On Wed, Jul 15, 2026 at 9:14 AM Mikko Perttunen <[email protected]> wrote: > > On Monday, July 13, 2026 8:53 PM Albert Esteve wrote: > > Callers of of_drm_find_panel() receive a pointer with no reference > > held, creating a window where the panel device can be unregistered > > and freed between the lookup and first use (e.g., drm_panel_prepare()). > > > > Fix the lookup function by acquiring a reference with drm_panel_get() > > before returning, under panel_lock. Callers are now responsible for > > calling drm_panel_put() when they no longer need the pointer. > > > > For bridge drivers that immediately wrap the panel in a panel_bridge > > (which acquires its own reference), release the lookup reference right > > after the bridge creation call. > > > > For analogix-anx6345, which stores the panel for direct use, release > > the reference in the i2c remove path. > > > > For platform drivers using analogix_dp_core with a component lifecycle > > (exynos_dp, rockchip analogix_dp), release the lookup reference in the > > platform remove() function. The panel_bridge created during bind() holds > > a separate reference that devm cleanup releases after remove() returns. > > > > Also fix devm_drm_of_get_bridge() and drmm_of_get_bridge() in > > bridge/panel.c itself: both call drm_of_find_panel_or_bridge() and > > then pass the panel to devm/drmm_panel_bridge_add(), which acquires > > its own reference via drm_panel_bridge_add_typed(). The lookup > > reference was never released; add drm_panel_put() after each bridge > > creation call. > > > > Assisted-by: Claude:claude-opus-4-6 > > Signed-off-by: Albert Esteve <[email protected]> > > --- > > drivers/gpu/drm/bridge/analogix/analogix-anx6345.c | 3 +++ > > drivers/gpu/drm/bridge/panel.c | 8 ++++++-- > > drivers/gpu/drm/drm_of.c | 3 ++- > > drivers/gpu/drm/drm_panel.c | 12 ++++++++---- > > drivers/gpu/drm/exynos/exynos_dp.c | 10 ++++++++++ > > drivers/gpu/drm/exynos/exynos_drm_dpi.c | 3 +++ > > drivers/gpu/drm/fsl-dcu/fsl_dcu_drm_rgb.c | 18 ++++++++++++++++++ > > drivers/gpu/drm/logicvc/logicvc_interface.c | 12 ++++++++++++ > > drivers/gpu/drm/rockchip/analogix_dp-rockchip.c | 11 +++++++++++ > > drivers/gpu/drm/sti/sti_dvo.c | 3 +++ > > drivers/gpu/drm/stm/lvds.c | 3 +++ > > drivers/gpu/drm/sun4i/sun4i_lvds.c | 13 +++++++++++++ > > drivers/gpu/drm/sun4i/sun4i_rgb.c | 13 +++++++++++++ > > drivers/gpu/drm/sun4i/sun6i_mipi_dsi.c | 2 ++ > > drivers/gpu/drm/tegra/dsi.c | 1 + > > drivers/gpu/drm/tegra/output.c | 3 +++ > > 16 files changed, 111 insertions(+), 7 deletions(-) > > > > ... > > diff --git a/drivers/gpu/drm/tegra/dsi.c b/drivers/gpu/drm/tegra/dsi.c > > index 7f25c50621c94..57a016f47434d 100644 > > --- a/drivers/gpu/drm/tegra/dsi.c > > +++ b/drivers/gpu/drm/tegra/dsi.c > > @@ -1516,6 +1516,7 @@ static int tegra_dsi_host_detach(struct mipi_dsi_host > > *host, > > struct tegra_output *output = &dsi->output; > > > > if (output->panel && &device->dev == output->panel->dev) { > > + drm_panel_put(output->panel); > > output->panel = NULL; > > > > if (output->connector.dev) > > diff --git a/drivers/gpu/drm/tegra/output.c b/drivers/gpu/drm/tegra/output.c > > index 49e4f63a5550d..90db39dbdd332 100644 > > --- a/drivers/gpu/drm/tegra/output.c > > +++ b/drivers/gpu/drm/tegra/output.c > > @@ -195,6 +195,9 @@ int tegra_output_probe(struct tegra_output *output) > > > > void tegra_output_remove(struct tegra_output *output) > > { > > + if (output->panel) > > + drm_panel_put(output->panel); > > + > > if (output->hpd_gpio) > > free_irq(output->hpd_irq, output); > > > > > > tegra_output_probe's error cleanup paths need to be updated to clean up > the refcount. Also, it can technically call drm_of_find_panel_or_bridge > and then overwrite that value with of_drm_find_panel. While there's > already a WARN_ON for that case, I think it would be good to fix the > refcounting there as well for consistency.
Agreed. I really missed those. I am doing another general check in case I missed similar cases. > > As a note, the tegra-dsi code also uses tegra_output and can overwrite > the panel field with its own -- but in those cases tegra_output should > never populate the panel and we've been talking about removing that > code path anyway, so the dsi code can continue to assume that > tegra_output_probe doesn't populate a panel. Thanks. I will add a note before of_drm_find_panel() in tegra/dsi.c to clarify. BR, Albert > > Cheers > Mikko > > > -- > > 2.54.0 > > > > > > > >
