From: Nickolay Goppen <setotau@mainlining.org>
To: sashiko-reviews@lists.linux.dev
Cc: dri-devel@lists.freedesktop.org, conor+dt@kernel.org,
robh@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v4 2/3] drivers: gpu: drm: panel: Add BOE NT51021 driver
Date: Thu, 17 Sep 2026 16:06:06 +0300 [thread overview]
Message-ID: <0a6d59c7-006c-4cb9-98ff-e8d859489bc4@mainlining.org> (raw)
In-Reply-To: <20260917130132.CEE401F00893@smtp.kernel.org>
17.09.2026 16:01, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] drm: panel: novatek-nt51021: UAF and crash due to premature devm_drm_panel_add()
> --
>
> commit 32c00aa725aa38b42eafcacc07a8f05495f7ed3d
> Author: Nickolay Goppen <setotau@mainlining.org>
>
> drivers: gpu: drm: panel: Add BOE NT51021 driver
>
> Add driver for BOE NT51021-based 8-inch and 10-inch DSI video mode
> panels used in Xiaomi Mi Pad 4, Mi Pad 4 Plus (xiaomi-clover)
> and Amazon Fire HD 10 (2017) (amazon-suez) tablets.
>
>> diff --git a/drivers/gpu/drm/panel/panel-novatek-nt51021.c b/drivers/gpu/drm/panel/panel-novatek-nt51021.c
>> new file mode 100644
>> index 0000000000000..94e7d6aaf0cb9
>> --- /dev/null
>> +++ b/drivers/gpu/drm/panel/panel-novatek-nt51021.c
> [ ... ]
>
>> +static int nt51021_novatek_probe(struct mipi_dsi_device *dsi)
>> +{
>> + struct device *dev = &dsi->dev;
> [ ... ]
>
>> + ctx->panel.prepare_prev_first = true;
>> +
>> + ret = drm_panel_of_backlight(&ctx->panel);
>> + if (ret)
>> + return dev_err_probe(dev, ret, "Failed to get backlight\n");
>> +
>> + ret = devm_drm_panel_add(dev, &ctx->panel);
>> + if (ret)
>> + return ret;
>> +
>> + return devm_mipi_dsi_attach(dev, dsi);
> [Severity: High]
> Can this sequence lead to a use-after-free or kernel crash?
>
> By calling devm_drm_panel_add() before devm_mipi_dsi_attach(), the panel is
> published globally before DSI attachment completes.
>
> If a DRM consumer discovers the panel via of_drm_find_panel() during this
> window, it takes a reference on the panel. If devm_mipi_dsi_attach() then
> fails, the probe function returns an error and devres cleans up the allocated
> GPIO and regulator resources. However, the panel memory remains allocated
> because of the consumer's reference.
>
> When the consumer later calls drm_panel_prepare(), the panel driver will
> dereference the freed GPIO and regulator pointers, causing a use-after-free.
>
> Additionally, if a consumer calls drm_panel_prepare() before mipi_dsi_attach()
> completes, it will trigger DSI commands on an unattached device, crashing the
> DSI host.
>
> Should devm_mipi_dsi_attach() be called before devm_drm_panel_add() to prevent
> this race window?
Other drivers do the same sequence of add and attach functions as I did.
>> +}
--
Best regards,
Nickolay
next prev parent reply other threads:[~2026-09-17 13:06 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 12:51 [PATCH v4 0/3] Novatek NT51021 DSI panel IC driver Nickolay Goppen
2026-09-17 12:51 ` [PATCH v4 1/3] dt-bindings: display: panel: Add Novatek NT51021 Nickolay Goppen
2026-09-21 10:49 ` AngeloGioacchino Del Regno
2026-09-17 12:51 ` [PATCH v4 2/3] drivers: gpu: drm: panel: Add BOE NT51021 driver Nickolay Goppen
2026-09-17 13:01 ` sashiko-bot
2026-09-17 13:06 ` Nickolay Goppen [this message]
2026-09-21 10:49 ` AngeloGioacchino Del Regno
2026-09-24 13:30 ` Neil Armstrong
2026-09-24 13:31 ` Neil Armstrong
2026-09-17 12:51 ` [PATCH v4 3/3] MAINTAINERS: Add myself and Ryan Brue as maintainers of NT51021 panel driver Nickolay Goppen
2026-09-21 10:50 ` AngeloGioacchino Del Regno
2026-09-24 13:32 ` Neil Armstrong
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=0a6d59c7-006c-4cb9-98ff-e8d859489bc4@mainlining.org \
--to=setotau@mainlining.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox