From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DC30338F25F for ; Thu, 20 Aug 2026 18:28:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787250531; cv=none; b=UyxdPcy5RrH01kSgaEdAryMXke4W2GCHCBv++qeoSqGka+s0vayVxaKwmOc61XA0hFhC+rwxXjiCoGrlG6SYLQPzj5k4aYYbeVZ+Gopr1Md4HcRb/EcpaAVDKh1g6A0V0L1Q98ZbQNHDbxzlyGxIX/ZJvZSifdnKTHd4/pHtVwA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787250531; c=relaxed/simple; bh=qtp5zr26lSBr8BeTaJn9m/Rq/Fqd+g6NRwKkEbu0jcE=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=L+2Vdc/oU2M7D9n8IQQ7ODO84avF2U73V8yxXZvqOPBng3KJz68+Esc3FJmRQunhnQKP63M3VL54TB6D8Hh9RQGSBV4wrofcnbWrVD7LYuVs9Ijfg3HAK7nJKCcOBLSA9WCQBlc+OdsDcY9ATioOga3Mj76IBfONfXD0beCtp20= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=VRfCv1ft; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=dvj6Al5a; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="VRfCv1ft"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="dvj6Al5a" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787250528; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=fvFKAPRcQcLsGMFTo6jCZYlK8au7/chi2AjGH/KyknY=; b=VRfCv1ftWBU3MgKMhRXJ8HhGlvjXLckiecxgYlXPZvxt9M36rdCnUQxA9Iolin8kpCkQFs 84faOlOlez5j/CBBT61Vi8eLCOsIO8/Fnt7aFgmL5r0imf4Jvg1DeFtcnBTz/33Y9LfCFE 729iZRf4lQuQ+owgvmyupN/QAYLjxEg= Received: from mail-qt1-f197.google.com (mail-qt1-f197.google.com [209.85.160.197]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-250-IsQnRP_KNdiIV5NXUIoj4A-1; Thu, 20 Aug 2026 14:28:37 -0400 X-MC-Unique: IsQnRP_KNdiIV5NXUIoj4A-1 X-Mimecast-MFC-AGG-ID: IsQnRP_KNdiIV5NXUIoj4A_1787250517 Received: by mail-qt1-f197.google.com with SMTP id d75a77b69052e-52d827597fbso1607811cf.0 for ; Thu, 20 Aug 2026 11:28:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1787250517; x=1787855317; darn=vger.kernel.org; h=mime-version:user-agent:content-transfer-encoding:content-type :references:in-reply-to:date:cc:to:from:subject:message-id:from:to :cc:subject:date:message-id:reply-to:content-type; bh=fvFKAPRcQcLsGMFTo6jCZYlK8au7/chi2AjGH/KyknY=; b=dvj6Al5aLNztDyJQIoBJbZMCVngPAifrnObkAvXj8/tlpCAQlQ9WpnZL5NAloDRSNB Wnz8Zl4ubNRb7sqTpiaOC+wBmI9cvquQ4OJXZ/PUfZD/eCJaHE4EDFwLjXkqTzlRNmsQ By9G6i7soFM85eC4CD/eHv8cFqySeaVeowwipNLZezM2BqTJxaJ4D+lcJOEcQ3sd5fZq 00Fz/BF5WSiU8tTv/IkhGzTTsEEEtGvLPRKBr1moQd4vsr986AXXDzd4ZxIIqQdv4kcc gw48S2yRj6bK78lGzIgI16heMa0elD76ybjyQF+0osWa/1kphS86rbUIOcz8R/bja0WC oo+A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787250517; x=1787855317; h=mime-version:user-agent:content-transfer-encoding:content-type :references:in-reply-to:date:cc:to:from:subject:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=fvFKAPRcQcLsGMFTo6jCZYlK8au7/chi2AjGH/KyknY=; b=Ok17R9A7aX3M9LTGyk55gZuRtH/qw4c+X2aJDVyAXFQ18cNGpc9z4YaAVJljPwjj4x omoWPyVaaYC5KPr3poV6Fuwo4TjbI42SmH4oScQdB5Qj22FdkdaslGV3/uHXyo0EgWFy d/EkTHcJK27G3pY2whTILowWW6r7nkSV7DRaZOp6PNu6vWLZ7ODmXMkkaCIND/mGXMdb x8IcliIzIbxQ/Oof+2XSBP27QPOcL4VM1lvyQ/K506SEUGYFEUZMJo0k/ReXD3A24rxt IDW7m66lmK5NrtBT9O/uqIdfof417feokV0CqiOGtyDtARskYGoYPoDMNT67Eae+z4OZ SAaA== X-Gm-Message-State: AOJu0YyPPC5jP0r251RzCASo8kQ/0kaWZoMmXcarl3rszi/AFsE3XHmp TsdFxUh43eSuCb+Q3t9wiWHtBDCK2+IZwfMLqyRLMOUaxJ+C9EmKn6Yx/EjYWCdkGI7awC812dx 6a83UuytZW38N4v/7KGU7WECVupRiPygmhAtNqMt9GUIHAj92eC13i/5gHUiOppNzqA== X-Gm-Gg: AR+sD12B+K8chFIDbgDdPkx2K+H6ta4zvGLwaL2rtA/7HUhkjuEGB7XZ/ZzxUbC12hL gOugdH6njGmxjnohvCj3xjeQPw820Y8LGgmpTzIN4X2H5HRUy6+034yDHJyV8SXlHcAasjWWdID gF5DogTdCmLvcrMPvGouWAUYK4PmzriFJ8pWmvPS0vp9TiBJhjpFyQ4aLEDfH+LOWZoBFQElD9R T4vRyuSDqCR8VJPbz4f2AHFDuO9mYa8Ivi9dtiIBATM0d5ZMJTScp0Z2KxEmuHLD/DPNPufsDPn K6eufZ0T8M0ayCo8Trya3EL1PVQFYPMgrbELvRvc8cf0gX5KBsLd7wUQKO7JZWOZbWF3Ccs9 X-Received: by 2002:ac8:5e06:0:b0:52d:4f43:d5b0 with SMTP id d75a77b69052e-52df5a07b41mr2811061cf.22.1787250516734; Thu, 20 Aug 2026 11:28:36 -0700 (PDT) X-Received: by 2002:ac8:5e06:0:b0:52d:4f43:d5b0 with SMTP id d75a77b69052e-52df5a07b41mr2810391cf.22.1787250515984; Thu, 20 Aug 2026 11:28:35 -0700 (PDT) Received: from [192.168.8.4] ([100.0.180.93]) by smtp.gmail.com with ESMTPSA id af79cd13be357-9372056b781sm421572785a.24.2026.08.20.11.28.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 11:28:34 -0700 (PDT) Message-ID: Subject: Re: [PATCH 3/3] drm/nouveau: don't dereference outp before checking it in nouveau_dp_irq From: lyude@redhat.com To: Marek Czernohous , nouveau@lists.freedesktop.org, dri-devel@lists.freedesktop.org Cc: linux-kernel@vger.kernel.org, Danilo Krummrich , David Airlie , Simona Vetter Date: Thu, 20 Aug 2026 14:28:33 -0400 In-Reply-To: <178682366004.3748010.14933649768375463967@gmail.com> References: <178682366001.3748010.7798811159846779765@gmail.com> <178682366004.3748010.14933649768375463967@gmail.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.58.3 (3.58.3-1.fc43) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reviewed-by: Lyude Paul On Sat, 2026-08-15 at 21:54 +0200, Marek Czernohous wrote: > From: Marek Czernohous >=20 > nouveau_dp_irq() looks the encoder up and dereferences it in the same > breath, five lines before testing it: >=20 > struct nouveau_encoder *outp =3D find_encoder(connector, > DCB_OUTPUT_DP); > struct nouveau_drm *drm =3D nouveau_drm(outp->base.base.dev); > ... > if (!outp) > return; >=20 > find_encoder() walks the connector's possible encoders and returns > NULL > when none of them matches the requested type, so the NULL test is not > decoration: it is the author saying this can happen. The initialiser > above it dereferences the same pointer regardless. >=20 > The NULL test predates the dereference. commit 773eb04d14a1 > ("drm/nouveau/disp: expose conn event class") turned nouveau_dp_irq() > into a work callback, and since the drm pointer was no longer passed > in > as an argument it was recovered from the encoder in the declaration > block, which put the dereference above the existing test. >=20 > Move the drm lookup below the test. No functional change when outp is > non-NULL. >=20 > Fixes: 773eb04d14a1 ("drm/nouveau/disp: expose conn event class") > Cc: stable@vger.kernel.org > Assisted-by: Claude:claude-opus-5 > Signed-off-by: Marek Czernohous > --- > =C2=A0drivers/gpu/drm/nouveau/nouveau_dp.c | 4 +++- > =C2=A01 file changed, 3 insertions(+), 1 deletion(-) >=20 > diff --git a/drivers/gpu/drm/nouveau/nouveau_dp.c > b/drivers/gpu/drm/nouveau/nouveau_dp.c > index 55691ec44aba..738802358d85 100644 > --- a/drivers/gpu/drm/nouveau/nouveau_dp.c > +++ b/drivers/gpu/drm/nouveau/nouveau_dp.c > @@ -486,7 +486,7 @@ nouveau_dp_irq(struct work_struct *work) > =C2=A0 container_of(work, typeof(*nv_connector), irq_work); > =C2=A0 struct drm_connector *connector =3D &nv_connector->base; > =C2=A0 struct nouveau_encoder *outp =3D find_encoder(connector, > DCB_OUTPUT_DP); > - struct nouveau_drm *drm =3D nouveau_drm(outp->base.base.dev); > + struct nouveau_drm *drm; > =C2=A0 struct nv50_mstm *mstm; > =C2=A0 u64 hpd =3D 0; > =C2=A0 int ret; > @@ -494,6 +494,8 @@ nouveau_dp_irq(struct work_struct *work) > =C2=A0 if (!outp) > =C2=A0 return; > =C2=A0 > + drm =3D nouveau_drm(outp->base.base.dev); > + > =C2=A0 mstm =3D outp->dp.mstm; > =C2=A0 NV_DEBUG(drm, "service %s\n", connector->name); > =C2=A0