On Thu, Mar 12, 2026 at 10:13:34AM -0700, Calvin Owens wrote:
> Commit e1b385726f7f ("drm/amd/display: Add additional checks for PSP
> footer size") introduced a use of an uninitialized stack variable
> in dm_dmub_sw_init() (region_params.bss_data_size).
> 
> Interestingly, this seems to cause no issue on normal kernels. But when
> full LTO is enabled, it causes the compiler to "optimize" out huge
> swaths of amdgpu initialization code, and the driver is unusable:
> 
>     amdgpu 0000:03:00.0: [drm] Loading DMUB firmware via PSP: 
> version=0x07002F00
>     amdgpu 0000:03:00.0: sw_init of IP block <dm> failed 5
>     amdgpu 0000:03:00.0: amdgpu_device_ip_init failed
>     amdgpu 0000:03:00.0: Fatal error during GPU init
> 
> It surprises me that neither gcc nor clang emit a warning about this: I
> only found it by bisecting the LTO breakage.
> 
> Fix by using the bss_data_size field from fw_meta_info_params, as was
> presumably intended.
> 
> Fixes: e1b385726f7f ("drm/amd/display: Add additional checks for PSP footer 
> size")
> Signed-off-by: Calvin Owens <[email protected]>

Reviewed-by: Nathan Chancellor <[email protected]>

> ---
> Changes in v2:
> * Use fw_meta_info_params.bss_data_size instead of repeating the load
>   from the payload header field [Nathan]
> 
>  drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c 
> b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
> index b3d6f2cd8ab6..0d1c772ef713 100644
> --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
> +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
> @@ -2553,9 +2553,9 @@ static int dm_dmub_sw_init(struct amdgpu_device *adev)
>       fw_meta_info_params.bss_data_size = le32_to_cpu(hdr->bss_data_bytes);
>       fw_meta_info_params.fw_inst_const = adev->dm.dmub_fw->data +
>                                           
> le32_to_cpu(hdr->header.ucode_array_offset_bytes) +
>                                           PSP_HEADER_BYTES_256;
> -     fw_meta_info_params.fw_bss_data = region_params.bss_data_size ? 
> adev->dm.dmub_fw->data +
> +     fw_meta_info_params.fw_bss_data = fw_meta_info_params.bss_data_size ? 
> adev->dm.dmub_fw->data +
>                                         
> le32_to_cpu(hdr->header.ucode_array_offset_bytes) +
>                                         le32_to_cpu(hdr->inst_const_bytes) : 
> NULL;
>       fw_meta_info_params.custom_psp_footer_size = 0;
>  
> -- 
> 2.47.3
> 
> 

Reply via email to