From: sashiko-bot@kernel.org
To: "Sebastian Reichel" <sebastian.reichel@collabora.com>
Cc: robh@kernel.org, devicetree@vger.kernel.org,
dri-devel@lists.freedesktop.org, conor+dt@kernel.org
Subject: Re: [PATCH v8 17/21] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot
Date: Fri, 31 Jul 2026 18:09:29 +0000 [thread overview]
Message-ID: <20260731180929.E15061F00AC4@smtp.kernel.org> (raw)
In-Reply-To: <20260731-synopsys-dw-dp-improvements-v8-17-ac1e6a75782f@collabora.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [Critical] Missing bounds check and integer underflow in DP AUX read allows a malicious DP sink to overflow the kernel stack.
Pre-existing issues:
- [High] Infinite loop in `dw_dp_link_clock_recovery()` triggered by oscillating sink requests.
--
--- Patch [17]: [PATCH v8 17/21] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot ---
commit 1a405fda22c71ea438c7181332eedd3948880f18
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot
This commit drops the useless reservation of the first SDP slot in the
atomic_enable code. It resolves a potential race condition with audio SDP
reservation once that feature is added.
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> index 4d4af6a388b19..193816126e44e 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> @@ -1697,9 +1697,6 @@ static void dw_dp_bridge_atomic_enable(struct drm_bridge *bridge,
> return;
> }
>
> - scoped_guard(mutex, &dp->sdp_lock)
> - set_bit(0, dp->sdp_reg_bank);
> -
> ret = dw_dp_link_enable(dp);
> if (ret < 0) {
> dev_err(dp->dev, "failed to enable link: %d\n", ret);
[ ... ]
> static int dw_dp_link_clock_recovery(struct dw_dp *dp)
> {
[ ... ]
> for (;;) {
[ ... ]
> adj_changed = dw_dp_link_get_adjustments(link, status);
> if (!adj_changed)
> tries++;
> else
> tries = 0;
>
> if (tries == 5)
> break;
> }
>
> return 0;
> }
[Severity: High]
This is a pre-existing issue, but does this code allow an infinite loop if a
non-compliant DP sink continuously alternates its requested voltage or
pre-emphasis levels?
Since there is no hard iteration limit, if the sink changes requests without
achieving clock recovery, adj_changed remains true and resets tries to 0.
Could this trap the kernel thread executing the atomic commit in an infinite
loop, leading to a permanent hung task?
[ ... ]
> @@ -1513,7 +1513,7 @@ static ssize_t dw_dp_aux_transfer(struct drm_dp_aux *aux,
> if (msg->request & DP_AUX_I2C_READ) {
> size_t count = FIELD_GET(AUX_BYTES_READ, value) - 1;
>
> - if (count != msg->size)
> + if (!count)
> return -EBUSY;
>
> ret = dw_dp_aux_read_data(dp, msg->buffer, count);
[Severity: Critical]
Does this change remove the bounds check against msg->size, introducing an
integer underflow and a potential buffer overflow?
If the hardware reports 0 bytes read, count = 0 - 1 underflows to SIZE_MAX.
This would cause !count to evaluate to false and dw_dp_aux_read_data() to
execute an effectively infinite write loop.
Even without underflow, if the hardware reports a size larger than msg->size,
could it write past the end of msg->buffer?
Since msg->buffer is frequently allocated on the stack by the DRM core for
small reads, this might grant an external device the ability to corrupt
kernel stack memory.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260731-synopsys-dw-dp-improvements-v8-0-ac1e6a75782f@collabora.com?part=17
next prev parent reply other threads:[~2026-07-31 18:09 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 14:42 [PATCH v8 00/21] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 01/21] drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach Sebastian Reichel
2026-07-31 15:03 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 02/21] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback Sebastian Reichel
2026-07-31 15:16 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 03/21] drm/bridge: synopsys: dw-dp: Cancel pending HPD work Sebastian Reichel
2026-07-31 15:30 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 04/21] drm/bridge: synopsys: dw-dp: Document missing reset line deassert Sebastian Reichel
2026-07-31 15:38 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 05/21] drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal Sebastian Reichel
2026-07-31 15:50 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 06/21] drm/bridge: synopsys: dw-dp: Fix AUX transfer timeout race condition Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 07/21] drm/bridge: synopsys: dw-dp: Fix support for short I2C reads Sebastian Reichel
2026-07-31 16:16 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 08/21] drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid Sebastian Reichel
2026-07-31 16:30 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 09/21] drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 10/21] drm/bridge: synopsys: dw-dp: Add follow-up bridge support Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 11/21] drm/bridge: Add out-of-band HPD notify handler Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 12/21] drm/bridge: synopsys: dw-dp: Support software triggered OOB HPD Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 13/21] drm/rockchip: dw_dp: Implement out-of-band HPD handling Sebastian Reichel
2026-07-31 17:10 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 14/21] drm/bridge: synopsys: dw-dp: Add Runtime PM support Sebastian Reichel
2026-07-31 17:23 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 15/21] drm/rockchip: dw_dp: Add runtime " Sebastian Reichel
2026-07-31 17:35 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 16/21] drm/bridge: synopsys: dw-dp: Protect sdp_reg_bank from concurrent access Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 17/21] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot Sebastian Reichel
2026-07-31 18:09 ` sashiko-bot [this message]
2026-07-31 14:42 ` [PATCH v8 18/21] drm/bridge: synopsys: dw-dp: Clear only enabled SDPs on atomic disable Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 19/21] drm/bridge: synopsys: dw-dp: Use regmap_set_bits in dw_dp_send_sdp Sebastian Reichel
2026-07-31 18:29 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 20/21] dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells Sebastian Reichel
2026-07-31 18:37 ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 21/21] drm/bridge: synopsys: dw-dp: Add audio support Sebastian Reichel
2026-07-31 18:50 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260731180929.E15061F00AC4@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sebastian.reichel@collabora.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox