[PATCH v11 12/74] drm/bridge: Fix unlocked list_del in drm_bridge_add()
Luca Ceresoli
luca.ceresoli at bootlin.com
Mon Sep 21 00:16:01 PDT 2026
Hello Cristian,
On Tue Sep 1, 2026 at 8:50 PM CEST, Cristian Ciocaltea wrote:
> When re-adding a bridge that was previously removed, drm_bridge_add()
> drops it from bridge_lingering_list without holding bridge_lock.
>
> Both bridge_list and bridge_lingering_list are protected by bridge_lock,
> as they are concurrently modified by drm_bridge_remove() and
> __drm_bridge_free(), and walked by the debugfs 'bridges' file. Running
> the list_empty() test and the list_del_init() outside of the lock may
> therefore corrupt either list.
The analysis appears correct, with a small nit: __drm_bridge_free() cannot
touch the list concurrently to other functions, because it only runs when
the refcount is 0, and all other functions tounch the lists only when they
have a reference. (Should this sentence be wrong, that would be a big bug!)
But definitely drm_bridge_remove() and debugfs can run concurrently.
> Perform both under bridge_lock.
>
> Fixes: 17805a15d175 ("drm/bridge: add list of removed refcounted bridges")
> Reported-by: Sashiko <sashiko-bot at kernel.org>
> Closes: https://lore.kernel.org/all/20260723015004.1F5711F000E9@smtp.kernel.org/
> Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea at collabora.com>
> ---
> drivers/gpu/drm/drm_bridge.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/drivers/gpu/drm/drm_bridge.c b/drivers/gpu/drm/drm_bridge.c
> index afaae272347c..2c457ad74f3b 100644
> --- a/drivers/gpu/drm/drm_bridge.c
> +++ b/drivers/gpu/drm/drm_bridge.c
> @@ -454,8 +454,10 @@ void drm_bridge_add(struct drm_bridge *bridge)
> * in bridge_lingering_list. Remove it or bridge_lingering_list will be
> * corrupted when adding this bridge to bridge_list below.
> */
> + mutex_lock(&bridge_lock);
> if (!list_empty(&bridge->list))
> list_del_init(&bridge->list);
> + mutex_unlock(&bridge_lock);
The fix appears correct too, and consistent with the similar
mutex_lock/unlock() below.
So, with the "and __drm_bridge_free()," string removed from the commit
message you can add:
+Reviewed-by: Luca Ceresoli <luca.ceresoli at bootlin.com>
Thanks!
Luca
--
Luca Ceresoli, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com
More information about the linux-arm-kernel
mailing list