[PATCH] media: mtk-jpeg: drain hardware completion before freeing context
Nicolas Dufresne
nicolas.dufresne at collabora.com
Wed Jul 15 18:06:32 PDT 2026
Le mercredi 08 juillet 2026 à 20:08 +0800, Guangshuo Li a écrit :
> The change referenced by the Fixes tag cancels ctx->jpeg_work before
> freeing the JPEG context from mtk_jpeg_release().
>
> That prevents a queued or running JPEG worker from dereferencing the
> context after it has been freed. However, on multi-core hardware the
> worker can program a hardware instance, arm the per-hardware timeout
> work, store the context in hw_param.curr_ctx and then return while the
> hardware completion is still pending.
>
> In that state cancel_work_sync(&ctx->jpeg_work) can complete even though
> the IRQ handler or timeout work can still recover the same context from
> hw_param.curr_ctx. If userspace closes the file before the hardware
> completion path has run, release can free the context and a later IRQ or
> timeout work can dereference the freed ctx while updating the done queues.
>
> Drain the in-flight hardware completion state associated with the context
> before freeing it.
>
> Fixes: 34c519feef3e ("media: mtk-jpeg: fix use-after-free in release path due to uncancelled work")
> Signed-off-by: Guangshuo Li <lgs201920130244 at gmail.com>
Build failed.
https://gitlab.freedesktop.org/linux-media/users/patchwork/-/jobs/104405577
Nicolas
> ---
> drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c b/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
> index d147ec483081..bc9eea0483ce 100644
> --- a/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
> +++ b/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
> @@ -1202,8 +1202,11 @@ static int mtk_jpeg_release(struct file *file)
> struct mtk_jpeg_dev *jpeg = video_drvdata(file);
> struct mtk_jpeg_ctx *ctx = mtk_jpeg_file_to_ctx(file);
>
> - if (jpeg->variant->jpeg_worker)
> + if (jpeg->variant->jpeg_worker) {
> cancel_work_sync(&ctx->jpeg_work);
> + mtk_jpeg_release_hw(jpeg, ctx);
> + }
> +
> mutex_lock(&jpeg->lock);
> v4l2_m2m_ctx_release(ctx->fh.m2m_ctx);
> v4l2_ctrl_handler_free(&ctx->ctrl_hdl);
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 228 bytes
Desc: This is a digitally signed message part
URL: <http://lists.infradead.org/pipermail/linux-mediatek/attachments/20260715/44b94b8c/attachment.sig>
More information about the Linux-mediatek
mailing list