From: sashiko-bot@kernel.org
To: "Maxime Ripard" <mripard@kernel.org>
Cc: dri-devel@lists.freedesktop.org, devicetree@vger.kernel.org,
bpf@vger.kernel.org, robh@kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH 2/6] drm/panel: Add generic MIPI-DSI panel driver with BPF init sequences
Date: Mon, 28 Sep 2026 16:34:42 +0000 [thread overview]
Message-ID: <20260928163443.087D81F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260928-drm-mipi-dsi-panel-ebpf-v1-2-5244926aace4@kernel.org>
Thank you for your contribution! Sashiko AI review found 6 potential issue(s) to consider:
- [High] bpf: Use-After-Free when BPF program detaches from an unbound panel
- [High] bpf: Out-of-bounds read due to missing NUL-termination on user strings
- [High] bpf: Out-of-bounds array access via negative enum indices in kfuncs
- [Medium] drm/panel: Missing hotplug event prevents display pipeline activation
- [Medium] bpf: Uninitialized kernel memory leaked over DSI bus via nullable pointers
- [Low] bpf: Tracepoints log incorrect status data instead of return value
--
commit 1f60161986e7e142490428d5f24fb3b831dddb58
Author: Maxime Ripard <mripard@kernel.org>
Subject: drm/panel: Add generic MIPI-DSI panel driver with BPF init sequences
This patch introduces a generic MIPI-DSI panel driver that uses BPF
programs loaded from userspace for panel-specific behavior. The driver
registers a disconnected drm_bridge, exposing sleepable kfuncs to
control regulators, GPIOs, and DSI data transfer.
> diff --git a/drivers/gpu/drm/panel/bpf/panel-bpf-mipi-dsi-ops.c b/drivers/gpu/drm/panel/bpf/panel-bpf-mipi-dsi-ops.c
> --- /dev/null
> +++ b/drivers/gpu/drm/panel/bpf/panel-bpf-mipi-dsi-ops.c
> @@ -32,25 +32,25 @@
> static int panel_bpf_mipi_dsi_bpf_init_member(const struct btf_type *t,
> const struct btf_member *member,
> void *kdata, const void *udata)
> {
> const struct drm_panel_dsi_bpf_ops *uops =
> (const struct drm_panel_dsi_bpf_ops *)udata;
> struct drm_panel_dsi_bpf_ops *kops =
> (struct drm_panel_dsi_bpf_ops *)kdata;
> u32 moff;
>
> moff = __btf_member_bit_offset(t, member) / 8;
>
> switch (moff) {
> case offsetof(struct drm_panel_dsi_bpf_ops, panel_id):
> memcpy(kops->panel_id, uops->panel_id,
> sizeof(kops->panel_id));
> return 1;
> case offsetof(struct drm_panel_dsi_bpf_ops, compatible):
> memcpy(kops->compatible, uops->compatible,
> sizeof(kops->compatible));
> return 1;
[Severity: High]
Does this memcpy() ensure the string is NUL-terminated? If userspace
provides a string that is fully packed with non-NUL characters up to
the length of the array, the kernel string will remain unterminated.
[ ... ]
> @@ -78,12 +78,12 @@
> static int panel_bpf_mipi_dsi_bpf_check_config(struct panel_bpf_mipi_dsi *panel,
> struct drm_panel_dsi_bpf_ops *ops)
> {
> struct mipi_dsi_device *dsi = panel->dsi;
> struct device *dev = &dsi->dev;
>
> if (!of_device_is_compatible(dev->of_node, ops->compatible)) {
[Severity: High]
Can this result in an out-of-bounds read? If ops->compatible was copied from
userspace without a NUL terminator in panel_bpf_mipi_dsi_bpf_init_member(),
the OF core functions like of_device_is_compatible() will read past the
buffer boundary when attempting string comparison.
> dev_err(dev,
> "BPF compatible \"%s\" doesn't match panel\n",
> ops->compatible);
> return -EINVAL;
> }
[ ... ]
> @@ -134,25 +134,25 @@
> static int panel_bpf_mipi_dsi_bpf_reg(void *kdata, struct bpf_link *link)
> {
> struct drm_panel_dsi_bpf_ops *ops = kdata;
> struct panel_bpf_mipi_dsi *panel;
> int ret;
>
> trace_panel_bpf_mipi_dsi_reg(ops->panel_id);
>
> guard(mutex)(&panel_bpf_mipi_dsi_list_lock);
>
> panel = panel_bpf_mipi_dsi_find_panel_unlocked(ops->panel_id);
> if (!panel)
> return -ENODEV;
>
> guard(mutex)(&panel->bpf_lock);
>
> if (panel->bpf_ops)
> return -EBUSY;
>
> ret = panel_bpf_mipi_dsi_bpf_check_config(panel, ops);
> if (ret)
> return ret;
>
> ops->bridge = &panel->bridge;
> panel->bpf_ops = ops;
>
> return 0;
> }
[Severity: Medium]
When a BPF program successfully attaches here, it changes the bridge's
detect callback behavior from returning connector_status_disconnected to
connector_status_connected. Should this function also broadcast a hotplug
notification to userspace so the display pipeline can be brought up without
waiting for the next KMS polling cycle?
[ ... ]
> @@ -168,21 +168,21 @@
> static void panel_bpf_mipi_dsi_bpf_unreg(void *kdata, struct bpf_link *link)
> {
> struct drm_panel_dsi_bpf_ops *ops = kdata;
> struct panel_bpf_mipi_dsi *panel;
>
> trace_panel_bpf_mipi_dsi_unreg(ops->panel_id);
>
> if (!ops->bridge)
> return;
>
> panel = drm_bridge_to_bpf_panel(ops->bridge);
>
> scoped_guard(mutex, &panel->bpf_lock) {
[Severity: High]
Can this sequence trigger a use-after-free when unregistering?
If a MIPI DSI device unbinds, devres triggers panel_bpf_mipi_dsi_list_cleanup()
which removes the panel from the global list but doesn't detach the BPF
program or clear ops->bridge before freeing the panel structure.
If userspace subsequently unregisters the BPF struct_ops link,
panel_bpf_mipi_dsi_bpf_unreg() appears to use the dangling ops->bridge
pointer to resolve the freed panel structure, and then locks its bpf_lock.
> diff --git a/drivers/gpu/drm/panel/bpf/panel-bpf-mipi-dsi-kfuncs.c b/drivers/gpu/drm/panel/bpf/panel-bpf-mipi-dsi-kfuncs.c
> --- /dev/null
> +++ b/drivers/gpu/drm/panel/bpf/panel-bpf-mipi-dsi-kfuncs.c
> @@ -36,15 +36,15 @@
> __bpf_kfunc int panel_bpf_mipi_dsi_regulator_enable_and_wait(struct panel_bpf_mipi_dsi_ctx *ctx,
> enum panel_bpf_mipi_dsi_supply supply,
> u32 settle_ms)
> {
> struct panel_bpf_mipi_dsi *panel = bpf_ctx_to_bpf_panel(ctx);
> int ret;
>
> if (supply >= PANEL_BPF_MIPI_DSI_SUPPLY_COUNT)
> return -EINVAL;
[Severity: High]
Does this bounds check adequately protect against out-of-bounds array accesses?
The BPF verifier validates kfunc enum parameters as signed scalar values,
which could be negative. A negative index here would pass the upper-bound
check and allow an out-of-bounds read into panel->supplies. This same
pattern exists for the GPIO enum checks elsewhere in this file.
>
> trace_panel_bpf_mipi_dsi_regulator_enable_and_wait(panel->panel_id,
> panel->supplies[supply].supply,
> settle_ms);
[ ... ]
> @@ -177,19 +177,19 @@
> __bpf_kfunc int panel_bpf_mipi_dsi_dcs_write_and_wait(struct panel_bpf_mipi_dsi_ctx *ctx,
> u8 cmd, const u8 *data__nullable,
> u32 data__nullable__sz,
> u32 settle_ms)
> {
> struct panel_bpf_mipi_dsi *panel = bpf_ctx_to_bpf_panel(ctx);
> int ret;
>
> trace_panel_bpf_mipi_dsi_dcs_write_and_wait(panel->panel_id, cmd, data__nullable,
> data__nullable__sz, settle_ms);
[Severity: Low]
Is this tracepoint logging the correct information? The trace event definition
expects the bus transaction's return value for the fifth argument (ret), but
this code passes the sleep duration settle_ms into the ret parameter.
>
> ret = mipi_dsi_dcs_write(panel->dsi, cmd, data__nullable,
> data__nullable__sz);
[Severity: Medium]
Could this result in uninitialized kernel memory being leaked over the DSI bus?
When data__nullable is NULL, the BPF verifier doesn't enforce that
data__nullable__sz is zero. mipi_dsi_dcs_write() will allocate a buffer of
size data__nullable__sz, skip the memcpy because the source is NULL, and then
transmit the uninitialized kmalloc buffer to the display. Should there be a
check for data__nullable == NULL && data__nullable__sz > 0?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260928-drm-mipi-dsi-panel-ebpf-v1-0-5244926aace4@kernel.org?part=2
next prev parent reply other threads:[~2026-09-28 16:34 UTC|newest]
Thread overview: 64+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 16:22 [PATCH 0/6] drm/bridge: Add a BPF-based MIPI-DSI panel driver Maxime Ripard
2026-09-28 16:22 ` [PATCH 1/6] dt-bindings: display: Add panel-mipi-dsi-bpf generic panel binding Maxime Ripard
2026-09-28 16:35 ` sashiko-bot
2026-09-28 19:16 ` Neil Armstrong
2026-09-28 20:40 ` Rob Herring
2026-09-29 8:39 ` Maxime Ripard
2026-09-29 22:28 ` Rob Herring
2026-09-30 8:04 ` Maxime Ripard
2026-09-30 19:07 ` Rob Herring
2026-10-01 7:22 ` Maxime Ripard
2026-10-01 16:03 ` Rob Herring
2026-09-30 13:32 ` Neil Armstrong
2026-10-01 7:09 ` Maxime Ripard
2026-10-02 7:28 ` Neil Armstrong
2026-09-28 20:43 ` Rob Herring (Arm)
2026-09-29 23:44 ` bot+bpf-ci
2026-09-28 16:22 ` [PATCH 2/6] drm/panel: Add generic MIPI-DSI panel driver with BPF init sequences Maxime Ripard
2026-09-28 16:34 ` sashiko-bot [this message]
2026-09-28 16:22 ` [PATCH 3/6] drm/panel: dsi-bpf: Add BPF program build infrastructure and helper header Maxime Ripard
2026-09-28 16:31 ` sashiko-bot
2026-09-29 23:44 ` bot+bpf-ci
2026-09-28 16:22 ` [PATCH 4/6] drm/panel: dsi-bpf: Add Raspberry Pi 7-inch panel BPF program Maxime Ripard
2026-09-28 16:34 ` sashiko-bot
2026-09-28 16:22 ` [PATCH 5/6] drm/panel: dsi-bpf: Add Raspberry Pi 5-inch " Maxime Ripard
2026-09-28 16:33 ` sashiko-bot
2026-09-28 16:22 ` [PATCH DO NOT MERGE 6/6] arm64: dts: broadcom: Add Raspberry Pi ILI9881C DSI panel overlays Maxime Ripard
2026-09-28 16:31 ` sashiko-bot
2026-09-28 16:37 ` [PATCH 0/6] drm/bridge: Add a BPF-based MIPI-DSI panel driver Laurent Pinchart
2026-09-28 17:31 ` Benjamin Tissoires
2026-09-28 18:12 ` Laurent Pinchart
2026-09-29 6:54 ` Maxime Ripard
2026-09-28 16:39 ` Neil Armstrong
2026-09-28 17:24 ` Benjamin Tissoires
2026-09-28 19:20 ` Neil Armstrong
2026-09-28 19:48 ` Benjamin Tissoires
2026-09-28 20:36 ` Neil Armstrong
2026-09-29 7:41 ` Maxime Ripard
2026-09-29 7:55 ` Javier Martinez Canillas
2026-09-30 13:37 ` Neil Armstrong
2026-10-01 6:50 ` Maxime Ripard
2026-10-02 7:30 ` Neil Armstrong
2026-10-02 7:37 ` Javier Martinez Canillas
2026-10-02 7:53 ` Neil Armstrong
2026-10-02 9:04 ` Javier Martinez Canillas
2026-09-30 13:36 ` Neil Armstrong
2026-09-30 20:59 ` Kumar Kartikeya Dwivedi
2026-10-01 6:38 ` Maxime Ripard
2026-10-01 17:03 ` Maxime Ripard
2026-09-29 7:27 ` Maxime Ripard
2026-09-30 13:49 ` Neil Armstrong
2026-10-01 7:01 ` Maxime Ripard
2026-10-02 7:39 ` Neil Armstrong
2026-09-29 7:13 ` Maxime Ripard
2026-09-29 7:46 ` Benjamin Tissoires
2026-09-30 13:46 ` Neil Armstrong
2026-10-01 6:48 ` Maxime Ripard
2026-10-02 8:11 ` Neil Armstrong
2026-09-29 9:03 ` Jani Nikula
2026-09-29 9:32 ` Benjamin Tissoires
2026-09-29 10:16 ` Jani Nikula
2026-09-29 12:28 ` Maxime Ripard
2026-09-30 14:01 ` Neil Armstrong
2026-09-30 19:18 ` Jani Nikula
2026-10-01 7:05 ` Maxime Ripard
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928163443.087D81F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=mripard@kernel.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox