2023-10-26 21:26:38

by Yuran Pereira

[permalink] [raw]
Subject: [PATCH] drm/amdgpu: Fixes uninitialized variable usage in amdgpu_dm_setup_replay

Since `pr_config` is not initialized after its declaration, the
following operations with `replay_enable_option` may be performed
when `replay_enable_option` is holding junk values which could
possibly lead to undefined behaviour

```
...
pr_config.replay_enable_option |= pr_enable_option_static_screen;
...

if (!pr_config.replay_timing_sync_supported)
pr_config.replay_enable_option &= ~pr_enable_option_general_ui;
...
```

This patch initializes `pr_config` after its declaration to ensure that
it doesn't contain junk data, and prevent any undefined behaviour

Addresses-Coverity-ID: 1544428 ("Uninitialized scalar variable")
Fixes: dede1fea4460 ("drm/amd/display: Add Freesync Panel DM code")
Signed-off-by: Yuran Pereira <[email protected]>
---
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c | 3 +++
1 file changed, 3 insertions(+)

diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
index 32d3086c4cb7..40526507f50b 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
@@ -23,6 +23,7 @@
*
*/

+#include <linux/string.h>
#include "amdgpu_dm_replay.h"
#include "dc.h"
#include "dm_helpers.h"
@@ -74,6 +75,8 @@ bool amdgpu_dm_setup_replay(struct dc_link *link, struct amdgpu_dm_connector *ac
struct replay_config pr_config;
union replay_debug_flags *debug_flags = NULL;

+ memset(&pr_config, 0, sizeof(pr_config));
+
// For eDP, if Replay is supported, return true to skip checks
if (link->replay_settings.config.replay_supported)
return true;
--
2.25.1


2023-10-27 15:53:35

by Hamza Mahfooz

[permalink] [raw]
Subject: Re: [PATCH] drm/amdgpu: Fixes uninitialized variable usage in amdgpu_dm_setup_replay

On 10/26/23 17:25, Yuran Pereira wrote:
> Since `pr_config` is not initialized after its declaration, the
> following operations with `replay_enable_option` may be performed
> when `replay_enable_option` is holding junk values which could
> possibly lead to undefined behaviour
>
> ```
> ...
> pr_config.replay_enable_option |= pr_enable_option_static_screen;
> ...
>
> if (!pr_config.replay_timing_sync_supported)
> pr_config.replay_enable_option &= ~pr_enable_option_general_ui;
> ...
> ```
>
> This patch initializes `pr_config` after its declaration to ensure that
> it doesn't contain junk data, and prevent any undefined behaviour
>
> Addresses-Coverity-ID: 1544428 ("Uninitialized scalar variable")
> Fixes: dede1fea4460 ("drm/amd/display: Add Freesync Panel DM code")
> Signed-off-by: Yuran Pereira <[email protected]>
> ---
> drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
> index 32d3086c4cb7..40526507f50b 100644
> --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
> +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
> @@ -23,6 +23,7 @@
> *
> */
>
> +#include <linux/string.h>
> #include "amdgpu_dm_replay.h"
> #include "dc.h"
> #include "dm_helpers.h"
> @@ -74,6 +75,8 @@ bool amdgpu_dm_setup_replay(struct dc_link *link, struct amdgpu_dm_connector *ac
> struct replay_config pr_config;

I would prefer setting pr_config = {0};

> union replay_debug_flags *debug_flags = NULL;
>
> + memset(&pr_config, 0, sizeof(pr_config));
> +
> // For eDP, if Replay is supported, return true to skip checks
> if (link->replay_settings.config.replay_supported)
> return true;
--
Hamza

2023-10-27 15:54:14

by Hamza Mahfooz

[permalink] [raw]
Subject: Re: [PATCH] drm/amdgpu: Fixes uninitialized variable usage in amdgpu_dm_setup_replay

Also, please write the tagline in present tense.
On 10/27/23 11:53, Hamza Mahfooz wrote:
> On 10/26/23 17:25, Yuran Pereira wrote:
>> Since `pr_config` is not initialized after its declaration, the
>> following operations with `replay_enable_option` may be performed
>> when `replay_enable_option` is holding junk values which could
>> possibly lead to undefined behaviour
>>
>> ```
>>      ...
>>      pr_config.replay_enable_option |= pr_enable_option_static_screen;
>>      ...
>>
>>      if (!pr_config.replay_timing_sync_supported)
>>          pr_config.replay_enable_option &= ~pr_enable_option_general_ui;
>>      ...
>> ```
>>
>> This patch initializes `pr_config` after its declaration to ensure that
>> it doesn't contain junk data, and prevent any undefined behaviour
>>
>> Addresses-Coverity-ID: 1544428 ("Uninitialized scalar variable")
>> Fixes: dede1fea4460 ("drm/amd/display: Add Freesync Panel DM code")
>> Signed-off-by: Yuran Pereira <[email protected]>
>> ---
>>   drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c | 3 +++
>>   1 file changed, 3 insertions(+)
>>
>> diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
>> b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
>> index 32d3086c4cb7..40526507f50b 100644
>> --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
>> +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
>> @@ -23,6 +23,7 @@
>>    *
>>    */
>> +#include <linux/string.h>
>>   #include "amdgpu_dm_replay.h"
>>   #include "dc.h"
>>   #include "dm_helpers.h"
>> @@ -74,6 +75,8 @@ bool amdgpu_dm_setup_replay(struct dc_link *link,
>> struct amdgpu_dm_connector *ac
>>       struct replay_config pr_config;
>
> I would prefer setting pr_config = {0};
>
>>       union replay_debug_flags *debug_flags = NULL;
>> +    memset(&pr_config, 0, sizeof(pr_config));
>> +
>>       // For eDP, if Replay is supported, return true to skip checks
>>       if (link->replay_settings.config.replay_supported)
>>           return true;
--
Hamza

2023-10-27 15:58:05

by Hamza Mahfooz

[permalink] [raw]
Subject: Re: [PATCH] drm/amdgpu: Fixes uninitialized variable usage in amdgpu_dm_setup_replay

On 10/27/23 11:55, Lakha, Bhawanpreet wrote:
> [AMD Official Use Only - General]
>
>
>
> There was a consensus to use memset instead of {0}. I remember making
> changes related to that previously.

Hm, seems like it's used rather consistently in the DM and in DC
though.

>
> Bhawan
>
> ------------------------------------------------------------------------
> *From:* Mahfooz, Hamza <[email protected]>
> *Sent:* October 27, 2023 11:53 AM
> *To:* Yuran Pereira <[email protected]>; [email protected]
> <[email protected]>
> *Cc:* Li, Sun peng (Leo) <[email protected]>; Lakha, Bhawanpreet
> <[email protected]>; Pan, Xinhui <[email protected]>; Siqueira,
> Rodrigo <[email protected]>; [email protected]
> <[email protected]>; [email protected]
> <[email protected]>; [email protected]
> <[email protected]>; Deucher, Alexander
> <[email protected]>; Koenig, Christian
> <[email protected]>;
> [email protected]
> <[email protected]>
> *Subject:* Re: [PATCH] drm/amdgpu: Fixes uninitialized variable usage in
> amdgpu_dm_setup_replay
> On 10/26/23 17:25, Yuran Pereira wrote:
>> Since `pr_config` is not initialized after its declaration, the
>> following operations with `replay_enable_option` may be performed
>> when `replay_enable_option` is holding junk values which could
>> possibly lead to undefined behaviour
>>
>> ```
>>      ...
>>      pr_config.replay_enable_option |= pr_enable_option_static_screen;
>>      ...
>>
>>      if (!pr_config.replay_timing_sync_supported)
>>          pr_config.replay_enable_option &= ~pr_enable_option_general_ui;
>>      ...
>> ```
>>
>> This patch initializes `pr_config` after its declaration to ensure that
>> it doesn't contain junk data, and prevent any undefined behaviour
>>
>> Addresses-Coverity-ID: 1544428 ("Uninitialized scalar variable")
>> Fixes: dede1fea4460 ("drm/amd/display: Add Freesync Panel DM code")
>> Signed-off-by: Yuran Pereira <[email protected]>
>> ---
>>   drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c | 3 +++
>>   1 file changed, 3 insertions(+)
>>
>> diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
>> index 32d3086c4cb7..40526507f50b 100644
>> --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
>> +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
>> @@ -23,6 +23,7 @@
>>    *
>>    */
>>
>> +#include <linux/string.h>
>>   #include "amdgpu_dm_replay.h"
>>   #include "dc.h"
>>   #include "dm_helpers.h"
>> @@ -74,6 +75,8 @@ bool amdgpu_dm_setup_replay(struct dc_link *link, struct amdgpu_dm_connector *ac
>>        struct replay_config pr_config;
>
> I would prefer setting pr_config = {0};
>
>>        union replay_debug_flags *debug_flags = NULL;
>>
>> +     memset(&pr_config, 0, sizeof(pr_config));
>> +
>>        // For eDP, if Replay is supported, return true to skip checks
>>        if (link->replay_settings.config.replay_supported)
>>                return true;
> --
> Hamza
>
--
Hamza

2023-10-28 00:48:35

by Yuran Pereira

[permalink] [raw]
Subject: Re: [PATCH] drm/amdgpu: Fixes uninitialized variable usage in amdgpu_dm_setup_replay

Hello,
On Fri, Oct 27, 2023 at 11:57:45AM -0400, Hamza Mahfooz wrote:
> On 10/27/23 11:55, Lakha, Bhawanpreet wrote:
> > [AMD Official Use Only - General]
> >
> >
> >
> > There was a consensus to use memset instead of {0}. I remember making
> > changes related to that previously.
>
> Hm, seems like it's used rather consistently in the DM and in DC
> though.
>
Have you decided which one should be used?

Should I submit a v2 patch using {0} instead of memset?


Yuran Pereira
> >
> > Bhawan
> >
> > ------------------------------------------------------------------------
> > *From:* Mahfooz, Hamza <[email protected]>
> > *Sent:* October 27, 2023 11:53 AM
> > *To:* Yuran Pereira <[email protected]>; [email protected]
> > <[email protected]>
> > *Cc:* Li, Sun peng (Leo) <[email protected]>; Lakha, Bhawanpreet
> > <[email protected]>; Pan, Xinhui <[email protected]>; Siqueira,
> > Rodrigo <[email protected]>; [email protected]
> > <[email protected]>; [email protected]
> > <[email protected]>; [email protected]
> > <[email protected]>; Deucher, Alexander
> > <[email protected]>; Koenig, Christian
> > <[email protected]>;
> > [email protected]
> > <[email protected]>
> > *Subject:* Re: [PATCH] drm/amdgpu: Fixes uninitialized variable usage in
> > amdgpu_dm_setup_replay
> > On 10/26/23 17:25, Yuran Pereira wrote:
> > > Since `pr_config` is not initialized after its declaration, the
> > > following operations with `replay_enable_option` may be performed
> > > when `replay_enable_option` is holding junk values which could
> > > possibly lead to undefined behaviour
> > >
> > > ```
> > > ????? ...
> > > ????? pr_config.replay_enable_option |= pr_enable_option_static_screen;
> > > ????? ...
> > >
> > > ????? if (!pr_config.replay_timing_sync_supported)
> > > ????????? pr_config.replay_enable_option &= ~pr_enable_option_general_ui;
> > > ????? ...
> > > ```
> > >
> > > This patch initializes `pr_config` after its declaration to ensure that
> > > it doesn't contain junk data, and prevent any undefined behaviour
> > >
> > > Addresses-Coverity-ID: 1544428 ("Uninitialized scalar variable")
> > > Fixes: dede1fea4460 ("drm/amd/display: Add Freesync Panel DM code")
> > > Signed-off-by: Yuran Pereira <[email protected]>
> > > ---
> > > ?? drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c | 3 +++
> > > ?? 1 file changed, 3 insertions(+)
> > >
> > > diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
> > > index 32d3086c4cb7..40526507f50b 100644
> > > --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
> > > +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
> > > @@ -23,6 +23,7 @@
> > > ??? *
> > > ??? */
> > > +#include <linux/string.h>
> > > ?? #include "amdgpu_dm_replay.h"
> > > ?? #include "dc.h"
> > > ?? #include "dm_helpers.h"
> > > @@ -74,6 +75,8 @@ bool amdgpu_dm_setup_replay(struct dc_link *link, struct amdgpu_dm_connector *ac
> > > ??????? struct replay_config pr_config;
> >
> > I would prefer setting pr_config = {0};
> >
> > > ??????? union replay_debug_flags *debug_flags = NULL;
> > > +???? memset(&pr_config, 0, sizeof(pr_config));
> > > +
> > > ??????? // For eDP, if Replay is supported, return true to skip checks
> > > ??????? if (link->replay_settings.config.replay_supported)
> > > ??????????????? return true;
> > --
> > Hamza
> >
> --
> Hamza
>

2023-10-30 15:52:42

by Christian König

[permalink] [raw]
Subject: Re: [PATCH] drm/amdgpu: Fixes uninitialized variable usage in amdgpu_dm_setup_replay

Am 28.10.23 um 02:48 schrieb Yuran Pereira:
> Hello,
> On Fri, Oct 27, 2023 at 11:57:45AM -0400, Hamza Mahfooz wrote:
>> On 10/27/23 11:55, Lakha, Bhawanpreet wrote:
>>> [AMD Official Use Only - General]
>>>
>>>
>>>
>>> There was a consensus to use memset instead of {0}. I remember making
>>> changes related to that previously.
>> Hm, seems like it's used rather consistently in the DM and in DC
>> though.
>>
> Have you decided which one should be used?
>
> Should I submit a v2 patch using {0} instead of memset?

The problem is that {0} doesn't initialize padding fields in structures.

So what can happen are problems like leaking bytes to userspace or
getting unstable hash keys etc...

So I think memset() is usually preferred and that not only counts for Linux.

Regards,
Christian.

>
>
> Yuran Pereira
>>> Bhawan
>>>
>>> ------------------------------------------------------------------------
>>> *From:* Mahfooz, Hamza <[email protected]>
>>> *Sent:* October 27, 2023 11:53 AM
>>> *To:* Yuran Pereira <[email protected]>; [email protected]
>>> <[email protected]>
>>> *Cc:* Li, Sun peng (Leo) <[email protected]>; Lakha, Bhawanpreet
>>> <[email protected]>; Pan, Xinhui <[email protected]>; Siqueira,
>>> Rodrigo <[email protected]>; [email protected]
>>> <[email protected]>; [email protected]
>>> <[email protected]>; [email protected]
>>> <[email protected]>; Deucher, Alexander
>>> <[email protected]>; Koenig, Christian
>>> <[email protected]>;
>>> [email protected]
>>> <[email protected]>
>>> *Subject:* Re: [PATCH] drm/amdgpu: Fixes uninitialized variable usage in
>>> amdgpu_dm_setup_replay
>>> On 10/26/23 17:25, Yuran Pereira wrote:
>>>> Since `pr_config` is not initialized after its declaration, the
>>>> following operations with `replay_enable_option` may be performed
>>>> when `replay_enable_option` is holding junk values which could
>>>> possibly lead to undefined behaviour
>>>>
>>>> ```
>>>>       ...
>>>>       pr_config.replay_enable_option |= pr_enable_option_static_screen;
>>>>       ...
>>>>
>>>>       if (!pr_config.replay_timing_sync_supported)
>>>>           pr_config.replay_enable_option &= ~pr_enable_option_general_ui;
>>>>       ...
>>>> ```
>>>>
>>>> This patch initializes `pr_config` after its declaration to ensure that
>>>> it doesn't contain junk data, and prevent any undefined behaviour
>>>>
>>>> Addresses-Coverity-ID: 1544428 ("Uninitialized scalar variable")
>>>> Fixes: dede1fea4460 ("drm/amd/display: Add Freesync Panel DM code")
>>>> Signed-off-by: Yuran Pereira <[email protected]>
>>>> ---
>>>>    drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c | 3 +++
>>>>    1 file changed, 3 insertions(+)
>>>>
>>>> diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
>>>> index 32d3086c4cb7..40526507f50b 100644
>>>> --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
>>>> +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_replay.c
>>>> @@ -23,6 +23,7 @@
>>>>     *
>>>>     */
>>>> +#include <linux/string.h>
>>>>    #include "amdgpu_dm_replay.h"
>>>>    #include "dc.h"
>>>>    #include "dm_helpers.h"
>>>> @@ -74,6 +75,8 @@ bool amdgpu_dm_setup_replay(struct dc_link *link, struct amdgpu_dm_connector *ac
>>>>         struct replay_config pr_config;
>>> I would prefer setting pr_config = {0};
>>>
>>>>         union replay_debug_flags *debug_flags = NULL;
>>>> +     memset(&pr_config, 0, sizeof(pr_config));
>>>> +
>>>>         // For eDP, if Replay is supported, return true to skip checks
>>>>         if (link->replay_settings.config.replay_supported)
>>>>                 return true;
>>> --
>>> Hamza
>>>
>> --
>> Hamza
>>