dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Thierry Reding <thierry.reding@gmail.com>
To: dri-devel@lists.freedesktop.org
Cc: Alexandre Courbot <gnurou@gmail.com>
Subject: [PATCH 5/8] drm/tegra: dc: Fix a potential race on page-flip completion
Date: Tue, 16 Dec 2014 17:15:12 +0100	[thread overview]
Message-ID: <1418746515-24773-6-git-send-email-thierry.reding@gmail.com> (raw)
In-Reply-To: <1418746515-24773-1-git-send-email-thierry.reding@gmail.com>

From: Thierry Reding <treding@nvidia.com>

Page-flip completion could race with page-flip submission, so extend the
critical section to include all accesses to page-flip related data.

Reported-by: Alexandre Courbot <acourbot@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
---
 drivers/gpu/drm/tegra/dc.c | 10 +++++++---
 1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/drivers/gpu/drm/tegra/dc.c b/drivers/gpu/drm/tegra/dc.c
index 4c6a8a828475..28040f7e4a43 100644
--- a/drivers/gpu/drm/tegra/dc.c
+++ b/drivers/gpu/drm/tegra/dc.c
@@ -814,8 +814,12 @@ static void tegra_dc_finish_page_flip(struct tegra_dc *dc)
 	unsigned long flags, base;
 	struct tegra_bo *bo;
 
-	if (!dc->event)
+	spin_lock_irqsave(&drm->event_lock, flags);
+
+	if (!dc->event) {
+		spin_unlock_irqrestore(&drm->event_lock, flags);
 		return;
+	}
 
 	bo = tegra_fb_get_plane(crtc->primary->fb, 0);
 
@@ -825,12 +829,12 @@ static void tegra_dc_finish_page_flip(struct tegra_dc *dc)
 	tegra_dc_writel(dc, 0, DC_CMD_STATE_ACCESS);
 
 	if (base == bo->paddr + crtc->primary->fb->offsets[0]) {
-		spin_lock_irqsave(&drm->event_lock, flags);
 		drm_crtc_send_vblank_event(crtc, dc->event);
 		drm_crtc_vblank_put(crtc);
 		dc->event = NULL;
-		spin_unlock_irqrestore(&drm->event_lock, flags);
 	}
+
+	spin_unlock_irqrestore(&drm->event_lock, flags);
 }
 
 void tegra_dc_cancel_page_flip(struct drm_crtc *crtc, struct drm_file *file)
-- 
2.1.3

_______________________________________________
dri-devel mailing list
dri-devel@lists.freedesktop.org
http://lists.freedesktop.org/mailman/listinfo/dri-devel

  parent reply	other threads:[~2014-12-16 16:15 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-12-16 16:15 [PATCH 0/8] drm/tegra: Fixes for v3.19-rc1 Thierry Reding
2014-12-16 16:15 ` [PATCH 1/8] drm/irq: Add drm_crtc_send_vblank_event() Thierry Reding
2014-12-16 16:15 ` [PATCH 2/8] drm/irq: Add drm_crtc_handle_vblank() Thierry Reding
2014-12-16 16:15 ` [PATCH 3/8] drm/irq: Add drm_crtc_vblank_count() Thierry Reding
2014-12-16 21:03   ` Daniel Vetter
2014-12-16 16:15 ` [PATCH 4/8] drm/tegra: dc: Consistently use the same pipe Thierry Reding
2014-12-16 16:15 ` Thierry Reding [this message]
2014-12-18 13:45   ` [PATCH 5/8] drm/tegra: dc: Fix a potential race on page-flip completion Alexandre Courbot
2014-12-16 16:15 ` [PATCH 6/8] drm/cache: Implement drm_clflush_*() for ARM Thierry Reding
2014-12-16 16:15 ` [PATCH 7/8] drm/tegra: gem: Flush buffer objects upon allocation Thierry Reding
2014-12-16 16:15 ` [PATCH 8/8] drm/tegra: gem: Use the proper size for GEM objects Thierry Reding
2014-12-16 18:38 ` [PATCH 0/8] drm/tegra: Fixes for v3.19-rc1 Sean Paul

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1418746515-24773-6-git-send-email-thierry.reding@gmail.com \
    --to=thierry.reding@gmail.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=gnurou@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox