From: sashiko-bot@kernel.org
To: "Nicolas Frattaroli" <nicolas.frattaroli@collabora.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH RFC 15/25] drm/edid: Parse QMS flag from HDMI SCDS
Date: Mon, 21 Sep 2026 16:18:13 +0000 [thread overview]
Message-ID: <20260921161813.9CC441F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260921-vrr-limiter-uapi-v1-15-2fcd7d011646@collabora.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] drm/edid: redundant VRR parsing has off-by-one length checks skipping valid EDID data
--
commit 5e1483c916355c112a6de67649f48244b2260d1e
Author: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
drm/edid: Parse QMS flag from HDMI SCDS
This commit adds support for parsing the Quick Media Switching (QMS) flag
from the HDMI Forum EDID extension. It adds the definition to the EDID
header file and parses it into the qms_capable member of drm_hdmi_info.
> diff --git a/drivers/gpu/drm/drm_edid.c b/drivers/gpu/drm/drm_edid.c
> index cc6f2ba8c9f4d..5a7d3b7e65daa 100644
> --- a/drivers/gpu/drm/drm_edid.c
> +++ b/drivers/gpu/drm/drm_edid.c
[ ... ]
> @@ -6318,6 +6318,7 @@ static void drm_parse_vrr_info(struct drm_display_info *info, const u8 *hf_scds)
> if (pld_len < 9)
> return;
>
> info->hdmi.cinema_vrr = !!(hf_scds[8] & DRM_EDID_CINEMA_VRR);
> + info->hdmi.qms_capable = !!(hf_scds[8] & DRM_EDID_QMS);
[Severity: Medium]
Does this off-by-one bounds check skip valid EDID data?
Looking at drm_parse_vrr_info(), it returns early if the payload length is
less than 9. This means it silently skips parsing the valid QMS and CinemaVRR
flags at hf_scds[8] for sinks whose payloads are exactly 8 bytes long.
For comparison, the pre-existing drm_parse_hdmi_gaming_info() function
correctly parses this exact same payload byte using:
if (cea_db_payload_len(db) < 8)
return;
Could we update the pld_len check in drm_parse_vrr_info() to < 8 so that it
matches the bounds logic in drm_parse_hdmi_gaming_info() and doesn't break
QMS/VRR limit detection for those sinks?
>
> if (pld_len < 10)
> return;
[ ... ]
> diff --git a/include/drm/drm_connector.h b/include/drm/drm_connector.h
> index b147b8474f1a9..c97cf0625fda5 100644
> --- a/include/drm/drm_connector.h
> +++ b/include/drm/drm_connector.h
> @@ -386,6 +386,9 @@ struct drm_hdmi_info {
>
> /** @cinema_vrr: The sink supports "CinemaVRR" */
> bool cinema_vrr;
> +
> + /** @qms_capable: The sink supports Quick Media Switching */
> + bool qms_capable;
[Severity: Medium]
Does the cinema_vrr field duplicate the existing vrr_cap.cinema_vrr field?
This isn't a bug introduced by this patch, but having a duplicate field can
create desynchronized state when parsed. Would it be better to consolidate
this redundant VRR parsing altogether?
> };
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260921-vrr-limiter-uapi-v1-0-2fcd7d011646@collabora.com?part=15
next prev parent reply other threads:[~2026-09-21 16:18 UTC|newest]
Thread overview: 75+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 15:51 [PATCH RFC 00/25] VRR Target Rate Limiter KMS uAPI and Implementation Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 01/25] drm/edid: Add a query for vrr range Nicolas Frattaroli
2026-09-21 16:08 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 02/25] drm: Add VRR state Nicolas Frattaroli
2026-09-24 6:55 ` Vidith Madhu
2026-09-21 15:51 ` [PATCH RFC 03/25] drm/atomic-helper: Set mode_changed on vrr_enabled change Nicolas Frattaroli
2026-09-21 16:13 ` sashiko-bot
2026-09-21 21:59 ` Leo Li
2026-09-22 12:53 ` Nicolas Frattaroli
2026-09-22 13:22 ` Maxime Ripard
2026-09-24 6:45 ` Vidith Madhu
2026-09-21 22:01 ` Leo Li
2026-09-21 15:51 ` [PATCH RFC 04/25] video/hdmi: Add VTEM EMP packing Nicolas Frattaroli
2026-09-21 16:07 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 05/25] drm/bridge: Add VTEM EMP support Nicolas Frattaroli
2026-09-21 16:01 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 06/25] drm/connector: hdmi: Add VTEM EMP generation Nicolas Frattaroli
2026-09-21 16:13 ` sashiko-bot
2026-09-25 3:48 ` Vidith Madhu
2026-09-25 10:42 ` Daniel Stone
2026-09-25 11:11 ` Jani Nikula
2026-09-26 11:03 ` Nicolas Frattaroli
2026-09-29 18:55 ` Vidith Madhu
2026-09-30 7:50 ` Michel Dänzer
2026-09-21 15:51 ` [PATCH RFC 07/25] drm/crtc-helper: Add VRR helper functions Nicolas Frattaroli
2026-09-21 16:05 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 08/25] drm/bridge: synopsys: Add VTEM EMP support Nicolas Frattaroli
2026-09-21 16:06 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 09/25] drm/connector: Add drm_display_info_is_vrr_capable Nicolas Frattaroli
2026-09-21 16:04 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 10/25] drm/rockchip: dw_hdmi_qp: Add VRR support Nicolas Frattaroli
2026-09-21 16:09 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 11/25] drm/rockchip: vop2: Enable VRR Nicolas Frattaroli
2026-09-21 16:16 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 12/25] drm/edid: Parse CinemaVRR flag from HDMI SCDS Nicolas Frattaroli
2026-09-21 16:13 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 13/25] drm: Add VRR target frame rate properties Nicolas Frattaroli
2026-09-21 16:14 ` sashiko-bot
2026-09-21 22:23 ` Leo Li
2026-09-22 15:26 ` Nicolas Frattaroli
2026-09-25 18:42 ` Leo Li
2026-09-26 12:13 ` Nicolas Frattaroli
2026-09-28 8:10 ` Michel Dänzer
2026-09-29 14:34 ` Leo Li
2026-09-29 16:00 ` Michel Dänzer
2026-09-29 18:14 ` Nicolas Frattaroli
2026-09-29 18:24 ` Nicolas Frattaroli
2026-09-23 9:51 ` Michel Dänzer
2026-09-23 9:54 ` Michel Dänzer
2026-09-23 14:39 ` Nicolas Frattaroli
2026-09-24 7:01 ` Vidith Madhu
2026-09-24 12:10 ` Nicolas Frattaroli
2026-09-29 19:16 ` Vidith Madhu
2026-09-29 19:55 ` Nicolas Frattaroli
2026-09-29 21:05 ` Vidith Madhu
2026-09-29 22:21 ` Xaver Hugl
2026-09-21 15:51 ` [PATCH RFC 14/25] drm: Implement VRR rate limiting Nicolas Frattaroli
2026-09-21 16:17 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 15/25] drm/edid: Parse QMS flag from HDMI SCDS Nicolas Frattaroli
2026-09-21 16:18 ` sashiko-bot [this message]
2026-09-21 15:51 ` [PATCH RFC 16/25] drm/edid: Parse QMS TFR min/max flags " Nicolas Frattaroli
2026-09-21 16:19 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 17/25] drm/connector: Add "qms_enabled" drm property Nicolas Frattaroli
2026-09-21 16:20 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 18/25] video/hdmi: Add support for QMS in VTEM EMP packing Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 19/25] drm/connector: hdmi: Add QMS to VTEM EMP generation Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 20/25] drm/connector: hdmi: Add QMS state validation and computation Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 21/25] drm/rockchip: dw_hdmi_qp: Add QMS support Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 22/25] drm/tests: hdmi: Add "Game Mode" VRR tests Nicolas Frattaroli
2026-09-21 16:26 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 23/25] drm/tests: hdmi: Add Fixed/Constrained rate " Nicolas Frattaroli
2026-09-21 15:51 ` [PATCH RFC 24/25] drm/tests: hdmi: Add Quick Media Switching tests Nicolas Frattaroli
2026-09-21 16:26 ` sashiko-bot
2026-09-21 15:51 ` [PATCH RFC 25/25] drm/atomic: Disable VRR in helper_set_config Nicolas Frattaroli
2026-09-21 16:26 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921161813.9CC441F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=nicolas.frattaroli@collabora.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox