mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 1/3] drm/msm: Avoid NULL dereference in msm_disp_state_print_regs()
@ 2024-10-14 16:36 Douglas Anderson
  2024-10-14 16:36 ` [PATCH 2/3] drm/msm: Allocate memory for disp snapshot with kvzalloc() Douglas Anderson
                   ` (3 more replies)
  0 siblings, 4 replies; 7+ messages in thread
From: Douglas Anderson @ 2024-10-14 16:36 UTC (permalink / raw)
  To: Rob Clark, Abhinav Kumar, Dmitry Baryshkov
  Cc: Stephen Boyd, Douglas Anderson, David Airlie, Marijn Suijten,
	Sean Paul, Simona Vetter, dri-devel, freedreno, linux-arm-msm,
	linux-kernel

If the allocation in msm_disp_state_dump_regs() failed then
`block->state` can be NULL. The msm_disp_state_print_regs() function
_does_ have code to try to handle it with:

  if (*reg)
    dump_addr = *reg;

...but since "dump_addr" is initialized to NULL the above is actually
a noop. The code then goes on to dereference `dump_addr`.

Make the function print "Registers not stored" when it sees a NULL to
solve this. Since we're touching the code, fix
msm_disp_state_print_regs() not to pointlessly take a double-pointer
and properly mark the pointer as `const`.

Fixes: 98659487b845 ("drm/msm: add support to take dpu snapshot")
Signed-off-by: Douglas Anderson <dianders@chromium.org>
---

 drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c | 15 ++++++++-------
 1 file changed, 8 insertions(+), 7 deletions(-)

diff --git a/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c b/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c
index add72bbc28b1..bb149281d31f 100644
--- a/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c
+++ b/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c
@@ -48,20 +48,21 @@ static void msm_disp_state_dump_regs(u32 **reg, u32 aligned_len, void __iomem *b
 	}
 }
 
-static void msm_disp_state_print_regs(u32 **reg, u32 len, void __iomem *base_addr,
-		struct drm_printer *p)
+static void msm_disp_state_print_regs(const u32 *dump_addr, u32 len,
+		void __iomem *base_addr, struct drm_printer *p)
 {
 	int i;
-	u32 *dump_addr = NULL;
 	void __iomem *addr;
 	u32 num_rows;
 
+	if (!dump_addr) {
+		drm_printf(p, "Registers not stored\n");
+		return;
+	}
+
 	addr = base_addr;
 	num_rows = len / REG_DUMP_ALIGN;
 
-	if (*reg)
-		dump_addr = *reg;
-
 	for (i = 0; i < num_rows; i++) {
 		drm_printf(p, "0x%lx : %08x %08x %08x %08x\n",
 				(unsigned long)(addr - base_addr),
@@ -89,7 +90,7 @@ void msm_disp_state_print(struct msm_disp_state *state, struct drm_printer *p)
 
 	list_for_each_entry_safe(block, tmp, &state->blocks, node) {
 		drm_printf(p, "====================%s================\n", block->name);
-		msm_disp_state_print_regs(&block->state, block->size, block->base_addr, p);
+		msm_disp_state_print_regs(block->state, block->size, block->base_addr, p);
 	}
 
 	drm_printf(p, "===================dpu drm state================\n");
-- 
2.47.0.rc1.288.g06298d1525-goog


^ permalink raw reply	[flat|nested] 7+ messages in thread

* [PATCH 2/3] drm/msm: Allocate memory for disp snapshot with kvzalloc()
  2024-10-14 16:36 [PATCH 1/3] drm/msm: Avoid NULL dereference in msm_disp_state_print_regs() Douglas Anderson
@ 2024-10-14 16:36 ` Douglas Anderson
  2024-10-14 18:56   ` Abhinav Kumar
  2024-10-14 16:36 ` [PATCH 3/3] drm/msm: Simplify NULL checking in msm_disp_state_dump_regs() Douglas Anderson
                   ` (2 subsequent siblings)
  3 siblings, 1 reply; 7+ messages in thread
From: Douglas Anderson @ 2024-10-14 16:36 UTC (permalink / raw)
  To: Rob Clark, Abhinav Kumar, Dmitry Baryshkov
  Cc: Stephen Boyd, Douglas Anderson, David Airlie, Marijn Suijten,
	Sean Paul, Simona Vetter, dri-devel, freedreno, linux-arm-msm,
	linux-kernel

With the "drm/msm: add a display mmu fault handler" series [1] we saw
issues in the field where memory allocation was failing when
allocating space for registers in msm_disp_state_dump_regs().
Specifically we were seeing an order 5 allocation fail. It's not
surprising that order 5 allocations will sometimes fail after the
system has been up and running for a while.

There's no need here for contiguous memory. Change the allocation to
kvzalloc() which should make it much less likely to fail.

[1] https://lore.kernel.org/r/20240628214848.4075651-1-quic_abhinavk@quicinc.com/

Fixes: 98659487b845 ("drm/msm: add support to take dpu snapshot")
Signed-off-by: Douglas Anderson <dianders@chromium.org>
---

 drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c b/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c
index bb149281d31f..4d55e3cf570f 100644
--- a/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c
+++ b/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c
@@ -26,7 +26,7 @@ static void msm_disp_state_dump_regs(u32 **reg, u32 aligned_len, void __iomem *b
 	end_addr = base_addr + aligned_len;
 
 	if (!(*reg))
-		*reg = kzalloc(len_padded, GFP_KERNEL);
+		*reg = kvzalloc(len_padded, GFP_KERNEL);
 
 	if (*reg)
 		dump_addr = *reg;
@@ -162,7 +162,7 @@ void msm_disp_state_free(void *data)
 
 	list_for_each_entry_safe(block, tmp, &disp_state->blocks, node) {
 		list_del(&block->node);
-		kfree(block->state);
+		kvfree(block->state);
 		kfree(block);
 	}
 
-- 
2.47.0.rc1.288.g06298d1525-goog


^ permalink raw reply	[flat|nested] 7+ messages in thread

* [PATCH 3/3] drm/msm: Simplify NULL checking in msm_disp_state_dump_regs()
  2024-10-14 16:36 [PATCH 1/3] drm/msm: Avoid NULL dereference in msm_disp_state_print_regs() Douglas Anderson
  2024-10-14 16:36 ` [PATCH 2/3] drm/msm: Allocate memory for disp snapshot with kvzalloc() Douglas Anderson
@ 2024-10-14 16:36 ` Douglas Anderson
  2024-10-14 19:03   ` Abhinav Kumar
  2024-10-14 18:52 ` [PATCH 1/3] drm/msm: Avoid NULL dereference in msm_disp_state_print_regs() Abhinav Kumar
  2024-10-27  2:04 ` Dmitry Baryshkov
  3 siblings, 1 reply; 7+ messages in thread
From: Douglas Anderson @ 2024-10-14 16:36 UTC (permalink / raw)
  To: Rob Clark, Abhinav Kumar, Dmitry Baryshkov
  Cc: Stephen Boyd, Douglas Anderson, David Airlie, Marijn Suijten,
	Sean Paul, Simona Vetter, dri-devel, freedreno, linux-arm-msm,
	linux-kernel

The msm_disp_state_dump_regs():

- Doesn't allocate if the caller already allocated. ...but there's one
  caller and it doesn't allocate so we don't need this check.
- Checks for allocation failure over and over even though it could
  just do it once right after the allocation.

Clean this up.

Signed-off-by: Douglas Anderson <dianders@chromium.org>
---

 .../gpu/drm/msm/disp/msm_disp_snapshot_util.c | 19 ++++++++-----------
 1 file changed, 8 insertions(+), 11 deletions(-)

diff --git a/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c b/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c
index 4d55e3cf570f..07a2c1e87219 100644
--- a/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c
+++ b/drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c
@@ -25,24 +25,21 @@ static void msm_disp_state_dump_regs(u32 **reg, u32 aligned_len, void __iomem *b
 	addr = base_addr;
 	end_addr = base_addr + aligned_len;
 
-	if (!(*reg))
-		*reg = kvzalloc(len_padded, GFP_KERNEL);
-
-	if (*reg)
-		dump_addr = *reg;
+	*reg = kvzalloc(len_padded, GFP_KERNEL);
+	if (!*reg)
+		return;
 
+	dump_addr = *reg;
 	for (i = 0; i < num_rows; i++) {
 		x0 = (addr < end_addr) ? readl_relaxed(addr + 0x0) : 0;
 		x4 = (addr + 0x4 < end_addr) ? readl_relaxed(addr + 0x4) : 0;
 		x8 = (addr + 0x8 < end_addr) ? readl_relaxed(addr + 0x8) : 0;
 		xc = (addr + 0xc < end_addr) ? readl_relaxed(addr + 0xc) : 0;
 
-		if (dump_addr) {
-			dump_addr[i * 4] = x0;
-			dump_addr[i * 4 + 1] = x4;
-			dump_addr[i * 4 + 2] = x8;
-			dump_addr[i * 4 + 3] = xc;
-		}
+		dump_addr[i * 4] = x0;
+		dump_addr[i * 4 + 1] = x4;
+		dump_addr[i * 4 + 2] = x8;
+		dump_addr[i * 4 + 3] = xc;
 
 		addr += REG_DUMP_ALIGN;
 	}
-- 
2.47.0.rc1.288.g06298d1525-goog


^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 1/3] drm/msm: Avoid NULL dereference in msm_disp_state_print_regs()
  2024-10-14 16:36 [PATCH 1/3] drm/msm: Avoid NULL dereference in msm_disp_state_print_regs() Douglas Anderson
  2024-10-14 16:36 ` [PATCH 2/3] drm/msm: Allocate memory for disp snapshot with kvzalloc() Douglas Anderson
  2024-10-14 16:36 ` [PATCH 3/3] drm/msm: Simplify NULL checking in msm_disp_state_dump_regs() Douglas Anderson
@ 2024-10-14 18:52 ` Abhinav Kumar
  2024-10-27  2:04 ` Dmitry Baryshkov
  3 siblings, 0 replies; 7+ messages in thread
From: Abhinav Kumar @ 2024-10-14 18:52 UTC (permalink / raw)
  To: Douglas Anderson, Rob Clark, Dmitry Baryshkov
  Cc: Stephen Boyd, David Airlie, Marijn Suijten, Sean Paul,
	Simona Vetter, dri-devel, freedreno, linux-arm-msm, linux-kernel



On 10/14/2024 9:36 AM, Douglas Anderson wrote:
> If the allocation in msm_disp_state_dump_regs() failed then
> `block->state` can be NULL. The msm_disp_state_print_regs() function
> _does_ have code to try to handle it with:
> 
>    if (*reg)
>      dump_addr = *reg;
> 
> ...but since "dump_addr" is initialized to NULL the above is actually
> a noop. The code then goes on to dereference `dump_addr`.
> 
> Make the function print "Registers not stored" when it sees a NULL to
> solve this. Since we're touching the code, fix
> msm_disp_state_print_regs() not to pointlessly take a double-pointer
> and properly mark the pointer as `const`.
> 
> Fixes: 98659487b845 ("drm/msm: add support to take dpu snapshot")
> Signed-off-by: Douglas Anderson <dianders@chromium.org>
> ---
> 
>   drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c | 15 ++++++++-------
>   1 file changed, 8 insertions(+), 7 deletions(-)
> 

LGTM, thanks for the fix

Reviewed-by: Abhinav Kumar <quic_abhinavk@quicinc.com>

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 2/3] drm/msm: Allocate memory for disp snapshot with kvzalloc()
  2024-10-14 16:36 ` [PATCH 2/3] drm/msm: Allocate memory for disp snapshot with kvzalloc() Douglas Anderson
@ 2024-10-14 18:56   ` Abhinav Kumar
  0 siblings, 0 replies; 7+ messages in thread
From: Abhinav Kumar @ 2024-10-14 18:56 UTC (permalink / raw)
  To: Douglas Anderson, Rob Clark, Dmitry Baryshkov
  Cc: Stephen Boyd, David Airlie, Marijn Suijten, Sean Paul,
	Simona Vetter, dri-devel, freedreno, linux-arm-msm, linux-kernel



On 10/14/2024 9:36 AM, Douglas Anderson wrote:
> With the "drm/msm: add a display mmu fault handler" series [1] we saw
> issues in the field where memory allocation was failing when
> allocating space for registers in msm_disp_state_dump_regs().
> Specifically we were seeing an order 5 allocation fail. It's not
> surprising that order 5 allocations will sometimes fail after the
> system has been up and running for a while.
> 
> There's no need here for contiguous memory. Change the allocation to
> kvzalloc() which should make it much less likely to fail.
> 
> [1] https://lore.kernel.org/r/20240628214848.4075651-1-quic_abhinavk@quicinc.com/
> 
> Fixes: 98659487b845 ("drm/msm: add support to take dpu snapshot")
> Signed-off-by: Douglas Anderson <dianders@chromium.org>
> ---
> 
>   drivers/gpu/drm/msm/disp/msm_disp_snapshot_util.c | 4 ++--
>   1 file changed, 2 insertions(+), 2 deletions(-)
> 

I had some doubts on how this issue happens considering that the devcore 
should automatically release the memory within 5 sec even if userspace 
had not read this. So there is no leak as such, its just that in a 
heavily loaded system, this can happen.

Fix looks okay to me,

Reviewed-by: Abhinav Kumar <quic_abhinavk@quicinc.com>

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 3/3] drm/msm: Simplify NULL checking in msm_disp_state_dump_regs()
  2024-10-14 16:36 ` [PATCH 3/3] drm/msm: Simplify NULL checking in msm_disp_state_dump_regs() Douglas Anderson
@ 2024-10-14 19:03   ` Abhinav Kumar
  0 siblings, 0 replies; 7+ messages in thread
From: Abhinav Kumar @ 2024-10-14 19:03 UTC (permalink / raw)
  To: Douglas Anderson, Rob Clark, Dmitry Baryshkov
  Cc: Stephen Boyd, David Airlie, Marijn Suijten, Sean Paul,
	Simona Vetter, dri-devel, freedreno, linux-arm-msm, linux-kernel



On 10/14/2024 9:36 AM, Douglas Anderson wrote:
> The msm_disp_state_dump_regs():
> 
> - Doesn't allocate if the caller already allocated. ...but there's one
>    caller and it doesn't allocate so we don't need this check.
> - Checks for allocation failure over and over even though it could
>    just do it once right after the allocation.
> 
> Clean this up.
> 
> Signed-off-by: Douglas Anderson <dianders@chromium.org>
> ---
> 
>   .../gpu/drm/msm/disp/msm_disp_snapshot_util.c | 19 ++++++++-----------
>   1 file changed, 8 insertions(+), 11 deletions(-)
> 

Reviewed-by: Abhinav Kumar <quic_abhinavk@quicinc.com>

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 1/3] drm/msm: Avoid NULL dereference in msm_disp_state_print_regs()
  2024-10-14 16:36 [PATCH 1/3] drm/msm: Avoid NULL dereference in msm_disp_state_print_regs() Douglas Anderson
                   ` (2 preceding siblings ...)
  2024-10-14 18:52 ` [PATCH 1/3] drm/msm: Avoid NULL dereference in msm_disp_state_print_regs() Abhinav Kumar
@ 2024-10-27  2:04 ` Dmitry Baryshkov
  3 siblings, 0 replies; 7+ messages in thread
From: Dmitry Baryshkov @ 2024-10-27  2:04 UTC (permalink / raw)
  To: Rob Clark, Abhinav Kumar, Douglas Anderson
  Cc: Stephen Boyd, David Airlie, Marijn Suijten, Sean Paul,
	Simona Vetter, dri-devel, freedreno, linux-arm-msm, linux-kernel


On Mon, 14 Oct 2024 09:36:08 -0700, Douglas Anderson wrote:
> If the allocation in msm_disp_state_dump_regs() failed then
> `block->state` can be NULL. The msm_disp_state_print_regs() function
> _does_ have code to try to handle it with:
> 
>   if (*reg)
>     dump_addr = *reg;
> 
> [...]

Applied, thanks!

[3/3] drm/msm: Simplify NULL checking in msm_disp_state_dump_regs()
      https://gitlab.freedesktop.org/lumag/msm/-/commit/74c374648ed0

Best regards,
-- 
Dmitry Baryshkov <dmitry.baryshkov@linaro.org>

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2024-10-27  2:04 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-10-14 16:36 [PATCH 1/3] drm/msm: Avoid NULL dereference in msm_disp_state_print_regs() Douglas Anderson
2024-10-14 16:36 ` [PATCH 2/3] drm/msm: Allocate memory for disp snapshot with kvzalloc() Douglas Anderson
2024-10-14 18:56   ` Abhinav Kumar
2024-10-14 16:36 ` [PATCH 3/3] drm/msm: Simplify NULL checking in msm_disp_state_dump_regs() Douglas Anderson
2024-10-14 19:03   ` Abhinav Kumar
2024-10-14 18:52 ` [PATCH 1/3] drm/msm: Avoid NULL dereference in msm_disp_state_print_regs() Abhinav Kumar
2024-10-27  2:04 ` Dmitry Baryshkov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®