mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 04:34:03 +02:00
drm/panel: novatek-nt36536: Fix panel double-remove on attach failure
The DSI attach error path calls drm_panel_remove() by hand even though
the panel was registered with devm_drm_panel_add(), which already
arranges for drm_panel_remove() to run on driver detach. When
mipi_dsi_attach() fails the panel is therefore removed twice: once
directly and once again while devres unwinds.
drm_panel_add() takes a reference and drm_panel_remove() drops one, so
the extra removal releases the last reference early and frees the panel
container. The put registered by devm_drm_panel_alloc() then operates on
freed memory, resulting in a use-after-free and a reference-count
underflow when a DSI host rejects the requested configuration during
probe.
Drop the manual drm_panel_remove() and let the managed cleanup handle
it, matching the other dual-DSI panel drivers.
Fixes: 75a5dbd1f4 ("drm/panel: Add Novatek NT36536 panel driver")
Signed-off-by: David Carlier <devnexen@gmail.com>
Reviewed-by: Pengyu Luo <mitltlatltl@gmail.com>
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260724041746.12887-1-devnexen@gmail.com
This commit is contained in:
parent
e1bde8ef0a
commit
4085da1e6a
|
|
@ -429,11 +429,9 @@ static int novatek_probe(struct mipi_dsi_device *dsi)
|
|||
ctx->dsi[i]->mode_flags = desc->mode_flags;
|
||||
ctx->dsi[i]->dsc = &ctx->dsc;
|
||||
ret = devm_mipi_dsi_attach(dev, ctx->dsi[i]);
|
||||
if (ret < 0) {
|
||||
drm_panel_remove(&ctx->panel);
|
||||
if (ret < 0)
|
||||
return dev_err_probe(dev, ret,
|
||||
"Failed to attach to DSI host\n");
|
||||
}
|
||||
}
|
||||
|
||||
if (desc->has_dcs_backlight) {
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user