All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Chaitanya Kumar Borah" <chaitanya.kumar.borah@intel.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [v5 09/14] drm/i915/color: Add support for 1D LUT in SDR planes
Date: Mon, 20 Jul 2026 05:28:28 +0000	[thread overview]
Message-ID: <20260720052829.0B3191F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260720045131.971650-10-chaitanya.kumar.borah@intel.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

Pre-existing issues:
- [High] This problem wasn't introduced by this patch, but if colorop initialization fails early, the cleanup path calls `intel_colorop_destroy()` on a partially initialized object, leading to a NULL pointer dereference and uninitialized list head usage.
- [High] This problem wasn't introduced by this patch, but an unchecked return value from `kasprintf()` leads to a NULL pointer dereference when creating the color pipeline property.
--

--- Patch [9]: [v5 09/14] drm/i915/color: Add support for 1D LUT in SDR planes ---
commit e6938001b7cb4179a20fa4b4c3bd94fef8282c50
Author: Chaitanya Kumar Borah <chaitanya.kumar.borah@intel.com>

drm/i915/color: Add support for 1D LUT in SDR planes

Extend the SDR plane color pipeline to include pre- and post-CSC 1D LUT blocks.
SDR planes use a smaller LUT size than HDR planes and therefore initialize the
1D LUT colorops with the appropriate hardware capacity.

> diff --git a/drivers/gpu/drm/i915/display/intel_color_pipeline.c b/drivers/gpu/drm/i915/display/intel_color_pipeline.c
> index 7457fa51cb97a..136b9378ca484 100644
> --- a/drivers/gpu/drm/i915/display/intel_color_pipeline.c
> +++ b/drivers/gpu/drm/i915/display/intel_color_pipeline.c

[ ... ]

> @@ -81,7 +86,9 @@ struct intel_colorop *intel_color_pipeline_plane_add_colorop(struct drm_plane *p
>  		ret = drm_plane_colorop_curve_1d_lut_init(dev,
>  							  &colorop->base, plane,
>  							  &intel_colorop_funcs,
> -							  PLANE_DEGAMMA_SIZE,
> +							  is_hdr ?
> +							  PLANE_DEGAMMA_SIZE :
> +							  PLANE_DEGAMMA_SIZE_SDR,
>  							  DRM_COLOROP_LUT1D_INTERPOLATION_LINEAR,
>  							  DRM_COLOROP_FLAG_ALLOW_BYPASS);
>  		break;

[Severity: High]
This isn't a bug introduced by this patch, but if colorop initialization fails
early, the cleanup path calls intel_colorop_destroy() on a partially
initialized object. Could this lead to a NULL pointer dereference and
uninitialized list head usage?

If drm_plane_colorop_init() fails early (e.g., drm_mode_object_add() returns
-ENOMEM), colorop->dev remains NULL and colorop->head is zero-filled. The error
path jumps to cleanup and invokes intel_colorop_destroy(), which delegates to
drm_colorop_cleanup():

drivers/gpu/drm/drm_colorop.c:drm_colorop_cleanup() {
    struct drm_mode_config *config = &dev->mode_config;

    list_del(&colorop->head);
    config->num_colorop--;
}

This unconditionally dereferences dev (which is NULL) and calls list_del() on a
zero-filled list head.

[Severity: High]
This is also a pre-existing issue in the same file, but an unchecked return
value from kasprintf() can lead to a NULL pointer dereference when creating the
color pipeline property.

In _intel_color_pipeline_plane_init(), kasprintf() allocates memory for
list->name:

drivers/gpu/drm/i915/display/intel_color_pipeline.c:_intel_color_pipeline_plane_init() {
    ...
    list->name = kasprintf(GFP_KERNEL, "Color Pipeline %d", colorop[0]->base.base.id);

    return 0;
}

If kasprintf() fails, it returns NULL, and the function unconditionally returns
success. This NULL name is later passed to drm_property_add_enum(), where a
strlen(name) call will crash the kernel:

drivers/gpu/drm/drm_property.c:drm_property_add_enum() {
    ...
    if (WARN_ON(strlen(name) >= DRM_PROP_NAME_LEN))
        return 0;
    ...
}

Should the return value of kasprintf() be checked and handled as an error here?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260720045131.971650-1-chaitanya.kumar.borah@intel.com?part=9

  reply	other threads:[~2026-07-20  5:28 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-20  4:51 [v5 00/14] drm/i915/color: Enable SDR plane color pipeline Chaitanya Kumar Borah
2026-07-20  4:51 ` [v5 01/14] drm/colorop: Add DRM_COLOROP_FIXED_MATRIX Chaitanya Kumar Borah
2026-07-20  5:22   ` sashiko-bot
2026-07-20  4:51 ` [v5 02/14] drm/i915/color: Add CSC on SDR plane color pipeline Chaitanya Kumar Borah
2026-07-20  5:33   ` sashiko-bot
2026-07-20  4:51 ` [v5 03/14] drm/i915/display: extract glk_plane_color_ctl_input_csc helper Chaitanya Kumar Borah
2026-07-20  4:51 ` [v5 04/14] drm/i915/display: simplify glk_plane_color_ctl_input_csc Chaitanya Kumar Borah
2026-07-20  4:51 ` [v5 05/14] drm/i915/display: Track CSC mode in intel plane state Chaitanya Kumar Borah
2026-07-20  5:28   ` sashiko-bot
2026-07-20  4:51 ` [v5 06/14] drm/i915/display: Program input CSC on SDR planes Chaitanya Kumar Borah
2026-07-20  5:27   ` sashiko-bot
2026-07-20  4:51 ` [v5 07/14] drm/i915/color: Add YCbCr limited-to-full range color block support Chaitanya Kumar Borah
2026-07-20  5:28   ` sashiko-bot
2026-07-20  4:51 ` [v5 08/14] drm/i915/color: Add YUV range correction to SDR plane pipeline Chaitanya Kumar Borah
2026-07-20  5:29   ` sashiko-bot
2026-07-20  4:51 ` [v5 09/14] drm/i915/color: Add support for 1D LUT in SDR planes Chaitanya Kumar Borah
2026-07-20  5:28   ` sashiko-bot [this message]
2026-07-20  4:51 ` [v5 10/14] drm/i915/color: Extract HDR pre-CSC LUT programming to helper function Chaitanya Kumar Borah
2026-07-20  4:51 ` [v5 11/14] drm/i915/color: Program Pre-CSC registers for SDR Chaitanya Kumar Borah
2026-07-20  4:51 ` [v5 12/14] drm/i915/color: Extract HDR post-CSC LUT programming to helper function Chaitanya Kumar Borah
2026-07-20  4:51 ` [v5 13/14] drm/i915/color: Program Plane Post CSC registers for SDR planes Chaitanya Kumar Borah
2026-07-20  4:51 ` [v5 14/14] drm/i915/color: Add color pipeline support " Chaitanya Kumar Borah
2026-07-20  5:39   ` sashiko-bot
2026-07-20 10:50 ` ✓ CI.KUnit: success for drm/i915/color: Enable SDR plane color pipeline (rev6) Patchwork
2026-07-20 11:26 ` ✓ Xe.CI.BAT: " Patchwork
2026-07-20 13:20 ` ✓ Xe.CI.FULL: " Patchwork
2026-07-20 16:07 ` ✓ i915.CI.BAT: " Patchwork
2026-07-20 22:01 ` ✗ i915.CI.Full: failure " Patchwork
2026-07-21  8:52 ` ✓ i915.CI.Full: success " Patchwork

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260720052829.0B3191F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=chaitanya.kumar.borah@intel.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.