Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [High] drm/panthor: UAF in arbitration IRQ handlers due to devres ordering --
commit 35b5829f1e7e37f44df0de386a8d626358959c51 Author: Karunika Choo <[email protected]> drm/panthor: Route arbitration events This commit wires the resource-group, scheduler, and partition-control blocks together. It routes resource-group messages and partition reset events to the scheduler, and adds callbacks for granting, yielding, and closing partition windows. > diff --git a/drivers/gpu/drm/panthor/arbitration/panthor_arbitration_drv.c > b/drivers/gpu/drm/panthor/arbitration/panthor_arbitration_drv.c > index 2d0c8d95f1abd..723cf605e16a3 100644 > --- a/drivers/gpu/drm/panthor/arbitration/panthor_arbitration_drv.c > +++ b/drivers/gpu/drm/panthor/arbitration/panthor_arbitration_drv.c > @@ -95,20 +95,42 @@ static int panthor_arbitration_runtime_resume(struct > device *dev) > return 0; > } > > +/* AW to Arbiter events */ > +int panthor_arbitration_on_request(struct panthor_arbitration *adev, u8 > aw_id) > +{ > + /* TODO: AW to PC assignment */ > + return panthor_arbitration_sched_on_request(adev->sched[0], aw_id); > +} [Severity: High] Does this introduce a use-after-free risk during driver teardown if a pending interrupt fires? In panthor_arbitration_probe(), the driver registers rg_irq_raw_handler and partition_irq_raw_handler using devm_request_irq() inside panthor_resource_group_init() before the sched structures are allocated using devm_kzalloc() in panthor_arbitration_sched_init(). Because devres releases resources in LIFO order on probe failure or driver removal, the scheduler memory is freed before the IRQs are unregistered. If an interrupt fires or is pending during this teardown window, the active handler can route the event to panthor_arbitration_on_request(), which will dereference the already-freed adev->sched[0] pointer. -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=17
