Re: [PATCH] drm/mediatek: Check CRTC state before freeing

CK Hu (胡俊光) <[email protected]>
Newsgroups org.infradead.lists.linux-mediatek,org.freedesktop.lists.dri-devel,org.infradead.lists.linux-arm-kernel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Tue, 2026-07-07 at 23:05 +0800, Ruoyu Wang wrote:
> External email : Please do not click links or open attachments until you have verified the sender or the content.
> 
> 
> mtk_crtc_reset() destroys the current CRTC state only when crtc->state
> is non-NULL, but it always converts crtc->state to struct mtk_crtc_state
> and passes the result to kfree().
> 
> When reset is called without an existing state, container_of(NULL, ...)
> does not produce NULL. Keep the mtk state free in the same crtc->state
> guard as the helper state destruction.
> 
> This issue was found by a static analysis checker and confirmed by
> manual source review.

Reviewed-by: CK Hu <[email protected]>

> 
> Fixes: 2d267b81898e ("drm/mtk: Use __drm_atomic_helper_crtc_reset")
> Signed-off-by: Ruoyu Wang <[email protected]>
> ---
>  drivers/gpu/drm/mediatek/mtk_crtc.c | 6 +++---
>  1 file changed, 3 insertions(+), 3 deletions(-)
> 
> diff --git a/drivers/gpu/drm/mediatek/mtk_crtc.c b/drivers/gpu/drm/mediatek/mtk_crtc.c
> index 8e552cdc3b53b..97e3ff412e6ee 100644
> --- a/drivers/gpu/drm/mediatek/mtk_crtc.c
> +++ b/drivers/gpu/drm/mediatek/mtk_crtc.c
> @@ -154,10 +154,10 @@ static void mtk_crtc_reset(struct drm_crtc *crtc)
>  {
>         struct mtk_crtc_state *state;
> 
> -       if (crtc->state)
> +       if (crtc->state) {
>                 __drm_atomic_helper_crtc_destroy_state(crtc->state);
> -
> -       kfree(to_mtk_crtc_state(crtc->state));
> +               kfree(to_mtk_crtc_state(crtc->state));
> +       }
>         crtc->state = NULL;
> 
>         state = kzalloc_obj(*state);
> --
> 2.51.0
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.