Re: [PATCH] media: mtk-mdp: unregister VPU watchdog handler

From: Nicolas Dufresne

Date: Thu Jul 16 2026 - 17:19:02 EST


Le mercredi 08 juillet 2026 à 20:19 +0800, Guangshuo Li a écrit :
> mtk_mdp_probe() registers the MDP reset handler with the VPU watchdog
> code and passes the MDP device as the private data.
>
> The handler is stored in the VPU device and can outlive the MDP probe or
> remove path. If probe fails after the handler has been registered, or if
> the MDP device is removed, the VPU watchdog table can keep a pointer to
> an MDP object that is about to be released. A later VPU watchdog reset can
> then call mtk_mdp_reset_handler() with a stale pointer and dereference
> freed memory while queuing the MDP watchdog work.
>
> Add a VPU watchdog unregister helper and clear the MDP watchdog handler
> from both the probe error path and the remove path before dropping the VPU
> device reference.
>
> Fixes: ee18fc7b0b95 ("media: mtk-mdp: handle vpu_wdt_reg_handler() errors during probe")
> Signed-off-by: Guangshuo Li <lgs201920130244@xxxxxxxxx>
> ---
>  .../media/platform/mediatek/mdp/mtk_mdp_core.c    |  2 ++
>  drivers/media/platform/mediatek/vpu/mtk_vpu.c     | 15 +++++++++++++++
>  drivers/media/platform/mediatek/vpu/mtk_vpu.h     |  2 ++
>  3 files changed, 19 insertions(+)
>
> diff --git a/drivers/media/platform/mediatek/mdp/mtk_mdp_core.c b/drivers/media/platform/mediatek/mdp/mtk_mdp_core.c
> index 8432833814f3..5ccb7aa925d9 100644
> --- a/drivers/media/platform/mediatek/mdp/mtk_mdp_core.c
> +++ b/drivers/media/platform/mediatek/mdp/mtk_mdp_core.c
> @@ -221,6 +221,7 @@ static int mtk_mdp_probe(struct platform_device *pdev)
>   return 0;
>  
>  err_reg_handler:
> + vpu_wdt_unreg_handler(mdp->vpu_dev, VPU_RST_MDP);
>   platform_device_put(mdp->vpu_dev);
>  
>  err_vpu_get_dev:
> @@ -254,6 +255,7 @@ static void mtk_mdp_remove(struct platform_device *pdev)
>  
>   pm_runtime_disable(&pdev->dev);
>   vb2_dma_contig_clear_max_seg_size(&pdev->dev);
> + vpu_wdt_unreg_handler(mdp->vpu_dev, VPU_RST_MDP);
>   platform_device_put(mdp->vpu_dev);
>   mtk_mdp_unregister_m2m_device(mdp);
>   v4l2_device_unregister(&mdp->v4l2_dev);
> diff --git a/drivers/media/platform/mediatek/vpu/mtk_vpu.c b/drivers/media/platform/mediatek/vpu/mtk_vpu.c
> index 8d8319f0cd22..5dc50a658c2b 100644
> --- a/drivers/media/platform/mediatek/vpu/mtk_vpu.c
> +++ b/drivers/media/platform/mediatek/vpu/mtk_vpu.c
> @@ -437,6 +437,21 @@ int vpu_wdt_reg_handler(struct platform_device *pdev,
>  }
>  EXPORT_SYMBOL_GPL(vpu_wdt_reg_handler);
>  
> +void vpu_wdt_unreg_handler(struct platform_device *pdev, enum rst_id id)
> +{
> + struct mtk_vpu *vpu = platform_get_drvdata(pdev);
> +
> + if (!vpu || id >= VPU_RST_MAX)
> + return;
> +
> + mutex_lock(&vpu->vpu_mutex);
> + vpu->wdt.handler[id].reset_func = NULL;
> + vpu->wdt.handler[id].priv = NULL;
> + mutex_unlock(&vpu->vpu_mutex);
> +}
> +EXPORT_SYMBOL_GPL(vpu_wdt_unreg_handler);
> +
> +

This extra blank makes checkpatch sad :-\ Since I see nothing else to comment
about, I'll simply apply this fix on my end.

Reviewed-by: Nicolas Dufresne <nicolas.dufresne@xxxxxxxxxxxxx>

regards,
Nicolas

>  unsigned int vpu_get_vdec_hw_capa(struct platform_device *pdev)
>  {
>   struct mtk_vpu *vpu = platform_get_drvdata(pdev);
> diff --git a/drivers/media/platform/mediatek/vpu/mtk_vpu.h b/drivers/media/platform/mediatek/vpu/mtk_vpu.h
> index 3951547e9ec5..2ccb481a04cf 100644
> --- a/drivers/media/platform/mediatek/vpu/mtk_vpu.h
> +++ b/drivers/media/platform/mediatek/vpu/mtk_vpu.h
> @@ -141,6 +141,8 @@ int vpu_wdt_reg_handler(struct platform_device *pdev,
>   void vpu_wdt_reset_func(void *priv),
>   void *priv, enum rst_id id);
>  
> +void vpu_wdt_unreg_handler(struct platform_device *pdev, enum rst_id id);
> +
>  /**
>   * vpu_get_vdec_hw_capa - get video decoder hardware capability
>   *

Attachment: signature.asc
Description: This is a digitally signed message part