From: sashiko-bot@kernel.org
To: "Svyatoslav Ryhel" <clamor95@gmail.com>
Cc: conor+dt@kernel.org, devicetree@vger.kernel.org,
dri-devel@lists.freedesktop.org, robh@kernel.org
Subject: Re: [PATCH v1 6/6] drm/panel: Add Hitachi TX10D07VM0BAA and LG LH400WV3-SD04 MIPI DBI panel driver
Date: Wed, 30 Sep 2026 07:15:45 +0000 [thread overview]
Message-ID: <20260930071546.6D83D1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260930070535.47130-7-clamor95@gmail.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] drm/panel: missing put_device() causes refcount leak in panel_dbi_prepare()
- [High] drm/panel: unsafe lockless access to remote drvdata risks UAF
--
commit af85d3c58c7325c679bd0289254561bdca27049a
Author: Svyatoslav Ryhel <clamor95@gmail.com>
drm/panel: Add Hitachi TX10D07VM0BAA and LG LH400WV3-SD04 MIPI DBI panel driver
This commit adds a DRM panel driver for the Hitachi TX10D07VM0BAA and LG
LH400WV3-SD04 MIPI DBI panels used in the LG Optimus 2X P990. These panels are
linked to the DRM encoder via an RGB to DBI bridge.
> diff --git a/drivers/gpu/drm/panel/panel-hitachi-tx10d07vm0baa.c b/drivers/gpu/drm/panel/panel-hitachi-tx10d07vm0baa.c
> new file mode 100644
> index 0000000000000..e78814c9697af
> --- /dev/null
> +++ b/drivers/gpu/drm/panel/panel-hitachi-tx10d07vm0baa.c
[ ... ]
> +static int panel_dbi_prepare(struct drm_panel *panel)
> +{
> + struct panel_dbi *priv = to_panel_dbi(panel);
> + struct platform_device *bridge_pdev;
> + struct device_node *bridge_node;
> + struct device *dev = panel->dev;
> + int ret;
> +
> + bridge_node = of_graph_get_remote_node(dev_of_node(dev), 0, 0);
> + if (!bridge_node)
> + return -ENODEV;
> +
> + bridge_pdev = of_find_device_by_node(bridge_node);
> + of_node_put(bridge_node);
> + if (!bridge_pdev)
> + return -ENODEV;
[Severity: High]
Does this code leak the reference to bridge_pdev?
The function of_find_device_by_node() increments the reference count of the
returned platform device, but it doesn't appear to be released with
put_device() anywhere in this function.
Since panel_dbi_prepare() is called on every display enable operation (such as
during a DPMS on/off cycle), couldn't this leak references incrementally and
eventually lead to a refcount overflow or memory exhaustion?
> +
> + priv->dbi = platform_get_drvdata(bridge_pdev);
[Severity: High]
Is it safe to cache the remote bridge device's drvdata locklessly here?
If the bridge device gets unbound via sysfs while the panel is still active,
the bridge's devres-managed memory would be freed. A subsequent panel
operation, such as calling panel_dbi_command() during teardown, would then
dereference the freed pointer:
ret = mipi_dbi_command_stackbuf((priv)->dbi, cmd, d, ARRAY_SIZE(d));
Could this lead to a use-after-free, since there is no device link or locking
holding a reference to the bridge's lifecycle?
> + if (!priv->dbi)
> + return -ENODEV;
> +
> + gpiod_set_value_cansleep(priv->reset_gpio, 1);
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260930070535.47130-1-clamor95@gmail.com?part=6
next prev parent reply other threads:[~2026-09-30 7:15 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 7:05 [PATCH v1 0/6] drm/tegra: Add support for Tegra20/Tegra30 8-bit CPU interface Svyatoslav Ryhel
2026-09-30 7:05 ` [PATCH v1 1/6] drm/tegra: dc: Expand available registers layouts Svyatoslav Ryhel
2026-09-30 7:15 ` sashiko-bot
2026-09-30 8:34 ` Thierry Reding
2026-09-30 8:55 ` Svyatoslav Ryhel
2026-09-30 7:05 ` [PATCH v1 2/6] drm/tegra: rgb: Parameterize configuration based on bus flags Svyatoslav Ryhel
2026-09-30 7:38 ` sashiko-bot
2026-09-30 7:05 ` [PATCH v1 3/6] dt-bindings: display: tegra: Document 8-bit CPU parallel interface Svyatoslav Ryhel
2026-09-30 7:15 ` sashiko-bot
2026-09-30 8:47 ` Thierry Reding
2026-09-30 9:00 ` Svyatoslav Ryhel
2026-09-30 10:34 ` Thierry Reding
2026-09-30 10:42 ` Svyatoslav Ryhel
2026-09-30 10:54 ` Thierry Reding
2026-09-30 11:10 ` Svyatoslav Ryhel
2026-09-30 11:41 ` Thierry Reding
2026-09-30 11:47 ` Svyatoslav Ryhel
2026-09-30 9:19 ` Mikko Perttunen
2026-09-30 9:52 ` Svyatoslav Ryhel
2026-09-30 10:50 ` Thierry Reding
2026-09-30 10:56 ` Svyatoslav Ryhel
2026-09-30 11:46 ` Thierry Reding
2026-09-30 11:56 ` Svyatoslav Ryhel
2026-09-30 12:58 ` Thierry Reding
2026-09-30 13:10 ` Svyatoslav Ryhel
2026-09-30 18:03 ` Svyatoslav Ryhel
2026-10-02 5:58 ` Mikko Perttunen
2026-09-30 11:51 ` Rob Herring (Arm)
2026-09-30 7:05 ` [PATCH v1 4/6] drm/tegra: Add support for 8-bit CPU interface Svyatoslav Ryhel
2026-09-30 7:25 ` sashiko-bot
2026-09-30 8:48 ` Thierry Reding
2026-09-30 9:02 ` Svyatoslav Ryhel
2026-09-30 10:39 ` Thierry Reding
2026-09-30 7:05 ` [PATCH v1 5/6] dt-bindings: display: panel: Document Hitachi TX10D07VM0BAA and LG LH400WV3 panels Svyatoslav Ryhel
2026-09-30 7:17 ` sashiko-bot
2026-09-30 7:05 ` [PATCH v1 6/6] drm/panel: Add Hitachi TX10D07VM0BAA and LG LH400WV3-SD04 MIPI DBI panel driver Svyatoslav Ryhel
2026-09-30 7:15 ` sashiko-bot [this message]
2026-09-30 9:02 ` Thierry Reding
2026-09-30 9:08 ` Svyatoslav Ryhel
2026-09-30 10:23 ` Thierry Reding
2026-09-30 10:34 ` Svyatoslav Ryhel
2026-09-30 10:43 ` Thierry Reding
2026-09-30 10:48 ` Svyatoslav Ryhel
2026-09-30 10:58 ` Thierry Reding
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930071546.6D83D1F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=clamor95@gmail.com \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox