Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [Medium] drm: memory leak in dw_mipi_dsi_host_attach/detach due to missing 
drm_bridge_put
--

commit 0d4a3bc896ba6f4b2176531a2fbcc45a4c4762cd
Author: Luca Ceresoli <[email protected]>

drm/bridge: dw-mipi-dsi: stop using deprecated devm_drm_of_get_bridge()

This commit switches from the deprecated devm_drm_of_get_bridge() to
of_drm_get_bridge_by_endpoint(). It assigns the returned refcounted bridge to
dsi->bridge.next_bridge to handle cleanup.

Link: https://lore.kernel.org/r/[email protected]

> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-mipi-dsi.c 
> b/drivers/gpu/drm/bridge/synopsys/dw-mipi-dsi.c
> index 5dd475fcaacf8..fad6c3f710324 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-mipi-dsi.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-mipi-dsi.c

[ ... ]

> @@ -333,12 +332,12 @@ static int dw_mipi_dsi_host_attach(struct mipi_dsi_host 
> *host,
>       dsi->format = device->format;
>       dsi->mode_flags = device->mode_flags;
>  
> -     bridge = devm_drm_of_get_bridge(dsi->dev, dsi->dev->of_node, 1, 0);
> +     bridge = of_drm_get_bridge_by_endpoint(dsi->dev->of_node, 1, 0);
>       if (IS_ERR(bridge))
>               return PTR_ERR(bridge);
>  
>       bridge->pre_enable_prev_first = true;
> -     dsi->panel_bridge = bridge;
> +     dsi->bridge.next_bridge = bridge;

[Severity: Medium]
Does this leak the bridge reference if the peripheral driver is manually
unbound and rebound?

Because of_drm_get_bridge_by_endpoint() returns a refcounted bridge, each
attach/detach cycle fetches a new reference. Overwriting next_bridge here
without releasing the previous reference could lead to a memory leak.

Also, what happens if the attach fails later in this function?

err_remove_bridge:
        drm_bridge_remove(&dsi->bridge);
        return ret;

It looks like the acquired bridge reference is left dangling in next_bridge
without being put on this error path.

>  
>       drm_bridge_add(&dsi->bridge);

[ ... ]

> @@ -368,8 +367,6 @@ static int dw_mipi_dsi_host_detach(struct mipi_dsi_host 
> *host,
>                       return ret;
>       }
>  
> -     drm_of_panel_bridge_remove(host->dev->of_node, 1, 0);
> -
>       drm_bridge_remove(&dsi->bridge);
>  
>       return 0;

[Severity: Medium]
Does this detach path leave the bridge reference unreleased?

The commit message notes that the bridge is put by using bridge.next_bridge,
but the host bridge (dsi->bridge) is not freed during peripheral detach, it
is only removed from the list.

Is a drm_bridge_put() needed here to balance the get from
of_drm_get_bridge_by_endpoint() in dw_mipi_dsi_host_attach()?

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/20260929-drm-fix-of_get_bridge-build-regression-v1-0-ccb7e602d...@bootlin.com?part=3

Reply via email to