dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Yongxing Mou" <yongxing.mou@oss.qualcomm.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v7 07/35] drm/msm/dp: add stream-aware link register accessors
Date: Tue, 29 Sep 2026 04:48:22 +0000	[thread overview]
Message-ID: <20260929044822.992D81F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929-msm-dp-mst-v7-7-4b81473185e7@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] drm/msm/dp: null pointer dereference in stream-aware link accessors
- [High] drm/msm/dp: hardware register misrouting for MST video enable
- [High] drm/msm/dp: resource mapping corruption due to hardcoded DT indices
--

commit 55281b71e2076f4bad3f57eba868f53bb2700307
Author: Yongxing Mou <yongxing.mou@oss.qualcomm.com>

drm/msm/dp: add stream-aware link register accessors

DisplayPort MST uses multiple stream-specific register spaces. Streams 0
and 1 share the primary link register block with different register offsets,
while streams 2 and 3 use dedicated MST link register blocks. Add
stream-aware register access helpers that translate stream-specific register
offsets and route accesses to the appropriate register space based on the
stream id.

> diff --git a/drivers/gpu/drm/msm/dp/dp_ctrl.c b/drivers/gpu/drm/msm/dp/dp_ctrl.c
> index c0f5226dc383b..e1614bc49a7ca 100644
> --- a/drivers/gpu/drm/msm/dp/dp_ctrl.c
> +++ b/drivers/gpu/drm/msm/dp/dp_ctrl.c
[ ... ]
> @@ -172,6 +174,49 @@ static inline void msm_dp_write_link(struct msm_dp_ctrl_private *ctrl,
>  	writel(data, ctrl->link_base + offset);
>  }
>  
> +static inline u32 msm_dp_read_stream_link(struct msm_dp_ctrl_private *ctrl,
> +					   enum msm_dp_stream_id stream_id, u32 offset)
> +{
> +	offset = msm_dp_stream_reg(stream_id, offset);
> +	switch (stream_id) {
> +	case DP_STREAM_0:
> +	case DP_STREAM_1:
> +		return readl_relaxed(ctrl->link_base + offset);
> +	case DP_STREAM_2:
> +		return readl_relaxed(ctrl->mst2link_base + offset);

[Severity: High]
Can this regression lead to a NULL pointer dereference? If a platform has 3
or 4 pixel clocks but omits mst2link in the device tree,
msm_dp_ioremap_optional() returns NULL for mst2link_base. If a connected MST
sink or userspace modeset then triggers stream 2 initialization, this direct
read access without validation will panic the kernel.

> +	case DP_STREAM_3:
> +		return readl_relaxed(ctrl->mst3link_base + offset);
> +	default:
> +		DRM_ERROR("error stream_id\n");
> +		return 0;
> +	}
> +}
> +
> +static inline void msm_dp_write_stream_link(struct msm_dp_ctrl_private *ctrl,
> +					     enum msm_dp_stream_id stream_id, u32 offset, u32 data)
> +{
> +	/*
> +	 * To make sure link reg writes happens before any other operation,
> +	 * this function uses writel() instread of writel_relaxed()
> +	 */
> +	offset = msm_dp_stream_reg(stream_id, offset);
> +	switch (stream_id) {
> +	case DP_STREAM_0:
> +	case DP_STREAM_1:
> +		writel(data, ctrl->link_base + offset);
> +		break;
> +	case DP_STREAM_2:
> +		writel(data, ctrl->mst2link_base + offset);

[Severity: High]
Does this code risk a write to a NULL pointer? Similar to the read accessor
above, if mst2link_base fails to map or is omitted from the device tree, this
direct write access will dereference a NULL pointer.

[Severity: High]
Is this a regression where MST streams 2 and 3 fail to enable video because
of a missed conversion to these new accessors?

Looking at msm_dp_ctrl_on_stream() in dp_ctrl.c:

	msm_dp_ctrl_setup_tr_unit(ctrl, panel);

	msm_dp_write_link(ctrl, REG_DP_STATE_CTRL, DP_STATE_CTRL_SEND_VIDEO);

	ret = msm_dp_ctrl_wait4video_ready(ctrl);

The code still unconditionally calls the non-stream-aware msm_dp_write_link()
which forces writes to ctrl->link_base (Stream 0/1's block) instead of using
msm_dp_write_stream_link(). This sends the video enable command for streams
2 and 3 to the wrong hardware register, causing silent corruption of stream
0's state.

> +		break;
> +	case DP_STREAM_3:
> +		writel(data, ctrl->mst3link_base + offset);
> +		break;
> +	default:
> +		DRM_ERROR("error stream_id\n");
> +		break;
> +	}
> +}
[ ... ]
> diff --git a/drivers/gpu/drm/msm/dp/dp_display.c b/drivers/gpu/drm/msm/dp/dp_display.c
> index d8b28a5626535..bb5e35e11b4d4 100644
> --- a/drivers/gpu/drm/msm/dp/dp_display.c
> +++ b/drivers/gpu/drm/msm/dp/dp_display.c
[ ... ]
> @@ -1208,6 +1222,14 @@ static int msm_dp_display_get_io(struct msm_dp_display_private *display)
>  			break;
>  	}
>  
> +	display->mst2link_base = msm_dp_ioremap_optional(pdev, 7, &display->mst2link_len);

[Severity: High]
Can this hardcoded index cause a resource mapping regression? Device tree
'reg' arrays are contiguous. If a platform has only 3 pixel bases
(p0, p1, p2), they occupy indices 3, 4, and 5, making the mst2link resource
occupy index 6. Fetching index 7 assumes there are exactly 4 pixel bases
preceding it, which may return NULL or map an unrelated memory region during
driver probe.

> +	if (IS_ERR(display->mst2link_base))
> +		return PTR_ERR(display->mst2link_base);
> +
> +	display->mst3link_base = msm_dp_ioremap_optional(pdev, 8, &display->mst3link_len);
> +	if (IS_ERR(display->mst3link_base))
> +		return PTR_ERR(display->mst3link_base);
> +
>  	return 0;
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929-msm-dp-mst-v7-0-4b81473185e7@oss.qualcomm.com?part=7

  reply	other threads:[~2026-09-29  4:48 UTC|newest]

Thread overview: 67+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  4:25 [PATCH v7 00/35] drm/msm/dp: Add MST support for MSM chipsets Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 01/35] drm/msm/dp: move link-level teardown from display_disable to display_unprepare Yongxing Mou
2026-09-29  4:49   ` sashiko-bot
2026-10-01 10:11   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 02/35] drm/msm/dp: Pass panel to msm_dp_ctrl_config_msa() Yongxing Mou
2026-10-01 10:13   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 03/35] drm/msm/dp: drop redundant config_ctrl_link() from msm_dp_ctrl_on_stream() Yongxing Mou
2026-10-01 10:13   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 04/35] drm/msm/dp: introduce stream_id for each DP panel Yongxing Mou
2026-09-29  4:44   ` sashiko-bot
2026-10-01 10:23   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 05/35] drm/msm/dp: add support for programming p1/p2/p3 register blocks Yongxing Mou
2026-10-01 10:24   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 06/35] drm/msm/dp: add MST stream register definitions Yongxing Mou
2026-10-01 10:26   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 07/35] drm/msm/dp: add stream-aware link register accessors Yongxing Mou
2026-09-29  4:48   ` sashiko-bot [this message]
2026-10-01 10:26   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 08/35] drm/msm/dp: add support to send ACT packets for MST Yongxing Mou
2026-09-29  4:42   ` sashiko-bot
2026-10-01 10:32   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 09/35] drm/msm/dp: add support to enable MST in mainlink control Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 10/35] drm/msm/dp: no need to update tu calculation for mst Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 11/35] drm/msm/dp: always program MST_FIFO_CONSTANT_FILL for MST use cases Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 12/35] drm/msm/dp: add support for sending VCPF packets in DP controller Yongxing Mou
2026-09-29  4:49   ` sashiko-bot
2026-10-01 10:34     ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 13/35] drm/msm/dp: add support for MST channel slot allocation Yongxing Mou
2026-09-29  4:42   ` sashiko-bot
2026-10-01 10:52   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 14/35] drm/msm/dp: replace power_on with active_stream_cnt Yongxing Mou
2026-09-29  4:44   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 15/35] drm/msm/dp: factor out _helper variants of bridge ops accepting a panel Yongxing Mou
2026-09-29  4:43   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 16/35] drm/msm/dp: add link_ready to manage link-level operations Yongxing Mou
2026-09-29  4:39   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 17/35] drm/msm/dp: add msm_dp_display_get_panel() to initialize DP panel Yongxing Mou
2026-09-29  4:44   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 18/35] drm/msm/dp: introduce dp_mst_drm module Yongxing Mou
2026-09-29  4:48   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 19/35] drm/msm/dp: add MST connector creation and topology callbacks Yongxing Mou
2026-09-29  4:48   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 20/35] drm/msm/dpu: pass msm_display_info to dpu_encoder_get_intf() Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 21/35] drm/msm/dpu: use stream_id to select MST interfaces Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 22/35] drm/msm/dpu: add per-stream MST encoders Yongxing Mou
2026-09-29  4:46   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 23/35] drm/msm/dp: move link capabilities to dp_link Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 24/35] drm/msm/dp: add atomic stream handling for MST Yongxing Mou
2026-09-29  4:54   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 25/35] drm/bridge_connector: suppress hotplug for IRQ_HPD without status changes Yongxing Mou
2026-09-29  4:51   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 26/35] drm/bridge_connector: avoid detect-based HPD notifications for DisplayPort Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 27/35] drm/msm/dp: add HPD callback for dp MST Yongxing Mou
2026-09-29  4:55   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 28/35] drm/msm/dp: wire MST helpers into atomic check and commit paths Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 29/35] drm/msm/dp: mark the SST bridge disconnected when mst is active Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 30/35] drm/msm/dp: enable MST on capable sinks Yongxing Mou
2026-09-29  4:58   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 31/35] drm/msm/dp: mark the SST bridge disconnected when an MST-capable sink is present Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 32/35] drm/msm/dp: mark the SST connector disconnected when MST is enabled Yongxing Mou
2026-09-29  4:54   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 33/35] drm/msm/dp: wake threaded handler for HPD IRQs Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 34/35] drm/msm/dp: order IRQ HPD handling with plug state changes Yongxing Mou
2026-09-29  4:54   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 35/35] soc: qcom: pmic-glink-altmode: skip retimer reset on DP IRQ Yongxing Mou
2026-09-29  4:55   ` sashiko-bot
2026-10-03  0:46 ` [PATCH v7 00/35] drm/msm/dp: Add MST support for MSM chipsets Dmitry Baryshkov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929044822.992D81F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=yongxing.mou@oss.qualcomm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox