From: sashiko-bot@kernel.org
To: "Daniel Golle" <daniel@makrotopia.org>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v6 09/13] drm/bridge: it6505: hold endpoint OF node reference while parsing it
Date: Sat, 25 Jul 2026 03:15:57 +0000 [thread overview]
Message-ID: <20260725031558.18CC31F000E9@smtp.kernel.org> (raw)
In-Reply-To: <d5abbb920321da662a735c880378513ff825fe39.1784947240.git.daniel@makrotopia.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Uninitialized stack variable `link_frequencies` is used if `of_property_read_variable_u64_array()` reads 0 elements.
--
--- Patch [9]: [PATCH v6 09/13] drm/bridge: it6505: hold endpoint OF node reference while parsing it ---
commit 635833fd1fe628586cc12b54a91fac7c8f243c4c
Author: Daniel Golle <daniel@makrotopia.org>
drm/bridge: it6505: hold endpoint OF node reference while parsing it
This commit delays dropping the reference to endpoint nodes in it6505_parse_dt()
until after their properties have been parsed. This prevents a race condition
where the node could be freed while its properties are still being read when
CONFIG_OF_DYNAMIC is enabled.
> diff --git a/drivers/gpu/drm/bridge/ite-it6505.c b/drivers/gpu/drm/bridge/ite-it6505.c
> --- a/drivers/gpu/drm/bridge/ite-it6505.c
> +++ b/drivers/gpu/drm/bridge/ite-it6505.c
[ ... ]
> @@ -3379,13 +3378,13 @@ static void it6505_parse_dt(struct it6505 *it6505)
[ ... ]
> ep = of_graph_get_endpoint_by_regs(np, 0, 0);
> - of_node_put(ep);
>
> if (ep) {
> len = of_property_read_variable_u64_array(ep,
[Severity: High]
This is a pre-existing issue, but can this lead to using uninitialized stack
memory?
If the link-frequencies property exists in the device tree but is empty,
of_property_read_variable_u64_array() (called with sz_min set to 0) will
return 0 and leave the link_frequencies stack variable unmodified.
Since the subsequent check if (len >= 0) evaluates to true, won't the code
proceed to pass the uninitialized link_frequencies variable to do_div()
and use it to calculate the maximum DPI pixel clock?
> @@ -3405,6 +3404,7 @@ static void it6505_parse_dt(struct it6505 *it6505)
> dev_err(dev, "error link frequencies, use default");
> *max_dpi_pixel_clock = DPI_PIXEL_CLK_MAX;
> }
> + of_node_put(ep);
> } else {
> dev_err(dev, "error endpoint, use default");
> *max_dpi_pixel_clock = DPI_PIXEL_CLK_MAX;
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1784947240.git.daniel@makrotopia.org?part=9
next prev parent reply other threads:[~2026-07-25 3:16 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-25 2:57 [PATCH v6 00/13] drm/bridge: it6505: DP audio support + shared-DAI hw_params fix Daniel Golle
2026-07-25 2:58 ` [PATCH v6 01/13] drm/bridge: it6505: quiesce event sources and work on remove() Daniel Golle
2026-07-25 3:23 ` sashiko-bot
2026-07-25 2:58 ` [PATCH v6 02/13] drm/bridge: it6505: balance and disable runtime PM on remove Daniel Golle
2026-07-25 3:18 ` sashiko-bot
2026-07-25 2:58 ` [PATCH v6 03/13] drm/bridge: it6505: unregister DP AUX adapter on bridge detach Daniel Golle
2026-07-25 3:17 ` sashiko-bot
2026-07-25 2:58 ` [PATCH v6 04/13] drm/bridge: it6505: complete poweroff even if disabling regulators fails Daniel Golle
2026-07-25 3:17 ` sashiko-bot
2026-07-25 2:58 ` [PATCH v6 05/13] drm/bridge: it6505: bail out of the IRQ handler when status reads fail Daniel Golle
2026-07-25 2:59 ` [PATCH v6 06/13] drm/bridge: it6505: avoid division by zero in pixel clock calculation Daniel Golle
2026-07-25 3:20 ` sashiko-bot
2026-07-25 2:59 ` [PATCH v6 07/13] drm/bridge: it6505: avoid division by zero in audio FS debug print Daniel Golle
2026-07-25 3:16 ` sashiko-bot
2026-07-25 2:59 ` [PATCH v6 08/13] drm/bridge: it6505: guard against zero channel count in audio infoframe Daniel Golle
2026-07-25 3:00 ` [PATCH v6 09/13] drm/bridge: it6505: hold endpoint OF node reference while parsing it Daniel Golle
2026-07-25 3:15 ` sashiko-bot [this message]
2026-07-25 3:00 ` [PATCH v6 10/13] drm/bridge: it6505: reject a too short link-frequencies property Daniel Golle
2026-07-25 3:00 ` [PATCH v6 11/13] drm/bridge: it6505: don't write an error code back to the reset register Daniel Golle
2026-07-25 3:19 ` sashiko-bot
2026-07-25 3:01 ` [PATCH v6 12/13] drm/bridge: it6505: Add audio support Daniel Golle
2026-07-25 5:25 ` sashiko-bot
2026-07-25 3:01 ` [PATCH v6 13/13] drm/bridge: it6505: Don't reject audio hw_params without an encoder Daniel Golle
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260725031558.18CC31F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=daniel@makrotopia.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.