Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [Medium] drm/bridge: dw-mipi-dsi2: memory leak of downstream bridge reference
--

commit 3a105594a4d4f8c22ed3e9167fb40a2696227085
Author: Luca Ceresoli <[email protected]>

drm/bridge: dw-mipi-dsi2: stop using deprecated devm_drm_of_get_bridge()

This commit replaces the deprecated devm_drm_of_get_bridge() function with
of_drm_get_bridge_by_endpoint(), which returns a refcounted bridge. It updates
the code to store the acquired bridge in the next_bridge field of the
drm_bridge structure so that the reference is automatically released when the
parent bridge is destroyed.

> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-mipi-dsi2.c 
> b/drivers/gpu/drm/bridge/synopsys/dw-mipi-dsi2.c
> index 7fd2f1e60654f..a008450d83aa3 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-mipi-dsi2.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-mipi-dsi2.c
> @@ -528,12 +527,12 @@ static int dw_mipi_dsi2_host_attach(struct 
> mipi_dsi_host *host,
>       dsi2->format = device->format;
>       dsi2->mode_flags = device->mode_flags;
>  
> -     bridge = devm_drm_of_get_bridge(dsi2->dev, dsi2->dev->of_node, 1, 0);
> +     bridge = of_drm_get_bridge_by_endpoint(dsi2->dev->of_node, 1, 0);
>       if (IS_ERR(bridge))
>               return PTR_ERR(bridge);
>  
>       bridge->pre_enable_prev_first = true;
> -     dsi2->panel_bridge = bridge;
> +     dsi2->bridge.next_bridge = bridge;

[Severity: Medium]
Does this assignment potentially leak the bridge reference if the error path is
taken later in dw_mipi_dsi2_host_attach()?

The DRM core automatically drops the next_bridge reference when the parent
bridge is freed (at driver unbind). However, if pdata->host_ops->attach()
fails later in this function, the error path calls drm_bridge_remove() but
next_bridge is not explicitly cleared or manually put.

If the DSI peripheral later triggers another attach attempt, will a new
reference overwrite next_bridge, permanently leaking the previous one?

>  
>       drm_bridge_add(&dsi2->bridge);
>  

[ ... ]

> @@ -565,8 +564,6 @@ static int dw_mipi_dsi2_host_detach(struct mipi_dsi_host 
> *host,
>  
>       drm_bridge_remove(&dsi2->bridge);
>  
> -     drm_of_panel_bridge_remove(host->dev->of_node, 1, 0);
> -
>       return 0;
>  }

[Severity: Medium]
Does this detach path also leak the downstream bridge reference if the DSI
device is unbound and rebound?

Similar to the error path in dw_mipi_dsi2_host_attach(), detaching removes the
bridge from the list but leaves the refcounted pointer in
dsi2->bridge.next_bridge without putting it. On the next attach attempt, a new
reference will be acquired and assigned, potentially stranding the previous
reference.

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/20260929-drm-fix-of_get_bridge-build-regression-v1-0-ccb7e602d...@bootlin.com?part=4

Reply via email to