Re: [PATCH v3 3/5] media: qcom: camss: vfe: Fix VFE reset while another line is streaming

From: Bryan O'Donoghue

Date: Mon Sep 28 2026 - 04:52:26 EST


On 28/09/2026 07:43, Hitesh Patel wrote:
@@ -814,6 +814,7 @@ static int vfe_disable_output(struct vfe_line *line)
struct vfe_output *output = &line->output;
unsigned long flags;
unsigned int i;
+ bool last;

spin_lock_irqsave(&vfe->output_lock, flags);
for (i = 0; i < output->wm_num; i++)
@@ -821,6 +822,13 @@ static int vfe_disable_output(struct vfe_line *line)
output->gen2.active_num = 0;
spin_unlock_irqrestore(&vfe->output_lock, flags);

+ mutex_lock(&vfe->stream_lock);
+ last = vfe->stream_count == 1;
+ mutex_unlock(&vfe->stream_lock);
+
+ if (!last)
+ return 0;
+

NAK.

This can't be correct, in fact its very racy and will break. Here is the existing code.

static int vfe_disable_output(struct vfe_line *line)
{
struct vfe_device *vfe = to_vfe(line);
struct vfe_output *output = &line->output;
unsigned long flags;
unsigned int i;

spin_lock_irqsave(&vfe->output_lock, flags);
for (i = 0; i < output->wm_num; i++)
vfe->res->hw_ops->vfe_wm_stop(vfe, output->wm_idx[i]);
output->gen2.active_num = 0;
spin_unlock_irqrestore(&vfe->output_lock, flags);

return vfe_reset(vfe);
}

/*
* vfe_disable - Disable streaming on VFE line
* @line: VFE line
*
* Return 0 on success or a negative error code otherwise
*/
int vfe_disable(struct vfe_line *line)
{
struct vfe_device *vfe = to_vfe(line);
int ret;

ret = vfe_disable_output(line);
if (ret)
goto error;

vfe_put_output(line);

mutex_lock(&vfe->stream_lock);

vfe->stream_count--;

mutex_unlock(&vfe->stream_lock);

error:
return ret;
}

Here's how

stream_count = 2;

thread0:
vfe_disable()
vfe_disable_output()
mutex_lock();
last = stream_count == 1; //false
mutex_unlock();
return;

thread1:
vfe_disable()
vfe_disable_output()
mutex_lock();
last = stream_count == 1; //false
mutex_unlock();
return;

thread0:
vfe_disable()
mutex_lock();
stream_count--; // => stream_count = 1;
mutex_unlock();

thread1:
vfe_disable()
mutex_lock();
stream_count--; // => stream_count = 0;
mutex_unlock();

vfe_reset() is never called.

this->

diff --git a/drivers/media/platform/qcom/camss/camss-vfe.c b/drivers/media/platform/qcom/camss/camss-vfe.c
index 34e4319d8f80c..3dafd5d778630 100644
--- a/drivers/media/platform/qcom/camss/camss-vfe.c
+++ b/drivers/media/platform/qcom/camss/camss-vfe.c
@@ -828,7 +828,7 @@ static int vfe_disable_output(struct vfe_line *line)
output->gen2.active_num = 0;
spin_unlock_irqrestore(&vfe->output_lock, flags);

- return vfe_reset(vfe);
+ return 0;
}

/*
@@ -850,7 +850,8 @@ int vfe_disable(struct vfe_line *line)

mutex_lock(&vfe->stream_lock);

- vfe->stream_count--;
+ if (--vfe->stream_count == 0)
+ ret = vfe_reset(vfe);

mutex_unlock(&vfe->stream_lock);

---
bod