This is a note to let you know that I've just added the patch titled drm/radeon: fix handling of v6 power tables to the 3.9-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: drm-radeon-fix-handling-of-v6-power-tables.patch and it can be found in the queue-3.9 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@xxxxxxxxxxxxxxx> know about it. >From 441e76ca83ac604eaf0f046def96d8e3a27eea28 Mon Sep 17 00:00:00 2001 From: Alex Deucher <alexander.deucher@xxxxxxx> Date: Wed, 1 May 2013 14:34:54 -0400 Subject: drm/radeon: fix handling of v6 power tables From: Alex Deucher <alexander.deucher@xxxxxxx> commit 441e76ca83ac604eaf0f046def96d8e3a27eea28 upstream. The code was mis-handling variable sized arrays. Reported-by: Sylvain BERTRAND <sylware@xxxxxxxxxx> Signed-off-by: Alex Deucher <alexander.deucher@xxxxxxx> Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> --- drivers/gpu/drm/radeon/radeon_atombios.c | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) --- a/drivers/gpu/drm/radeon/radeon_atombios.c +++ b/drivers/gpu/drm/radeon/radeon_atombios.c @@ -2518,6 +2518,7 @@ static int radeon_atombios_parse_power_t int index = GetIndexIntoMasterTable(DATA, PowerPlayInfo); u16 data_offset; u8 frev, crev; + u8 *power_state_offset; if (!atom_parse_data_header(mode_info->atom_context, index, NULL, &frev, &crev, &data_offset)) @@ -2540,11 +2541,11 @@ static int radeon_atombios_parse_power_t state_array->ucNumEntries, GFP_KERNEL); if (!rdev->pm.power_state) return state_index; + power_state_offset = (u8 *)state_array->states; for (i = 0; i < state_array->ucNumEntries; i++) { mode_index = 0; - power_state = (union pplib_power_state *)&state_array->states[i]; - /* XXX this might be an inagua bug... */ - non_clock_array_index = i; /* power_state->v2.nonClockInfoIndex */ + power_state = (union pplib_power_state *)power_state_offset; + non_clock_array_index = power_state->v2.nonClockInfoIndex; non_clock_info = (struct _ATOM_PPLIB_NONCLOCK_INFO *) &non_clock_info_array->nonClockInfo[non_clock_array_index]; rdev->pm.power_state[i].clock_info = kzalloc(sizeof(struct radeon_pm_clock_info) * @@ -2556,9 +2557,6 @@ static int radeon_atombios_parse_power_t if (power_state->v2.ucNumDPMLevels) { for (j = 0; j < power_state->v2.ucNumDPMLevels; j++) { clock_array_index = power_state->v2.clockInfoIndex[j]; - /* XXX this might be an inagua bug... */ - if (clock_array_index >= clock_info_array->ucNumEntries) - continue; clock_info = (union pplib_clock_info *) &clock_info_array->clockInfo[clock_array_index * clock_info_array->ucEntrySize]; valid = radeon_atombios_parse_pplib_clock_info(rdev, @@ -2580,6 +2578,7 @@ static int radeon_atombios_parse_power_t non_clock_info); state_index++; } + power_state_offset += 2 + power_state->v2.ucNumDPMLevels; } /* if multiple clock modes, mark the lowest as no display */ for (i = 0; i < state_index; i++) { Patches currently in stable-queue which might be from alexander.deucher@xxxxxxx are queue-3.9/drm-radeon-fix-typo-in-rv515_mc_resume.patch queue-3.9/drm-radeon-fix-possible-segfault-when-parsing-pm-tables.patch queue-3.9/drm-radeon-disable-the-crtcs-in-mc_stop-r5xx-r7xx-v2.patch queue-3.9/drm-radeon-fix-handling-of-v6-power-tables.patch queue-3.9/drm-radeon-update-wait_for_vblank-for-evergreen.patch queue-3.9/drm-radeon-fix-endian-bugs-in-atom_allocate_fb_scratch.patch queue-3.9/drm-radeon-add-some-new-si-pci-ids.patch queue-3.9/drm-radeon-dce6-add-missing-display-reg-for-tiling-setup.patch queue-3.9/drm-radeon-fix-hdmi-mode-enable-on-rs600-rs690-rs740.patch queue-3.9/drm-radeon-always-flush-the-vm.patch queue-3.9/drm-radeon-don-t-use-get_engine_clock-on-apus.patch queue-3.9/drm-radeon-add-new-richland-pci-ids.patch queue-3.9/drm-radeon-update-wait_for_vblank-for-r5xx-r7xx.patch queue-3.9/drm-radeon-properly-lock-disp-in-mc_stop-resume-for-r5xx-r7xx.patch queue-3.9/drm-radeon-update-wait_for_vblank-for-r1xx-r4xx.patch queue-3.9/drm-radeon-disable-the-crtcs-in-mc_stop-evergreen-v2.patch queue-3.9/drm-radeon-use-frac-fb-div-on-rs780-rs880.patch queue-3.9/drm-radeon-cleanup-properly-if-mmio-mapping-fails.patch queue-3.9/drm-radeon-evergreen-don-t-enable-hpd-interrupts-on-edp-lvds.patch queue-3.9/drm-radeon-fix-typo-in-si_select_se_sh.patch queue-3.9/drm-radeon-properly-lock-disp-in-mc_stop-resume-for-evergreen.patch -- To unsubscribe from this list: send the line "unsubscribe stable" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html