[{"id":13318,"web_url":"https://patchwork.libcamera.org/comment/13318/","msgid":"<fa4996cb-8054-584b-51b4-c82bced07803@ideasonboard.com>","date":"2020-10-21T09:58:46","subject":"Re: [libcamera-devel] [PATCH 1/2] libcamera: v4l2_videodevice:\n\tCheck plane count when setting format","submitter":{"id":4,"url":"https://patchwork.libcamera.org/api/people/4/","name":"Kieran Bingham","email":"kieran.bingham@ideasonboard.com"},"content":"Hi Laurent,\n\nOn 21/10/2020 03:47, Laurent Pinchart wrote:\n> When setting (or trying) a format with a multiplanar device, the\n> V4L2VideoDevice::trySetFormatMeta() function iterates over all planes\n> available in the V4L2DeviceFormat structure. The caller is responsible\n> for setting the plane count, and failure to do so properly may result in\n> memory corruption. This can lead to a crash way after the function\n> returns, making the problem difficult to debug.\n> \n> As the issue is caused by a bug in the caller, use an assertion to catch\n> it.\n> \n> Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>\n\nSounds reasonable to me, I wonder if you've hit this ...\n\nReviewed-by: Kieran Bingham <kieran.bingham@ideasonboard.com>\n\n> ---\n>  src/libcamera/v4l2_videodevice.cpp | 2 ++\n>  1 file changed, 2 insertions(+)\n> \n> diff --git a/src/libcamera/v4l2_videodevice.cpp b/src/libcamera/v4l2_videodevice.cpp\n> index 16162e1edba3..3ba9e5ba134a 100644\n> --- a/src/libcamera/v4l2_videodevice.cpp\n> +++ b/src/libcamera/v4l2_videodevice.cpp\n> @@ -861,6 +861,8 @@ int V4L2VideoDevice::trySetFormatMultiplane(V4L2DeviceFormat *format, bool set)\n>  \tpix->num_planes = format->planesCount;\n>  \tpix->field = V4L2_FIELD_NONE;\n>  \n> +\tASSERT(pix->num_planes <= ARRAY_SIZE(pix->plane_fmt));\n> +\n>  \tfor (unsigned int i = 0; i < pix->num_planes; ++i) {\n>  \t\tpix->plane_fmt[i].bytesperline = format->planes[i].bpl;\n>  \t\tpix->plane_fmt[i].sizeimage = format->planes[i].size;\n>","headers":{"Return-Path":"<libcamera-devel-bounces@lists.libcamera.org>","X-Original-To":"parsemail@patchwork.libcamera.org","Delivered-To":"parsemail@patchwork.libcamera.org","Received":["from lancelot.ideasonboard.com (lancelot.ideasonboard.com\n\t[92.243.16.209])\n\tby patchwork.libcamera.org (Postfix) with ESMTPS id 496B9C3D3C\n\tfor <parsemail@patchwork.libcamera.org>;\n\tWed, 21 Oct 2020 09:58:51 +0000 (UTC)","from lancelot.ideasonboard.com (localhost [IPv6:::1])\n\tby lancelot.ideasonboard.com (Postfix) with ESMTP id CF1CE60361;\n\tWed, 21 Oct 2020 11:58:50 +0200 (CEST)","from perceval.ideasonboard.com (perceval.ideasonboard.com\n\t[IPv6:2001:4b98:dc2:55:216:3eff:fef7:d647])\n\tby lancelot.ideasonboard.com (Postfix) with ESMTPS id C76A860352\n\tfor <libcamera-devel@lists.libcamera.org>;\n\tWed, 21 Oct 2020 11:58:49 +0200 (CEST)","from [192.168.0.20]\n\t(cpc89244-aztw30-2-0-cust3082.18-1.cable.virginm.net [86.31.172.11])\n\tby perceval.ideasonboard.com (Postfix) with ESMTPSA id 9E8BD92;\n\tWed, 21 Oct 2020 11:58:48 +0200 (CEST)"],"Authentication-Results":"lancelot.ideasonboard.com;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=ideasonboard.com header.i=@ideasonboard.com\n\theader.b=\"TizsXTBg\"; dkim-atps=neutral","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/simple; d=ideasonboard.com;\n\ts=mail; t=1603274329;\n\tbh=fn7bsto3eAD3FLQoTFQopATZeuTLTKY06CoGX1GH0N4=;\n\th=Reply-To:Subject:To:References:From:Date:In-Reply-To:From;\n\tb=TizsXTBgbzkqBpX02xmc9SvAPguuLGAfZWvzNQx7SXgcNfKA1og3KLO3theMcXGho\n\t/zzKp6vGaBdaXjxzk3FAh/rzDN6nUpteL/G/kJJTdhbXvmGqsST5+yV8UgeeSHVLiA\n\tCLXosdkhiwo39vxmLxPb0jzscKapyyxEuBrY9/v8=","To":"Laurent Pinchart <laurent.pinchart@ideasonboard.com>,\n\tlibcamera-devel@lists.libcamera.org","References":"<20201021024744.19047-1-laurent.pinchart@ideasonboard.com>","From":"Kieran Bingham <kieran.bingham@ideasonboard.com>","Autocrypt":"addr=kieran.bingham@ideasonboard.com; keydata=\n\tmQINBFYE/WYBEACs1PwjMD9rgCu1hlIiUA1AXR4rv2v+BCLUq//vrX5S5bjzxKAryRf0uHat\n\tV/zwz6hiDrZuHUACDB7X8OaQcwhLaVlq6byfoBr25+hbZG7G3+5EUl9cQ7dQEdvNj6V6y/SC\n\trRanWfelwQThCHckbobWiQJfK9n7rYNcPMq9B8e9F020LFH7Kj6YmO95ewJGgLm+idg1Kb3C\n\tpotzWkXc1xmPzcQ1fvQMOfMwdS+4SNw4rY9f07Xb2K99rjMwZVDgESKIzhsDB5GY465sCsiQ\n\tcSAZRxqE49RTBq2+EQsbrQpIc8XiffAB8qexh5/QPzCmR4kJgCGeHIXBtgRj+nIkCJPZvZtf\n\tKr2EAbc6tgg6DkAEHJb+1okosV09+0+TXywYvtEop/WUOWQ+zo+Y/OBd+8Ptgt1pDRyOBzL8\n\tRXa8ZqRf0Mwg75D+dKntZeJHzPRJyrlfQokngAAs4PaFt6UfS+ypMAF37T6CeDArQC41V3ko\n\tlPn1yMsVD0p+6i3DPvA/GPIksDC4owjnzVX9kM8Zc5Cx+XoAN0w5Eqo4t6qEVbuettxx55gq\n\t8K8FieAjgjMSxngo/HST8TpFeqI5nVeq0/lqtBRQKumuIqDg+Bkr4L1V/PSB6XgQcOdhtd36\n\tOe9X9dXB8YSNt7VjOcO7BTmFn/Z8r92mSAfHXpb07YJWJosQOQARAQABtDBLaWVyYW4gQmlu\n\tZ2hhbSA8a2llcmFuLmJpbmdoYW1AaWRlYXNvbmJvYXJkLmNvbT6JAlcEEwEKAEECGwMFCwkI\n\tBwIGFQgJCgsCBBYCAwECHgECF4ACGQEWIQSQLdeYP70o/eNy1HqhHkZyEKRh/QUCXWTtygUJ\n\tCyJXZAAKCRChHkZyEKRh/f8dEACTDsbLN2nioNZMwyLuQRUAFcXNolDX48xcUXsWS2QjxaPm\n\tVsJx8Uy8aYkS85mdPBh0C83OovQR/OVbr8AxhGvYqBs3nQvbWuTl/+4od7DfK2VZOoKBAu5S\n\tQK2FYuUcikDqYcFWJ8DQnubxfE8dvzojHEkXw0sA4igINHDDFX3HJGZtLio+WpEFQtCbfTAG\n\tYZslasz1YZRbwEdSsmO3/kqy5eMnczlm8a21A3fKUo3g8oAZEFM+f4DUNzqIltg31OAB/kZS\n\tenKZQ/SWC8PmLg/ZXBrReYakxXtkP6w3FwMlzOlhGxqhIRNiAJfXJBaRhuUWzPOpEDE9q5YJ\n\tBmqQL2WJm1VSNNVxbXJHpaWMH1sA2R00vmvRrPXGwyIO0IPYeUYQa3gsy6k+En/aMQJd27dp\n\taScf9am9PFICPY5T4ppneeJLif2lyLojo0mcHOV+uyrds9XkLpp14GfTkeKPdPMrLLTsHRfH\n\tfA4I4OBpRrEPiGIZB/0im98MkGY/Mu6qxeZmYLCcgD6qz4idOvfgVOrNh+aA8HzIVR+RMW8H\n\tQGBN9f0E3kfwxuhl3omo6V7lDw8XOdmuWZNC9zPq1UfryVHANYbLGz9KJ4Aw6M+OgBC2JpkD\n\thXMdHUkC+d20dwXrwHTlrJi1YNp6rBc+xald3wsUPOZ5z8moTHUX/uPA/qhGsbkCDQRWBP1m\n\tARAAzijkb+Sau4hAncr1JjOY+KyFEdUNxRy+hqTJdJfaYihxyaj0Ee0P0zEi35CbE6lgU0Uz\n\ttih9fiUbSV3wfsWqg1Ut3/5rTKu7kLFp15kF7eqvV4uezXRD3Qu4yjv/rMmEJbbD4cTvGCYI\n\td6MDC417f7vK3hCbCVIZSp3GXxyC1LU+UQr3fFcOyCwmP9vDUR9JV0BSqHHxRDdpUXE26Dk6\n\tmhf0V1YkspE5St814ETXpEus2urZE5yJIUROlWPIL+hm3NEWfAP06vsQUyLvr/GtbOT79vXl\n\tEn1aulcYyu20dRRxhkQ6iILaURcxIAVJJKPi8dsoMnS8pB0QW12AHWuirPF0g6DiuUfPmrA5\n\tPKe56IGlpkjc8cO51lIxHkWTpCMWigRdPDexKX+Sb+W9QWK/0JjIc4t3KBaiG8O4yRX8ml2R\n\t+rxfAVKM6V769P/hWoRGdgUMgYHFpHGSgEt80OKK5HeUPy2cngDUXzwrqiM5Sz6Od0qw5pCk\n\tNlXqI0W/who0iSVM+8+RmyY0OEkxEcci7rRLsGnM15B5PjLJjh1f2ULYkv8s4SnDwMZ/kE04\n\t/UqCMK/KnX8pwXEMCjz0h6qWNpGwJ0/tYIgQJZh6bqkvBrDogAvuhf60Sogw+mH8b+PBlx1L\n\toeTK396wc+4c3BfiC6pNtUS5GpsPMMjYMk7kVvEAEQEAAYkCPAQYAQoAJgIbDBYhBJAt15g/\n\tvSj943LUeqEeRnIQpGH9BQJdizzIBQkLSKZiAAoJEKEeRnIQpGH9eYgQAJpjaWNgqNOnMTmD\n\tMJggbwjIotypzIXfhHNCeTkG7+qCDlSaBPclcPGYrTwCt0YWPU2TgGgJrVhYT20ierN8LUvj\n\t6qOPTd+Uk7NFzL65qkh80ZKNBFddx1AabQpSVQKbdcLb8OFs85kuSvFdgqZwgxA1vl4TFhNz\n\tPZ79NAmXLackAx3sOVFhk4WQaKRshCB7cSl+RIng5S/ThOBlwNlcKG7j7W2MC06BlTbdEkUp\n\tECzuuRBv8wX4OQl+hbWbB/VKIx5HKlLu1eypen/5lNVzSqMMIYkkZcjV2SWQyUGxSwq0O/sx\n\tS0A8/atCHUXOboUsn54qdxrVDaK+6jIAuo8JiRWctP16KjzUM7MO0/+4zllM8EY57rXrj48j\n\tsbEYX0YQnzaj+jO6kJtoZsIaYR7rMMq9aUAjyiaEZpmP1qF/2sYenDx0Fg2BSlLvLvXM0vU8\n\tpQk3kgDu7kb/7PRYrZvBsr21EIQoIjXbZxDz/o7z95frkP71EaICttZ6k9q5oxxA5WC6sTXc\n\tMW8zs8avFNuA9VpXt0YupJd2ijtZy2mpZNG02fFVXhIn4G807G7+9mhuC4XG5rKlBBUXTvPU\n\tAfYnB4JBDLmLzBFavQfvonSfbitgXwCG3vS+9HEwAjU30Bar1PEOmIbiAoMzuKeRm2LVpmq4\n\tWZw01QYHU/GUV/zHJSFk","Organization":"Ideas on Board","Message-ID":"<fa4996cb-8054-584b-51b4-c82bced07803@ideasonboard.com>","Date":"Wed, 21 Oct 2020 10:58:46 +0100","User-Agent":"Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101\n\tThunderbird/68.10.0","MIME-Version":"1.0","In-Reply-To":"<20201021024744.19047-1-laurent.pinchart@ideasonboard.com>","Content-Language":"en-GB","Subject":"Re: [libcamera-devel] [PATCH 1/2] libcamera: v4l2_videodevice:\n\tCheck plane count when setting format","X-BeenThere":"libcamera-devel@lists.libcamera.org","X-Mailman-Version":"2.1.29","Precedence":"list","List-Id":"<libcamera-devel.lists.libcamera.org>","List-Unsubscribe":"<https://lists.libcamera.org/options/libcamera-devel>,\n\t<mailto:libcamera-devel-request@lists.libcamera.org?subject=unsubscribe>","List-Archive":"<https://lists.libcamera.org/pipermail/libcamera-devel/>","List-Post":"<mailto:libcamera-devel@lists.libcamera.org>","List-Help":"<mailto:libcamera-devel-request@lists.libcamera.org?subject=help>","List-Subscribe":"<https://lists.libcamera.org/listinfo/libcamera-devel>,\n\t<mailto:libcamera-devel-request@lists.libcamera.org?subject=subscribe>","Reply-To":"kieran.bingham@ideasonboard.com","Content-Type":"text/plain; charset=\"us-ascii\"","Content-Transfer-Encoding":"7bit","Errors-To":"libcamera-devel-bounces@lists.libcamera.org","Sender":"\"libcamera-devel\" <libcamera-devel-bounces@lists.libcamera.org>"}},{"id":13348,"web_url":"https://patchwork.libcamera.org/comment/13348/","msgid":"<20201021132956.GA2158081@oden.dyn.berto.se>","date":"2020-10-21T13:29:56","subject":"Re: [libcamera-devel] [PATCH 1/2] libcamera: v4l2_videodevice:\n\tCheck plane count when setting format","submitter":{"id":5,"url":"https://patchwork.libcamera.org/api/people/5/","name":"Niklas Söderlund","email":"niklas.soderlund@ragnatech.se"},"content":"Hi Laurent,\n\nThanks for your work.\n\nOn 2020-10-21 05:47:43 +0300, Laurent Pinchart wrote:\n> When setting (or trying) a format with a multiplanar device, the\n> V4L2VideoDevice::trySetFormatMeta() function iterates over all planes\n> available in the V4L2DeviceFormat structure. The caller is responsible\n> for setting the plane count, and failure to do so properly may result in\n> memory corruption. This can lead to a crash way after the function\n> returns, making the problem difficult to debug.\n> \n> As the issue is caused by a bug in the caller, use an assertion to catch\n> it.\n> \n> Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>\n\nReviewed-by: Niklas Söderlund <niklas.soderlund@ragnatech.se>\n\n> ---\n>  src/libcamera/v4l2_videodevice.cpp | 2 ++\n>  1 file changed, 2 insertions(+)\n> \n> diff --git a/src/libcamera/v4l2_videodevice.cpp b/src/libcamera/v4l2_videodevice.cpp\n> index 16162e1edba3..3ba9e5ba134a 100644\n> --- a/src/libcamera/v4l2_videodevice.cpp\n> +++ b/src/libcamera/v4l2_videodevice.cpp\n> @@ -861,6 +861,8 @@ int V4L2VideoDevice::trySetFormatMultiplane(V4L2DeviceFormat *format, bool set)\n>  \tpix->num_planes = format->planesCount;\n>  \tpix->field = V4L2_FIELD_NONE;\n>  \n> +\tASSERT(pix->num_planes <= ARRAY_SIZE(pix->plane_fmt));\n> +\n>  \tfor (unsigned int i = 0; i < pix->num_planes; ++i) {\n>  \t\tpix->plane_fmt[i].bytesperline = format->planes[i].bpl;\n>  \t\tpix->plane_fmt[i].sizeimage = format->planes[i].size;\n> -- \n> Regards,\n> \n> Laurent Pinchart\n> \n> _______________________________________________\n> libcamera-devel mailing list\n> libcamera-devel@lists.libcamera.org\n> https://lists.libcamera.org/listinfo/libcamera-devel","headers":{"Return-Path":"<libcamera-devel-bounces@lists.libcamera.org>","X-Original-To":"parsemail@patchwork.libcamera.org","Delivered-To":"parsemail@patchwork.libcamera.org","Received":["from lancelot.ideasonboard.com (lancelot.ideasonboard.com\n\t[92.243.16.209])\n\tby patchwork.libcamera.org (Postfix) with ESMTPS id 2E33FBDB13\n\tfor <parsemail@patchwork.libcamera.org>;\n\tWed, 21 Oct 2020 13:30:01 +0000 (UTC)","from lancelot.ideasonboard.com (localhost [IPv6:::1])\n\tby lancelot.ideasonboard.com (Postfix) with ESMTP id 9D67961DDB;\n\tWed, 21 Oct 2020 15:30:00 +0200 (CEST)","from mail-lf1-x141.google.com (mail-lf1-x141.google.com\n\t[IPv6:2a00:1450:4864:20::141])\n\tby lancelot.ideasonboard.com (Postfix) with ESMTPS id EB39B61D7F\n\tfor <libcamera-devel@lists.libcamera.org>;\n\tWed, 21 Oct 2020 15:29:58 +0200 (CEST)","by mail-lf1-x141.google.com with SMTP id h6so3157161lfj.3\n\tfor <libcamera-devel@lists.libcamera.org>;\n\tWed, 21 Oct 2020 06:29:58 -0700 (PDT)","from localhost (h-209-203.A463.priv.bahnhof.se. [155.4.209.203])\n\tby smtp.gmail.com with ESMTPSA id\n\tg3sm422639ljl.42.2020.10.21.06.29.57\n\t(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n\tWed, 21 Oct 2020 06:29:57 -0700 (PDT)"],"Authentication-Results":"lancelot.ideasonboard.com;\n\tdkim=fail reason=\"signature verification failed\" (2048-bit key;\n\tunprotected) header.d=ragnatech-se.20150623.gappssmtp.com\n\theader.i=@ragnatech-se.20150623.gappssmtp.com\n\theader.b=\"umNq1LaA\"; dkim-atps=neutral","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=ragnatech-se.20150623.gappssmtp.com; s=20150623;\n\th=date:from:to:cc:subject:message-id:references:mime-version\n\t:content-disposition:content-transfer-encoding:in-reply-to;\n\tbh=zx25EDaLFVKoqI0B1259CPWtQuBbw95L+cbXQfjSdNo=;\n\tb=umNq1LaAT2j9LLjPdrojW8xRk4bmPGniDRKs+ihw4qx4Pnhm9L51RsLaDmn47VxUMG\n\t9Qf5qh3RNhgiJssOa5eeW0n4vAqMdro5ftbQniaLYkgwW7qS6zX5YgLpFo/bdOzurTx3\n\tTv2TyCwEw1DvJSyaD4fHpNEI20YookAXEEMobF5WTAYV88eTWfuoxEQFSCwttN0/NpkR\n\tNptSxG0XlHt1fwfW5Pih4i+wPktVYC1Z1aeN2TTwdJo8fMcWKy8Wgcjn6QKsIwycuvCN\n\tfdaxmI8ntBQzhmmnoliFmYkw/CaAdFFEN6J9QO7dOcu3Nb8L9CNn+EYBRKTRyC/wxceQ\n\tHkkA==","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n\td=1e100.net; s=20161025;\n\th=x-gm-message-state:date:from:to:cc:subject:message-id:references\n\t:mime-version:content-disposition:content-transfer-encoding\n\t:in-reply-to;\n\tbh=zx25EDaLFVKoqI0B1259CPWtQuBbw95L+cbXQfjSdNo=;\n\tb=nYzkh8uY5jR3JigfKBcEycl6WVr6erFXAFLgXTemcHkzw+9hSNW4dF1bRj30POtuTg\n\t2u2BLntsht1Xa4kVMrKQ1c7xDNHSnkfSoaCPPOegHsQqn8EwYaZMVSVsjlPjzqNPUIYh\n\tAGj2QVgt9Yomb1Q51R97WDV13XWZPgk5NeHN+3gwOJOB+fvGd1xwjbueTGjo36+wD8bT\n\t9FSFGu80fqgjm5eSzAL/fJ3NV0iOHSKSv4nBze61CBK3XMUKcW7XbPkir5L5Hd8Sp+vq\n\tLSlMfL+VrlGIjuf3MLqJsfqELcOvnZNZjR72qmUwN2ESmzBk46uLhXDVZzp5nU4RGOAj\n\tsJQg==","X-Gm-Message-State":"AOAM531Q0qGBOjZYdj9C0rHJ0AEN+dauZS3dtPXyUUzTFtcjvHo14cTY\n\tExsOKMAZBGiK9El8kr9CW10zIw==","X-Google-Smtp-Source":"ABdhPJyRPG0WTEcfj573DFxHdoCUH3QQRcc37O5ja+opZDA8bTgEUgvmYZEoBEsEVJKZzW401HdQrQ==","X-Received":"by 2002:a05:6512:2101:: with SMTP id\n\tq1mr1351049lfr.187.1603286998329; \n\tWed, 21 Oct 2020 06:29:58 -0700 (PDT)","Date":"Wed, 21 Oct 2020 15:29:56 +0200","From":"Niklas =?iso-8859-1?q?S=F6derlund?= <niklas.soderlund@ragnatech.se>","To":"Laurent Pinchart <laurent.pinchart@ideasonboard.com>","Message-ID":"<20201021132956.GA2158081@oden.dyn.berto.se>","References":"<20201021024744.19047-1-laurent.pinchart@ideasonboard.com>","MIME-Version":"1.0","Content-Disposition":"inline","In-Reply-To":"<20201021024744.19047-1-laurent.pinchart@ideasonboard.com>","Subject":"Re: [libcamera-devel] [PATCH 1/2] libcamera: v4l2_videodevice:\n\tCheck plane count when setting format","X-BeenThere":"libcamera-devel@lists.libcamera.org","X-Mailman-Version":"2.1.29","Precedence":"list","List-Id":"<libcamera-devel.lists.libcamera.org>","List-Unsubscribe":"<https://lists.libcamera.org/options/libcamera-devel>,\n\t<mailto:libcamera-devel-request@lists.libcamera.org?subject=unsubscribe>","List-Archive":"<https://lists.libcamera.org/pipermail/libcamera-devel/>","List-Post":"<mailto:libcamera-devel@lists.libcamera.org>","List-Help":"<mailto:libcamera-devel-request@lists.libcamera.org?subject=help>","List-Subscribe":"<https://lists.libcamera.org/listinfo/libcamera-devel>,\n\t<mailto:libcamera-devel-request@lists.libcamera.org?subject=subscribe>","Cc":"libcamera-devel@lists.libcamera.org","Content-Type":"text/plain; charset=\"iso-8859-1\"","Content-Transfer-Encoding":"quoted-printable","Errors-To":"libcamera-devel-bounces@lists.libcamera.org","Sender":"\"libcamera-devel\" <libcamera-devel-bounces@lists.libcamera.org>"}},{"id":13360,"web_url":"https://patchwork.libcamera.org/comment/13360/","msgid":"<20201021143729.GA3942@pendragon.ideasonboard.com>","date":"2020-10-21T14:37:29","subject":"Re: [libcamera-devel] [PATCH 1/2] libcamera: v4l2_videodevice:\n\tCheck plane count when setting format","submitter":{"id":2,"url":"https://patchwork.libcamera.org/api/people/2/","name":"Laurent Pinchart","email":"laurent.pinchart@ideasonboard.com"},"content":"Hi Kieran,\n\nOn Wed, Oct 21, 2020 at 10:58:46AM +0100, Kieran Bingham wrote:\n> On 21/10/2020 03:47, Laurent Pinchart wrote:\n> > When setting (or trying) a format with a multiplanar device, the\n> > V4L2VideoDevice::trySetFormatMeta() function iterates over all planes\n> > available in the V4L2DeviceFormat structure. The caller is responsible\n> > for setting the plane count, and failure to do so properly may result in\n> > memory corruption. This can lead to a crash way after the function\n> > returns, making the problem difficult to debug.\n> > \n> > As the issue is caused by a bug in the caller, use an assertion to catch\n> > it.\n> > \n> > Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>\n> \n> Sounds reasonable to me, I wonder if you've hit this ...\n\nHow did you guess ? :-) It lead to a corrupted stack, so gdb was not\nhelpful. I wanted to make sure the next person to hit this issue won't\nhave a too hard time.\n\n> Reviewed-by: Kieran Bingham <kieran.bingham@ideasonboard.com>\n> \n> > ---\n> >  src/libcamera/v4l2_videodevice.cpp | 2 ++\n> >  1 file changed, 2 insertions(+)\n> > \n> > diff --git a/src/libcamera/v4l2_videodevice.cpp b/src/libcamera/v4l2_videodevice.cpp\n> > index 16162e1edba3..3ba9e5ba134a 100644\n> > --- a/src/libcamera/v4l2_videodevice.cpp\n> > +++ b/src/libcamera/v4l2_videodevice.cpp\n> > @@ -861,6 +861,8 @@ int V4L2VideoDevice::trySetFormatMultiplane(V4L2DeviceFormat *format, bool set)\n> >  \tpix->num_planes = format->planesCount;\n> >  \tpix->field = V4L2_FIELD_NONE;\n> >  \n> > +\tASSERT(pix->num_planes <= ARRAY_SIZE(pix->plane_fmt));\n> > +\n> >  \tfor (unsigned int i = 0; i < pix->num_planes; ++i) {\n> >  \t\tpix->plane_fmt[i].bytesperline = format->planes[i].bpl;\n> >  \t\tpix->plane_fmt[i].sizeimage = format->planes[i].size;","headers":{"Return-Path":"<libcamera-devel-bounces@lists.libcamera.org>","X-Original-To":"parsemail@patchwork.libcamera.org","Delivered-To":"parsemail@patchwork.libcamera.org","Received":["from lancelot.ideasonboard.com (lancelot.ideasonboard.com\n\t[92.243.16.209])\n\tby patchwork.libcamera.org (Postfix) with ESMTPS id C63CAC3D3C\n\tfor <parsemail@patchwork.libcamera.org>;\n\tWed, 21 Oct 2020 14:38:16 +0000 (UTC)","from lancelot.ideasonboard.com (localhost [IPv6:::1])\n\tby lancelot.ideasonboard.com (Postfix) with ESMTP id 9295161E10;\n\tWed, 21 Oct 2020 16:38:16 +0200 (CEST)","from perceval.ideasonboard.com (perceval.ideasonboard.com\n\t[IPv6:2001:4b98:dc2:55:216:3eff:fef7:d647])\n\tby lancelot.ideasonboard.com (Postfix) with ESMTPS id 86ED161DDB\n\tfor <libcamera-devel@lists.libcamera.org>;\n\tWed, 21 Oct 2020 16:38:15 +0200 (CEST)","from pendragon.ideasonboard.com (62-78-145-57.bb.dnainternet.fi\n\t[62.78.145.57])\n\tby perceval.ideasonboard.com (Postfix) with ESMTPSA id 15AC792;\n\tWed, 21 Oct 2020 16:38:15 +0200 (CEST)"],"Authentication-Results":"lancelot.ideasonboard.com;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n\tunprotected) header.d=ideasonboard.com header.i=@ideasonboard.com\n\theader.b=\"HOiCWk3c\"; dkim-atps=neutral","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/simple; d=ideasonboard.com;\n\ts=mail; t=1603291095;\n\tbh=L7I6D/Q81HmN/EIDZs654U2MK8RsEIR2uSnRp6SObo0=;\n\th=Date:From:To:Cc:Subject:References:In-Reply-To:From;\n\tb=HOiCWk3ca/gViZD0N/UQ1u9r6ujDbyXCmPDWMKNFVzirHYsLI+/YOB6zFFMEdrc7M\n\t+uXRyn5yg5v345JEAu3nzXTOvbk7yDDTxXRRjUNLyau1M6fD6G0MIKfSiki3qUo4Tl\n\tRu8NZ1h52rngsr0XXRRS0ucrxAXSeFew9vA3M5vU=","Date":"Wed, 21 Oct 2020 17:37:29 +0300","From":"Laurent Pinchart <laurent.pinchart@ideasonboard.com>","To":"Kieran Bingham <kieran.bingham@ideasonboard.com>","Message-ID":"<20201021143729.GA3942@pendragon.ideasonboard.com>","References":"<20201021024744.19047-1-laurent.pinchart@ideasonboard.com>\n\t<fa4996cb-8054-584b-51b4-c82bced07803@ideasonboard.com>","MIME-Version":"1.0","Content-Disposition":"inline","In-Reply-To":"<fa4996cb-8054-584b-51b4-c82bced07803@ideasonboard.com>","Subject":"Re: [libcamera-devel] [PATCH 1/2] libcamera: v4l2_videodevice:\n\tCheck plane count when setting format","X-BeenThere":"libcamera-devel@lists.libcamera.org","X-Mailman-Version":"2.1.29","Precedence":"list","List-Id":"<libcamera-devel.lists.libcamera.org>","List-Unsubscribe":"<https://lists.libcamera.org/options/libcamera-devel>,\n\t<mailto:libcamera-devel-request@lists.libcamera.org?subject=unsubscribe>","List-Archive":"<https://lists.libcamera.org/pipermail/libcamera-devel/>","List-Post":"<mailto:libcamera-devel@lists.libcamera.org>","List-Help":"<mailto:libcamera-devel-request@lists.libcamera.org?subject=help>","List-Subscribe":"<https://lists.libcamera.org/listinfo/libcamera-devel>,\n\t<mailto:libcamera-devel-request@lists.libcamera.org?subject=subscribe>","Cc":"libcamera-devel@lists.libcamera.org","Content-Type":"text/plain; charset=\"us-ascii\"","Content-Transfer-Encoding":"7bit","Errors-To":"libcamera-devel-bounces@lists.libcamera.org","Sender":"\"libcamera-devel\" <libcamera-devel-bounces@lists.libcamera.org>"}}]