From patchwork Fri Jun 26 12:03:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Albert Esteve X-Patchwork-Id: 2473 Return-Path: X-Original-To: noreply@patchwork.local Delivered-To: noreply@patchwork.local Received: from sea.lore.kernel.org (sea.lore.kernel.org [172.234.253.10]) by mxe881.netcup.net (Postfix) with ESMTPS id 89FA21C00A4 for ; Fri, 26 Jun 2026 14:07:25 +0200 (CEST) Authentication-Results: mxe881; dkim=pass header.d=redhat.com; spf=pass (sender IP is 172.234.253.10) smtp.mailfrom=linux-sunxi+bounces-23947-noreply=patchwork.local@lists.linux.dev smtp.helo=sea.lore.kernel.org Received-SPF: pass (mxe881: domain of lists.linux.dev designates 172.234.253.10 as permitted sender) client-ip=172.234.253.10; envelope-from=linux-sunxi+bounces-23947-noreply=patchwork.local@lists.linux.dev; helo=sea.lore.kernel.org; Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sea.lore.kernel.org (Postfix) with ESMTP id 06FF53050466 for ; Fri, 26 Jun 2026 12:04:57 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id CF2FB3F410A; Fri, 26 Jun 2026 12:04:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="OWKsr9Nr" X-Original-To: linux-sunxi@lists.linux.dev Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 62F2B3F410C for ; Fri, 26 Jun 2026 12:04:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782475496; cv=none; b=C1L27B8/d36fwopdZsouTNXz63AOCCUgkDTyvxmHF8imuJEq4Gt77FvsaWOQCDuEqdRFJ+6VXf5wX6O2b1nWWgHlVkhZkLt/w+kH6EB8D8Lp0xuW7FKDYl2wZv//7ui9bv7XwLL05gFMEVhrfZ0eSr0LLdTCt+U19lK/DYLjyXo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782475496; c=relaxed/simple; bh=RQvWf2cmmOjDppG6XHJdIYzhop10IpGk0cqKF1/LF20=; h=From:Date:Subject:MIME-Version:Message-Id:References:In-Reply-To: To:Cc:Content-Type; b=aOI94PbYiRQp1qcwwKqve5zBGmrQWaXusWqx2/98g9TPr2jfdA0Mn8+0y7PqaFA1pfvGrY8rkxPhYIbLIa5HIIQi0su4gm5gMHsyZOg0ojeYjRGygEo39ckfiSKWvBpI0fMsxhtJv3Erbva3rgIHUWVRdqQlOcF2/RasHoWmk7A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=OWKsr9Nr; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1782475494; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=tAXt9BpJq2YIR4eaVSRC7C34o5liCLbDvfRHWn5C0ys=; b=OWKsr9Nry6UfmoBr05POUQinuXS1EEegxY3e0nEZDOrUJlrz02rD5WDqDufdnkSMJLUnz0 bFn21KEHCpK5sptExNxl7dt/9JI5m4f+v2NCCd3/Bd5u4Mz9FAIm/fJq624ZJMqXev4Vdy enph0lnu73FDN4z43GcjTFWpDgGEMu8= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-512-ao0NrWhXO4-8iOwPVHqcSw-1; Fri, 26 Jun 2026 08:04:51 -0400 X-MC-Unique: ao0NrWhXO4-8iOwPVHqcSw-1 X-Mimecast-MFC-AGG-ID: ao0NrWhXO4-8iOwPVHqcSw_1782475486 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id D9039180AE0D; Fri, 26 Jun 2026 12:04:45 +0000 (UTC) Received: from [192.168.1.153] (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 6643118005B1; Fri, 26 Jun 2026 12:04:26 +0000 (UTC) From: Albert Esteve Date: Fri, 26 Jun 2026 14:03:25 +0200 Subject: [PATCH 3/5] drm/panel: make *find_panel*() return a counted reference Precedence: bulk X-Mailing-List: linux-sunxi@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-Id: <20260626-drm_refcount_wiring-v1-3-cca1a7b3bdef@redhat.com> References: <20260626-drm_refcount_wiring-v1-0-cca1a7b3bdef@redhat.com> In-Reply-To: <20260626-drm_refcount_wiring-v1-0-cca1a7b3bdef@redhat.com> To: Neil Armstrong , Jessica Zhang , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , Andrzej Hajda , Robert Foss , Laurent Pinchart , Jonas Karlman , Jernej Skrabec , Luca Ceresoli , Inki Dae , Jagan Teki , Marek Szyprowski , Laurentiu Palcu , Lucas Stach , Frank Li , Sascha Hauer , Pengutronix Kernel Team , Fabio Estevam , Paul Cercueil , Linus Walleij , Marek Vasut , Stefan Agner , Tomi Valkeinen , Laurent Pinchart , Kieran Bingham , Geert Uytterhoeven , Magnus Damm , Biju Das , Sandy Huang , =?utf-8?q?Heiko_St=C3=BCbner?= , Andy Yan , Yannick Fertre , Raphael Gallais-Pou , Philippe Cornu , Maxime Coquelin , Alexandre Torgue , Chen-Yu Tsai , Samuel Holland , Jyri Sarha , Jingoo Han , Seung-Woo Kim , Kyungmin Park , Krzysztof Kozlowski , Peter Griffin , Alim Akhtar , Alison Wang , Paul Kocialkowski , Alain Volmat , Raphael Gallais-Pou , Thierry Reding , Mikko Perttunen , Jonathan Hunter Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, imx@lists.linux.dev, linux-arm-kernel@lists.infradead.org, linux-mips@vger.kernel.org, linux-renesas-soc@vger.kernel.org, linux-rockchip@lists.infradead.org, linux-stm32@st-md-mailman.stormreply.com, linux-sunxi@lists.linux.dev, linux-samsung-soc@vger.kernel.org, linux-tegra@vger.kernel.org, Albert Esteve X-Developer-Signature: v=1; a=ed25519-sha256; t=1782475410; l=3606; i=aesteve@redhat.com; s=20260303; h=from:subject:message-id; bh=RQvWf2cmmOjDppG6XHJdIYzhop10IpGk0cqKF1/LF20=; b=8W4ovjLmvfzm95lBgOYTjqgTr37+/SUy6z65QeUY1DlWACyNlGh9CVciNc0EOMA4rxo+vhk6F nJQflgDdg2KBtgX+1gkj9BX1jBOVslRJjljQ/ZPAFhjR23p1/0zbIA9 X-Developer-Key: i=aesteve@redhat.com; a=ed25519; pk=YSFz6sOHd2L45+Fr8DIvHTi6lSIjhLZ5T+rkxspJt1s= X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: _o4-smPaX5D253NW84V3BI9N_yg2bXOawSH-IhF6yGg_1782475486 X-Mimecast-Originator: redhat.com X-MORS-Enabled: yes X-MORS-DOMAIN: patchwork.local X-MORS-HOSTING: hosting172546 X-MORS-USER: hosting172546 X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= Callers of of_drm_find_panel() receive a pointer with no reference held, creating a window where the panel device can be unregistered and freed between the lookup and first use (e.g., drm_panel_prepare()). find_panel_by_fwnode() is the fwnode counterpart of of_drm_find_panel(). drm_panel_add_follower() worked around the missing panel kref by calling get_device() on the panel's underlying struct device. However, get_device() only prevents the device kobject from being freed. It does not prevent the panel's kzalloc()'d container memory from being released when the kref reaches zero. Fix both lookup functions by acquiring a reference with drm_panel_get() before returning, under panel_lock. Callers are now responsible for calling drm_panel_put() when they no longer need the pointer. Signed-off-by: Albert Esteve --- drivers/gpu/drm/drm_panel.c | 22 +++++++++++++++++----- 1 file changed, 17 insertions(+), 5 deletions(-) diff --git a/drivers/gpu/drm/drm_panel.c b/drivers/gpu/drm/drm_panel.c index 545fe93dc28fe..a00ae98ed0956 100644 --- a/drivers/gpu/drm/drm_panel.c +++ b/drivers/gpu/drm/drm_panel.c @@ -458,14 +458,17 @@ EXPORT_SYMBOL(__devm_drm_panel_alloc); #ifdef CONFIG_OF /** - * of_drm_find_panel - look up a panel using a device tree node + * of_drm_find_panel - look up and reference a panel by device tree node * @np: device tree node of the panel * * Searches the set of registered panels for one that matches the given device - * tree node. If a matching panel is found, return a pointer to it. + * tree node. If a matching panel is found, the panel's reference count is + * incremented before returning a pointer to it. The caller must call + * drm_panel_put() when it no longer needs the panel pointer. * - * Return: A pointer to the panel registered for the specified device tree - * node or an ERR_PTR() if no panel matching the device tree node can be found. + * Return: A reference-counted pointer to the panel registered for the specified + * device tree node or an ERR_PTR() if no panel matching the device tree node + * can be found. * * Possible error codes returned by this function: * @@ -484,6 +487,7 @@ struct drm_panel *of_drm_find_panel(const struct device_node *np) list_for_each_entry(panel, &panel_list, list) { if (panel->dev->of_node == np) { + drm_panel_get(panel); mutex_unlock(&panel_lock); return panel; } @@ -538,7 +542,13 @@ int of_drm_get_panel_orientation(const struct device_node *np, EXPORT_SYMBOL(of_drm_get_panel_orientation); #endif -/* Find panel by fwnode. This should be identical to of_drm_find_panel(). */ +/* + * Find panel by fwnode, returning a counted reference. + * + * Behaves identically to of_drm_find_panel(). On success the returned + * pointer has been passed through drm_panel_get(); the caller must call + * drm_panel_put() when done with it. + */ static struct drm_panel *find_panel_by_fwnode(const struct fwnode_handle *fwnode) { struct drm_panel *panel; @@ -550,6 +560,7 @@ static struct drm_panel *find_panel_by_fwnode(const struct fwnode_handle *fwnode list_for_each_entry(panel, &panel_list, list) { if (dev_fwnode(panel->dev) == fwnode) { + drm_panel_get(panel); mutex_unlock(&panel_lock); return panel; } @@ -686,6 +697,7 @@ void drm_panel_remove_follower(struct drm_panel_follower *follower) mutex_unlock(&panel->follower_lock); put_device(panel->dev); + drm_panel_put(panel); } EXPORT_SYMBOL(drm_panel_remove_follower);