From patchwork Mon Jan 22 11:11:28 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Katya Orlova X-Patchwork-Id: 190097 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a05:7301:2bc4:b0:101:a8e8:374 with SMTP id hx4csp2505327dyb; Mon, 22 Jan 2024 03:27:09 -0800 (PST) X-Google-Smtp-Source: AGHT+IFVPo6iQNmOl9TUng064fNDiuN3am06Festn/S/NRMzppGvmcQSoUMNfLhkMFuY5f5ZY+mP X-Received: by 2002:a05:6402:38f:b0:55c:63c5:8412 with SMTP id o15-20020a056402038f00b0055c63c58412mr163951edv.43.1705922829083; Mon, 22 Jan 2024 03:27:09 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1705922829; cv=pass; d=google.com; s=arc-20160816; b=Q7cR2xcWSgIxKKJobqmmOyiRqtbRQTLw5boxAU6vVHS1HzUrSDzrgQNL3Es16hrbS9 fBb2uMWK4wx9PplQMvQ0dwfSwt+RJ2BDenikf5phU980j1INFjJ6QAneiHSC0X/5fqf0 zCSRELt7+H4fUVkN8Hcl9gW9j24PGO3jc1bO1Z2YC8kD4aw7n0ZV/I//FMHZQmpjNxhp c/9TwV3qsA0HH/RN5DYkamA1YhM8Ht0MKsUj86cT7LZSoredw/6XLO8HmQahnzn/Jl9Q ad8AgIpi9ji/ZMk7HunKebfhG/bEBFmhl6FWoipm8UXPQ3RrzgEE1wqXn5ObJQU7jzao aJ2A== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:in-reply-to:message-id :date:subject:cc:to:from:dkim-signature:dkim-filter; bh=4qafhDsstu+fI2ZE276xbjZ5WzhAT+Anma2zk/rbwu4=; fh=qJHlo3IUbq3BHalE8e8W33rZ8IE9TUSAGs/+VFOm8kY=; b=yqzr3+StPWUEO2v7nEXs2SAViDsYt30mVJAsAcVb40v8nEdP/sn3pmMRgE/u6cHoDc 8neDrNPMHZMVYCbqWJrVIuis6s4r7YsiAvF2ulePeIr/4bGu9oA3pH160XGj/tOUQ/eQ vogYjoHOJO7WU86Cl3WvfUFcMgnDlhG0D1m8sIctn6SCaoeqfDt2eMjVTcliOM5AgONM kqlbRsJLu09S2J7fQPADlqISRogWLZBfo9sEb5toGo89Fyb0wQl+58ljOHs31RcbNgM+ 47uhvskO4mtfAsUxDE8nqfyYTTKT4GEdhNxXZRF70N5NbDZ66fZD3gg9Y6Cgbgc1ogFk awdg== ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@ispras.ru header.s=default header.b=bKNx41Ut; arc=pass (i=1 spf=pass spfdomain=ispras.ru dkim=pass dkdomain=ispras.ru dmarc=pass fromdomain=ispras.ru); spf=pass (google.com: domain of linux-kernel+bounces-32884-ouuuleilei=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) smtp.mailfrom="linux-kernel+bounces-32884-ouuuleilei=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ispras.ru Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [147.75.80.249]) by mx.google.com with ESMTPS id es14-20020a056402380e00b0055a908eb533si2522430edb.54.2024.01.22.03.27.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 22 Jan 2024 03:27:09 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-32884-ouuuleilei=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) client-ip=147.75.80.249; Authentication-Results: mx.google.com; dkim=pass header.i=@ispras.ru header.s=default header.b=bKNx41Ut; arc=pass (i=1 spf=pass spfdomain=ispras.ru dkim=pass dkdomain=ispras.ru dmarc=pass fromdomain=ispras.ru); spf=pass (google.com: domain of linux-kernel+bounces-32884-ouuuleilei=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) smtp.mailfrom="linux-kernel+bounces-32884-ouuuleilei=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ispras.ru Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id B3A671F21EA5 for ; Mon, 22 Jan 2024 11:26:45 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id CA80F4CB34; Mon, 22 Jan 2024 11:12:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=ispras.ru header.i=@ispras.ru header.b="bKNx41Ut" Received: from mail.ispras.ru (mail.ispras.ru [83.149.199.84]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 540194C609 for ; Mon, 22 Jan 2024 11:11:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=83.149.199.84 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1705921925; cv=none; b=LofzYbwQeCtEnaFBBtVMlBoQH/ri0zIdlapKNfW7Q6hm5QXvdnv2/WRqMmrJDMDynNL/uwU3iIcPzNIEZRTaYHBaewTZhRuand+SlqsxvidWmjUaX9P+Rv9NT44+ZDjgPqEV/b9k06bQD6voPz7gN2IsKk0bL3D6BT/8AjxMgDY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1705921925; c=relaxed/simple; bh=18FXR6Q5xROo9X2pMM68D0Ki8ZVCWsmS1INeFq+vG/E=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=l+Eq5rqZShod9zGWu0txnWLZkc+IG265JiGNv+LpyGHC1cv5Rom3OO4R+Sn7FaGyEHb8gzm3TORr5/XgzN6/WCZjEnshe0uJNM55VBj0h+r7XPUhrkZQeAX9didm0mVjlsGxKg8HSIYQTtTzXtYmMp5BMj52gnyj62dD+Ovt8aU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=ispras.ru; spf=pass smtp.mailfrom=ispras.ru; dkim=pass (1024-bit key) header.d=ispras.ru header.i=@ispras.ru header.b=bKNx41Ut; arc=none smtp.client-ip=83.149.199.84 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=ispras.ru Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ispras.ru Received: from lvc-arm12.ispras.local (unknown [83.149.199.78]) by mail.ispras.ru (Postfix) with ESMTPSA id 4A49840F1DE6; Mon, 22 Jan 2024 11:11:51 +0000 (UTC) DKIM-Filter: OpenDKIM Filter v2.11.0 mail.ispras.ru 4A49840F1DE6 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ispras.ru; s=default; t=1705921911; bh=4qafhDsstu+fI2ZE276xbjZ5WzhAT+Anma2zk/rbwu4=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=bKNx41UtGMHF9O/8QysFpjmNL9P43M+0zzrdWvGjzWA+3/CiYC7WPxZNMocobhdp3 mL2KG6x5uDjIfZHuwNdXCB5VhWzvfFwoAVAtaH3yclYjsLzKiKMNvmplCbDSIv6A2A CSnv3AEIBi5nHdsuJB0E6JKg62efRkJUgNnldzLA= From: Katya Orlova To: Raphael Gallais-Pou Cc: Katya Orlova , Yannick Fertre , Philippe Cornu , David Airlie , Daniel Vetter , Maxime Coquelin , Alexandre Torgue , Philipp Zabel , dri-devel@lists.freedesktop.org, linux-stm32@st-md-mailman.stormreply.com, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, lvc-project@linuxtesting.org Subject: [PATCH v3] drm/stm: Avoid use-after-free issues with crtc and plane Date: Mon, 22 Jan 2024 14:11:28 +0300 Message-Id: <20240122111128.10852-1-e.orlova@ispras.ru> X-Mailer: git-send-email 2.30.2 In-Reply-To: <76b4dfd8-f8c2-41f1-96df-539b168f9e80@foss.st.com> References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-THRID: 1780270150882606039 X-GMAIL-MSGID: 1788789736219941120 ltdc_load() calls functions drm_crtc_init_with_planes(), drm_universal_plane_init() and drm_encoder_init(). These functions should not be called with parameters allocated with devm_kzalloc() to avoid use-after-free issues [1]. Use allocations managed by the DRM framework. Found by Linux Verification Center (linuxtesting.org). [1] https://lore.kernel.org/lkml/u366i76e3qhh3ra5oxrtngjtm2u5lterkekcz6y2jkndhuxzli@diujon4h7qwb/ Signed-off-by: Katya Orlova --- v3: style problems v2: use allocations managed by the DRM as Raphael Gallais-Pou suggested. Also add a fix for encoder. drivers/gpu/drm/stm/drv.c | 3 +- drivers/gpu/drm/stm/ltdc.c | 69 +++++++++----------------------------- 2 files changed, 18 insertions(+), 54 deletions(-) diff --git a/drivers/gpu/drm/stm/drv.c b/drivers/gpu/drm/stm/drv.c index e8523abef27a..152bec2c0238 100644 --- a/drivers/gpu/drm/stm/drv.c +++ b/drivers/gpu/drm/stm/drv.c @@ -25,6 +25,7 @@ #include #include #include +#include #include "ltdc.h" @@ -75,7 +76,7 @@ static int drv_load(struct drm_device *ddev) DRM_DEBUG("%s\n", __func__); - ldev = devm_kzalloc(ddev->dev, sizeof(*ldev), GFP_KERNEL); + ldev = drmm_kzalloc(ddev, sizeof(*ldev), GFP_KERNEL); if (!ldev) return -ENOMEM; diff --git a/drivers/gpu/drm/stm/ltdc.c b/drivers/gpu/drm/stm/ltdc.c index 5576fdae4962..e050b519ad38 100644 --- a/drivers/gpu/drm/stm/ltdc.c +++ b/drivers/gpu/drm/stm/ltdc.c @@ -36,6 +36,7 @@ #include #include #include +#include #include