drm/hyperv: validate resolution_count and fix WIN8 fallback

JIRA: https://issues.redhat.com/browse/RHEL-180329

commit 8a114b25b5521eae451b13bce98ae978624962e5
Author: Berkant Koc <me@berkoc.com>
Date:   Tue May 19 22:08:17 2026 +0200

    drm/hyperv: validate resolution_count and fix WIN8 fallback

    commit 13d33b9ef67066c77c84273fac5a1d3fde3533d1 upstream.

    A SYNTHVID_RESOLUTION_RESPONSE with resolution_count > 64 walks past
    the supported_resolution[SYNTHVID_MAX_RESOLUTION_COUNT] array in the
    parse loop. Bound resolution_count against the array size, folded
    into the existing zero-check.

    When the WIN10 resolution probe fails, the caller in
    hyperv_connect_vsp() left hv->screen_*_max / preferred_* unpopulated,
    which sets mode_config.max_width / max_height to 0 and makes
    drm_internal_framebuffer_create() reject every userspace framebuffer
    with -EINVAL. The pre-WIN10 branch had the same gap for
    preferred_width / preferred_height. Use a single post-probe fallback
    guarded by screen_width_max == 0 so both paths converge on the WIN8
    defaults.

    Signed-off-by: Berkant Koc <me@berkoc.com>
    Assisted-by: Claude:claude-opus-4-7 berkoc-pipeline
    Fixes: 76c56a5aff ("drm/hyperv: Add DRM driver for hyperv synthetic video device")
    Cc: stable@vger.kernel.org # 5.14+
    Reviewed-by: Michael Kelley <mhklinux@outlook.com>
    Tested-by: Michael Kelley <mhklinux@outlook.com>
    Signed-off-by: Hamza Mahfooz <hamzamahfooz@linux.microsoft.com>
    Link: https://patch.msgid.link/6945b22419c7d404b4954a113de2ac9c900dba93.1779542874.git.me@berkoc.com
    Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Signed-off-by: Anusha Srivatsa <asrivats@redhat.com>
This commit is contained in:
Anusha Srivatsa
2026-08-03 14:53:53 -05:00
parent c96e72ae14
commit 885a12aaa7
+10 -3
View File
@@ -391,8 +391,11 @@ static int hyperv_get_supported_resolution(struct hv_device *hdev)
return -ETIMEDOUT;
}
if (msg->resolution_resp.resolution_count == 0) {
drm_err(dev, "No supported resolutions\n");
if (msg->resolution_resp.resolution_count == 0 ||
msg->resolution_resp.resolution_count >
SYNTHVID_MAX_RESOLUTION_COUNT) {
drm_err(dev, "Invalid resolution count: %d\n",
msg->resolution_resp.resolution_count);
return -ENODEV;
}
@@ -508,9 +511,13 @@ int hyperv_connect_vsp(struct hv_device *hdev)
ret = hyperv_get_supported_resolution(hdev);
if (ret)
drm_err(dev, "Failed to get supported resolution from host, use default\n");
} else {
}
if (!hv->screen_width_max) {
hv->screen_width_max = SYNTHVID_WIDTH_WIN8;
hv->screen_height_max = SYNTHVID_HEIGHT_WIN8;
hv->preferred_width = SYNTHVID_WIDTH_WIN8;
hv->preferred_height = SYNTHVID_HEIGHT_WIN8;
}
hv->mmio_megabytes = hdev->channel->offermsg.offer.mmio_megabytes;