From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 64AB7C433FE for ; Mon, 15 Nov 2021 11:31:31 +0000 (UTC) Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 32D4D61BC1 for ; Mon, 15 Nov 2021 11:31:31 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org 32D4D61BC1 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=cerno.tech Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=lists.freedesktop.org Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id 06C3F6E8A5; Mon, 15 Nov 2021 11:31:25 +0000 (UTC) Received: from wnew2-smtp.messagingengine.com (wnew2-smtp.messagingengine.com [64.147.123.27]) by gabe.freedesktop.org (Postfix) with ESMTPS id 332096E8A5 for ; Mon, 15 Nov 2021 11:31:24 +0000 (UTC) Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailnew.west.internal (Postfix) with ESMTP id 3F8DF2B0117B; Mon, 15 Nov 2021 06:31:23 -0500 (EST) Received: from mailfrontend1 ([10.202.2.162]) by compute4.internal (MEProxy); Mon, 15 Nov 2021 06:31:24 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cerno.tech; h= from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; s=fm1; bh=qY59QflZqGdib KtuT1mhf0ArM0xf5eWjNaPb+uKRHcE=; b=TDloX5bCEyhVXNV9oO7zA0De/PYJD Ph0VMraygAPB5VUaVoWNcS5c9vS9ZJdpgk8wVzmANWbXGs1V42GCZ+TedO5QtbVm 3EgHp+e2zBGoeGgsFtH3Z3i+Ql6KGTx2RxMMNDYY3YrzIBuHyDwTRkEMorjsg29U qH6rMjiwJaVUVpYOWlrbKi3fWV+3s3NwB+Dt65kbofThejA76rnR7EP8M1jK+F7k mNEqp4eF8CbilIbJokJW6MN4PbYctncxujSS4bWOHsHFu20Do+gLsT2IkeZfyrOs bStJKkRJ3MlPWMmRa7mHjdu0Vw0EFzuqmEDb14Yipo8aKz1Us/41RSASg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:date:from :in-reply-to:message-id:mime-version:references:subject:to :x-me-proxy:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm1; bh=qY59QflZqGdibKtuT1mhf0ArM0xf5eWjNaPb+uKRHcE=; b=YNZ3Pddh bC1cfFgV5MeBXIK5GpbZgcC/8nUQzpgvHBiPzEs8LTJeCh+pn2il07GT1joAcW+T /2GGexvkQPUzIJSgpZOJ43zESOUT7d28tvzolPu1LGo4lZ8FqTPiijkWcaaNPKAr TypwGphWhc2de/nrCtv/ufWIa50GjXAL/ox5lEAJJyDtbtCt0bdTcMY6XigN6TEJ j2Dg9eYUpdhTXW/XZ37XKCaNs63zKVySW5JNr8cVBFkj1JwhN/13gsVwgfRfPn9p 7q90tr+QVcg7ftBdSTrvlIt/pAVSiprrEQP7+plDeY17gpZgguzT0BUL4zzDPfMv gVZGZyqdHocMPw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvuddrfedtgddtfecutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu uegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenuc fjughrpefhvffufffkofgjfhgggfestdekredtredttdenucfhrhhomhepofgrgihimhgv ucftihhprghrugcuoehmrgigihhmvgestggvrhhnohdrthgvtghhqeenucggtffrrghtth gvrhhnpedvkeelveefffekjefhffeuleetleefudeifeehuddugffghffhffehveevheeh vdenucevlhhushhtvghrufhiiigvpedunecurfgrrhgrmhepmhgrihhlfhhrohhmpehmrg igihhmvgestggvrhhnohdrthgvtghh X-ME-Proxy: Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 15 Nov 2021 06:31:22 -0500 (EST) From: Maxime Ripard To: Maarten Lankhorst , Thomas Zimmermann , Maxime Ripard , Daniel Vetter , David Airlie Subject: [PATCH 4/6] drm/vc4: kms: Clear the HVS FIFO commit pointer once done Date: Mon, 15 Nov 2021 12:31:03 +0100 Message-Id: <20211115113105.103275-5-maxime@cerno.tech> X-Mailer: git-send-email 2.33.1 In-Reply-To: <20211115113105.103275-1-maxime@cerno.tech> References: <20211115113105.103275-1-maxime@cerno.tech> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: dri-devel@lists.freedesktop.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Direct Rendering Infrastructure - Development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Dom Cobley , Tim Gover , Dave Stevenson , Jian-Hong Pan , dri-devel@lists.freedesktop.org, Phil Elwell Errors-To: dri-devel-bounces@lists.freedesktop.org Sender: "dri-devel" Commit 9ec03d7f1ed3 ("drm/vc4: kms: Wait on previous FIFO users before a commit") introduced a wait on the previous commit done on a given HVS FIFO. However, we never cleared that pointer once done. Since drm_crtc_commit_put can free the drm_crtc_commit structure directly if we were the last user, this means that it can lead to a use-after free if we were to duplicate the state, and that stale pointer would even be copied to the new state. Set the pointer to NULL once we're done with the wait so that we don't carry over a pointer to a free'd structure. Fixes: 9ec03d7f1ed3 ("drm/vc4: kms: Wait on previous FIFO users before a commit") Signed-off-by: Maxime Ripard --- drivers/gpu/drm/vc4/vc4_kms.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/gpu/drm/vc4/vc4_kms.c b/drivers/gpu/drm/vc4/vc4_kms.c index 4847d1af399a..217a2009c651 100644 --- a/drivers/gpu/drm/vc4/vc4_kms.c +++ b/drivers/gpu/drm/vc4/vc4_kms.c @@ -374,6 +374,7 @@ static void vc4_atomic_commit_tail(struct drm_atomic_state *state) drm_err(dev, "Timed out waiting for commit\n"); drm_crtc_commit_put(commit); + old_hvs_state->fifo_state[channel].pending_commit = NULL; } if (vc4->hvs->hvs5) -- 2.33.1