From: sashiko-bot@kernel.org
To: "Yongxing Mou" <yongxing.mou@oss.qualcomm.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v6 10/29] drm/msm/dp: no need to update tu calculation for mst
Date: Mon, 31 Aug 2026 09:06:58 +0000 [thread overview]
Message-ID: <20260831090659.1424F1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260831-msm-dp-mst-v6-10-c91d35d6fb9e@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] If memory allocation fails during TU calculation, the function returns early without initializing its output parameters, leading to uninitialized stack memory being written to hardware registers.
- [High] Calling sleeping and blocking functions from an atomic context causes system instability and deadlocks.
--
commit 17eb62d850306afdfafe9f15909840906306ec84
Author: Abhinav Kumar <quic_abhinavk@quicinc.com>
drm/msm/dp: no need to update tu calculation for mst
This commit skips the calculation and programming of TU parameters for MST
cases, as the DP stream is transmitted in transfer units only for SST.
> diff --git a/drivers/gpu/drm/msm/dp/dp_ctrl.c b/drivers/gpu/drm/msm/dp/dp_ctrl.c
> index cd6ae0d5372c9..77506e8408832 100644
> --- a/drivers/gpu/drm/msm/dp/dp_ctrl.c
> +++ b/drivers/gpu/drm/msm/dp/dp_ctrl.c
> @@ -2703,7 +2703,8 @@ int msm_dp_ctrl_on_stream(struct msm_dp_ctrl *msm_dp_ctrl, struct msm_dp_panel *
>
> msm_dp_panel_clear_dsc_dto(panel);
>
> - msm_dp_ctrl_setup_tr_unit(ctrl, panel);
> + if (!ctrl->mst_active)
> + msm_dp_ctrl_setup_tr_unit(ctrl, panel);
[Severity: High]
This isn't a bug introduced by this patch, but can we write uninitialized
stack memory to MMIO link registers if memory allocation fails?
Looking at msm_dp_ctrl_setup_tr_unit() in drivers/gpu/drm/msm/dp/dp_ctrl.c,
it allocates tu_calc_table on the stack and passes it down for initialization:
drivers/gpu/drm/msm/dp/dp_ctrl.c:msm_dp_ctrl_setup_tr_unit() {
struct msm_dp_vc_tu_mapping_table tu_calc_table;
msm_dp_ctrl_calc_tu_parameters(ctrl, panel, &tu_calc_table);
msm_dp_tu |= tu_calc_table.tu_size_minus1;
...
}
However, if _dp_ctrl_calc_tu() fails to allocate memory, it returns early
without initializing its output parameter:
drivers/gpu/drm/msm/dp/dp_ctrl.c:_dp_ctrl_calc_tu() {
...
tu = kzalloc_obj(*tu);
if (!tu)
return;
...
}
Will this cause msm_dp_ctrl_setup_tr_unit() to use the uninitialized
tu_calc_table stack memory and program it into hardware registers like
REG_DP_VALID_BOUNDARY and REG_DP_TU, potentially leading to display
corruption or kernel panics?
[Severity: High]
This is a pre-existing issue, but does msm_dp_ctrl_on_stream() violate
atomic context constraints by calling sleeping or blocking functions?
The DRM guidelines state that encoder/bridge atomic enable callbacks, such as
msm_dp_display_atomic_enable(), execute in a non-sleeping atomic context.
However, msm_dp_display_atomic_enable() calls msm_dp_ctrl_on_stream(), which
appears to trigger several functions that can sleep or block:
- msm_dp_ctrl_mst_send_act() in drivers/gpu/drm/msm/dp/dp_ctrl.c directly
sleeps:
msleep(frame_time_ms);
- msm_dp_ctrl_wait4video_ready() uses a blocking completion wait:
if (!wait_for_completion_timeout(&ctrl->video_comp,
WAIT_FOR_VIDEO_READY_TIMEOUT_JIFFIES)) {
- msm_dp_ctrl_setup_tr_unit() triggers a memory allocation that can sleep to
reclaim memory:
tu = kzalloc_obj(*tu);
Could these calls cause system deadlocks or lockups when the stream is
activated during atomic commits?
>
> msm_dp_write_link(ctrl, REG_DP_STATE_CTRL, DP_STATE_CTRL_SEND_VIDEO);
>
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260831-msm-dp-mst-v6-0-c91d35d6fb9e@oss.qualcomm.com?part=10
next prev parent reply other threads:[~2026-08-31 9:07 UTC|newest]
Thread overview: 48+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 8:17 [PATCH v6 00/29] drm/msm/dp: Add MST support for MSM chipsets Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 01/29] drm/msm/dp: move link-level teardown from display_disable to display_unprepare Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 02/29] drm/msm/dp: refactor msm_dp_ctrl_config_msa() to take panel Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 03/29] drm/msm/dp: drop redundant config_ctrl_link() from msm_dp_ctrl_on_stream() Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 04/29] drm/msm/dp: introduce stream_id for each DP panel Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 05/29] drm/msm/dp: add support for programming p1/p2/p3 register blocks Yongxing Mou
2026-08-31 8:39 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 06/29] drm/msm/dp: add MST stream register definitions Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 07/29] drm/msm/dp: add stream-aware link register accessors Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 08/29] drm/msm/dp: add support to send ACT packets for MST Yongxing Mou
2026-08-31 8:49 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 09/29] drm/msm/dp: add support to enable MST in mainlink control Yongxing Mou
2026-08-31 9:01 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 10/29] drm/msm/dp: no need to update tu calculation for mst Yongxing Mou
2026-08-31 9:06 ` sashiko-bot [this message]
2026-08-31 8:17 ` [PATCH v6 11/29] drm/msm/dp: always program MST_FIFO_CONSTANT_FILL for MST use cases Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 12/29] drm/msm/dp: add support for sending VCPF packets in DP controller Yongxing Mou
2026-08-31 9:12 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 13/29] drm/msm/dp: add support for MST channel slot allocation Yongxing Mou
2026-08-31 9:11 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 14/29] drm/msm/dp: replace power_on with active_stream_cnt Yongxing Mou
2026-08-31 9:18 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 15/29] drm/msm/dp: factor out _helper variants of bridge ops accepting a panel Yongxing Mou
2026-08-31 9:21 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 16/29] drm/msm/dp: add link_ready to manage link-level operations Yongxing Mou
2026-08-31 9:26 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 17/29] drm/msm/dp: add msm_dp_display_get_panel() to initialize DP panel Yongxing Mou
2026-08-31 9:28 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 18/29] drm/msm/dp: introduce dp_mst_drm module Yongxing Mou
2026-08-31 9:37 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 19/29] drm/msm/dp: add MST connector creation and topology callbacks Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 20/29] drm/msm/dpu: pass msm_display_info to dpu_encoder_get_intf() Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 21/29] drm/msm/dpu: use stream_id to select MST interfaces Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 22/29] drm/msm/dpu: add per-stream MST encoders Yongxing Mou
2026-08-31 9:47 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 23/29] drm/msm/dp: add atomic stream handling for MST Yongxing Mou
2026-08-31 9:48 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 24/29] drm/msm/dp: add HPD callback for dp MST Yongxing Mou
2026-08-31 10:00 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 25/29] drm/msm/dp: wire MST helpers into atomic check and commit paths Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 26/29] drm/msm/dp: mark the SST bridge disconnected when mst is active Yongxing Mou
2026-08-31 10:00 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 27/29] drm/msm/dp: enable MST on capable sinks Yongxing Mou
2026-08-31 10:04 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 28/29] drm/msm/dp: mark the SST bridge disconnected when an MST-capable sink is present Yongxing Mou
2026-08-31 10:26 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 29/29] drm/msm/dp: mark the SST connector disconnected when MST is enabled Yongxing Mou
2026-08-31 10:15 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831090659.1424F1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=yongxing.mou@oss.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox