From: "Adrián Larumbe" <adrian.larumbe@collabora.com>
To: narmstrong@baylibre.com, khilman@baylibre.com,
linux-amlogic@lists.infradead.org,
dri-devel@lists.freedesktop.org
Cc: adrian.larumbe@collabora.com
Subject: [PATCH 0/3] drm/meson: fix use-after-free driver unload issues
Date: Mon, 19 Sep 2022 02:09:37 +0100 [thread overview]
Message-ID: <20220919010940.419893-1-adrian.larumbe@collabora.com> (raw)
This patch series tries to fix some use-after-free bugs I've observed with
the help of KASAN in Amlogic's KMS DRM driver.
The first patch in the series reorders the driver deinitialisation sequence
so that devres won't deallocate things that are still expected to be around
by a later call to drm_dev_put.
The second patch adds a missing call to component_master_del inside a new
driver's remove callback.
The third patch makes sure some drm bridges added during driver
initialisation are removed at module unload time, to make sure the global
bridge list doesn't keep nodes to freed memory.
All three patches have been tested on an Odroid N2+ plus SBC.
Adrián Larumbe (3):
drm/meson: reorder driver deinit sequence to fix use-after-free bug
drm/meson: explicitly remove aggregate driver at module unload time
drm/meson: remove drm bridges at aggregate driver unbind time
drivers/gpu/drm/meson/meson_drv.c | 14 +++++++++++++-
drivers/gpu/drm/meson/meson_drv.h | 7 +++++++
drivers/gpu/drm/meson/meson_encoder_cvbs.c | 7 +++++++
drivers/gpu/drm/meson/meson_encoder_cvbs.h | 1 +
drivers/gpu/drm/meson/meson_encoder_hdmi.c | 7 +++++++
drivers/gpu/drm/meson/meson_encoder_hdmi.h | 1 +
drivers/gpu/drm/meson/meson_venc.h | 15 +++++++++++++++
7 files changed, 51 insertions(+), 1 deletion(-)
--
2.37.0
_______________________________________________
linux-amlogic mailing list
linux-amlogic@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-amlogic
next reply other threads:[~2022-09-19 1:10 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-09-19 1:09 Adrián Larumbe [this message]
2022-09-19 1:09 ` [PATCH 1/3] drm/meson: reorder driver deinit sequence to fix use-after-free bug Adrián Larumbe
2022-09-19 12:57 ` Neil Armstrong
2022-09-19 1:09 ` [PATCH 2/3] drm/meson: explicitly remove aggregate driver at module unload time Adrián Larumbe
2022-09-19 12:57 ` Neil Armstrong
2022-09-19 1:09 ` [PATCH 3/3] drm/meson: remove drm bridges at aggregate driver unbind time Adrián Larumbe
2022-09-19 13:03 ` Neil Armstrong
2022-09-20 11:49 ` Adrián Larumbe
2022-09-20 12:56 ` Neil Armstrong
2022-09-20 22:28 ` [PATCH v2 " Adrián Larumbe
2022-09-23 9:28 ` Neil Armstrong
2022-09-23 9:48 ` (subset) [PATCH 0/3] drm/meson: fix use-after-free driver unload issues Neil Armstrong
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20220919010940.419893-1-adrian.larumbe@collabora.com \
--to=adrian.larumbe@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=khilman@baylibre.com \
--cc=linux-amlogic@lists.infradead.org \
--cc=narmstrong@baylibre.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®