From: sashiko-bot@kernel.org
To: fausten <yunfeng.li.nb@gmail.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v4] drm/vmwgfx: Treat zero SVGA_REG_CURSOR_MAX_DIMENSION as unset
Date: Sun, 30 Aug 2026 15:26:52 +0000 [thread overview]
Message-ID: <20260830152653.0D47D1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260830151619.2452307-1-yunfeng.li.nb@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] The patch incorrectly groups the `mob_max_size` validation under the `cursor_max_dim > 0` condition in `vmw_cursor_mob_get()`.
--
commit 4e542ce85fcba71b4d6d0cd77e13a02898b305c1
Author: fausten <yunfeng.li.nb@gmail.com>
Date: Sun Aug 30 15:16:19 2026 +0000
drm/vmwgfx: Treat zero SVGA_REG_CURSOR_MAX_DIMENSION as unset
This commit modifies the cursor plane validation to treat a reported
SVGA_REG_CURSOR_MAX_DIMENSION of 0 as "not implemented". This restores
the hardware cursor visibility on older SVGA version 2 guests.
> diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_cursor_plane.c b/drivers/gpu/drm/vmwgfx/vmwgfx_cursor_plane.c
> --- a/drivers/gpu/drm/vmwgfx/vmwgfx_cursor_plane.c
> +++ b/drivers/gpu/drm/vmwgfx/vmwgfx_cursor_plane.c
> @@ -237,8 +237,10 @@ static int vmw_cursor_mob_get(struct vmw_cursor_plane *vcp,
> mob_max_size = vmw_read(dev_priv, SVGA_REG_MOB_MAX_SIZE);
> cursor_max_dim = vmw_read(dev_priv, SVGA_REG_CURSOR_MAX_DIMENSION);
>
> - if (size > mob_max_size || vps->base.crtc_w > cursor_max_dim ||
> - vps->base.crtc_h > cursor_max_dim)
> + /* Cursor MOBs, and thus this register, exist only on hw version 18+. */
> + if (cursor_max_dim > 0 &&
> + (size > mob_max_size || vps->base.crtc_w > cursor_max_dim ||
> + vps->base.crtc_h > cursor_max_dim))
[Severity: Low]
Does this incorrectly bypass the mob_max_size check when cursor_max_dim
evaluates to 0?
The parentheses group size > mob_max_size with the cursor dimension
checks. If cursor_max_dim is 0, the logical AND fails early, which
completely skips checking if the size exceeds mob_max_size in
vmw_cursor_mob_get().
While this shouldn't cause an immediate out-of-bounds update since
vmw_cursor_plane_atomic_check() independently validates mob_max_size,
should the mob_max_size check remain separate from the cursor_max_dim
validation to ensure it is always evaluated here?
> return -EINVAL;
>
> if (vps->cursor.mob) {
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260830151619.2452307-1-yunfeng.li.nb@gmail.com?part=1
next prev parent reply other threads:[~2026-08-30 15:26 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-23 8:32 [PATCH] drm/vmwgfx: Treat zero SVGA_REG_CURSOR_MAX_DIMENSION as unset fausten
2026-08-23 8:59 ` [PATCH v2] " fausten
2026-08-23 9:15 ` sashiko-bot
2026-08-26 0:51 ` Maaz Mombasawala
2026-08-28 1:17 ` Maaz Mombasawala
2026-08-30 15:16 ` [PATCH v4] " fausten
2026-08-30 15:26 ` sashiko-bot [this message]
2026-09-02 20:44 ` Maaz Mombasawala
2026-08-28 11:04 ` [PATCH v3] " fausten
2026-08-28 11:23 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260830152653.0D47D1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=yunfeng.li.nb@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.