Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [High] drm/vc4: dsi: bridge reference leak on bind failure/retry
--

commit d1b5b987d3dbb5f94782b8b596d7895539b38c8d
Author: Luca Ceresoli <[email protected]>

drm/vc4: dsi: stop using deprecated drmm_of_get_bridge()

This commit replaces the deprecated devm_drm_of_get_bridge() with
of_drm_get_bridge_by_endpoint(), storing the refcounted bridge in
dsi->bridge.next_bridge. It also removes an unused include.

> diff --git a/drivers/gpu/drm/vc4/vc4_dsi.c b/drivers/gpu/drm/vc4/vc4_dsi.c
> index 0148f2befed14..30598738cfcf3 100644
> --- a/drivers/gpu/drm/vc4/vc4_dsi.c
> +++ b/drivers/gpu/drm/vc4/vc4_dsi.c
[ ... ]
> @@ -1749,9 +1747,9 @@ static int vc4_dsi_bind(struct device *dev, struct 
> device *master, void *data)
>               return ret;
>       }
>  
> -     dsi->out_bridge = drmm_of_get_bridge(drm, dev->of_node, 0, 0);
> -     if (IS_ERR(dsi->out_bridge))
> -             return PTR_ERR(dsi->out_bridge);
> +     dsi->bridge.next_bridge = of_drm_get_bridge_by_endpoint(dev->of_node, 
> 0, 0);
> +     if (IS_ERR(dsi->bridge.next_bridge))
> +             return PTR_ERR(dsi->bridge.next_bridge);

[Severity: High]
Does this leak the bridge reference if a subsequent initialization step fails?

If a later call in vc4_dsi_bind() fails or returns -EPROBE_DEFER, the function
exits without putting the newly acquired bridge reference. For example, further
down in vc4_dsi_bind():

        ret = drm_bridge_attach(encoder, &dsi->bridge, NULL, 0);
        if (ret)
                return ret;

Because the component framework tears down the drm_device and its actions
on failure, the drmm cleanup runs vc4_dsi_release_action() which drops the
dsi->bridge refcount. However, because the refcount does not reach 0,
__drm_bridge_free() is not called and the next_bridge pointer is never put
or cleared.

When the bind is retried, of_drm_get_bridge_by_endpoint() is called again,
overwriting dsi->bridge.next_bridge and permanently leaking the previous
reference.

Is there a missing drm_bridge_put() or cleanup path to ensure the reference
is dropped when vc4_dsi_bind() fails?

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/20260929-drm-fix-of_get_bridge-build-regression-v1-0-ccb7e602d...@bootlin.com?part=6

Reply via email to