Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Sebastian Reichel" <sebastian.reichel@collabora.com>
Cc: robh@kernel.org, devicetree@vger.kernel.org,
	dri-devel@lists.freedesktop.org, conor+dt@kernel.org
Subject: Re: [PATCH v8 17/21] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot
Date: Fri, 31 Jul 2026 18:09:29 +0000	[thread overview]
Message-ID: <20260731180929.E15061F00AC4@smtp.kernel.org> (raw)
In-Reply-To: <20260731-synopsys-dw-dp-improvements-v8-17-ac1e6a75782f@collabora.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

New issues:
- [Critical] Missing bounds check and integer underflow in DP AUX read allows a malicious DP sink to overflow the kernel stack.

Pre-existing issues:
- [High] Infinite loop in `dw_dp_link_clock_recovery()` triggered by oscillating sink requests.
--

--- Patch [17]: [PATCH v8 17/21] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot ---
commit 1a405fda22c71ea438c7181332eedd3948880f18
Author: Sebastian Reichel <sebastian.reichel@collabora.com>

drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot

This commit drops the useless reservation of the first SDP slot in the
atomic_enable code. It resolves a potential race condition with audio SDP
reservation once that feature is added.

> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> index 4d4af6a388b19..193816126e44e 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> @@ -1697,9 +1697,6 @@ static void dw_dp_bridge_atomic_enable(struct drm_bridge *bridge,
>  		return;
>  	}
>  
> -	scoped_guard(mutex, &dp->sdp_lock)
> -		set_bit(0, dp->sdp_reg_bank);
> -
>  	ret = dw_dp_link_enable(dp);
>  	if (ret < 0) {
>  		dev_err(dp->dev, "failed to enable link: %d\n", ret);

[ ... ]

> static int dw_dp_link_clock_recovery(struct dw_dp *dp)
> {
[ ... ]
> 	for (;;) {
[ ... ]
> 		adj_changed = dw_dp_link_get_adjustments(link, status);
> 		if (!adj_changed)
> 			tries++;
> 		else
> 			tries = 0;
> 
> 		if (tries == 5)
> 			break;
> 	}
> 
> 	return 0;
> }

[Severity: High]
This is a pre-existing issue, but does this code allow an infinite loop if a
non-compliant DP sink continuously alternates its requested voltage or
pre-emphasis levels?

Since there is no hard iteration limit, if the sink changes requests without
achieving clock recovery, adj_changed remains true and resets tries to 0.

Could this trap the kernel thread executing the atomic commit in an infinite
loop, leading to a permanent hung task?

[ ... ]

> @@ -1513,7 +1513,7 @@ static ssize_t dw_dp_aux_transfer(struct drm_dp_aux *aux,
>  		if (msg->request & DP_AUX_I2C_READ) {
>  			size_t count = FIELD_GET(AUX_BYTES_READ, value) - 1;
>  
> -			if (count != msg->size)
> +			if (!count)
>  				return -EBUSY;
>  
>  			ret = dw_dp_aux_read_data(dp, msg->buffer, count);

[Severity: Critical]
Does this change remove the bounds check against msg->size, introducing an
integer underflow and a potential buffer overflow?

If the hardware reports 0 bytes read, count = 0 - 1 underflows to SIZE_MAX.
This would cause !count to evaluate to false and dw_dp_aux_read_data() to
execute an effectively infinite write loop.

Even without underflow, if the hardware reports a size larger than msg->size,
could it write past the end of msg->buffer?

Since msg->buffer is frequently allocated on the stack by the DRM core for
small reads, this might grant an external device the ability to corrupt
kernel stack memory.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260731-synopsys-dw-dp-improvements-v8-0-ac1e6a75782f@collabora.com?part=17

  reply	other threads:[~2026-07-31 18:09 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-31 14:42 [PATCH v8 00/21] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 01/21] drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach Sebastian Reichel
2026-07-31 15:03   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 02/21] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback Sebastian Reichel
2026-07-31 15:16   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 03/21] drm/bridge: synopsys: dw-dp: Cancel pending HPD work Sebastian Reichel
2026-07-31 15:30   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 04/21] drm/bridge: synopsys: dw-dp: Document missing reset line deassert Sebastian Reichel
2026-07-31 15:38   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 05/21] drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal Sebastian Reichel
2026-07-31 15:50   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 06/21] drm/bridge: synopsys: dw-dp: Fix AUX transfer timeout race condition Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 07/21] drm/bridge: synopsys: dw-dp: Fix support for short I2C reads Sebastian Reichel
2026-07-31 16:16   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 08/21] drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid Sebastian Reichel
2026-07-31 16:30   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 09/21] drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 10/21] drm/bridge: synopsys: dw-dp: Add follow-up bridge support Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 11/21] drm/bridge: Add out-of-band HPD notify handler Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 12/21] drm/bridge: synopsys: dw-dp: Support software triggered OOB HPD Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 13/21] drm/rockchip: dw_dp: Implement out-of-band HPD handling Sebastian Reichel
2026-07-31 17:10   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 14/21] drm/bridge: synopsys: dw-dp: Add Runtime PM support Sebastian Reichel
2026-07-31 17:23   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 15/21] drm/rockchip: dw_dp: Add runtime " Sebastian Reichel
2026-07-31 17:35   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 16/21] drm/bridge: synopsys: dw-dp: Protect sdp_reg_bank from concurrent access Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 17/21] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot Sebastian Reichel
2026-07-31 18:09   ` sashiko-bot [this message]
2026-07-31 14:42 ` [PATCH v8 18/21] drm/bridge: synopsys: dw-dp: Clear only enabled SDPs on atomic disable Sebastian Reichel
2026-07-31 14:42 ` [PATCH v8 19/21] drm/bridge: synopsys: dw-dp: Use regmap_set_bits in dw_dp_send_sdp Sebastian Reichel
2026-07-31 18:29   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 20/21] dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells Sebastian Reichel
2026-07-31 18:37   ` sashiko-bot
2026-07-31 14:42 ` [PATCH v8 21/21] drm/bridge: synopsys: dw-dp: Add audio support Sebastian Reichel
2026-07-31 18:50   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260731180929.E15061F00AC4@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=sebastian.reichel@collabora.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox