From mboxrd@z Thu Jan 1 00:00:00 1970 From: Laurent Pinchart Subject: Re: [PATCH] qxl: fix null-pointer crash during suspend Date: Tue, 02 Oct 2018 13:05:50 +0300 Message-ID: <1688275.zophSNHJ2k@avalon> References: <20180904202747.14968-1-peter@lekensteyn.nl> <20181002081422.GH11082@phenom.ffwll.local> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Return-path: Received: from perceval.ideasonboard.com (perceval.ideasonboard.com [IPv6:2001:4b98:dc2:55:216:3eff:fef7:d647]) by gabe.freedesktop.org (Postfix) with ESMTPS id 497026E0CC for ; Tue, 2 Oct 2018 10:05:36 +0000 (UTC) In-Reply-To: <20181002081422.GH11082@phenom.ffwll.local> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dri-devel-bounces@lists.freedesktop.org Sender: "dri-devel" To: Daniel Vetter Cc: Laurent Pinchart , linux-kernel@vger.kernel.org, dri-devel@lists.freedesktop.org, virtualization@lists.linux-foundation.org, Alan Jenkins , Peter Wu , Dave Airlie , Gerd Hoffmann List-Id: dri-devel@lists.freedesktop.org SGVsbG8sCgpPbiBUdWVzZGF5LCAyIE9jdG9iZXIgMjAxOCAxMToxNDoyMiBFRVNUIERhbmllbCBW ZXR0ZXIgd3JvdGU6Cj4gT24gVHVlLCBTZXAgMDQsIDIwMTggYXQgMTA6Mjc6NDdQTSArMDIwMCwg UGV0ZXIgV3Ugd3JvdGU6Cj4gPiAiY3J0Yy0+aGVscGVyX3ByaXZhdGUiIGlzIG5vdCBpbml0aWFs aXplZCBieSB0aGUgUVhMIGRyaXZlciBhbmQgdGh1cyB0aGUKPiAKPiBUaGlzIGlzIHN0aWxsIGlu aXRpYWxpemVkLCBpdCdzIHRoZSAtPmRpc2FibGUgdGhhdCBnb2VzIGJvb20uIEF0IGxlYXN0IHRo ZQo+IGNhbGwgdG8gZHJtX2NydGNfaGVscGVyX2FkZCBpcyBzdGlsbCB0aGVyZS4gVGhlIC0+ZGlz YWJsZSB3YXMgcmVtb3ZlZCBpbjoKPiAKPiBjb21taXQgNjQ1ODE3MTRiNThiYzNlMTZlZGU4ZGMz N2EwMjVjM2FhMGUwZWVmMQo+IEF1dGhvcjogTGF1cmVudCBQaW5jaGFydCA8bGF1cmVudC5waW5j aGFydCtyZW5lc2FzQGlkZWFzb25ib2FyZC5jb20+Cj4gRGF0ZTogICBGcmkgSnVuIDMwIDEyOjM2 OjQ1IDIwMTcgKzAzMDAKPiAKPiAgICAgZHJtOiBDb252ZXJ0IGF0b21pYyBkcml2ZXJzIGZyb20g Q1JUQyAuZGlzYWJsZSgpIHRvIC5hdG9taWNfZGlzYWJsZSgpCj4gCj4gRml4ZXM6IDY0NTgxNzE0 YjU4YiAoImRybTogQ29udmVydCBhdG9taWMgZHJpdmVycyBmcm9tIENSVEMgLmRpc2FibGUoKSB0 bwo+IC5hdG9taWNfZGlzYWJsZSgpIikgQ2M6IDxzdGFibGVAdmdlci5rZXJuZWwub3JnPiAjIHY0 LjE0Kwo+IFJldmlld2VkLWJ5OiBEYW5pZWwgVmV0dGVyIDxkYW5pZWwudmV0dGVyQGZmd2xsLmNo Pgo+IAo+IEknbGwgbGV0IEdlcmQgcGljayB0aGlzIG9uZSB1cCwgYWZ0ZXIgc29tZSB0ZXN0aW5n LiBBbHNvIGFkZGluZyBMYXVyZW50LgoKU29ycnkgZm9yIGJyZWFraW5nIGl0IDotKCBQbGVhc2Ug bGV0IG1lIGtub3cgaWYgdGhlcmUncyBzb21ldGhpbmcgSSBjYW4gZG8gdG8gCmhlbHAuCgo+ID4g ImNydGNfZnVuY3MtPmRpc2FibGUiIGNhbGwgd291bGQgY3Jhc2ggKHJlc3VsdGluZyBpbiBzdXNw ZW5kIGZhaWx1cmUpLgo+ID4gRml4IHRoaXMgYnkgY29udmVydGluZyB0aGUgc3VzcGVuZC9yZXN1 bWUgZnVuY3Rpb25zIHRvIHVzZSB0aGUKPiA+IGRybV9tb2RlX2NvbmZpZ19oZWxwZXJfKiBoZWxw ZXJzLgo+ID4gCj4gPiBUZXN0ZWQgc3lzdGVtIHNsZWVwIHdpdGggUUVNVSAzLjAgdXNpbmcgImVj aG8gbWVtID4gL3N5cy9wb3dlci9zdGF0ZSIuCj4gPiAKPiA+IER1cmluZyBzdXNwZW5kIHRoZSBm b2xsb3dpbmcgbWVzc2FnZSBpcyB2aXNpYmxlIGZyb20gUUVNVToKPiA+ICAgICBzcGljZS9zZXJ2 ZXIvZGlzcGxheS1jaGFubmVsLmM6MjQyNTpkaXNwbGF5X2NoYW5uZWxfdmFsaWRhdGVfc3VyZmFj ZToKPiA+ICAgICBjYW52YXMgYWRkcmVzcyBpcyAweDdmZDA1ZGE2ODMwOCBmb3IgMCAoYW5kIGlz IE5VTEwpCj4gPiAgICAgc3BpY2Uvc2VydmVyL2Rpc3BsYXktY2hhbm5lbC5jOjI0MjY6ZGlzcGxh eV9jaGFubmVsX3ZhbGlkYXRlX3N1cmZhY2U6Cj4gPiAgICAgZmFpbGVkIG9uIDA+IAo+ID4gVGhp cyBzZWVtcyB0byBiZSB0cmlnZ2VyZWQgYnkgUVhMX0lPX05PVElGWV9DTUQgYWZ0ZXIKPiA+IFFY TF9JT19ERVNUUk9ZX1BSSU1BUllfQVNZTkMsIGJ1dCBhc2lkZSBmcm9tIHRoZSB3YXJuaW5nIHRo aW5ncyBzdGlsbAo+ID4gc2VlbSB0byB3b3JrICh0ZXN0ZWQgd2l0aCBib3RoIHRoZSBHVEsgYW5k IC1zcGljZSBvcHRpb25zKS4KPiA+IAo+ID4gU2lnbmVkLW9mZi1ieTogUGV0ZXIgV3UgPHBldGVy QGxla2Vuc3RleW4ubmw+Cj4gPiAtLS0KPiA+IEhpLAo+ID4gCj4gPiBJIGZvdW5kIHRoaXMgaXNz dWUgd2hpbGUgdHJ5aW5nIHRvIHN1c3BlbmQgYSBWTSB0aGF0IHVzZXMgUVhMLiBJbiBvcmRlciB0 bwo+ID4gc2VlIHRoZSBzdGFjayB0cmFjZSBvdmVyIHNlcmlhbCwgYm9vdCB3aXRoIG5vX2NvbnNv bGVfc3VzcGVuZC4gU2VhcmNoaW5nCj4gPiBmb3IgInF4bF9kcm1fZnJlZXplIiBzaG93ZWQgb25l IHJlY2VudCByZXBvcnQgZnJvbSBBbGFuOgo+ID4gaHR0cHM6Ly9sa21sLmtlcm5lbC5vcmcvci84 OTFlMzM0Yy1jZjE5LTAzMmMtYjk5Ni01OWFjMTY2ZmNkZTFAZ21haWwuY29tCj4gPiAKPiA+IEtp bmQgcmVnYXJkcywKPiA+IFBldGVyCj4gPiAtLS0KPiA+IAo+ID4gIGRyaXZlcnMvZ3B1L2RybS9x eGwvcXhsX2Rydi5jIHwgMjYgKysrKystLS0tLS0tLS0tLS0tLS0tLS0tLS0KPiA+ICAxIGZpbGUg Y2hhbmdlZCwgNSBpbnNlcnRpb25zKCspLCAyMSBkZWxldGlvbnMoLSkKPiA+IAo+ID4gZGlmZiAt LWdpdCBhL2RyaXZlcnMvZ3B1L2RybS9xeGwvcXhsX2Rydi5jIGIvZHJpdmVycy9ncHUvZHJtL3F4 bC9xeGxfZHJ2LmMKPiA+IGluZGV4IDI0NDVlNzVjZjdlYS4uZDAwZjQ1ZWVkMDNjIDEwMDY0NAo+ ID4gLS0tIGEvZHJpdmVycy9ncHUvZHJtL3F4bC9xeGxfZHJ2LmMKPiA+ICsrKyBiL2RyaXZlcnMv Z3B1L2RybS9xeGwvcXhsX2Rydi5jCj4gPiBAQCAtMTM2LDIwICsxMzYsMTEgQEAgc3RhdGljIGlu dCBxeGxfZHJtX2ZyZWV6ZShzdHJ1Y3QgZHJtX2RldmljZSAqZGV2KQo+ID4gCj4gPiAgewo+ID4g IAo+ID4gIAlzdHJ1Y3QgcGNpX2RldiAqcGRldiA9IGRldi0+cGRldjsKPiA+ICAJc3RydWN0IHF4 bF9kZXZpY2UgKnFkZXYgPSBkZXYtPmRldl9wcml2YXRlOwo+ID4gCj4gPiAtCXN0cnVjdCBkcm1f Y3J0YyAqY3J0YzsKPiA+IC0KPiA+IC0JZHJtX2ttc19oZWxwZXJfcG9sbF9kaXNhYmxlKGRldik7 Cj4gPiAtCj4gPiAtCWNvbnNvbGVfbG9jaygpOwo+ID4gLQlxeGxfZmJkZXZfc2V0X3N1c3BlbmQo cWRldiwgMSk7Cj4gPiAtCWNvbnNvbGVfdW5sb2NrKCk7Cj4gPiArCWludCByZXQ7Cj4gPiAKPiA+ IC0JLyogdW5waW4gdGhlIGZyb250IGJ1ZmZlcnMgKi8KPiA+IC0JbGlzdF9mb3JfZWFjaF9lbnRy eShjcnRjLCAmZGV2LT5tb2RlX2NvbmZpZy5jcnRjX2xpc3QsIGhlYWQpIHsKPiA+IC0JCWNvbnN0 IHN0cnVjdCBkcm1fY3J0Y19oZWxwZXJfZnVuY3MgKmNydGNfZnVuY3MgPSBjcnRjLQo+aGVscGVy X3ByaXZhdGU7Cj4gPiAtCQlpZiAoY3J0Yy0+ZW5hYmxlZCkKPiA+IC0JCQkoKmNydGNfZnVuY3Mt PmRpc2FibGUpKGNydGMpOwo+ID4gLQl9Cj4gPiArCXJldCA9IGRybV9tb2RlX2NvbmZpZ19oZWxw ZXJfc3VzcGVuZChkZXYpOwo+ID4gKwlpZiAocmV0KQo+ID4gKwkJcmV0dXJuIHJldDsKPiA+IAo+ ID4gIAlxeGxfZGVzdHJveV9tb25pdG9yc19vYmplY3QocWRldik7Cj4gPiAgCXF4bF9zdXJmX2V2 aWN0KHFkZXYpOwo+ID4gCj4gPiBAQCAtMTc1LDE0ICsxNjYsNyBAQCBzdGF0aWMgaW50IHF4bF9k cm1fcmVzdW1lKHN0cnVjdCBkcm1fZGV2aWNlICpkZXYsCj4gPiBib29sIHRoYXcpPiAKPiA+ICAJ fQo+ID4gIAkKPiA+ICAJcXhsX2NyZWF0ZV9tb25pdG9yc19vYmplY3QocWRldik7Cj4gPiAKPiA+ IC0JZHJtX2hlbHBlcl9yZXN1bWVfZm9yY2VfbW9kZShkZXYpOwo+ID4gLQo+ID4gLQljb25zb2xl X2xvY2soKTsKPiA+IC0JcXhsX2ZiZGV2X3NldF9zdXNwZW5kKHFkZXYsIDApOwo+ID4gLQljb25z b2xlX3VubG9jaygpOwo+ID4gLQo+ID4gLQlkcm1fa21zX2hlbHBlcl9wb2xsX2VuYWJsZShkZXYp Owo+ID4gLQlyZXR1cm4gMDsKPiA+ICsJcmV0dXJuIGRybV9tb2RlX2NvbmZpZ19oZWxwZXJfcmVz dW1lKGRldik7Cj4gPiAKPiA+ICB9Cj4gPiAgCj4gPiAgc3RhdGljIGludCBxeGxfcG1fc3VzcGVu ZChzdHJ1Y3QgZGV2aWNlICpkZXYpCgoKLS0gClJlZ2FyZHMsCgpMYXVyZW50IFBpbmNoYXJ0CgoK Cl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fCmRyaS1kZXZl bCBtYWlsaW5nIGxpc3QKZHJpLWRldmVsQGxpc3RzLmZyZWVkZXNrdG9wLm9yZwpodHRwczovL2xp c3RzLmZyZWVkZXNrdG9wLm9yZy9tYWlsbWFuL2xpc3RpbmZvL2RyaS1kZXZlbAo= From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.8 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH,MAILING_LIST_MULTI, SIGNED_OFF_BY,SPF_PASS,URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2353AC43143 for ; Tue, 2 Oct 2018 10:05:39 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id DB4D420645 for ; Tue, 2 Oct 2018 10:05:38 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (1024-bit key) header.d=ideasonboard.com header.i=@ideasonboard.com header.b="nIhD2XX3" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org DB4D420645 Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=ideasonboard.com Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727619AbeJBQsF (ORCPT ); Tue, 2 Oct 2018 12:48:05 -0400 Received: from perceval.ideasonboard.com ([213.167.242.64]:40326 "EHLO perceval.ideasonboard.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726178AbeJBQsF (ORCPT ); Tue, 2 Oct 2018 12:48:05 -0400 Received: from avalon.localnet (dfj612ybrt5fhg77mgycy-3.rev.dnainternet.fi [IPv6:2001:14ba:21f5:5b00:2e86:4862:ef6a:2804]) by perceval.ideasonboard.com (Postfix) with ESMTPSA id BCB57B7F; Tue, 2 Oct 2018 12:05:33 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ideasonboard.com; s=mail; t=1538474734; bh=T1m9qReArjdzu/gT/PvWRp9Ej0V6qc/h5NHTJKbh7UY=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=nIhD2XX3X2N9GogC09gaI4y8WJNXIet+3ckvAYCu69baNW8f19qM8yXX7vyiBNzFB hxQHDL6LvaRIb0ufgbSTSkV7cu+cFzX/YeEMKcQX0g+6i5imN/U71wMjNKTym7qSHE 9+lF9zhG/HB2WZHZMNYknwhvQtbKvuOzad8zD6/c= From: Laurent Pinchart To: Daniel Vetter Cc: Peter Wu , Laurent Pinchart , Dave Airlie , Gerd Hoffmann , Alan Jenkins , linux-kernel@vger.kernel.org, dri-devel@lists.freedesktop.org, virtualization@lists.linux-foundation.org Subject: Re: [PATCH] qxl: fix null-pointer crash during suspend Date: Tue, 02 Oct 2018 13:05:50 +0300 Message-ID: <1688275.zophSNHJ2k@avalon> Organization: Ideas on Board Oy In-Reply-To: <20181002081422.GH11082@phenom.ffwll.local> References: <20180904202747.14968-1-peter@lekensteyn.nl> <20181002081422.GH11082@phenom.ffwll.local> MIME-Version: 1.0 Content-Transfer-Encoding: 7Bit Content-Type: text/plain; charset="us-ascii" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hello, On Tuesday, 2 October 2018 11:14:22 EEST Daniel Vetter wrote: > On Tue, Sep 04, 2018 at 10:27:47PM +0200, Peter Wu wrote: > > "crtc->helper_private" is not initialized by the QXL driver and thus the > > This is still initialized, it's the ->disable that goes boom. At least the > call to drm_crtc_helper_add is still there. The ->disable was removed in: > > commit 64581714b58bc3e16ede8dc37a025c3aa0e0eef1 > Author: Laurent Pinchart > Date: Fri Jun 30 12:36:45 2017 +0300 > > drm: Convert atomic drivers from CRTC .disable() to .atomic_disable() > > Fixes: 64581714b58b ("drm: Convert atomic drivers from CRTC .disable() to > .atomic_disable()") Cc: # v4.14+ > Reviewed-by: Daniel Vetter > > I'll let Gerd pick this one up, after some testing. Also adding Laurent. Sorry for breaking it :-( Please let me know if there's something I can do to help. > > "crtc_funcs->disable" call would crash (resulting in suspend failure). > > Fix this by converting the suspend/resume functions to use the > > drm_mode_config_helper_* helpers. > > > > Tested system sleep with QEMU 3.0 using "echo mem > /sys/power/state". > > > > During suspend the following message is visible from QEMU: > > spice/server/display-channel.c:2425:display_channel_validate_surface: > > canvas address is 0x7fd05da68308 for 0 (and is NULL) > > spice/server/display-channel.c:2426:display_channel_validate_surface: > > failed on 0> > > This seems to be triggered by QXL_IO_NOTIFY_CMD after > > QXL_IO_DESTROY_PRIMARY_ASYNC, but aside from the warning things still > > seem to work (tested with both the GTK and -spice options). > > > > Signed-off-by: Peter Wu > > --- > > Hi, > > > > I found this issue while trying to suspend a VM that uses QXL. In order to > > see the stack trace over serial, boot with no_console_suspend. Searching > > for "qxl_drm_freeze" showed one recent report from Alan: > > https://lkml.kernel.org/r/891e334c-cf19-032c-b996-59ac166fcde1@gmail.com > > > > Kind regards, > > Peter > > --- > > > > drivers/gpu/drm/qxl/qxl_drv.c | 26 +++++--------------------- > > 1 file changed, 5 insertions(+), 21 deletions(-) > > > > diff --git a/drivers/gpu/drm/qxl/qxl_drv.c b/drivers/gpu/drm/qxl/qxl_drv.c > > index 2445e75cf7ea..d00f45eed03c 100644 > > --- a/drivers/gpu/drm/qxl/qxl_drv.c > > +++ b/drivers/gpu/drm/qxl/qxl_drv.c > > @@ -136,20 +136,11 @@ static int qxl_drm_freeze(struct drm_device *dev) > > > > { > > > > struct pci_dev *pdev = dev->pdev; > > struct qxl_device *qdev = dev->dev_private; > > > > - struct drm_crtc *crtc; > > - > > - drm_kms_helper_poll_disable(dev); > > - > > - console_lock(); > > - qxl_fbdev_set_suspend(qdev, 1); > > - console_unlock(); > > + int ret; > > > > - /* unpin the front buffers */ > > - list_for_each_entry(crtc, &dev->mode_config.crtc_list, head) { > > - const struct drm_crtc_helper_funcs *crtc_funcs = crtc- >helper_private; > > - if (crtc->enabled) > > - (*crtc_funcs->disable)(crtc); > > - } > > + ret = drm_mode_config_helper_suspend(dev); > > + if (ret) > > + return ret; > > > > qxl_destroy_monitors_object(qdev); > > qxl_surf_evict(qdev); > > > > @@ -175,14 +166,7 @@ static int qxl_drm_resume(struct drm_device *dev, > > bool thaw)> > > } > > > > qxl_create_monitors_object(qdev); > > > > - drm_helper_resume_force_mode(dev); > > - > > - console_lock(); > > - qxl_fbdev_set_suspend(qdev, 0); > > - console_unlock(); > > - > > - drm_kms_helper_poll_enable(dev); > > - return 0; > > + return drm_mode_config_helper_resume(dev); > > > > } > > > > static int qxl_pm_suspend(struct device *dev) -- Regards, Laurent Pinchart