Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [High] mm: memory leak of msm_dp_panel during DRM master bind/unbind
--

commit cfe400464204530420fa599c1a7624cb1685cc3b
Author: Yongxing Mou <[email protected]>

drm/msm/dpu: add per-stream MST encoders

This commit establishes the per-stream encoder infrastructure required for
DP MST support. It creates one DRM encoder per MST stream, associates it
with a stream ID, and initializes it with MST-specific encoder helper
callbacks.

[ ... ]
> diff --git a/drivers/gpu/drm/msm/dp/dp_mst_drm.c 
> b/drivers/gpu/drm/msm/dp/dp_mst_drm.c
> index 169b34f985c0e..88687b97ed6e6 100644
> --- a/drivers/gpu/drm/msm/dp/dp_mst_drm.c
> +++ b/drivers/gpu/drm/msm/dp/dp_mst_drm.c
> @@ -145,6 +145,26 @@ static int msm_dp_mst_encoder_stream_id(struct 
> msm_dp_mst *mst,
>       return -1;
>  }
>  
> +int msm_dp_mst_attach_encoder(struct msm_dp *dp_display, unsigned int 
> stream_id,
> +                           struct drm_encoder *encoder)
> +{
> +     struct msm_dp_mst *mst = dp_display->msm_dp_mst;
> +     struct msm_dp_panel *dp_panel;
> +
> +     dp_panel = msm_dp_display_get_panel(dp_display, stream_id);

[Severity: High]
Does this code leak the struct msm_dp_panel allocations on DRM master
bind/unbind cycles?

When KMS initialization executes during the DRM master bind sequence, it
calls msm_dp_mst_attach_encoder(). This in turn allocates a new panel for
each stream via the following chain:

msm_dp_mst_attach_encoder()
  msm_dp_display_get_panel()
    msm_dp_panel_get(&dp->msm_dp_display.pdev->dev, ...)
      devm_kzalloc(dev, sizeof(*panel), GFP_KERNEL);

The devres allocation is anchored to the persistent subordinate DP platform
device rather than the ephemeral DRM master device. When the DRM master is
unbound, KMS is torn down but the DP platform device remains bound. On the
next DRM master bind cycle, new panels are allocated on the same DP
platform device, permanently leaking the previous allocations.

Can this lead to resource exhaustion if a user repeatedly unbinds and binds
the DRM master via sysfs?

> +     if (!dp_panel) {
> +             drm_err(dp_display->drm_dev,
> +                     "[MST] failed to allocate panel for stream %d\n", 
> stream_id);
> +             return -ENOMEM;
> +     }
> +
> +     mst->mst_encoders[stream_id].enc = encoder;
> +     mst->mst_encoders[stream_id].stream_id = stream_id;
> +     mst->mst_encoders[stream_id].dp_panel = dp_panel;
> +
> +     return 0;
> +}
[ ... ]

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=22

Reply via email to