Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [High] drm/panthor: UAF in arbitration IRQ handlers due to devres ordering
--

commit 35b5829f1e7e37f44df0de386a8d626358959c51
Author: Karunika Choo <[email protected]>

drm/panthor: Route arbitration events

This commit wires the resource-group, scheduler, and partition-control blocks
together. It routes resource-group messages and partition reset events to the
scheduler, and adds callbacks for granting, yielding, and closing partition
windows.

> diff --git a/drivers/gpu/drm/panthor/arbitration/panthor_arbitration_drv.c 
> b/drivers/gpu/drm/panthor/arbitration/panthor_arbitration_drv.c
> index 2d0c8d95f1abd..723cf605e16a3 100644
> --- a/drivers/gpu/drm/panthor/arbitration/panthor_arbitration_drv.c
> +++ b/drivers/gpu/drm/panthor/arbitration/panthor_arbitration_drv.c
> @@ -95,20 +95,42 @@ static int panthor_arbitration_runtime_resume(struct 
> device *dev)
>       return 0;
>  }
>  
> +/* AW to Arbiter events */
> +int panthor_arbitration_on_request(struct panthor_arbitration *adev, u8 
> aw_id)
> +{
> +     /* TODO: AW to PC assignment */
> +     return panthor_arbitration_sched_on_request(adev->sched[0], aw_id);
> +}

[Severity: High]
Does this introduce a use-after-free risk during driver teardown if a
pending interrupt fires?

In panthor_arbitration_probe(), the driver registers rg_irq_raw_handler and 
partition_irq_raw_handler using devm_request_irq() inside 
panthor_resource_group_init() before the sched structures are allocated using
devm_kzalloc() in panthor_arbitration_sched_init().

Because devres releases resources in LIFO order on probe failure or driver 
removal, the scheduler memory is freed before the IRQs are unregistered. 

If an interrupt fires or is pending during this teardown window, the active 
handler can route the event to panthor_arbitration_on_request(), which will 
dereference the already-freed adev->sched[0] pointer.

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=17

Reply via email to