dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown
@ 2026-09-22 15:51 Arthur Liberman
  2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman
  2026-09-22 15:58 ` [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
  0 siblings, 2 replies; 6+ messages in thread
From: Arthur Liberman @ 2026-09-22 15:51 UTC (permalink / raw)
  To: amd-gfx@lists.freedesktop.org
  Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
	Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher,
	Christian König, airlied@gmail.com, simona@ffwll.ch

From b554858dc4f2c48be0d44e3c66ed781842365bd1 Mon Sep 17 00:00:00 2001
Message-ID: <cover.1790083445.git.arthur_liberman@hotmail.com>
From: Arthur Liberman <arthur_liberman@hotmail.com>
Date: Tue, 22 Sep 2026 16:24:05 +0300
Subject: [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown

*** BLURB HERE ***

Arthur Liberman (3):
  drm/amd/display: fix NULL stream deref on MST DPMS-off
  drm/amd/display: skip destructive HPD verify on live links
  drm/amd/display: skip MST slot release if port is gone

 .../amd/display/amdgpu_dm/amdgpu_dm_mst_types.c |  6 +++++-
 drivers/gpu/drm/amd/display/dc/core/dc_stream.c | 14 ++++++++++++--
 .../drm/amd/display/dc/link/link_detection.c    | 17 ++++++++++++++++-
 drivers/gpu/drm/amd/display/dc/link/link_dpms.c |  7 +++++++
 4 files changed, 40 insertions(+), 4 deletions(-)


base-commit: cf48bd0a46279f4607956cb17c71bda96ee802e3
-- 
2.55.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off
  2026-09-22 15:51 [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
@ 2026-09-22 15:53 ` Arthur Liberman
  2026-09-22 15:53   ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman
  2026-09-22 16:09   ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off sashiko-bot
  2026-09-22 15:58 ` [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
  1 sibling, 2 replies; 6+ messages in thread
From: Arthur Liberman @ 2026-09-22 15:53 UTC (permalink / raw)
  To: amd-gfx@lists.freedesktop.org
  Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
	Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher,
	Christian König, airlied@gmail.com, simona@ffwll.ch

From dff1f3ce5f313dc88503c1da01c959638b7d42e4 Mon Sep 17 00:00:00 2001
Message-ID: <dff1f3ce5f313dc88503c1da01c959638b7d42e4.1790083445.git.arthur_liberman@hotmail.com>
In-Reply-To: <cover.1790083445.git.arthur_liberman@hotmail.com>
References: <cover.1790083445.git.arthur_liberman@hotmail.com>
From: Arthur Liberman <arthur_liberman@hotmail.com>
Date: Mon, 21 Sep 2026 01:41:20 +0300
Subject: [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off

dc_stream_get_status() and dc_stream_get_status_const() load
stream->ctx with no NULL check. HPD detect of an MST daisy-chain
reaches them from link_set_all_streams_dpms_off_for_link() through
dc_commit_updates_for_stream(). On 6.13 that oopsed when the first
full update released current_state and the next loop iteration passed
the cleared pipe stream:

  BUG: unable to handle page fault for address: 0000000000006460
  RIP: dc_stream_get_status
  Call Trace:
    update_planes_and_stream_v1
    dc_commit_updates_for_stream
    link_set_all_streams_dpms_off_for_link
    link_detect
    handle_hpd_irq_helper

Commit 1561782686cc ("drm/amd/display: fix link_set_dpms_off
multi-display MST corner case") caches those pointers before the
loop, so the loop no longer re-reads the cleared pipe_ctx. The
helpers still oops if a caller passes NULL.

Return NULL when stream is NULL, and skip a NULL cached entry in
the DPMS-off loop.

Fixes: 09f609c34fc8 ("drm/amd/display: Fix driver load crash in amdgpu_dm")
Cc: stable@vger.kernel.org
Assisted-by: Cursor:xai-grok-4.6
Signed-off-by: Arthur Liberman <arthur_liberman@hotmail.com>
---
 drivers/gpu/drm/amd/display/dc/core/dc_stream.c | 14 ++++++++++++--
 drivers/gpu/drm/amd/display/dc/link/link_dpms.c |  7 +++++++
 2 files changed, 19 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/amd/display/dc/core/dc_stream.c b/drivers/gpu/drm/amd/display/dc/core/dc_stream.c
index 8d3aacc7b96c..e5134c103bdb 100644
--- a/drivers/gpu/drm/amd/display/dc/core/dc_stream.c
+++ b/drivers/gpu/drm/amd/display/dc/core/dc_stream.c
@@ -267,14 +267,24 @@ struct dc_stream_state *dc_copy_stream(const struct dc_stream_state *stream)
 struct dc_stream_status *dc_stream_get_status(
 	struct dc_stream_state *stream)
 {
-	struct dc *dc = stream->ctx->dc;
+	struct dc *dc;
+
+	if (!stream)
+		return NULL;
+
+	dc = stream->ctx->dc;
 	return dc_state_get_stream_status(dc->current_state, stream);
 }
 
 const struct dc_stream_status *dc_stream_get_status_const(
 	const struct dc_stream_state *stream)
 {
-	struct dc *dc = stream->ctx->dc;
+	struct dc *dc;
+
+	if (!stream)
+		return NULL;
+
+	dc = stream->ctx->dc;
 	return dc_state_get_stream_status(dc->current_state, stream);
 }
 
diff --git a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
index 48b086d15ab0..17cb831ce8c4 100644
--- a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
+++ b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
@@ -177,6 +177,13 @@ void link_set_all_streams_dpms_off_for_link(struct dc_link *link)
 		streams[i] = pipes[i]->stream;
 
 	for (i = 0; i < count; i++) {
+		/* A full update can release current_state and NULL remaining
+		 * pipe streams. MST daisy-chains have multiple streams on one
+		 * link, so skip any that disappeared mid-loop.
+		 */
+		if (!streams[i])
+			continue;
+
 		stream_update.stream = streams[i];
 		dc_commit_updates_for_stream(link->ctx->dc, NULL, 0,
 				streams[i], &stream_update,
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links
  2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman
@ 2026-09-22 15:53   ` Arthur Liberman
  2026-09-22 15:54     ` [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone Arthur Liberman
  2026-09-22 16:09   ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off sashiko-bot
  1 sibling, 1 reply; 6+ messages in thread
From: Arthur Liberman @ 2026-09-22 15:53 UTC (permalink / raw)
  To: amd-gfx@lists.freedesktop.org
  Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
	Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher,
	Christian König, airlied@gmail.com, simona@ffwll.ch

From 242fdfdef877fd756a789b1bba8323fb1de0b594 Mon Sep 17 00:00:00 2001
Message-ID: <242fdfdef877fd756a789b1bba8323fb1de0b594.1790083445.git.arthur_liberman@hotmail.com>
In-Reply-To: <cover.1790083445.git.arthur_liberman@hotmail.com>
References: <cover.1790083445.git.arthur_liberman@hotmail.com>
From: Arthur Liberman <arthur_liberman@hotmail.com>
Date: Mon, 21 Sep 2026 01:41:29 +0300
Subject: [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live
 links

Destructive link-cap verify DPMS-offs every live stream from the HPD
worker via dc_commit_updates_for_stream(). DP takes that path unless
the link is embedded, training is skipped, or dpcd_caps.is_mst_capable
is set.

detect_link_and_local_sink() re-reads DPCD before
verify_link_capability(). Switching input or powering off an MST
daisy-chain while the CRTCs are still on can clear is_mst_capable,
so the MST exemption no longer applies and detect takes the
destructive path before MST rediscovery.

Keep the non-destructive verify while the link still has DPMS-on
master pipes. Userspace will disable the CRTCs; a later detect can
train.

Fixes: c282d9512cdd ("drm/amd/display: factor out dp detection link training and mst top detection")
Cc: stable@vger.kernel.org
Assisted-by: Cursor:xai-grok-4.6
Signed-off-by: Arthur Liberman <arthur_liberman@hotmail.com>
---
 .../drm/amd/display/dc/link/link_detection.c    | 17 ++++++++++++++++-
 1 file changed, 16 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/amd/display/dc/link/link_detection.c b/drivers/gpu/drm/amd/display/dc/link/link_detection.c
index 12fd4fd24a90..66fb3bc06a1f 100644
--- a/drivers/gpu/drm/amd/display/dc/link/link_detection.c
+++ b/drivers/gpu/drm/amd/display/dc/link/link_detection.c
@@ -960,13 +960,28 @@ static bool should_verify_link_capability_destructively(struct dc_link *link,
 					link);
 
 	if (dc_is_dp_signal(link->local_sink->sink_signal)) {
+		struct pipe_ctx *pipes[MAX_PIPES];
+		uint8_t active_count = 0;
+
 		max_link_cap = dp_get_max_link_cap(link);
 		destrictive = true;
 
+		/*
+		 * Destructive verify DPMS-off's every live stream via
+		 * dc_commit_updates_for_stream() on the HPD worker. That
+		 * races MST teardown (input switch / power-off while the
+		 * displays are still on) and can NULL remaining pipe streams.
+		 * Keep the non-destructive path until userspace disables the
+		 * CRTCs; a later detect can train.
+		 */
+		link_get_master_pipes_with_dpms_on(link, link->dc->current_state,
+						   &active_count, pipes);
+
 		if (link->dc->debug.skip_detection_link_training ||
 				dc_is_embedded_signal(link->local_sink->sink_signal) ||
 				(link->ep_type == DISPLAY_ENDPOINT_USB4_DPIA &&
-				!link->dc->config.enable_dpia_pre_training)) {
+				!link->dc->config.enable_dpia_pre_training) ||
+				active_count) {
 			destrictive = false;
 		} else if (link_dp_get_encoding_format(&max_link_cap) ==
 				DP_8b_10b_ENCODING) {
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone
  2026-09-22 15:53   ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman
@ 2026-09-22 15:54     ` Arthur Liberman
  0 siblings, 0 replies; 6+ messages in thread
From: Arthur Liberman @ 2026-09-22 15:54 UTC (permalink / raw)
  To: amd-gfx@lists.freedesktop.org
  Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
	Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher,
	Christian König, airlied@gmail.com, simona@ffwll.ch

From b554858dc4f2c48be0d44e3c66ed781842365bd1 Mon Sep 17 00:00:00 2001
Message-ID: <b554858dc4f2c48be0d44e3c66ed781842365bd1.1790083445.git.arthur_liberman@hotmail.com>
In-Reply-To: <cover.1790083445.git.arthur_liberman@hotmail.com>
References: <cover.1790083445.git.arthur_liberman@hotmail.com>
From: Arthur Liberman <arthur_liberman@hotmail.com>
Date: Mon, 21 Sep 2026 16:36:52 +0300
Subject: [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone

dm_dp_mst_atomic_check() always called
drm_dp_atomic_release_time_slots() even when mst_root or the output
port connector was already cleared after an MST topology restart.
That is the amdgpu side of the kwin_wayland NULL deref in the helper.

Do not call the helper unless mst_root, the port, and port->connector
are still present.

Fixes: 3261e013c0ca ("drm/amd/display: Add MST atomic routines")
Cc: stable@vger.kernel.org
Assisted-by: Cursor:xai-grok-4.6
Signed-off-by: Arthur Liberman <arthur_liberman@hotmail.com>
---
 drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c
index a5b15bef8aa0..104b874b6ef6 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c
@@ -614,9 +614,13 @@ STATIC_IFN_KUNIT int dm_dp_mst_atomic_check(struct drm_connector *connector,
 					    struct drm_atomic_commit *state)
 {
 	struct amdgpu_dm_connector *aconnector = to_amdgpu_dm_connector(connector);
-	struct drm_dp_mst_topology_mgr *mst_mgr = &aconnector->mst_root->mst_mgr;
+	struct drm_dp_mst_topology_mgr *mst_mgr;
 	struct drm_dp_mst_port *mst_port = aconnector->mst_output_port;
 
+	if (!aconnector->mst_root || !mst_port || !mst_port->connector)
+		return 0;
+
+	mst_mgr = &aconnector->mst_root->mst_mgr;
 	return drm_dp_atomic_release_time_slots(state, mst_mgr, mst_port);
 }
 EXPORT_IF_KUNIT(dm_dp_mst_atomic_check);
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* Re: [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown
  2026-09-22 15:51 [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
  2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman
@ 2026-09-22 15:58 ` Arthur Liberman
  1 sibling, 0 replies; 6+ messages in thread
From: Arthur Liberman @ 2026-09-22 15:58 UTC (permalink / raw)
  To: amd-gfx@lists.freedesktop.org
  Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
	Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher,
	Christian König, airlied@gmail.com, simona@ffwll.ch

Sorry, the cover letter still had the placeholder text. The summary is:

MST hotplug and topology teardown can run while the CRTCs are still
enabled. That oopses in two amdgpu paths, and a third path turns the
link off during detection.

HPD detect of an MST daisy-chain reaches dc_stream_get_status() from
link_set_all_streams_dpms_off_for_link() with a NULL stream. The
helpers load stream->ctx with no NULL check. Return NULL when stream
is NULL, and skip a NULL entry in the DPMS-off loop.

verify_link_capability() DPMS-offs every live stream unless the link
is embedded, training is skipped, or dpcd_caps.is_mst_capable is set.
detect_link_and_local_sink() re-reads DPCD first and can clear
is_mst_capable while the CRTCs are still on, so detect takes the
destructive path before MST rediscovery. Keep the non-destructive
verify while the link still has DPMS-on master pipes.

dm_dp_mst_atomic_check() calls drm_dp_atomic_release_time_slots()
after an MST topology restart has cleared mst_root or the output port
connector. That is the amdgpu side of a NULL deref in the helper
during kwin_wayland atomic check. Call the helper only while
mst_root, the port, and port->connector are still present.

The matching drm_dp_mst helper fix is sent separately to dri-devel.

Reproduced on a Raphael iGPU (Ryzen 9 9950X) with a USB-C to
DisplayPort MST daisy-chain.

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off
  2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman
  2026-09-22 15:53   ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman
@ 2026-09-22 16:09   ` sashiko-bot
  1 sibling, 0 replies; 6+ messages in thread
From: sashiko-bot @ 2026-09-22 16:09 UTC (permalink / raw)
  To: Arthur Liberman; +Cc: dri-devel

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] drm/amd/display: dead code in MST DPMS-off loop
--

commit 07293e89053ea9e3ce60dc0852be04a50a4ec01e
Author: Arthur Liberman <arthur_liberman@hotmail.com>

    drm/amd/display: fix NULL stream deref on MST DPMS-off

This commit adds a NULL check for streams in the MST DPMS-off loop in
link_set_all_streams_dpms_off_for_link() and adds stream NULL checks in
dc_stream_get_status().

> diff --git a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
> index 48b086d15ab0c..17cb831ce8c48 100644
> --- a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
> +++ b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
> @@ -177,6 +177,13 @@ void link_set_all_streams_dpms_off_for_link(struct dc_link *link)
>  		streams[i] = pipes[i]->stream;
>  
>  	for (i = 0; i < count; i++) {
> +		/* A full update can release current_state and NULL remaining
> +		 * pipe streams. MST daisy-chains have multiple streams on one
> +		 * link, so skip any that disappeared mid-loop.
> +		 */
> +		if (!streams[i])
> +			continue;
> +

[Severity: Low]
Does this check actually protect against mid-loop state changes?

The function link_get_master_pipes_with_dpms_on() guarantees that
pipes[i]->stream is non-NULL when populated, and these pointers are copied
into the local streams[] array before the loop.

Since streams[] is a local array and its elements are not updated inside this
loop, is it possible for streams[i] to become NULL during iteration? It appears
this check might be dead code that provides no runtime protection.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/DB9PR03MB73884B0D604BA858636247CF8A832@DB9PR03MB7388.eurprd03.prod.outlook.com?part=1

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-22 16:09 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-22 15:51 [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman
2026-09-22 15:53   ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman
2026-09-22 15:54     ` [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone Arthur Liberman
2026-09-22 16:09   ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off sashiko-bot
2026-09-22 15:58 ` [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox