* [PATCH v2] drm/log: Fix division by zero when scale module parameter is 0
@ 2026-07-29 10:58 oushixiong1025
2026-07-29 11:14 ` Shixiong Ou
` (2 more replies)
0 siblings, 3 replies; 5+ messages in thread
From: oushixiong1025 @ 2026-07-29 10:58 UTC (permalink / raw)
To: Jocelyn Falempe
Cc: Javier Martinez Canillas, Maarten Lankhorst, Maxime Ripard,
Thomas Zimmermann, David Airlie, Simona Vetter, dri-devel,
linux-kernel, Shixiong Ou
From: Shixiong Ou <oushixiong@kylinos.cn>
The scale module parameter can be set to 0 via kernel command line or
sysfs. When scale is 0, scaled_font_h and scaled_font_w become 0,
causing a division by zero in the rows/columns calculation.
Introduce a drm_log_scale() helper that returns scale ?: 1, and use it
at all read sites. This avoids a race that a setter-based clamp would
have between param_set_uint() and the subsequent check, where another
CPU could observe scale == 0.
Signed-off-by: Shixiong Ou <oushixiong@kylinos.cn>
---
v1->v2:
Introduce a drm_log_scale() helper.
drivers/gpu/drm/clients/drm_log.c | 15 ++++++++++-----
1 file changed, 10 insertions(+), 5 deletions(-)
diff --git a/drivers/gpu/drm/clients/drm_log.c b/drivers/gpu/drm/clients/drm_log.c
index 294b3be1a6b3..9522c1344123 100644
--- a/drivers/gpu/drm/clients/drm_log.c
+++ b/drivers/gpu/drm/clients/drm_log.c
@@ -29,6 +29,11 @@ static unsigned int scale = 1;
module_param(scale, uint, 0444);
MODULE_PARM_DESC(scale, "Integer scaling factor for drm_log, default is 1");
+static inline unsigned int drm_log_scale(void)
+{
+ return scale ?: 1;
+}
+
/**
* DOC: overview
*
@@ -76,13 +81,13 @@ static void drm_log_blit(struct iosys_map *dst, unsigned int dst_pitch,
{
switch (px_width) {
case 2:
- drm_draw_blit16(dst, dst_pitch, src, src_pitch, height, width, scale, color);
+ drm_draw_blit16(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
break;
case 3:
- drm_draw_blit24(dst, dst_pitch, src, src_pitch, height, width, scale, color);
+ drm_draw_blit24(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
break;
case 4:
- drm_draw_blit32(dst, dst_pitch, src, src_pitch, height, width, scale, color);
+ drm_draw_blit32(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
break;
default:
WARN_ONCE(1, "Can't blit with pixel width %d\n", px_width);
@@ -216,8 +221,8 @@ static int drm_log_setup_modeset(struct drm_client_dev *client,
return -ENOMEM;
}
mode_set->fb = scanout->buffer->fb;
- scanout->scaled_font_h = scanout->font->height * scale;
- scanout->scaled_font_w = scanout->font->width * scale;
+ scanout->scaled_font_h = scanout->font->height * drm_log_scale();
+ scanout->scaled_font_w = scanout->font->width * drm_log_scale();
scanout->rows = height / scanout->scaled_font_h;
scanout->columns = width / scanout->scaled_font_w;
scanout->front_color = drm_draw_color_from_xrgb8888(0xffffff, format);
--
2.25.1
No virus found
Checked by Hillstone Network AntiVirus
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH v2] drm/log: Fix division by zero when scale module parameter is 0
2026-07-29 10:58 [PATCH v2] drm/log: Fix division by zero when scale module parameter is 0 oushixiong1025
@ 2026-07-29 11:14 ` Shixiong Ou
2026-07-29 12:01 ` Jani Nikula
2026-07-29 15:00 ` Jocelyn Falempe
2 siblings, 0 replies; 5+ messages in thread
From: Shixiong Ou @ 2026-07-29 11:14 UTC (permalink / raw)
To: oushixiong1025, Jocelyn Falempe
Cc: Javier Martinez Canillas, Maarten Lankhorst, Maxime Ripard,
Thomas Zimmermann, David Airlie, Simona Vetter, dri-devel,
linux-kernel, Jani Nikula
Adding to Cc Jani Nikula
On 2026/7/29 18:58, oushixiong1025@163.com wrote:
> From: Shixiong Ou <oushixiong@kylinos.cn>
>
> The scale module parameter can be set to 0 via kernel command line or
> sysfs. When scale is 0, scaled_font_h and scaled_font_w become 0,
> causing a division by zero in the rows/columns calculation.
>
> Introduce a drm_log_scale() helper that returns scale ?: 1, and use it
> at all read sites. This avoids a race that a setter-based clamp would
> have between param_set_uint() and the subsequent check, where another
> CPU could observe scale == 0.
>
> Signed-off-by: Shixiong Ou <oushixiong@kylinos.cn>
> ---
> v1->v2:
> Introduce a drm_log_scale() helper.
>
> drivers/gpu/drm/clients/drm_log.c | 15 ++++++++++-----
> 1 file changed, 10 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/gpu/drm/clients/drm_log.c b/drivers/gpu/drm/clients/drm_log.c
> index 294b3be1a6b3..9522c1344123 100644
> --- a/drivers/gpu/drm/clients/drm_log.c
> +++ b/drivers/gpu/drm/clients/drm_log.c
> @@ -29,6 +29,11 @@ static unsigned int scale = 1;
> module_param(scale, uint, 0444);
> MODULE_PARM_DESC(scale, "Integer scaling factor for drm_log, default is 1");
>
> +static inline unsigned int drm_log_scale(void)
> +{
> + return scale ?: 1;
> +}
> +
> /**
> * DOC: overview
> *
> @@ -76,13 +81,13 @@ static void drm_log_blit(struct iosys_map *dst, unsigned int dst_pitch,
> {
> switch (px_width) {
> case 2:
> - drm_draw_blit16(dst, dst_pitch, src, src_pitch, height, width, scale, color);
> + drm_draw_blit16(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
> break;
> case 3:
> - drm_draw_blit24(dst, dst_pitch, src, src_pitch, height, width, scale, color);
> + drm_draw_blit24(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
> break;
> case 4:
> - drm_draw_blit32(dst, dst_pitch, src, src_pitch, height, width, scale, color);
> + drm_draw_blit32(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
> break;
> default:
> WARN_ONCE(1, "Can't blit with pixel width %d\n", px_width);
> @@ -216,8 +221,8 @@ static int drm_log_setup_modeset(struct drm_client_dev *client,
> return -ENOMEM;
> }
> mode_set->fb = scanout->buffer->fb;
> - scanout->scaled_font_h = scanout->font->height * scale;
> - scanout->scaled_font_w = scanout->font->width * scale;
> + scanout->scaled_font_h = scanout->font->height * drm_log_scale();
> + scanout->scaled_font_w = scanout->font->width * drm_log_scale();
> scanout->rows = height / scanout->scaled_font_h;
> scanout->columns = width / scanout->scaled_font_w;
> scanout->front_color = drm_draw_color_from_xrgb8888(0xffffff, format);
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v2] drm/log: Fix division by zero when scale module parameter is 0
2026-07-29 10:58 [PATCH v2] drm/log: Fix division by zero when scale module parameter is 0 oushixiong1025
2026-07-29 11:14 ` Shixiong Ou
@ 2026-07-29 12:01 ` Jani Nikula
2026-07-29 15:00 ` Jocelyn Falempe
2 siblings, 0 replies; 5+ messages in thread
From: Jani Nikula @ 2026-07-29 12:01 UTC (permalink / raw)
To: oushixiong1025, Jocelyn Falempe
Cc: Javier Martinez Canillas, Maarten Lankhorst, Maxime Ripard,
Thomas Zimmermann, David Airlie, Simona Vetter, dri-devel,
linux-kernel, Shixiong Ou
On Wed, 29 Jul 2026, oushixiong1025@163.com wrote:
> From: Shixiong Ou <oushixiong@kylinos.cn>
>
> The scale module parameter can be set to 0 via kernel command line or
> sysfs. When scale is 0, scaled_font_h and scaled_font_w become 0,
> causing a division by zero in the rows/columns calculation.
>
> Introduce a drm_log_scale() helper that returns scale ?: 1, and use it
> at all read sites. This avoids a race that a setter-based clamp would
> have between param_set_uint() and the subsequent check, where another
> CPU could observe scale == 0.
>
> Signed-off-by: Shixiong Ou <oushixiong@kylinos.cn>
> ---
> v1->v2:
> Introduce a drm_log_scale() helper.
>
> drivers/gpu/drm/clients/drm_log.c | 15 ++++++++++-----
> 1 file changed, 10 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/gpu/drm/clients/drm_log.c b/drivers/gpu/drm/clients/drm_log.c
> index 294b3be1a6b3..9522c1344123 100644
> --- a/drivers/gpu/drm/clients/drm_log.c
> +++ b/drivers/gpu/drm/clients/drm_log.c
> @@ -29,6 +29,11 @@ static unsigned int scale = 1;
> module_param(scale, uint, 0444);
> MODULE_PARM_DESC(scale, "Integer scaling factor for drm_log, default is 1");
>
> +static inline unsigned int drm_log_scale(void)
Please don't use "inline" in .c files. The compiler will know better
what to do.
BR,
Jani.
> +{
> + return scale ?: 1;
> +}
> +
> /**
> * DOC: overview
> *
> @@ -76,13 +81,13 @@ static void drm_log_blit(struct iosys_map *dst, unsigned int dst_pitch,
> {
> switch (px_width) {
> case 2:
> - drm_draw_blit16(dst, dst_pitch, src, src_pitch, height, width, scale, color);
> + drm_draw_blit16(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
> break;
> case 3:
> - drm_draw_blit24(dst, dst_pitch, src, src_pitch, height, width, scale, color);
> + drm_draw_blit24(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
> break;
> case 4:
> - drm_draw_blit32(dst, dst_pitch, src, src_pitch, height, width, scale, color);
> + drm_draw_blit32(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
> break;
> default:
> WARN_ONCE(1, "Can't blit with pixel width %d\n", px_width);
> @@ -216,8 +221,8 @@ static int drm_log_setup_modeset(struct drm_client_dev *client,
> return -ENOMEM;
> }
> mode_set->fb = scanout->buffer->fb;
> - scanout->scaled_font_h = scanout->font->height * scale;
> - scanout->scaled_font_w = scanout->font->width * scale;
> + scanout->scaled_font_h = scanout->font->height * drm_log_scale();
> + scanout->scaled_font_w = scanout->font->width * drm_log_scale();
> scanout->rows = height / scanout->scaled_font_h;
> scanout->columns = width / scanout->scaled_font_w;
> scanout->front_color = drm_draw_color_from_xrgb8888(0xffffff, format);
--
Jani Nikula, Intel
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v2] drm/log: Fix division by zero when scale module parameter is 0
2026-07-29 10:58 [PATCH v2] drm/log: Fix division by zero when scale module parameter is 0 oushixiong1025
2026-07-29 11:14 ` Shixiong Ou
2026-07-29 12:01 ` Jani Nikula
@ 2026-07-29 15:00 ` Jocelyn Falempe
2026-07-29 15:16 ` Jani Nikula
2 siblings, 1 reply; 5+ messages in thread
From: Jocelyn Falempe @ 2026-07-29 15:00 UTC (permalink / raw)
To: oushixiong1025
Cc: Javier Martinez Canillas, Maarten Lankhorst, Maxime Ripard,
Thomas Zimmermann, David Airlie, Simona Vetter, dri-devel,
linux-kernel, Shixiong Ou
On 29/07/2026 12:58, oushixiong1025@163.com wrote:
> From: Shixiong Ou <oushixiong@kylinos.cn>
>
> The scale module parameter can be set to 0 via kernel command line or
> sysfs. When scale is 0, scaled_font_h and scaled_font_w become 0,
> causing a division by zero in the rows/columns calculation.
>
> Introduce a drm_log_scale() helper that returns scale ?: 1, and use it
> at all read sites. This avoids a race that a setter-based clamp would
> have between param_set_uint() and the subsequent check, where another
> CPU could observe scale == 0.
The scale module parameter is read only (that's the meaning of 0444 in
module_param()) so it can't be set by sysfs, or change at runtime.
So this check can be done only once in drm_log_register().
Best regards,
--
Jocelyn
>
> Signed-off-by: Shixiong Ou <oushixiong@kylinos.cn>
> ---
> v1->v2:
> Introduce a drm_log_scale() helper.
>
> drivers/gpu/drm/clients/drm_log.c | 15 ++++++++++-----
> 1 file changed, 10 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/gpu/drm/clients/drm_log.c b/drivers/gpu/drm/clients/drm_log.c
> index 294b3be1a6b3..9522c1344123 100644
> --- a/drivers/gpu/drm/clients/drm_log.c
> +++ b/drivers/gpu/drm/clients/drm_log.c
> @@ -29,6 +29,11 @@ static unsigned int scale = 1;
> module_param(scale, uint, 0444);
> MODULE_PARM_DESC(scale, "Integer scaling factor for drm_log, default is 1");
>
> +static inline unsigned int drm_log_scale(void)
> +{
> + return scale ?: 1;
> +}
> +
> /**
> * DOC: overview
> *
> @@ -76,13 +81,13 @@ static void drm_log_blit(struct iosys_map *dst, unsigned int dst_pitch,
> {
> switch (px_width) {
> case 2:
> - drm_draw_blit16(dst, dst_pitch, src, src_pitch, height, width, scale, color);
> + drm_draw_blit16(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
> break;
> case 3:
> - drm_draw_blit24(dst, dst_pitch, src, src_pitch, height, width, scale, color);
> + drm_draw_blit24(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
> break;
> case 4:
> - drm_draw_blit32(dst, dst_pitch, src, src_pitch, height, width, scale, color);
> + drm_draw_blit32(dst, dst_pitch, src, src_pitch, height, width, drm_log_scale(), color);
> break;
> default:
> WARN_ONCE(1, "Can't blit with pixel width %d\n", px_width);
> @@ -216,8 +221,8 @@ static int drm_log_setup_modeset(struct drm_client_dev *client,
> return -ENOMEM;
> }
> mode_set->fb = scanout->buffer->fb;
> - scanout->scaled_font_h = scanout->font->height * scale;
> - scanout->scaled_font_w = scanout->font->width * scale;
> + scanout->scaled_font_h = scanout->font->height * drm_log_scale();
> + scanout->scaled_font_w = scanout->font->width * drm_log_scale();
> scanout->rows = height / scanout->scaled_font_h;
> scanout->columns = width / scanout->scaled_font_w;
> scanout->front_color = drm_draw_color_from_xrgb8888(0xffffff, format);
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH v2] drm/log: Fix division by zero when scale module parameter is 0
2026-07-29 15:00 ` Jocelyn Falempe
@ 2026-07-29 15:16 ` Jani Nikula
0 siblings, 0 replies; 5+ messages in thread
From: Jani Nikula @ 2026-07-29 15:16 UTC (permalink / raw)
To: Jocelyn Falempe, oushixiong1025
Cc: Javier Martinez Canillas, Maarten Lankhorst, Maxime Ripard,
Thomas Zimmermann, David Airlie, Simona Vetter, dri-devel,
linux-kernel, Shixiong Ou
On Wed, 29 Jul 2026, Jocelyn Falempe <jfalempe@redhat.com> wrote:
> On 29/07/2026 12:58, oushixiong1025@163.com wrote:
>> From: Shixiong Ou <oushixiong@kylinos.cn>
>>
>> The scale module parameter can be set to 0 via kernel command line or
>> sysfs. When scale is 0, scaled_font_h and scaled_font_w become 0,
>> causing a division by zero in the rows/columns calculation.
>>
>> Introduce a drm_log_scale() helper that returns scale ?: 1, and use it
>> at all read sites. This avoids a race that a setter-based clamp would
>> have between param_set_uint() and the subsequent check, where another
>> CPU could observe scale == 0.
>
> The scale module parameter is read only (that's the meaning of 0444 in
> module_param()) so it can't be set by sysfs, or change at runtime.
>
> So this check can be done only once in drm_log_register().
Oops, missed this in my review completely, thanks!
--
Jani Nikula, Intel
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-07-29 15:16 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-29 10:58 [PATCH v2] drm/log: Fix division by zero when scale module parameter is 0 oushixiong1025
2026-07-29 11:14 ` Shixiong Ou
2026-07-29 12:01 ` Jani Nikula
2026-07-29 15:00 ` Jocelyn Falempe
2026-07-29 15:16 ` Jani Nikula
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox