Re: [PATCH] media: hantro: Harden MPEG-2 control access against NULL

Nicolas Dufresne <[email protected]>
Newsgroups dev.linux.lists.linux-kernel-mentees,org.infradead.lists.linux-rockchip,org.kernel.vger.linux-kernel,org.kernel.vger.linux-media
Organization Collabora Canada
Message-ID <[email protected]>
Le vendredi 31 juillet 2026 à 14:07 +0000, Tharit Tangkijwanichakul a écrit :
> The MPEG-2 sequence and picture controls are validated
> before a job is queued, so hantro_get_ctrl() is not expected to return
> NULL in hantro_g1_mpeg2_dec_run(). The controls are nonetheless
> dereferenced unconditionally.
> 
> Harden the invariant by checking the sequence and picture controls with
> WARN_ON().
> 
> Found by code inspection.
> 
> Fixes: f329e21e9dad ("media: uapi: mpeg2: Split sequence and picture parameters")
> Signed-off-by: Tharit Tangkijwanichakul <[email protected]>

Reviewed-by: Nicolas Dufresne <[email protected]>

p.s. this is a bit cosmetic, since only a programming error could lead to that,
once a control is registered, it has a value. But that makes it consistent with
all other use of hantro_get_ctrl() in this driver, which I like.

Nicolas

> ---
> Tested on a Rockchip RK3588 (Rock 5B) board with Fluster:
>   MPEG-2 (MPEG2_VIDEO-MAIN): 23/43, unchanged
> 
>  drivers/media/platform/verisilicon/hantro_g1_mpeg2_dec.c | 5 +++++
>  1 file changed, 5 insertions(+)
> 
> diff --git a/drivers/media/platform/verisilicon/hantro_g1_mpeg2_dec.c b/drivers/media/platform/verisilicon/hantro_g1_mpeg2_dec.c
> index e0d6bd0a6e44..6a942f4b8a2d 100644
> --- a/drivers/media/platform/verisilicon/hantro_g1_mpeg2_dec.c
> +++ b/drivers/media/platform/verisilicon/hantro_g1_mpeg2_dec.c
> @@ -161,8 +161,13 @@ int hantro_g1_mpeg2_dec_run(struct hantro_ctx *ctx)
>  
>  	seq = hantro_get_ctrl(ctx,
>  			      V4L2_CID_STATELESS_MPEG2_SEQUENCE);
> +	if (WARN_ON(!seq))
> +		return -EINVAL;
> +
>  	pic = hantro_get_ctrl(ctx,
>  			      V4L2_CID_STATELESS_MPEG2_PICTURE);
> +	if (WARN_ON(!pic))
> +		return -EINVAL;
>  
>  	reg = G1_REG_DEC_AXI_RD_ID(0) |
>  	      G1_REG_DEC_TIMEOUT_E(1) |
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQTvDVKBFcTDwhoEbxLZQZRRKWBy9AUCannbqAAKCRDZQZRRKWBy
9PC2AQDVAd/UdtrSKkwnBgNQg0ktJGp/cu6WEQ6j3In+PD+JiAEA0ZU60FJ2OJJD
VeT5C82uLSGrdUmNhdpqYU1ti06g2w8=
=2WtK
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.