Thread (58 messages) 58 messages, 9 authors, 7d ago

Re: [PATCH v3 08/19] drm/bridge: inno-hdmi: Allow the register map to come from a parent

From: sashiko-bot@kernel.org
Date: 2026-09-04 13:43:41
Also in: dri-devel, linux-clk, linux-phy

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Early HPD interrupt can cause a NULL pointer dereference of `hdmi->bridge.dev` if it fires before `drm_bridge_attach` completes.
--

commit 1a1229643b989df67626f64f580add186cebd6ed
Author: Michal Wilczynski [off-list ref]

drm/bridge: inno-hdmi: Allow the register map to come from a parent
    
On some SoCs the HDMI controller does not own its register window. The
StarFive JH7110 documents one 64 KB block, u0_hdmitx, that holds both
the controller and the PHY, so the parent device maps it and owns the
regmap while the two children share it.
quoted hunk ↗ jump to hunk
diff --git a/drivers/gpu/drm/bridge/inno-hdmi.c b/drivers/gpu/drm/bridge/inno-hdmi.c
index aab474740f7f5..8bd7717611804 100644
--- a/drivers/gpu/drm/bridge/inno-hdmi.c
+++ b/drivers/gpu/drm/bridge/inno-hdmi.c
[ ... ]
quoted hunk ↗ jump to hunk
@@ -1095,9 +1110,19 @@ struct inno_hdmi *inno_hdmi_probe(struct platform_device *pdev,
 	hdmi->dev = dev;
 	hdmi->plat_data = plat_data;
 
-	hdmi->regs = devm_platform_ioremap_resource(pdev, 0);
-	if (IS_ERR(hdmi->regs))
-		return ERR_CAST(hdmi->regs);
+	/*
+	 * On platforms where the controller shares a register space with
+	 * other blocks, the parent owns the regmap. Fall back to mapping
+	 * our own resource where it does not.
+	 */
+	if (dev->parent)
+		hdmi->regmap = dev_get_regmap(dev->parent, NULL);
+
+	if (!hdmi->regmap) {
+		hdmi->regs = devm_platform_ioremap_resource(pdev, 0);
+		if (IS_ERR(hdmi->regs))
+			return ERR_CAST(hdmi->regs);
+	}
 
 	hdmi->pclk = devm_clk_get_enabled(hdmi->dev, "pclk");
 	if (IS_ERR(hdmi->pclk)) {
[Severity: High]
This is a pre-existing issue, but could this code trigger a NULL pointer
dereference if the hotplug interrupt fires early?

Looking at the rest of inno_hdmi_probe(), the hardware interrupt is unmuted
in inno_hdmi_init_hw(), and then the handler is registered:

    inno_hdmi_init_hw(hdmi);
    ...
    ret = devm_request_threaded_irq(dev, irq, inno_hdmi_hardirq,
                                    inno_hdmi_irq, IRQF_SHARED,
                                    dev_name(dev), hdmi);

If a cable is already connected or plugged in at this exact moment, the
interrupt can fire immediately. The threaded handler inno_hdmi_irq() will
then execute:

    drm_helper_hpd_irq_event(hdmi->bridge.dev);

However, hdmi->bridge.dev appears to be NULL at this point, as it is only
populated later when the upstream display controller calls
drm_bridge_attach().

Is there something preventing this race condition, or should the IRQ handler
registration be deferred?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260904-jh7110-clean-send-v3-0-484f9ae72715@samsung.com?part=8
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help