From: Imre Deak <imre.deak@intel.com>
To: Dan Carpenter <error27@gmail.com>
Cc: <intel-gfx@lists.freedesktop.org>
Subject: Re: [bug report] drm/i915/dp_mst: Fix configuring TUs for a disconnected stream
Date: Thu, 17 Sep 2026 17:31:50 +0300 [thread overview]
Message-ID: <aqv51ovysYHHiKZ1@ideak-desk.lan> (raw)
In-Reply-To: <aqvz_dSzr7AbUp9j@stanley.mountain>
Hi,
On Thu, Sep 17, 2026 at 05:06:53PM +0300, Dan Carpenter wrote:
> Hello Imre Deak,
>
> Commit ee00f8fbb2b2 ("drm/i915/dp_mst: Fix configuring TUs for a
> disconnected stream") from Sep 7, 2026 (linux-next), leads to the
> following Smatch static checker warning:
>
> drivers/gpu/drm/i915/display/intel_link_bw.c:69 intel_link_bw_init_limits()
> error: we previously assumed 'crtc_state' could be null (see line 67)
>
> drivers/gpu/drm/i915/display/intel_link_bw.c
> 53 void intel_link_bw_init_limits(struct intel_atomic_state *state,
> 54 struct intel_link_bw_limits *limits)
> 55 {
> 56 struct intel_display *display = to_intel_display(state);
> 57 enum pipe pipe;
> 58
> 59 limits->link_dsc_pipes = 0;
> 60 limits->bpp_limit_reached_pipes = 0;
> 61 for_each_pipe(display, pipe) {
> 62 struct intel_crtc *crtc = intel_crtc_for_pipe(display, pipe);
> 63 const struct intel_crtc_state *crtc_state =
> 64 intel_atomic_get_new_crtc_state(state, crtc);
> 65 int forced_bpp_x16 = get_forced_link_bpp_x16(state, crtc);
> 66
> 67 if ((state->base.duplicated && crtc_state) ||
> ^^^^^^^^^^
> Check for NULL
>
> 68 intel_dp_mst_stream_disconnected(state, crtc)) {
> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
> Possible this also implied crtc_state is non-NULL? It looks more like
> intel_dp_mst_stream_disconnected() assumes that crtc_state is non-NULL...
>
> --> 69 limits->max_bpp_x16[pipe] = crtc_state->max_link_bpp_x16;
> ^^^^^^^^^^^^
> Unchecked dereference.
intel_dp_mst_stream_disconnected() will return true only if the state of
the given stream's (i.e. the passed crtc's) connector is in the passed
atomic state. Since that connector will point to the passed crtc, it's
also guaranteed that the state of the crtc (i.e. crtc_state returned by
intel_atomic_get_new_crtc_state()) is also in the atomic state and hence
non-NULL.
>
> 70 if (intel_dsc_enabled_on_link(crtc_state))
> 71 limits->link_dsc_pipes |= BIT(pipe);
> 72 } else {
> 73 limits->max_bpp_x16[pipe] = INT_MAX;
> 74 }
> 75
> 76 if (forced_bpp_x16)
> 77 limits->max_bpp_x16[pipe] = min(limits->max_bpp_x16[pipe], forced_bpp_x16);
> 78 }
> 79 }
>
> This email is a free service from the Smatch-CI project [smatch.sf.net].
>
> regards,
> dan carpenter
prev parent reply other threads:[~2026-09-17 14:32 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 14:06 [bug report] drm/i915/dp_mst: Fix configuring TUs for a disconnected stream Dan Carpenter
2026-09-17 14:31 ` Imre Deak [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aqv51ovysYHHiKZ1@ideak-desk.lan \
--to=imre.deak@intel.com \
--cc=error27@gmail.com \
--cc=intel-gfx@lists.freedesktop.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox