All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Esben Haabendal" <esben@geanix.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v5 1/2] drm/bridge: ti-sn65dsi83: Fix error handling in sn65dsi83_reset_work()
Date: Mon, 31 Aug 2026 12:31:03 +0000	[thread overview]
Message-ID: <20260831123103.70EF71F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260831-ti-sn65dsi83-fixes-v5-1-e712765d6c4f@geanix.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Missing `cancel_work_sync` for `reset_work` leads to a use-after-free on driver unbind.
--

commit 47920da4c643294656a651a954618ec33114a7d9
Author: Esben Haabendal <esben@geanix.com>

drm/bridge: ti-sn65dsi83: Fix error handling in sn65dsi83_reset_work()

The commit reintroduces a non-zero return value from sn65dsi83_reset_pipe()
on error to prevent erroneous IRQ re-enabling during failures. It also
updates sn65dsi83_reset_work() to properly exit the DRM bridge critical
section by always calling drm_bridge_exit().

> diff --git a/drivers/gpu/drm/bridge/ti-sn65dsi83.c b/drivers/gpu/drm/bridge/ti-sn65dsi83.c
> index 42b451432bbb6..9f530cd05d2f3 100644
> --- a/drivers/gpu/drm/bridge/ti-sn65dsi83.c
> +++ b/drivers/gpu/drm/bridge/ti-sn65dsi83.c
[ ... ]
> @@ -419,11 +419,13 @@ static void sn65dsi83_reset_work(struct work_struct *ws)
>  	ret = sn65dsi83_reset_pipe(ctx);
>  	if (ret) {
>  		dev_err(ctx->dev, "reset pipe failed %pe\n", ERR_PTR(ret));
> -		return;
> +		goto bridge_exit;
>  	}
> +
>  	if (ctx->irq)
>  		enable_irq(ctx->irq);
>  
> +bridge_exit:
>  	drm_bridge_exit(idx);
>  }

[Severity: High]
This isn't a bug introduced by this patch, but I noticed a potential
use-after-free related to the reset_work structure that is being modified here.

During driver unbind (e.g., via sysfs), sn65dsi83_remove() unplugs the bridge
but does not explicitly call cancel_work_sync(&ctx->reset_work). After
sn65dsi83_remove() returns, devres automatically frees the IRQ and the ctx
structure.

If an interrupt had previously scheduled the work, the work item might remain
in the queue and eventually execute sn65dsi83_reset_work(), which will attempt
to access the freed ctx pointer (e.g., when calling
drm_bridge_enter(&ctx->bridge, &idx)).

Should sn65dsi83_remove() be updated to include a call to
cancel_work_sync(&ctx->reset_work) to ensure the work is fully cancelled
before devres tears down the allocated memory?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260831-ti-sn65dsi83-fixes-v5-0-e712765d6c4f@geanix.com?part=1

  reply	other threads:[~2026-08-31 12:31 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31 12:21 [PATCH v5 0/2] drm/bridge: ti-sn65dsi83: Various fixes Esben Haabendal
2026-08-31 12:21 ` [PATCH v5 1/2] drm/bridge: ti-sn65dsi83: Fix error handling in sn65dsi83_reset_work() Esben Haabendal
2026-08-31 12:31   ` sashiko-bot [this message]
2026-08-31 12:59   ` Herve Codina
2026-09-01  9:48   ` Luca Ceresoli
2026-09-01 12:05   ` Luca Ceresoli
2026-08-31 12:21 ` [PATCH v5 2/2] drm/bridge: ti-sn65dsi83: Support LVDS Channel B on SN65DSI84 Esben Haabendal
2026-09-09 15:18 ` (subset) [PATCH v5 0/2] drm/bridge: ti-sn65dsi83: Various fixes Luca Ceresoli

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260831123103.70EF71F00A3D@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=esben@geanix.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.