[PATCH] drm/amd/display: fix NULL deref when opening a closed DDC

From: Arthur Liberman

Date: Wed Oct 07 2026 - 13:47:25 EST


dal_ddc_open() uses gpio->pin after dal_gpio_service_open() installs
it. Close clears that pointer. HPD sink detection and a KWin atomic
check can both open the same DDC: the check reads DPCD for DSC while
the HPD worker closes the pin. The load of hw_gpio.store.en then
oopses at offset 0x28 and kwin_wayland exits with IRQs disabled.

If either pin is gone after open, close what this call holds and
return GPIO_RESULT_NULL_HANDLE so the AUX transfer fails instead.
This does not serialize the two threads.

Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: Cursor:xai-grok-4.7
Signed-off-by: Arthur Liberman <arthur_liberman@xxxxxxxxxxx>
---
drivers/gpu/drm/amd/display/dc/gpio/gpio_service.c | 11 +++++++++++
1 file changed, 11 insertions(+)

diff --git a/drivers/gpu/drm/amd/display/dc/gpio/gpio_service.c b/drivers/gpu/drm/amd/display/dc/gpio/gpio_service.c
index 95f8b7c7d657..a3145cd82d8b 100644
--- a/drivers/gpu/drm/amd/display/dc/gpio/gpio_service.c
+++ b/drivers/gpu/drm/amd/display/dc/gpio/gpio_service.c
@@ -577,6 +577,17 @@ enum gpio_result dal_ddc_open(
goto failure;
}

+ /*
+ * dal_gpio_service_open() installs gpio->pin, and close clears it.
+ * MST bring-up can AUX-read for DSC while HPD teardown closes the
+ * same DDC. pin is NULL again in that window; do not dereference it.
+ */
+ if (!ddc->pin_data->pin || !ddc->pin_clock->pin) {
+ dal_gpio_close(ddc->pin_clock);
+ dal_gpio_close(ddc->pin_data);
+ return GPIO_RESULT_NULL_HANDLE;
+ }
+
/* DDC clock and data pins should belong
* to the same DDC block id,
* we use the data pin to set the pad mode. */

base-commit: 41505ac433cc4c5179deee8860d197b04f6d1c1d
--
2.55.0