This is an automated email from the git hooks/post-receive script. Git pushed a commit to branch release/8.1 in repository ffmpeg.
commit ff48edd8b29406ec2614db1137e972e77b15a10b Author: nyanmisaka <[email protected]> AuthorDate: Sun Apr 12 20:50:38 2026 +0800 Commit: Lynne <[email protected]> CommitDate: Sun Sep 27 22:53:24 2026 +0000 hwcontext_vulkan: fix double free when vulkan_map_to_drm fails The multiplanar image with storage_bit enabled fails to be exported to DMA-BUF on the QCOM turnip driver, thus triggering this double-free issue. ``` [Parsed_hwmap_2 @ 0xffff5c002a70] Configure hwmap vulkan -> drm_prime. [hwmap @ 0xffff5c001180] Filter input: vulkan, 1920x1080 (0). [AVHWFramesContext @ 0xffff5c004e00] Unable to export the image as a FD! free(): double free detected in tcache 2 Aborted ``` Additionally, add back an av_unused attribute. Otherwise, the compiler will complain about unused variables when CUDA is not enabled. Signed-off-by: nyanmisaka <[email protected]> (cherry picked from commit ab7b6ef0a2c54c363abcb87b0df7b6f71d256f08) Assisted-by: Fairy --- libavutil/hwcontext_vulkan.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/libavutil/hwcontext_vulkan.c b/libavutil/hwcontext_vulkan.c index 942ad726de..9e53c2347c 100644 --- a/libavutil/hwcontext_vulkan.c +++ b/libavutil/hwcontext_vulkan.c @@ -4249,7 +4249,7 @@ static int vulkan_map_to_drm(AVHWFramesContext *hwfc, AVFrame *dst, .sType = VK_STRUCTURE_TYPE_IMAGE_DRM_FORMAT_MODIFIER_PROPERTIES_EXT, }; const int nb_sems = nb_images; - + int free_drm_desc_on_err = 1; int sync_fd = -1; AVDRMFrameDescriptor *drm_desc = av_mallocz(sizeof(*drm_desc)); @@ -4287,6 +4287,9 @@ static int vulkan_map_to_drm(AVHWFramesContext *hwfc, AVFrame *dst, if (err < 0) goto end; + /* It will be freed in ff_hwframe_map_create callback */ + free_drm_desc_on_err = 0; + ret = vk->GetImageDrmFormatModifierPropertiesEXT(hwctx->act_dev, f->img[0], &drm_mod); if (ret != VK_SUCCESS) { @@ -4387,7 +4390,8 @@ static int vulkan_map_to_drm(AVHWFramesContext *hwfc, AVFrame *dst, end: for (int i = 0; i < drm_desc->nb_objects; i++) close(drm_desc->objects[i].fd); - av_free(drm_desc); + if (free_drm_desc_on_err) + av_free(drm_desc); if (sync_fd >= 0) close(sync_fd); return err; @@ -4869,7 +4873,7 @@ end: static int vulkan_transfer_data_to(AVHWFramesContext *hwfc, AVFrame *dst, const AVFrame *src) { - VulkanDevicePriv *p = hwfc->device_ctx->hwctx; + av_unused VulkanDevicePriv *p = hwfc->device_ctx->hwctx; switch (src->format) { #if CONFIG_CUDA -- To stop receiving notification emails like this one, please contact [email protected]. _______________________________________________ ffmpeg-cvslog mailing list -- [email protected] To unsubscribe send an email to [email protected]
