* [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown @ 2026-09-22 15:51 Arthur Liberman 2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman 2026-09-22 15:58 ` [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman 0 siblings, 2 replies; 6+ messages in thread From: Arthur Liberman @ 2026-09-22 15:51 UTC (permalink / raw) To: amd-gfx@lists.freedesktop.org Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher, Christian König, airlied@gmail.com, simona@ffwll.ch From b554858dc4f2c48be0d44e3c66ed781842365bd1 Mon Sep 17 00:00:00 2001 Message-ID: <cover.1790083445.git.arthur_liberman@hotmail.com> From: Arthur Liberman <arthur_liberman@hotmail.com> Date: Tue, 22 Sep 2026 16:24:05 +0300 Subject: [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown *** BLURB HERE *** Arthur Liberman (3): drm/amd/display: fix NULL stream deref on MST DPMS-off drm/amd/display: skip destructive HPD verify on live links drm/amd/display: skip MST slot release if port is gone .../amd/display/amdgpu_dm/amdgpu_dm_mst_types.c | 6 +++++- drivers/gpu/drm/amd/display/dc/core/dc_stream.c | 14 ++++++++++++-- .../drm/amd/display/dc/link/link_detection.c | 17 ++++++++++++++++- drivers/gpu/drm/amd/display/dc/link/link_dpms.c | 7 +++++++ 4 files changed, 40 insertions(+), 4 deletions(-) base-commit: cf48bd0a46279f4607956cb17c71bda96ee802e3 -- 2.55.0 ^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off 2026-09-22 15:51 [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman @ 2026-09-22 15:53 ` Arthur Liberman 2026-09-22 15:53 ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman 2026-09-22 16:09 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off sashiko-bot 2026-09-22 15:58 ` [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman 1 sibling, 2 replies; 6+ messages in thread From: Arthur Liberman @ 2026-09-22 15:53 UTC (permalink / raw) To: amd-gfx@lists.freedesktop.org Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher, Christian König, airlied@gmail.com, simona@ffwll.ch From dff1f3ce5f313dc88503c1da01c959638b7d42e4 Mon Sep 17 00:00:00 2001 Message-ID: <dff1f3ce5f313dc88503c1da01c959638b7d42e4.1790083445.git.arthur_liberman@hotmail.com> In-Reply-To: <cover.1790083445.git.arthur_liberman@hotmail.com> References: <cover.1790083445.git.arthur_liberman@hotmail.com> From: Arthur Liberman <arthur_liberman@hotmail.com> Date: Mon, 21 Sep 2026 01:41:20 +0300 Subject: [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off dc_stream_get_status() and dc_stream_get_status_const() load stream->ctx with no NULL check. HPD detect of an MST daisy-chain reaches them from link_set_all_streams_dpms_off_for_link() through dc_commit_updates_for_stream(). On 6.13 that oopsed when the first full update released current_state and the next loop iteration passed the cleared pipe stream: BUG: unable to handle page fault for address: 0000000000006460 RIP: dc_stream_get_status Call Trace: update_planes_and_stream_v1 dc_commit_updates_for_stream link_set_all_streams_dpms_off_for_link link_detect handle_hpd_irq_helper Commit 1561782686cc ("drm/amd/display: fix link_set_dpms_off multi-display MST corner case") caches those pointers before the loop, so the loop no longer re-reads the cleared pipe_ctx. The helpers still oops if a caller passes NULL. Return NULL when stream is NULL, and skip a NULL cached entry in the DPMS-off loop. Fixes: 09f609c34fc8 ("drm/amd/display: Fix driver load crash in amdgpu_dm") Cc: stable@vger.kernel.org Assisted-by: Cursor:xai-grok-4.6 Signed-off-by: Arthur Liberman <arthur_liberman@hotmail.com> --- drivers/gpu/drm/amd/display/dc/core/dc_stream.c | 14 ++++++++++++-- drivers/gpu/drm/amd/display/dc/link/link_dpms.c | 7 +++++++ 2 files changed, 19 insertions(+), 2 deletions(-) diff --git a/drivers/gpu/drm/amd/display/dc/core/dc_stream.c b/drivers/gpu/drm/amd/display/dc/core/dc_stream.c index 8d3aacc7b96c..e5134c103bdb 100644 --- a/drivers/gpu/drm/amd/display/dc/core/dc_stream.c +++ b/drivers/gpu/drm/amd/display/dc/core/dc_stream.c @@ -267,14 +267,24 @@ struct dc_stream_state *dc_copy_stream(const struct dc_stream_state *stream) struct dc_stream_status *dc_stream_get_status( struct dc_stream_state *stream) { - struct dc *dc = stream->ctx->dc; + struct dc *dc; + + if (!stream) + return NULL; + + dc = stream->ctx->dc; return dc_state_get_stream_status(dc->current_state, stream); } const struct dc_stream_status *dc_stream_get_status_const( const struct dc_stream_state *stream) { - struct dc *dc = stream->ctx->dc; + struct dc *dc; + + if (!stream) + return NULL; + + dc = stream->ctx->dc; return dc_state_get_stream_status(dc->current_state, stream); } diff --git a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c index 48b086d15ab0..17cb831ce8c4 100644 --- a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c +++ b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c @@ -177,6 +177,13 @@ void link_set_all_streams_dpms_off_for_link(struct dc_link *link) streams[i] = pipes[i]->stream; for (i = 0; i < count; i++) { + /* A full update can release current_state and NULL remaining + * pipe streams. MST daisy-chains have multiple streams on one + * link, so skip any that disappeared mid-loop. + */ + if (!streams[i]) + continue; + stream_update.stream = streams[i]; dc_commit_updates_for_stream(link->ctx->dc, NULL, 0, streams[i], &stream_update, -- 2.55.0 ^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links 2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman @ 2026-09-22 15:53 ` Arthur Liberman 2026-09-22 15:54 ` [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone Arthur Liberman 2026-09-22 16:09 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off sashiko-bot 1 sibling, 1 reply; 6+ messages in thread From: Arthur Liberman @ 2026-09-22 15:53 UTC (permalink / raw) To: amd-gfx@lists.freedesktop.org Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher, Christian König, airlied@gmail.com, simona@ffwll.ch From 242fdfdef877fd756a789b1bba8323fb1de0b594 Mon Sep 17 00:00:00 2001 Message-ID: <242fdfdef877fd756a789b1bba8323fb1de0b594.1790083445.git.arthur_liberman@hotmail.com> In-Reply-To: <cover.1790083445.git.arthur_liberman@hotmail.com> References: <cover.1790083445.git.arthur_liberman@hotmail.com> From: Arthur Liberman <arthur_liberman@hotmail.com> Date: Mon, 21 Sep 2026 01:41:29 +0300 Subject: [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Destructive link-cap verify DPMS-offs every live stream from the HPD worker via dc_commit_updates_for_stream(). DP takes that path unless the link is embedded, training is skipped, or dpcd_caps.is_mst_capable is set. detect_link_and_local_sink() re-reads DPCD before verify_link_capability(). Switching input or powering off an MST daisy-chain while the CRTCs are still on can clear is_mst_capable, so the MST exemption no longer applies and detect takes the destructive path before MST rediscovery. Keep the non-destructive verify while the link still has DPMS-on master pipes. Userspace will disable the CRTCs; a later detect can train. Fixes: c282d9512cdd ("drm/amd/display: factor out dp detection link training and mst top detection") Cc: stable@vger.kernel.org Assisted-by: Cursor:xai-grok-4.6 Signed-off-by: Arthur Liberman <arthur_liberman@hotmail.com> --- .../drm/amd/display/dc/link/link_detection.c | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/amd/display/dc/link/link_detection.c b/drivers/gpu/drm/amd/display/dc/link/link_detection.c index 12fd4fd24a90..66fb3bc06a1f 100644 --- a/drivers/gpu/drm/amd/display/dc/link/link_detection.c +++ b/drivers/gpu/drm/amd/display/dc/link/link_detection.c @@ -960,13 +960,28 @@ static bool should_verify_link_capability_destructively(struct dc_link *link, link); if (dc_is_dp_signal(link->local_sink->sink_signal)) { + struct pipe_ctx *pipes[MAX_PIPES]; + uint8_t active_count = 0; + max_link_cap = dp_get_max_link_cap(link); destrictive = true; + /* + * Destructive verify DPMS-off's every live stream via + * dc_commit_updates_for_stream() on the HPD worker. That + * races MST teardown (input switch / power-off while the + * displays are still on) and can NULL remaining pipe streams. + * Keep the non-destructive path until userspace disables the + * CRTCs; a later detect can train. + */ + link_get_master_pipes_with_dpms_on(link, link->dc->current_state, + &active_count, pipes); + if (link->dc->debug.skip_detection_link_training || dc_is_embedded_signal(link->local_sink->sink_signal) || (link->ep_type == DISPLAY_ENDPOINT_USB4_DPIA && - !link->dc->config.enable_dpia_pre_training)) { + !link->dc->config.enable_dpia_pre_training) || + active_count) { destrictive = false; } else if (link_dp_get_encoding_format(&max_link_cap) == DP_8b_10b_ENCODING) { -- 2.55.0 ^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone 2026-09-22 15:53 ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman @ 2026-09-22 15:54 ` Arthur Liberman 0 siblings, 0 replies; 6+ messages in thread From: Arthur Liberman @ 2026-09-22 15:54 UTC (permalink / raw) To: amd-gfx@lists.freedesktop.org Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher, Christian König, airlied@gmail.com, simona@ffwll.ch From b554858dc4f2c48be0d44e3c66ed781842365bd1 Mon Sep 17 00:00:00 2001 Message-ID: <b554858dc4f2c48be0d44e3c66ed781842365bd1.1790083445.git.arthur_liberman@hotmail.com> In-Reply-To: <cover.1790083445.git.arthur_liberman@hotmail.com> References: <cover.1790083445.git.arthur_liberman@hotmail.com> From: Arthur Liberman <arthur_liberman@hotmail.com> Date: Mon, 21 Sep 2026 16:36:52 +0300 Subject: [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone dm_dp_mst_atomic_check() always called drm_dp_atomic_release_time_slots() even when mst_root or the output port connector was already cleared after an MST topology restart. That is the amdgpu side of the kwin_wayland NULL deref in the helper. Do not call the helper unless mst_root, the port, and port->connector are still present. Fixes: 3261e013c0ca ("drm/amd/display: Add MST atomic routines") Cc: stable@vger.kernel.org Assisted-by: Cursor:xai-grok-4.6 Signed-off-by: Arthur Liberman <arthur_liberman@hotmail.com> --- drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c index a5b15bef8aa0..104b874b6ef6 100644 --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c @@ -614,9 +614,13 @@ STATIC_IFN_KUNIT int dm_dp_mst_atomic_check(struct drm_connector *connector, struct drm_atomic_commit *state) { struct amdgpu_dm_connector *aconnector = to_amdgpu_dm_connector(connector); - struct drm_dp_mst_topology_mgr *mst_mgr = &aconnector->mst_root->mst_mgr; + struct drm_dp_mst_topology_mgr *mst_mgr; struct drm_dp_mst_port *mst_port = aconnector->mst_output_port; + if (!aconnector->mst_root || !mst_port || !mst_port->connector) + return 0; + + mst_mgr = &aconnector->mst_root->mst_mgr; return drm_dp_atomic_release_time_slots(state, mst_mgr, mst_port); } EXPORT_IF_KUNIT(dm_dp_mst_atomic_check); -- 2.55.0 ^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off 2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman 2026-09-22 15:53 ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman @ 2026-09-22 16:09 ` sashiko-bot 1 sibling, 0 replies; 6+ messages in thread From: sashiko-bot @ 2026-09-22 16:09 UTC (permalink / raw) To: Arthur Liberman; +Cc: dri-devel Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [Low] drm/amd/display: dead code in MST DPMS-off loop -- commit 07293e89053ea9e3ce60dc0852be04a50a4ec01e Author: Arthur Liberman <arthur_liberman@hotmail.com> drm/amd/display: fix NULL stream deref on MST DPMS-off This commit adds a NULL check for streams in the MST DPMS-off loop in link_set_all_streams_dpms_off_for_link() and adds stream NULL checks in dc_stream_get_status(). > diff --git a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c > index 48b086d15ab0c..17cb831ce8c48 100644 > --- a/drivers/gpu/drm/amd/display/dc/link/link_dpms.c > +++ b/drivers/gpu/drm/amd/display/dc/link/link_dpms.c > @@ -177,6 +177,13 @@ void link_set_all_streams_dpms_off_for_link(struct dc_link *link) > streams[i] = pipes[i]->stream; > > for (i = 0; i < count; i++) { > + /* A full update can release current_state and NULL remaining > + * pipe streams. MST daisy-chains have multiple streams on one > + * link, so skip any that disappeared mid-loop. > + */ > + if (!streams[i]) > + continue; > + [Severity: Low] Does this check actually protect against mid-loop state changes? The function link_get_master_pipes_with_dpms_on() guarantees that pipes[i]->stream is non-NULL when populated, and these pointers are copied into the local streams[] array before the loop. Since streams[] is a local array and its elements are not updated inside this loop, is it possible for streams[i] to become NULL during iteration? It appears this check might be dead code that provides no runtime protection. -- Sashiko AI review · https://sashiko.dev/#/patchset/DB9PR03MB73884B0D604BA858636247CF8A832@DB9PR03MB7388.eurprd03.prod.outlook.com?part=1 ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown 2026-09-22 15:51 [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman 2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman @ 2026-09-22 15:58 ` Arthur Liberman 1 sibling, 0 replies; 6+ messages in thread From: Arthur Liberman @ 2026-09-22 15:58 UTC (permalink / raw) To: amd-gfx@lists.freedesktop.org Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Harry Wentland, Leo Li, Rodrigo Siqueira, Alex Deucher, Christian König, airlied@gmail.com, simona@ffwll.ch Sorry, the cover letter still had the placeholder text. The summary is: MST hotplug and topology teardown can run while the CRTCs are still enabled. That oopses in two amdgpu paths, and a third path turns the link off during detection. HPD detect of an MST daisy-chain reaches dc_stream_get_status() from link_set_all_streams_dpms_off_for_link() with a NULL stream. The helpers load stream->ctx with no NULL check. Return NULL when stream is NULL, and skip a NULL entry in the DPMS-off loop. verify_link_capability() DPMS-offs every live stream unless the link is embedded, training is skipped, or dpcd_caps.is_mst_capable is set. detect_link_and_local_sink() re-reads DPCD first and can clear is_mst_capable while the CRTCs are still on, so detect takes the destructive path before MST rediscovery. Keep the non-destructive verify while the link still has DPMS-on master pipes. dm_dp_mst_atomic_check() calls drm_dp_atomic_release_time_slots() after an MST topology restart has cleared mst_root or the output port connector. That is the amdgpu side of a NULL deref in the helper during kwin_wayland atomic check. Call the helper only while mst_root, the port, and port->connector are still present. The matching drm_dp_mst helper fix is sent separately to dri-devel. Reproduced on a Raphael iGPU (Ryzen 9 9950X) with a USB-C to DisplayPort MST daisy-chain. ^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-09-22 16:09 UTC | newest] Thread overview: 6+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-09-22 15:51 [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman 2026-09-22 15:53 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off Arthur Liberman 2026-09-22 15:53 ` [PATCH 2/3] drm/amd/display: skip destructive HPD verify on live links Arthur Liberman 2026-09-22 15:54 ` [PATCH 3/3] drm/amd/display: skip MST slot release if port is gone Arthur Liberman 2026-09-22 16:09 ` [PATCH 1/3] drm/amd/display: fix NULL stream deref on MST DPMS-off sashiko-bot 2026-09-22 15:58 ` [PATCH 0/3] drm/amd/display: fix NULL derefs on MST HPD and teardown Arthur Liberman
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox