All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Guangshuo Li" <lgs201920130244@gmail.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH] drm/tegra: gr2d: fix autosuspend cleanup during teardown
Date: Sat, 08 Aug 2026 14:21:37 +0000	[thread overview]
Message-ID: <20260808142138.69B0E1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260808140622.2887873-1-lgs201920130244@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

New issues:
- [Medium] The commit message falsely claims that gr2d_probe() calls pm_runtime_use_autosuspend(), and adds a redundant cleanup to gr2d_remove() based on this false premise.

Pre-existing issues:
- [High] Unbinding the gr2d driver while a DRM channel is open causes a Use-After-Free when the DRM file is later closed by userspace.
--

--- Patch [1]: [PATCH] drm/tegra: gr2d: fix autosuspend cleanup during teardown ---
commit 9b1fea12d4967b1c2b4a943c3958df804b6cd6a8
Author: Guangshuo Li <lgs201920130244@gmail.com>

    drm/tegra: gr2d: fix autosuspend cleanup during teardown

This commit adds a pm_runtime_dont_use_autosuspend() call to the driver's
remove function. It attempts to fix a leaked usage count reference that the
commit message states was taken in gr2d_probe().

>     gr2d_probe() calls pm_runtime_use_autosuspend(), but gr2d_remove()
>     does not call the matching pm_runtime_dont_use_autosuspend() during
>     teardown.

[Severity: Medium]
Is this description accurate?

Looking at the code, gr2d_probe() does not call pm_runtime_use_autosuspend().

Furthermore, pm_runtime_dont_use_autosuspend() is already properly called
during teardown inside gr2d_exit(), which is reached via
host1x_client_unregister().

Does this patch add a redundant cleanup based on an incorrect premise?

> diff --git a/drivers/gpu/drm/tegra/gr2d.c b/drivers/gpu/drm/tegra/gr2d.c
> index 21f4dd0fa6aff..8063e06b0b87a 100644
> --- a/drivers/gpu/drm/tegra/gr2d.c
> +++ b/drivers/gpu/drm/tegra/gr2d.c
> @@ -293,6 +293,7 @@ static void gr2d_remove(struct platform_device *pdev)
>  {
>  	struct gr2d *gr2d = platform_get_drvdata(pdev);
>  
> +	pm_runtime_dont_use_autosuspend(&pdev->dev);
>  	pm_runtime_disable(&pdev->dev);
>  	host1x_client_unregister(&gr2d->client.base);
>  }

[Severity: High]
This is a pre-existing issue, but does unbinding the driver here
cause a use-after-free if a DRM channel remains open?

If an administrator unbinds the tegra-gr2d driver while userspace has a DRM
channel open, gr2d_remove() will execute. The struct gr2d driver data will
then be freed by devres.

When userspace subsequently closes the DRM file descriptor,
tegra_drm_postclose() calls tegra_drm_context_free(), which dereferences
the freed client ops:

drivers/gpu/drm/tegra/drm.c:tegra_drm_context_free() {
    ...
    context->client->ops->close_channel(context);
    ...
}

Should the DRM layer be coordinated with to revoke active contexts before the
device structure is destroyed?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260808140622.2887873-1-lgs201920130244@gmail.com?part=1

      reply	other threads:[~2026-08-08 14:21 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-08 14:06 [PATCH] drm/tegra: gr2d: fix autosuspend cleanup during teardown Guangshuo Li
2026-08-08 14:21 ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260808142138.69B0E1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=lgs201920130244@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.