Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [Medium] drm/vc4: bridge reference leak on component bind failure or rebind
--

commit 583ab26f73be63066db6ca20da5c1de3ee1767ef
Author: Luca Ceresoli <[email protected]>

drm/vc4: dsi: stop using deprecated drmm_of_get_bridge()

This commit replaces the deprecated drmm_of_get_bridge() with
of_drm_get_bridge_by_endpoint() to acquire the DRM bridge. It assigns the
returned refcounted bridge to dsi->bridge.next_bridge to rely on automatic
cleanup upon destruction.

> diff --git a/drivers/gpu/drm/vc4/vc4_dsi.c b/drivers/gpu/drm/vc4/vc4_dsi.c
> index 0148f2befed14..30598738cfcf3 100644
> --- a/drivers/gpu/drm/vc4/vc4_dsi.c
> +++ b/drivers/gpu/drm/vc4/vc4_dsi.c

[ ... ]

> @@ -1749,9 +1747,9 @@ static int vc4_dsi_bind(struct device *dev, struct 
> device *master, void *data)
>               return ret;
>       }
>  
> -     dsi->out_bridge = drmm_of_get_bridge(drm, dev->of_node, 0, 0);
> -     if (IS_ERR(dsi->out_bridge))
> -             return PTR_ERR(dsi->out_bridge);
> +     dsi->bridge.next_bridge = of_drm_get_bridge_by_endpoint(dev->of_node, 
> 0, 0);
> +     if (IS_ERR(dsi->bridge.next_bridge))
> +             return PTR_ERR(dsi->bridge.next_bridge);
>  
>       /* The esc clock rate is supposed to always be 100Mhz. */
>       ret = clk_set_rate(dsi->escape_clock, 100 * 1000000);

[Severity: Medium]
Does this code leak the bridge reference if vc4_dsi_bind() fails here or in
subsequent initialization steps?

Since of_drm_get_bridge_by_endpoint() returns a refcounted pointer (unlike
the previous devm-managed drmm_of_get_bridge()), if clk_set_rate() fails
just below this hunk, the function returns without putting the newly
acquired reference.

If the aggregate DRM device defers probe and retries binding components,
vc4_dsi_bind() could run again, overwriting dsi->bridge.next_bridge and
permanently leaking the previous reference. The automatic cleanup of
next_bridge only happens when dsi->bridge is destroyed, which does not
occur during component bind failures or component unbinds.

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/20260929-drm-fix-of_get_bridge-build-regression-v2-0-6da431d8f...@bootlin.com?part=6

Reply via email to