ARM Sunxi Platform Development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Cristian Ciocaltea" <cristian.ciocaltea@collabora.com>
Cc: dri-devel@lists.freedesktop.org, linux-sunxi@lists.linux.dev
Subject: Re: [PATCH v10 32/69] drm/rockchip: dw_hdmi_qp: Use local dev variable consistently in bind()
Date: Fri, 31 Jul 2026 20:47:55 +0000	[thread overview]
Message-ID: <20260731204755.8A9631F00AC4@smtp.kernel.org> (raw)
In-Reply-To: <20260731-dw-hdmi-qp-scramb-v10-32-294364b2cf15@collabora.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:

Pre-existing issues:
- [High] Use-After-Free and resource leaks due to devm_ allocations in component bind callback.
- [High] Pending delayed work is not canceled on error paths, leading to Use-After-Free.
- [High] Missing cleanup for dw_hdmi_qp_bind() on the error path leads to resource and bridge leaks.
--

--- Patch [32]: [PATCH v10 32/69] drm/rockchip: dw_hdmi_qp: Use local dev variable consistently in bind() ---
commit 43fdb5eca012528d707389ce53b62eb4132b9532
Author: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>

drm/rockchip: dw_hdmi_qp: Use local dev variable consistently in bind()

Replace indirect struct device accesses via hdmi->dev and pdev->dev with
the local dev parameter already available in dw_hdmi_qp_rockchip_bind(),
for consistency and readability.

> diff --git a/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c b/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c
> index 8b48558deb3e7..36043bf82273c 100644
> --- a/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c
> +++ b/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c

[ ... ]

> @@ -670,7 +669,7 @@ static int dw_hdmi_qp_rockchip_bind(struct device *dev, struct device *master,
>  	if (irq < 0)
>  		return irq;
>  
> -	ret = devm_request_threaded_irq(hdmi->dev, irq,
> +	ret = devm_request_threaded_irq(dev, irq,
>  					cfg->ctrl_ops->hardirq_callback,
>  					cfg->ctrl_ops->irq_callback,
>  					IRQF_SHARED, "dw-hdmi-qp-hpd",
>  					hdmi);

[Severity: High]
This isn't a bug introduced by this patch, but does the use of devm_ here
cause a use-after-free and resource leak on component unbind?

The hdmi context is allocated via drmm_kzalloc, tying its lifetime to the
DRM master device. However, devm_request_threaded_irq ties the HPD IRQ
handler to the platform device's lifecycle, not the component bind/unbind
lifecycle.

If the component is unbound (e.g. the DRM master is removed), drmm will free
the hdmi context, but the IRQ remains active. A subsequent HPD interrupt
will trigger the handler, which dereferences the freed hdmi pointer. Also,
every bind retry leaks devm resources like clocks and GPIOs since they
aren't tied to the bind lifecycle.

>  	if (ret)
>  		return ret;
>  
>  	drm_encoder_helper_add(encoder, &dw_hdmi_qp_rockchip_encoder_helper_funcs);
>  	ret = drmm_encoder_init(drm, encoder, NULL, DRM_MODE_ENCODER_TMDS, NULL);
>  	if (ret)
> -		return dev_err_probe(hdmi->dev, ret, "Failed to init encoder\n");
> +		return dev_err_probe(dev, ret, "Failed to init encoder\n");

[Severity: High]
This is a pre-existing issue, but does this error path lead to a
use-after-free?

The HPD IRQ is requested earlier and can fire immediately, scheduling
hdmi->hpd_work. If drmm_encoder_init() fails here, we return directly
without calling cancel_delayed_work_sync().

The DRM core handles the component bind failure by tearing down the DRM
device, causing drmm to free the hdmi structure. The pending delayed work
will then execute and dereference the freed hdmi pointer.

>  
>  	hdmi->hdmi = dw_hdmi_qp_bind(pdev, encoder, &plat_data);
>  	if (IS_ERR(hdmi->hdmi))
> -		return dev_err_probe(hdmi->dev, PTR_ERR(hdmi->hdmi),
> +		return dev_err_probe(dev, PTR_ERR(hdmi->hdmi),
>  				     "Failed to bind dw-hdmi-qp\n");
>  
>  	connector = drm_bridge_connector_init(drm, encoder);
>  	if (IS_ERR(connector))
> -		return dev_err_probe(hdmi->dev, PTR_ERR(connector),
> +		return dev_err_probe(dev, PTR_ERR(connector),
>  				     "Failed to init bridge connector\n");

[Severity: High]
This isn't a bug introduced by this patch, but does this error path
permanently leak devm-managed bridges?

dw_hdmi_qp_bind() allocates state and registers a DRM bridge using devm_
functions tied to the platform device. If drm_bridge_connector_init() fails,
we return directly without calling dw_hdmi_qp_unbind() or cleaning up the
bridge.

Because the resources are managed by devm_ tied to the platform device, they
won't be freed when the component bind fails. Every retry of the component
bind will allocate new memory and register duplicate DRM bridges in the
global list.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260731-dw-hdmi-qp-scramb-v10-0-294364b2cf15@collabora.com?part=32

  reply	other threads:[~2026-07-31 20:47 UTC|newest]

Thread overview: 93+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-31 16:19 [PATCH v10 00/69] Add HDMI 2.0 support to DW HDMI QP TX Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 01/69] video/hdmi: Introduce HDMI version enum Cristian Ciocaltea
2026-07-31 16:25   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 02/69] drm/connector: hdmi: Handle reset() state allocation failure Cristian Ciocaltea
2026-07-31 16:37   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 03/69] drm/display: hdmi: Rename drmm_connector_hdmi_init() to *_ini2() Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 04/69] drm/connector: Add drmm_connector_hdmi_init() with new signature Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 05/69] drm/display: bridge_connector: Convert to drmm_connector_hdmi_init() Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 06/69] drm/probe-helper: Introduce .force_ctx() connector callback Cristian Ciocaltea
2026-07-31 17:06   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 07/69] drm/connector: Add HDMI 2.0 scrambler infrastructure Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 08/69] drm/display: scdc-helper: Add macro for connector-prefixed debug messages Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 09/69] drm/display: scdc-helper: Add helper to set SCDC version information Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 10/69] drm/display: hdmi: Add HDMI 2.0 scrambling management helpers Cristian Ciocaltea
2026-07-31 17:33   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 11/69] drm/display: hdmi: Advertise SCDC source version when scrambling Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 12/69] drm/bridge: Fix unlocked list_del in drm_bridge_add() Cristian Ciocaltea
2026-07-31 17:50   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 13/69] drm/bridge: Fix unlocked list access in drm_bridge_attach() Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 14/69] drm/bridge: Remove redundant error check in drm_bridge_helper_reset_crtc() Cristian Ciocaltea
2026-07-31 18:01   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 15/69] drm/bridge: Add bridge ops for source-side HDMI 2.0 scrambling Cristian Ciocaltea
2026-07-31 18:09   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 16/69] drm/display: bridge_connector: Use cached connector status in .get_modes() Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 17/69] drm/display: bridge_connector: Switch to .detect_ctx() connector helper Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 18/69] drm/display: bridge_connector: Switch to .force_ctx() " Cristian Ciocaltea
2026-07-31 18:31   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 19/69] drm/display: bridge_connector: Wire up HDMI 2.0 scrambler callbacks Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 20/69] drm/display: hdmi-state-helper: Add source TMDS rate validation Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 21/69] drm/display: hdmi-state-helper: Pass acquire ctx to hotplug helpers Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 22/69] drm/display: hdmi-state-helper: Sync SCDC state on hotplug Cristian Ciocaltea
2026-07-31 19:02   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 23/69] drm/display: hdmi-state-helper: Set HDMI scrambling requirement Cristian Ciocaltea
2026-07-31 19:20   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 24/69] drm/bridge: dw-hdmi-qp: Rate limit i2c read error messages Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 25/69] drm/bridge: dw-hdmi-qp: Provide .{enable,disable}_hpd() PHY ops Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 26/69] drm/bridge: dw-hdmi-qp: Remove unused workqueue include and define Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 27/69] drm/bridge: dw-hdmi-qp: Add HDMI 2.0 scrambling support Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 28/69] drm/bridge: dw-hdmi-qp: Provide dw_hdmi_qp_hpd_notify() helper Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 29/69] drm/rockchip: dw_hdmi_qp: Fix invalid drvdata access in PM ops Cristian Ciocaltea
2026-07-31 20:19   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 30/69] drm/rockchip: dw_hdmi_qp: Cancel pending HPD work on suspend Cristian Ciocaltea
2026-07-31 20:30   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 31/69] drm/rockchip: dw_hdmi_qp: Add missing newlines in dev_err_probe() messages Cristian Ciocaltea
2026-07-31 20:38   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 32/69] drm/rockchip: dw_hdmi_qp: Use local dev variable consistently in bind() Cristian Ciocaltea
2026-07-31 20:47   ` sashiko-bot [this message]
2026-07-31 16:19 ` [PATCH v10 33/69] drm/rockchip: dw_hdmi_qp: Avoid spurious HPD IRQ thread wakeups Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 34/69] drm/rockchip: dw_hdmi_qp: Mask RK3576 HPD IRQ in io_init Cristian Ciocaltea
2026-07-31 21:14   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 35/69] drm/rockchip: dw_hdmi_qp: Implement .{enable,disable}_hpd() PHY ops Cristian Ciocaltea
2026-07-31 21:27   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 36/69] drm/rockchip: dw_hdmi_qp: Factor out HPD interrupt (un)mask helpers Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 37/69] drm/rockchip: dw_hdmi_qp: Control the HPD IRQ line via the bridge HPD ops Cristian Ciocaltea
2026-07-31 21:47   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 38/69] drm/rockchip: dw_hdmi_qp: Use dw_hdmi_qp_hpd_notify() for HPD reports Cristian Ciocaltea
2026-07-31 22:04   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 39/69] drm/bridge: dw-hdmi-qp: Drop unused .setup_hpd() phy op Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 40/69] drm/vc4: hdmi: Use common TMDS char rate constants Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 41/69] drm/vc4: hdmi: Switch to drm_hdmi_mode_needs_scrambling() Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 42/69] drm/vc4: hdmi: Switch to .force_ctx() connector helper Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 43/69] drm/vc4: hdmi: Propagate -EDEADLK to the top level Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 44/69] drm/vc4: hdmi: Convert to drmm_connector_hdmi_init() Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 45/69] drm/vc4: hdmi: Convert to common HDMI 2.0 scrambling infrastructure Cristian Ciocaltea
2026-07-31 22:44   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 46/69] drm/vc4: hdmi: Defer pixel clock validation to HDMI helpers Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 47/69] drm/display: hdmi-state-helper: Drop drm_atomic_helper_connector_hdmi_force() Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 48/69] drm/bridge: adv7511: Advertise HDMI 1.2 capabilities Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 49/69] drm/bridge: inno-hdmi: " Cristian Ciocaltea
2026-07-31 23:10   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 50/69] drm/bridge: ite-it6263: Drop redundant .mode_valid hook Cristian Ciocaltea
2026-07-31 16:19 ` [PATCH v10 51/69] drm/bridge: ite-it6263: Advertise HDMI 1.3 capabilities Cristian Ciocaltea
2026-07-31 23:24   ` sashiko-bot
2026-07-31 16:19 ` [PATCH v10 52/69] drm/bridge: ite-it66121: Advertise HDMI 1.2 capabilities Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 53/69] drm/bridge: lontium-lt9611: Advertise HDMI 1.4 capabilities Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 54/69] drm/rockchip: rk3066_hdmi: " Cristian Ciocaltea
2026-07-31 23:41   ` sashiko-bot
2026-07-31 16:20 ` [PATCH v10 55/69] drm/sun4i: hdmi: Convert to drmm_connector_hdmi_init() Cristian Ciocaltea
2026-07-31 23:47   ` sashiko-bot
2026-07-31 16:20 ` [PATCH v10 56/69] drm/tests: edid: Add 4K@60Hz EDID with 600MHz TMDS Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 57/69] drm/tests: edid: Fix conformity for 1080p+4K YUV420 200MHz EDID Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 58/69] drm/tests: edid: Fix conformity for 4K RGB/YUV 340MHz EDID Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 59/69] drm/tests: bridge: Set supported HDMI version Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 60/69] drm/tests: connector: Convert to drmm_connector_hdmi_init() Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 61/69] drm/tests: connector: Add HDMI max_tmds_char_rate init coverage Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 62/69] drm/tests: connector: Add HDMI source-side scrambler coverage Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 63/69] drm/tests: hdmi_state_helper: Convert to drmm_connector_hdmi_init() Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 64/69] drm/tests: hdmi_state_helper: Add connector-provided max_tmds_char_rate coverage Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 65/69] drm/tests: hdmi_state_helper: Cover source-side scrambling decision Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 66/69] drm/connector: Remove drmm_connector_hdmi_ini2() Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 67/69] drm/connector: Drop redundant hdmi vendor/product fields Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 68/69] drm/connector: Drop redundant hdmi supported_formats field Cristian Ciocaltea
2026-07-31 16:20 ` [PATCH v10 69/69] drm/connector: Drop redundant max_bpc field Cristian Ciocaltea

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260731204755.8A9631F00AC4@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=cristian.ciocaltea@collabora.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=linux-sunxi@lists.linux.dev \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox