[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-08-20 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #18 from Johannes Hirte (johannes.hi...@datenkhaos.de) ---
[183309.195913]
==
[183309.195937] BUG: KASAN: use-after-free in
drm_atomic_helper_wait_for_flip_done+0x212/0x270
[183309.195944] Read of size 8 at addr 880115b906a8 by task
kworker/u8:1/12462

[183309.195956] CPU: 1 PID: 12462 Comm: kworker/u8:1 Not tainted
4.18.0-1-g61b0dd9978b0 #14
[183309.195961] Hardware name: HP HP ProBook 645 G2/80FE, BIOS N77 Ver. 01.15
03/26/2018
[183309.195968] Workqueue: events_unbound commit_work
[183309.195973] Call Trace:
[183309.195985]  dump_stack+0x5b/0x90
[183309.195993]  print_address_description+0x60/0x229
[183309.195999]  ? drm_atomic_helper_wait_for_flip_done+0x212/0x270
[183309.196005]  kasan_report.cold.5+0x241/0x2ff
[183309.196011]  drm_atomic_helper_wait_for_flip_done+0x212/0x270
[183309.196020]  amdgpu_dm_atomic_commit_tail+0x2718/0x4040
[183309.196029]  ? _raw_spin_unlock_irq+0x35/0x50
[183309.196034]  ? wait_for_completion_timeout+0x214/0x2d0
[183309.196040]  ? commit_planes_to_stream.constprop.47+0x13b0/0x13b0
[183309.196047]  ? finish_task_switch+0x1a0/0x700
[183309.196052]  ? drm_atomic_helper_wait_for_dependencies+0x478/0x7e0
[183309.196058]  commit_tail+0x91/0xe0
[183309.196064]  process_one_work+0x866/0x1460
[183309.196071]  worker_thread+0x82/0xf60
[183309.196076]  ? _raw_spin_unlock_irqrestore+0x3a/0x70
[183309.196081]  ? __kthread_parkme+0x7d/0xf0
[183309.196086]  ? rescuer_thread+0xcd0/0xcd0
[183309.196090]  kthread+0x2cf/0x380
[183309.196095]  ? kthread_create_worker+0xd0/0xd0
[183309.196100]  ret_from_fork+0x22/0x40

[183309.196109] Allocated by task 570:
[183309.196116]  kasan_kmalloc+0xbf/0xe0
[183309.196123]  kmem_cache_alloc_trace+0xf3/0x1f0
[183309.196128]  dm_crtc_duplicate_state+0x73/0x130
[183309.196134]  drm_atomic_get_crtc_state+0x142/0x400
[183309.196138]  page_flip_common+0x52/0x220
[183309.196142]  drm_atomic_helper_page_flip+0xa1/0x100
[183309.196148]  drm_mode_page_flip_ioctl+0xc46/0x1090
[183309.196152]  drm_ioctl_kernel+0x192/0x210
[183309.196156]  drm_ioctl+0x3ea/0x850
[183309.196161]  amdgpu_drm_ioctl+0xc7/0x1a0
[183309.196165]  do_vfs_ioctl+0x18e/0xed0
[183309.196169]  ksys_ioctl+0x5b/0x90
[183309.196173]  __x64_sys_ioctl+0x6a/0xb0
[183309.196177]  do_syscall_64+0x95/0x2f0
[183309.196183]  entry_SYSCALL_64_after_hwframe+0x44/0xa9

[183309.196188] Freed by task 634:
[183309.196193]  __kasan_slab_free+0x125/0x170
[183309.196197]  kfree+0x8b/0x1c0
[183309.196202]  drm_atomic_state_default_clear+0x310/0xc40
[183309.196206]  __drm_atomic_state_free+0x30/0xc0
[183309.196210]  drm_atomic_helper_update_plane+0xa7/0x350
[183309.196214]  __setplane_internal+0x2d1/0x820
[183309.196218]  drm_mode_cursor_universal+0x2f0/0x910
[183309.196222]  drm_mode_cursor_common+0x49a/0x880
[183309.196226]  drm_mode_cursor_ioctl+0x81/0xb0
[183309.196229]  drm_ioctl_kernel+0x192/0x210
[183309.196233]  drm_ioctl+0x3ea/0x850
[183309.196237]  amdgpu_drm_ioctl+0xc7/0x1a0
[183309.196241]  do_vfs_ioctl+0x18e/0xed0
[183309.196244]  ksys_ioctl+0x5b/0x90
[183309.196248]  __x64_sys_ioctl+0x6a/0xb0
[183309.196252]  do_syscall_64+0x95/0x2f0
[183309.196256]  entry_SYSCALL_64_after_hwframe+0x44/0xa9

[183309.196263] The buggy address belongs to the object at 880115b90480
 which belongs to the cache kmalloc-1024 of size 1024
[183309.196269] The buggy address is located 552 bytes inside of
 1024-byte region [880115b90480, 880115b90880)
[183309.196274] The buggy address belongs to the page:
[183309.196279] page:ea000456e400 count:1 mapcount:0
mapping:8803ef002c40 index:0x0 compound_mapcount: 0
[183309.196286] flags: 0x20008100(slab|head)
[183309.196294] raw: 20008100 ea000ceba800 00020002
8803ef002c40
[183309.196300] raw:  801c001c 0001

[183309.196303] page dumped because: kasan: bad access detected

[183309.196308] Memory state around the buggy address:
[183309.196312]  880115b90580: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
fb
[183309.196317]  880115b90600: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
fb
[183309.196321] >880115b90680: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
fb
[183309.196324]   ^
[183309.196328]  880115b90700: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
fb
[183309.196332]  880115b90780: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
fb
[183309.196335]
==
[183309.196338] Disabling lock debugging due to kernel taint


This is with kernel 4.18.0 and your patch on top.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-08-17 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

Daniel Vetter (dan...@ffwll.ch) changed:

   What|Removed |Added

 CC||dan...@ffwll.ch

--- Comment #17 from Daniel Vetter (dan...@ffwll.ch) ---
Can you pls attach a new kasan backtrace with my patch

https://patchwork.freedesktop.org/patch/230355/

applied? Just want to double check nothing has moved, and also whether some
other peculiarities of the stacktraces are invariant.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-07-25 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #16 from Johannes Hirte (johannes.hi...@datenkhaos.de) ---
(In reply to mikita.lip...@amd.com from comment #15)
> Lyude Paul fixed this issue, please try his patch:
> 
> https://patchwork.kernel.org/patch/10480569/
> 
> Thanks

As written in https://bugzilla.kernel.org/show_bug.cgi?id=199425#c13, this
patch fix another bug. It doesn't help with this use-after-free. Your patch is
still needed.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-07-25 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #15 from mikita.lip...@amd.com (mikita.lip...@amd.com) ---
Lyude Paul fixed this issue, please try his patch:

https://patchwork.kernel.org/patch/10480569/

Thanks

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-07-25 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #14 from Johannes Hirte (johannes.hi...@datenkhaos.de) ---
(In reply to mikita.lip...@amd.com from comment #10)
> Johannes,
> My patch wasn't merged into DRM, but Daniel Vetter proposed another patch
> that might remove legacy code that causes the issue. Could you remove my
> patch from your tree and apply the following patch:
> 
> https://patchwork.freedesktop.org/patch/230355/
> 
> Could you please if it fixes the Kasan issue for you, thanks.

Doesn't avoid the use-after-free. Tested with the patch on top of 4.18-rc6.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-07-24 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #13 from Johannes Hirte (johannes.hi...@datenkhaos.de) ---
(In reply to Harry Wentland from comment #11)
> Should be fixed by https://patchwork.freedesktop.org/patch/230831/ which is
> merged into amd-staging-drm-next

Just tested with 4.18-rc6 that has this patch applied. Still getting the
use-after-free. Looking at this patch, this seems to fix another bug:

BUG: KASAN: use-after-free in amdgpu_dm_atomic_commit_tail.cold.50+0x13d/0x15a
[amdgpu]

whereas this one is:

BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x212/0x270

I'll try the patch from Daniel Vetter now.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-07-03 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #12 from Johannes Hirte (johannes.hi...@datenkhaos.de) ---
(In reply to mikita.lip...@amd.com from comment #10)
> Johannes,
> My patch wasn't merged into DRM, but Daniel Vetter proposed another patch
> that might remove legacy code that causes the issue. Could you remove my
> patch from your tree and apply the following patch:
> 
> https://patchwork.freedesktop.org/patch/230355/
> 
> Could you please if it fixes the Kasan issue for you, thanks.

Sorry, I don't have access to the Carrizo system at moment. I hope, I'll have
it back in a week or so. Will test it, as soon as possible.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-06-27 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #11 from Harry Wentland (harry.wentl...@amd.com) ---
Should be fixed by https://patchwork.freedesktop.org/patch/230831/ which is
merged into amd-staging-drm-next

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-06-21 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #10 from mikita.lip...@amd.com (mikita.lip...@amd.com) ---
Johannes,
My patch wasn't merged into DRM, but Daniel Vetter proposed another patch that
might remove legacy code that causes the issue. Could you remove my patch from
your tree and apply the following patch:

https://patchwork.freedesktop.org/patch/230355/

Could you please if it fixes the Kasan issue for you, thanks.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-06-15 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #9 from Michel Dänzer (mic...@daenzer.net) ---
Mikita, can you send this patch to the dri-devel mailing list for review?

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-05-28 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #8 from Johannes Hirte (johannes.hi...@datenkhaos.de) ---
(In reply to mikita.lip...@amd.com from comment #6)
> Created attachment 276173 [details]
> Patch to either dublicate or reuse an existing crtc state that might pervent
> use-after-free error in race condition
> 
> Sorry, the previous patch is irrelevant and was attached by mistake! Please
> try the one above. Thanks

The patch seems to help. I was running the system the last days without any
use-after-free.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-05-25 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #7 from Johannes Hirte (johannes.hi...@datenkhaos.de) ---
dmesg output with drm.debug=0x6 and without your patch:

May 25 13:40:54 probook kernel: [drm:amdgpu_dm_do_flip] crtc:0,
pflip_stat:AMDGPU_FLIP_SUBMITTED
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_do_flip] amdgpu_dm_do_flip
Flipping to hi: 0xf4, low: 0x1a01 
May 25 13:40:54 probook kernel: [drm:dm_pflip_high_irq] dm_pflip_high_irq -
crtc :0[bae227b0], pflip_stat:AMDGPU_FLIP_NONE
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:54 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 crtc_state_flags: enable:1, active:1, planes_changed:1,
mode_changed:0,active_changed:0,connectors_changed:0
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail]
handle_cursor_update: crtc_id=0 with size 128 to 128
May 25 13:40:55 probook kernel: [drm:amdgpu_dm_atomic_commit_tail] amdgpu_crtc
id:0 

[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-05-24 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #6 from mikita.lip...@amd.com (mikita.lip...@amd.com) ---
Created attachment 276173
  --> https://bugzilla.kernel.org/attachment.cgi?id=276173=edit
Patch to either dublicate or reuse an existing crtc state that might pervent
use-after-free error in race condition

Sorry, the previous patch is irrelevant and was attached by mistake! Please try
the one above. Thanks

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-05-24 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #5 from mikita.lip...@amd.com (mikita.lip...@amd.com) ---
Created attachment 276171
  --> https://bugzilla.kernel.org/attachment.cgi?id=276171=edit
Patch to either dublicate or reuse an existing crtc state that might pervent
use-after-free error in race condition

I wasn't able to reproduce the issue, but could you please try applying this
patch and seeing if does any difference?

Also could add a dmesg log with drm.debug=0x6 to see whats the chain of events
that caused the issue 

Thanks

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-05-23 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #4 from Johannes Hirte (johannes.hi...@datenkhaos.de) ---
Sadly I don't have a reproducer for this. I'm starting the system, and after
some time I get the kasan-warning. Sometimes it happened really fast after
boot, sometimes it took several hours.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-05-23 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

mikita.lip...@amd.com (mikita.lip...@amd.com) changed:

   What|Removed |Added

 CC||mikita.lip...@amd.com

--- Comment #3 from mikita.lip...@amd.com (mikita.lip...@amd.com) ---
Hi Johannes,

We have started investigating the issue. 

Whats the scenario to reproduce the issue?

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-05-22 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #2 from Johannes Hirte (johannes.hi...@datenkhaos.de) ---
ping? We have rc6, a use-after-free and no developer cares?

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel


[Bug 199425] BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

2018-04-25 Thread bugzilla-daemon
https://bugzilla.kernel.org/show_bug.cgi?id=199425

--- Comment #1 from Johannes Hirte (johannes.hi...@datenkhaos.de) ---
(gdb) list *(drm_atomic_helper_wait_for_flip_done+0x247)
0x82043447 is in drm_atomic_helper_wait_for_flip_done
(drivers/gpu/drm/drm_atomic_helper.c:1381).
1376struct drm_crtc_state *new_crtc_state;
1377struct drm_crtc *crtc;
1378int i;
1379
1380for_each_new_crtc_in_state(old_state, crtc, new_crtc_state, i)
{
1381struct drm_crtc_commit *commit =
new_crtc_state->commit;
1382int ret;
1383
1384if (!commit)
1385continue;
(gdb)

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
___
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel