On Wed, Jul 15, 2026 at 09:54:36AM +0800, [email protected] wrote: > From: Sunyun Yang <[email protected]> > > The LT7911EXC is an I2C-controlled bridge that receives eDP1.4 > and output mipi dsi. This series introduces: > > - A device tree binding YAML file describing the hardware > - A new DRM bridge driver implementing the basic functionality > > Signed-off-by: Sunyun Yang<[email protected]> > --- > Change in v17: > - dt-binding: > - drm/bridge: > 1. [High] devm leak and list corruption on panel rebind > [sashiko-bot] > False positive. The -EBUSY guard at the top of host_attach() (line > 527) rejects re-attach > when output_bridge is already set, so neither > devm_drm_of_get_bridge() nor drm_bridge_add() > is reached on panel rebind.
This is not a changelog. Don't mix replies, with the changes in the patches. > 2. [High] Dangling bridge.dev pointer > [sashiko-bot] > DRM bridge framework limitation. drm_bridge_remove() does not > clear bridge.dev. All bridge > drivers using drm_kms_helper_hotplug_event() share this risk. > Requires framework-level fix. > Triggering needs root sysfs access plus DRM driver unload > simultaneously. > 3. [Medium] output_bridge not cleared prevents re-attach > [sashiko-bot] > Intentional. Same as cdns-dsi-core.c cdns_dsi_detach(). Clearing > would > cause devm_drm_of_get_bridge() to leak on re-attach. DRM bridge > framework does not support > dynamic chain reconfiguration. Panel rebind requires host driver > reload. > 4. [Low] Mutating downstream bridge's pre_enable_prev_first > [sashiko-bot] > Hardware constraint. DSI stream (0xe0b0) must be enabled after > panel power-on. Safe because > transfer() is a stub — DCS commands are discarded, panel init is > done by chip firmware. > Comment documents the rationale. > 5. [Low] Unsynchronized removed read > [sashiko-bot] > Fixed. Now protected by ocm_lock (lines 372-375). > - Link to v16: > https://lore.kernel.org/all/[email protected]/ > > Change in v16: > - dt-binding: > 1. [Low] Use standard generic DT node name > Renamed mipi-bridge@41 to bridge@41 per Devicetree spec for > standard generic names. [sashiko-bot] > - drm/bridge: > 1. [High] Prevent devm_drm_of_get_bridge() devres leak in host_attach > Added -EBUSY guard to reject re-attach, preventing devm memory > leak and use-after-free on [sashiko-bot] > panel unbind/rebind. > 2. [High] Fix double drm_bridge_remove() in lt7911exc_remove() > [sashiko-bot] > Removed the flawed list_empty() check that caused a second > drm_bridge_remove() call, > leading to double mutex_destroy() and use-after-free. > 3. [High] Clear upgrade flag before hotplug event > [sashiko-bot] > Reordered to clear upgrade = false before > drm_kms_helper_hotplug_event(), preventing modesets from > silently skipping hardware enable (0xe0b0) and causing black > screen. > 4. [Medium] Document pre_enable_prev_first override > [sashiko-bot] > Added comment explaining the hardware constraint: DSI stream > must be enabled after panel power-on. > The override is safe because transfer() is a stub — DCS commands > are discarded and panel init is > handled by chip firmware. > 5. [Medium] Guard hotplug with removed flag > [sashiko-bot] > Added !lt7911exc->removed check to prevent hotplug events during > device removal. > 6. [High] Use local variable for error handling > [sashiko-bot] > Introduced local bridge variable for IS_ERR()/PTR_ERR() checks, > ensuring output_bridge stays NULL on > failure so -EPROBE_DEFER retries are not blocked by the -EBUSY > guard. > - Link to v15: > https://lore.kernel.org/all/[email protected]/ > > Change in v15: > - dt-binding: > - drm/bridge: > 1. Remove the Reviewed-by: Dmitry Baryshkov > <[email protected]> tag. > 2. Adjust the design architecture of the chip's MIPI host and bridge. > 3. remove devm_drm_panel_bridge_add_typed and drm_of_find_panel_or_bridge > 4. Use REGCACHE_NONE to avoid cache inconsistency due to internal MCU > modifying registers asynchronously > - Link to v14: > https://lore.kernel.org/all/[email protected]/ > > Change in v14: > - dt-binding: > - drm/bridge: > 1. [High] AB-BA / self-deadlock between the bridge's ocm_lock and DRM > modeset [sashiko-bot] > locks during hotplug notification. - fixed > 2. [High] Freeing the panel bridge in lt7911exc_dsi_host_detach while it is > still > attached to the DRM bridge chain causes a Use-After-Free. - fixed > - Link to v13: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v13: > - dt-binding: > - drm/bridge: > 1. [High] Dangling pointer created during MIPI DSI host detach if the > downstream [sashiko-bot] > device is a bridge rather than a panel. - fixed > 2. [High] Firmware upgrade CRC mismatch due to unpadded partial page writes. > - hardware erases the entire flash area into a default state of > 0xff. When doing > a partial page short write,the total unwritten residual bytes on > the physical > flash sector inherently retain their 0xff state. Therefore, no > modification is required. > 3. [High] Firmware upgrade workqueue accesses `bridge.dev` without ensuring > the DRM device is alive, > leading to a Use-After-Free. - fixed > 4. [High] Regmap page selector cache desynchronization after device reset > causes firmware upgrade > commands to be routed to the wrong register page. - fixed > - Link to v12: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v12: > - dt-binding: > - drm/bridge: > 1. Move the cleanup work of drm_panel_bridge_remove() forward into > lt7911exc_dsi_host_detach(). [sashiko-bot] > 2. Do not hold any lock during lt7911exc_reset(). > - Link to v11: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v11: > - dt-binding: > - drm/bridge: > 1. Removed Reviewed-by, we would appreciate it if the maintainer could help > review this. > 2. Use devm_gpiod_get(,, GPIOD_OUT_HIGH) to fix the reset GPIO backpowering > issue. [sashiko-bot] > 3. Fixed Use-After-Free vulnerability due to dynamic DRM bridge removal in > DSI detach callback. > 4. Fixed Use-After-Free of regmap during DRM teardown because firmware > upgrade worker defeats removal safeguard. > 5. Fixed firmware upgrade performs a hardware reset, causing silent loss of > DRM state and a blank screen. > 6. Use of kmalloc for a 64KB software buffer is susceptible to memory > fragmentation failures - Fix by using kvmalloc > 7. Use the 'lt7911exc->ocm_lock' mutex and the 'lt7911exc->upgrade' flag to > resolve the race condition between > DRM atomic modeset and firmware upgrade. > 8. Use the 'lt7911exc->upgrade_lock' mutex to prevent redundant upgrades. > 9. Use the 'lt7911exc->removed' flag to prevent the driver from being > triggered to upgrade during the unload process. > - Link to v10: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v10: > - dt-binding: > - drm/bridge: > 1. Fixed the firmware upgrade error paths to always clear the upgrade > flag before returning, including firmware size validation failures > and allocation failures. > [sashiko-bot] > 2. Added proper locking in lt7911exc_atomic_pre_enable() and > lt7911exc_atomic_post_disable() to serialize register accesses with the > firmware upgrade flow and avoid concurrent I2C transactions. > 3. Added an exclusivity check in lt7911exc_dsi_host_attach() to reject > multiple > downstream attachments and prevent repeated drm_bridge_add() calls and > panel bridge leaks. > 4. Reworked lt7911exc_firmware_store() to use mutex_trylock() so concurrent > sysfs writers > immediately return -EBUSY instead of blocking behind an active firmware > upgrade. > 5. Updated the remove path to prevent new firmware upgrade work from being > queued after > device removal by setting the upgrade state before cancelling the worker. > - Link to v9: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v9: > - dt-binding: > - drm/bridge: > 1. DSI transfer callback returns success for reads without populating > [sashiko-bot] > the receive buffer, leaking uninitialized memory. - fixed it by > implementing a strict whitelist mechanism. > 2. DSI transfer callback polls for eDP video readiness before the > upstream encoder is enabled, guaranteeing a timeout. - removed > 3. The driver attempts I2C transfers while the hardware is held in > physical reset. - fixed > 4. Missing DRM_MIPI_DSI Kconfig dependency causes linker errors. - fixed > 5. request_firmware is called while holding the hardware lock and > halting the MCU, risking a system pipeline stall. - fixed > 6. Sleeping functions are called from atomic context in the DRM bridge > callbacks. - fixed > 7. lt7911exc_dsi_host_transfer bypasses the required MCU hardware halt > sequence. - fixed by > internal firmware controls the panel initialization sequence and handles > all MIPI > DSI command transmission. > - Link to v8: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v8: > - dt-binding: > - drm/bridge: > 1. Protect firmware upgrade and DRM bridge callback paths with ocm_lock. > [sashiko-bot] > 2. Remove the hardware reset from the remove callback, and ensure that > all hardware reset operations are protected by ocm_lock. > 3. crc reconstruction explicitly casts each byte to u32 before shifting > 4. The display configuration is handled by the firmware, and the MIPI > DSI host registration issue has been fixed. > 5. The batch register read/write operations have already been updated > to include return value checking. > 6. The dev_err_probe() used outside of probe context has been fixed. > - Link to v7: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v7: > - dt-binding: > 1. fix commit message typos(Receiver、signal) > [sashiko-bot] > 2. remove the ambiguity caused by "signal/dual". > - drm/bridge: > 1. using devm_regulator_get_enable avoids power leaks. > [sashiko-bot] > 2. set reset gpio is low after cutting off power in lt7911exc_remove > function, avoid backpowering. > 3. synchronous request_firmware() call cause a permanent probe failure if > the driver is built-in, > probe executes before the root filesystem is mounted, which would cause > this to fail with -ENOENT, > we have removed this functionality. Use trigger to upgrade. > 4. add `depends on I2C` and `select REGMAP_I2C` in Kconfig. > 5. add return value of `devm_drm_bridge_add()` in `probe()`. > 6. add directly header files (linux/slab.h, linux/delay.h, > linux/regulator/consumer.h) > - Link to v6: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v6: > - dt-binding: > - drm/bridge: > 1. use #define FW_FILE "Lontium/lt7911exc_fw.bin" to match linux-firmware > - Link to v5: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v5: > - dt-binding: > - drm/bridge: > 1. Change "mipi" to "mipi dsi" in the commit message. [Dmitry] > 2. Change "eDP/MIPI" to "eDP/MIPI DSI" in Kconfig. > - Link to v4: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v4: > - dt-binding: > 1. Fix the missing spaces on the "subject". [Krzysztof] > 2. Fix the error descriptions for port@0 and port@1. > - drm/bridge: > - Link to v3: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v3: > - dt-binding: > - drm/bridge: > 1. already submit lt7911exc_fw.bin to linux-firmware. [Dmitry] > 2. remove lt7911exc_remove function. > 3. drop the "lontium, " in lt7911exc_i2c_table. > - Link to v2: > https://lore.kernel.org/lkml/[email protected]/ > > Change in v2: > - dt-binding: > 1. reset pins use active low. [Dmitry] > - drm/bridge: > 1. use atomic_* callbacks. [Quentin] > 2. fix the incorrect formatting and spaces. > 3. add the required header files. [Dmitry] > 4. remove "enabled" flag. > 5. remove *fw from the lt7911exc struct. > 6. .max_register and .range_max use actual range. > 7. regulator use bulk interface. > 8. use dev_err_probe, devm_mutex_init and devm_drm_bridge_add. > 9. Replace GPL v2 with GPL. > - Link to v1: > https://lore.kernel.org/lkml/[email protected]/ > > --- > Sunyun Yang (2): > dt-bindings: bridge: Add Lontium LT7911EXC eDP to MIPI DSI bridge > drm/bridge: Add Lontium LT7911EXC eDP to MIPI DSI bridge > > .../display/bridge/lontium,lt7911exc.yaml | 89 ++ > drivers/gpu/drm/bridge/Kconfig | 17 + > drivers/gpu/drm/bridge/Makefile | 1 + > drivers/gpu/drm/bridge/lontium-lt7911exc.c | 787 ++++++++++++++++++ > 4 files changed, 894 insertions(+) > create mode 100644 > Documentation/devicetree/bindings/display/bridge/lontium,lt7911exc.yaml > create mode 100644 drivers/gpu/drm/bridge/lontium-lt7911exc.c > > -- > 2.34.1 > -- With best wishes Dmitry
