dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Karunika Choo" <karunika.choo@arm.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v1 06/27] drm/panthor: Derive MMU AS register addresses from base and stride
Date: Tue, 22 Sep 2026 21:00:15 +0000	[thread overview]
Message-ID: <20260922210016.0C0961F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260922204535.2850094-7-karunika.choo@arm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] panthor: NULL pointer dereference in MMU IRQ handler on spurious interrupts
--

commit 9aecd8c0de2222b2839590424b986eaecb02eee6
Author: Karunika Choo <karunika.choo@arm.com>

drm/panthor: Derive MMU AS register addresses from base and stride

This commit moves the MMU address-space register layout into the hardware
description. It computes the iomem pointer for each AS slot based on the base
offset and per-AS stride to prepare for GPUs with non-fixed MMU AS register
regions.

> diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/panthor/panthor_mmu.c
> index d75d575473da4..169550413a1a5 100644
> --- a/drivers/gpu/drm/panthor/panthor_mmu.c
> +++ b/drivers/gpu/drm/panthor/panthor_mmu.c
> @@ -1871,8 +1877,8 @@ static void panthor_mmu_irq_handler(struct panthor_irq *pirq, u32 status)
>  		u32 access_type;
>  		u32 source_id;
>  
> -		fault_status = gpu_read(mmu->iomem, AS_FAULTSTATUS(as));
> -		addr = gpu_read64(mmu->iomem, AS_FAULTADDRESS(as));
> +		fault_status = gpu_read(as_iomem(mmu, as), AS_FAULTSTATUS);
> +		addr = gpu_read64(as_iomem(mmu, as), AS_FAULTADDRESS);

[Severity: High]
Could this lead to a NULL pointer dereference on a spurious interrupt?

If the MMU interrupt status register has bits set for non-present AS slots
(such as from a hardware glitch, or reading 0xFFFFFFFF during a device
unplug or reset state), the loop in panthor_mmu_irq_handler() will process
these unpopulated slots.

Since as_iomem() returns NULL for slots that weren't initialized, passing
that NULL pointer to gpu_read() would trigger a kernel crash.

[ ... ]

> @@ -3408,7 +3417,13 @@ int panthor_mmu_init(struct panthor_device *ptdev)
>  	if (ret)
>  		return ret;
>  
> -	mmu->iomem = ptdev->iomem + MMU_AS_BASE;
> +	for_each_set_bit(as_id, &as_present_mask, MAX_AS_SLOTS) {
> +		u64 offset = regbank->offset + (regbank->stride * as_id);
> +
> +		guard(mutex)(&mmu->as.slots_lock);
> +		mmu->as.slots[as_id].iomem = ptdev->iomem + offset;
> +	}
> +

[Severity: High]
Because we only initialize the iomem pointers for present AS slots here,
the remaining array elements are left as NULL. Is there a need to guard
against accessing uninitialized slots in panthor_mmu_irq_handler() before
calling as_iomem() to prevent the issue mentioned above?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260922204535.2850094-1-karunika.choo@arm.com?part=6

  reply	other threads:[~2026-09-22 21:00 UTC|newest]

Thread overview: 54+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22 20:44 [PATCH v1 00/27] drm/panthor: Add Mali v15 virtualization support Karunika Choo
2026-09-22 20:44 ` [PATCH v1 01/27] drm/panthor: Ignore -EOPNOTSUPP for shader-present nvmem lookup Karunika Choo
2026-09-22 20:44 ` [PATCH v1 02/27] drm/panthor: Move register access helpers out of panthor_device.h Karunika Choo
2026-09-22 20:54   ` sashiko-bot
2026-09-22 20:44 ` [PATCH v1 03/27] drm/panthor: Parse and store GPU_ID fields Karunika Choo
2026-09-22 20:56   ` sashiko-bot
2026-09-22 20:44 ` [PATCH v1 04/27] drm/panthor: Add 64-bit GPU_ID decoding for v15 GPUs Karunika Choo
2026-09-22 21:01   ` sashiko-bot
2026-09-22 23:23   ` Deborah Brouwer
2026-09-22 20:44 ` [PATCH v1 05/27] drm/panthor: Move register base offsets to the HW description Karunika Choo
2026-09-22 20:45 ` [PATCH v1 06/27] drm/panthor: Derive MMU AS register addresses from base and stride Karunika Choo
2026-09-22 21:00   ` sashiko-bot [this message]
2026-09-22 20:45 ` [PATCH v1 07/27] dt-bindings: gpu: mali-valhall-csf: Add Mali Gen5 AM compatible Karunika Choo
2026-09-28 10:02   ` Krzysztof Kozlowski
2026-09-22 20:45 ` [PATCH v1 08/27] drm/panthor: Add Mali v15 hardware support Karunika Choo
2026-09-22 20:58   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 09/27] drm/panthor: Skip devfreq when no OPP table is present Karunika Choo
2026-09-22 20:45 ` [PATCH v1 10/27] dt-bindings: gpu: panthor: Document panthor-system bindings Karunika Choo
2026-09-22 20:56   ` sashiko-bot
2026-09-28 10:05   ` Krzysztof Kozlowski
2026-09-22 20:45 ` [PATCH v1 11/27] drm/panthor: Add AM_SYSTEM platform driver Karunika Choo
2026-09-22 20:59   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 12/27] dt-bindings: gpu: panthor: Document panthor-arbitration bindings Karunika Choo
2026-09-22 20:59   ` sashiko-bot
2026-09-28 10:06   ` Krzysztof Kozlowski
2026-09-22 20:45 ` [PATCH v1 13/27] drm/panthor: Add AM_PARTITION_CONTROL support Karunika Choo
2026-09-22 20:57   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 14/27] drm/panthor: Add AM message helpers Karunika Choo
2026-09-22 20:58   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 15/27] drm/panthor: Add AM_RESOURCE_GROUP support Karunika Choo
2026-09-22 20:56   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 16/27] drm/panthor: Add arbitration scheduler Karunika Choo
2026-09-22 21:00   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 17/27] drm/panthor: Route arbitration events Karunika Choo
2026-09-22 21:04   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 18/27] dt-bindings: gpu: panthor: Document AW assignment DT property Karunika Choo
2026-09-22 20:57   ` sashiko-bot
2026-09-28 10:06   ` Krzysztof Kozlowski
2026-09-22 20:45 ` [PATCH v1 19/27] drm/panthor: Add AW assignment tracking Karunika Choo
2026-09-22 20:45 ` [PATCH v1 20/27] drm/panthor: Handle partition control INVALID_COMMAND interrupt Karunika Choo
2026-09-22 21:04   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 21/27] drm/panthor: Request AW to yield GPU access on idle Karunika Choo
2026-09-22 21:07   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 22/27] drm/panthor: Add access-window support Karunika Choo
2026-09-22 21:05   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 23/27] drm/panthor: Synchronize HW component PM transitions Karunika Choo
2026-09-22 20:45 ` [PATCH v1 24/27] drm/panthor: Route HW component PM through access windows Karunika Choo
2026-09-22 21:06   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 25/27] drm/panthor: Tolerate access-window loss during HW waits Karunika Choo
2026-09-22 21:14   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 26/27] drm/panthor: Prevent missed post-yield cleanup due to reset Karunika Choo
2026-09-22 21:12   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 27/27] drm/panthor: Release GPU access immediately for out-of-band grants Karunika Choo
2026-09-22 21:06   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260922210016.0C0961F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=karunika.choo@arm.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox