Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1394481

[PATCH 2/3] drm/fb_helper: Fix references to dev->mode_config.num_connector

From Lyude <cpaul@redhat.com>
Newsgroups linux.kernel
Subject [PATCH 2/3] drm/fb_helper: Fix references to dev->mode_config.num_connector
Date 2016-05-04 17:40 +0200
Message-ID <rv747-6DR-29@gated-at.bofh.it> (permalink)
References <rv746-6DR-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


During boot, MST hotplugs are generally expected (even if no physical
hotplugging occurs) and result in DRM's connector topology changing.
This means that using num_connector from the current mode configuration
can lead to the number of connectors changing under us. This can lead to
some nasty scenarios in fbcon:

- We allocate an array to the size of dev->mode_config.num_connectors.
- MST hotplug occurs, dev->mode_config.num_connectors gets incremented.
- We try to loop through each element in the array using the new value
  of dev->mode_config.num_connectors, and end up going out of bounds
  since dev->mode_config.num_connectors is now larger then the array we
  allocated.

fb_helper->connector_count however, will always remain consistent while
we do a modeset in fb_helper.

Cc: stable@vger.kernel.org
Signed-off-by: Lyude <cpaul@redhat.com>
---
 drivers/gpu/drm/drm_fb_helper.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/drm_fb_helper.c b/drivers/gpu/drm/drm_fb_helper.c
index 855108e..15204c0 100644
--- a/drivers/gpu/drm/drm_fb_helper.c
+++ b/drivers/gpu/drm/drm_fb_helper.c
@@ -1914,7 +1914,7 @@ static int drm_pick_crtcs(struct drm_fb_helper *fb_helper,
 	if (modes[n] == NULL)
 		return best_score;
 
-	crtcs = kzalloc(dev->mode_config.num_connector *
+	crtcs = kzalloc(fb_helper->connector_count *
 			sizeof(struct drm_fb_helper_crtc *), GFP_KERNEL);
 	if (!crtcs)
 		return best_score;
@@ -1960,7 +1960,7 @@ static int drm_pick_crtcs(struct drm_fb_helper *fb_helper,
 		if (score > best_score) {
 			best_score = score;
 			memcpy(best_crtcs, crtcs,
-			       dev->mode_config.num_connector *
+			       fb_helper->connector_count *
 			       sizeof(struct drm_fb_helper_crtc *));
 		}
 	}
-- 
2.5.5

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 1/3] drm/i915/fbdev: Fix num_connector references in intel_fb_initial_config() Lyude <cpaul@redhat.com> - 2016-05-04 17:40 +0200
  [PATCH 3/3] drm/fb_helper: Fix a few typos Lyude <cpaul@redhat.com> - 2016-05-04 17:40 +0200
    Re: [Intel-gfx] [PATCH 3/3] drm/fb_helper: Fix a few typos Daniel Vetter <daniel@ffwll.ch> - 2016-05-04 18:20 +0200
  [PATCH 2/3] drm/fb_helper: Fix references to dev->mode_config.num_connector Lyude <cpaul@redhat.com> - 2016-05-04 17:40 +0200
    Re: [PATCH 2/3] drm/fb_helper: Fix references to  dev->mode_config.num_connector Daniel Vetter <daniel@ffwll.ch> - 2016-05-04 19:20 +0200
      Re: [PATCH 2/3] drm/fb_helper: Fix references to  dev->mode_config.num_connector Lyude Paul <cpaul@redhat.com> - 2016-05-05 17:30 +0200
  Re: [PATCH 1/3] drm/i915/fbdev: Fix num_connector references in  intel_fb_initial_config() Daniel Vetter <daniel@ffwll.ch> - 2016-05-04 18:20 +0200

csiph-web