From: sashiko-bot@kernel.org
To: "Maxime Ripard" <mripard@kernel.org>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v2 13/13] drm/crtc: Remove reset
Date: Mon, 31 Aug 2026 21:09:40 +0000 [thread overview]
Message-ID: <20260831210941.2BEFD1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260831-drm-no-more-crtc-reset-v2-13-4500d49a337f@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Unchecked dereference of optional `crtc->helper_private` in `drm_mode_config_crtc_reset_with_create_state()` before calling `hw_reset`.
--
commit c111ccec175b0bcef9dba73f9b4a2e31404bd779
Author: Maxime Ripard <mripard@kernel.org>
drm/crtc: Remove reset
This commit removes the reset hook from struct drm_crtc_funcs. As a result,
all crtc drivers now rely on the atomic_create_state hook for initial state
creation, and drm_mode_config_reset() is updated to reflect this.
> diff --git a/drivers/gpu/drm/drm_mode_config.c b/drivers/gpu/drm/drm_mode_config.c
> index bb2efc274323e..5eed5c194b661 100644
> --- a/drivers/gpu/drm/drm_mode_config.c
> +++ b/drivers/gpu/drm/drm_mode_config.c
> @@ -307,9 +307,7 @@ void drm_mode_config_reset(struct drm_device *dev)
> }
>
> drm_for_each_crtc(crtc, dev) {
> - if (crtc->funcs->reset)
> - crtc->funcs->reset(crtc);
> - else if (crtc->funcs->atomic_create_state)
> + if (crtc->funcs->atomic_create_state)
> drm_mode_config_crtc_reset_with_create_state(crtc);
[Severity: High]
This is a pre-existing issue, but does removing the fallback to the reset
hook expose a kernel panic during initialization or resume?
By forcing all CRTCs that implement atomic_create_state through
drm_mode_config_crtc_reset_with_create_state(), we unconditionally hit a path
that dereferences the optional helper_private pointer without checking if it
exists.
Looking at drm_mode_config_crtc_reset_with_create_state() in
drivers/gpu/drm/drm_mode_config.c:
drm_mode_config_crtc_reset_with_create_state() {
const struct drm_crtc_helper_funcs *crtc_funcs = crtc->helper_private;
...
if (crtc_funcs->hw_reset)
crtc_funcs->hw_reset(crtc);
...
}
If an atomic DRM driver provides its own atomic implementations and does not
use the CRTC helpers, helper_private will be NULL. In that case, crtc_funcs
is NULL and the check for crtc_funcs->hw_reset will cause a NULL pointer
dereference.
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260831-drm-no-more-crtc-reset-v2-0-4500d49a337f@kernel.org?part=13
next prev parent reply other threads:[~2026-08-31 21:09 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 15:34 [PATCH v2 00/13] drm/crtc: Convert all drivers to atomic_create_state and remove reset Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 01/13] drm/crtc: Introduce hw_reset helper hook Maxime Ripard
2026-08-31 18:34 ` sashiko-bot
2026-09-02 7:05 ` Thomas Zimmermann
2026-08-31 15:34 ` [PATCH v2 02/13] drm/amdgpu: vkms: Switch to drm_atomic_helper_crtc_create_state Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 03/13] drm/logicvc: " Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 04/13] drm/tilcdc: Move hardware reset to CRTC creation Maxime Ripard
2026-08-31 19:11 ` sashiko-bot
2026-09-02 7:07 ` Thomas Zimmermann
2026-08-31 15:34 ` [PATCH v2 05/13] drm/tilcdc: Switch to drm_atomic_helper_crtc_create_state Maxime Ripard
2026-08-31 19:46 ` sashiko-bot
2026-08-31 15:34 ` [PATCH v2 06/13] drm/atomic-helper: Remove drm_atomic_helper_crtc_reset Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 07/13] drm/amdgpu: dm: Convert to atomic_create_state Maxime Ripard
2026-08-31 20:02 ` sashiko-bot
2026-08-31 15:34 ` [PATCH v2 08/13] drm/loongson: Move hardware reset to CRTC creation Maxime Ripard
2026-08-31 16:08 ` Icenowy Zheng
2026-08-31 20:13 ` sashiko-bot
2026-09-02 7:10 ` Thomas Zimmermann
2026-09-04 1:47 ` wuqianhai
2026-08-31 15:34 ` [PATCH v2 09/13] drm/loongson: Convert to atomic_create_state Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 10/13] drm/mediatek: " Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 11/13] drm/sitronix: st7920: " Maxime Ripard
2026-08-31 20:40 ` sashiko-bot
2026-09-01 11:05 ` Iker Pedrosa
2026-08-31 15:34 ` [PATCH v2 12/13] drm/atomic-helper: Remove __drm_atomic_helper_crtc_reset Maxime Ripard
2026-08-31 15:34 ` [PATCH v2 13/13] drm/crtc: Remove reset Maxime Ripard
2026-08-31 21:09 ` sashiko-bot [this message]
2026-09-02 7:11 ` [PATCH v2 00/13] drm/crtc: Convert all drivers to atomic_create_state and remove reset Thomas Zimmermann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831210941.2BEFD1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=mripard@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.