From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtpout-04.galae.net (smtpout-04.galae.net [185.171.202.116]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AFA1538A724 for ; Fri, 13 Mar 2026 09:57:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=185.171.202.116 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773395838; cv=none; b=DKi71D76eSoFK7ed69m+niH0lCTea58Nf8eSmjl37yZPrifhBZ14ecVhZP9YL/KVycOCAQHdiAOGSAEE9hP8RUTKO++VTnzlLRwc4+4Ajdj5xV980Yw02tKxiN0ZmGAlZvcB7mZ4AyFc01v6HhExxkuMpsO7dqn6QujTn3u7yQ8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773395838; c=relaxed/simple; bh=7nwbGDlhYWWsVfEDC3FIAEshQhM9mJiOkcZCqyEdERI=; h=Mime-Version:Content-Type:Date:Message-Id:Subject:Cc:To:From: References:In-Reply-To; b=MgpBab2+sK0notKjN/29t5TB63tNb81KdjUj+VDXn1UwY91YO0KYw2CF5J66vHvDPjGI3UyCJskpOmArfMscpHvwKW3CuLpEvxhmK+S9EmhRrPWQwK6vvgzHFL+Bl8zxsnaa1qIqvLeUkpfcbyQ1kbF90Mc5IkySH1Bv1bYq8b8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bootlin.com; spf=pass smtp.mailfrom=bootlin.com; dkim=pass (2048-bit key) header.d=bootlin.com header.i=@bootlin.com header.b=ZrUNCM8b; arc=none smtp.client-ip=185.171.202.116 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bootlin.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bootlin.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bootlin.com header.i=@bootlin.com header.b="ZrUNCM8b" Received: from smtpout-01.galae.net (smtpout-01.galae.net [212.83.139.233]) by smtpout-04.galae.net (Postfix) with ESMTPS id 02531C42700; Fri, 13 Mar 2026 09:57:35 +0000 (UTC) Received: from mail.galae.net (mail.galae.net [212.83.136.155]) by smtpout-01.galae.net (Postfix) with ESMTPS id CDC7A60027; Fri, 13 Mar 2026 09:57:12 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPSA id B582510369555; Fri, 13 Mar 2026 10:57:05 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bootlin.com; s=dkim; t=1773395831; h=from:subject:date:message-id:to:cc:mime-version:content-type: content-transfer-encoding:in-reply-to:references; bh=eKWS03vYWvtAulTKAJqEs6VwKTpPs2JFJdOpYOJ3OE4=; b=ZrUNCM8bFcWt/OXyf8fdWX2jFo8Fp7dMZqziaep1tFWQNPqvZ/liqq7viT73LxbtPT/9a3 7FraEa8PsbpgYArphpG+R2xvhm+PjIOD8wcQde+oEIOx2lJfMWXh6PJv/GHf1D6+dOfGBb 6doASvsSLRKkUTbQCFQ6++q8QjAWZjzLcXUBmiBZVKYO/EsqJbeM+kGcdqLbV4d3+r4JMk CloyF+PDYa0uYes8Ubs41LNBEB4WvlpDmTSOHtSWGoEq3vP+DTbUahlBMQ1ruUC7TwA7Hq 0OZaDbtHY+2OmJOdy5zEeSdMK2D7ZCwV2/QluTMg975WWNq8GnvKWnbCbmnBoQ== Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Fri, 13 Mar 2026 10:57:04 +0100 Message-Id: Subject: Re: [PATCH] drm/bridge: Fix refcount shown via debugfs for encoder_bridges_show() Cc: "Marco Felsch" , , To: "Liu Ying" , "Andrzej Hajda" , "Neil Armstrong" , "Robert Foss" , "Laurent Pinchart" , "Jonas Karlman" , "Jernej Skrabec" , "Maarten Lankhorst" , "Maxime Ripard" , "Thomas Zimmermann" , "David Airlie" , "Simona Vetter" From: "Luca Ceresoli" X-Mailer: aerc 0.20.1 References: <20260312-drm-misc-next-2026-03-05-fix-encoder-bridges-refcount-v1-1-b9ba3d844732@nxp.com> <53c257df-9800-48ed-a975-d7bfe4d71be1@nxp.com> In-Reply-To: <53c257df-9800-48ed-a975-d7bfe4d71be1@nxp.com> X-Last-TLS-Session-Version: TLSv1.3 On Fri Mar 13, 2026 at 9:33 AM CET, Liu Ying wrote: > On Thu, Mar 12, 2026 at 06:30:22PM +0100, Luca Ceresoli wrote: >> Hello Liu, Maxime, >> >> On Thu Mar 12, 2026 at 7:05 AM CET, Liu Ying wrote: >>> A typical bridge refcount value is 3 after a bridge chain is formed: >>> - devm_drm_bridge_alloc() initializes the refcount value to be 1. >>> - drm_bridge_add() gets an additional reference hence 2. >>> - drm_bridge_attach() gets the third reference hence 3. >>> >>> This typical refcount value aligns with allbridges_show()'s behaviour. >>> However, since encoder_bridges_show() uses >>> drm_for_each_bridge_in_chain_scoped() to automatically get/put the >>> bridge reference while iterating, a bogus reference is accidentally >>> got when showing the wrong typical refcount value as 4 to users via >>> debugfs. Fix this by caching the refcount value returned from >>> kref_read() while iterating and explicitly decreasing the cached >>> refcount value by 1 before showing it to users. >> >> Good point, indeed the refcount shown by >> /dri//encoder-0/bridges is by one unit higher than the on= e >> shown in /dri/bridges. I understand it's puzzling from a debugf= s >> user point of view. >> >> As you noticed, this is because the _scoped loop holds an extra ref on t= he >> current bridge. >> >> For other reasons I proposed a mutex for stronger protection around the >> bridge chain [v2]. With the mutex the extra ref is redundant, so in [v2] >> the extra ref is removed, thus making your patch unneeded. However Maxim= e >> asked to keep the extra ref, and so my latest iteration [v4] still has t= he >> extra ref. >> >> That series is still on the mailing list, we are still in time to redisc= uss >> it. >> >> @Maxime: based on the issue Liu is trying to work around, do you think i= t >> would make sense to go back to the initial approach for that series? >> I.e. drm_for_each_bridge_in_chain_scoped() grabs the chain lock, which i= s a >> superset of the per-bridge refcount, and thus the refcount can be droppe= d? >> This would remove the debugfs issue, slightly simplify >> drm_for_each_bridge_in_chain_scoped(), and introduce no new issues AFAIK= . > > Just my take on the chain lock approach - I agree Maxime's comment on [v2= ] > that keeping the get/put is a better than using the chain lock to ensure > the refcount is correct. The chain lock could be added later on if neede= d. Well, no, adding the chain mutex is necessary(*), otherwise Thread A could iterate over the chain while thread B is adding/removing bridges to/from the chain. And the chain mutex is a superset of the per-bridge refcount, so when adding the mutex the refcount inside drm_for_each_bridge_in_chain_scoped() becomes useless (and slightly hurting as it makes the refcount shown in debugfs inconsistent, as you noticed). (*) by "necessary" I mean it's necessary to support a bridge chain that changes after the card is populated, i.e. for bridge hotplug. Luca -- Luca Ceresoli, Bootlin Embedded Linux and Kernel engineering https://bootlin.com