dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Maxime Ripard" <mripard@kernel.org>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v2 22/37] drm/bridge: ti-tfp410: Switch to atomic bridge callbacks
Date: Tue, 07 Jul 2026 15:48:17 +0000	[thread overview]
Message-ID: <20260707154817.C747D1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260707-drm-all-atomic-bridges-v2-22-21d03cbca446@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] This problem wasn't introduced by this patch, but there is a use-after-free vulnerability and missing cleanup of the HPD registration on the `tfp410_attach` error path.
--

--- Patch [22]: [PATCH v2 22/37] drm/bridge: ti-tfp410: Switch to atomic bridge callbacks ---
commit fb525e8e18293a40cab99e1a43c62c7f5ee18083
Author: Maxime Ripard <mripard@kernel.org>

drm/bridge: ti-tfp410: Switch to atomic bridge callbacks

This commit switches the ti-tfp410 bridge from legacy non-atomic enable and
disable callbacks to their atomic counterparts. It also adds the necessary
atomic state handlers to help remove legacy support from the DRM bridge core.

> diff --git a/drivers/gpu/drm/bridge/ti-tfp410.c b/drivers/gpu/drm/bridge/ti-tfp410.c
> index 6f06f7b4e9926..f0a14f52aaace 100644
> --- a/drivers/gpu/drm/bridge/ti-tfp410.c
> +++ b/drivers/gpu/drm/bridge/ti-tfp410.c
[ ... ]
> @@ -242,8 +244,8 @@ static int tfp410_atomic_check(struct drm_bridge *bridge,
>  static const struct drm_bridge_funcs tfp410_bridge_funcs = {
>  	.attach		= tfp410_attach,
>  	.detach		= tfp410_detach,
> -	.enable		= tfp410_enable,
> -	.disable	= tfp410_disable,

[Severity: High]
This isn't a bug introduced by this patch, but there appears to be a
use-after-free risk and missing cleanup of the HPD registration on the error
path in tfp410_attach().

When tfp410_attach() successfully registers the HPD callback on the next bridge,
but drm_connector_init_with_ddc() subsequently fails, it returns an error
without disabling the HPD callback:

drivers/gpu/drm/bridge/ti-tfp410.c:tfp410_attach() {
    ...
	ret = drm_connector_init_with_ddc(bridge->dev, &dvi->connector,
					  &tfp410_con_funcs,
					  dvi->bridge.next_bridge->type,
					  dvi->bridge.next_bridge->ddc);
	if (ret) {
		dev_err(dvi->dev, "drm_connector_init_with_ddc() failed: %d\n",
			ret);
		return ret;
	}
    ...
}

If the attachment fails, .detach() isn't called, and the next bridge might still
retain the HPD callback pointing to the freed dvi structure. A hardware
hotplug event could then trigger the callback and dereference the freed pointer.

Should this error path deregister the HPD callback before returning?

> +	.atomic_enable = tfp410_enable,
> +	.atomic_disable = tfp410_disable,
>  	.mode_valid	= tfp410_mode_valid,
>  	.atomic_create_state = drm_atomic_helper_bridge_create_state,
>  	.atomic_duplicate_state = drm_atomic_helper_bridge_duplicate_state,

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260707-drm-all-atomic-bridges-v2-0-21d03cbca446@kernel.org?part=22

  reply	other threads:[~2026-07-07 15:48 UTC|newest]

Thread overview: 63+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-07 15:11 [PATCH v2 00/37] drm/bridge: Convert all bridges to atomic Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 01/37] drm/adp: mipi: Add atomic bridge state handlers Maxime Ripard
2026-07-07 15:29   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 02/37] drm/bridge: analogix-anx6345: Switch to atomic bridge callbacks Maxime Ripard
2026-07-07 15:28   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 03/37] drm/bridge: analogix-anx78xx: " Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 04/37] drm/bridge: aux-bridge: Add atomic bridge state handlers Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 05/37] drm/bridge: aux-hpd-bridge: " Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 06/37] drm/bridge: chrontel-ch7033: Switch to atomic bridge callbacks Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 07/37] drm/bridge: cros-ec-anx7688: Add atomic bridge state handlers Maxime Ripard
2026-07-07 15:29   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 08/37] drm/bridge: lontium-lt8713sx: " Maxime Ripard
2026-07-07 15:27   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 09/37] drm/bridge: lontium-lt8912b: Switch to atomic bridge callbacks Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 10/37] drm/bridge: lontium-lt9611uxc: Add atomic bridge state handlers Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 11/37] drm/bridge: lvds-codec: Switch to atomic bridge callbacks Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 12/37] drm/bridge: megachips-stdpxxxx-ge-b850v3-fw: Add atomic bridge state handlers Maxime Ripard
2026-07-07 15:35   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 13/37] drm/bridge: microchip-lvds: " Maxime Ripard
2026-07-07 15:38   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 14/37] drm/bridge: nxp-ptn3460: Switch to atomic bridge callbacks Maxime Ripard
2026-07-07 15:41   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 15/37] drm/bridge: of-display-mode-bridge: Add atomic bridge state handlers Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 16/37] drm/bridge: parade-ps8622: Switch to atomic bridge callbacks Maxime Ripard
2026-07-07 15:39   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 17/37] drm/bridge: sii9234: Add atomic bridge state handlers Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 18/37] drm/bridge: sil-sii8620: " Maxime Ripard
2026-07-07 15:57   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 19/37] drm/bridge: simple-bridge: Switch to atomic bridge callbacks Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 20/37] drm/bridge: tc358764: " Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 21/37] drm/bridge: tda998x: " Maxime Ripard
2026-07-07 15:52   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 22/37] drm/bridge: ti-tfp410: " Maxime Ripard
2026-07-07 15:48   ` sashiko-bot [this message]
2026-07-07 15:11 ` [PATCH v2 23/37] drm/bridge: ti-tpd12s015: Add atomic bridge state handlers Maxime Ripard
2026-07-07 15:43   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 24/37] drm/bridge: thc63lvd1024: Switch to atomic bridge callbacks Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 25/37] drm/bridge: waveshare-dsi: " Maxime Ripard
2026-07-07 15:51   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 26/37] drm/exynos: mic: " Maxime Ripard
2026-07-07 16:00   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 27/37] drm/mcde: dsi: Add atomic bridge state handlers Maxime Ripard
2026-07-07 15:53   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 28/37] drm/mediatek: dpi: Switch to atomic bridge callbacks Maxime Ripard
2026-07-07 15:56   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 29/37] drm/msm: dsi: " Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 30/37] drm/omap: dpi: " Maxime Ripard
2026-07-07 16:08   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 31/37] drm/omap: dsi: " Maxime Ripard
2026-07-07 16:04   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 32/37] drm/omap: sdi: " Maxime Ripard
2026-07-07 16:06   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 33/37] drm/omap: venc: " Maxime Ripard
2026-07-07 16:04   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 34/37] drm/sti: dvo: " Maxime Ripard
2026-07-07 16:09   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 35/37] drm/sti: hda: " Maxime Ripard
2026-07-07 15:11 ` [PATCH v2 36/37] drm/sti: hdmi: " Maxime Ripard
2026-07-07 16:11   ` sashiko-bot
2026-07-07 15:11 ` [PATCH v2 37/37] drm/bridge: Remove legacy bridge callback support Maxime Ripard
2026-07-07 16:17   ` sashiko-bot
2026-07-08 17:12 ` [PATCH v2 00/37] drm/bridge: Convert all bridges to atomic Luca Ceresoli
2026-07-15  7:50 ` Maxime Ripard

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260707154817.C747D1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=mripard@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox