From: sashiko-bot@kernel.org
To: "Louis Chauvet" <louis.chauvet@bootlin.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v5 23/38] drm/vkms: Introduce configfs for plane format
Date: Sat, 27 Jun 2026 03:45:06 +0000 [thread overview]
Message-ID: <20260627034506.ECB191F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260627-vkms-all-config-v5-23-854aa0840926@bootlin.com>
Thank you for your contribution! Sashiko AI review found 5 potential issue(s) to consider:
- [High] Strict length validation in `plane_supported_formats_store` rejects valid shell inputs containing trailing newlines.
- [High] Type punning between a `char` array and `int *` causes unaligned memory accesses and produces corrupted FourCC codes on big-endian architectures.
- [High] Missing `plane->dev->enabled` check in `plane_supported_formats_store` allows userspace to modify formats while the device is active, causing a Use-After-Free.
- [Medium] Incorrect pointer arithmetic in `vkms_configfs_parse_next_format` results in a negative length, defeating bounds checking for `strnchr`.
- [Low] `vkms_configfs_parse_next_format` is completely unused in the operational driver and causes a build failure when KUnit is disabled.
--
commit a7abf4a30e4c9317197078c2d2f5f96c79800929
Author: Louis Chauvet <louis.chauvet@bootlin.com>
Subject: drm/vkms: Introduce configfs for plane format
This commit introduces a configfs interface to configure the available
formats per planes in VKMS. It adds parsing logic and test cases to
allow userspace to test multiple hardware configurations.
> diff --git a/drivers/gpu/drm/vkms/vkms_configfs.c b/drivers/gpu/drm/vkms/vkms_configfs.c
> --- a/drivers/gpu/drm/vkms/vkms_configfs.c
> +++ b/drivers/gpu/drm/vkms/vkms_configfs.c
[ ... ]
> +static ssize_t plane_supported_formats_show(struct config_item *item, char *page)
> +{
> + struct vkms_configfs_plane *plane;
> +
> + plane = plane_item_to_vkms_configfs_plane(item);
> +
> + page[0] = '\0';
> +
> + scoped_guard(mutex, &plane->dev->lock) {
> + u32 *formats = vkms_config_plane_get_supported_formats(plane->config);
> +
> + for (int i = 0;
> + i < vkms_config_plane_get_supported_formats_count(plane->config);
> + i++) {
> + char tmp[6] = { 0 };
> + const ssize_t ret = snprintf(tmp, ARRAY_SIZE(tmp), "%.*s\n",
> + (int)sizeof(*formats),
> + (char *)&formats[i]);
[Severity: High]
Does this cast to a char pointer cause endianness issues on big-endian
architectures?
Since DRM FourCC codes are strictly little-endian, interpreting the integer
directly as a character array might reverse the format string on big-endian
machines.
> + if (ret < 0)
> + return ret;
[ ... ]
> +VISIBLE_IF_KUNIT
> +int vkms_configfs_parse_next_format(const char *page, const char *page_end, char **out)
[Severity: Low]
Since this function isn't called anywhere in the operational driver paths, does
it cause a -Wunused-function build failure when CONFIG_KUNIT is disabled and
VISIBLE_IF_KUNIT evaluates to static?
> +{
> + int count = page - page_end;
[Severity: Medium]
Since page comes before page_end in memory, won't this calculation result in a
negative count?
When passed to strnchr() which takes a size_t, won't this negative value
become a massive positive integer and bypass the bounds check?
> + char *tmp_plus = strnchr(page, count, '+');
> + char *tmp_minus = strnchr(page, count, '-');
[ ... ]
> +static ssize_t plane_supported_formats_store(struct config_item *item,
> + const char *page, size_t count)
> +{
> + struct vkms_configfs_plane *plane;
> +
> + plane = plane_item_to_vkms_configfs_plane(item);
> + int ret = 0;
> +
> + if (count < 2 || count > 5)
> + return -EINVAL;
> +
> + if (page[0] != '+' && page[0] != '-')
> + return -EINVAL;
> +
> + if (page[1] == '*' && count != 2)
> + return -EINVAL;
[Severity: High]
Does this rigid length validation reject standard shell inputs?
When users configure the format using standard commands like
echo "+AR24" > supported_formats, the shell appends a trailing newline,
making the count 6 instead of 5. For echo "+*", the count becomes 3 instead
of 2.
Will this prevent userspace from using the interface as documented?
> +
> + scoped_guard(mutex, &plane->dev->lock) {
[Severity: High]
Should there be a check here to ensure the device is not enabled, similar to
other configfs store functions like plane_zpos_enabled_store()?
If userspace modifies or clears the supported formats while the virtual DRM
device is active, vkms_config_plane_remove_all_formats() frees the formats
array. Could this lead to a use-after-free if the rendering pipeline is
concurrently accessing it?
For example, shouldn't we have:
if (plane->dev->enabled)
return -EBUSY;
> + char fmt[4] = {' ', ' ', ' ', ' '};
> +
> + memcpy(fmt, &page[1], min(count - 1, 4));
> +
> + if (page[0] == '+' && page[1] == '*')
> + ret = vkms_config_plane_add_all_formats(plane->config);
> + else if (page[0] == '-' && page[1] == '*')
> + vkms_config_plane_remove_all_formats(plane->config);
> + else if (page[0] == '+')
> + ret = vkms_config_plane_add_format(plane->config, *(int *)fmt);
[Severity: High]
Does casting this 4-byte character array to an int pointer risk alignment
faults?
If the character array on the stack is not 4-byte aligned, won't this cause
a panic on architectures that enforce strict alignment?
Additionally, similar to the show() function, does this type punning create
endianness issues on big-endian systems?
> + else if (page[0] == '-')
> + vkms_config_plane_remove_format(plane->config, *(int *)fmt);
> +
> + if (ret)
> + return ret;
> + }
> +
> + return count;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260627-vkms-all-config-v5-0-854aa0840926@bootlin.com?part=23
next prev parent reply other threads:[~2026-06-27 3:45 UTC|newest]
Thread overview: 65+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-27 3:30 [PATCH v5 00/38] VKMS: Introduce multiple configFS attributes Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 01/38] drm/drm_mode_config: Add helper to get plane type name Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 02/38] drm/blend: Get a rotation name from it's bitfield Louis Chauvet
2026-06-27 3:41 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 03/38] drm/drm_color_mgmt: Expose drm_get_color_encoding_name Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 04/38] drm/drm_color_mgmt: Expose drm_get_color_range_name Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 05/38] drm/connector: Export drm_get_colorspace_name Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 06/38] drm/drm_atomic_state_helper: Properly load default value for rotation Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 07/38] Documentation: ABI: vkms: Add current VKMS ABI documentation Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 08/38] drm/vkms: Add error handling in plane config creation Louis Chauvet
2026-06-27 3:41 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 09/38] drm/vkms: Simplify plane_release code Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 10/38] drm/vkms: Explicitly display plane type Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 11/38] drm/vkms: Use enabled/disabled instead of 1/0 for debug Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 12/38] drm/vkms: Explicitly display connector status Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 13/38] drm/vkms: Introduce config for plane name Louis Chauvet
2026-06-27 3:46 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 14/38] drm/vkms: Use plane folder name as " Louis Chauvet
2026-06-27 3:43 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 15/38] drm/vkms: Introduce config for plane rotation Louis Chauvet
2026-06-27 3:42 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 16/38] drm/vkms: Use DRM_ROTATION_FMT macros for rotation display Louis Chauvet
2026-06-27 3:39 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 17/38] drm/vkms: Introduce configfs for plane rotation Louis Chauvet
2026-06-27 3:46 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 18/38] drm/vkms: Introduce config for plane color encoding Louis Chauvet
2026-06-27 3:43 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 19/38] drm/vkms: Introduce configfs " Louis Chauvet
2026-06-27 3:49 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 20/38] drm/vkms: Introduce config for plane color range Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 21/38] drm/vkms: Introduce configfs " Louis Chauvet
2026-06-27 3:45 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 22/38] drm/vkms: Introduce config for plane format Louis Chauvet
2026-06-27 3:46 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 23/38] drm/vkms: Introduce configfs " Louis Chauvet
2026-06-27 3:45 ` sashiko-bot [this message]
2026-06-27 3:30 ` [PATCH v5 24/38] drm/vkms: Properly render plane using their zpos Louis Chauvet
2026-06-27 3:44 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 25/38] drm/vkms: Introduce config for plane zpos property Louis Chauvet
2026-06-27 3:41 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 26/38] drm/vkms: Introduce configfs " Louis Chauvet
2026-06-27 3:46 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 27/38] drm/vkms: Introduce config for connector type Louis Chauvet
2026-06-27 3:45 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 28/38] drm/vkms: Introduce configfs " Louis Chauvet
2026-06-27 3:45 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 29/38] drm/vkms: Rename vkms_connector_init to vkms_connector_init_static Louis Chauvet
2026-06-27 3:30 ` [PATCH v5 30/38] drm/vkms: Introduce config for connector supported colorspace Louis Chauvet
2026-06-27 3:58 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 31/38] drm/vkms: Introduce configfs " Louis Chauvet
2026-06-27 3:48 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 32/38] drm/vkms: Introduce config for connector EDID Louis Chauvet
2026-06-27 3:48 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 33/38] drm/vkms: Introduce configfs " Louis Chauvet
2026-06-27 3:50 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 34/38] drm/vkms: Store the enabled/disabled status for connector Louis Chauvet
2026-06-27 3:48 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 35/38] drm/vkms: Allow to hot-add connectors Louis Chauvet
2026-06-27 3:50 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 36/38] drm/vkms: Introduce configfs for dynamic connector creation Louis Chauvet
2026-06-27 3:55 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 37/38] drm/vkms: Add connector parent configuration in vkms_config Louis Chauvet
2026-06-27 3:57 ` sashiko-bot
2026-06-27 3:30 ` [PATCH v5 38/38] drm/vkms: Add ConfigFS interface for connector parent and port_id Louis Chauvet
2026-06-27 3:45 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260627034506.ECB191F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=louis.chauvet@bootlin.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.