Thread (101 messages) flat view 101 messages, 3 authors, 15h ago

Re: [PATCH v11 12/74] drm/bridge: Fix unlocked list_del in drm_bridge_add()

From: "Luca Ceresoli" <luca.ceresoli@bootlin.com>
Date: 2026-09-21 07:16:21
Also in: dri-devel, linux-arm-kernel, linux-rockchip, linux-sunxi, lkml

Hello Cristian,

On Tue Sep 1, 2026 at 8:50 PM CEST, Cristian Ciocaltea wrote:
When re-adding a bridge that was previously removed, drm_bridge_add()
drops it from bridge_lingering_list without holding bridge_lock.

Both bridge_list and bridge_lingering_list are protected by bridge_lock,
as they are concurrently modified by drm_bridge_remove() and
__drm_bridge_free(), and walked by the debugfs 'bridges' file.  Running
the list_empty() test and the list_del_init() outside of the lock may
therefore corrupt either list.
The analysis appears correct, with a small nit: __drm_bridge_free() cannot
touch the list concurrently to other functions, because it only runs when
the refcount is 0, and all other functions tounch the lists only when they
have a reference. (Should this sentence be wrong, that would be a big bug!)

But definitely drm_bridge_remove() and debugfs can run concurrently.
quoted hunk ↗ jump to hunk
Perform both under bridge_lock.

Fixes: 17805a15d175 ("drm/bridge: add list of removed refcounted bridges")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260723015004.1F5711F000E9@smtp.kernel.org/ (local)
Signed-off-by: Cristian Ciocaltea <redacted>
---
 drivers/gpu/drm/drm_bridge.c | 2 ++
 1 file changed, 2 insertions(+)
diff --git a/drivers/gpu/drm/drm_bridge.c b/drivers/gpu/drm/drm_bridge.c
index afaae272347c..2c457ad74f3b 100644
--- a/drivers/gpu/drm/drm_bridge.c
+++ b/drivers/gpu/drm/drm_bridge.c
@@ -454,8 +454,10 @@ void drm_bridge_add(struct drm_bridge *bridge)
 	 * in bridge_lingering_list. Remove it or bridge_lingering_list will be
 	 * corrupted when adding this bridge to bridge_list below.
 	 */
+	mutex_lock(&bridge_lock);
 	if (!list_empty(&bridge->list))
 		list_del_init(&bridge->list);
+	mutex_unlock(&bridge_lock);
The fix appears correct too, and consistent with the similar
mutex_lock/unlock() below.

So, with the "and __drm_bridge_free()," string removed from the commit
message you can add:

+Reviewed-by: Luca Ceresoli [off-list ref]

Thanks!

Luca

--
Luca Ceresoli, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help