All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Lyude Paul" <lyude@redhat.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v4 1/5] drm/nouveau: Fix cleanup bug in nouveau_drm_device_new()
Date: Thu, 30 Jul 2026 20:45:45 +0000	[thread overview]
Message-ID: <20260730204546.554B91F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260730203723.1649433-2-lyude@redhat.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] NULL pointer dereference in nouveau_drm_device_init() due to nouveau_drm_device_new() returning 0 (NULL) on success.
--

--- Patch [1]: [PATCH v4 1/5] drm/nouveau: Fix cleanup bug in nouveau_drm_device_new() ---
commit a5372851dc75d5b677c79a26019c14c8143d697d
Author: Lyude Paul <lyude@redhat.com>

drm/nouveau: Fix cleanup bug in nouveau_drm_device_new()

This patch fixes the error handling path in nouveau_drm_device_new() so
it doesn't attempt to free an error pointer if drm_dev_alloc fails. It
replaces the single done label with specific error labels.

> diff --git a/drivers/gpu/drm/nouveau/nouveau_drm.c b/drivers/gpu/drm/nouveau/nouveau_drm.c
> --- a/drivers/gpu/drm/nouveau/nouveau_drm.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_drm.c
[ ... ]
> @@ -762,39 +762,43 @@ nouveau_drm_device_new(const struct drm_driver *drm_driver, struct device *paren
[ ... ]
>  	ret = nvif_mmu_ctor(&drm->device.object, "drmMmu", mmus[ret].oclass, &drm->mmu);
>  	if (ret) {
>  		NV_ERROR(drm, "MMU allocation failed: %d\n", ret);
> -		goto done;
> +		goto err_device_del;
>  	}
>  
> -done:
> -	if (ret) {
> -		nouveau_drm_device_del(drm);
> -		drm = NULL;
> -	}
> +	return 0;

[Severity: High]
Does this code cause a NULL pointer dereference during device probe?

The function nouveau_drm_device_new() returns a struct nouveau_drm pointer,
but the success path was changed to return 0 (NULL).

Since the caller checks for failure using IS_ERR(), it will consider NULL a
success and pass the NULL pointer to nouveau_drm_device_init(), where it will
be dereferenced:

nouveau_drm_device_init()
    struct drm_device *dev = drm->dev;

Should this return the drm pointer instead?

> +
> +err_free_drm:
> +	kfree(drm);
> +
> +	return ERR_PTR(ret);
> +
> +err_device_del:
> +	nouveau_drm_device_del(drm);
>  
> -	return ret ? ERR_PTR(ret) : drm;
> +	return ERR_PTR(ret);
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260730203723.1649433-1-lyude@redhat.com?part=1

  reply	other threads:[~2026-07-30 20:45 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-30 20:36 [PATCH v4 0/5] Enable atomic modesetting by default Lyude Paul
2026-07-30 20:36 ` Lyude Paul
2026-07-30 20:36 ` [PATCH v4 1/5] drm/nouveau: Fix cleanup bug in nouveau_drm_device_new() Lyude Paul
2026-07-30 20:36   ` Lyude Paul
2026-07-30 20:45   ` sashiko-bot [this message]
2026-07-30 20:36 ` [PATCH v4 2/5] drm/nouveau: Print the nouveau.atomic parameter in nouveau_display_options() Lyude Paul
2026-07-30 20:36   ` Lyude Paul
2026-07-30 20:36 ` [PATCH v4 3/5] drm/nouveau: Fix drm_driver struct/nouveau.atomic parameter handling Lyude Paul
2026-07-30 20:36   ` Lyude Paul
2026-07-30 20:54   ` sashiko-bot
2026-07-30 20:36 ` [PATCH v4 4/5] drm/nouveau/kms: Only allow enabling atomic modesetting on nv50+ Lyude Paul
2026-07-30 20:36   ` Lyude Paul
2026-07-30 20:36 ` [PATCH v4 5/5] drm/nouveau/kms/nv50-: Enable atomic modesetting by default Lyude Paul
2026-07-30 20:36   ` Lyude Paul

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260730204546.554B91F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=lyude@redhat.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.