Thread (25 messages) 25 messages, 5 authors, 2021-10-04

Re: [PATCH v5 02/15] drm/edid: Break out reading block 0 of the EDID

From: Doug Anderson <dianders@chromium.org>
Date: 2021-10-04 16:33:00
Also in: dri-devel, linux-arm-msm, linux-renesas-soc, lkml

Hi,

On Mon, Oct 4, 2021 at 8:42 AM Geert Uytterhoeven [off-list ref] wrote:
quoted
-       if ((edid = kmalloc(EDID_LENGTH, GFP_KERNEL)) == NULL)
+       edid = (u8 *)drm_do_get_edid_base_block(get_edid_block, data,
+                                               &connector->edid_corrupt,
+                                               &connector->null_edid_counter);
+       if (IS_ERR_OR_NULL(edid)) {
+               if (IS_ERR(edid))
So edid is an error code, not a valid pointer...
quoted
+                       connector_bad_edid(connector, edid, 1);
... while connector_bad_edid() expects edid to be a valid pointer,
causing a crash:

Unable to handle kernel NULL pointer dereference at virtual address
Sigh. Thanks for the report and analysis. I guess I don't have any
displays reporting invalid EDIDs to test with. Hopefully this will
help:

https://lore.kernel.org/r/20211004092100.1.Ic90a5ebd44c75db963112be167a03cc96f9fb249@changeid/ (local)

-Doug
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help