All of lore.kernel.org
 help / color / mirror / Atom feed
From: David Carlier <devnexen@gmail.com>
To: neil.armstrong@linaro.org, mitltlatltl@gmail.com
Cc: jesszhan0024@gmail.com, maarten.lankhorst@linux.intel.com,
	mripard@kernel.org, tzimmermann@suse.de, airlied@gmail.com,
	simona@ffwll.ch, dri-devel@lists.freedesktop.org,
	linux-kernel@vger.kernel.org, David Carlier <devnexen@gmail.com>
Subject: [PATCH] drm/panel: novatek-nt36536: Fix panel double-remove on attach failure
Date: Fri, 24 Jul 2026 05:17:46 +0100	[thread overview]
Message-ID: <20260724041746.12887-1-devnexen@gmail.com> (raw)

The DSI attach error path calls drm_panel_remove() by hand even though
the panel was registered with devm_drm_panel_add(), which already
arranges for drm_panel_remove() to run on driver detach. When
mipi_dsi_attach() fails the panel is therefore removed twice: once
directly and once again while devres unwinds.

drm_panel_add() takes a reference and drm_panel_remove() drops one, so
the extra removal releases the last reference early and frees the panel
container. The put registered by devm_drm_panel_alloc() then operates on
freed memory, resulting in a use-after-free and a reference-count
underflow when a DSI host rejects the requested configuration during
probe.

Drop the manual drm_panel_remove() and let the managed cleanup handle
it, matching the other dual-DSI panel drivers.

Fixes: 75a5dbd1f4f7 ("drm/panel: Add Novatek NT36536 panel driver")
Signed-off-by: David Carlier <devnexen@gmail.com>
---
 drivers/gpu/drm/panel/panel-novatek-nt36536.c | 4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/drivers/gpu/drm/panel/panel-novatek-nt36536.c b/drivers/gpu/drm/panel/panel-novatek-nt36536.c
index 2a82b54880c3..8bd125650168 100644
--- a/drivers/gpu/drm/panel/panel-novatek-nt36536.c
+++ b/drivers/gpu/drm/panel/panel-novatek-nt36536.c
@@ -429,11 +429,9 @@ static int novatek_probe(struct mipi_dsi_device *dsi)
 		ctx->dsi[i]->mode_flags = desc->mode_flags;
 		ctx->dsi[i]->dsc = &ctx->dsc;
 		ret = devm_mipi_dsi_attach(dev, ctx->dsi[i]);
-		if (ret < 0) {
-			drm_panel_remove(&ctx->panel);
+		if (ret < 0)
 			return dev_err_probe(dev, ret,
 					     "Failed to attach to DSI host\n");
-		}
 	}
 
 	if (desc->has_dcs_backlight) {
-- 
2.53.0


                 reply	other threads:[~2026-07-24  4:17 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260724041746.12887-1-devnexen@gmail.com \
    --to=devnexen@gmail.com \
    --cc=airlied@gmail.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=jesszhan0024@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=maarten.lankhorst@linux.intel.com \
    --cc=mitltlatltl@gmail.com \
    --cc=mripard@kernel.org \
    --cc=neil.armstrong@linaro.org \
    --cc=simona@ffwll.ch \
    --cc=tzimmermann@suse.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.