From: sashiko-bot@kernel.org
To: "Maxime Ripard" <mripard@kernel.org>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v2 07/13] drm/amdgpu: dm: Convert to atomic_create_state
Date: Mon, 31 Aug 2026 20:02:22 +0000 [thread overview]
Message-ID: <20260831200223.4CC511F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260831-drm-no-more-crtc-reset-v2-7-4500d49a337f@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Use-after-free and list corruption in `amdgpu_dm_crtc_init()` error path.
--
commit 0347668ca054c8ea5682a0562b13ea3c763f5fc2
Author: Maxime Ripard <mripard@kernel.org>
drm/amdgpu: dm: Convert to atomic_create_state
This commit converts the AMDGPU DM CRTC implementation to use the
atomic_create_state hook rather than a custom reset hook. It initializes
the state with __drm_atomic_helper_crtc_state_init() and handles the
newly created state during CRTC initialization.
[ ... ]
> diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crtc.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crtc.c
> index 62eac6e65334b..cfe1fbfbab8ea 100644
> --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crtc.c
> +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crtc.c
> @@ -781,9 +780,18 @@ int amdgpu_dm_crtc_init(struct amdgpu_display_manager *dm,
>
> drm_crtc_helper_add(&acrtc->base, &amdgpu_dm_crtc_helper_funcs);
>
> - /* Create (reset) the plane state */
> - if (acrtc->base.funcs->reset)
> - acrtc->base.funcs->reset(&acrtc->base);
> + /* Create the plane state */
> + if (acrtc->base.funcs->atomic_create_state) {
> + struct drm_crtc_state *crtc_state;
> +
> + crtc_state = acrtc->base.funcs->atomic_create_state(&acrtc->base);
> + if (IS_ERR(crtc_state)) {
> + res = PTR_ERR(crtc_state);
> + goto fail;
[Severity: High]
Does this error path leave dangling pointers in the DRM core lists?
This patch introduces a new failure point that jumps to the fail block after
the CRTC and plane have already been successfully initialized and linked via
drm_crtc_init_with_planes() earlier in amdgpu_dm_crtc_init().
Looking at the fail block in amdgpu_dm_crtc_init():
fail:
kfree(acrtc);
kfree(cursor_plane);
return res;
Freeing acrtc and cursor_plane directly without unregistering them via
drm_crtc_cleanup() and drm_plane_cleanup() leaves freed memory linked in the
DRM mode configuration lists. Subsequent traversals of these lists will
dereference the freed memory, which can cause a kernel panic.
While the plane cleanup omission existed previously, the CRTC list corruption
was newly introduced in this patch.
> + }
> +
> + acrtc->base.state = crtc_state;
> + }
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260831-drm-no-more-crtc-reset-v2-0-4500d49a337f@kernel.org?part=7
next prev parent reply other threads:[~2026-08-31 20:02 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 15:34 [PATCH v2 00/13] drm/crtc: Convert all drivers to atomic_create_state and remove reset Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 01/13] drm/crtc: Introduce hw_reset helper hook Maxime Ripard
2026-08-31 18:34 ` sashiko-bot
2026-09-02 7:05 ` Thomas Zimmermann
2026-08-31 15:34 ` [PATCH v2 02/13] drm/amdgpu: vkms: Switch to drm_atomic_helper_crtc_create_state Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 03/13] drm/logicvc: " Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 04/13] drm/tilcdc: Move hardware reset to CRTC creation Maxime Ripard
2026-08-31 19:11 ` sashiko-bot
2026-09-02 7:07 ` Thomas Zimmermann
2026-08-31 15:34 ` [PATCH v2 05/13] drm/tilcdc: Switch to drm_atomic_helper_crtc_create_state Maxime Ripard
2026-08-31 19:46 ` sashiko-bot
2026-08-31 15:34 ` [PATCH v2 06/13] drm/atomic-helper: Remove drm_atomic_helper_crtc_reset Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 07/13] drm/amdgpu: dm: Convert to atomic_create_state Maxime Ripard
2026-08-31 20:02 ` sashiko-bot [this message]
2026-08-31 15:34 ` [PATCH v2 08/13] drm/loongson: Move hardware reset to CRTC creation Maxime Ripard
2026-08-31 16:08 ` Icenowy Zheng
2026-08-31 20:13 ` sashiko-bot
2026-09-02 7:10 ` Thomas Zimmermann
2026-09-04 1:47 ` wuqianhai
2026-08-31 15:34 ` [PATCH v2 09/13] drm/loongson: Convert to atomic_create_state Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 10/13] drm/mediatek: " Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 11/13] drm/sitronix: st7920: " Maxime Ripard
2026-08-31 20:40 ` sashiko-bot
2026-09-01 11:05 ` Iker Pedrosa
2026-08-31 15:34 ` [PATCH v2 12/13] drm/atomic-helper: Remove __drm_atomic_helper_crtc_reset Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 13/13] drm/crtc: Remove reset Maxime Ripard
2026-08-31 21:09 ` sashiko-bot
2026-09-02 7:11 ` [PATCH v2 00/13] drm/crtc: Convert all drivers to atomic_create_state and remove reset Thomas Zimmermann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831200223.4CC511F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=mripard@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.