From: sashiko-bot@kernel.org
To: "David Heidelberg" <david@ixit.cz>
Cc: robh@kernel.org, dri-devel@lists.freedesktop.org,
devicetree@vger.kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v2 08/11] drm/panel: s6e3ha8: add Samsung AMB630QY01 (Google Pixel 3 XL) panel
Date: Thu, 24 Sep 2026 14:12:19 +0000 [thread overview]
Message-ID: <20260924141219.7D87A1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260924-crosshatch-panel-v2-8-08d5c7bf72fc@ixit.cz>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] drm/panel: s6e3ha8: unconditional DCS command in backlight update causes DSI host wedge
--
commit cc2d04d32c8c8a9c163b61b933026b6a253b1aca
Author: David Heidelberg <david@ixit.cz>
drm/panel: s6e3ha8: add Samsung AMB630QY01 (Google Pixel 3 XL) panel
The Google Pixel 3 XL (crosshatch) uses a Samsung AMB630QY01 6.3" 1440x2960
flexible AMOLED panel, driven by the same S6E3HA8 DDIC as the Galaxy S9 panel
this driver already supports. This commit adds the initialization sequences and
timings, along with a backlight device since brightness is controlled via
standard DCS commands.
> diff --git a/drivers/gpu/drm/panel/panel-samsung-s6e3ha8.c b/drivers/gpu/drm/panel/panel-samsung-s6e3ha8.c
> index 2591b8c1a7753..e02f1d9f0dcd0 100644
> --- a/drivers/gpu/drm/panel/panel-samsung-s6e3ha8.c
> +++ b/drivers/gpu/drm/panel/panel-samsung-s6e3ha8.c
[ ... ]
> @@ -271,6 +294,136 @@ static const struct s6e3ha8_desc s6e3ha8_amb577px01_wqhd_desc = {
[ ... ]
> +static int s6e3ha8_bl_update_status(struct backlight_device *bl)
> +{
> + struct mipi_dsi_device *dsi = bl_get_data(bl);
> + u16 brightness = backlight_get_brightness(bl);
> +
> + return mipi_dsi_dcs_set_display_brightness_large(dsi, brightness);
[Severity: High]
Could this transmission wedge the display pipeline? In
drivers/gpu/drm/panel/panel-samsung-s6e3ha8.c within
s6e3ha8_bl_update_status(), this DSI transmission is executed unconditionally
without verifying if the panel's regulators and DSI link are active (e.g.
lacking a prepared state check).
Writing to the sysfs brightness attribute while the display is suspended or
disabled causes the driver to send DCS commands over the DSI bus when the DSI
host clocks and PHY may be gated or panel regulators disabled.
On many platforms (including the target Qualcomm sdm845), unclocked accesses
or DSI timeouts can result in a system crash (NOC error) or permanently wedge
the display pipeline.
> +}
[ ... ]
> @@ -313,6 +466,13 @@ static int s6e3ha8_probe(struct mipi_dsi_device *dsi)
>
> priv->panel.prepare_prev_first = true;
>
> + if (priv->desc->has_backlight) {
> + priv->panel.backlight = s6e3ha8_create_backlight(dsi);
[Severity: High]
Does this code create a race condition for early or late backlight updates?
In drivers/gpu/drm/panel/panel-samsung-s6e3ha8.c, this exposes the backlight
interface to userspace in s6e3ha8_probe(), creating the window for the race
condition where sysfs writes can trigger before the panel is prepared or after
it is unprepared.
A user-space process or udev rule could write to the sysfs brightness
attribute after the panel has been disabled via drm_panel_unprepare/disable.
The sysfs interface is typically accessible to unprivileged users, making this
easily reachable from user-space.
> + if (IS_ERR(priv->panel.backlight))
> + return dev_err_probe(dev, PTR_ERR(priv->panel.backlight),
> + "Failed to create backlight\n");
> + }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924-crosshatch-panel-v2-0-08d5c7bf72fc@ixit.cz?part=8
next prev parent reply other threads:[~2026-09-24 14:12 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 14:01 [PATCH v2 00/11] Pixel 3 XL display panel support David Heidelberg via B4 Relay
2026-09-24 14:01 ` [PATCH v2 01/11] dt-bindings: display: panel: s6e3ha8: Adjust to reflect the DDIC and panel used David Heidelberg via B4 Relay
2026-09-29 7:39 ` Krzysztof Kozlowski
2026-09-24 14:01 ` [PATCH v2 02/11] dt-bindings: display: panel: samsung,s6e3ha8: Add AMB630QY01 panel David Heidelberg via B4 Relay
2026-09-29 7:40 ` Krzysztof Kozlowski
2026-09-24 14:01 ` [PATCH v2 03/11] drm/panel: s6e3ha8: Really assert reset on the failure David Heidelberg via B4 Relay
2026-09-24 20:00 ` Petr Vorel
2026-09-29 7:43 ` Krzysztof Kozlowski
2026-09-24 14:01 ` [PATCH v2 04/11] drm/panel: s6e3ha8: Introduce AMB577PX01 panel compatible David Heidelberg via B4 Relay
2026-09-24 14:01 ` [PATCH v2 05/11] drm/panel: s6e3ha8: Prepare for supporting multiple panels David Heidelberg via B4 Relay
2026-09-24 14:01 ` [PATCH v2 06/11] drm/panel: s6e3ha8: Correct the polarity logic within David Heidelberg via B4 Relay
2026-09-29 7:45 ` Krzysztof Kozlowski
2026-09-29 9:41 ` David Heidelberg
2026-09-29 9:51 ` Krzysztof Kozlowski
2026-09-29 9:59 ` David Heidelberg
2026-09-29 10:36 ` Krzysztof Kozlowski
2026-09-29 12:12 ` David Heidelberg
2026-09-29 12:26 ` Krzysztof Kozlowski
2026-09-24 14:01 ` [PATCH v2 07/11] drm/panel: s6e3ha8: Assert reset GPIO in unprepare David Heidelberg via B4 Relay
2026-09-24 14:01 ` [PATCH v2 08/11] drm/panel: s6e3ha8: add Samsung AMB630QY01 (Google Pixel 3 XL) panel David Heidelberg via B4 Relay
2026-09-24 14:12 ` sashiko-bot [this message]
2026-09-24 14:01 ` [PATCH v2 09/11] arm64: dts: qcom: sdm845-samsung-starqltechn: Update panel compatible David Heidelberg via B4 Relay
2026-09-29 7:46 ` Krzysztof Kozlowski
2026-09-24 14:01 ` [PATCH v2 10/11] arm64: dts: qcom: sdm845-google: Move panel pins into common David Heidelberg via B4 Relay
2026-09-30 10:39 ` Konrad Dybcio
2026-09-24 14:01 ` [PATCH v2 11/11] arm64: dts: qcom: sdm845-google-crosshatch: Add display panel David Heidelberg via B4 Relay
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924141219.7D87A1F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=david@ixit.cz \
--cc=devicetree@vger.kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox