Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1394481

[PATCH 2/3] drm/fb_helper: Fix references to dev->mode_config.num_connector

Path csiph.com!news.mixmin.net!aioe.org!gothmog.csi.it!bofh.it!news.nic.it!robomod
From Lyude <cpaul@redhat.com>
Newsgroups linux.kernel
Subject [PATCH 2/3] drm/fb_helper: Fix references to dev->mode_config.num_connector
Date Wed, 04 May 2016 17:40:03 +0200
Message-ID <rv747-6DR-29@gated-at.bofh.it> (permalink)
References <rv746-6DR-7@gated-at.bofh.it>
X-Scanned-By MIMEDefang 2.68 on 10.5.11.26
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 46
Organization linux.* mail to news gateway
X-Original-Cc Lyude <cpaul@redhat.com>, stable@vger.kernel.org, David Airlie <airlied@linux.ie>, linux-kernel@vger.kernel.org (open list)
X-Original-Date Wed, 4 May 2016 11:28:52 -0400
X-Original-Message-ID <1462375734-8213-2-git-send-email-cpaul@redhat.com>
X-Original-References <1462375734-8213-1-git-send-email-cpaul@redhat.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1394481

Show key headers only | View raw


During boot, MST hotplugs are generally expected (even if no physical
hotplugging occurs) and result in DRM's connector topology changing.
This means that using num_connector from the current mode configuration
can lead to the number of connectors changing under us. This can lead to
some nasty scenarios in fbcon:

- We allocate an array to the size of dev->mode_config.num_connectors.
- MST hotplug occurs, dev->mode_config.num_connectors gets incremented.
- We try to loop through each element in the array using the new value
  of dev->mode_config.num_connectors, and end up going out of bounds
  since dev->mode_config.num_connectors is now larger then the array we
  allocated.

fb_helper->connector_count however, will always remain consistent while
we do a modeset in fb_helper.

Cc: stable@vger.kernel.org
Signed-off-by: Lyude <cpaul@redhat.com>
---
 drivers/gpu/drm/drm_fb_helper.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/drm_fb_helper.c b/drivers/gpu/drm/drm_fb_helper.c
index 855108e..15204c0 100644
--- a/drivers/gpu/drm/drm_fb_helper.c
+++ b/drivers/gpu/drm/drm_fb_helper.c
@@ -1914,7 +1914,7 @@ static int drm_pick_crtcs(struct drm_fb_helper *fb_helper,
 	if (modes[n] == NULL)
 		return best_score;
 
-	crtcs = kzalloc(dev->mode_config.num_connector *
+	crtcs = kzalloc(fb_helper->connector_count *
 			sizeof(struct drm_fb_helper_crtc *), GFP_KERNEL);
 	if (!crtcs)
 		return best_score;
@@ -1960,7 +1960,7 @@ static int drm_pick_crtcs(struct drm_fb_helper *fb_helper,
 		if (score > best_score) {
 			best_score = score;
 			memcpy(best_crtcs, crtcs,
-			       dev->mode_config.num_connector *
+			       fb_helper->connector_count *
 			       sizeof(struct drm_fb_helper_crtc *));
 		}
 	}
-- 
2.5.5

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 1/3] drm/i915/fbdev: Fix num_connector references in intel_fb_initial_config() Lyude <cpaul@redhat.com> - 2016-05-04 17:40 +0200
  [PATCH 3/3] drm/fb_helper: Fix a few typos Lyude <cpaul@redhat.com> - 2016-05-04 17:40 +0200
    Re: [Intel-gfx] [PATCH 3/3] drm/fb_helper: Fix a few typos Daniel Vetter <daniel@ffwll.ch> - 2016-05-04 18:20 +0200
  [PATCH 2/3] drm/fb_helper: Fix references to dev->mode_config.num_connector Lyude <cpaul@redhat.com> - 2016-05-04 17:40 +0200
    Re: [PATCH 2/3] drm/fb_helper: Fix references to  dev->mode_config.num_connector Daniel Vetter <daniel@ffwll.ch> - 2016-05-04 19:20 +0200
      Re: [PATCH 2/3] drm/fb_helper: Fix references to  dev->mode_config.num_connector Lyude Paul <cpaul@redhat.com> - 2016-05-05 17:30 +0200
  Re: [PATCH 1/3] drm/i915/fbdev: Fix num_connector references in  intel_fb_initial_config() Daniel Vetter <daniel@ffwll.ch> - 2016-05-04 18:20 +0200

csiph-web