| Message ID | 20260901-dw-hdmi-qp-scramb-v11-40-bc12954a0688@collabora.com (mailing list archive) |
|---|---|
| State | New |
| Headers |
Return-Path: <linux-sunxi+bounces-25431-sunxi=pue.re@lists.linux.dev> X-Original-To: noreply@patchwork.local Delivered-To: noreply@patchwork.local Received: from sto.lore.kernel.org (sto.lore.kernel.org [172.232.135.74]) by mxe881.netcup.net (Postfix) with ESMTPS id 6BE4E1C002D for <noreply@patchwork.local>; Tue, 1 Sep 2026 20:57:15 +0200 (CEST) Authentication-Results: mxe881; dkim=pass header.d=collabora.com; spf=pass (sender IP is 172.232.135.74) smtp.mailfrom=linux-sunxi+bounces-25431-noreply=patchwork.local@lists.linux.dev smtp.helo=sto.lore.kernel.org Received-SPF: pass (mxe881: domain of lists.linux.dev designates 172.232.135.74 as permitted sender) client-ip=172.232.135.74; envelope-from=linux-sunxi+bounces-25431-noreply=patchwork.local@lists.linux.dev; helo=sto.lore.kernel.org; Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sto.lore.kernel.org (Postfix) with ESMTP id 90C83607A0F for <noreply@patchwork.local>; Tue, 1 Sep 2026 18:55:37 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id C69414A5EC8; Tue, 1 Sep 2026 18:51:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="Y+QXInC0" X-Original-To: linux-sunxi@lists.linux.dev Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 59C984A5C29 for <linux-sunxi@lists.linux.dev>; Tue, 1 Sep 2026 18:51:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788288676; cv=none; b=tqBMGoYobZlXBwCzkELfzW9QThdrKoIvpWB4POtxFVmJJWy5Brwk+5hi5CZEhJhiLNOgzSCQunij8M02SDJCtunDvHgR7oRVVN87pfhGCAN8YBTJ0YGPunjZV+agxyn76k8DznL0g2fiOEnlnrqrwqWp9LrKGBA01QJrMxK3OKQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788288676; c=relaxed/simple; bh=rOcaPyCXPILsJJZu+k8FKv3RjoMz7iu1oJUoZ0ESuBw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Ucvi1gkfrJYfkTzL2JSIoiuZ8aGR5G8bpR27k3xfOFV7u+kvwyCvh4dRaiN4tDYO2TNR8uNXIgx7gQMU0+hR9VN1F+5NENfNbXYb5F99h/RuW2XAMDDWQOm+ksStu0HZ0SYri6/TYZh46RXGhdkwb/DTimhhxQO7209yUon1cq4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=Y+QXInC0; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1788288670; bh=rOcaPyCXPILsJJZu+k8FKv3RjoMz7iu1oJUoZ0ESuBw=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=Y+QXInC086neqovXgnrBC3GMAfT2ZBiM+bzOv0uaLbFUcaeFsvxsreIkG8iZb9sT/ s3XuuzOGV/DrKoyPAc6m9O5Ij5UEkSibG+sF6vbFENSbQiyFt9D0HksUQ8W68v2mlq zIuBSVnkETwGx+Vqxc7O8HW1h6IGRZxI55QlNWRRNX1KqJR/osQrkUPsGHicE1kIhq 2LmzWHipxXfuPb/aQjaVL0UDcQYUYdOfT1NQdAUFGKx6i2Ooqbi6aj+6Y14+cyr24p QDiiWStAaXj5k/AeZ87I812LpqdCg+RZWqIScv5glMgaFra9b9x2liQTYvr6lGyV4J UBraW0+S1k1Ig== Received: from localhost (unknown [100.64.0.241]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange secp256r1 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: cristicc) by bali.collaboradmins.com (Postfix) with ESMTPSA id 9411C17E3C5D; Tue, 01 Sep 2026 20:51:10 +0200 (CEST) From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com> Date: Tue, 01 Sep 2026 21:51:04 +0300 Subject: [PATCH v11 40/74] drm/rockchip: dw_hdmi_qp: Use dw_hdmi_qp_hpd_notify() for HPD reports Precedence: bulk X-Mailing-List: linux-sunxi@lists.linux.dev List-Id: <linux-sunxi.lists.linux.dev> List-Subscribe: <mailto:linux-sunxi+subscribe@lists.linux.dev> List-Unsubscribe: <mailto:linux-sunxi+unsubscribe@lists.linux.dev> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260901-dw-hdmi-qp-scramb-v11-40-bc12954a0688@collabora.com> References: <20260901-dw-hdmi-qp-scramb-v11-0-bc12954a0688@collabora.com> In-Reply-To: <20260901-dw-hdmi-qp-scramb-v11-0-bc12954a0688@collabora.com> To: Maarten Lankhorst <maarten.lankhorst@linux.intel.com>, Maxime Ripard <mripard@kernel.org>, Thomas Zimmermann <tzimmermann@suse.de>, David Airlie <airlied@gmail.com>, Simona Vetter <simona@ffwll.ch>, Dave Stevenson <dave.stevenson@raspberrypi.com>, Dmitry Baryshkov <lumag@kernel.org>, Andrzej Hajda <andrzej.hajda@intel.com>, Neil Armstrong <neil.armstrong@linaro.org>, Robert Foss <rfoss@kernel.org>, Laurent Pinchart <Laurent.pinchart@ideasonboard.com>, Jonas Karlman <jonas@kwiboo.se>, Jernej Skrabec <jernej.skrabec@gmail.com>, Luca Ceresoli <luca.ceresoli@bootlin.com>, Chen-Yu Tsai <wens@kernel.org>, Samuel Holland <samuel@sholland.org>, =?utf-8?q?Ma=C3=ADra_Canal?= <mcanal@igalia.com>, Raspberry Pi Kernel Maintenance <kernel-list@raspberrypi.com>, Raphael Gallais-Pou <rgallaispou@gmail.com>, Sandy Huang <hjc@rock-chips.com>, =?utf-8?q?Heiko_St=C3=BCbner?= <heiko@sntech.de>, Andy Yan <andy.yan@rock-chips.com>, Algea Cao <algea.cao@rock-chips.com>, Daniel Stone <daniels@collabora.com>, Liu Ying <victor.liu@nxp.com>, Phong LE <ple@baylibre.com>, Helge Deller <deller@gmx.de> Cc: kernel@collabora.com, linux-kernel@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-rockchip@lists.infradead.org, linux-fbdev@vger.kernel.org, Maud Spierings <maud_spierings@hotmail.com>, Diederik de Haas <diederik@cknow-tech.com> X-Mailer: b4 0.15.2 X-MORS-Enabled: yes X-MORS-DOMAIN: patchwork.local X-MORS-HOSTING: hosting172546 X-MORS-USER: hosting172546 X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= |
| Series |
Add HDMI 2.0 support to DW HDMI QP TX
|
|
Commit Message
Cristian Ciocaltea
Sept. 1, 2026, 6:51 p.m. UTC
Notify only the affected connector instead of polling all of them, and ensure .detect_ctx() runs on reconnect to recover SCDC state. Tested-by: Maud Spierings <maud_spierings@hotmail.com> Tested-by: Diederik de Haas <diederik@cknow-tech.com> # NanoPC-T6 LTS, Rock 5B Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com> --- drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c | 12 ++---------- 1 file changed, 2 insertions(+), 10 deletions(-)
Comments
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Lifetime mismatch between drmm_ allocated state and devm_ managed resources causes Use-After-Free and resource leaks.
--
commit 4f79590505cad08e229d9cf38e2f40905ce2991c
Author: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
drm/rockchip: dw_hdmi_qp: Use dw_hdmi_qp_hpd_notify() for HPD reports
Notify only the affected connector instead of polling all of them, and
ensure .detect_ctx() runs on reconnect to recover SCDC state.
> diff --git a/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c b/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c
> index 1c547016ee009..f2a1ea8dfefa5 100644
> --- a/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c
> +++ b/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c
[ ... ]
> @@ -398,14 +397,8 @@ static void dw_hdmi_qp_rk3588_hpd_work(struct work_struct *work)
> struct rockchip_hdmi_qp *hdmi = container_of(work,
> struct rockchip_hdmi_qp,
> hpd_work.work);
> - struct drm_device *drm = hdmi->encoder.encoder.dev;
> - bool changed;
>
> - if (drm) {
> - changed = drm_helper_hpd_irq_event(drm);
> - if (changed)
> - dev_dbg(hdmi->dev, "connector status changed\n");
> - }
> + dw_hdmi_qp_hpd_notify(hdmi->hdmi);
> }
[Severity: High]
This is a pre-existing issue, but can the hpd_work or IRQ handler outlive the
hdmi structure, leading to a use-after-free here?
The hdmi structure is allocated with DRM device lifetime in
dw_hdmi_qp_rockchip_bind():
hdmi = drmm_kzalloc(drm, sizeof(*hdmi), GFP_KERNEL);
However, the IRQ is registered with platform device lifetime:
ret = devm_request_threaded_irq(dev, hdmi->hpd_irq,
cfg->ctrl_ops->hardirq_callback,
cfg->ctrl_ops->irq_callback,
IRQF_NO_AUTOEN, "dw-hdmi-qp-hpd",
hdmi);
During a component unbind (e.g. via sysfs or EPROBE_DEFER),
dw_hdmi_qp_rockchip_unbind() does not explicitly disable the IRQ or unregister
the bridge:
static void dw_hdmi_qp_rockchip_unbind(struct device *dev,
struct device *master,
void *data)
{
struct rockchip_hdmi_qp *hdmi = dev_get_drvdata(dev);
dev_set_drvdata(dev, NULL);
cancel_delayed_work_sync(&hdmi->hpd_work);
}
If the DRM device is freed, the hdmi structure is also freed. But because devm_
resources are tied to the platform device (which isn't removed during a
component unbind), the IRQ remains active.
If a hotplug event fires afterwards, won't it dereference the freed hdmi
pointer and cause a panic?
diff --git a/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c b/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c index 1c547016ee00..f2a1ea8dfefa 100644 --- a/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c +++ b/drivers/gpu/drm/rockchip/dw_hdmi_qp-rockchip.c @@ -24,7 +24,6 @@ #include <drm/drm_bridge_connector.h> #include <drm/drm_managed.h> #include <drm/drm_of.h> -#include <drm/drm_probe_helper.h> #include "rockchip_drm_drv.h" @@ -398,14 +397,8 @@ static void dw_hdmi_qp_rk3588_hpd_work(struct work_struct *work) struct rockchip_hdmi_qp *hdmi = container_of(work, struct rockchip_hdmi_qp, hpd_work.work); - struct drm_device *drm = hdmi->encoder.encoder.dev; - bool changed; - if (drm) { - changed = drm_helper_hpd_irq_event(drm); - if (changed) - dev_dbg(hdmi->dev, "connector status changed\n"); - } + dw_hdmi_qp_hpd_notify(hdmi->hdmi); } static irqreturn_t dw_hdmi_qp_rk3576_hardirq(int irq, void *dev_id) @@ -792,8 +785,7 @@ static int __maybe_unused dw_hdmi_qp_rockchip_resume(struct device *dev) dw_hdmi_qp_resume(dev, hdmi->hdmi); - if (hdmi->encoder.encoder.dev) - drm_helper_hpd_irq_event(hdmi->encoder.encoder.dev); + dw_hdmi_qp_hpd_notify(hdmi->hdmi); return 0; }