From: sashiko-bot@kernel.org
To: "Nicolas Frattaroli" <nicolas.frattaroli@collabora.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH RFC 04/25] video/hdmi: Add VTEM EMP packing
Date: Mon, 21 Sep 2026 16:07:29 +0000 [thread overview]
Message-ID: <20260921160730.229451F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260921-vrr-limiter-uapi-v1-4-2fcd7d011646@collabora.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] video/hdmi: hdmi_infoframe_pack_only() missing EMP support
- [Medium] video/hdmi: missing bounds check for VTEM base_refresh_rate
- [Low] video/hdmi: VTEM pack returns -EINVAL on insufficient buffer
--
commit 453def06fd91297425481a25d9a912cdc54c08f8
Author: Derek Foreman <derek.foreman@collabora.com>
video/hdmi: Add VTEM EMP packing
VTEM EMPs are a type of infoframe that is required for Variable Refresh
Rate. Add code to pack them.
> diff --git a/drivers/video/hdmi.c b/drivers/video/hdmi.c
> index 45b42f14a7503..ed9abc7ad2285 100644
> --- a/drivers/video/hdmi.c
> +++ b/drivers/video/hdmi.c
> @@ -983,6 +983,10 @@ hdmi_infoframe_pack(union hdmi_infoframe *frame,
> length = hdmi_vendor_any_infoframe_pack(&frame->vendor,
> buffer, size);
> break;
> + case HDMI_INFOFRAME_TYPE_EMP:
> + length = hdmi_emp_infoframe_vtem_pack(&frame->vtem,
> + buffer, size);
> + break;
[Severity: High]
This adds EMP support to hdmi_infoframe_pack(), but does
hdmi_infoframe_pack_only() also need an update?
Drivers that rely exclusively on hdmi_infoframe_pack_only() (such as i915 and
SDVO) will hit a WARN(1) backtrace and fail with -EINVAL if they attempt to
pack an EMP (VTEM) infoframe.
[ ... ]
> +ssize_t hdmi_emp_infoframe_vtem_pack(struct hdmi_emp_infoframe_vtem *vtem,
> + void *buffer, size_t size)
[Severity: High]
To be supported in hdmi_infoframe_pack_only(), wouldn't this function need
to accept a const pointer?
hdmi_infoframe_pack_only() guarantees a const union hdmi_infoframe *frame,
but the lack of a const qualifier on vtem prevents it from being safely
called without casting away constness.
> +{
> + u8 *ptr = buffer;
> +
> + if (size < HDMI_INFOFRAME_SIZE(VTEM))
> + return -EINVAL;
[Severity: Low]
Should this return -ENOSPC instead of -EINVAL when the provided buffer is
smaller than the required frame size?
All other packing functions in drivers/video/hdmi.c (e.g.,
hdmi_avi_infoframe_pack_only(), hdmi_drm_infoframe_pack_only()) explicitly
return -ENOSPC when size is insufficient. Returning -EINVAL might break error
handling logic in callers that expect -ENOSPC.
> +
> + /* 4 bits max */
> + if (vtem->fva_factor_m1 > 0xF)
> + return -EINVAL;
> +
[Severity: Medium]
Does base_refresh_rate also need a bounds check here?
The base_refresh_rate field is a u16 and can hold values up to 65535, but it
is restricted to 10 bits. If a caller supplies a value greater than 1023, it
will be silently truncated later in this function rather than gracefully
rejected. Could this result in the hardware transmitting an incorrect VRR
refresh rate to the display?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260921-vrr-limiter-uapi-v1-0-2fcd7d011646@collabora.com?part=4
next prev parent reply other threads:[~2026-09-21 16:07 UTC|newest]
Thread overview: 75+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 15:51 [PATCH RFC 00/25] VRR Target Rate Limiter KMS uAPI and Implementation Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 01/25] drm/edid: Add a query for vrr range Nicolas Frattaroli
2026-09-21 16:08 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 02/25] drm: Add VRR state Nicolas Frattaroli
2026-09-24 6:55 ` Vidith Madhu
2026-09-21 15:51 ` [PATCH RFC 03/25] drm/atomic-helper: Set mode_changed on vrr_enabled change Nicolas Frattaroli
2026-09-21 16:13 ` sashiko-bot
2026-09-21 21:59 ` Leo Li
2026-09-22 12:53 ` Nicolas Frattaroli
2026-09-22 13:22 ` Maxime Ripard
2026-09-24 6:45 ` Vidith Madhu
2026-09-21 22:01 ` Leo Li
2026-09-21 15:51 ` [PATCH RFC 04/25] video/hdmi: Add VTEM EMP packing Nicolas Frattaroli
2026-09-21 16:07 ` sashiko-bot [this message]
2026-09-21 15:51 ` [PATCH RFC 05/25] drm/bridge: Add VTEM EMP support Nicolas Frattaroli
2026-09-21 16:01 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 06/25] drm/connector: hdmi: Add VTEM EMP generation Nicolas Frattaroli
2026-09-21 16:13 ` sashiko-bot
2026-09-25 3:48 ` Vidith Madhu
2026-09-25 10:42 ` Daniel Stone
2026-09-25 11:11 ` Jani Nikula
2026-09-26 11:03 ` Nicolas Frattaroli
2026-09-29 18:55 ` Vidith Madhu
2026-09-30 7:50 ` Michel Dänzer
2026-09-21 15:51 ` [PATCH RFC 07/25] drm/crtc-helper: Add VRR helper functions Nicolas Frattaroli
2026-09-21 16:05 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 08/25] drm/bridge: synopsys: Add VTEM EMP support Nicolas Frattaroli
2026-09-21 16:06 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 09/25] drm/connector: Add drm_display_info_is_vrr_capable Nicolas Frattaroli
2026-09-21 16:04 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 10/25] drm/rockchip: dw_hdmi_qp: Add VRR support Nicolas Frattaroli
2026-09-21 16:09 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 11/25] drm/rockchip: vop2: Enable VRR Nicolas Frattaroli
2026-09-21 16:16 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 12/25] drm/edid: Parse CinemaVRR flag from HDMI SCDS Nicolas Frattaroli
2026-09-21 16:13 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 13/25] drm: Add VRR target frame rate properties Nicolas Frattaroli
2026-09-21 16:14 ` sashiko-bot
2026-09-21 22:23 ` Leo Li
2026-09-22 15:26 ` Nicolas Frattaroli
2026-09-25 18:42 ` Leo Li
2026-09-26 12:13 ` Nicolas Frattaroli
2026-09-28 8:10 ` Michel Dänzer
2026-09-29 14:34 ` Leo Li
2026-09-29 16:00 ` Michel Dänzer
2026-09-29 18:14 ` Nicolas Frattaroli
2026-09-29 18:24 ` Nicolas Frattaroli
2026-09-23 9:51 ` Michel Dänzer
2026-09-23 9:54 ` Michel Dänzer
2026-09-23 14:39 ` Nicolas Frattaroli
2026-09-24 7:01 ` Vidith Madhu
2026-09-24 12:10 ` Nicolas Frattaroli
2026-09-29 19:16 ` Vidith Madhu
2026-09-29 19:55 ` Nicolas Frattaroli
2026-09-29 21:05 ` Vidith Madhu
2026-09-29 22:21 ` Xaver Hugl
2026-09-21 15:51 ` [PATCH RFC 14/25] drm: Implement VRR rate limiting Nicolas Frattaroli
2026-09-21 16:17 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 15/25] drm/edid: Parse QMS flag from HDMI SCDS Nicolas Frattaroli
2026-09-21 16:18 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 16/25] drm/edid: Parse QMS TFR min/max flags " Nicolas Frattaroli
2026-09-21 16:19 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 17/25] drm/connector: Add "qms_enabled" drm property Nicolas Frattaroli
2026-09-21 16:20 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 18/25] video/hdmi: Add support for QMS in VTEM EMP packing Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 19/25] drm/connector: hdmi: Add QMS to VTEM EMP generation Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 20/25] drm/connector: hdmi: Add QMS state validation and computation Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 21/25] drm/rockchip: dw_hdmi_qp: Add QMS support Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 22/25] drm/tests: hdmi: Add "Game Mode" VRR tests Nicolas Frattaroli
2026-09-21 16:26 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 23/25] drm/tests: hdmi: Add Fixed/Constrained rate " Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 24/25] drm/tests: hdmi: Add Quick Media Switching tests Nicolas Frattaroli
2026-09-21 16:26 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 25/25] drm/atomic: Disable VRR in helper_set_config Nicolas Frattaroli
2026-09-21 16:26 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921160730.229451F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=nicolas.frattaroli@collabora.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox