From: sashiko-bot@kernel.org
To: "Sebastian Reichel" <sebastian.reichel@collabora.com>
Cc: conor+dt@kernel.org, robh@kernel.org,
dri-devel@lists.freedesktop.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v4 01/10] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback
Date: Tue, 21 Jul 2026 18:05:19 +0000 [thread overview]
Message-ID: <20260721180520.1AD241F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260721-synopsys-dw-dp-improvements-v4-1-f0f4a4ede712@collabora.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [Critical] Missing `cancel_work_sync(&dp->hpd_work)` during unbind allows the workqueue to execute after the device is unbound and removed, leading to a Use-After-Free.
--
--- Patch [1]: [PATCH v4 01/10] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback ---
commit ad3d9fe60dfef89b2bbe919cc696921df60e683f
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback
This commit introduces a new probe helper function to acquire resources early
rather than during the bind callback. This aligns resource allocation with
device lifecycle instead of driver bind and unbind time.
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
[ ... ]
> +void dw_dp_unbind(struct dw_dp *dp)
> +{
> + disable_irq(dp->irq);
> phy_exit(dp->phy);
> + drm_dp_aux_unregister(&dp->aux);
> + drm_bridge_remove(&dp->bridge);
> }
[Severity: Critical]
This is a pre-existing issue, but could this leave pending work items
running after the device is unbound?
If an HPD interrupt fires right before or during dw_dp_unbind(), the
interrupt handler schedules dp->hpd_work. While disable_irq() prevents
new interrupts, it doesn't cancel already pending work.
When the driver is subsequently removed and the devm-allocated dp structure
is freed, the system workqueue could execute dw_dp_hpd_work() and trigger a
use-after-free on the released memory.
Would it be appropriate to add cancel_work_sync(&dp->hpd_work) here during
the teardown sequence?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260721-synopsys-dw-dp-improvements-v4-0-f0f4a4ede712@collabora.com?part=1
next prev parent reply other threads:[~2026-07-21 18:05 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-21 17:52 [PATCH v4 00/10] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
2026-07-21 17:52 ` Sebastian Reichel
2026-07-21 17:52 ` [PATCH v4 01/10] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback Sebastian Reichel
2026-07-21 17:52 ` Sebastian Reichel
2026-07-21 18:05 ` sashiko-bot [this message]
2026-07-21 17:52 ` [PATCH v4 02/10] drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED Sebastian Reichel
2026-07-21 17:52 ` Sebastian Reichel
2026-07-21 18:05 ` sashiko-bot
2026-07-21 17:52 ` [PATCH v4 03/10] drm/bridge: synopsys: dw-dp: Add follow-up bridge support Sebastian Reichel
2026-07-21 17:52 ` Sebastian Reichel
2026-07-21 18:04 ` sashiko-bot
2026-07-21 17:52 ` [PATCH v4 04/10] drm/bridge: Add out-of-band HPD notify handler Sebastian Reichel
2026-07-21 17:52 ` Sebastian Reichel
2026-07-21 17:52 ` [PATCH v4 05/10] drm/bridge: synopsys: dw-dp: Support software triggered OOB HPD Sebastian Reichel
2026-07-21 17:52 ` Sebastian Reichel
2026-07-21 18:14 ` sashiko-bot
2026-07-21 17:52 ` [PATCH v4 06/10] drm/rockchip: dw_dp: Implement out-of-band HPD handling Sebastian Reichel
2026-07-21 17:52 ` Sebastian Reichel
2026-07-21 18:15 ` sashiko-bot
2026-07-21 17:52 ` [PATCH v4 07/10] drm/bridge: synopsys: dw-dp: Add Runtime PM support Sebastian Reichel
2026-07-21 17:52 ` Sebastian Reichel
2026-07-21 18:16 ` sashiko-bot
2026-07-21 17:52 ` [PATCH v4 08/10] drm/rockchip: dw_dp: Add runtime " Sebastian Reichel
2026-07-21 17:52 ` Sebastian Reichel
2026-07-21 18:23 ` sashiko-bot
2026-07-21 17:52 ` [PATCH v4 09/10] dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells Sebastian Reichel
2026-07-21 17:52 ` Sebastian Reichel
2026-07-21 18:26 ` sashiko-bot
2026-07-22 7:22 ` Krzysztof Kozlowski
2026-07-22 7:22 ` Krzysztof Kozlowski
2026-07-21 17:52 ` [PATCH v4 10/10] drm/bridge: synopsys: dw-dp: Add audio support Sebastian Reichel
2026-07-21 17:52 ` Sebastian Reichel
2026-07-21 18:25 ` sashiko-bot
2026-07-22 8:06 ` Alexey Charkov
2026-07-22 8:06 ` Alexey Charkov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260721180520.1AD241F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sebastian.reichel@collabora.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.