Re: [PATCH v11 12/74] drm/bridge: Fix unlocked list_del in drm_bridge_add()
From: "Luca Ceresoli" <luca.ceresoli@bootlin.com>
Date: 2026-09-21 07:16:21
Also in:
dri-devel, linux-arm-kernel, linux-rockchip, linux-sunxi, lkml
Hello Cristian, On Tue Sep 1, 2026 at 8:50 PM CEST, Cristian Ciocaltea wrote:
When re-adding a bridge that was previously removed, drm_bridge_add() drops it from bridge_lingering_list without holding bridge_lock. Both bridge_list and bridge_lingering_list are protected by bridge_lock, as they are concurrently modified by drm_bridge_remove() and __drm_bridge_free(), and walked by the debugfs 'bridges' file. Running the list_empty() test and the list_del_init() outside of the lock may therefore corrupt either list.
The analysis appears correct, with a small nit: __drm_bridge_free() cannot touch the list concurrently to other functions, because it only runs when the refcount is 0, and all other functions tounch the lists only when they have a reference. (Should this sentence be wrong, that would be a big bug!) But definitely drm_bridge_remove() and debugfs can run concurrently.
quoted hunk ↗ jump to hunk
Perform both under bridge_lock. Fixes: 17805a15d175 ("drm/bridge: add list of removed refcounted bridges") Reported-by: Sashiko <sashiko-bot@kernel.org> Closes: https://lore.kernel.org/all/20260723015004.1F5711F000E9@smtp.kernel.org/ (local) Signed-off-by: Cristian Ciocaltea <redacted> --- drivers/gpu/drm/drm_bridge.c | 2 ++ 1 file changed, 2 insertions(+)diff --git a/drivers/gpu/drm/drm_bridge.c b/drivers/gpu/drm/drm_bridge.c index afaae272347c..2c457ad74f3b 100644 --- a/drivers/gpu/drm/drm_bridge.c +++ b/drivers/gpu/drm/drm_bridge.c@@ -454,8 +454,10 @@ void drm_bridge_add(struct drm_bridge *bridge) * in bridge_lingering_list. Remove it or bridge_lingering_list will be * corrupted when adding this bridge to bridge_list below. */ + mutex_lock(&bridge_lock); if (!list_empty(&bridge->list)) list_del_init(&bridge->list); + mutex_unlock(&bridge_lock);
The fix appears correct too, and consistent with the similar mutex_lock/unlock() below. So, with the "and __drm_bridge_free()," string removed from the commit message you can add: +Reviewed-by: Luca Ceresoli [off-list ref] Thanks! Luca -- Luca Ceresoli, Bootlin Embedded Linux and Kernel engineering https://bootlin.com