Skip to content

gk7205v500: build the XMedia module set from vendor SDK source - #229

Merged
widgetii merged 4 commits into
mainfrom
gk7205v500-xmedia
Sep 25, 2026
Merged

widgetii merged 4 commits into
mainfrom
gk7205v500-xmedia

Conversation

@widgetii

Copy link
Copy Markdown
Member

Adds CHIPARCH=gk7205v500 for the XMedia xm720xxxx dies (GK7205V500/V510/
V530, GK7202V330, GK7201V200), from XMediaIPCLinuxV100R002C00SPC020
(MPP_V1.0.0.0 B00, objects dated Apr 2023).

What is built from source

osal (with MMZ and the media bus), sys_config, the ISP kernel driver,
sensor_i2c/sensor_spi/pwm/piris/sample_ist, init, wdt and adc -- all of
modules/ in the SDK.

What is relinked

base, sys, vi, vpss, rgn, vgs, chnl, rc, venc, vedu, h264e, h265e,
jpege, mipi_rx, ive, cipher_drv, tde and audio ship only as objects.
Each SDK .o is already a complete module (init_module, modinfo), so it
is relinked as-is and modpost stamps the target kernel's vermagic.
The objects in obj/gk7205v500/{V200,V500}/ are byte-identical to the
SDK's obj_ko_lib//linux-4.9.y/obj_dynamic/obj_nolog.

The SDK ships two blob sets that are not interchangeable: V200 for
xm72050200-class dies and V500 for xm72050500-class ones. XM_SET picks
one (default V500); GK7201V200 (chip id 0x72010200) is a V200 die and
needs XM_SET=V200. The source modules get the matching -Dxm7205x0x00.

The objects were compiled against the SDK's xm72050200_tiny_defconfig
and call kernel APIs directly, so the kernel has to keep its struct
layouts: CONFIG_PM off (it moves struct device's fields -- with it on,
the media bus registration dereferences dev->class at the wrong offset)
and CONFIG_MODULE_UNLOAD off.

sys_config

The only functional change to vendor source. The SDK predates the
GK7201V200 die and only matches xm720xxxxx chip strings; anything else
falls through every strncmp() and silently skips pinmux() and clkcfg().
On GK7201V200 that leaves the sensor i2c pins unmuxed (i2c "wait idle
timeout", no sensor). Now:

  • OpenIPC SoC names (what load_goke passes) and xm72010200 are mapped to
    the SDK chip whose pinmux/clock setup they share;
  • the VI clock tables accept chip id 0x72010200 with the V200 dies;
  • mis2008 gets the 27 MHz sensor clock.

Verification

  • Both sets build against openipc/linux 4.9.37 (gk7201v200_lite kernel
    with CONFIG_PM and CONFIG_MODULE_UNLOAD off): V200 34 modules, V500
    36 (DISABLE_VO=1; gfbg needs fbdev, which OpenIPC leaves out).
  • QEMU (qemu-hisilicon -M gk7201v200): the V200 set loads in the stock
    firmware's order -- osal, sysconfig chip=gk7201v200 sensors=mis2008,
    base, sys, rgn, vgs, vi, isp, vpss, chnl, vedu, rc, venc, h264e,
    h265e, jpege, ive, sensor_i2c, audio, mipi_rx -- every module prints
    its "load ... OK" and there is no oops.

Firmware integration (package wiring, kernel config) follows separately, after this lands. Not yet hardware-tested; the GK7201V200 run will be posted here before merge.

Adds CHIPARCH=gk7205v500 for the XMedia xm720xxxx dies (GK7205V500/V510/
V530, GK7202V330, GK7201V200), from XMediaIPCLinuxV100R002C00SPC020
(MPP_V1.0.0.0 B00, objects dated Apr 2023).

## What is built from source

osal (with MMZ and the media bus), sys_config, the ISP kernel driver,
sensor_i2c/sensor_spi/pwm/piris/sample_ist, init, wdt and adc -- all of
modules/ in the SDK.

## What is relinked

base, sys, vi, vpss, rgn, vgs, chnl, rc, venc, vedu, h264e, h265e,
jpege, mipi_rx, ive, cipher_drv, tde and audio ship only as objects.
Each SDK .o is already a complete module (init_module, modinfo), so it
is relinked as-is and modpost stamps the target kernel's vermagic.
The objects in obj/gk7205v500/{V200,V500}/ are byte-identical to the
SDK's obj_ko_lib/<set>/linux-4.9.y/obj_dynamic/obj_nolog.

The SDK ships two blob sets that are not interchangeable: V200 for
xm72050200-class dies and V500 for xm72050500-class ones. XM_SET picks
one (default V500); GK7201V200 (chip id 0x72010200) is a V200 die and
needs XM_SET=V200. The source modules get the matching -Dxm7205x0x00.

The objects were compiled against the SDK's xm72050200_tiny_defconfig
and call kernel APIs directly, so the kernel has to keep its struct
layouts: CONFIG_PM off (it moves struct device's fields -- with it on,
the media bus registration dereferences dev->class at the wrong offset)
and CONFIG_MODULE_UNLOAD off.

## sys_config

The only functional change to vendor source. The SDK predates the
GK7201V200 die and only matches xm720xxxxx chip strings; anything else
falls through every strncmp() and silently skips pinmux() and clkcfg().
On GK7201V200 that leaves the sensor i2c pins unmuxed (i2c "wait idle
timeout", no sensor). Now:

- OpenIPC SoC names (what load_goke passes) and xm72010200 are mapped to
  the SDK chip whose pinmux/clock setup they share;
- the VI clock tables accept chip id 0x72010200 with the V200 dies;
- mis2008 gets the 27 MHz sensor clock.

## Verification

- Both sets build against openipc/linux 4.9.37 (gk7201v200_lite kernel
  with CONFIG_PM and CONFIG_MODULE_UNLOAD off): V200 34 modules, V500
  36 (DISABLE_VO=1; gfbg needs fbdev, which OpenIPC leaves out).
- QEMU (qemu-hisilicon -M gk7201v200): the V200 set loads in the stock
  firmware's order -- osal, sysconfig chip=gk7201v200 sensors=mis2008,
  base, sys, rgn, vgs, vi, isp, vpss, chnl, vedu, rc, venc, h264e,
  h265e, jpege, ive, sensor_i2c, audio, mipi_rx -- every module prints
  its "load ... OK" and there is no oops.

Firmware integration (package wiring, kernel config) follows separately.
@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Add gk7205v500 XMedia kernel module build support

✨ Enhancement ⚙️ Configuration changes 🕐 40+ Minutes

Grey Divider

AI Description

• Adds source-built XMedia drivers for GK7205V500-family SoCs.
• Selects compatible V200 or V500 closed modules through XM_SET.
• Fixes GK7201V200 pinmux, VI clocks, and mis2008 sensor clock configuration.
Diagram

graph TD
  BUILD["Kernel Kbuild"] --> SELECT{"XM_SET"} --> SOURCE["Source drivers"] --> MODULES["XMedia modules"] --> KERNEL["Linux 4.9"] --> HARDWARE["XMedia SoCs"]
  SELECT --> BLOBS[("Vendor objects")] --> MODULES
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Distribute vendor-built .ko files
  • ➕ Avoids importing and maintaining the available vendor source
  • ➕ Keeps the build definition smaller
  • ➖ Retains the SDK kernel vermagic instead of targeting OpenIPC
  • ➖ Makes kernel ABI compatibility harder to validate and reproduce
  • ➖ Cannot apply the GK7201V200 system-configuration fixes cleanly
2. Reimplement the media stack
  • ➕ Could remove vendor coding conventions and undocumented compatibility assumptions
  • ➕ Could target newer kernels and configurations directly
  • ➖ Requires replacing a very large proprietary media and ISP interface
  • ➖ Closed codec and accelerator implementations remain unavailable
  • ➖ Introduces substantially greater schedule and hardware-validation risk

Recommendation: Use the PR's hybrid strategy: compile every available SDK module from source and relink only modules distributed as complete objects. This preserves vendor interfaces, permits the required GK7201V200 fixes, and stamps modules for the target kernel; the strict CONFIG_PM and CONFIG_MODULE_UNLOAD requirements should remain prominently documented and enforced during firmware integration.

Files changed (208) +64623 / -1

Enhancement (203) +62613 / -0
adc.cAdd XMedia LSADC driver +376/-0

Add XMedia LSADC driver

• Implements register access, channel configuration, interrupts, and the ADC device interface.

kernel/adc/gk7205v500/adc.c

adc.hDefine private ADC interfaces +33/-0

Define private ADC interfaces

• Declares the LSADC driver's internal commands and data structures.

kernel/adc/gk7205v500/adc.h

adc.hExpose ADC control API +33/-0

Expose ADC control API

• Adds public ADC ioctl definitions for the gk7205v500 module set.

kernel/include/gk7205v500/adc.h

ae_comm.hAdd AE shared definitions +185/-0

Add AE shared definitions

• Defines automatic-exposure statistics, results, callbacks, and parameter structures.

kernel/include/gk7205v500/ae_comm.h

af_comm.hAdd AF shared definitions +23/-0

Add AF shared definitions

• Defines common automatic-focus data types used by ISP integrations.

kernel/include/gk7205v500/af_comm.h

audio_aacdec.hAdd AAC decoder interface +278/-0

Add AAC decoder interface

• Defines the vendor AAC decoder API, options, and stream structures.

kernel/include/gk7205v500/audio_aacdec.h

audio_aacenc.hAdd AAC encoder interface +204/-0

Add AAC encoder interface

• Defines the vendor AAC encoder API, configuration, and output structures.

kernel/include/gk7205v500/audio_aacenc.h

audio_acodec.hAdd audio codec controls +192/-0

Add audio codec controls

• Defines analog codec ioctl commands and audio path configuration types.

kernel/include/gk7205v500/audio_acodec.h

audio_bcd.hAdd BCD audio interface +48/-0

Add BCD audio interface

• Declares audio BCD configuration and processing interfaces.

kernel/include/gk7205v500/audio_bcd.h

audio_mp3dec.hAdd MP3 decoder interface +139/-0

Add MP3 decoder interface

• Defines MP3 decoding configuration, stream, and result types.

kernel/include/gk7205v500/audio_mp3dec.h

audio_mp3enc.hAdd MP3 encoder interface +100/-0

Add MP3 encoder interface

• Defines MP3 encoding parameters and API contracts.

kernel/include/gk7205v500/audio_mp3enc.h

awb_comm.hAdd AWB shared definitions +152/-0

Add AWB shared definitions

• Defines automatic-white-balance statistics, results, and callback structures.

kernel/include/gk7205v500/awb_comm.h

buffer.hAdd media buffer primitives +639/-0

Add media buffer primitives

• Defines queues, blocks, pools, and helper contracts used across media modules.

kernel/include/gk7205v500/buffer.h

comm_3a.hAdd common 3A contracts +406/-0

Add common 3A contracts

• Defines shared AE, AWB, and AF algorithm registration structures.

kernel/include/gk7205v500/comm_3a.h

comm_adec.hAdd audio decoder contracts +100/-0

Add audio decoder contracts

• Defines decoder channels, streams, attributes, and status structures.

kernel/include/gk7205v500/comm_adec.h

comm_aenc.hAdd audio encoder contracts +84/-0

Add audio encoder contracts

• Defines encoder channels, stream metadata, and codec registration structures.

kernel/include/gk7205v500/comm_aenc.h

comm_ai.hAdd audio input contracts +24/-0

Add audio input contracts

• Defines audio-input channel parameter structures.

kernel/include/gk7205v500/comm_ai.h

comm_aio.hAdd common audio I/O types +495/-0

Add common audio I/O types

• Defines audio devices, formats, frames, resampling, and VQE structures.

kernel/include/gk7205v500/comm_aio.h

comm_ao.hAdd audio output contracts +25/-0

Add audio output contracts

• Defines audio-output channel parameter structures.

kernel/include/gk7205v500/comm_ao.h

comm_cipher.hAdd cipher contracts +347/-0

Add cipher contracts

• Defines cryptographic channels, keys, hashes, RSA, and ioctl-facing data types.

kernel/include/gk7205v500/comm_cipher.h

comm_dis.hAdd stabilization definitions +82/-0

Add stabilization definitions

• Defines digital image stabilization configuration and motion data.

kernel/include/gk7205v500/comm_dis.h

comm_gdc.hAdd geometric correction types +143/-0

Add geometric correction types

• Defines lens-distortion and geometric correction task structures.

kernel/include/gk7205v500/comm_gdc.h

comm_isp.hAdd ISP public data model +2227/-0

Add ISP public data model

• Defines the extensive ISP configuration, statistics, tuning, and metadata contracts.

kernel/include/gk7205v500/comm_isp.h

comm_ive.hAdd IVE shared contracts +344/-0

Add IVE shared contracts

• Defines image and video engine controls, memory, and operation structures.

kernel/include/gk7205v500/comm_ive.h

comm_npu.hAdd NPU shared contracts +81/-0

Add NPU shared contracts

• Defines neural-processing memory, model, and execution structures.

kernel/include/gk7205v500/comm_npu.h

comm_rc.hAdd rate-control contracts +415/-0

Add rate-control contracts

• Defines bitrate-control modes, thresholds, statistics, and codec parameters.

kernel/include/gk7205v500/comm_rc.h

comm_region.hAdd region overlay contracts +228/-0

Add region overlay contracts

• Defines overlays, covers, mosaics, canvases, and region channel attributes.

kernel/include/gk7205v500/comm_region.h

comm_snap.hAdd snapshot contracts +88/-0

Add snapshot contracts

• Defines snapshot modes, frame selection, and processing attributes.

kernel/include/gk7205v500/comm_snap.h

comm_sns.hAdd sensor contracts +408/-0

Add sensor contracts

• Defines sensor bus, register, mode, synchronization, and callback structures.

kernel/include/gk7205v500/comm_sns.h

comm_sys.hAdd system media contracts +168/-0

Add system media contracts

• Defines module binding, chip identification, cache, and system configuration types.

kernel/include/gk7205v500/comm_sys.h

comm_vb.hAdd video-buffer contracts +120/-0

Add video-buffer contracts

• Defines buffer-pool configuration, block metadata, and allocation structures.

kernel/include/gk7205v500/comm_vb.h

comm_venc.hAdd video encoder contracts +816/-0

Add video encoder contracts

• Defines codec attributes, streams, packs, reference modes, and encoder status.

kernel/include/gk7205v500/comm_venc.h

comm_vgs.hAdd video graphics contracts +109/-0

Add video graphics contracts

• Defines VGS tasks, drawing operations, scaling, and rotation structures.

kernel/include/gk7205v500/comm_vgs.h

comm_vi.hAdd video input contracts +722/-0

Add video input contracts

• Defines VI devices, pipes, channels, timing, and frame-processing attributes.

kernel/include/gk7205v500/comm_vi.h

comm_video.hAdd common video types +610/-0

Add common video types

• Defines pixel formats, frames, rectangles, compression, and dynamic-range metadata.

kernel/include/gk7205v500/comm_video.h

comm_vo.hAdd video output contracts +444/-0

Add video output contracts

• Defines VO devices, layers, channels, timing, and display attributes.

kernel/include/gk7205v500/comm_vo.h

comm_vpss.hAdd VPSS contracts +454/-0

Add VPSS contracts

• Defines processing groups, channels, noise reduction, and crop attributes.

kernel/include/gk7205v500/comm_vpss.h

common.hAdd common media identifiers +388/-0

Add common media identifiers

• Defines shared module IDs, channel descriptors, and utility macros.

kernel/include/gk7205v500/common.h

common_qr.hAdd QR common definitions +54/-0

Add QR common definitions

• Defines shared QR processing constants and structures.

kernel/include/gk7205v500/common_qr.h

defines.hAdd SDK constants and macros +424/-0

Add SDK constants and macros

• Provides common XMedia limits, alignment helpers, and compile-time definitions.

kernel/include/gk7205v500/defines.h

dev_ext.hAdd device extension interface +119/-0

Add device extension interface

• Declares kernel-side device registration and file-operation abstractions.

kernel/include/gk7205v500/dev_ext.h

errcode.hAdd XMedia error codes +78/-0

Add XMedia error codes

• Defines shared status codes and module-specific error construction helpers.

kernel/include/gk7205v500/errcode.h

gfbg.hAdd framebuffer interface +411/-0

Add framebuffer interface

• Defines graphics framebuffer layers, formats, canvases, and ioctl controls.

kernel/include/gk7205v500/gfbg.h

i2c.hAdd sensor I2C callback types +35/-0

Add sensor I2C callback types

• Declares ISP-facing sensor I2C write contracts.

kernel/include/gk7205v500/i2c.h

isp_bin.hAdd ISP binary metadata +37/-0

Add ISP binary metadata

• Defines ISP tuning binary headers and section metadata.

kernel/include/gk7205v500/isp_bin.h

isp_debug.hAdd ISP debug helpers +17/-0

Add ISP debug helpers

• Provides ISP logging and assertion macros.

kernel/include/gk7205v500/isp_debug.h

isp_defines.hAdd ISP limits and constants +167/-0

Add ISP limits and constants

• Defines supported ISP dimensions, counts, and feature limits.

kernel/include/gk7205v500/isp_defines.h

ive.hAdd IVE operation API +783/-0

Add IVE operation API

• Declares image-processing operations and associated control structures.

kernel/include/gk7205v500/ive.h

ivp.hAdd IVP processing API +412/-0

Add IVP processing API

• Defines intelligent video processing handles, images, and operation contracts.

kernel/include/gk7205v500/ivp.h

ivs_qr.hAdd QR analysis API +29/-0

Add QR analysis API

• Declares QR analysis creation, processing, and result interfaces.

kernel/include/gk7205v500/ivs_qr.h

list.hAdd SDK list helpers +120/-0

Add SDK list helpers

• Provides intrusive linked-list types and manipulation macros.

kernel/include/gk7205v500/list.h

math_fun.hAdd fixed-point math helpers +237/-0

Add fixed-point math helpers

• Declares integer and fixed-point mathematical utilities used by media drivers.

kernel/include/gk7205v500/math_fun.h

md.hAdd motion-detection API +37/-0

Add motion-detection API

• Defines motion-detection attributes and processing interfaces.

kernel/include/gk7205v500/md.h

mipi.hAdd MIPI receiver controls +253/-0

Add MIPI receiver controls

• Defines MIPI/LVDS input configuration, synchronization, and ioctl commands.

kernel/include/gk7205v500/mipi.h

mpp_debug.hAdd media debug infrastructure +148/-0

Add media debug infrastructure

• Defines module logging levels, tracing macros, and debug controls.

kernel/include/gk7205v500/mpp_debug.h

resampler_api.hAdd audio resampler API +110/-0

Add audio resampler API

• Declares resampler creation, processing, and teardown contracts.

kernel/include/gk7205v500/resampler_api.h

securec.hAdd secure C interfaces +291/-0

Add secure C interfaces

• Declares bounds-checked string and memory helper functions used by the SDK.

kernel/include/gk7205v500/securec.h

securectype.hAdd secure C support types +515/-0

Add secure C support types

• Defines secure-library errors, limits, and compatibility types.

kernel/include/gk7205v500/securectype.h

sns_ctrl.hAdd sensor control interface +164/-0

Add sensor control interface

• Defines sensor object callbacks for registration, bus setup, and mode control.

kernel/include/gk7205v500/sns_ctrl.h

spi.hAdd sensor SPI callback types +70/-0

Add sensor SPI callback types

• Declares ISP-facing sensor SPI read and write contracts.

kernel/include/gk7205v500/spi.h

ssp.hAdd SSP definitions +24/-0

Add SSP definitions

• Defines synchronous serial port constants and basic interfaces.

kernel/include/gk7205v500/ssp.h

streamer.hAdd stream helper interface +27/-0

Add stream helper interface

• Declares stream buffer access and traversal helpers.

kernel/include/gk7205v500/streamer.h

tde_api.hAdd TDE operation API +156/-0

Add TDE operation API

• Declares 2D engine jobs, blits, fills, scaling, and compositing operations.

kernel/include/gk7205v500/tde_api.h

tde_errcode.hAdd TDE error codes +43/-0

Add TDE error codes

• Defines 2D engine status and failure codes.

kernel/include/gk7205v500/tde_errcode.h

tde_type.hAdd TDE data model +450/-0

Add TDE data model

• Defines surfaces, rectangles, color keys, blend modes, and operation options.

kernel/include/gk7205v500/tde_type.h

type.hAdd XMedia scalar types +111/-0

Add XMedia scalar types

• Defines SDK integer, pointer, boolean, and handle aliases.

kernel/include/gk7205v500/type.h

types.hAdd compatibility type aliases +34/-0

Add compatibility type aliases

• Provides supplemental SDK scalar and address type definitions.

kernel/include/gk7205v500/types.h

vou_exp.hAdd video-output exports +21/-0

Add video-output exports

• Declares kernel export hooks exposed by the video-output module.

kernel/include/gk7205v500/vou_exp.h

vqe_register_api.hAdd VQE registration API +52/-0

Add VQE registration API

• Declares audio quality algorithm registration and unregistration contracts.

kernel/include/gk7205v500/vqe_register_api.h

watchdog.hExpose watchdog controls +44/-0

Expose watchdog controls

• Defines watchdog ioctl commands and user-facing control constants.

kernel/include/gk7205v500/watchdog.h

xmedia_aacdec.hAdd XMedia AAC decoder wrapper +29/-0

Add XMedia AAC decoder wrapper

• Exposes the namespaced AAC decoder entry points.

kernel/include/gk7205v500/xmedia_aacdec.h

xmedia_aacenc.hAdd XMedia AAC encoder wrapper +29/-0

Add XMedia AAC encoder wrapper

• Exposes the namespaced AAC encoder entry points.

kernel/include/gk7205v500/xmedia_aacenc.h

xmedia_api_ae.hAdd AE application API +66/-0

Add AE application API

• Declares automatic-exposure registration and configuration operations.

kernel/include/gk7205v500/xmedia_api_ae.h

xmedia_api_ai.hAdd audio-input application API +180/-0

Add audio-input application API

• Declares audio-input device, channel, frame, and VQE operations.

kernel/include/gk7205v500/xmedia_api_ai.h

xmedia_api_audio.hAdd common audio application API +150/-0

Add common audio application API

• Declares shared audio encoding, decoding, and processing operations.

kernel/include/gk7205v500/xmedia_api_audio.h

xmedia_api_awb.hAdd AWB application API +50/-0

Add AWB application API

• Declares automatic-white-balance registration and configuration operations.

kernel/include/gk7205v500/xmedia_api_awb.h

xmedia_api_awb_natura.hAdd Natura AWB API +52/-0

Add Natura AWB API

• Declares the vendor Natura white-balance algorithm integration.

kernel/include/gk7205v500/xmedia_api_awb_natura.h

xmedia_api_cipher.hAdd cipher application API +93/-0

Add cipher application API

• Declares encryption, hashing, random-number, and RSA operations.

kernel/include/gk7205v500/xmedia_api_cipher.h

xmedia_api_isp.hAdd ISP application API +206/-0

Add ISP application API

• Declares ISP lifecycle, tuning, statistics, and metadata operations.

kernel/include/gk7205v500/xmedia_api_isp.h

xmedia_api_ive.hAdd IVE application API +144/-0

Add IVE application API

• Declares image and video engine jobs and query operations.

kernel/include/gk7205v500/xmedia_api_ive.h

xmedia_api_npu.hAdd NPU application API +42/-0

Add NPU application API

• Declares model loading, task execution, and resource management operations.

kernel/include/gk7205v500/xmedia_api_npu.h

xmedia_api_pdm.hAdd parameter-data API +81/-0

Add parameter-data API

• Declares persistent parameter and calibration data access.

kernel/include/gk7205v500/xmedia_api_pdm.h

xmedia_api_region.hAdd region application API +43/-0

Add region application API

• Declares region creation, attachment, canvas, and display operations.

kernel/include/gk7205v500/xmedia_api_region.h

xmedia_api_snap.hAdd snapshot application API +38/-0

Add snapshot application API

• Declares snapshot enablement and frame-processing operations.

kernel/include/gk7205v500/xmedia_api_snap.h

xmedia_api_sys.hAdd system application API +97/-0

Add system application API

• Declares media-system initialization, binding, cache, and version operations.

kernel/include/gk7205v500/xmedia_api_sys.h

xmedia_api_vb.hAdd video-buffer application API +57/-0

Add video-buffer application API

• Declares pool creation, block allocation, mapping, and release operations.

kernel/include/gk7205v500/xmedia_api_vb.h

xmedia_api_venc.hAdd encoder application API +170/-0

Add encoder application API

• Declares video encoder channel, stream, ROI, and codec controls.

kernel/include/gk7205v500/xmedia_api_venc.h

xmedia_api_vgs.hAdd VGS application API +49/-0

Add VGS application API

• Declares graphics job management and frame transformation operations.

kernel/include/gk7205v500/xmedia_api_vgs.h

xmedia_api_vi.hAdd video-input application API +178/-0

Add video-input application API

• Declares VI device, pipe, channel, frame, and dump operations.

kernel/include/gk7205v500/xmedia_api_vi.h

xmedia_api_vo.hAdd video-output application API +161/-0

Add video-output application API

• Declares VO device, layer, channel, frame, and synchronization operations.

kernel/include/gk7205v500/xmedia_api_vo.h

xmedia_api_vpss.hAdd VPSS application API +131/-0

Add VPSS application API

• Declares processing-group and channel lifecycle, frame, and crop operations.

kernel/include/gk7205v500/xmedia_api_vpss.h

xmedia_audio_bcd.hAdd XMedia BCD wrapper +34/-0

Add XMedia BCD wrapper

• Exposes the namespaced audio BCD processing interface.

kernel/include/gk7205v500/xmedia_audio_bcd.h

xmedia_cl.hAdd compute-layer interface +265/-0

Add compute-layer interface

• Defines the XMedia compute runtime, kernels, memory, and execution contracts.

kernel/include/gk7205v500/xmedia_cl.h

xmedia_ivp.hAdd XMedia IVP wrapper +60/-0

Add XMedia IVP wrapper

• Exposes namespaced intelligent video processing operations.

kernel/include/gk7205v500/xmedia_ivp.h

xmedia_ivs_md.hAdd motion-analysis wrapper +45/-0

Add motion-analysis wrapper

• Exposes namespaced motion-detection creation and processing operations.

kernel/include/gk7205v500/xmedia_ivs_md.h

xmedia_ivs_qr.hAdd QR-analysis wrapper +29/-0

Add QR-analysis wrapper

• Exposes namespaced QR analysis operations.

kernel/include/gk7205v500/xmedia_ivs_qr.h

xmedia_mp3dec.hAdd XMedia MP3 decoder wrapper +27/-0

Add XMedia MP3 decoder wrapper

• Exposes the namespaced MP3 decoder entry points.

kernel/include/gk7205v500/xmedia_mp3dec.h

xmedia_mp3enc.hAdd XMedia MP3 encoder wrapper +27/-0

Add XMedia MP3 encoder wrapper

• Exposes the namespaced MP3 encoder entry points.

kernel/include/gk7205v500/xmedia_mp3enc.h

xmedia_resampler_api.hAdd XMedia resampler wrapper +33/-0

Add XMedia resampler wrapper

• Exposes namespaced audio resampling operations.

kernel/include/gk7205v500/xmedia_resampler_api.h

xmedia_tde_api.hAdd XMedia TDE wrapper +132/-0

Add XMedia TDE wrapper

• Exposes namespaced 2D graphics engine operations.

kernel/include/gk7205v500/xmedia_tde_api.h

xmedia_vqe_register_api.hAdd XMedia VQE wrapper +35/-0

Add XMedia VQE wrapper

• Exposes namespaced audio quality algorithm registration operations.

kernel/include/gk7205v500/xmedia_vqe_register_api.h

adc_init.cRegister the ADC platform driver +74/-0

Register the ADC platform driver

• Maps ADC resources from the device tree and connects platform probing to LSADC initialization.

kernel/init/gk7205v500/adc_init.c

wdt_init.cRegister the watchdog platform driver +72/-0

Register the watchdog platform driver

• Maps watchdog resources, exposes module parameters, and connects platform lifecycle callbacks.

kernel/init/gk7205v500/wdt_init.c

xmedia_init.cAdd monolithic XMedia initialization +133/-0

Add monolithic XMedia initialization

• Defines ordered built-in initialization for the media stack, peripheral drivers, and V200/V500-specific modules.

kernel/init/gk7205v500/xmedia_init.c

isp_ext.hAdd ISP kernel export contracts +305/-0

Add ISP kernel export contracts

• Defines cross-module ISP callbacks, exports, and invocation helpers.

kernel/isp/gk7205v500/ext_inc/isp_ext.h

mm_ext.hAdd memory-manager exports +89/-0

Add memory-manager exports

• Declares MMZ and media-memory hooks consumed by ISP extensions.

kernel/isp/gk7205v500/ext_inc/mm_ext.h

mod_ext.hAdd module-manager exports +70/-0

Add module-manager exports

• Declares media module registration and export lookup contracts.

kernel/isp/gk7205v500/ext_inc/mod_ext.h

ot_mpi_ae.hAdd compatible AE MPI declarations +69/-0

Add compatible AE MPI declarations

• Provides AE application declarations expected by the imported ISP sources.

kernel/isp/gk7205v500/ext_inc/ot_mpi_ae.h

ot_mpi_awb.hAdd compatible AWB MPI declarations +53/-0

Add compatible AWB MPI declarations

• Provides AWB application declarations expected by the imported ISP sources.

kernel/isp/gk7205v500/ext_inc/ot_mpi_awb.h

ot_mpi_isp.hAdd compatible ISP MPI declarations +208/-0

Add compatible ISP MPI declarations

• Provides ISP application declarations expected by the imported driver.

kernel/isp/gk7205v500/ext_inc/ot_mpi_isp.h

proc_ext.hAdd proc integration contracts +73/-0

Add proc integration contracts

• Declares media proc-entry registration and output helpers.

kernel/isp/gk7205v500/ext_inc/proc_ext.h

sys_ext.hAdd system-module exports +618/-0

Add system-module exports

• Defines system clock, binding, timing, and module callback contracts used by ISP.

kernel/isp/gk7205v500/ext_inc/sys_ext.h

vb_ext.hAdd video-buffer exports +504/-0

Add video-buffer exports

• Defines kernel-facing pool and block operations used by ISP.

kernel/isp/gk7205v500/ext_inc/vb_ext.h

vi_ext.hAdd video-input exports +307/-0

Add video-input exports

• Defines VI callback and frame-management contracts used by ISP.

kernel/isp/gk7205v500/ext_inc/vi_ext.h

isp_config.hAdd ISP register configuration accessors +4617/-0

Add ISP register configuration accessors

• Defines generated bitfield accessors for the XMedia ISP register map.

kernel/isp/gk7205v500/firmware/arch/include/isp_config.h

isp_config_u32.hAdd 32-bit ISP register accessors +5265/-0

Add 32-bit ISP register accessors

• Defines generated 32-bit configuration helpers for ISP hardware registers.

kernel/isp/gk7205v500/firmware/arch/include/isp_config_u32.h

isp_lut_config.hAdd ISP LUT configuration helpers +337/-0

Add ISP LUT configuration helpers

• Defines lookup-table register programming helpers for ISP firmware.

kernel/isp/gk7205v500/firmware/arch/include/isp_lut_config.h

isp_lut_define.hAdd ISP LUT definitions +252/-0

Add ISP LUT definitions

• Defines ISP lookup-table sizes, addresses, and data layouts.

kernel/isp/gk7205v500/firmware/arch/include/isp_lut_define.h

isp_stt_define.hAdd ISP statistics definitions +429/-0

Add ISP statistics definitions

• Defines hardware statistics buffers, register layouts, and constants.

kernel/isp/gk7205v500/firmware/arch/include/isp_stt_define.h

isp_vreg.hAdd ISP virtual-register accessors +199/-0

Add ISP virtual-register accessors

• Defines virtual-register addresses and read/write helpers used by ISP firmware.

kernel/isp/gk7205v500/firmware/arch/include/isp_vreg.h

yuv_cmos_ex.hAdd YUV sensor extensions +287/-0

Add YUV sensor extensions

• Defines YUV sensor state, mode, and callback integration structures.

kernel/isp/gk7205v500/firmware/arch/include/yuv_cmos_ex.h

isp_alg.hAdd ISP algorithm framework +292/-0

Add ISP algorithm framework

• Defines algorithm nodes, contexts, callbacks, and registration helpers.

kernel/isp/gk7205v500/firmware/include/isp_alg.h

isp_block.hAdd ISP block management +96/-0

Add ISP block management

• Defines image block partitioning and overlap calculations.

kernel/isp/gk7205v500/firmware/include/isp_block.h

isp_dcfinfo.hAdd ISP DCF metadata interface +29/-0

Add ISP DCF metadata interface

• Declares capture metadata initialization and update helpers.

kernel/isp/gk7205v500/firmware/include/isp_dcfinfo.h

isp_debug.hAdd ISP firmware diagnostics +40/-0

Add ISP firmware diagnostics

• Defines firmware-side tracing and assertion helpers.

kernel/isp/gk7205v500/firmware/include/isp_debug.h

isp_defaults.hAdd ISP default configuration interface +39/-0

Add ISP default configuration interface

• Declares default tuning and register initialization helpers.

kernel/isp/gk7205v500/firmware/include/isp_defaults.h

isp_dnginfo.hAdd ISP DNG metadata interface +37/-0

Add ISP DNG metadata interface

• Declares DNG metadata initialization and update helpers.

kernel/isp/gk7205v500/firmware/include/isp_dnginfo.h

isp_frameinfo.hAdd ISP frame metadata interface +62/-0

Add ISP frame metadata interface

• Declares frame-information initialization, update, and retrieval helpers.

kernel/isp/gk7205v500/firmware/include/isp_frameinfo.h

isp_inner.hAdd ISP internal context definitions +128/-0

Add ISP internal context definitions

• Defines internal firmware state and pipeline helper contracts.

kernel/isp/gk7205v500/firmware/include/isp_inner.h

isp_main.hAdd ISP firmware lifecycle contracts +360/-0

Add ISP firmware lifecycle contracts

• Defines firmware contexts, run states, synchronization, and control entry points.

kernel/isp/gk7205v500/firmware/include/isp_main.h

isp_math_utils.hAdd ISP math utilities +54/-0

Add ISP math utilities

• Declares interpolation and fixed-point helpers used by ISP algorithms.

kernel/isp/gk7205v500/firmware/include/isp_math_utils.h

isp_proc.hAdd ISP proc reporting interface +35/-0

Add ISP proc reporting interface

• Declares ISP diagnostic output and proc lifecycle helpers.

kernel/isp/gk7205v500/firmware/include/isp_proc.h

isp_regcfg.hAdd ISP register configuration model +102/-0

Add ISP register configuration model

• Defines register configuration contexts and pipeline update operations.

kernel/isp/gk7205v500/firmware/include/isp_regcfg.h

isp_sensor.hAdd ISP sensor integration +50/-0

Add ISP sensor integration

• Declares sensor registration, default loading, and register update helpers.

kernel/isp/gk7205v500/firmware/include/isp_sensor.h

isp_statistics.hAdd ISP statistics interface +30/-0

Add ISP statistics interface

• Declares statistics initialization, acquisition, and release operations.

kernel/isp/gk7205v500/firmware/include/isp_statistics.h

isp_drv_defines.hAdd ISP driver constants +174/-0

Add ISP driver constants

• Defines hardware addresses, interrupts, dimensions, and driver limits.

kernel/isp/gk7205v500/kernel/arch/include/isp_drv_defines.h

isp_drv.cAdd xm72050200 ISP hardware layer +3115/-0

Add xm72050200 ISP hardware layer

• Implements ISP register programming, statistics handling, interrupts, and hardware-specific pipeline control.

kernel/isp/gk7205v500/kernel/arch/xm72050200/hal/isp_drv.c

isp_drv.hDeclare ISP hardware-layer entry points +13/-0

Declare ISP hardware-layer entry points

• Exposes architecture-specific ISP driver operations.

kernel/isp/gk7205v500/kernel/arch/xm72050200/include/isp_drv.h

mkp_isp.hAdd ISP kernel control ABI +2791/-0

Add ISP kernel control ABI

• Defines ISP ioctl commands, contexts, buffers, events, and synchronization structures.

kernel/isp/gk7205v500/kernel/arch/xm72050200/include/mkp_isp.h

isp_init.cRegister the ISP platform driver +78/-0

Register the ISP platform driver

• Binds to xmedia,isp, resolves the ISP interrupt, and starts or stops the core driver.

kernel/isp/gk7205v500/kernel/init/linux/isp_init.c

isp.hAdd ISP core driver declarations +335/-0

Add ISP core driver declarations

• Declares core ISR, synchronization, buffer, and module lifecycle operations.

kernel/isp/gk7205v500/kernel/mkp/include/isp.h

isp_drv_vreg.hAdd ISP virtual-register driver interface +51/-0

Add ISP virtual-register driver interface

• Declares virtual-register allocation, mapping, and cleanup operations.

kernel/isp/gk7205v500/kernel/mkp/include/isp_drv_vreg.h

isp_list.hAdd ISP list interface +49/-0

Add ISP list interface

• Defines the list primitives used by ISP task and event management.

kernel/isp/gk7205v500/kernel/mkp/include/isp_list.h

isp.cAdd the XMedia ISP kernel core +8181/-0

Add the XMedia ISP kernel core

• Implements ISP devices, interrupts, ioctls, statistics, buffers, synchronization, and cross-module integration.

kernel/isp/gk7205v500/kernel/mkp/src/isp.c

isp_drv_vreg.cImplement ISP virtual registers +220/-0

Implement ISP virtual registers

• Manages allocation, mapping, lookup, and release of ISP virtual-register regions.

kernel/isp/gk7205v500/kernel/mkp/src/isp_drv_vreg.c

isp_list.cImplement ISP list management +269/-0

Implement ISP list management

• Provides synchronized list operations used by ISP runtime structures.

kernel/isp/gk7205v500/kernel/mkp/src/isp_list.c

isp_st.cImplement ISP synchronization tasks +328/-0

Implement ISP synchronization tasks

• Manages ISP synchronization task registr...

@qodo-free-for-open-source-projects

qodo-free-for-open-source-projects Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (2) 📘 Rule violations (0) 📎 Requirement gaps (0) 🎨 UX issues (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Device cleanup corrupts kernel memory ✓ Resolved 🐞 Bug ≡ Correctness
Description
media_register() and media_unregister() index the 64-entry dynamic-minor bitmap with every fixed
minor, while the new ADC and watchdog devices request minors 255 and 101. Registration failures,
device unbinding, or cleanup therefore access beyond media_minors and corrupt adjacent kernel
memory.
Code

kernel/osal/gk7205v500/media/media.c[R230-232]

+    if (err < 0) {
+        media_minors[media->minor >> 3] &= ~(1 << (media->minor & 7));
+        goto out;
Evidence
The bitmap contains only 64 minor bits, but the new devices deliberately register fixed minors above
that range and the cleanup code indexes the bitmap unconditionally.

kernel/osal/gk7205v500/media/media.c[28-30]
kernel/osal/gk7205v500/media/media.c[208-232]
kernel/osal/gk7205v500/media/media.c[270-292]
kernel/adc/gk7205v500/adc.c[337-342]
kernel/wdt/gk7205v500/wdt.c[33-33]
kernel/wdt/gk7205v500/wdt.c[484-489]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Fixed media minors outside the dynamic-minor range are used to index the dynamic-minor bitmap, causing out-of-bounds kernel writes during error handling and deregistration.
## Fix Focus Areas
- kernel/osal/gk7205v500/media/media.c[224-292]
- kernel/adc/gk7205v500/adc.c[339-340]
- kernel/wdt/gk7205v500/wdt.c[486-488]
## Recommended Fix
Only set or clear `media_minors` when the minor is below `DYNAMIC_MINORS`, including every registration error path and unregister path. Preserve support for fixed minors without representing them in the dynamic bitmap.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


2. Mappings expose adjacent physical memory ✓ Resolved 🐞 Bug ⛨ Security
Description
mmz_userdev_mmap() verifies only that the requested starting address lies in an MMZ block and
never verifies that the VMA ends within that block. A caller with raw-I/O capability can request an
oversized mapping that reaches adjacent allocations or unrelated physical pages.
Code

kernel/osal/gk7205v500/mmz/mmz-userdev.c[R803-805]

+    if (pfn_valid(vma->vm_pgoff)) {
+        unsigned long start = vma->vm_start;
+        unsigned long pfn = vma->vm_pgoff;
Evidence
Both allocation lookups compare only one address with the block bounds, after which the complete
unrestricted vm_end - vm_start range is mapped.

kernel/osal/gk7205v500/mmz/mmz-userdev.c[724-740]
kernel/osal/gk7205v500/mmz/mmz-userdev.c[803-840]
kernel/osal/gk7205v500/mmz/media-mem.c[563-577]
kernel/osal/gk7205v500/mmz/media-mem.c[598-607]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The MMZ mmap handler accepts a user-selected mapping length after validating only its starting physical address.
## Fix Focus Areas
- kernel/osal/gk7205v500/mmz/mmz-userdev.c[724-844]
- kernel/osal/gk7205v500/mmz/media-mem.c[563-607]
## Recommended Fix
Resolve the containing allocation and offset, reject overflow, and require the requested VMA length to be no greater than the allocation length minus that offset before inserting pages or calling `remap_pfn_range()`.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


3. Default builds program the wrong die ✓ Resolved 🐞 Bug ≡ Correctness
Description
chip_list defaults to xm72050200 even though the default XM_SET=V500 build selects
xm72050500, and the compile-time selection never updates this runtime value. Loading the default
module without an explicit chip argument sends the V200 identity into pinmux and clock
configuration for a V500 blob set.
Code

kernel/sys_config/gk7205v500/sys_config.c[R33-34]

+char chip_list[CHIP_NAME_STR_LEN]     = "xm72050200";  /* xm72050200 xm72050300 xm72020300 xm76050100 */
+char board_list[BOARD_NAME_LEN]   = "demo";         /* sck demo*/
Evidence
Kbuild defaults the blob and source selection to V500, but sysconfig independently initializes its
chip parameter to V200 and later passes it directly to the hardware setup functions.

kernel/gk7205v500.kbuild[32-43]
kernel/sys_config/gk7205v500/sys_config.c[30-34]
kernel/sys_config/gk7205v500/sys_config.c[236-254]
kernel/sys_config/gk7205v500/sys_config.c[1618-1621]
kernel/sys_config/gk7205v500/sys_config.c[1709-1710]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The default V500 build retains a V200 runtime chip identity, selecting the wrong pinmux and clock tables unless userspace overrides the module parameter.
## Fix Focus Areas
- kernel/gk7205v500.kbuild[32-43]
- kernel/sys_config/gk7205v500/sys_config.c[30-34]
## Recommended Fix
Derive the default `chip_list` value from the compile-time chip macro selected by `XM_SET`, while continuing to allow the module parameter and alias resolver to override it.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


View high (7)
4. Closing an idle iris blocks forever ✓ Resolved 🐞 Bug ☼ Reliability
Description
piris_close_set() always reinitializes and waits for a completion after requesting the supplied
current position. When that position already equals src_pos, the timer callback returns before
calling complete(), so the ioctl never returns.
Code

kernel/piris/gk7205v500/piris.c[R207-210]

+    init_completion(&pstPiris->piris_comp);
+    piris_gpio_update(dev, &piris_pos);
+    // wait for piris origin done
+    wait_for_completion(&pstPiris->piris_comp);
Evidence
The close ioctl waits unconditionally, whereas the timer's equal-position branch exits without
signaling the completion that releases the waiter.

kernel/piris/gk7205v500/piris.c[198-210]
kernel/piris/gk7205v500/piris.c[372-383]
kernel/piris/gk7205v500/piris.c[460-487]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
A close request whose target is already current waits on a completion that the timer callback never signals.
## Fix Focus Areas
- kernel/piris/gk7205v500/piris.c[198-210]
- kernel/piris/gk7205v500/piris.c[372-383]
- kernel/piris/gk7205v500/piris.c[460-487]
## Recommended Fix
Detect an already-satisfied target before waiting and complete or return immediately. Also use a bounded interruptible wait so hardware or timer failures cannot block the ioctl indefinitely.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


5. The platform loads without core services ✓ Resolved 🐞 Bug ☼ Reliability
Description
osal_init() discards failures from both media_init() and media_mem_init() and always returns
success. Device-bus or memory-service setup failures therefore leave OSAL reported as loaded, and
unloading can run unconditional cleanup against components whose initialization already failed or
unwound.
Code

kernel/osal/gk7205v500/osal_init.c[R18-22]

+    osal_device_init();
+    osal_proc_init();
+    media_init();
+    media_mem_init();
+    osal_printk("osal %s init success!\n", OSAL_VERSION);
Evidence
The top-level initializer ignores both integer return values, while media_init() has failure paths
that already tear down resources before returning an error.

kernel/osal/gk7205v500/osal_init.c[15-31]
kernel/osal/gk7205v500/media/media.c[303-340]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
OSAL reports successful module initialization even when its media bus or MMZ service fails to initialize.
## Fix Focus Areas
- kernel/osal/gk7205v500/osal_init.c[15-31]
- kernel/osal/gk7205v500/media/media.c[303-340]
## Recommended Fix
Check every initialization return value, unwind only previously successful stages in reverse order, and return the original error so dependent modules cannot load against unavailable services.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


6. The image driver binds after failure ✓ Resolved 🐞 Bug ☼ Reliability
Description
vendor_isp_probe() ignores the result of ISP_ModInit() and unconditionally returns zero.
Failures creating the device, proc entry, exported module, or underlying driver therefore leave the
platform core believing a partially initialized driver is bound.
Code

kernel/isp/gk7205v500/kernel/init/linux/isp_init.c[R30-32]

+    ISP_ModInit();
+
+    return 0;
Evidence
The internal initializer has several explicit failure returns, but the platform probe discards all
of them and returns success.

kernel/isp/gk7205v500/kernel/init/linux/isp_init.c[18-32]
kernel/isp/gk7205v500/kernel/mkp/src/isp.c[8102-8144]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The platform probe reports success even when the image subsystem's internal initialization fails.
## Fix Focus Areas
- kernel/isp/gk7205v500/kernel/init/linux/isp_init.c[18-32]
- kernel/isp/gk7205v500/kernel/mkp/src/isp.c[8102-8144]
## Recommended Fix
Capture and return `ISP_ModInit()`'s status from the probe. Ensure `ISP_ModInit()` unwinds each completed stage before returning its error.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


7. Failed setup can leave resets armed ✓ Resolved 🐞 Bug ☼ Reliability
Description
dog_init() starts the watchdog before creating its feeder thread, but the thread-creation failure
path only unregisters and destroys the device. If thread creation fails, initialization returns an
error while the hardware remains active and can reset the system without a feeder.
Code

kernel/wdt/gk7205v500/wdt.c[R499-501]

+    ret = dog_init();
+    if(ret) {
+        goto watchdog_init_err6;
Evidence
Hardware activation precedes feeder creation, while the corresponding error label performs device
cleanup without invoking the existing stop operation.

kernel/wdt/gk7205v500/wdt.c[184-205]
kernel/wdt/gk7205v500/wdt.c[400-419]
kernel/wdt/gk7205v500/wdt.c[495-512]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The watchdog is started before feeder creation and is not stopped when feeder creation fails.
## Fix Focus Areas
- kernel/wdt/gk7205v500/wdt.c[400-419]
- kernel/wdt/gk7205v500/wdt.c[495-512]
## Recommended Fix
Call the hardware stop routine before deregistering the device on every failure occurring after `dog_start()`, or defer starting the watchdog until all fallible setup has completed.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


8. Pin setup failures look successful ✓ Resolved 🐞 Bug ☼ Reliability
Description
sysconfig_init() routes every register-mapping failure to an out label that returns zero.
Missing clock, control, pinmux, GPIO, or PWM mappings therefore produce a successfully loaded module
even though pinmux and sensor setup were skipped.
Code

kernel/sys_config/gk7205v500/sys_config.c[R1633-1635]

+out:
+    sysconfig_instant_exit();
+    return 0;
Evidence
Each null mapping branches to the same exit label, which performs partial cleanup and always returns
zero regardless of whether initialization reached hardware configuration.

kernel/sys_config/gk7205v500/sys_config.c[1562-1616]
kernel/sys_config/gk7205v500/sys_config.c[1618-1635]
kernel/sys_config/gk7205v500/sys_config.c[1637-1698]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Sysconfig silently reports success when any required hardware register range cannot be mapped.
## Fix Focus Areas
- kernel/sys_config/gk7205v500/sys_config.c[1562-1635]
- kernel/sys_config/gk7205v500/sys_config.c[1637-1698]
## Recommended Fix
Track a negative error code for every mapping failure, unwind all mappings acquired so far, and return that error instead of zero. Print the success messages only after all hardware setup completes.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


9. ADC probe can access an invalid register map ✓ Resolved 🐞 Bug ☼ Reliability
Description
adc_probe() logs an IS_ERR() result from devm_ioremap_resource() but still passes the error
pointer in lsadc_reg to lsadc_init(), whose NULL-only check treats it as a mapped register base.
When the device tree lacks a valid ADC memory resource or mapping fails, initialization publishes a
device whose operations can use the invalid address for MMIO.
Code

kernel/init/gk7205v500/adc_init.c[R28-33]

+    lsadc_reg = (volatile void *)devm_ioremap_resource(&pdev->dev, mem);
+    if (IS_ERR((void* )lsadc_reg))
+    {
+        //printk("mem->start %#x. \n", mem->start);
+        dev_err(&pdev->dev, "lsadc reg map failed. \n");
+    }
Evidence
The probe retains the error pointer and reaches lsadc_init() after merely logging the mapping
failure, while the initializer checks only for NULL and therefore cannot distinguish an ERR_PTR
from a valid mapped register region.

kernel/init/gk7205v500/adc_init.c[27-37]
kernel/adc/gk7205v500/adc.c[305-317]
kernel/adc/gk7205v500/adc.c[339-354]
kernel/init/gk7205v500/adc_init.c[20-37]
kernel/adc/gk7205v500/adc.c[305-316]
kernel/adc/gk7205v500/adc.c[337-342]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
ADC probing continues after `devm_ioremap_resource()` returns an error pointer. The later initialization code only recognizes NULL as an absent mapping, allowing a device to be published with operations that can use the error pointer as an MMIO address.
## Fix Focus Areas
- kernel/init/gk7205v500/adc_init.c[20-37]
- kernel/adc/gk7205v500/adc.c[305-342]
## Recommended Fix
After `devm_ioremap_resource()`, test `IS_ERR(lsadc_reg)` and immediately return `PTR_ERR(lsadc_reg)` so that `lsadc_init()` is called only when resource mapping succeeds. As a defensive measure, use `IS_ERR_OR_NULL()` wherever the register pointer is validated.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


10. Local callers can corrupt kernel memory ✓ Resolved 🐞 Bug ⛨ Security
Description
SampleIst_Ioctl() directly dereferences the caller's userspace pointer and checks only whether the
resulting index is at or above MAX_TEST_NODES, allowing negative values to address memory before
syncNode. An unprivileged caller of the registered misc device can supply an invalid pointer that
immediately faults the kernel or cause both ISP registration and removal routines to receive an
out-of-bounds syncNode object.
Code

kernel/sample_ist/gk7205v500/sample_ist.c[R108-113]

+    int __user *argp = (int __user *)(XMEDIA_UINTPTR_T)arg;
+    int node_index = *argp;
+
+    if (node_index >= MAX_TEST_NODES) {
+        return -1;
+    }
Evidence
The misc device exposes SampleIst_Ioctl() directly to userspace through its Linux file operations;
the handler accesses the __user pointer without a copy operation, validates only the index's upper
bound, and uses the unchecked value in both commands to form an address within syncNode.

kernel/sample_ist/gk7205v500/sample_ist.c[106-128]
kernel/sample_ist/gk7205v500/sample_ist.c[145-156]
kernel/sample_ist/gk7205v500/sample_ist.c[160-177]
kernel/sample_ist/gk7205v500/sample_ist.c[103-128]
kernel/sample_ist/gk7205v500/sample_ist.c[144-156]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The sample IST ioctl handler dereferences a userspace address directly and permits negative node indexes, which are subsequently used to address the fixed-size `syncNode` array in registration and removal commands.
## Fix Focus Areas
- kernel/sample_ist/gk7205v500/sample_ist.c[103-128]
- kernel/sample_ist/gk7205v500/sample_ist.c[145-177]
## Recommended Fix
Use `copy_from_user()` to copy the requested index into a kernel-local integer and return `-EFAULT` if the copy fails. Before any access to `syncNode`, reject the value unless `0 <= node_index && node_index < MAX_TEST_NODES`.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Remediation recommended

11. Partial image setup leaks mappings 🐞 Bug ☼ Reliability
Description
The ISP remap routines return immediately when a later MMIO mapping fails without releasing mappings
created earlier in the same sequence. ISP_DRV_Init() propagates the error, but the enclosing
module failure path never calls ISP_DRV_Exit(), leaving scarce mappings and partial global state
behind.
Code

kernel/isp/gk7205v500/kernel/arch/xm72050200/hal/isp_drv.c[R601-604]

+
+        if (reg_viproc_base_va[IspBePhyPipe] == XMEDIA_NULL) {
+            osal_printk("Remap isp viproc[%d] failed!\n", IspBePhyPipe);
+            return XMEDIA_FAILURE;
Evidence
BE, VIPROC, VICAP, FE, and channel mappings are acquired sequentially, but failure returns bypass
the available unmap routines and the outer failure cleanup removes only proc and device
registrations.

kernel/isp/gk7205v500/kernel/arch/xm72050200/hal/isp_drv.c[588-667]
kernel/isp/gk7205v500/kernel/mkp/src/isp.c[7810-7839]
kernel/isp/gk7205v500/kernel/mkp/src/isp.c[8127-8144]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Image-driver register mapping failures leak earlier mappings and preserve partially initialized global pointers.
## Fix Focus Areas
- kernel/isp/gk7205v500/kernel/arch/xm72050200/hal/isp_drv.c[588-667]
- kernel/isp/gk7205v500/kernel/mkp/src/isp.c[7810-7830]
- kernel/isp/gk7205v500/kernel/mkp/src/isp.c[8127-8144]
## Recommended Fix
On each remap failure, unmap all ranges acquired by that routine and all earlier initialization stages, clearing their global pointers. Alternatively centralize failure unwinding in `ISP_DRV_Init()` and invoke it from every enclosing failure path.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


12. The aggregate module initializes nothing ✓ Resolved 🐞 Bug ≡ Correctness
Description
kernel/gk7205v500.kbuild builds xmedia_init.c as open_init.ko, which defines MODULE and
excludes xmedia_driver_init() together with its module_init() declaration. Loading that
generated module therefore performs none of the intended subsystem registrations, while the source's
aggregate initialization path is only usable for a built-in build.
Code

kernel/gk7205v500.kbuild[R74-77]

+$(PREFIX)init-objs := init/gk7205v500/xmedia_init.o
+$(PREFIX)wdt-objs := wdt/gk7205v500/wdt.o init/gk7205v500/wdt_init.o
+$(PREFIX)adc-objs := adc/gk7205v500/adc.o init/gk7205v500/adc_init.o
+obj-m += $(PREFIX)init.o $(PREFIX)wdt.o $(PREFIX)adc.o
Evidence
The Kbuild target compiles the source as an external module, whereas the source only defines its
initialization callback in the non-module conditional branch.

kernel/gk7205v500.kbuild[74-77]
kernel/init/gk7205v500/xmedia_init.c[14-16]
kernel/init/gk7205v500/xmedia_init.c[59-60]
kernel/init/gk7205v500/xmedia_init.c[128-131]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
`open_init.ko` is declared as a loadable module, but its only source file wraps its initialization callback and module metadata in `#ifndef MODULE`. Remove this output from the modular build, or provide a module-specific initialization implementation that does not attempt to aggregate independently loadable vendor modules.
### Fix Focus Areas
- kernel/gk7205v500.kbuild[74-77]
- kernel/init/gk7205v500/xmedia_init.c[14-131]
### Recommended Fix
Remove `$(PREFIX)init-objs` and `$(PREFIX)init.o` from the modular Kbuild configuration. Retain `xmedia_init.c` only for a future built-in configuration, where its aggregate initialization model is valid.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


13. IMX206 cameras cannot communicate 🐞 Bug ≡ Correctness
Description
sensor_bus_pin_mux() recognizes imx206 but leaves its required vi_slave_mode_mux() call
commented out and has no SPI fallback configuration. Whenever sensor_config() is given the SPI
sensor that parse_sensor_bus_type() advertises, its pins remain unmuxed before the clock is
programmed.
Code

kernel/sys_config/gk7205v500/sys_config.c[R1529-1532]

+    if (0 == strncmp("imx206", name, len))
+    {
+        //vi_slave_mode_mux();
+    }
Evidence
The new source marks IMX206 as SPI, invokes the pinmux function during every sensor configuration,
but implements neither its specific slave-mode mux call nor any generic SPI setup. The analogous
existing sysconfig implementation invokes the slave-mode mux for this same sensor.

kernel/sys_config/gk7205v500/sys_config.c[116-124]
kernel/sys_config/gk7205v500/sys_config.c[1523-1556]
kernel/sys_config/hi3516cv500/sys_config.c[908-924]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The new sysconfig source classifies `imx206` as an SPI sensor but does not configure its slave-mode pins. The only relevant pinmux call is present but commented out, leaving the sensor bus unusable.
### Fix Focus Areas
- kernel/sys_config/gk7205v500/sys_config.c[1523-1540]
- kernel/sys_config/gk7205v500/sys_config.c[1543-1556]
### Recommended Fix
Call `vi_slave_mode_mux()` for the `imx206` case, and preserve an explicit SPI configuration path if further SPI sensors are supported. Verify the corresponding sensor clock selection while enabling this path.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Tip of the day
💡 Did you know, you can enable the Remediation agent and Qodo fixes findings in a dedicated fix PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread kernel/osal/gk7205v500/media/media.c
Comment thread kernel/osal/gk7205v500/mmz/mmz-userdev.c
Comment thread kernel/sys_config/gk7205v500/sys_config.c
Comment thread kernel/piris/gk7205v500/piris.c Outdated
Comment thread kernel/osal/gk7205v500/osal_init.c
Comment thread kernel/isp/gk7205v500/kernel/arch/xm72050200/hal/isp_drv.c
Comment thread kernel/gk7205v500.kbuild Outdated
Comment thread kernel/init/gk7205v500/adc_init.c
Comment thread kernel/sample_ist/gk7205v500/sample_ist.c
Comment thread kernel/sys_config/gk7205v500/sys_config.c
SPC020's V200 sys gates SYS_ModInit on efuse 0x100a0028 bits [7:4] and
accepts only 1..8 and 10..12. GK7201V200 fuses 0xD4 (nibble 13), so sys
prints "SDK version do NOT support this chip!!!", its probe fails, and
rgn then dereferences the missing sys function table -- the RGN_Init
oops reported in OpenIPC/firmware#2428. The vendor's Jan 2024 sys, as
shipped on these cameras, accepts 0xD0/0xD4.

scripts/xm-sys-fuse-gk7201v200.sh rewrites the last whitelist entry in
place, same length:

  ubfx r3, r3, #4, #4 ; cmp r3, #12   (bits[7:4] == 12)
  ubfx r3, r3, #5, #3 ; cmp r3, #6    (bits[7:5] == 6: nibble 12 or 13)

so every chip accepted before still is. It refuses any input but the
SPC020 V200 sys.o (md5-pinned; the V500 object has the same bytes at the
same offset) and the committed object stays byte-identical to the SDK.

Hardware (GK7201V200 / MIS2008, openipc/linux 4.9.37 with CONFIG_PM and
CONFIG_MODULE_UNLOAD off and the devfreq userspace governor on):
load_goke detects mis2008, and osal, sysconfig, base, sys, rgn, vgs, vi,
isp, vpss, chnl, vedu, rc, venc, h264e, h265e, jpege, ive, sensor_i2c/
spi, audio and mipi_rx all load -- 26 modules, no oops.
… MIS2008

Replaces the sys.o byte patch. Widening sys's start-up whitelist was not
enough: vi (145 sites), vpss (107) and venc (54) also key their
capabilities on the efuse SKU byte at 0x100a0028, and with GK7201V200's
0xD4 venc refuses every channel (F008FFFF -- the error in
OpenIPC/firmware#2464). The vendor's 2024 blobs know 0xD0/0xD4; SPC020
does not.

They all read it through the pointer sys hands out, and sys maps it with
osal_ioremap. So the V200 sys.o is relinked with osal_ioremap/iounmap
redefined (objcopy) to init/gk7205v500/sys_efuse_shadow.c, which serves
the efuse block from a RAM copy of its first 0x100 bytes (the modules
read 0x10, 0x28, 0x34) with a 0xDx code presented as 0x1x -- the code
stock's own vi groups 0xD0 with. Other mappings and codes pass through;
efuse_sku= overrides the byte. The committed sys.o stays SDK-identical.

libraries/sensor/gk7205v500/imagedesign_mis2008: the hi3516ev200 driver
ported to the XMedia API (GK_* -> XMEDIA_*, gk_api_*.h ->
xmedia_api_*.h), built against the SDK ISP headers now imported under
kernel/isp/gk7205v500/include. The SDK ships no MIS2008 driver; stock
links one into its App.

Hardware (GK7201V200 / MIS2008, majestic lite with the SDK V200
userspace): "sys: efuse SKU 0xd4 presented as 0x14", MIS2008 initialises
at 1080p, VENC channel created, RTSP serves H.264 1920x1080 25 fps.
Image quality is not there yet: the picture is washed out and magenta
with AE at minimum exposure, while VI/MIPI attributes, Bayer order and
black level all match stock -- the sensor init/ISP defaults inherited
from the ev200 driver are the next suspect.
@widgetii

Copy link
Copy Markdown
Member Author

Correction to the image-quality note in 849837d: the test camera had no lens mounted (so no IR-cut filter and no focus). A bare sensor flooded with unfocused light and IR gives exactly what was seen -- AE at minimum exposure, a flat frame, and a magenta cast with AWB lost (CoTemp 14084 K). VI/MIPI attributes, Bayer order and black level match stock, and AE register writes reach the sensor (0x3100 read back = the AE line count). So there is no evidence against the MIS2008 port; image quality still needs a check with the lens back on.

@widgetii

Copy link
Copy Markdown
Member Author

Lens back on: the GK7201V200 / MIS2008 camera streams a normal image -- H.264 1920x1080 25 fps over RTSP from majestic, correct colours, AE and AWB settled. That closes the image-quality question from 849837d: the magenta frame was the missing lens/IR-cut, and the MIS2008 port (hi3516ev200 driver moved to the XMedia API) works as is.

Review follow-up (qodo on #229) for the XMedia SDK sources:

- osal media: release a minor from the dynamic bitmap only if it is in
  range; fixed minors (the watchdog's 130) were cleared past its end on
  every failure/unregister path.
- mmz mmap: bound the mapping to the rest of the mmb it starts in; only
  the start address was checked, so an oversized request mapped whatever
  physical memory followed.
- sys_config: default chip follows XM_SET (xm72050500 for V500 builds,
  not xm72050200); a register block that cannot be mapped now fails the
  load and unmaps instead of reporting success with nothing configured.
  The unmap moved out of the __exit function, which a MODULE_UNLOAD=n
  kernel discards.
- osal_init: propagate media/mmz init failures and unwind.
- isp probe: return -ENODEV on a missing IRQ (was XMEDIA_FALSE, i.e. 0)
  and on ISP_ModInit failure.
- wdt: stop the watchdog if its feeder thread cannot be started.
- adc probe: stop on an ioremap error instead of using the ERR_PTR.
- sample_ist ioctl: copy_from_user the node index and reject negatives.
- piris close: do not wait for a move to the current position (the timer
  never completes it); bound the wait.
- drop open_init.ko: xmedia_init.c only does anything built-in (#ifndef
  MODULE), so the module was empty.

Rechecked on the GK7201V200 / MIS2008 camera: 26 modules, no oops, no
mmap rejections, majestic streams 1080p25 H.264 with a correct image.
@widgetii
widgetii merged commit 1920d9c into main Sep 25, 2026
35 checks passed
@widgetii
widgetii deleted the gk7205v500-xmedia branch September 25, 2026 11:30
widgetii added a commit that referenced this pull request Sep 25, 2026
#229 added libraries/sensor/gk7205v500/imagedesign_mis2008, a copy of the
hi3516ev200 MIS2008 driver with GK_* renamed to XMEDIA_*. That is the same
driver twice: the XMedia SPC020 sensor interface is the V4 one rebranded,
the same relationship HiSilicon's and Goke's already have and that
include/hicompat.h bridges for the V4 drivers.

So the copy goes, and CHIPARCH=gk7205v500 builds sensor/hi3516ev200 like
the other V4 targets. sensor/compat/xmedia maps the drivers' Goke names
onto the SDK:

- xm_gk_compat.h: GK_*/gk_* types and constants onto XMEDIA_*. Force-
  included: the drivers often get the Goke types only through the SDK
  headers, and those include their own type.h relative to themselves, so
  shadowing type.h on the include path cannot reach them;
- gk_api_{isp,ae,awb}.h, hicompat.h: GK_API_* onto XMEDIA_API_*, with the
  SDK's own prototypes.

libraries/Makefile puts these and the SDK headers imported under kernel/
ahead of the V4 include/ the per-sensor Makefiles add; no driver or
per-sensor Makefile changes.

All 30 V4 sensor drivers now build for gk7205v500 (before: only MIS2008,
as the copy), with no warning the gk7205v200 build of the same sources
does not already have; gk7205v200 still builds all 30. On the GK7201V200 /
MIS2008 camera the shared-source libsns_mis2008.so initialises the sensor
and majestic streams 1080p25 H.264 with a correct image.
widgetii added a commit that referenced this pull request Sep 25, 2026
* gk7205v500: build the V4 sensor drivers from their one source

#229 added libraries/sensor/gk7205v500/imagedesign_mis2008, a copy of the
hi3516ev200 MIS2008 driver with GK_* renamed to XMEDIA_*. That is the same
driver twice: the XMedia SPC020 sensor interface is the V4 one rebranded,
the same relationship HiSilicon's and Goke's already have and that
include/hicompat.h bridges for the V4 drivers.

So the copy goes, and CHIPARCH=gk7205v500 builds sensor/hi3516ev200 like
the other V4 targets. sensor/compat/xmedia maps the drivers' Goke names
onto the SDK:

- xm_gk_compat.h: GK_*/gk_* types and constants onto XMEDIA_*. Force-
  included: the drivers often get the Goke types only through the SDK
  headers, and those include their own type.h relative to themselves, so
  shadowing type.h on the include path cannot reach them;
- gk_api_{isp,ae,awb}.h, hicompat.h: GK_API_* onto XMEDIA_API_*, with the
  SDK's own prototypes.

libraries/Makefile puts these and the SDK headers imported under kernel/
ahead of the V4 include/ the per-sensor Makefiles add; no driver or
per-sensor Makefile changes.

All 30 V4 sensor drivers now build for gk7205v500 (before: only MIS2008,
as the copy), with no warning the gk7205v200 build of the same sources
does not already have; gk7205v200 still builds all 30. On the GK7201V200 /
MIS2008 camera the shared-source libsns_mis2008.so initialises the sensor
and majestic streams 1080p25 H.264 with a correct image.

* mis2008: stop the Dgain lookup reading 15 entries past its table

cmos_dgain_calc_table() used a hard-coded size of 255 for Dgain_table[],
which has 240 entries, so its saturation check read Dgain_table[254] --
whatever the linker put after the table -- and returned that as the
sensor digital gain. What that is depends on the build: an -O0 build
happened to get a large value and behaved, the optimised firmware build
of the same source gets 0. With a Dgain of 0 the AE's system gain is 0,
so it holds exposure short and makes the picture up with ~4x ISP digital
gain -- a noisy, yellow-cast image (seen on GK7201V200: Line 64, Again
1x, Dgain 0, IspDg 4176, ISO 0).

The size now comes from the table. Same camera, same scene, firmware
build: Line 2694, Again 8x, Dgain 1024, IspDg ~1x, ISO 843, clean image.
The bug is in the shared V4 driver, so hi3516ev200/gk7205v200 builds had
it too.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant