All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Dmitry Baryshkov" <dmitry.baryshkov@oss.qualcomm.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v2 1/6] drm/msm: serialise framebuffer pin state
Date: Tue, 08 Sep 2026 15:38:08 +0000	[thread overview]
Message-ID: <20260908153839.00A621F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260908-fd-kms-fix-smmu-v2-1-9391815742a8@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Initialization order vulnerability: mutex and refcount initialized after object is globally visible.
--

commit 43edb96a02a3e020c9ba63b15f602a74d5eb759f
Author: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>

drm/msm: serialise framebuffer pin state

This commit introduces a mutex to serialize framebuffer pin states, 
resolving an issue where parallel prepare and cleanup callbacks could 
leave a plane programmed with a NULL base address.

> diff --git a/drivers/gpu/drm/msm/msm_fb.c b/drivers/gpu/drm/msm/msm_fb.c
> --- a/drivers/gpu/drm/msm/msm_fb.c
> +++ b/drivers/gpu/drm/msm/msm_fb.c

[ ... ]

> @@ -206,6 +227,7 @@ msm_framebuffer_init(struct drm_device *dev, const struct drm_format_info *info,
>  	}
>  
>  	refcount_set(&msm_fb->dirtyfb, 1);
> +	mutex_init(&msm_fb->lock);

[Severity: High]
Since drm_framebuffer_init() is called just before this block and registers
the object in the DRM core IDR, the framebuffer becomes immediately visible
to userspace.

If userspace guesses the assigned framebuffer ID and concurrently issues an
atomic commit ioctl, could msm_framebuffer_prepare() execute and call
mutex_lock(&msm_fb->lock) before mutex_init() finishes here?

Could this race lead to memory corruption or deadlocks by clobbering the
mutex state? Would it be safer to move the mutex initialization to before
the drm_framebuffer_init() call?

>  
>  	drm_dbg_state(dev, "create: FB ID: %d (%p)\n", fb->base.id, fb);
>

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260908-fd-kms-fix-smmu-v2-0-9391815742a8@oss.qualcomm.com?part=1

  reply	other threads:[~2026-09-08 15:38 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-08 15:24 [PATCH v2 0/6] drm/msm: fix SMMU fault dumps Dmitry Baryshkov
2026-09-08 15:24 ` [PATCH v2 1/6] drm/msm: serialise framebuffer pin state Dmitry Baryshkov
2026-09-08 15:38   ` sashiko-bot [this message]
2026-09-08 15:24 ` [PATCH v2 2/6] drm/msm: fix framebuffer pin refcount leak on prepare failure Dmitry Baryshkov
2026-09-08 15:24 ` [PATCH v2 3/6] drm/msm: release scanout framebuffers only after a vblank Dmitry Baryshkov
2026-09-08 15:42   ` sashiko-bot
2026-09-08 15:24 ` [PATCH v2 4/6] drm/msm/dpu: clear the DSPP pointer when no DSPP is assigned Dmitry Baryshkov
2026-09-08 15:42   ` sashiko-bot
2026-09-08 15:24 ` [PATCH v2 5/6] drm/msm/dpu: only reassign resources when the encoder is reprogrammed Dmitry Baryshkov
2026-09-08 15:24 ` [PATCH v2 6/6] drm/ci: mark pixel-format tests as passing on SC7180 Dmitry Baryshkov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260908153839.00A621F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dmitry.baryshkov@oss.qualcomm.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.