Am Mittwoch, 24. Juni 2026, 14:31:37 CEST schrieb [email protected]: > Thank you for your contribution! Sashiko AI review found 1 potential issue(s) > to consider: > > Pre-existing issues: > - [High] The bridge detach function `tc_edp_bridge_detach` does not call > `drm_connector_cleanup()` for the connector initialized in > `tc_edp_bridge_attach()`, leading to a use-after-free when the module unloads. > -- > > commit 29555064108dbff74cdded5aeba9baee8adfd8a7 > Author: Alexander Stein <[email protected]> > > drm/bridge: tc358767: register DP aux bus even in > DRM_BRIDGE_ATTACH_NO_CONNECTOR case > > This commit changes the bridge attach sequence to always register the DP aux > bus. It achieves this by moving the check for the no-connector flag to after > the aux registration is complete. > > > diff --git a/drivers/gpu/drm/bridge/tc358767.c > > b/drivers/gpu/drm/bridge/tc358767.c > > index 7188935fdb826..a1663cc6c2236 100644 > > --- a/drivers/gpu/drm/bridge/tc358767.c > > +++ b/drivers/gpu/drm/bridge/tc358767.c > > @@ -1833,14 +1833,14 @@ static int tc_edp_bridge_attach(struct drm_bridge > > *bridge, > > return ret; > > } > > > > - if (flags & DRM_BRIDGE_ATTACH_NO_CONNECTOR) > > - return 0; > > - > > tc->aux.drm_dev = drm; > > ret = drm_dp_aux_register(&tc->aux); > > if (ret < 0) > > return ret; > > > > + if (flags & DRM_BRIDGE_ATTACH_NO_CONNECTOR) > > + return 0; > > + > > /* Create DP/eDP connector */ > > drm_connector_helper_add(&tc->connector, &tc_connector_helper_funcs); > > ret = drm_connector_init(drm, &tc->connector, &tc_connector_funcs, > > tc->bridge.type); > > [Severity: High] > This isn't a bug introduced by this patch, but is a pre-existing issue. Does > tc_edp_bridge_detach() properly clean up the connector initialized here? > > Looking at the detach function in drivers/gpu/drm/bridge/tc358767.c: > > static void tc_edp_bridge_detach(struct drm_bridge *bridge) > { > drm_dp_aux_unregister(&bridge_to_tc(bridge)->aux); > } > > It seems drm_connector_cleanup() is never called for tc->connector.
drm_connector_cleanup() is called from the drm_connector_funcs::destroy. > > Since tc_data (which embeds the connector) is allocated via devm_kzalloc, > could the freed connector remain linked in the active drm_device connector > list when the driver is unbound? What I can see is that the connector is removed from the list in drm_connector_remove() called by drm_connector_cleanup(). > Would this cause a use-after-free if the DRM core accesses the connector list > after the module is unloaded or unbound? > > -- TQ-Systems GmbH | Mühlstraße 2, Gut Delling | 82229 Seefeld, Germany Amtsgericht München, HRB 105018 Geschäftsführer: Detlef Schneider, Rüdiger Stahl, Stefan Schneider http://www.tq-group.com/
