On Mon Aug 3 15:29:36 2026 +0800, Junrui Luo wrote:
> job_ready() only honours the is_header_valid() verdict when
> ctx->comp_has_frame is set, and comp_has_frame is only set once
> comp_size reaches the full frame size. Since the copy is clamped to
> ctx->comp_max_size, a header advertising a larger size leaves comp_size
> stuck at comp_max_size, so comp_has_frame stays false and the failed
> validation is discarded.
> 
> Control then falls into the resolution change branch, which calls
> update_capture_data_from_header(). That function re-derives info via
> info_from_header(), assigns it to q_dst->info and dereferences it as
> q_dst->info->sizeimage_mult, with no NULL check of its own.
> is_header_valid() does check that same info_from_header() result --
> if (!info) return false which is precisely the false verdict
> job_ready() discarded above. info_from_header() returns NULL whenever the
> header flags resolve to no supported pixel format.
> 
> Drop the comp_has_frame conjunct so an invalid header always bails out.
> The resolution change path is unaffected, as it is entered with a valid
> header. Oversized frames are then rejected by device_process(), which
> already returns -EINVAL when comp_frame_size exceeds comp_max_size.
> 
> Fixes: 3b15f68e19c2 ("media: vicodec: Add support for resolution change 
> event.")
> Reported-by: Yuhao Jiang <[email protected]>
> Cc: [email protected]
> Signed-off-by: Junrui Luo <[email protected]>
> Signed-off-by: Nicolas Dufresne <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/test-drivers/vicodec/vicodec-core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

---

diff --git a/drivers/media/test-drivers/vicodec/vicodec-core.c 
b/drivers/media/test-drivers/vicodec/vicodec-core.c
index 7ea024b14f0e..a6d12ab66a0f 100644
--- a/drivers/media/test-drivers/vicodec/vicodec-core.c
+++ b/drivers/media/test-drivers/vicodec/vicodec-core.c
@@ -654,7 +654,7 @@ restart:
         * if the header is invalid the device_run will just drop the frame
         * with an error
         */
-       if (!is_header_valid(&ctx->state.header) && ctx->comp_has_frame)
+       if (!is_header_valid(&ctx->state.header))
                return 1;
        flags = ntohl(ctx->state.header.flags);
        hdr_width_div = (flags & V4L2_FWHT_FL_CHROMA_FULL_WIDTH) ? 1 : 2;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to