From: Daniel Golle <daniel@makrotopia.org>
To: Andrzej Hajda <andrzej.hajda@intel.com>,
Neil Armstrong <neil.armstrong@linaro.org>,
Robert Foss <rfoss@kernel.org>,
Laurent Pinchart <Laurent.pinchart@ideasonboard.com>,
Jonas Karlman <jonas@kwiboo.se>,
Jernej Skrabec <jernej.skrabec@gmail.com>,
Luca Ceresoli <luca.ceresoli@bootlin.com>,
Maarten Lankhorst <maarten.lankhorst@linux.intel.com>,
Maxime Ripard <mripard@kernel.org>,
Thomas Zimmermann <tzimmermann@suse.de>,
David Airlie <airlied@gmail.com>, Simona Vetter <simona@ffwll.ch>,
Matthias Brugger <matthias.bgg@gmail.com>,
AngeloGioacchino Del Regno
<angelogioacchino.delregno@collabora.com>,
Allen Chen <allen.chen@ite.com.tw>,
Hermes Wu <hermes.wu@ite.com.tw>,
Pin-yen Lin <treapking@chromium.org>,
dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
linux-arm-kernel@lists.infradead.org,
linux-mediatek@lists.infradead.org
Subject: [PATCH v7 01/14] drm/bridge: it6505: quiesce event sources and work on remove()
Date: Thu, 24 Sep 2026 19:40:05 +0100 [thread overview]
Message-ID: <6f2f7bd3e6b259266bde53b3396a1ef87633bc85.1790275151.git.daniel@makrotopia.org> (raw)
In-Reply-To: <cover.1790275151.git.daniel@makrotopia.org>
struct it6505 is freed by devres right after remove() returns, but
remove() cancels none of the driver's work items, so link_works,
hdcp_wait_ksv_list, hdcp_work and extcon_wq can still run afterwards
and dereference freed memory. Cancelling alone would not be enough:
the threaded IRQ and the extcon notifier stay live until devres
teardown and can requeue the works.
Unregister the extcon notifier and disable the IRQ first, then cancel
all work. Make it6505_remove_notifier_module() idempotent, tracking
the registration in a flag under extcon_lock, as both .detach() and
remove() call it now. The notifier_call pointer is left intact:
extcon traverses its raw notifier chain without holding a lock, so a
traversal racing with the unregistration may still invoke the
callback. Also initialise extcon_wq in probe: cancel_work_sync() on a
never-initialised work item trips WARN_ON(!work->func).
Fixes: b5c84a9edcd4 ("drm/bridge: add it6505 driver")
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
---
v7: no changes
v6: track registration in a flag instead of clearing notifier_call,
which an unlocked chain traversal racing the unregistration
could have called as NULL
v5: serialise notifier registration state with extcon_lock
v4:
* quiesce event sources before cancelling work; retitled
* initialise extcon_wq in probe to avoid WARN_ON(!work->func)
v3: new patch
---
drivers/gpu/drm/bridge/ite-it6505.c | 27 +++++++++++++++++++++------
1 file changed, 21 insertions(+), 6 deletions(-)
diff --git a/drivers/gpu/drm/bridge/ite-it6505.c b/drivers/gpu/drm/bridge/ite-it6505.c
index e136ac71edbb..e980cc6d5760 100644
--- a/drivers/gpu/drm/bridge/ite-it6505.c
+++ b/drivers/gpu/drm/bridge/ite-it6505.c
@@ -443,6 +443,7 @@ struct it6505 {
struct drm_display_mode source_output_mode;
struct drm_display_mode video_info;
struct notifier_block event_nb;
+ bool extcon_registered;
struct extcon_dev *extcon;
struct work_struct extcon_wq;
int extcon_state;
@@ -2934,11 +2935,15 @@ static int it6505_use_notifier_module(struct it6505 *it6505)
int ret;
struct device *dev = it6505->dev;
+ mutex_lock(&it6505->extcon_lock);
it6505->event_nb.notifier_call = it6505_extcon_notifier;
- INIT_WORK(&it6505->extcon_wq, it6505_extcon_work);
ret = devm_extcon_register_notifier(it6505->dev,
it6505->extcon, EXTCON_DISP_DP,
&it6505->event_nb);
+ if (!ret)
+ it6505->extcon_registered = true;
+ mutex_unlock(&it6505->extcon_lock);
+
if (ret) {
dev_err(dev, "failed to register notifier for DP");
return ret;
@@ -2951,13 +2956,16 @@ static int it6505_use_notifier_module(struct it6505 *it6505)
static void it6505_remove_notifier_module(struct it6505 *it6505)
{
- if (it6505->extcon) {
- devm_extcon_unregister_notifier(it6505->dev,
- it6505->extcon, EXTCON_DISP_DP,
+ mutex_lock(&it6505->extcon_lock);
+ if (it6505->extcon && it6505->extcon_registered) {
+ devm_extcon_unregister_notifier(it6505->dev, it6505->extcon,
+ EXTCON_DISP_DP,
&it6505->event_nb);
-
- flush_work(&it6505->extcon_wq);
+ it6505->extcon_registered = false;
}
+ mutex_unlock(&it6505->extcon_lock);
+
+ flush_work(&it6505->extcon_wq);
}
static void __maybe_unused it6505_delayed_audio(struct work_struct *work)
@@ -3613,6 +3621,7 @@ static int it6505_i2c_probe(struct i2c_client *client)
INIT_WORK(&it6505->link_works, it6505_link_training_work);
INIT_WORK(&it6505->hdcp_wait_ksv_list, it6505_hdcp_wait_ksv_list);
INIT_DELAYED_WORK(&it6505->hdcp_work, it6505_hdcp_work);
+ INIT_WORK(&it6505->extcon_wq, it6505_extcon_work);
init_completion(&it6505->extcon_completion);
memset(it6505->dpcd, 0, sizeof(it6505->dpcd));
it6505->powered = false;
@@ -3645,6 +3654,12 @@ static void it6505_i2c_remove(struct i2c_client *client)
drm_bridge_remove(&it6505->bridge);
drm_dp_aux_unregister(&it6505->aux);
it6505_debugfs_remove(it6505);
+ it6505_remove_notifier_module(it6505);
+ disable_irq(it6505->irq);
+ cancel_work_sync(&it6505->link_works);
+ cancel_work_sync(&it6505->hdcp_wait_ksv_list);
+ cancel_delayed_work_sync(&it6505->hdcp_work);
+ cancel_work_sync(&it6505->extcon_wq);
it6505_poweroff(it6505);
it6505_remove_edid(it6505);
}
--
2.55.0
next prev parent reply other threads:[~2026-09-24 18:40 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 18:39 [PATCH v7 00/14] drm/bridge: it6505: DP audio support + shared-DAI hw_params fix Daniel Golle
2026-09-24 18:40 ` Daniel Golle [this message]
2026-09-24 18:40 ` [PATCH v7 02/14] drm/bridge: it6505: quiesce work items before powering off Daniel Golle
2026-09-24 18:40 ` [PATCH v7 03/14] drm/bridge: it6505: balance and disable runtime PM on remove Daniel Golle
2026-09-24 18:40 ` [PATCH v7 04/14] drm/bridge: it6505: unregister DP AUX adapter on bridge detach Daniel Golle
2026-09-24 18:40 ` [PATCH v7 05/14] drm/bridge: it6505: complete poweroff even if disabling regulators fails Daniel Golle
2026-09-24 18:40 ` [PATCH v7 06/14] drm/bridge: it6505: bail out of the IRQ handler when status reads fail Daniel Golle
2026-09-24 18:40 ` [PATCH v7 07/14] drm/bridge: it6505: avoid division by zero in pixel clock calculation Daniel Golle
2026-09-24 18:41 ` [PATCH v7 08/14] drm/bridge: it6505: avoid division by zero in audio FS debug print Daniel Golle
2026-09-24 18:41 ` [PATCH v7 09/14] drm/bridge: it6505: guard against zero channel count in audio infoframe Daniel Golle
2026-09-24 18:41 ` [PATCH v7 10/14] drm/bridge: it6505: hold endpoint OF node reference while parsing it Daniel Golle
2026-09-24 18:42 ` [PATCH v7 11/14] drm/bridge: it6505: reject a too short link-frequencies property Daniel Golle
2026-09-24 18:42 ` [PATCH v7 12/14] drm/bridge: it6505: don't write an error code back to the reset register Daniel Golle
2026-09-24 18:42 ` [PATCH v7 13/14] drm/bridge: it6505: Add audio support Daniel Golle
2026-09-24 18:42 ` [PATCH v7 14/14] drm/bridge: it6505: Don't reject audio hw_params without an encoder Daniel Golle
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6f2f7bd3e6b259266bde53b3396a1ef87633bc85.1790275151.git.daniel@makrotopia.org \
--to=daniel@makrotopia.org \
--cc=Laurent.pinchart@ideasonboard.com \
--cc=airlied@gmail.com \
--cc=allen.chen@ite.com.tw \
--cc=andrzej.hajda@intel.com \
--cc=angelogioacchino.delregno@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=hermes.wu@ite.com.tw \
--cc=jernej.skrabec@gmail.com \
--cc=jonas@kwiboo.se \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mediatek@lists.infradead.org \
--cc=luca.ceresoli@bootlin.com \
--cc=maarten.lankhorst@linux.intel.com \
--cc=matthias.bgg@gmail.com \
--cc=mripard@kernel.org \
--cc=neil.armstrong@linaro.org \
--cc=rfoss@kernel.org \
--cc=simona@ffwll.ch \
--cc=treapking@chromium.org \
--cc=tzimmermann@suse.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®