All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Mario Limonciello" <mario.limonciello@amd.com>
Cc: intel-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org,
	intel-xe@lists.freedesktop.org
Subject: Re: [PATCH v8 09/14] drm/amdgpu: Check bios_scratch_reg_offset in backlight level helper
Date: Tue, 08 Sep 2026 04:51:46 +0000	[thread overview]
Message-ID: <20260908045146.963151F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260908044035.62093-10-mario.limonciello@amd.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] This problem wasn't introduced by this patch, but this patch provides an incomplete fix. It adds a check for `!adev->bios_scratch_reg_offset` in the backlight helper to prevent unmapped MMIO accesses, but fails to add this necessary safety check to several other functions that unconditionally access scratch registers using the identical offset.
--

commit 23cd4f591b277fb308823be50c628e3526a8743e
Author: Mario Limonciello (AMD) <superm1@kernel.org>

drm/amdgpu: Check bios_scratch_reg_offset in backlight level helper

Ensure adev->bios_scratch_reg_offset is non-zero before accessing
scratch registers in amdgpu_atombios_scratch_regs_set_backlight_level()
to avoid dereferencing unmapped MMIO offsets.

> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_atombios.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_atombios.c
> index 27c0dc8f6137a..2d8c2ba04e670 100644
> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_atombios.c
> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_atombios.c
> @@ -1622,7 +1622,12 @@ void amdgpu_atombios_scratch_regs_engine_hung(struct amdgpu_device *adev,
>  void amdgpu_atombios_scratch_regs_set_backlight_level(struct amdgpu_device *adev,
>  						      u32 backlight_level)
>  {
> -	u32 tmp = RREG32(adev->bios_scratch_reg_offset + 2);
> +	u32 tmp;
> +
> +	if (!adev->bios_scratch_reg_offset)
> +		return;
> +

[Severity: High]
This is a pre-existing issue, but while this patch adds a safety check here,
should we also add similar checks to other functions that access scratch
registers using the identical offset? 

If the firmware info table is missing or fails to parse properly, leaving the
offset at 0, these other paths are exposed to arbitrary MMIO writes:

In amdgpu_atombios_scratch_regs_engine_hung()
(drivers/gpu/drm/amd/amdgpu/amdgpu_atombios.c):
    u32 tmp = RREG32(adev->bios_scratch_reg_offset + 3);

In amdgpu_atombios_scratch_need_asic_init()
(drivers/gpu/drm/amd/amdgpu/amdgpu_atombios.c):
    u32 tmp = RREG32(adev->bios_scratch_reg_offset + 7);

In smu_v11_0_baco_set_state()
(drivers/gpu/drm/amd/pm/swsmu/smu11/smu_v11_0.c):
    WREG32(adev->bios_scratch_reg_offset + 6, 0);

Could this missing coverage lead to corrupting hardware state or triggering
machine check exceptions during GPU initialization, GPU reset, and BACO state
transitions if the offset is 0?

> +	tmp = RREG32(adev->bios_scratch_reg_offset + 2);
>  
>  	tmp &= ~ATOM_S2_CURRENT_BL_LEVEL_MASK;
[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260908044035.62093-1-mario.limonciello@amd.com?part=9

  reply	other threads:[~2026-09-08  4:51 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-08  4:40 [PATCH v8 00/14] Add support for a DRM backlight capability Mario Limonciello
2026-09-08  4:40 ` [PATCH v8 01/14] Revert "backlight: Remove notifier" Mario Limonciello
2026-09-08  4:51   ` sashiko-bot
2026-09-08  4:40 ` [PATCH v8 02/14] backlight: add kernel-internal backlight API Mario Limonciello
2026-09-08  4:52   ` sashiko-bot
2026-09-08 15:45   ` Jani Nikula
2026-09-08 16:00     ` Mario Limonciello
2026-09-08 16:33       ` Jani Nikula
2026-09-08  4:40 ` [PATCH v8 03/14] drm/property: add a per-connector luminance flag Mario Limonciello
2026-09-08  4:54   ` sashiko-bot
2026-09-08  4:40 ` [PATCH v8 04/14] drm: add connector backlight (LUMINANCE) infrastructure Mario Limonciello
2026-09-08  4:54   ` sashiko-bot
2026-09-08 15:48   ` Jani Nikula
2026-09-08  4:40 ` [PATCH v8 05/14] drm: add DRM_CLIENT_CAP_LUMINANCE Mario Limonciello
2026-09-08  4:55   ` sashiko-bot
2026-09-08  4:40 ` [PATCH v8 06/14] drm/amd/display: Pass up errors reading actual brightness Mario Limonciello
2026-09-08  4:40 ` [PATCH v8 07/14] drm/amd: Indicate driver supports luminance Mario Limonciello
2026-09-08  4:40 ` [PATCH v8 08/14] drm/amd/display: use drm backlight Mario Limonciello
2026-09-08  4:57   ` sashiko-bot
2026-09-08  4:40 ` [PATCH v8 09/14] drm/amdgpu: Check bios_scratch_reg_offset in backlight level helper Mario Limonciello
2026-09-08  4:51   ` sashiko-bot [this message]
2026-09-08  4:40 ` [PATCH v8 10/14] drm/amd/display: Update KUnit backlight tests for luminance property and fixtures Mario Limonciello
2026-09-08  4:54   ` sashiko-bot
2026-09-08  4:40 ` [PATCH v8 11/14] drm/bridge: auto-link panel backlight in bridge connector Mario Limonciello
2026-09-08  4:40 ` [PATCH v8 12/14] drm/xe: Indicate support for luminance on the connector Mario Limonciello
2026-09-08  4:57   ` sashiko-bot
2026-09-08  4:40 ` [PATCH v8 13/14] drm/i915: " Mario Limonciello
2026-09-08  4:40 ` [PATCH v8 14/14] drm/i915/display: use drm backlight Mario Limonciello
2026-09-08  5:03   ` sashiko-bot
2026-09-08  4:51 ` ✗ CI.checkpatch: warning for Add support for a DRM backlight capability (rev3) Patchwork
2026-09-08  4:53 ` ✓ CI.KUnit: success " Patchwork
2026-09-08  5:09 ` ✗ CI.checksparse: warning " Patchwork
2026-09-08  5:51 ` ✓ Xe.CI.BAT: success " Patchwork
2026-09-08  6:31 ` ✗ Xe.CI.FULL: failure " Patchwork
2026-09-08  9:32 ` ✓ i915.CI.BAT: success " Patchwork
2026-09-08 18:45 ` ✗ i915.CI.Full: failure " Patchwork

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260908045146.963151F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=intel-gfx@lists.freedesktop.org \
    --cc=intel-xe@lists.freedesktop.org \
    --cc=mario.limonciello@amd.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.