From: sashiko-bot@kernel.org
To: "Jani Nikula" <jani.nikula@intel.com>
Cc: intel-xe@lists.freedesktop.org, intel-gfx@lists.freedesktop.org
Subject: Re: [PATCH 07/11] drm/i915/hdcp: switch to drm_dp_dpcd_{read_byte, read_data, write_data}()
Date: Wed, 16 Sep 2026 08:35:31 +0000 [thread overview]
Message-ID: <20260916083531.D26AD1F00893@smtp.kernel.org> (raw)
In-Reply-To: <e168dad72f78fdb74419da94b0a38d732159fc82.1789547331.git.jani.nikula@intel.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] drm/i915/hdcp: incorrect buffer advancement in intel_dp_hdcp2_read_msg()
--
commit ef5e2443a19df2b1333678ad805fe64be928f4df
Author: Jani Nikula <jani.nikula@intel.com>
drm/i915/hdcp: switch to drm_dp_dpcd_{read_byte, read_data, write_data}()
This commit switches DPCD accesses to modern functions that return 0 on success
and negative error codes on failure. It simplifies error handling and converts
logging to use %pe and ERR_PTR().
> diff --git a/drivers/gpu/drm/i915/display/intel_dp_hdcp.c b/drivers/gpu/drm/i915/display/intel_dp_hdcp.c
> --- a/drivers/gpu/drm/i915/display/intel_dp_hdcp.c
> +++ b/drivers/gpu/drm/i915/display/intel_dp_hdcp.c
[ ... ]
> @@ -493,14 +493,13 @@ ssize_t get_receiver_id_list_rx_info(struct intel_connector *connector,
> {
> struct intel_digital_port *dig_port = intel_attached_dig_port(connector);
> struct drm_dp_aux *aux = &dig_port->dp.aux;
> - ssize_t ret;
> u8 *rx_info = byte;
> + int ret;
>
> - ret = drm_dp_dpcd_read(aux,
> - DP_HDCP_2_2_REG_RXINFO_OFFSET,
> - (void *)rx_info, HDCP_2_2_RXINFO_LEN);
> - if (ret != HDCP_2_2_RXINFO_LEN)
> - return ret >= 0 ? -EIO : ret;
> + ret = drm_dp_dpcd_read_data(aux, DP_HDCP_2_2_REG_RXINFO_OFFSET,
> + rx_info, HDCP_2_2_RXINFO_LEN);
> + if (ret < 0)
> + return ret;
[Severity: High]
Will this return value cause issues for downstream topology authentication?
Since drm_dp_dpcd_read_data() returns 0 on success (instead of the number of
bytes read), get_receiver_id_list_rx_info() now returns 0 on success.
Looking at the caller in intel_dp_hdcp2_read_msg(), it expects the return
value to be the number of bytes read so it can advance the buffer pointer:
if (msg_id == HDCP_2_2_REP_SEND_RECVID_LIST) {
ret = get_receiver_id_list_rx_info(connector, &dev_cnt, byte);
if (ret < 0)
return ret;
byte += ret;
Since ret is 0, the pointer won't advance, which could cause the subsequent
payload read to overwrite the rx_info field.
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1789547331.git.jani.nikula@intel.com?part=7
next prev parent reply other threads:[~2026-09-16 8:35 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 8:29 [PATCH 00/11] drm/i915/display: switch to modern drm_dp_dpcd* accessors Jani Nikula
2026-09-16 8:29 ` [PATCH 01/11] drm/i915/lspcon: use u8 variable to hold 1-byte DPCD reads Jani Nikula
2026-09-16 9:14 ` Kandpal, Suraj
2026-09-16 8:29 ` [PATCH 02/11] drm/i915/lspcon: switch to drm_dp_dpcd_{read_byte, write_byte, write_data} Jani Nikula
2026-09-16 9:16 ` Kandpal, Suraj
2026-09-17 12:03 ` Jani Nikula
2026-09-18 3:02 ` Kandpal, Suraj
2026-09-16 8:29 ` [PATCH 03/11] drm/i915/alpm: switch to drm_dp_dpcd_{read_byte, write_byte} Jani Nikula
2026-09-16 9:17 ` Kandpal, Suraj
2026-09-18 3:04 ` Kandpal, Suraj
2026-09-16 8:29 ` [PATCH 04/11] drm/i915/ddi: switch to drm_dp_dpcd_write_byte() Jani Nikula
2026-09-18 3:05 ` Kandpal, Suraj
2026-09-16 8:29 ` [PATCH 05/11] drm/i915/lspcon: switch to drm_dp_dpcd_{read_byte, read_data, write_byte, write_data}() Jani Nikula
2026-09-18 3:08 ` Kandpal, Suraj
2026-09-16 8:29 ` [PATCH 06/11] drm/i915/dp: switch to drm_dp_dpcd_{read_byte, read_data, write_byte, write_data} Jani Nikula
2026-09-18 3:09 ` Kandpal, Suraj
2026-09-16 8:29 ` [PATCH 07/11] drm/i915/hdcp: switch to drm_dp_dpcd_{read_byte, read_data, write_data}() Jani Nikula
2026-09-16 8:35 ` sashiko-bot [this message]
2026-09-18 3:36 ` Kandpal, Suraj
2026-09-21 9:41 ` [PATCH v2] " Jani Nikula
2026-09-22 12:03 ` [PATCH v2] drm/i915/hdcp: switch to drm_dp_dpcd_{read_byte,read_data,write_data}() Kandpal, Suraj
2026-09-22 13:43 ` Jani Nikula
2026-09-16 8:29 ` [PATCH 08/11] drm/i915/dp: switch link training to drm_dp_dpcd_{read_byte, read_data, write_byte, write_data}() Jani Nikula
2026-09-18 3:38 ` Kandpal, Suraj
2026-09-16 8:29 ` [PATCH 09/11] drm/i915/dp-mst: switch to drm_dp_dpcd_read_byte() Jani Nikula
2026-09-16 9:29 ` Kandpal, Suraj
2026-09-16 8:29 ` [PATCH 10/11] drm/i915/dp-test: switch to drm_dp_dpcd_{read_byte, read_data, write_byte, write_data}() Jani Nikula
2026-09-18 3:38 ` Kandpal, Suraj
2026-09-16 8:29 ` [PATCH 11/11] drm/i915/psr: " Jani Nikula
2026-09-16 9:30 ` Kandpal, Suraj
2026-09-16 9:44 ` ✓ i915.CI.BAT: success for drm/i915/display: switch to modern drm_dp_dpcd* accessors Patchwork
2026-09-16 14:26 ` ✓ i915.CI.Full: " Patchwork
2026-09-21 13:10 ` ✓ i915.CI.BAT: success for drm/i915/display: switch to modern drm_dp_dpcd* accessors (rev2) Patchwork
2026-09-21 17:24 ` ✗ i915.CI.Full: failure " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916083531.D26AD1F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=intel-gfx@lists.freedesktop.org \
--cc=intel-xe@lists.freedesktop.org \
--cc=jani.nikula@intel.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox