Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Use-After-Free and -EBUSY on re-bind due to missing drm_bridge_detach in component unbind.
--
--- Patch [2]: [PATCH v11 02/21] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback ---
commit 8317a23524c759645b1aec330e9a401578a81a81
Author: Sebastian Reichel <[email protected]>
drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback
This commit moves the bridge allocation and resource requests from the bind
callback to the probe callback using a new dw_dp_probe() helper. It also
disables the IRQ in the detach callback to prevent spurious interrupts.
Reported-by: Sashiko <[email protected]>
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> index 60feb3d1e14bb..d7945f7fe9f05 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
[ ... ]
> @@ -1982,6 +1988,18 @@ static const struct regmap_config dw_dp_regmap_config = {
> .rd_table = &dw_dp_readable_table,
> };
>
> +int dw_dp_bind(struct dw_dp *dp, struct drm_encoder *encoder)
> +{
> + return drm_bridge_attach(encoder, &dp->bridge, NULL, DRM_BRIDGE_ATTACH_NO_CONNECTOR);
> +}
> +EXPORT_SYMBOL_GPL(dw_dp_bind);
> +
> +void dw_dp_unbind(struct dw_dp *dp)
> +{
> + /* nothing to do as bridge is detached automatically */
> +}
> +EXPORT_SYMBOL_GPL(dw_dp_unbind);
[Severity: High]
Since the bridge allocation was moved to probe using devm, the bridge
structure now outlives the component bind/unbind cycle. If the bridge is
not explicitly detached here, does this cause issues during re-bind?
Specifically, if we unbind and re-bind the component, won't
drm_bridge_attach() in dw_dp_bind() return -EBUSY because the bridge is
still attached to the old encoder?
Additionally, can this cause a use-after-free on driver removal? If the
platform driver is removed while a DRM file descriptor is kept open, devm
will free the dp structure. When the file descriptor is eventually closed,
DRM core will call dw_dp_bridge_detach():
static void dw_dp_bridge_detach(struct drm_bridge *bridge)
{
struct dw_dp *dp = bridge_to_dp(bridge);
disable_irq(dp->irq);
cancel_work_sync(&dp->hpd_work);
...
}
Since dp was already freed by devm, will accessing dp->irq and dp->hpd_work
here crash? Should this unbind function explicitly call drm_bridge_detach()
to prevent both the re-bind failure and the use-after-free?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260806-synopsys-dw-dp-improvements-v11-0-0d508505f383@collabora.com?part=2
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.