From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx07-00178001.pphosted.com (mx08-00178001.pphosted.com [91.207.212.93]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 968E0249E1 for ; Fri, 5 Jan 2024 09:21:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=foss.st.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=foss.st.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=foss.st.com header.i=@foss.st.com header.b="TvqDL3NS" Received: from pps.filterd (m0046661.ppops.net [127.0.0.1]) by mx07-00178001.pphosted.com (8.17.1.22/8.17.1.22) with ESMTP id 4052xVtj026982; Fri, 5 Jan 2024 10:21:10 +0100 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=foss.st.com; h= message-id:date:mime-version:subject:to:cc:references:from :in-reply-to:content-type:content-transfer-encoding; s= selector1; bh=vW8CYyGIP/vC0L2YTygi0W0H7YOr9Bs1QNabt8ZBU1M=; b=Tv qDL3NSqwEnMohCzDKfiJx/4bDSTntsHCmJ93nwH9C+miyfsS9+R9rbUPshYJtqX5 LPD0N2PGDrqjjg/XxQbBx/BGH5+SfgNjOvlHRAZmSDYKDDD9agRoJxf1WQFWGemP bflaXuetxu030U1SxNqX4Wo2V66XtPgnYpiydlRl4UkV41/Jm8b9wDP4pK233w0h ySbV4rDlpZsu67A4bp03GO5hR1yCZQe3XjWVm3+sucXT7r6ehFChl+GD5ZgttqCU VVuoblEAcqoHXRzLfGDAh8i9APGuDKwjlS5d6QqV5ZTrOLJF5HfI4WIamAX0cp78 9Y/TxhvmDDQPmueDN8Iw== Received: from beta.dmz-eu.st.com (beta.dmz-eu.st.com [164.129.1.35]) by mx07-00178001.pphosted.com (PPS) with ESMTPS id 3ve9fd19g7-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 05 Jan 2024 10:21:10 +0100 (CET) Received: from euls16034.sgp.st.com (euls16034.sgp.st.com [10.75.44.20]) by beta.dmz-eu.st.com (STMicroelectronics) with ESMTP id 978ED10002A; Fri, 5 Jan 2024 10:21:09 +0100 (CET) Received: from Webmail-eu.st.com (shfdag1node2.st.com [10.75.129.70]) by euls16034.sgp.st.com (STMicroelectronics) with ESMTP id 830EE21861F; Fri, 5 Jan 2024 10:21:09 +0100 (CET) Received: from [10.252.5.254] (10.252.5.254) by SHFDAG1NODE2.st.com (10.75.129.70) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.27; Fri, 5 Jan 2024 10:21:09 +0100 Message-ID: <76b4dfd8-f8c2-41f1-96df-539b168f9e80@foss.st.com> Date: Fri, 5 Jan 2024 10:21:08 +0100 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v2] drm/stm: Avoid use-after-free issues with crtc and plane Content-Language: en-US To: Katya Orlova CC: Yannick Fertre , Philippe Cornu , David Airlie , Daniel Vetter , Maxime Coquelin , Alexandre Torgue , Philipp Zabel , , , , , References: <20231124100415.21713-1-e.orlova@ispras.ru> From: Raphael Gallais-Pou In-Reply-To: <20231124100415.21713-1-e.orlova@ispras.ru> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 8bit X-ClientProxiedBy: EQNCAS1NODE3.st.com (10.75.129.80) To SHFDAG1NODE2.st.com (10.75.129.70) X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.997,Hydra:6.0.619,FMLib:17.11.176.26 definitions=2024-01-05_04,2024-01-05_01,2023-05-22_02 On 11/24/23 11:04, Katya Orlova wrote: > ltdc_load() calls functions drm_crtc_init_with_planes(), > drm_universal_plane_init() and drm_encoder_init(). These functions > should not be called with parameters allocated with devm_kzalloc() > to avoid use-after-free issues [1]. > > Use allocations managed by the DRM framework. > > Found by Linux Verification Center (linuxtesting.org). > > [1] > https://lore.kernel.org/lkml/u366i76e3qhh3ra5oxrtngjtm2u5lterkekcz6y2jkndhuxzli@diujon4h7qwb/ > > Signed-off-by: Katya Orlova > --- > v2: use allocations managed by the DRM as > Raphael Gallais-Pou suggested. > Also add a fix for encoder. > drivers/gpu/drm/stm/drv.c | 3 +- > drivers/gpu/drm/stm/ltdc.c | 68 +++++++++----------------------------- > 2 files changed, 18 insertions(+), 53 deletions(-) > > diff --git a/drivers/gpu/drm/stm/drv.c b/drivers/gpu/drm/stm/drv.c > index e8523abef27a..152bec2c0238 100644 > --- a/drivers/gpu/drm/stm/drv.c > +++ b/drivers/gpu/drm/stm/drv.c > @@ -25,6 +25,7 @@ > #include > #include > #include > +#include > > #include "ltdc.h" > > @@ -75,7 +76,7 @@ static int drv_load(struct drm_device *ddev) > > DRM_DEBUG("%s\n", __func__); > > - ldev = devm_kzalloc(ddev->dev, sizeof(*ldev), GFP_KERNEL); > + ldev = drmm_kzalloc(ddev, sizeof(*ldev), GFP_KERNEL); > if (!ldev) > return -ENOMEM; > > diff --git a/drivers/gpu/drm/stm/ltdc.c b/drivers/gpu/drm/stm/ltdc.c > index 5576fdae4962..02a7c8375f44 100644 > --- a/drivers/gpu/drm/stm/ltdc.c > +++ b/drivers/gpu/drm/stm/ltdc.c > @@ -36,6 +36,7 @@ > #include > #include > #include > +#include > > #include