All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Maarten Lankhorst" <dev@lankhorst.se>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v8 04/27] drm/intel/display: Convert vblank event handling to 2-stage arming
Date: Mon, 15 Jun 2026 20:35:31 +0000	[thread overview]
Message-ID: <20260615203532.044E71F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260615201846.307297-5-dev@lankhorst.se>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Vblank events and workers execute one frame too early if vblank evasion occurs, causing premature page flip completions and potential use-after-free.
--

commit 4b140829cb62a6227f3079e278066d8cfb9ea1b4
Author: Maarten Lankhorst <dev@lankhorst.se>

drm/intel/display: Convert vblank event handling to 2-stage arming

This converts the vblank functions to be called with interrupts disabled,
even on PREEMPT_RT kernels.

> diff --git a/drivers/gpu/drm/i915/display/intel_crtc.c b/drivers/gpu/drm/i915/display/intel_crtc.c
> index 365267c79e54f..6b71810803139 100644
> --- a/drivers/gpu/drm/i915/display/intel_crtc.c
> +++ b/drivers/gpu/drm/i915/display/intel_crtc.c
> @@ -527,6 +527,10 @@ static void intel_crtc_vblank_work_init(struct intel_crtc_state *crtc_state)
>  
>  	drm_vblank_work_init(&crtc_state->vblank_work, &crtc->base,
>  			     intel_crtc_vblank_work);
> +
> +	drm_vblank_work_schedule_disabled(&crtc_state->vblank_work,
> +					  drm_crtc_accurate_vblank_count(&crtc->base) + 1);
> +
>  	/*
>  	 * Interrupt latency is critical for getting the vblank
>  	 * work executed as early as possible during the vblank.

[ ... ]

> @@ -607,6 +626,8 @@ void intel_pipe_update_start(struct intel_atomic_state *state,
>  
>  	if (intel_crtc_needs_vblank_work(new_crtc_state))
>  		intel_crtc_vblank_work_init(new_crtc_state);
> +	else
> +		intel_crtc_arm_vblank_event(new_crtc_state);
>  
>  	if (state->base.legacy_cursor_update) {
>  		struct intel_plane *plane;

[ ... ]

> @@ -754,29 +758,10 @@ void intel_pipe_update_end(struct intel_atomic_state *state,
>  	 * event outside of the critical section - the spinlock might spin for a
>  	 * while ... */
>  	if (intel_crtc_needs_vblank_work(new_crtc_state)) {
> -		drm_vblank_work_schedule(&new_crtc_state->vblank_work,
> -					 drm_crtc_accurate_vblank_count(&crtc->base) + 1,
> -					 false);
> -	} else {
> -		intel_crtc_arm_vblank_event(new_crtc_state);
> -	}
> -
> -	if (state->base.legacy_cursor_update) {
> -		struct intel_plane *plane;
> -		struct intel_plane_state *old_plane_state;
> -		int i;
> -
> -		for_each_old_intel_plane_in_state(state, plane, old_plane_state, i) {
> -			if (old_plane_state->hw.crtc == &crtc->base &&
> -			    old_plane_state->unpin_work.vblank) {
> -				drm_vblank_work_schedule(&old_plane_state->unpin_work,
> -							 drm_crtc_accurate_vblank_count(&crtc->base) + 1,
> -							 false);
> -
> -				/* Remove plane from atomic state, cleanup/free is done from vblank worker. */
> -				memset(&state->base.planes[i], 0, sizeof(state->base.planes[i]));
> -			}
> -		}
> +		drm_vblank_work_enable(&new_crtc_state->vblank_work);
> +	} else if (new_crtc_state->uapi.event) {
> +		drm_crtc_arm_prepared_vblank_event(new_crtc_state->uapi.event);
> +		new_crtc_state->uapi.event = NULL;
>  	}

[Severity: High]
If intel_vblank_evade() spins and the hardware vblank counter increments,
will the target sequence number calculated earlier in
intel_pipe_update_start() become stale?

Since intel_crtc_vblank_work_init() and intel_crtc_arm_vblank_event() now
run before evasion, the target sequence is calculated as N + 1. If evasion
occurs, the counter increments to N + 1, and the hardware will latch the
new state at N + 2.

When drm_vblank_work_enable() or drm_crtc_arm_prepared_vblank_event() are
called here, they are still targeted for N + 1. Could this result in the
event firing immediately and signaling completion one frame before the
hardware actually latches the new display state, potentially leading to
premature freeing of the old framebuffer?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260615201846.307297-1-dev@lankhorst.se?part=4

  reply	other threads:[~2026-06-15 20:35 UTC|newest]

Thread overview: 52+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-15 20:18 [PATCH v8 00/27] drm/i915/display: All patches to make PREEMPT_RT work on i915 + xe Maarten Lankhorst
2026-06-15 20:18 ` [PATCH v8 01/27] drm/vblank_work: Add methods to schedule vblank_work in 2 stages Maarten Lankhorst
2026-06-15 20:30   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 02/27] drm/vblank: Add a 2-stage version of drm_crtc_arm_vblank_event Maarten Lankhorst
2026-06-15 20:31   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 03/27] drm/intel/display: Make intel_crtc_arm_vblank_event static Maarten Lankhorst
2026-06-15 20:18 ` [PATCH v8 04/27] drm/intel/display: Convert vblank event handling to 2-stage arming Maarten Lankhorst
2026-06-15 20:35   ` sashiko-bot [this message]
2026-06-15 20:18 ` [PATCH v8 05/27] drm/i915/display: Move vblank put until after critical section Maarten Lankhorst
2026-06-15 20:25   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 06/27] drm/i915/display: Remove locking from intel_vblank_evade " Maarten Lankhorst
2026-06-15 20:39   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 07/27] drm/i915/display: Handle vlv dsi workaround in scanline_in_safe_range too Maarten Lankhorst
2026-06-15 20:29   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 08/27] drm/i915: Use preempt_disable/enable_rt() where recommended Maarten Lankhorst
2026-06-15 20:32   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 09/27] drm/i915/display: Make get_vblank_counter use intel_de_read_fw() Maarten Lankhorst
2026-06-15 20:39   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 10/27] drm/i915/display: Do not take uncore lock in i915_get_vblank_counter Maarten Lankhorst
2026-06-15 20:35   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 11/27] drm/i915/display: Make icl_dsi_frame_update use _fw too Maarten Lankhorst
2026-06-15 20:18 ` [PATCH v8 12/27] drm/i915/display: Use intel_de_read/write_fw in colorops Maarten Lankhorst
2026-06-15 20:18 ` [PATCH v8 13/27] drm/i915/display: Use intel_de_write_fw in intel_pipe_fastset Maarten Lankhorst
2026-06-15 20:46   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 14/27] drm/i915/display: Make set_pipeconf use the fw variants Maarten Lankhorst
2026-06-15 20:44   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 15/27] drm/i915/gt: Use spin_lock_irq() instead of local_irq_disable() + spin_lock() Maarten Lankhorst
2026-06-15 20:39   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 16/27] drm/i915: Drop the irqs_disabled() check Maarten Lankhorst
2026-06-15 20:18 ` [PATCH v8 17/27] drm/i915/guc: Consider also RCU depth in busy loop Maarten Lankhorst
2026-06-15 20:18 ` [PATCH v8 18/27] drm/i915/gt: Fix selftests on PREEMPT_RT Maarten Lankhorst
2026-06-15 20:18 ` [PATCH v8 19/27] drm/i915/gt: Set stop_timeout() correctly on PREEMPT-RT Maarten Lankhorst
2026-06-15 20:18 ` [PATCH v8 20/27] drm/i915/display: Remove uncore lock from vlv_atomic_update_fifo Maarten Lankhorst
2026-06-15 20:36   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 21/27] drm/i915: Use sleeping selftests for igt_atomic on PREEMPT_RT Maarten Lankhorst
2026-06-15 20:18 ` [PATCH v8 22/27] Revert "drm/i915: Depend on !PREEMPT_RT." Maarten Lankhorst
2026-06-15 20:18 ` [PATCH v8 23/27] PREEMPT_RT injection Maarten Lankhorst
2026-06-15 20:39   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 24/27] FOR-CI: bump MAX_STACK_TRACE_ENTRIES Maarten Lankhorst
2026-06-15 20:35   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 25/27] drm/i915/gt: Add a spinlock to prevent starvation of irq_work Maarten Lankhorst
2026-06-15 20:38   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 26/27] drm/xe/display: Always use system memory on PREEMPT_RT for DPT Maarten Lankhorst
2026-06-15 20:39   ` sashiko-bot
2026-06-15 20:18 ` [PATCH v8 27/27] drm/xe/display: Prefer not to allocate a framebuffers in stolen memory Maarten Lankhorst
2026-06-15 20:41   ` sashiko-bot
2026-06-15 20:33 ` ✗ CI.checkpatch: warning for drm/i915/display: All patches to make PREEMPT_RT work on i915 + xe. (rev16) Patchwork
2026-06-15 20:34 ` ✓ CI.KUnit: success " Patchwork
2026-06-15 20:50 ` ✗ CI.checksparse: warning " Patchwork
2026-06-15 21:27 ` ✗ Xe.CI.BAT: failure " Patchwork
2026-06-15 21:48 ` ✗ i915.CI.BAT: " Patchwork
2026-06-15 23:22 ` ✗ Xe.CI.FULL: " Patchwork

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260615203532.044E71F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dev@lankhorst.se \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.