All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Sebastian Reichel" <sebastian.reichel@collabora.com>
Cc: robh@kernel.org, devicetree@vger.kernel.org, conor+dt@kernel.org,
	dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v7 09/18] drm/bridge: Add out-of-band HPD notify handler
Date: Tue, 28 Jul 2026 19:19:43 +0000	[thread overview]
Message-ID: <20260728191943.7EEC81F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260728-synopsys-dw-dp-improvements-v7-9-b7640fa8cf48@collabora.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Potential Use-After-Free of the connector and encoder due to missing DRM device reference in OOB hotplug event handling.
--

--- Patch [9]: [PATCH v7 09/18] drm/bridge: Add out-of-band HPD notify handler ---
commit 60a32b50437d6f06ebb30ed7d8a1cc757f684526
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
Subject: drm/bridge: Add out-of-band HPD notify handler

This commit adds an out-of-band hotplug detection notify handler to the DRM
bridge structure. It allows notifying all bridges in a pipeline of hotplug
events, which is useful for forcing DP controllers HPD signals for USB-C DP
AltMode.

> diff --git a/drivers/gpu/drm/display/drm_bridge_connector.c b/drivers/gpu/drm/display/drm_bridge_connector.c
> index 8b54069fa53a4..632cc3ae3b544 100644
> --- a/drivers/gpu/drm/display/drm_bridge_connector.c
> +++ b/drivers/gpu/drm/display/drm_bridge_connector.c
> @@ -180,6 +180,12 @@ static void drm_bridge_connector_oob_hotplug_event(struct drm_connector *connect
>  	struct drm_bridge_connector *bridge_connector =
>  		to_drm_bridge_connector(connector);
>  
> +	/* Notify all bridges in the pipeline of hotplug events. */
> +	drm_for_each_bridge_in_chain(bridge_connector->encoder, bridge) {

[Severity: High]
This is a pre-existing issue, but I have a question about the use of
bridge_connector->encoder and connector here.

The Type-C subsystem calls drm_connector_oob_hotplug_event() in
drivers/gpu/drm/drm_connector.c, which acquires a reference to the
connector via drm_connector_find_by_fwnode().

However, drm_connector_get() only increments the connector's internal
kref, not the refcount of the parent drm_device.

If the DRM driver is concurrently unbound (e.g., via sysfs) during a
hotplug event, the drm_device refcount can drop to 0.

This triggers drmm_ cleanup handlers that free the drmm_kzalloc'ed
connector memory while the Type-C subsystem is still executing
connector->funcs->oob_hotplug_event().

Could this lead to accessing a freed bridge_connector->encoder and
passing the freed connector object down the stack to the newly added
oob_notify callbacks?

> +		if (bridge->funcs->oob_notify)
> +			bridge->funcs->oob_notify(bridge, connector, status);
> +	}
> +
>  	drm_bridge_connector_handle_hpd(bridge_connector, status);
>  }
>  

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260728-synopsys-dw-dp-improvements-v7-0-b7640fa8cf48@collabora.com?part=9

  reply	other threads:[~2026-07-28 19:19 UTC|newest]

Thread overview: 50+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-28 17:40 [PATCH v7 00/18] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
2026-07-28 17:40 ` Sebastian Reichel
2026-07-28 17:40 ` [PATCH v7 01/18] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 17:59   ` sashiko-bot
2026-07-28 17:40 ` [PATCH v7 02/18] drm/bridge: synopsys: dw-dp: Cancel pending HPD work on unbind Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 18:09   ` sashiko-bot
2026-07-28 17:40 ` [PATCH v7 03/18] drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 18:20   ` sashiko-bot
2026-07-28 17:40 ` [PATCH v7 04/18] drm/bridge: synopsys: dw-dp: Add missing reinit_completion Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 18:34   ` sashiko-bot
2026-07-28 17:40 ` [PATCH v7 05/18] drm/bridge: synopsys: dw-dp: Reset AUX channel on transfer timeout Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 18:43   ` sashiko-bot
2026-07-28 17:40 ` [PATCH v7 06/18] drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 17:40 ` [PATCH v7 07/18] drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 17:40 ` [PATCH v7 08/18] drm/bridge: synopsys: dw-dp: Add follow-up bridge support Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 17:40 ` [PATCH v7 09/18] drm/bridge: Add out-of-band HPD notify handler Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 19:19   ` sashiko-bot [this message]
2026-07-28 17:40 ` [PATCH v7 10/18] drm/bridge: synopsys: dw-dp: Support software triggered OOB HPD Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 17:40 ` [PATCH v7 11/18] drm/rockchip: dw_dp: Implement out-of-band HPD handling Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 19:41   ` sashiko-bot
2026-07-28 17:40 ` [PATCH v7 12/18] drm/bridge: synopsys: dw-dp: Add Runtime PM support Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 19:58   ` sashiko-bot
2026-07-28 17:40 ` [PATCH v7 13/18] drm/rockchip: dw_dp: Add runtime " Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 20:14   ` sashiko-bot
2026-07-28 17:40 ` [PATCH v7 14/18] drm/bridge: synopsys: dw-dp: Protect sdp_reg_bank from concurrent access Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 20:26   ` sashiko-bot
2026-07-28 17:40 ` [PATCH v7 15/18] drm/bridge: synopsys: dw-dp: Use regmap_set_bits in dw_dp_send_sdp Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 17:40 ` [PATCH v7 16/18] dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 17:40 ` [PATCH v7 17/18] drm/bridge: synopsys: dw-dp: Clear only enabled SDPs on atomic disable Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 20:50   ` sashiko-bot
2026-07-28 17:40 ` [PATCH v7 18/18] drm/bridge: synopsys: dw-dp: Add audio support Sebastian Reichel
2026-07-28 17:40   ` Sebastian Reichel
2026-07-28 21:05   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260728191943.7EEC81F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=sebastian.reichel@collabora.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.