Commit 538d10d187 for ffmpeg
commit 538d10d1878fb546c3a2645efa56119848f9ccfc
Author: Diego de Souza <ddesouza@nvidia.com>
Date: Thu Oct 8 15:23:51 2026 +0200
avcodec/dxva2: fix frame->buf[] data race with frame threading
ff_dxva2_common_end_frame() adds a reference to the decoder to
frame->buf[], so that the decoder outlives the frames decoded with it.
It is called from the hwaccel end_frame() callback, which with frame
threading may run after ff_thread_finish_setup(). From that point on,
other threads may copy the frame: the H.264 decoder keeps a separate
AVFrame per picture in each thread and synchronizes them in
update_thread_context() with av_frame_replace(), which reads
frame->buf[] while the decoding thread may be writing to it. As noted
in fa77cb258b ("avcodec/h264dec: Fix data race when updating
decode_error_flags"), a decoding thread must not modify any field that
av_frame_ref() copies after ff_thread_finish_setup().
This has been observed as an intermittent access violation in
av_buffer_replace() when decoding H.264 with D3D11VA and frame
threading on Windows on Arm: the copying thread read a non-NULL
frame->buf[1] entry, but saw the fields of the AVBufferRef it points
to as zero, and dereferenced the NULL buffer pointer when incrementing
the reference count.
Store the decoder reference in FrameDecodeData.hwaccel_priv instead,
as nvdec does for its per-frame state. The decode data is attached to
frame->private_ref when the buffer is allocated, before
ff_thread_finish_setup(), and all references to the frame share it, so
update_thread_context() only takes a new reference to it. The decoder
reference is added to frame->buf[] by hwaccel_priv_post_process(),
which runs in the caller's thread when the frame is returned, so
returned frames keep the decoder alive. Since the decode data
is shared, the second field of a field pair no longer adds a second
decoder reference to the frame.
Signed-off-by: Diego de Souza <ddesouza@nvidia.com>
diff --git a/libavcodec/dxva2.c b/libavcodec/dxva2.c
index 5817a0e7d7..6919d52680 100644
--- a/libavcodec/dxva2.c
+++ b/libavcodec/dxva2.c
@@ -927,6 +927,20 @@ static int frame_add_buf(AVFrame *frame, AVBufferRef *ref)
return AVERROR(EINVAL);
}
+static void dxva2_frame_priv_free(void *priv)
+{
+ AVBufferRef *decoder_ref = priv;
+
+ av_buffer_unref(&decoder_ref);
+}
+
+static int dxva2_frame_post_process(void *logctx, AVFrame *frame)
+{
+ const FrameDecodeData *fdd = frame->private_ref;
+
+ return frame_add_buf(frame, fdd->hwaccel_priv);
+}
+
int ff_dxva2_common_end_frame(AVCodecContext *avctx, AVFrame *frame,
const void *pp, unsigned pp_size,
const void *qm, unsigned qm_size,
@@ -949,9 +963,24 @@ int ff_dxva2_common_end_frame(AVCodecContext *avctx, AVFrame *frame,
FFDXVASharedContext *sctx = DXVA_SHARED_CONTEXT(avctx);
if (sctx->decoder_ref) {
- result = frame_add_buf(frame, sctx->decoder_ref);
- if (result < 0)
- return result;
+ FrameDecodeData *fdd = frame->private_ref;
+
+ /* With frame threading, this may run after ff_thread_finish_setup(),
+ * when other threads may already be copying this AVFrame, so its
+ * buf[] array must not be modified here. Store the decoder
+ * reference in the per-frame decode data, which all references to
+ * the frame share, and add it to frame->buf[] once the frame is
+ * output. The second field of a field pair reuses the reference
+ * stored for the first. */
+ if (!fdd->hwaccel_priv) {
+ AVBufferRef *decoder_ref = av_buffer_ref(sctx->decoder_ref);
+ if (!decoder_ref)
+ return AVERROR(ENOMEM);
+
+ fdd->hwaccel_priv = decoder_ref;
+ fdd->hwaccel_priv_free = dxva2_frame_priv_free;
+ fdd->hwaccel_priv_post_process = dxva2_frame_post_process;
+ }
}
do {