Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:

Pre-existing issues:
- [High] Dangling pointer in panic_msg array causes use-after-free during 
kernel panic after the test module is unloaded.
--

--- Patch [13]: [PATCH v2 13/13] drm/panic: Compile KUnit tests as module ---
commit 9a00d4c3f17fad5dbc6e3335649c2316482a4fad
Author: Thomas Zimmermann <[email protected]>
Subject: drm/panic: Compile KUnit tests as module
    
Fix dependency of the panic-helper KUnit tests on CONFIG_DRM_KUNIT_TEST=y
and make them build as a module. Export the necessary interfaces from the
panic helpers iff the KUnit framework has been enabled.

> diff --git a/drivers/gpu/drm/drm_panic_helper.c 
> b/drivers/gpu/drm/drm_panic_helper.c
> index 669f09225f8ed..253262b7e0d4c 100644
> --- a/drivers/gpu/drm/drm_panic_helper.c
> +++ b/drivers/gpu/drm/drm_panic_helper.c

[ ... ]

> -static void drm_panic_helper_set_description(const char *description)
> +VISIBLE_IF_KUNIT void drm_panic_helper_set_description(const char 
> *description)
>  {
>       u32 len;
>  
>       if (description) {
>               struct drm_panic_line *desc_line = &panic_msg[panic_msg_lines - 
> 1];
>  
>               desc_line->txt = description;
>               len = strlen(description);
>               /* ignore the last newline character */
>               if (len && description[len - 1] == '\n')
>                       len -= 1;
>               desc_line->len = len;
>       }
>  }
> +EXPORT_SYMBOL_IF_KUNIT(drm_panic_helper_set_description);

[Severity: High]
This is a pre-existing issue, but since the test can now be built as a module,
does unloading it leave a dangling pointer in the global panic_msg array?

In drivers/gpu/drm/tests/drm_panic_helper_test.c, drm_test_panic_init()
calls drm_panic_helper_set_description("Kunit testing"), which stores a
pointer to the test module's .rodata.

When the drm_panic_helper_test module is unloaded, this memory is freed. Since
the test suite lacks an .exit callback to call
drm_panic_helper_clear_description(), the dangling pointer remains in the
global array.

If a real kernel panic occurs later where detail->description is NULL (such as
via kmsg_dump(KMSG_DUMP_PANIC) on some architectures), this function silently
ignores the NULL input and leaves the dangling pointer intact.

Will this cause a use-after-free read when the panic screen rendering
dereferences desc_line->txt, potentially preventing the panic screen from
displaying during an actual crash?

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=13

Reply via email to