From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtpout-02.galae.net (smtpout-02.galae.net [185.246.84.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BC1A227732 for ; Sat, 24 Jan 2026 01:06:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=185.246.84.56 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769216776; cv=none; b=rBGpPCqNdXeFL+uAOE4IySakVUatmWnchms+kbIXW6EdbOdWRyWcYFk75WUQVElrsVwAUPY/5wHV8WSHyama9h4UX+y0tkYHE5CPJZC7VHeNH69FRv43gVRsc0n62b6hH5RByfuUzdG7CxfdrTEB+jgaB0nPqu+FhgnTrugjB6E= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769216776; c=relaxed/simple; bh=h8BpzeLfO4KSGGctA2H3pC1CWZspQ3HziKvo0ua/dDo=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=TUeWy+Ak+WIPmG21ju8fGQtgkm4PxqmHrCcgAVCOtNP1F9KfLDW051z94cr7V5vlouh6B7xqDNUV/iwrHW5YhQEg13u9RqHqGzU2FklvPcLgt3Vy1nhMfgBFroGfPvB6SNg0qqUw9nuAbXw3dE2fqm4bymg1yeIeO/YljLQL3Wk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bootlin.com; spf=pass smtp.mailfrom=bootlin.com; dkim=pass (2048-bit key) header.d=bootlin.com header.i=@bootlin.com header.b=F1bRYiy2; arc=none smtp.client-ip=185.246.84.56 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bootlin.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bootlin.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bootlin.com header.i=@bootlin.com header.b="F1bRYiy2" Received: from smtpout-01.galae.net (smtpout-01.galae.net [212.83.139.233]) by smtpout-02.galae.net (Postfix) with ESMTPS id 1C7281A2A41; Sat, 24 Jan 2026 01:06:11 +0000 (UTC) Received: from mail.galae.net (mail.galae.net [212.83.136.155]) by smtpout-01.galae.net (Postfix) with ESMTPS id C99A660760; Sat, 24 Jan 2026 01:06:10 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPSA id ACDB3119A836A; Sat, 24 Jan 2026 02:06:02 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bootlin.com; s=dkim; t=1769216769; h=from:subject:date:message-id:to:cc:mime-version:content-type: content-transfer-encoding:content-language:in-reply-to:references; bh=yVcNQe5CVuMwqB3e4Nejf9DQznk27DfMCyjqn6VJXgM=; b=F1bRYiy2zKp+8/TNzT2/DTi6JZ3DiKxxT0Ij8Ape7tNpSxgyHnPtc/bCYoZMC3tVNkSnbr 2grEbI8VLPlBOr/A2k6nl/1cY01vZkID45xhuekd4jxNn4PMkQkwMEwCfyD9905olOgyo5 lbN2xqdmZBzpkPlljrqM5n9fxdbTe04Wak9hI+wuHr3LzAcDRhQDFe+auoTZeaOo/BofzI EPwcTeVtf046pXT8SisnppJmwC95Ei3FkCtKz0lticllLWPgOtwZK5gXtEqn2mWSYSWH0o /gjWgVX6Oaml2wMnAK1L6LPDKaJX7fT2KrB2x6Uk3zGs6TUQeX4ignhHTcfPrw== Message-ID: Date: Sat, 24 Jan 2026 02:06:27 +0100 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v6 4/4] vkms: Pass the vkms connector as opposed to the device on hotplug To: Nicolas Frattaroli , =?UTF-8?B?VmlsbGUgU3lyasOkbMOk?= , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , Haneen Mohammed , Melissa Wen , Daniel Stone , Ian Forbes , Dmitry Baryshkov Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, kernel@collabora.com, Marius Vlad References: <20260123-hot-plug-passup-v6-0-aaaf61d960bb@collabora.com> <20260123-hot-plug-passup-v6-4-aaaf61d960bb@collabora.com> From: Louis Chauvet Content-Language: en-US In-Reply-To: <20260123-hot-plug-passup-v6-4-aaaf61d960bb@collabora.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Last-TLS-Session-Version: TLSv1.3 Hello Nicolas, On the principle I agree with this patch, I just need to take time to properly think about lifetime of vkms_config vs connector and pointer validity to avoid use-after-free / null pointer dereference. I will try to review it next week or more probably just after the FOSDEM. In the meantime, if you want to try / think about the possible issue: I think there will be a use-after-free if you unbind the driver using the sysfs interface and interract with configfs interface. Thanks a lot for this series, Louis Chauvet On 1/23/26 20:44, Nicolas Frattaroli wrote: > From: Marius Vlad > > By passing the connector rather than the device to > vkms_trigger_connector_hotplug, vkms can trigger connector hotplugging > events that contain the connector ID. > > Signed-off-by: Marius Vlad > Signed-off-by: Nicolas Frattaroli > --- > drivers/gpu/drm/vkms/vkms_configfs.c | 2 +- > drivers/gpu/drm/vkms/vkms_connector.c | 6 +++--- > drivers/gpu/drm/vkms/vkms_connector.h | 4 ++-- > 3 files changed, 6 insertions(+), 6 deletions(-) > > diff --git a/drivers/gpu/drm/vkms/vkms_configfs.c b/drivers/gpu/drm/vkms/vkms_configfs.c > index d6e203d59b45..63a27f671e6a 100644 > --- a/drivers/gpu/drm/vkms/vkms_configfs.c > +++ b/drivers/gpu/drm/vkms/vkms_configfs.c > @@ -554,7 +554,7 @@ static ssize_t connector_status_store(struct config_item *item, > vkms_config_connector_set_status(connector->config, status); > > if (connector->dev->enabled && old_status != status) > - vkms_trigger_connector_hotplug(connector->dev->config->dev); > + vkms_trigger_connector_hotplug(connector->config->connector); Here connector->config is valid, but connector->config->connector is probably invalid if the driver is unbind. We may need to add some refcount to avoid this kind of issue. The other way around, I think there could be issue if the configfs folder is completly removed (that possible, there is no way to forbid deletions in configfs), the config object is freed but maybe used in the "DRM" part of VKMS (for connector status update maybe). > } > > return (ssize_t)count; > diff --git a/drivers/gpu/drm/vkms/vkms_connector.c b/drivers/gpu/drm/vkms/vkms_connector.c > index b0a6b212d3f4..cad64eff72ea 100644 > --- a/drivers/gpu/drm/vkms/vkms_connector.c > +++ b/drivers/gpu/drm/vkms/vkms_connector.c > @@ -88,9 +88,9 @@ struct vkms_connector *vkms_connector_init(struct vkms_device *vkmsdev) > return connector; > } > > -void vkms_trigger_connector_hotplug(struct vkms_device *vkmsdev) > +void vkms_trigger_connector_hotplug(struct vkms_connector *vkms_connector) > { > - struct drm_device *dev = &vkmsdev->drm; > + struct drm_connector *connector = &vkms_connector->base; > > - drm_kms_helper_hotplug_event(dev); > + drm_kms_helper_connector_hotplug_event(connector); > } > diff --git a/drivers/gpu/drm/vkms/vkms_connector.h b/drivers/gpu/drm/vkms/vkms_connector.h > index ed312f4eff3a..7cd76d01b10b 100644 > --- a/drivers/gpu/drm/vkms/vkms_connector.h > +++ b/drivers/gpu/drm/vkms/vkms_connector.h > @@ -28,8 +28,8 @@ struct vkms_connector *vkms_connector_init(struct vkms_device *vkmsdev); > > /** > * vkms_trigger_connector_hotplug() - Update the device's connectors status > - * @vkmsdev: VKMS device to update > + * @vkms_connector: VKMS connector to update > */ > -void vkms_trigger_connector_hotplug(struct vkms_device *vkmsdev); > +void vkms_trigger_connector_hotplug(struct vkms_connector *vkms_connector); > > #endif /* _VKMS_CONNECTOR_H_ */ >