* [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown
@ 2026-09-22 15:51 Arthur Liberman
2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman
2026-09-22 15:58 ` [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
0 siblings, 2 replies; 6+ messages in thread
From: Arthur Liberman @ 2026-09-22 15:51 UTC (permalink / raw)
To: amd-gfx@lists.freedesktop.org
Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher,
Christian König, airlied@gmail.com, simona@ffwll.ch
From b554858dc4f2c48be0d44e3c66ed781842365bd1 Mon Sep 17 00:00:00 2001
Message-ID: <cover.1790083445.git.arthur_liberman@hotmail.com>
From: Arthur Liberman <arthur_liberman@hotmail.com>
Date: Tue, 22 Sep 2026 16:24:05 +0300
Subject: [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown
*** BLURB HERE ***
Arthur Liberman (3):
drm/amd/display: fix NULL stream deref on MST DPMS-off
drm/amd/display: skip destructive HPD verify on live links
drm/amd/display: skip MST slot release if port is gone
.../amd/display/amdgpu_dm/amdgpu_dm_mst_types.c | 6 +++++-
drivers/gpu/drm/amd/display/dc/core/dc_stream.c | 14 ++++++++++++--
.../drm/amd/display/dc/link/link_detection.c | 17 ++++++++++++++++-
drivers/gpu/drm/amd/display/dc/link/link_dpms.c | 7 +++++++
4 files changed, 40 insertions(+), 4 deletions(-)
base-commit: cf48bd0a46279f4607956cb17c71bda96ee802e3
--
2.55.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off
2026-09-22 15:51 [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
@ 2026-09-22 15:53 ` Arthur Liberman
2026-09-22 15:53 ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman
2026-09-22 16:09 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off sashiko-bot
2026-09-22 15:58 ` [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
1 sibling, 2 replies; 6+ messages in thread
From: Arthur Liberman @ 2026-09-22 15:53 UTC (permalink / raw)
To: amd-gfx@lists.freedesktop.org
Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher,
Christian König, airlied@gmail.com, simona@ffwll.ch
From dff1f3ce5f313dc88503c1da01c959638b7d42e4 Mon Sep 17 00:00:00 2001
Message-ID: <dff1f3ce5f313dc88503c1da01c959638b7d42e4.1790083445.git.arthur_liberman@hotmail.com>
In-Reply-To: <cover.1790083445.git.arthur_liberman@hotmail.com>
References: <cover.1790083445.git.arthur_liberman@hotmail.com>
From: Arthur Liberman <arthur_liberman@hotmail.com>
Date: Mon, 21 Sep 2026 01:41:20 +0300
Subject: [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off
dc_stream_get_status() and dc_stream_get_status_const() load
stream->ctx with no NULL check. HPD detect of an MST daisy-chain
reaches them from link_set_all_streams_dpms_off_for_link() through
dc_commit_updates_for_stream(). On 6.13 that oopsed when the first
full update released current_state and the next loop iteration passed
the cleared pipe stream:
BUG: unable to handle page fault for address: 0000000000006460
RIP: dc_stream_get_status
Call Trace:
update_planes_and_stream_v1
dc_commit_updates_for_stream
link_set_all_streams_dpms_off_for_link
link_detect
handle_hpd_irq_helper
Commit 1561782686cc ("drm/amd/display: fix link_set_dpms_off
multi-display MST corner case") caches those pointers before the
loop, so the loop no longer re-reads the cleared pipe_ctx. The
helpers still oops if a caller passes NULL.
Return NULL when stream is NULL, and skip a NULL cached entry in
the DPMS-off loop.
Fixes: 09f609c34fc8 ("drm/amd/display: Fix driver load crash in amdgpu_dm")
Cc: stable@vger.kernel.org
Assisted-by: Cursor:xai-grok-4.6
Signed-off-by: Arthur Liberman <arthur_liberman@hotmail.com>
---
drivers/gpu/drm/amd/display/dc/core/dc_stream.c | 14 ++++++++++++--
drivers/gpu/drm/amd/display/dc/link/link_dpms.c | 7 +++++++
2 files changed, 19 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/amd/display/dc/core/dc_stream.c b/drivers/gpu/drm/amd/display/dc/core/dc_stream.c
index 8d3aacc7b96c..e5134c103bdb 100644
--- a/drivers/gpu/drm/amd/display/dc/core/dc_stream.c
+++ b/drivers/gpu/drm/amd/display/dc/core/dc_stream.c
@@ -267,14 +267,24 @@ struct dc_stream_state *dc_copy_stream(const struct dc_stream_state *stream)
struct dc_stream_status *dc_stream_get_status(
struct dc_stream_state *stream)
{
- struct dc *dc = stream->ctx->dc;
+ struct dc *dc;
+
+ if (!stream)
+ return NULL;
+
+ dc = stream->ctx->dc;
return dc_state_get_stream_status(dc->current_state, stream);
}
const struct dc_stream_status *dc_stream_get_status_const(
const struct dc_stream_state *stream)
{
- struct dc *dc = stream->ctx->dc;
+ struct dc *dc;
+
+ if (!stream)
+ return NULL;
+
+ dc = stream->ctx->dc;
return dc_state_get_stream_status(dc->current_state, stream);
}
diff --git a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
index 48b086d15ab0..17cb831ce8c4 100644
--- a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
+++ b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
@@ -177,6 +177,13 @@ void link_set_all_streams_dpms_off_for_link(struct dc_link *link)
streams[i] = pipes[i]->stream;
for (i = 0; i < count; i++) {
+ /* A full update can release current_state and NULL remaining
+ * pipe streams. MST daisy-chains have multiple streams on one
+ * link, so skip any that disappeared mid-loop.
+ */
+ if (!streams[i])
+ continue;
+
stream_update.stream = streams[i];
dc_commit_updates_for_stream(link->ctx->dc, NULL, 0,
streams[i], &stream_update,
--
2.55.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links
2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman
@ 2026-09-22 15:53 ` Arthur Liberman
2026-09-22 15:54 ` [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone Arthur Liberman
2026-09-22 16:09 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off sashiko-bot
1 sibling, 1 reply; 6+ messages in thread
From: Arthur Liberman @ 2026-09-22 15:53 UTC (permalink / raw)
To: amd-gfx@lists.freedesktop.org
Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher,
Christian König, airlied@gmail.com, simona@ffwll.ch
From 242fdfdef877fd756a789b1bba8323fb1de0b594 Mon Sep 17 00:00:00 2001
Message-ID: <242fdfdef877fd756a789b1bba8323fb1de0b594.1790083445.git.arthur_liberman@hotmail.com>
In-Reply-To: <cover.1790083445.git.arthur_liberman@hotmail.com>
References: <cover.1790083445.git.arthur_liberman@hotmail.com>
From: Arthur Liberman <arthur_liberman@hotmail.com>
Date: Mon, 21 Sep 2026 01:41:29 +0300
Subject: [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live
links
Destructive link-cap verify DPMS-offs every live stream from the HPD
worker via dc_commit_updates_for_stream(). DP takes that path unless
the link is embedded, training is skipped, or dpcd_caps.is_mst_capable
is set.
detect_link_and_local_sink() re-reads DPCD before
verify_link_capability(). Switching input or powering off an MST
daisy-chain while the CRTCs are still on can clear is_mst_capable,
so the MST exemption no longer applies and detect takes the
destructive path before MST rediscovery.
Keep the non-destructive verify while the link still has DPMS-on
master pipes. Userspace will disable the CRTCs; a later detect can
train.
Fixes: c282d9512cdd ("drm/amd/display: factor out dp detection link training and mst top detection")
Cc: stable@vger.kernel.org
Assisted-by: Cursor:xai-grok-4.6
Signed-off-by: Arthur Liberman <arthur_liberman@hotmail.com>
---
.../drm/amd/display/dc/link/link_detection.c | 17 ++++++++++++++++-
1 file changed, 16 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/amd/display/dc/link/link_detection.c b/drivers/gpu/drm/amd/display/dc/link/link_detection.c
index 12fd4fd24a90..66fb3bc06a1f 100644
--- a/drivers/gpu/drm/amd/display/dc/link/link_detection.c
+++ b/drivers/gpu/drm/amd/display/dc/link/link_detection.c
@@ -960,13 +960,28 @@ static bool should_verify_link_capability_destructively(struct dc_link *link,
link);
if (dc_is_dp_signal(link->local_sink->sink_signal)) {
+ struct pipe_ctx *pipes[MAX_PIPES];
+ uint8_t active_count = 0;
+
max_link_cap = dp_get_max_link_cap(link);
destrictive = true;
+ /*
+ * Destructive verify DPMS-off's every live stream via
+ * dc_commit_updates_for_stream() on the HPD worker. That
+ * races MST teardown (input switch / power-off while the
+ * displays are still on) and can NULL remaining pipe streams.
+ * Keep the non-destructive path until userspace disables the
+ * CRTCs; a later detect can train.
+ */
+ link_get_master_pipes_with_dpms_on(link, link->dc->current_state,
+ &active_count, pipes);
+
if (link->dc->debug.skip_detection_link_training ||
dc_is_embedded_signal(link->local_sink->sink_signal) ||
(link->ep_type == DISPLAY_ENDPOINT_USB4_DPIA &&
- !link->dc->config.enable_dpia_pre_training)) {
+ !link->dc->config.enable_dpia_pre_training) ||
+ active_count) {
destrictive = false;
} else if (link_dp_get_encoding_format(&max_link_cap) ==
DP_8b_10b_ENCODING) {
--
2.55.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone
2026-09-22 15:53 ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman
@ 2026-09-22 15:54 ` Arthur Liberman
0 siblings, 0 replies; 6+ messages in thread
From: Arthur Liberman @ 2026-09-22 15:54 UTC (permalink / raw)
To: amd-gfx@lists.freedesktop.org
Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher,
Christian König, airlied@gmail.com, simona@ffwll.ch
From b554858dc4f2c48be0d44e3c66ed781842365bd1 Mon Sep 17 00:00:00 2001
Message-ID: <b554858dc4f2c48be0d44e3c66ed781842365bd1.1790083445.git.arthur_liberman@hotmail.com>
In-Reply-To: <cover.1790083445.git.arthur_liberman@hotmail.com>
References: <cover.1790083445.git.arthur_liberman@hotmail.com>
From: Arthur Liberman <arthur_liberman@hotmail.com>
Date: Mon, 21 Sep 2026 16:36:52 +0300
Subject: [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone
dm_dp_mst_atomic_check() always called
drm_dp_atomic_release_time_slots() even when mst_root or the output
port connector was already cleared after an MST topology restart.
That is the amdgpu side of the kwin_wayland NULL deref in the helper.
Do not call the helper unless mst_root, the port, and port->connector
are still present.
Fixes: 3261e013c0ca ("drm/amd/display: Add MST atomic routines")
Cc: stable@vger.kernel.org
Assisted-by: Cursor:xai-grok-4.6
Signed-off-by: Arthur Liberman <arthur_liberman@hotmail.com>
---
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c
index a5b15bef8aa0..104b874b6ef6 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c
@@ -614,9 +614,13 @@ STATIC_IFN_KUNIT int dm_dp_mst_atomic_check(struct drm_connector *connector,
struct drm_atomic_commit *state)
{
struct amdgpu_dm_connector *aconnector = to_amdgpu_dm_connector(connector);
- struct drm_dp_mst_topology_mgr *mst_mgr = &aconnector->mst_root->mst_mgr;
+ struct drm_dp_mst_topology_mgr *mst_mgr;
struct drm_dp_mst_port *mst_port = aconnector->mst_output_port;
+ if (!aconnector->mst_root || !mst_port || !mst_port->connector)
+ return 0;
+
+ mst_mgr = &aconnector->mst_root->mst_mgr;
return drm_dp_atomic_release_time_slots(state, mst_mgr, mst_port);
}
EXPORT_IF_KUNIT(dm_dp_mst_atomic_check);
--
2.55.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown
2026-09-22 15:51 [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman
@ 2026-09-22 15:58 ` Arthur Liberman
1 sibling, 0 replies; 6+ messages in thread
From: Arthur Liberman @ 2026-09-22 15:58 UTC (permalink / raw)
To: amd-gfx@lists.freedesktop.org
Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher,
Christian König, airlied@gmail.com, simona@ffwll.ch
Sorry, the cover letter still had the placeholder text. The summary is:
MST hotplug and topology teardown can run while the CRTCs are still
enabled. That oopses in two amdgpu paths, and a third path turns the
link off during detection.
HPD detect of an MST daisy-chain reaches dc_stream_get_status() from
link_set_all_streams_dpms_off_for_link() with a NULL stream. The
helpers load stream->ctx with no NULL check. Return NULL when stream
is NULL, and skip a NULL entry in the DPMS-off loop.
verify_link_capability() DPMS-offs every live stream unless the link
is embedded, training is skipped, or dpcd_caps.is_mst_capable is set.
detect_link_and_local_sink() re-reads DPCD first and can clear
is_mst_capable while the CRTCs are still on, so detect takes the
destructive path before MST rediscovery. Keep the non-destructive
verify while the link still has DPMS-on master pipes.
dm_dp_mst_atomic_check() calls drm_dp_atomic_release_time_slots()
after an MST topology restart has cleared mst_root or the output port
connector. That is the amdgpu side of a NULL deref in the helper
during kwin_wayland atomic check. Call the helper only while
mst_root, the port, and port->connector are still present.
The matching drm_dp_mst helper fix is sent separately to dri-devel.
Reproduced on a Raphael iGPU (Ryzen 9 9950X) with a USB-C to
DisplayPort MST daisy-chain.
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off
2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman
2026-09-22 15:53 ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman
@ 2026-09-22 16:09 ` sashiko-bot
1 sibling, 0 replies; 6+ messages in thread
From: sashiko-bot @ 2026-09-22 16:09 UTC (permalink / raw)
To: Arthur Liberman; +Cc: dri-devel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] drm/amd/display: dead code in MST DPMS-off loop
--
commit 07293e89053ea9e3ce60dc0852be04a50a4ec01e
Author: Arthur Liberman <arthur_liberman@hotmail.com>
drm/amd/display: fix NULL stream deref on MST DPMS-off
This commit adds a NULL check for streams in the MST DPMS-off loop in
link_set_all_streams_dpms_off_for_link() and adds stream NULL checks in
dc_stream_get_status().
> diff --git a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
> index 48b086d15ab0c..17cb831ce8c48 100644
> --- a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
> +++ b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c
> @@ -177,6 +177,13 @@ void link_set_all_streams_dpms_off_for_link(struct dc_link *link)
> streams[i] = pipes[i]->stream;
>
> for (i = 0; i < count; i++) {
> + /* A full update can release current_state and NULL remaining
> + * pipe streams. MST daisy-chains have multiple streams on one
> + * link, so skip any that disappeared mid-loop.
> + */
> + if (!streams[i])
> + continue;
> +
[Severity: Low]
Does this check actually protect against mid-loop state changes?
The function link_get_master_pipes_with_dpms_on() guarantees that
pipes[i]->stream is non-NULL when populated, and these pointers are copied
into the local streams[] array before the loop.
Since streams[] is a local array and its elements are not updated inside this
loop, is it possible for streams[i] to become NULL during iteration? It appears
this check might be dead code that provides no runtime protection.
--
Sashiko AI review · https://sashiko.dev/#/patchset/DB9PR03MB73884B0D604BA858636247CF8A832@DB9PR03MB7388.eurprd03.prod.outlook.com?part=1
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-09-22 16:09 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-22 15:51 [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman
2026-09-22 15:53 ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman
2026-09-22 15:54 ` [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone Arthur Liberman
2026-09-22 16:09 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off sashiko-bot
2026-09-22 15:58 ` [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox