drm/panel: novatek-nt36536: Fix panel double-remove on attach failure

The DSI attach error path calls drm_panel_remove() by hand even though
the panel was registered with devm_drm_panel_add(), which already
arranges for drm_panel_remove() to run on driver detach. When
mipi_dsi_attach() fails the panel is therefore removed twice: once
directly and once again while devres unwinds.

drm_panel_add() takes a reference and drm_panel_remove() drops one, so
the extra removal releases the last reference early and frees the panel
container. The put registered by devm_drm_panel_alloc() then operates on
freed memory, resulting in a use-after-free and a reference-count
underflow when a DSI host rejects the requested configuration during
probe.

Drop the manual drm_panel_remove() and let the managed cleanup handle
it, matching the other dual-DSI panel drivers.

Fixes: 75a5dbd1f4 ("drm/panel: Add Novatek NT36536 panel driver")
Signed-off-by: David Carlier <devnexen@gmail.com>
Reviewed-by: Pengyu Luo <mitltlatltl@gmail.com>
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260724041746.12887-1-devnexen@gmail.com
This commit is contained in:
David Carlier 2026-07-24 05:17:46 +01:00 committed by Neil Armstrong
parent e1bde8ef0a
commit 4085da1e6a

View File

@ -429,11 +429,9 @@ static int novatek_probe(struct mipi_dsi_device *dsi)
ctx->dsi[i]->mode_flags = desc->mode_flags;
ctx->dsi[i]->dsc = &ctx->dsc;
ret = devm_mipi_dsi_attach(dev, ctx->dsi[i]);
if (ret < 0) {
drm_panel_remove(&ctx->panel);
if (ret < 0)
return dev_err_probe(dev, ret,
"Failed to attach to DSI host\n");
}
}
if (desc->has_dcs_backlight) {