Thank you for your contribution! Sashiko AI review found 2 potential issue(s) 
to consider:
- [High] drm/solomon: heap buffer overflow during 1bpp framebuffer conversion
- [High] drm/solomon: illegal DMA mapping of .rodata via SPI tx_buf
--

commit 097c6bbe33ac16a0e3a2bddb2a05e16d23d7914c
Author: Devarsh Thakkar <[email protected]>

drm/solomon: ssd16xx: Add support for Solomon SSD1677 controller

Add infrastructure to support the Solomon SSD1677 e-paper controller
(up to 960x680 pixels, 10-bit pixel-level X/Y RAM addressing).

> diff --git a/drivers/gpu/drm/solomon/ssd16xx.c 
> b/drivers/gpu/drm/solomon/ssd16xx.c
> index c478309d08e9f..93fa064cf5894 100644
> --- a/drivers/gpu/drm/solomon/ssd16xx.c
> +++ b/drivers/gpu/drm/solomon/ssd16xx.c
[ ... ]
> @@ -420,6 +426,29 @@ static const struct ssd16xx_controller_config 
> ssd16xx_controller_configs[] = {
>               },
>               .ctrl2_load_temp_lut     = SSD1683_CTRL2_LOAD_TEMP_LUT,
>       },
> +     [SSD1677] = {
> +             /*
> +              * 10-bit pixel-level X/Y addressing; only deep sleep mode
> +              * 0x03 is supported (no RAM-retain mode). Border waveform
> +              * encoding matches SSD1683.
> +              */
> +             .max_width  = 960,
> +             .max_height = 680,
> +             .ram_x_address_bits = 10,

[Severity: High]
Does this configuration allow panels with widths that are not a multiple of 8,
leading to a heap buffer overflow during framebuffer conversion?

Because ram_x_address_bits is 10, it bypasses the multiple-of-8 width check in
ssd16xx_probe():

        if (device->controller_cfg->ram_x_address_bits == 8 &&
            device->width % 8 != 0) {
                drm_err(drm, "panel width %u not a multiple of 8 required for 
byte-addressed X controller)\n",
                        device->width);
                return -EINVAL;
        }

This permits device->width to not be a multiple of 8. However,
ssd16xx_alloc_tx_bufs() calculates the buffer size using global packing:

        size_t frame_size = DIV_ROUND_UP(device->width * device->height, 8);
        device->tx_buf = drmm_kmalloc(&device->drm, frame_size, GFP_KERNEL);

But ssd16xx_convert_fb_to_1bpp() pads each row to a byte boundary:

        for (y = rect->y1; y < rect->y2; y++) {
                ...
                if (++bit_pos == 8) {
                        dst[dst_idx++] = byte;
                        byte = 0;
                        bit_pos = 0;
                }
                ...
                if (bit_pos > 0) {
                        dst[dst_idx++] = byte;
                        byte = 0;
                        bit_pos = 0;
                }
        }

This padding means it writes DIV_ROUND_UP(width, 8) * height bytes in total,
which exceeds the allocated frame_size, causing memory corruption past the end
of device->tx_buf.

[ ... ]
> @@ -691,21 +736,34 @@ static int ssd16xx_hw_init(struct ssd16xx_device 
> *device)
>  
>       ssd16xx_hw_reset(device);
>  
> -     /* Software reset */
> +     /* Software reset (0x12): resets command/parameter registers to 
> defaults. */
>       ssd16xx_send_cmd(device, SSD16XX_CMD_SW_RESET, &err);
>       ssd16xx_wait_for_device(device, &err);
>  
>       /* Internal temperature sensor (SSD1683/SSD1680 only; not present in 
> SSD1673) */
>       if (device->controller_cfg->has_temp_sensor_ctrl) {
>               ssd16xx_send_cmd(device, 
> SSD1683_CMD_TEMPERATURE_SENSOR_CONTROL, &err);
>               ssd16xx_send_data(device, SSD1683_TEMP_SENSOR_INTERNAL, &err);
>       }
>  
> +     /*
> +      * Booster soft-start (0x0C): panel-specific charge pump tuning.
> +      * Some panels (e.g. PIXPAPER 4.26m on SSD1677) require this step;
> +      * others (e.g. GDEY042T81 on SSD1683) omit it.
> +      */
> +     if (device->device_cfg->booster_soft_start_data) {
> +             ssd16xx_send_cmd(device, SSD16XX_CMD_BOOSTER_SOFT_START, &err);
> +             ssd16xx_send_data_bulk(device,
> +                                    
> device->device_cfg->booster_soft_start_data,
> +                                    
> device->device_cfg->booster_soft_start_len,
> +                                    &err);

[Severity: High]
Does this pass a .rodata pointer directly to the SPI core, causing an illegal
DMA mapping?

The booster_soft_start_data pointer comes from the device configuration, which
points to static const tuning data. When this is passed to
ssd16xx_send_data_bulk() under 4-wire SPI mode:

        if (device->dc) {
                /* 4-wire SPI: D/C# GPIO high selects data mode */
                xfer.tx_buf = data;
                xfer.len = len;
                gpiod_set_value_cansleep(device->dc, 1);
                ssd16xx_spi_sync(device->spi, &msg, err);

The SPI core will attempt to DMA map the xfer.tx_buf. Mapping .rodata for DMA
is prohibited and can cause kernel panics or mapping failures.

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=6

Reply via email to