All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Daniel Golle" <daniel@makrotopia.org>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v6 03/13] drm/bridge: it6505: unregister DP AUX adapter on bridge detach
Date: Sat, 25 Jul 2026 03:17:09 +0000	[thread overview]
Message-ID: <20260725031709.818A51F000E9@smtp.kernel.org> (raw)
In-Reply-To: <e18f8cf3b9c6993c9d628f28f64b0f39c111e2a7.1784947240.git.daniel@makrotopia.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Removing `drm_dp_aux_unregister()` from the I2C `remove` function causes a use-after-free and leaves a zombie DP AUX adapter if the I2C driver is unbound while the DRM device remains attached.
--

--- Patch [3]: [PATCH v6 03/13] drm/bridge: it6505: unregister DP AUX adapter on bridge detach ---
commit d6c69e9e1c11461da60c039acb301f1120930d47
Author: Daniel Golle <daniel@makrotopia.org>

drm/bridge: it6505: unregister DP AUX adapter on bridge detach

This commit moves the DP AUX adapter unregistration from the I2C remove
routine to the DRM bridge detach and attach error paths, to avoid
registering the adapter multiple times during unbind/rebind cycles.

> diff --git a/drivers/gpu/drm/bridge/ite-it6505.c b/drivers/gpu/drm/bridge/ite-it6505.c
> index 7c61b02cc7e60..c10cc6a786b5d 100644
> --- a/drivers/gpu/drm/bridge/ite-it6505.c
> +++ b/drivers/gpu/drm/bridge/ite-it6505.c
[ ... ]
> @@ -3106,6 +3107,7 @@ static void it6505_bridge_detach(struct drm_bridge *bridge)
>  
>  	flush_work(&it6505->link_works);
>  	it6505_remove_notifier_module(it6505);
> +	drm_dp_aux_unregister(&it6505->aux);
>  }
>  
[ ... ]
> @@ -3654,7 +3656,6 @@ static void it6505_i2c_remove(struct i2c_client *client)
>  	struct it6505 *it6505 = i2c_get_clientdata(client);
>  
>  	drm_bridge_remove(&it6505->bridge);
> -	drm_dp_aux_unregister(&it6505->aux);

[Severity: High]
Does removing drm_dp_aux_unregister() here cause a use-after-free if the I2C
driver is unbound while the DRM device is still attached?

If the I2C driver is unbound (e.g., via sysfs) while the DRM display
controller is still bound, it6505_i2c_remove() is called. The
drm_bridge_remove() call only moves the bridge to a lingering list and
does not immediately call it6505_bridge_detach().

Because drm_dp_aux_unregister() was removed from this path, the AUX adapter
remains registered. When the remove function returns, devres frees the
it6505 structure. 

Could a local user trigger a use-after-free by accessing the leaked
/dev/drm_dp_auxN character device or I2C sysfs nodes which now point to
the freed structure?

Since i2c_del_adapter() and drm_dp_aux_unregister_devnode() both contain
safety guards against unregistered adapters, is it safer to leave
drm_dp_aux_unregister() in the remove path as well to ensure it is always
unregistered before devres frees the memory?

>  	it6505_debugfs_remove(it6505);
>  	it6505_remove_notifier_module(it6505);
>  	disable_irq(it6505->irq);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1784947240.git.daniel@makrotopia.org?part=3

  reply	other threads:[~2026-07-25  3:17 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-25  2:57 [PATCH v6 00/13] drm/bridge: it6505: DP audio support + shared-DAI hw_params fix Daniel Golle
2026-07-25  2:58 ` [PATCH v6 01/13] drm/bridge: it6505: quiesce event sources and work on remove() Daniel Golle
2026-07-25  3:23   ` sashiko-bot
2026-07-25  2:58 ` [PATCH v6 02/13] drm/bridge: it6505: balance and disable runtime PM on remove Daniel Golle
2026-07-25  3:18   ` sashiko-bot
2026-07-25  2:58 ` [PATCH v6 03/13] drm/bridge: it6505: unregister DP AUX adapter on bridge detach Daniel Golle
2026-07-25  3:17   ` sashiko-bot [this message]
2026-07-25  2:58 ` [PATCH v6 04/13] drm/bridge: it6505: complete poweroff even if disabling regulators fails Daniel Golle
2026-07-25  3:17   ` sashiko-bot
2026-07-25  2:58 ` [PATCH v6 05/13] drm/bridge: it6505: bail out of the IRQ handler when status reads fail Daniel Golle
2026-07-25  2:59 ` [PATCH v6 06/13] drm/bridge: it6505: avoid division by zero in pixel clock calculation Daniel Golle
2026-07-25  3:20   ` sashiko-bot
2026-07-25  2:59 ` [PATCH v6 07/13] drm/bridge: it6505: avoid division by zero in audio FS debug print Daniel Golle
2026-07-25  3:16   ` sashiko-bot
2026-07-25  2:59 ` [PATCH v6 08/13] drm/bridge: it6505: guard against zero channel count in audio infoframe Daniel Golle
2026-07-25  3:00 ` [PATCH v6 09/13] drm/bridge: it6505: hold endpoint OF node reference while parsing it Daniel Golle
2026-07-25  3:15   ` sashiko-bot
2026-07-25  3:00 ` [PATCH v6 10/13] drm/bridge: it6505: reject a too short link-frequencies property Daniel Golle
2026-07-25  3:00 ` [PATCH v6 11/13] drm/bridge: it6505: don't write an error code back to the reset register Daniel Golle
2026-07-25  3:19   ` sashiko-bot
2026-07-25  3:01 ` [PATCH v6 12/13] drm/bridge: it6505: Add audio support Daniel Golle
2026-07-25  5:25   ` sashiko-bot
2026-07-25  3:01 ` [PATCH v6 13/13] drm/bridge: it6505: Don't reject audio hw_params without an encoder Daniel Golle

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260725031709.818A51F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=daniel@makrotopia.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.