dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Yongxing Mou" <yongxing.mou@oss.qualcomm.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v7 25/35] drm/bridge_connector: suppress hotplug for IRQ_HPD without status changes
Date: Tue, 29 Sep 2026 04:51:35 +0000	[thread overview]
Message-ID: <20260929045136.0AA9D1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929-msm-dp-mst-v7-25-4b81473185e7@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] drm: missing hotplug event due to TOCTOU race in HPD handler
--

commit c7445c99ee548cba258205accae2588f4d6fc9bb
Author: Yongxing Mou <yongxing.mou@oss.qualcomm.com>

drm/bridge_connector: suppress hotplug for IRQ_HPD without status changes

This commit suppresses hotplug events for DP IRQ_HPD notifications if there
are no connection status changes. It checks the actual connector status
after handling the notification using the bridge detect callback. Hotplug
events are only sent if the connection state transitions, preventing
unnecessary reprobes.

> diff --git a/drivers/gpu/drm/display/drm_bridge_connector.c b/drivers/gpu/drm/display/drm_bridge_connector.c
> --- a/drivers/gpu/drm/display/drm_bridge_connector.c
> +++ b/drivers/gpu/drm/display/drm_bridge_connector.c
> @@ -159,15 +159,28 @@ static void drm_bridge_connector_handle_hpd(struct drm_bridge_connector *drm_bri
[ ... ]
>  	mutex_lock(&dev->mode_config.mutex);
> -	connector->status = status;
> +	old_status = connector->status;
>  	mutex_unlock(&dev->mode_config.mutex);
>  
>  	drm_bridge_connector_hpd_notify(connector, status, event);
>  
> -	drm_kms_helper_connector_hotplug_event(connector);
> +	mutex_lock(&dev->mode_config.mutex);
> +	new_status = detect ? detect->funcs->detect(detect, connector) : status;
> +	connector->status = new_status;
> +	changed = new_status != old_status;

[Severity: Medium]
Could this logic cause a missing hotplug event due to a race condition?

If old_status = A is read, the lock is dropped. During the execution of
drm_bridge_connector_hpd_notify(), a concurrent ioctl (like
DRM_IOCTL_MODE_GETCONNECTOR) might acquire the lock, probe the hardware,
update connector->status to B, and return state B to userspace.

If the hardware then changes back to A before this HPD handler reacquires
the lock, the detect call could return A. The new_status becomes A, and the
code calculates changed = (A != A), which is false, suppressing the hotplug
event.

In this scenario, userspace tracks state B, but the kernel tracks state A,
and userspace never receives the hotplug event to notify it of the
transition back to A.

Should old_status be read within the second critical section just before
calling the detect function, so that we compare against the most recent
state?

> +	mutex_unlock(&dev->mode_config.mutex);
> +
> +	if (changed || level_hpd)
> +		drm_kms_helper_connector_hotplug_event(connector);
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929-msm-dp-mst-v7-0-4b81473185e7@oss.qualcomm.com?part=25

  reply	other threads:[~2026-09-29  4:51 UTC|newest]

Thread overview: 67+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  4:25 [PATCH v7 00/35] drm/msm/dp: Add MST support for MSM chipsets Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 01/35] drm/msm/dp: move link-level teardown from display_disable to display_unprepare Yongxing Mou
2026-09-29  4:49   ` sashiko-bot
2026-10-01 10:11   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 02/35] drm/msm/dp: Pass panel to msm_dp_ctrl_config_msa() Yongxing Mou
2026-10-01 10:13   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 03/35] drm/msm/dp: drop redundant config_ctrl_link() from msm_dp_ctrl_on_stream() Yongxing Mou
2026-10-01 10:13   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 04/35] drm/msm/dp: introduce stream_id for each DP panel Yongxing Mou
2026-09-29  4:44   ` sashiko-bot
2026-10-01 10:23   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 05/35] drm/msm/dp: add support for programming p1/p2/p3 register blocks Yongxing Mou
2026-10-01 10:24   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 06/35] drm/msm/dp: add MST stream register definitions Yongxing Mou
2026-10-01 10:26   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 07/35] drm/msm/dp: add stream-aware link register accessors Yongxing Mou
2026-09-29  4:48   ` sashiko-bot
2026-10-01 10:26   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 08/35] drm/msm/dp: add support to send ACT packets for MST Yongxing Mou
2026-09-29  4:42   ` sashiko-bot
2026-10-01 10:32   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 09/35] drm/msm/dp: add support to enable MST in mainlink control Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 10/35] drm/msm/dp: no need to update tu calculation for mst Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 11/35] drm/msm/dp: always program MST_FIFO_CONSTANT_FILL for MST use cases Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 12/35] drm/msm/dp: add support for sending VCPF packets in DP controller Yongxing Mou
2026-09-29  4:49   ` sashiko-bot
2026-10-01 10:34     ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 13/35] drm/msm/dp: add support for MST channel slot allocation Yongxing Mou
2026-09-29  4:42   ` sashiko-bot
2026-10-01 10:52   ` Dmitry Baryshkov
2026-09-29  4:25 ` [PATCH v7 14/35] drm/msm/dp: replace power_on with active_stream_cnt Yongxing Mou
2026-09-29  4:44   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 15/35] drm/msm/dp: factor out _helper variants of bridge ops accepting a panel Yongxing Mou
2026-09-29  4:43   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 16/35] drm/msm/dp: add link_ready to manage link-level operations Yongxing Mou
2026-09-29  4:39   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 17/35] drm/msm/dp: add msm_dp_display_get_panel() to initialize DP panel Yongxing Mou
2026-09-29  4:44   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 18/35] drm/msm/dp: introduce dp_mst_drm module Yongxing Mou
2026-09-29  4:48   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 19/35] drm/msm/dp: add MST connector creation and topology callbacks Yongxing Mou
2026-09-29  4:48   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 20/35] drm/msm/dpu: pass msm_display_info to dpu_encoder_get_intf() Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 21/35] drm/msm/dpu: use stream_id to select MST interfaces Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 22/35] drm/msm/dpu: add per-stream MST encoders Yongxing Mou
2026-09-29  4:46   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 23/35] drm/msm/dp: move link capabilities to dp_link Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 24/35] drm/msm/dp: add atomic stream handling for MST Yongxing Mou
2026-09-29  4:54   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 25/35] drm/bridge_connector: suppress hotplug for IRQ_HPD without status changes Yongxing Mou
2026-09-29  4:51   ` sashiko-bot [this message]
2026-09-29  4:25 ` [PATCH v7 26/35] drm/bridge_connector: avoid detect-based HPD notifications for DisplayPort Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 27/35] drm/msm/dp: add HPD callback for dp MST Yongxing Mou
2026-09-29  4:55   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 28/35] drm/msm/dp: wire MST helpers into atomic check and commit paths Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 29/35] drm/msm/dp: mark the SST bridge disconnected when mst is active Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 30/35] drm/msm/dp: enable MST on capable sinks Yongxing Mou
2026-09-29  4:58   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 31/35] drm/msm/dp: mark the SST bridge disconnected when an MST-capable sink is present Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 32/35] drm/msm/dp: mark the SST connector disconnected when MST is enabled Yongxing Mou
2026-09-29  4:54   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 33/35] drm/msm/dp: wake threaded handler for HPD IRQs Yongxing Mou
2026-09-29  4:25 ` [PATCH v7 34/35] drm/msm/dp: order IRQ HPD handling with plug state changes Yongxing Mou
2026-09-29  4:54   ` sashiko-bot
2026-09-29  4:25 ` [PATCH v7 35/35] soc: qcom: pmic-glink-altmode: skip retimer reset on DP IRQ Yongxing Mou
2026-09-29  4:55   ` sashiko-bot
2026-10-03  0:46 ` [PATCH v7 00/35] drm/msm/dp: Add MST support for MSM chipsets Dmitry Baryshkov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929045136.0AA9D1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=yongxing.mou@oss.qualcomm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox