x173/0x620
> v4l2_fwht_decode+0x751/0x1120
> device_run+0x6bb/0x1850
>
> Round the dimension itself up to a multiple of 8 * div. The rounding
> changes only for div == 2 and dim % 16 == 1, and MAX_WIDTH and MAX_HEIGHT
> are both multiples of 16, so the rounded value still fits the advertised
> limits.
>
> Fixes: 3b15f68e19c2 ("media: vicodec: Add support for resolution change
> event.")
> Reported-by: Yuhao Jiang <[email protected]>
> Assisted-by: Claude:claude-opus-5
> Cc: [email protected]
> Signed-off-by: Junrui Luo <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/test-drivers/vicodec/codec-fwht.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
---
diff --git a/drivers/media/test-drivers/vicodec/codec-fwht.h
b/drivers/media/test-drivers/vicodec/codec-fwht.h
index 0eab24020e9e..4b4d39031089 100644
--- a/drivers/media/test-drivers/vicodec/codec-fwht.h
+++ b/drivers/media/test-drivers/vicodec/codec-fwht.h
@@ -61,7 +61,7 @@
* both luma and chroma components resolutions are rounded up to
* a multiple of 8
*/
-#define vic_round_dim(dim, div) (round_up((dim) / (div), 8) * (div))
+#define vic_round_dim(dim, div) round_up(dim, 8 * (div))
struct fwht_cframe_hdr {
u32 magic1;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]