From: sashiko-bot@kernel.org
To: "Yongxing Mou" <yongxing.mou@oss.qualcomm.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v6 17/29] drm/msm/dp: add msm_dp_display_get_panel() to initialize DP panel
Date: Mon, 31 Aug 2026 09:28:52 +0000 [thread overview]
Message-ID: <20260831092853.414571F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260831-msm-dp-mst-v6-17-c91d35d6fb9e@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] msm_dp_display_get_panel() blindly allocates a duplicate panel structure for a given stream ID, leading to desynchronized internal state.
- [High] Missing NULL pointer check for optional pixel_base resource leads to a kernel panic during stream setup.
--
commit 09c5d687d7add705558b0ff0b93169b01fc6922e
Author: Abhinav Kumar <quic_abhinavk@quicinc.com>
drm/msm/dp: add msm_dp_display_get_panel() to initialize DP panel
This commit adds the msm_dp_display_get_panel API to initialize and
return a DP panel structure for use by the DP MST module.
> diff --git a/drivers/gpu/drm/msm/dp/dp_display.c b/drivers/gpu/drm/msm/dp/dp_display.c
> index 90e3d2c4ef478..6952f83db0065 100644
> --- a/drivers/gpu/drm/msm/dp/dp_display.c
> +++ b/drivers/gpu/drm/msm/dp/dp_display.c
[ ... ]
> @@ -529,6 +529,33 @@ static int msm_dp_irq_hpd_handle(struct msm_dp_display_private *dp)
> return rc;
> }
>
> +struct msm_dp_panel *msm_dp_display_get_panel(struct msm_dp *msm_dp_display,
> + enum msm_dp_stream_id stream_id)
> +{
> + struct msm_dp_display_private *dp;
> + struct msm_dp_panel *dp_panel;
> +
> + dp = container_of(msm_dp_display, struct msm_dp_display_private, msm_dp_display);
> +
> + if (stream_id >= msm_dp_ctrl_get_stream_cnt(dp->ctrl)) {
> + DRM_ERROR("invalid stream_id %d\n", stream_id);
> + return NULL;
> + }
> +
> + dp_panel = msm_dp_panel_get(&dp->msm_dp_display.pdev->dev, dp->aux, dp->link,
> + dp->link_base, dp->mst2link_base, dp->mst3link_base,
> + dp->pixel_base[stream_id]);
[Severity: High]
Does this inadvertently create a duplicate panel structure that lacks
initialized state?
When an MST stream is enabled, this dynamically allocates a new panel struct
where link_info is zeroed. Since the primary panel usually populates dpcd and
link_info (via msm_dp_panel_read_link_caps()), bandwidth calculations in
msm_dp_panel_get_supported_bpp() will evaluate to 0 for this secondary panel.
Will this permanently degrade the display to the minimum 18bpp fallback?
[Severity: High]
Can dp->pixel_base[stream_id] be NULL here?
The pixel_base memory regions are explicitly handled as optional in
msm_dp_display_get_io(). If the device tree specifies a pixel clock but
omits the corresponding register region, passing dp->pixel_base[stream_id]
as NULL to msm_dp_panel_get() stores a NULL panel->pixel_base.
When the display pipeline attempts to configure the panel timings later
(e.g., via msm_dp_write_pn()), could it dereference this NULL pointer and
cause a panic?
> +
> + if (IS_ERR(dp_panel)) {
> + DRM_ERROR("failed to initialize panel\n");
> + return NULL;
> + }
> +
> + dp_panel->stream_id = stream_id;
> +
> + return dp_panel;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260831-msm-dp-mst-v6-0-c91d35d6fb9e@oss.qualcomm.com?part=17
next prev parent reply other threads:[~2026-08-31 9:28 UTC|newest]
Thread overview: 48+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 8:17 [PATCH v6 00/29] drm/msm/dp: Add MST support for MSM chipsets Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 01/29] drm/msm/dp: move link-level teardown from display_disable to display_unprepare Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 02/29] drm/msm/dp: refactor msm_dp_ctrl_config_msa() to take panel Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 03/29] drm/msm/dp: drop redundant config_ctrl_link() from msm_dp_ctrl_on_stream() Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 04/29] drm/msm/dp: introduce stream_id for each DP panel Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 05/29] drm/msm/dp: add support for programming p1/p2/p3 register blocks Yongxing Mou
2026-08-31 8:39 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 06/29] drm/msm/dp: add MST stream register definitions Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 07/29] drm/msm/dp: add stream-aware link register accessors Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 08/29] drm/msm/dp: add support to send ACT packets for MST Yongxing Mou
2026-08-31 8:49 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 09/29] drm/msm/dp: add support to enable MST in mainlink control Yongxing Mou
2026-08-31 9:01 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 10/29] drm/msm/dp: no need to update tu calculation for mst Yongxing Mou
2026-08-31 9:06 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 11/29] drm/msm/dp: always program MST_FIFO_CONSTANT_FILL for MST use cases Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 12/29] drm/msm/dp: add support for sending VCPF packets in DP controller Yongxing Mou
2026-08-31 9:12 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 13/29] drm/msm/dp: add support for MST channel slot allocation Yongxing Mou
2026-08-31 9:11 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 14/29] drm/msm/dp: replace power_on with active_stream_cnt Yongxing Mou
2026-08-31 9:18 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 15/29] drm/msm/dp: factor out _helper variants of bridge ops accepting a panel Yongxing Mou
2026-08-31 9:21 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 16/29] drm/msm/dp: add link_ready to manage link-level operations Yongxing Mou
2026-08-31 9:26 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 17/29] drm/msm/dp: add msm_dp_display_get_panel() to initialize DP panel Yongxing Mou
2026-08-31 9:28 ` sashiko-bot [this message]
2026-08-31 8:17 ` [PATCH v6 18/29] drm/msm/dp: introduce dp_mst_drm module Yongxing Mou
2026-08-31 9:37 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 19/29] drm/msm/dp: add MST connector creation and topology callbacks Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 20/29] drm/msm/dpu: pass msm_display_info to dpu_encoder_get_intf() Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 21/29] drm/msm/dpu: use stream_id to select MST interfaces Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 22/29] drm/msm/dpu: add per-stream MST encoders Yongxing Mou
2026-08-31 9:47 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 23/29] drm/msm/dp: add atomic stream handling for MST Yongxing Mou
2026-08-31 9:48 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 24/29] drm/msm/dp: add HPD callback for dp MST Yongxing Mou
2026-08-31 10:00 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 25/29] drm/msm/dp: wire MST helpers into atomic check and commit paths Yongxing Mou
2026-08-31 8:17 ` [PATCH v6 26/29] drm/msm/dp: mark the SST bridge disconnected when mst is active Yongxing Mou
2026-08-31 10:00 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 27/29] drm/msm/dp: enable MST on capable sinks Yongxing Mou
2026-08-31 10:04 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 28/29] drm/msm/dp: mark the SST bridge disconnected when an MST-capable sink is present Yongxing Mou
2026-08-31 10:26 ` sashiko-bot
2026-08-31 8:17 ` [PATCH v6 29/29] drm/msm/dp: mark the SST connector disconnected when MST is enabled Yongxing Mou
2026-08-31 10:15 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831092853.414571F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=yongxing.mou@oss.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox