Devicetree
 help / color / mirror / Atom feed
From: Nickolay Goppen <setotau@mainlining.org>
To: sashiko-reviews@lists.linux.dev
Cc: dri-devel@lists.freedesktop.org, conor+dt@kernel.org,
	robh@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v4 2/3] drivers: gpu: drm: panel: Add BOE NT51021 driver
Date: Thu, 17 Sep 2026 16:06:06 +0300	[thread overview]
Message-ID: <0a6d59c7-006c-4cb9-98ff-e8d859489bc4@mainlining.org> (raw)
In-Reply-To: <20260917130132.CEE401F00893@smtp.kernel.org>


17.09.2026 16:01, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] drm: panel: novatek-nt51021: UAF and crash due to premature devm_drm_panel_add()
> --
>
> commit 32c00aa725aa38b42eafcacc07a8f05495f7ed3d
> Author: Nickolay Goppen <setotau@mainlining.org>
>
>      drivers: gpu: drm: panel: Add BOE NT51021 driver
>      
>      Add driver for BOE NT51021-based 8-inch and 10-inch DSI video mode
>      panels used in Xiaomi Mi Pad 4, Mi Pad 4 Plus (xiaomi-clover)
>      and Amazon Fire HD 10 (2017) (amazon-suez) tablets.
>
>> diff --git a/drivers/gpu/drm/panel/panel-novatek-nt51021.c b/drivers/gpu/drm/panel/panel-novatek-nt51021.c
>> new file mode 100644
>> index 0000000000000..94e7d6aaf0cb9
>> --- /dev/null
>> +++ b/drivers/gpu/drm/panel/panel-novatek-nt51021.c
> [ ... ]
>
>> +static int nt51021_novatek_probe(struct mipi_dsi_device *dsi)
>> +{
>> +	struct device *dev = &dsi->dev;
> [ ... ]
>
>> +	ctx->panel.prepare_prev_first = true;
>> +
>> +	ret = drm_panel_of_backlight(&ctx->panel);
>> +	if (ret)
>> +		return dev_err_probe(dev, ret, "Failed to get backlight\n");
>> +
>> +	ret = devm_drm_panel_add(dev, &ctx->panel);
>> +	if (ret)
>> +		return ret;
>> +
>> +	return devm_mipi_dsi_attach(dev, dsi);
> [Severity: High]
> Can this sequence lead to a use-after-free or kernel crash?
>
> By calling devm_drm_panel_add() before devm_mipi_dsi_attach(), the panel is
> published globally before DSI attachment completes.
>
> If a DRM consumer discovers the panel via of_drm_find_panel() during this
> window, it takes a reference on the panel. If devm_mipi_dsi_attach() then
> fails, the probe function returns an error and devres cleans up the allocated
> GPIO and regulator resources. However, the panel memory remains allocated
> because of the consumer's reference.
>
> When the consumer later calls drm_panel_prepare(), the panel driver will
> dereference the freed GPIO and regulator pointers, causing a use-after-free.
>
> Additionally, if a consumer calls drm_panel_prepare() before mipi_dsi_attach()
> completes, it will trigger DSI commands on an unattached device, crashing the
> DSI host.
>
> Should devm_mipi_dsi_attach() be called before devm_drm_panel_add() to prevent
> this race window?
Other drivers do the same sequence of add and attach functions as I did.
>> +}

-- 
Best regards,
Nickolay


  reply	other threads:[~2026-09-17 13:06 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 12:51 [PATCH v4 0/3] Novatek NT51021 DSI panel IC driver Nickolay Goppen
2026-09-17 12:51 ` [PATCH v4 1/3] dt-bindings: display: panel: Add Novatek NT51021 Nickolay Goppen
2026-09-21 10:49   ` AngeloGioacchino Del Regno
2026-09-17 12:51 ` [PATCH v4 2/3] drivers: gpu: drm: panel: Add BOE NT51021 driver Nickolay Goppen
2026-09-17 13:01   ` sashiko-bot
2026-09-17 13:06     ` Nickolay Goppen [this message]
2026-09-21 10:49   ` AngeloGioacchino Del Regno
2026-09-24 13:30     ` Neil Armstrong
2026-09-24 13:31   ` Neil Armstrong
2026-09-17 12:51 ` [PATCH v4 3/3] MAINTAINERS: Add myself and Ryan Brue as maintainers of NT51021 panel driver Nickolay Goppen
2026-09-21 10:50   ` AngeloGioacchino Del Regno
2026-09-24 13:32   ` Neil Armstrong

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=0a6d59c7-006c-4cb9-98ff-e8d859489bc4@mainlining.org \
    --to=setotau@mainlining.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox