From patchwork Fri Feb 16 12:50:40 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Katya Orlova X-Patchwork-Id: 202114 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a05:7300:c619:b0:108:e6aa:91d0 with SMTP id hn25csp490962dyb; Fri, 16 Feb 2024 04:59:33 -0800 (PST) X-Forwarded-Encrypted: i=3; AJvYcCWktTOLWTn+0fl2owrAopc4nOIiKo+8ySv7fGY90ood+nemLIL5HYTLzNF/TO2R5VybeghvOXI6JNxhjow8xkmMPnhfsw== X-Google-Smtp-Source: AGHT+IGe5P5c2qePH0WROuN0XWqXaSKGKKLhCUNV3OjIMevhxRn1Jw2mhw5W68ozOdBmuYpewnYQ X-Received: by 2002:aa7:c1d2:0:b0:561:e8c:791e with SMTP id d18-20020aa7c1d2000000b005610e8c791emr3642422edp.38.1708088373488; Fri, 16 Feb 2024 04:59:33 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1708088373; cv=pass; d=google.com; s=arc-20160816; b=NjnMyre2iudJ4y9UBAOSWnQvY/URfjAR20LpYaKN5uxQs6C1Fq0DsOfkQ5h2zy7wHw sIIpb5HEv8IAgnWQf+f466gmZDQdaN73wMhNzvx/dJXZJzgxaBSXSGqTorqNzYWE+5ZG JZemQVG8hqcaDr8sQdHcSYQ00j/Tdm9e5rJNZv47YriWxFx1dkwMgXrp8NpMSsuqpycJ A9LC9vcRkJgqOKkbm5El4nO17t8B2ju81wLGomk6fYa6maHYsgSlspc6V9ulpJIevfo5 NdMA1OTTQVFGYA9AwjsvA2vATkjnwj1nQh3c/L0f5QWdT4k/txg4/KE/ctTPTJkKcjpk X0wQ== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:in-reply-to:message-id :date:subject:cc:to:from:dkim-signature:dkim-filter; bh=S1r8Mq3qgF/963ARXbA2g2vgUJ1UOzD2+uwWm8hvuMU=; fh=qJHlo3IUbq3BHalE8e8W33rZ8IE9TUSAGs/+VFOm8kY=; b=aGGKtCpSg3JGDI8MjSwaDvTNMtTKys0bshqTOID78rahJYlkWYEPV/uq79IyGYem0E n2PRMc5vjctZgkvpdUyjXLVES40UfgKKZ6KNGIvfzJXwg7+QnBEns37XUqfG5R0lKQz+ ek6bdm9/75kM7rFDe8BEh0x3tIJQiv6LUizXf16cPMfJ/aLVWTZ48p1w8VpMW3kkLLB4 MHJYJSL/OOSJgJLV0ZkVU9605p3xF3RRDoYAomh7U3PlLwSYvshRhVEPFIwuraLA1ynh uPNErvNe4cusxJJtkOqWvvEHJzI8DRoHGK6Oo2orAFrr0UqJ/O4btMDYcJHRR1Jr1fSa 8lVg==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@ispras.ru header.s=default header.b=l530KQlS; arc=pass (i=1 spf=pass spfdomain=ispras.ru dkim=pass dkdomain=ispras.ru dmarc=pass fromdomain=ispras.ru); spf=pass (google.com: domain of linux-kernel+bounces-68602-ouuuleilei=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-68602-ouuuleilei=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ispras.ru Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [2604:1380:4601:e00::3]) by mx.google.com with ESMTPS id m22-20020a50d7d6000000b00563ff5841acsi306467edj.654.2024.02.16.04.59.33 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 16 Feb 2024 04:59:33 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-68602-ouuuleilei=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) client-ip=2604:1380:4601:e00::3; Authentication-Results: mx.google.com; dkim=pass header.i=@ispras.ru header.s=default header.b=l530KQlS; arc=pass (i=1 spf=pass spfdomain=ispras.ru dkim=pass dkdomain=ispras.ru dmarc=pass fromdomain=ispras.ru); spf=pass (google.com: domain of linux-kernel+bounces-68602-ouuuleilei=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-68602-ouuuleilei=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ispras.ru Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id 9DD021F26206 for ; Fri, 16 Feb 2024 12:59:32 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 0113C1292ED; Fri, 16 Feb 2024 12:59:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=ispras.ru header.i=@ispras.ru header.b="l530KQlS" Received: from mail.ispras.ru (mail.ispras.ru [83.149.199.84]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8F1201292D3 for ; Fri, 16 Feb 2024 12:59:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=83.149.199.84 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1708088355; cv=none; b=Wp8ovbMZ4nkEcEWJF1FwwPouLmiGYZOaGEq37P2owiZ5i+fncojcP/PcXQo/Bdovjb0bcjZdJV/L1DWZfIVTo6BVWwQ3SlUPLqgVLJXY4k0LbEoPMG2LUAAD2N+3uBma9wzD1dNVPy+GRCyfw3qo+XnC8HGMIPOadLFyKzub1XM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1708088355; c=relaxed/simple; bh=ztukOrv72pACnLN/LBb1pjlApd0Wuv5E3PPbJyRaPJE=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=J7FNg2wM3cUrYWJrKj2qYU1/yTfk16qbQmwc2eQz1eK2Co3xSo64bEitmxz+G1fosbMmjShSWYDYHWjZ0OAoWFOSF/Yiz+c4UhCbhVpYn0vD4CoZLbI2fukf5t7hXN3iaA3u9pj3mOstJgc6gR1gKIq6z2RY+sbZrWJcF6PndTM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=ispras.ru; spf=pass smtp.mailfrom=ispras.ru; dkim=pass (1024-bit key) header.d=ispras.ru header.i=@ispras.ru header.b=l530KQlS; arc=none smtp.client-ip=83.149.199.84 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=ispras.ru Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ispras.ru Received: from lvc-arm12.ispras.local (unknown [83.149.199.78]) by mail.ispras.ru (Postfix) with ESMTPSA id BE57B40241B8; Fri, 16 Feb 2024 12:51:18 +0000 (UTC) DKIM-Filter: OpenDKIM Filter v2.11.0 mail.ispras.ru BE57B40241B8 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ispras.ru; s=default; t=1708087878; bh=S1r8Mq3qgF/963ARXbA2g2vgUJ1UOzD2+uwWm8hvuMU=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=l530KQlS2F9fEvWEyHl8g2mcEv5y1S8LDqebs9zWqV1IBJoQpJB2NWVvHu1/byxMK /7f0bxZaBr3BjfVZmVEoS2lzkVSq2rYwDfOsAO4nmCgr7cbEofREBynkQkJM808RiS lqUSHobGdoN8Dl115yt8N6JYyQeh5nLP3fKFt1YY= From: Katya Orlova To: Raphael Gallais-Pou Cc: Katya Orlova , Yannick Fertre , Philippe Cornu , David Airlie , Daniel Vetter , Maxime Coquelin , Alexandre Torgue , Philipp Zabel , dri-devel@lists.freedesktop.org, linux-stm32@st-md-mailman.stormreply.com, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, lvc-project@linuxtesting.org Subject: [PATCH v4] drm/stm: Avoid use-after-free issues with crtc and plane Date: Fri, 16 Feb 2024 15:50:40 +0300 Message-Id: <20240216125040.8968-1-e.orlova@ispras.ru> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20240122111128.10852-1-e.orlova@ispras.ru> References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-THRID: 1780270150882606039 X-GMAIL-MSGID: 1791060474249491011 ltdc_load() calls functions drm_crtc_init_with_planes(), drm_universal_plane_init() and drm_encoder_init(). These functions should not be called with parameters allocated with devm_kzalloc() to avoid use-after-free issues [1]. Use allocations managed by the DRM framework. Found by Linux Verification Center (linuxtesting.org). [1] https://lore.kernel.org/lkml/u366i76e3qhh3ra5oxrtngjtm2u5lterkekcz6y2jkndhuxzli@diujon4h7qwb/ Signed-off-by: Katya Orlova Acked-by: Raphaƫl Gallais-Pou --- v4: rebase on the drm-misc v3: style problems v2: use allocations managed by the DRM as Raphael Gallais-Pou suggested. Also add a fix for encoder. drivers/gpu/drm/stm/drv.c | 3 +- drivers/gpu/drm/stm/ltdc.c | 73 ++++++++++---------------------------- 2 files changed, 20 insertions(+), 56 deletions(-) diff --git a/drivers/gpu/drm/stm/drv.c b/drivers/gpu/drm/stm/drv.c index e8523abef27a..152bec2c0238 100644 --- a/drivers/gpu/drm/stm/drv.c +++ b/drivers/gpu/drm/stm/drv.c @@ -25,6 +25,7 @@ #include #include #include +#include #include "ltdc.h" @@ -75,7 +76,7 @@ static int drv_load(struct drm_device *ddev) DRM_DEBUG("%s\n", __func__); - ldev = devm_kzalloc(ddev->dev, sizeof(*ldev), GFP_KERNEL); + ldev = drmm_kzalloc(ddev, sizeof(*ldev), GFP_KERNEL); if (!ldev) return -ENOMEM; diff --git a/drivers/gpu/drm/stm/ltdc.c b/drivers/gpu/drm/stm/ltdc.c index 5576fdae4962..eeaabb4e10d3 100644 --- a/drivers/gpu/drm/stm/ltdc.c +++ b/drivers/gpu/drm/stm/ltdc.c @@ -36,6 +36,7 @@ #include #include #include +#include #include