The drm_panel subsystem provides kref-based reference counting [1] (drm_panel_get/put) but almost nothing in the tree actually uses it. This results in a systemic use-after-free pattern throughout the codebase.
This series aims to close all those issues. Patches 1-2: fix the infrastructure. drm_panel_add/remove now keep a counted reference for the list entry. drm_panel_bridge_add_typed() now holds a counted reference for the lifetime of the panel_bridge. Patch 3: change the semantics of of_drm_find_panel(). It now acquires a reference before returning, under panel_lock. All in-tree callers of of_drm_find_panel() and drm_of_find_panel_or_bridge() are updated. Two patterns are common in these fixes: - Bridge-wrapping: the panel is passed to devm_drm_panel_bridge_add() or equivalent, which acquires its own reference. The caller (including devm_drm_of_get_bridge() and drmm_of_get_bridge()) releases its lookup reference immediately after. - Store-and-use: the panel pointer is kept in a driver struct and used directly for the device lifetime. The reference is released in the remove/unbind path, or via devm_add_action_or_reset() where no explicit teardown function exists. Patch 4: extend the same fix to find_panel_by_fwnode(), a static helper used internally by drm_panel_add_follower(). Since it has no external callers, the fix is self-contained: drm_panel_remove_follower() is updated to call drm_panel_put() to balance the reference. In order to catch all places in the tree that required releasing the reference, the search was assisted by an AI model. Specifically, a Coccinelle script was designed by the agent to address the trivial changes (not included in the series). Although a few required manual fixes, with goto labels or bracket additions. Additionally, the model helped to discern implicit teardown paths that were addressed with devm_add_action_or_reset() calls. Thus, these commits have the Assisted-by label following the project guidelines. No functional change is intended for any driver. The reference counting only affects object lifetime; panel operations are unaffected. [1] https://lore.kernel.org/all/[email protected]/ Signed-off-by: Albert Esteve <[email protected]> --- Changes in v3: - Squashed patches 3 and 5 - Fix probe failure paths that leaked reference - Fix UAF and other smaller issues found by Sashiko - Add comment in tegra-dsi explaining why panel is always NULL in that path and so no early drm_panel_put() is required - Link to v2: https://lore.kernel.org/r/[email protected] Changes in v2: - Squash of_drm_find_panel() API change with its caller fixes - Split find_panel_by_fwnode() into its own commit - Update kernel-doc for drm_of_find_panel_or_bridge() - Link to v1: https://lore.kernel.org/r/[email protected] --- Albert Esteve (4): drm/panel: have drm_panel_add/remove manage a list reference drm/bridge/panel: hold a reference to the wrapped panel drm/panel: of_drm_find_panel() return a counted reference drm/panel: find_panel_by_fwnode() return a counted reference drivers/gpu/drm/bridge/analogix/analogix-anx6345.c | 12 +++++++++++ drivers/gpu/drm/bridge/fsl-ldb.c | 1 + drivers/gpu/drm/bridge/lontium-lt9211.c | 1 + drivers/gpu/drm/bridge/lvds-codec.c | 1 + drivers/gpu/drm/bridge/panel.c | 20 ++++++++++++++---- drivers/gpu/drm/bridge/samsung-dsim.c | 1 + drivers/gpu/drm/bridge/ssd2825.c | 1 + drivers/gpu/drm/bridge/tc358767.c | 2 ++ drivers/gpu/drm/bridge/tc358768.c | 1 + drivers/gpu/drm/bridge/waveshare-dsi.c | 1 + drivers/gpu/drm/drm_of.c | 3 ++- drivers/gpu/drm/drm_panel.c | 24 +++++++++++++++++----- drivers/gpu/drm/exynos/exynos_dp.c | 19 ++++++++++++++++- drivers/gpu/drm/exynos/exynos_drm_dpi.c | 3 +++ drivers/gpu/drm/fsl-dcu/fsl_dcu_drm_rgb.c | 18 ++++++++++++++++ drivers/gpu/drm/imx/dcss/dcss-kms.c | 3 +++ drivers/gpu/drm/ingenic/ingenic-drm-drv.c | 4 +++- drivers/gpu/drm/logicvc/logicvc_interface.c | 12 +++++++++++ drivers/gpu/drm/mcde/mcde_drv.c | 1 + drivers/gpu/drm/mcde/mcde_dsi.c | 1 + drivers/gpu/drm/mxsfb/mxsfb_drv.c | 1 + drivers/gpu/drm/omapdrm/dss/output.c | 1 + drivers/gpu/drm/pl111/pl111_drv.c | 1 + drivers/gpu/drm/renesas/rcar-du/rcar_du_encoder.c | 1 + drivers/gpu/drm/renesas/rcar-du/rcar_lvds.c | 1 + drivers/gpu/drm/renesas/rz-du/rzg2l_du_encoder.c | 1 + drivers/gpu/drm/rockchip/analogix_dp-rockchip.c | 11 ++++++++++ drivers/gpu/drm/rockchip/rockchip_lvds.c | 4 ++++ drivers/gpu/drm/rockchip/rockchip_rgb.c | 3 +++ drivers/gpu/drm/sti/sti_dvo.c | 3 +++ drivers/gpu/drm/stm/ltdc.c | 1 + drivers/gpu/drm/stm/lvds.c | 12 ++++++++--- drivers/gpu/drm/sun4i/sun4i_lvds.c | 13 ++++++++++++ drivers/gpu/drm/sun4i/sun4i_rgb.c | 13 ++++++++++++ drivers/gpu/drm/sun4i/sun4i_tcon.c | 2 ++ drivers/gpu/drm/sun4i/sun6i_mipi_dsi.c | 6 +++++- drivers/gpu/drm/tegra/dsi.c | 5 +++++ drivers/gpu/drm/tegra/output.c | 24 +++++++++++++++++++--- drivers/gpu/drm/tidss/tidss_kms.c | 16 ++++++++++----- drivers/gpu/drm/tve200/tve200_drv.c | 1 + 40 files changed, 225 insertions(+), 24 deletions(-) --- base-commit: 8cdeaa50eae8dad34885515f62559ee83e7e8dda change-id: 20260513-drm_refcount_wiring-4e5e757e9047 Best regards, -- Albert Esteve <[email protected]>
