| Message ID | 20260902201640.2024648-4-mukesh.ojha@oss.qualcomm.com (mailing list archive) |
|---|---|
| State | New |
| Headers |
Return-Path: <linux-sunxi+bounces-25516-sunxi=pue.re@lists.linux.dev>
X-Original-To: noreply@patchwork.local
Delivered-To: noreply@patchwork.local
Received: from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114])
by mxe881.netcup.net (Postfix) with ESMTPS id F01071C0130
for <noreply@patchwork.local>; Wed, 2 Sep 2026 22:28:48 +0200 (CEST)
Authentication-Results: mxe881;
dkim=pass header.d=qualcomm.com;
dkim=pass header.d=oss.qualcomm.com;
spf=pass (sender IP is 172.105.105.114)
smtp.mailfrom=linux-sunxi+bounces-25516-noreply=patchwork.local@lists.linux.dev
smtp.helo=tor.lore.kernel.org
Received-SPF: pass (mxe881: domain of lists.linux.dev designates
172.105.105.114 as permitted sender) client-ip=172.105.105.114;
envelope-from=linux-sunxi+bounces-25516-noreply=patchwork.local@lists.linux.dev;
helo=tor.lore.kernel.org;
Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org
[100.90.174.1])
by tor.lore.kernel.org (Postfix) with ESMTP id EDA0A446EE
for <noreply@patchwork.local>; Wed, 2 Sep 2026 20:17:26 +0000 (UTC)
Received: from localhost.localdomain (localhost.localdomain [127.0.0.1])
by smtp.subspace.kernel.org (Postfix) with ESMTP id A14331E98E3;
Wed, 2 Sep 2026 20:17:20 +0000 (UTC)
Authentication-Results: smtp.subspace.kernel.org;
dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com
header.b="a0sYz4CC";
dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com
header.b="jcKaU/W0"
X-Original-To: linux-sunxi@lists.linux.dev
Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com
[205.220.168.131])
(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
(No client certificate requested)
by smtp.subspace.kernel.org (Postfix) with ESMTPS id 37EE73A9D99
for <linux-sunxi@lists.linux.dev>; Wed, 2 Sep 2026 20:17:19 +0000 (UTC)
Authentication-Results: smtp.subspace.kernel.org;
arc=none smtp.client-ip=205.220.168.131
ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116;
t=1788380240; cv=none;
b=JlH4XCq0CvGIZSsYleG594ywEBMBa5RLsB17NJxhAHGLMjRd3gVjBHDPuAdFIJVZNod100W3jq6uOKWQl29ErxaB1oJOiu8f05euiytXxXZ2LRcxD+elRAPLfti/od3eyerCDQ3s+aZwPE2Xt3xcVu4rzl7XZCu/zX7CCodaD2M=
ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org;
s=arc-20240116; t=1788380240; c=relaxed/simple;
bh=J5fU6hQOqgYnobNq0y67Kn6rZ5FR9aF1CDB13ndNBPE=;
h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References:
MIME-Version;
b=cRwaVKFcW3SlJzjW/Y8T9TWb0pGem2JBnrzxkcpCNGQXn4q6WJ9/ra1/R4v4Z6wVhX8qBpd+2vqk7HAElisMDnOBv6MrUKf1lBvUOib6vpftWJm8rgB9uhQ/xVqSCqRRdCIj70hjFd7jwxLacrbzMSgtAqAShjsYD+NwMrdc/X4=
ARC-Authentication-Results: i=1; smtp.subspace.kernel.org;
dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com;
spf=pass smtp.mailfrom=oss.qualcomm.com;
dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com
header.b=a0sYz4CC;
dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com
header.b=jcKaU/W0; arc=none smtp.client-ip=205.220.168.131
Authentication-Results: smtp.subspace.kernel.org;
dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com
Authentication-Results: smtp.subspace.kernel.org;
spf=pass smtp.mailfrom=oss.qualcomm.com
Received: from pps.filterd (m0279865.ppops.net [127.0.0.1])
by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id
682KH2jW3288550
for <linux-sunxi@lists.linux.dev>; Wed, 2 Sep 2026 20:17:18 GMT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h=
cc:content-transfer-encoding:date:from:in-reply-to:message-id
:mime-version:references:subject:to; s=qcppdkim1; bh=9lDnpS9AG8B
MnKFjVCsDrmYG+UZscdm8zFBOnLWOShw=; b=a0sYz4CCAZERJ5cvQgZ067dKOaN
q3zsMGdWtgW4siEJGM7JhH5S27ck/eEvpze57SsRdLn6TIb6EYfN4QDUd0EgoQ47
hCyZGr6sDbJ7x0sKo2J5FjWKamDlSx8J1AfHtG13YKSYWtdxi8lr8kdNCA37Mrn7
ffVtMIw9RXL7cpU0LXHWe8Y2v1Hng0Cw8YAniRAajGPRp4mAkHO15m2C94aUICNL
VtHZwWDy3QkuVzs9vQCqcXewaaRtyixuRjgqgrCtOI+jCbl0UhLpkfLp1PykMbjL
qokITfmOkJByT5TuP8bH+8444POICdhc+B1vucMlN5DsaaxXwT4RQuCrmzQ==
Received: from mail-pj1-f72.google.com (mail-pj1-f72.google.com
[209.85.216.72])
by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4gerdn8qx3-1
(version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT)
for <linux-sunxi@lists.linux.dev>; Wed, 02 Sep 2026 20:17:18 +0000 (GMT)
Received: by mail-pj1-f72.google.com with SMTP id
98e67ed59e1d1-38e8fee6af3so2192712a91.1
for <linux-sunxi@lists.linux.dev>;
Wed, 02 Sep 2026 13:17:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=oss.qualcomm.com; s=google; t=1788380238; x=1788985038;
darn=lists.linux.dev;
h=content-transfer-encoding:mime-version:references:in-reply-to
:message-id:date:subject:cc:to:from:from:to:cc:subject:date
:message-id:reply-to:content-type;
bh=9lDnpS9AG8BMnKFjVCsDrmYG+UZscdm8zFBOnLWOShw=;
b=jcKaU/W0+hIu3SGsDA2EYNd758TrBByKlVvEFkX5ATRDkeJfIoh0gpL9aiU4tPnczA
jCK2X6+o1gHxxv5cpFOHg4eQJM9CtrdpgjX0UnP3lJVYxhC5jx2VKIJpPWaTwe4AgtTO
sT8h7vpJVzQR5q3riIZa9MzQ8dHHkKbIBBOe7NrgYoLv73HNpY5HIJdqffPA4R47aEYa
VlO4h/HlTVxYANHTLEZvM1idGij2wsWIENt/iUFY2FzULd7LBnzFFRm4mw6ceT8OA9HA
fGEmDskTk2+JPDwW2mYE/U2JNDoODSuQ2UCb6yYEIHsLugKvqOqCp4rymweSB5Hhq4FH
BmRg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20251104; t=1788380238; x=1788985038;
h=content-transfer-encoding:mime-version:references:in-reply-to
:message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from
:to:cc:subject:date:message-id:reply-to:content-type;
bh=9lDnpS9AG8BMnKFjVCsDrmYG+UZscdm8zFBOnLWOShw=;
b=fikewXVqtgt4my6IO+/06GSyM174qexIcKGQUVq5s4AXBCHHMLG/5Oal8i7YSlWiYx
Cg0oAuhAMTX5vOdo9KI19JAk2CWWws2kR+HneO47VKpndWDlyOXh7+s2DVcb4NYzIqoN
0f2mUEq0MRIx6sSkJJz/qzBSxE0Ko3fSSP7PJoi+1V/evr7yqhCEsms3tNfSqmeaGxGh
5h3L5ZxkTs8L6wyDQsxSqYpN6sTXZGxdZBWVNOAB9tyLodUy3SloASSsyGWNgfcHFcUY
KONSk62nNs60FVS2uJxNKelllCHcqhRig67VXa4pyfrR9EXvhnBp4ASe0kN7SOZOwAfj
SC+A==
X-Forwarded-Encrypted: i=1;
AKwUvBz1lF3d5WK82qPdr/GCRgA/TvoI9g6xpV9Qr1ev5EocbmAK8CLqI8X2bPlx7aGtwF6ASqMOoSZ+O5IBBg==@lists.linux.dev
X-Gm-Message-State: AFuF++meU8NCBdcxVPzKLjl9V/+nS5bD0jvM2g1rOE2TEHeCCB0UnRTN
iFU0W16gGqWzi04nkWJx2TQnpmMklPkxH1mOl6tMxMYvb4soz8EmiBaxEwQfOJw/D60gLx8hfes
Qhzkh85uMAL8WLWbixA1b2zbQay1gaVo0rUR9ZVCjbpFTK4lM0XMyl6i/pR6lwdGpEw==
X-Gm-Gg: AYBFou30FurmMFkLdaivGt2fz1oEl2jaGXQ/aNsTdpkYOKiHvLrbfLNw2gcr/At6tJI
xAMf6slyJhRGrdCHPH2aHWf+SPUdR5e53Rq4zgBO6Hu92G4SjCdIJinZtsZ6M2n1QRQhJvoXseN
JPxqd/rg9HgURoDI6aHsOid62z8zl1Qmx4X5tkIjDDM5fjs3oDMzbR6RIz+WSsF54r8LhGldaVs
3Pvg/CuoF+l2M4PrnxPdlxYcaZRKjGSyc18MkdST4hzNxPvnuey8jHDFQK4sX4c8EddWUtnr+Km
p/jST6m7gFRgJRqzyEEZcec8hl2WDUr6W6NJvLmzyf0gVCVM6/8bLLEb+yhueog5GdzQnp0oQhq
EZsnXbz7dQ/pqCrny1t9NEK0/GGs=
X-Received: by 2002:a17:90b:1dc9:b0:398:c794:ca26 with SMTP id
98e67ed59e1d1-39aee17a0ecmr11378960a91.25.1788380237652;
Wed, 02 Sep 2026 13:17:17 -0700 (PDT)
X-Received: by 2002:a17:90b:1dc9:b0:398:c794:ca26 with SMTP id
98e67ed59e1d1-39aee17a0ecmr11378858a91.25.1788380237159;
Wed, 02 Sep 2026 13:17:17 -0700 (PDT)
Received: from hu-mojha-hyd.qualcomm.com ([202.46.23.25])
by smtp.gmail.com with ESMTPSA id
5a478bee46e88-33256414c60sm497205eec.24.2026.09.02.13.17.09
(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
Wed, 02 Sep 2026 13:17:16 -0700 (PDT)
From: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
To: Liviu Dudau <liviu.dudau@arm.com>,
Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
Maxime Ripard <mripard@kernel.org>,
Thomas Zimmermann <tzimmermann@suse.de>,
David Airlie <airlied@gmail.com>, Simona Vetter <simona@ffwll.ch>,
Joel Stanley <joel@jms.id.au>,
Andrew Jeffery <andrew@codeconstruct.com.au>,
Paul Cercueil <paul@crapouillou.net>,
Anitha Chrisanthus <anitha.chrisanthus@intel.com>,
Paul Kocialkowski <paulk@sys-base.io>,
Linus Walleij <linusw@kernel.org>, Chen-Yu Tsai <wens@kernel.org>,
Jernej Skrabec <jernej.skrabec@gmail.com>,
Samuel Holland <samuel@sholland.org>,
Alexey Brodkin <abrodkin@synopsys.com>,
Laurent Pinchart <laurent.pinchart@ideasonboard.com>,
Tomi Valkeinen <tomi.valkeinen@ideasonboard.com>,
Michal Simek <michal.simek@amd.com>
Cc: Ryan Chen <ryan_chen@aspeedtech.com>,
Billy Tsai <billy_tsai@aspeedtech.com>,
dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
linux-aspeed@lists.ozlabs.org, linux-arm-kernel@lists.infradead.org,
linux-mips@vger.kernel.org, linux-sunxi@lists.linux.dev,
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Subject: [PATCH v2 3/11] drm: pl111: Use devm_of_reserved_mem_device_init()
Date: Thu, 3 Sep 2026 01:46:32 +0530
Message-ID: <20260902201640.2024648-4-mukesh.ojha@oss.qualcomm.com>
X-Mailer: git-send-email 2.55.0
In-Reply-To: <20260902201640.2024648-1-mukesh.ojha@oss.qualcomm.com>
References: <20260902201640.2024648-1-mukesh.ojha@oss.qualcomm.com>
Precedence: bulk
X-Mailing-List: linux-sunxi@lists.linux.dev
List-Id: <linux-sunxi.lists.linux.dev>
List-Subscribe: <mailto:linux-sunxi+subscribe@lists.linux.dev>
List-Unsubscribe: <mailto:linux-sunxi+unsubscribe@lists.linux.dev>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
X-Authority-Analysis: v=2.4 cv=YcmNIQRf c=1 sm=1 tr=0 ts=6a98844e cx=c_pps
a=RP+M6JBNLl+fLTcSJhASfg==:117 a=ZePRamnt/+rB5gQjfz0u9A==:17
a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22
a=u7WPNUs3qKkmUXheDGA7:22 a=Um2Pa8k9VHT-vaBCBUpS:22 a=VwQbUJbxAAAA:8
a=7CQSdrXTAAAA:8 a=EUspDBNiAAAA:8 a=cxSrDiPXJhrM2elx99wA:9
a=iS9zxrgQBfv6-_F4QbHw:22 a=a-qgeE7W1pNrGK8U0ZQC:22
X-Proofpoint-Spam-Info: AW1haW4tMjYwOTAyMDE3OSBTYWx0ZWRfX//O9n747uF89
Ncm6SDD3CLKgm61g3iTqCe1G1sRMMTrH2b9Ek249zUgB1QLrrPQMZUamkBvis8GwxdCSiDC+0zd
27FlX8Mxkk5/qNvPHFKEkAhZiKTHXsI=
X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTAyMDE3OSBTYWx0ZWRfX6U+vPhu+I2jf
qj68IlZdDr7VC0PgK3tVThVaeOb4Q2xVjxOqVTN1Uu5j2Q1KlgPzgVgM3zRdnaPw+Ri7wjUNpvg
OKVBVjqjxBoeK+KI04bOTpFD25B9QCjwTTKP41TxW0BbITwlurDSSFCNoH82gzw3n/J+6F2fUbZ
U3OReatBnIwcTdzeNvBBOt8XH7QiSri8kSYjvGvzU+VuDol/p1TlbCC8cup21AVv25q/h59m2oP
N2JmBAFx+LcVMBtyyrLvzE2g5xwpH5o9j3r70U82rPN5i2ZlIOOyj/cuG44LRDZVtqrGVWSbYYa
YJ8FEr/cLYSz/rIRfx32p4RvikKS/YsLl5s/UtmsizKEU4SqRn+/Te5Wo7Gnmq+xsdTY0kUcCR0
w48wtxFegA5/79IFcsiMpkDgm50nfTBawFcZj3iAzxaRFabcUW0tT0oK5tbfTRSj96BL7tfySCE
ORywUVGWteHB+BfzD7Q==
X-Proofpoint-GUID: zM9UXz7qpuF40Io5oGms7204nwLQX3qP
X-Proofpoint-ORIG-GUID: zM9UXz7qpuF40Io5oGms7204nwLQX3qP
X-Proofpoint-Virus-Version: vendor=baseguard
engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49
definitions=2026-09-02_05,2026-09-02_04,2025-10-01_01
X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0
clxscore=1015 malwarescore=0 priorityscore=1501 lowpriorityscore=0
adultscore=0 phishscore=0 impostorscore=0 spamscore=0 suspectscore=0
bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound
adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000
definitions=main-2609020179
X-Rspamd-Server: rspamd-worker-8404
X-Spamd-Result: default: False [4.84 / 15.00];
RBL_SENDERSCORE(2.00)[172.105.105.114:from];
SUSPICIOUS_RECIPS(1.50)[];
MID_CONTAINS_FROM(1.00)[];
R_MISSING_CHARSET(0.50)[];
MAILLIST(-0.15)[generic];
MIME_GOOD(-0.10)[text/plain];
BAD_REP_POLICIES(0.10)[];
HAS_LIST_UNSUB(-0.01)[];
FROM_HAS_DN(0.00)[];
R_DKIM_ALLOW(0.00)[qualcomm.com:s=qcppdkim1];
PRECEDENCE_BULK(0.00)[];
TAGGED_RCPT(0.00)[];
RCVD_VIA_SMTP_AUTH(0.00)[];
DBL_BLOCKED_OPENRESOLVER(0.00)[qualcomm.com:email,qualcomm.com:dkim,tor.lore.kernel.org:rdns,tor.lore.kernel.org:helo,arm.com:email];
RCPT_COUNT_TWELVE(0.00)[28];
RCVD_COUNT_SEVEN(0.00)[8];
FROM_NEQ_ENVFROM(0.00)[mukesh.ojha@oss.qualcomm.com,linux-sunxi@lists.linux.dev];
ARC_ALLOW(0.00)[subspace.kernel.org:s=arc-20240116:i=1];
ASN(0.00)[asn:63949, ipnet:172.105.96.0/20, country:SG];
TO_DN_SOME(0.00)[];
R_SPF_ALLOW(0.00)[+ip4:172.105.105.114];
RECEIVED_SPAMHAUS_BLOCKED_OPENRESOLVER(0.00)[205.220.168.131:received,209.85.216.72:received,100.90.174.1:received,202.46.23.25:received];
FORGED_SENDER_MAILLIST(0.00)[];
TAGGED_FROM(0.00)[bounces-25516-noreply=patchwork.local];
DKIM_TRACE(0.00)[qualcomm.com:+];
FREEMAIL_TO(0.00)[arm.com,linux.intel.com,kernel.org,suse.de,gmail.com,ffwll.ch,jms.id.au,codeconstruct.com.au,crapouillou.net,intel.com,sys-base.io,sholland.org,synopsys.com,ideasonboard.com,amd.com];
RCVD_TLS_LAST(0.00)[];
DMARC_POLICY_ALLOW(0.00)[qualcomm.com,reject];
MIME_TRACE(0.00)[0:+];
FORGED_RECIPIENTS_MAILLIST(0.00)[];
RBL_SPAMHAUS_BLOCKED_OPENRESOLVER(0.00)[172.105.105.114:from]
X-Rspamd-Queue-Id: F01071C0130
X-MORS-Enabled: yes
X-MORS-DOMAIN: patchwork.local
X-MORS-HOSTING: hosting172546
X-MORS-USER: hosting172546
X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?=
|
| Series |
drm: Use devm_of_reserved_mem_device_init()
|
|
Commit Message
Mukesh Ojha
Sept. 2, 2026, 8:16 p.m. UTC
Switch to devm_of_reserved_mem_device_init() so the reserved memory region is released automatically on probe failure or device removal. Remove the explicit of_reserved_mem_device_release() calls in the dev_put error path and pl111_amba_remove(). Reviewed-by: Linus Walleij <linusw@kernel.org> Reviewed-by: Liviu Dudau <liviu.dudau@arm.com> Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com> --- drivers/gpu/drm/pl111/pl111_drv.c | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-)
Comments
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider: Pre-existing issues: - [High] Pre-existing use-after-free and memory corruption risks due to tying resource lifetimes (`priv` structure and reserved memory) to `devres` (driver unbind) while the `drm_device` can outlive the unbind. - [High] The `drm_panel_bridge` allocated via `drm_panel_bridge_add_typed()` in `pl111_modeset_init()` is leaked if `drm_dev_register()` fails. - [High] When `INTEGRATOR_CLCD_CM` is matched, `pl111_versatile_init()` overwrites `np` without dropping the original reference. If the second match fails, probe incorrectly fails. -- commit 76a1e18802677a9e3db4c051729d253910d2a13c Author: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com> drm: pl111: Use devm_of_reserved_mem_device_init() This patch converts the driver to use devm_of_reserved_mem_device_init, allowing the reserved memory region to be released automatically on probe failure or device removal. It removes the explicit cleanup calls. > diff --git a/drivers/gpu/drm/pl111/pl111_drv.c b/drivers/gpu/drm/pl111/pl111_drv.c > index 8ec659b3c08eb..a07b17261961c 100644 > --- a/drivers/gpu/drm/pl111/pl111_drv.c > +++ b/drivers/gpu/drm/pl111/pl111_drv.c > @@ -255,7 +255,7 @@ static int pl111_amba_probe(struct amba_device *amba_dev, > drm->dev_private = priv; > priv->variant = variant; > > - ret = of_reserved_mem_device_init(dev); > + ret = devm_of_reserved_mem_device_init(dev); [Severity: High] This is a pre-existing issue, but does tying resource lifetimes to devres here expose a use-after-free risk? The priv structure is allocated via devm_kzalloc() and the reserved memory is now managed via devres, tying their lifetimes to the driver unbind lifecycle. However, the drm_device is allocated without devres via drm_dev_alloc() and tied to a refcount. If a local user holds an open DRM file descriptor (like /dev/dri/card0) and the driver is unbound via sysfs, devres will free priv and the reserved memory while the DRM device persists. Because pl111_amba_remove() calls drm_dev_unregister() instead of drm_dev_unplug(), the device is not marked as unplugged and subsequent ioctls are not blocked. An ioctl like DRM_IOCTL_PRIME_FD_TO_HANDLE will call pl111_gem_import_sg_table(), which accesses dev->dev_private (priv), potentially causing a use-after-free. Should the driver be migrated to drm_dev_unplug() and devm_drm_dev_alloc() to prevent this? [ ... ] > @@ -314,7 +314,6 @@ static int pl111_amba_probe(struct amba_device *amba_dev, > > dev_put: > drm_dev_put(drm); > - of_reserved_mem_device_release(dev); > > return ret; > } [Severity: High] This is a pre-existing issue, but does this error path leak the panel bridge? During probe, a bridge is created by calling drm_panel_bridge_add_typed() inside pl111_modeset_init(), which adds the bridge to the global DRM bridge list with a reference count of 2. If drm_dev_register() subsequently fails, the probe function jumps to the dev_put label. The error path calls drm_dev_put(drm) but fails to call drm_panel_bridge_remove(priv->bridge). When the panel device is eventually unbound, its devres cleanup drops one reference on the bridge, but the bridge is never removed from the global list, leaving a dangling pointer. Does this need an explicit drm_panel_bridge_remove() call here? Also, while reviewing the probe path, I noticed a potential node reference issue in pl111_versatile_init() called earlier in this function: drivers/gpu/drm/pl111/pl111_versatile.c:pl111_versatile_init() { ... np = of_find_matching_node_and_match(NULL, versatile_clcd_of_match, &clcd_id); ... if (clcd_id == INTEGRATOR_CLCD_CM) { np = of_find_matching_node_and_match(NULL, impd1_clcd_of_match, &clcd_id); } [Severity: High] This is a pre-existing issue, but does overwriting np without dropping the original reference cause a memory leak? For the INTEGRATOR_CLCD_CM type, a second call to of_find_matching_node_and_match() is made, and its result overwrites np without calling of_node_put() on the original node. If the IM-PD1 syscon is not found, the second call returns NULL. The probe then calls syscon_node_to_regmap(NULL), which fails and returns an error, preventing the driver from probing successfully on valid standard Integrator AP hardware. Should of_node_put() be called before reassigning np?
diff --git a/drivers/gpu/drm/pl111/pl111_drv.c b/drivers/gpu/drm/pl111/pl111_drv.c index 8ec659b3c08e..a07b17261961 100644 --- a/drivers/gpu/drm/pl111/pl111_drv.c +++ b/drivers/gpu/drm/pl111/pl111_drv.c @@ -255,7 +255,7 @@ static int pl111_amba_probe(struct amba_device *amba_dev, drm->dev_private = priv; priv->variant = variant; - ret = of_reserved_mem_device_init(dev); + ret = devm_of_reserved_mem_device_init(dev); if (!ret) { drm_info(drm, "using device-specific reserved memory\n"); priv->use_device_memory = true; @@ -314,7 +314,6 @@ static int pl111_amba_probe(struct amba_device *amba_dev, dev_put: drm_dev_put(drm); - of_reserved_mem_device_release(dev); return ret; } @@ -330,7 +329,6 @@ static void pl111_amba_remove(struct amba_device *amba_dev) if (priv->panel) drm_panel_bridge_remove(priv->bridge); drm_dev_put(drm); - of_reserved_mem_device_release(dev); } static void pl111_amba_shutdown(struct amba_device *amba_dev)