[PATCH v3 0/4] drm/panel: refcounting panel lookups and references
From: Albert Esteve
Date: Fri Jul 17 2026 - 10:02:51 EST
The drm_panel subsystem provides kref-based reference counting [1]
(drm_panel_get/put) but almost nothing in the tree actually uses it.
This results in a systemic use-after-free pattern throughout the codebase.
This series aims to close all those issues.
Patches 1-2: fix the infrastructure. drm_panel_add/remove now keep
a counted reference for the list entry. drm_panel_bridge_add_typed()
now holds a counted reference for the lifetime of the panel_bridge.
Patch 3: change the semantics of of_drm_find_panel(). It now acquires
a reference before returning, under panel_lock. All in-tree callers
of of_drm_find_panel() and drm_of_find_panel_or_bridge() are updated.
Two patterns are common in these fixes:
- Bridge-wrapping: the panel is passed to devm_drm_panel_bridge_add()
or equivalent, which acquires its own reference. The caller (including
devm_drm_of_get_bridge() and drmm_of_get_bridge()) releases its lookup
reference immediately after.
- Store-and-use: the panel pointer is kept in a driver struct and
used directly for the device lifetime. The reference is released in the
remove/unbind path, or via devm_add_action_or_reset() where no explicit
teardown function exists.
Patch 4: extend the same fix to find_panel_by_fwnode(), a static helper
used internally by drm_panel_add_follower(). Since it has no external
callers, the fix is self-contained: drm_panel_remove_follower() is
updated to call drm_panel_put() to balance the reference.
In order to catch all places in the tree that required releasing the
reference, the search was assisted by an AI model. Specifically, a
Coccinelle script was designed by the agent to address the trivial changes
(not included in the series). Although a few required manual fixes, with goto
labels or bracket additions. Additionally, the model helped to discern implicit
teardown paths that were addressed with devm_add_action_or_reset() calls.
Thus, these commits have the Assisted-by label following the project guidelines.
No functional change is intended for any driver. The reference
counting only affects object lifetime; panel operations are unaffected.
[1] https://lore.kernel.org/all/20250331-b4-panel-refcounting-v4-0-dad50c60c6c9@xxxxxxxxxx/
Signed-off-by: Albert Esteve <aesteve@xxxxxxxxxx>
---
Changes in v3:
- Squashed patches 3 and 5
- Fix probe failure paths that leaked reference
- Fix UAF and other smaller issues found by Sashiko
- Add comment in tegra-dsi explaining why panel is always
NULL in that path and so no early drm_panel_put() is required
- Link to v2: https://lore.kernel.org/r/20260713-drm_refcount_wiring-v2-0-d3bb61f4bd4d@xxxxxxxxxx
Changes in v2:
- Squash of_drm_find_panel() API change with its caller fixes
- Split find_panel_by_fwnode() into its own commit
- Update kernel-doc for drm_of_find_panel_or_bridge()
- Link to v1: https://lore.kernel.org/r/20260626-drm_refcount_wiring-v1-0-cca1a7b3bdef@xxxxxxxxxx
---
Albert Esteve (4):
drm/panel: have drm_panel_add/remove manage a list reference
drm/bridge/panel: hold a reference to the wrapped panel
drm/panel: of_drm_find_panel() return a counted reference
drm/panel: find_panel_by_fwnode() return a counted reference
drivers/gpu/drm/bridge/analogix/analogix-anx6345.c | 12 +++++++++++
drivers/gpu/drm/bridge/fsl-ldb.c | 1 +
drivers/gpu/drm/bridge/lontium-lt9211.c | 1 +
drivers/gpu/drm/bridge/lvds-codec.c | 1 +
drivers/gpu/drm/bridge/panel.c | 20 ++++++++++++++----
drivers/gpu/drm/bridge/samsung-dsim.c | 1 +
drivers/gpu/drm/bridge/ssd2825.c | 1 +
drivers/gpu/drm/bridge/tc358767.c | 2 ++
drivers/gpu/drm/bridge/tc358768.c | 1 +
drivers/gpu/drm/bridge/waveshare-dsi.c | 1 +
drivers/gpu/drm/drm_of.c | 3 ++-
drivers/gpu/drm/drm_panel.c | 24 +++++++++++++++++-----
drivers/gpu/drm/exynos/exynos_dp.c | 19 ++++++++++++++++-
drivers/gpu/drm/exynos/exynos_drm_dpi.c | 3 +++
drivers/gpu/drm/fsl-dcu/fsl_dcu_drm_rgb.c | 18 ++++++++++++++++
drivers/gpu/drm/imx/dcss/dcss-kms.c | 3 +++
drivers/gpu/drm/ingenic/ingenic-drm-drv.c | 4 +++-
drivers/gpu/drm/logicvc/logicvc_interface.c | 12 +++++++++++
drivers/gpu/drm/mcde/mcde_drv.c | 1 +
drivers/gpu/drm/mcde/mcde_dsi.c | 1 +
drivers/gpu/drm/mxsfb/mxsfb_drv.c | 1 +
drivers/gpu/drm/omapdrm/dss/output.c | 1 +
drivers/gpu/drm/pl111/pl111_drv.c | 1 +
drivers/gpu/drm/renesas/rcar-du/rcar_du_encoder.c | 1 +
drivers/gpu/drm/renesas/rcar-du/rcar_lvds.c | 1 +
drivers/gpu/drm/renesas/rz-du/rzg2l_du_encoder.c | 1 +
drivers/gpu/drm/rockchip/analogix_dp-rockchip.c | 11 ++++++++++
drivers/gpu/drm/rockchip/rockchip_lvds.c | 4 ++++
drivers/gpu/drm/rockchip/rockchip_rgb.c | 3 +++
drivers/gpu/drm/sti/sti_dvo.c | 3 +++
drivers/gpu/drm/stm/ltdc.c | 1 +
drivers/gpu/drm/stm/lvds.c | 12 ++++++++---
drivers/gpu/drm/sun4i/sun4i_lvds.c | 13 ++++++++++++
drivers/gpu/drm/sun4i/sun4i_rgb.c | 13 ++++++++++++
drivers/gpu/drm/sun4i/sun4i_tcon.c | 2 ++
drivers/gpu/drm/sun4i/sun6i_mipi_dsi.c | 6 +++++-
drivers/gpu/drm/tegra/dsi.c | 5 +++++
drivers/gpu/drm/tegra/output.c | 24 +++++++++++++++++++---
drivers/gpu/drm/tidss/tidss_kms.c | 16 ++++++++++-----
drivers/gpu/drm/tve200/tve200_drv.c | 1 +
40 files changed, 225 insertions(+), 24 deletions(-)
---
base-commit: 8cdeaa50eae8dad34885515f62559ee83e7e8dda
change-id: 20260513-drm_refcount_wiring-4e5e757e9047
Best regards,
--
Albert Esteve <aesteve@xxxxxxxxxx>