From: sashiko-bot@kernel.org
To: "Maxime Ripard" <mripard@kernel.org>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH 35/70] drm/tiny: sharp: Switch to drm_atomic_helper_crtc_create_state
Date: Fri, 21 Aug 2026 15:25:37 +0000 [thread overview]
Message-ID: <20260821152538.60A131F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260821-drm-no-more-crtc-reset-v1-35-fb793475c05a@kernel.org>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
Pre-existing issues:
- [High] The background kthread or PWM signal is not stopped on probe error paths, leading to Use-After-Free when the device memory is freed.
- [High] The driver does not check the return value of kthread_run(), which causes a kernel panic in the remove path if thread creation fails.
- [High] Plane atomic update callback calls sleeping functions (mutex_lock and spi_write) in an atomic context.
--
--- Patch [35]: [PATCH 35/70] drm/tiny: sharp: Switch to drm_atomic_helper_crtc_create_state ---
commit d365eb0228322a04306eb8553f60a438b3220d14
Author: Maxime Ripard <mripard@kernel.org>
drm/tiny: sharp: Switch to drm_atomic_helper_crtc_create_state
The sharp crtc implementation uses the deprecated
drm_atomic_helper_crtc_reset() as its reset hook. Switch to
drm_atomic_helper_crtc_create_state() instead.
> diff --git a/drivers/gpu/drm/tiny/sharp-memory.c b/drivers/gpu/drm/tiny/sharp-memory.c
> index 7efd7b567f3b2..434e73bd25a58 100644
> --- a/drivers/gpu/drm/tiny/sharp-memory.c
> +++ b/drivers/gpu/drm/tiny/sharp-memory.c
> @@ -345,7 +345,7 @@ static const struct drm_crtc_helper_funcs sharp_memory_crtc_helper_funcs = {
> };
>
> static const struct drm_crtc_funcs sharp_memory_crtc_funcs = {
> - .reset = drm_atomic_helper_crtc_reset,
> + .atomic_create_state = drm_atomic_helper_crtc_create_state,
[Severity: High]
This isn't a bug introduced by this patch, but does the plane atomic update
callback call sleeping functions in an atomic context?
The DRM subsystem executes plane atomic update callbacks in an atomic
context where sleeping is forbidden, but sharp_memory_plane_atomic_update()
invokes the display update flow:
drivers/gpu/drm/tiny/sharp-memory.c:sharp_memory_plane_atomic_update() {
...
sharp_memory_fb_dirty(plane_state->fb, shadow_plane_state->data,
&rect, &shadow_plane_state->fmtcnv_state);
...
}
which then calls sleeping functions unconditionally:
drivers/gpu/drm/tiny/sharp-memory.c:sharp_memory_update_display() {
...
mutex_lock(&smd->tx_mutex);
/* Populate the transmit buffer with frame data */
...
ret = sharp_memory_spi_write(smd->spi, tx_buffer, tx_buffer_size);
...
}
Could this lead to kernel splats and potential deadlocks on any atomic
plane update from userspace?
[Severity: High]
This is a pre-existing issue, but does the probe error path return directly
without stopping the kthread or PWM?
In sharp_memory_probe(), the background kthread is started, but if subsequent
initialization steps fail, the function returns directly:
drivers/gpu/drm/tiny/sharp-memory.c:sharp_memory_probe() {
...
smd->sw_vcom_signal = kthread_run(sharp_memory_sw_vcom_signal_thread,
smd, "sw_vcom_signal");
...
if (ret)
return dev_err_probe(dev, ret, "Failed to initialize display pipeline.\n");
...
}
Can this lead to a Use-After-Free memory corruption if the smd structure is
freed by devres while the running kthread continues executing and
dereferencing the freed memory?
[Severity: High]
This is also a pre-existing issue, but is the return value of kthread_run()
used without checking IS_ERR()?
If kthread creation fails in sharp_memory_probe(), smd->sw_vcom_signal would
hold an ERR_PTR:
drivers/gpu/drm/tiny/sharp-memory.c:sharp_memory_probe() {
...
smd->sw_vcom_signal = kthread_run(sharp_memory_sw_vcom_signal_thread,
smd, "sw_vcom_signal");
...
}
Would this cause a kernel panic due to an invalid pointer dereference when
the driver is removed and kthread_stop() is unconditionally called?
drivers/gpu/drm/tiny/sharp-memory.c:sharp_memory_remove() {
...
kthread_stop(smd->sw_vcom_signal);
...
}
> .destroy = drm_crtc_cleanup,
> .set_config = drm_atomic_helper_set_config,
> .page_flip = drm_atomic_helper_page_flip,
> .atomic_duplicate_state = drm_atomic_helper_crtc_duplicate_state,
> .atomic_destroy_state = drm_atomic_helper_crtc_destroy_state,
> };
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260821-drm-no-more-crtc-reset-v1-0-fb793475c05a@kernel.org?part=35
next prev parent reply other threads:[~2026-08-21 15:25 UTC|newest]
Thread overview: 106+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-21 14:38 [PATCH 00/70] drm/crtc: Convert all drivers to atomic_create_state and remove reset Maxime Ripard
2026-08-21 14:38 ` [PATCH 01/70] drm/adp: Switch to drm_atomic_helper_crtc_create_state Maxime Ripard
2026-08-21 14:55 ` sashiko-bot
2026-08-21 14:38 ` [PATCH 02/70] drm/amdgpu: vkms: " Maxime Ripard
2026-08-21 14:38 ` [PATCH 03/70] drm/arm: hdlcd: " Maxime Ripard
2026-08-24 10:48 ` Liviu Dudau
2026-08-21 14:38 ` [PATCH 04/70] drm/armada: " Maxime Ripard
2026-08-21 14:38 ` [PATCH 05/70] drm/exynos: " Maxime Ripard
2026-08-21 14:38 ` [PATCH 06/70] drm/fsl-dcu: " Maxime Ripard
2026-08-21 14:38 ` [PATCH 07/70] drm/gud: " Maxime Ripard
2026-08-23 16:36 ` Ruben Wauters
2026-08-21 14:38 ` [PATCH 08/70] drm/hisilicon: hibmc: " Maxime Ripard
2026-08-21 14:38 ` [PATCH 09/70] drm/hisilicon: kirin: " Maxime Ripard
2026-08-21 20:06 ` John Stultz
2026-08-21 14:38 ` [PATCH 10/70] drm/hyperv: " Maxime Ripard
2026-08-21 14:38 ` [PATCH 11/70] drm/imx: dc: " Maxime Ripard
2026-08-21 15:00 ` sashiko-bot
2026-08-21 14:38 ` [PATCH 12/70] drm/imx: dcss: " Maxime Ripard
2026-08-21 14:38 ` [PATCH 13/70] drm/ingenic: " Maxime Ripard
2026-08-24 9:43 ` Paul Cercueil
2026-08-21 14:38 ` [PATCH 14/70] drm/kmb: " Maxime Ripard
2026-08-21 14:38 ` [PATCH 15/70] drm/logicvc: " Maxime Ripard
2026-08-24 11:39 ` Paul Kocialkowski
2026-08-21 14:38 ` [PATCH 16/70] drm/meson: " Maxime Ripard
2026-08-21 14:38 ` [PATCH 17/70] drm/msm: mdp4: " Maxime Ripard
2026-08-22 7:51 ` Dmitry Baryshkov
2026-08-21 14:38 ` [PATCH 18/70] drm/mxs: mxsfb: " Maxime Ripard
2026-08-21 15:12 ` sashiko-bot
2026-08-21 14:38 ` [PATCH 19/70] drm/qxl: " Maxime Ripard
2026-08-21 14:38 ` [PATCH 20/70] drm/renesas: shmobile: " Maxime Ripard
2026-08-21 14:38 ` [PATCH 21/70] drm/simple-kms: Remove unused reset_crtc hook Maxime Ripard
2026-08-21 14:38 ` [PATCH 22/70] drm/simple-kms: Switch to drm_atomic_helper_crtc_create_state Maxime Ripard
2026-08-21 14:38 ` [PATCH 23/70] drm/sitronix: st7571: " Maxime Ripard
2026-08-21 15:14 ` sashiko-bot
2026-08-21 14:39 ` [PATCH 24/70] drm/sprd: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 25/70] drm/sti: " Maxime Ripard
2026-08-26 21:20 ` Raphaël Gallais-Pou
2026-08-21 14:39 ` [PATCH 26/70] drm/stm: " Maxime Ripard
2026-08-26 21:22 ` Raphaël Gallais-Pou
2026-08-21 14:39 ` [PATCH 27/70] drm/sun4i: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 28/70] drm/tests: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 29/70] drm/tilcdc: Move hardware reset to CRTC creation Maxime Ripard
2026-08-21 15:13 ` sashiko-bot
2026-08-21 14:39 ` [PATCH 30/70] drm/tilcdc: Switch to drm_atomic_helper_crtc_create_state Maxime Ripard
2026-08-21 14:39 ` [PATCH 31/70] drm/tiny: appletbdrm: " Maxime Ripard
2026-08-21 15:16 ` sashiko-bot
2026-08-24 11:32 ` Aditya Garg
2026-08-21 14:39 ` [PATCH 32/70] drm/tiny: bochs: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 33/70] drm/tiny: cirrus: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 34/70] drm/tiny: pixpaper: " Maxime Ripard
2026-08-21 15:26 ` sashiko-bot
2026-08-21 14:39 ` [PATCH 35/70] drm/tiny: sharp: " Maxime Ripard
2026-08-21 15:25 ` sashiko-bot [this message]
2026-08-21 14:39 ` [PATCH 36/70] drm/udl: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 37/70] drm/vbox: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 38/70] drm/verisilicon: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 39/70] drm/virtio: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 40/70] drm/xlnx: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 41/70] drm/mipi-dbi: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 42/70] drm/atomic-helper: Remove drm_atomic_helper_crtc_reset Maxime Ripard
2026-08-21 14:39 ` [PATCH 43/70] sysfb: Convert to create_state Maxime Ripard
2026-08-21 14:39 ` [PATCH 44/70] drm/amdgpu: dm: Convert to atomic_create_state Maxime Ripard
2026-08-21 15:28 ` sashiko-bot
2026-08-21 14:39 ` [PATCH 45/70] drm/komeda: " Maxime Ripard
2026-08-24 10:48 ` Liviu Dudau
2026-08-21 14:39 ` [PATCH 46/70] drm/malidp: " Maxime Ripard
2026-08-24 10:49 ` Liviu Dudau
2026-08-21 14:39 ` [PATCH 47/70] drm/ast: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 48/70] drm/atmel-hlcdc: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 49/70] drm/imx: ipuv3: " Maxime Ripard
2026-08-24 14:32 ` Philipp Zabel
2026-08-21 14:39 ` [PATCH 50/70] drm/loongsoon: Move hardware reset to CRTC creation Maxime Ripard
2026-08-21 15:36 ` sashiko-bot
2026-08-24 11:20 ` Thomas Zimmermann
2026-08-21 14:39 ` [PATCH 51/70] drm/loongson: Convert to atomic_create_state Maxime Ripard
2026-08-21 15:35 ` sashiko-bot
2026-08-21 14:39 ` [PATCH 52/70] drm/mediatek: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 53/70] drm/mgag200: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 54/70] drm/msm: dpu1: " Maxime Ripard
2026-08-22 8:14 ` Dmitry Baryshkov
2026-08-21 14:39 ` [PATCH 55/70] drm/msm: mdp5: " Maxime Ripard
2026-08-22 8:47 ` Dmitry Baryshkov
2026-08-21 14:39 ` [PATCH 56/70] drm/mxsfb: lcdif: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 57/70] drm/nouveau: " Maxime Ripard
2026-08-21 20:51 ` lyude
2026-08-21 14:39 ` [PATCH 58/70] drm/omapdrm: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 59/70] drm/rcar-du: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 60/70] drm/rzg2l-du: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 61/70] drm/rockchip: vop: " Maxime Ripard
2026-08-27 13:32 ` Heiko Stuebner
2026-08-21 14:39 ` [PATCH 62/70] drm/rockchip: vop2: " Maxime Ripard
2026-08-27 13:32 ` Heiko Stuebner
2026-08-21 14:39 ` [PATCH 63/70] drm/sitronix: st7920: " Maxime Ripard
2026-08-21 15:41 ` sashiko-bot
2026-08-21 14:39 ` [PATCH 64/70] drm/solomon: ssd130x: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 65/70] drm/tegra: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 66/70] drm/vc4: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 67/70] drm/vkms: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 68/70] drm/vmwgfx: " Maxime Ripard
2026-08-21 14:39 ` [PATCH 69/70] drm/atomic-helper: Remove __drm_atomic_helper_crtc_reset Maxime Ripard
2026-08-21 15:45 ` sashiko-bot
2026-08-22 8:47 ` Dmitry Baryshkov
2026-08-21 14:39 ` [PATCH 70/70] drm/crtc: Remove reset Maxime Ripard
2026-08-21 15:51 ` sashiko-bot
2026-08-23 21:19 ` Dmitry Baryshkov
2026-08-24 11:28 ` [PATCH 00/70] drm/crtc: Convert all drivers to atomic_create_state and remove reset Thomas Zimmermann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260821152538.60A131F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=mripard@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox