From: Daniel Vetter <daniel@ffwll.ch>
To: Russell King - ARM Linux <linux@arm.linux.org.uk>
Cc: linux-arm-kernel@lists.infradead.org,
Rob Clark <robdclark@gmail.com>,
Jason Cooper <jason@lakedaemon.net>,
dri-devel@lists.freedesktop.org,
Sebastian Hesselbarth <sebastian.hesselbarth@gmail.com>
Subject: Re: [PATCH RFC 2/8] DRM: Armada: Add Armada DRM driver
Date: Fri, 14 Jun 2013 15:53:41 +0200 [thread overview]
Message-ID: <20130614135341.GJ23483@phenom.ffwll.local> (raw)
In-Reply-To: <20130613115016.GB18614@n2100.arm.linux.org.uk>
On Thu, Jun 13, 2013 at 12:50:16PM +0100, Russell King - ARM Linux wrote:
> On Thu, Jun 13, 2013 at 12:19:03PM +0100, Russell King - ARM Linux wrote:
> > The deeper I look, the more bugs there seem to be in this DRM stuff,
> > and I'm continuing to look because I'm chasing a framebuffer refcount
> > bug.
>
> So, this refcount bug - I think I've just found it. This is the flow of
> references to the new fb on mode set:
>
> drm_mode_setcrtc():
> fb = drm_framebuffer_lookup(dev, crtc_req->fb_id);
> set.fb = fb;
> ret = drm_mode_set_config_internal(&set);
> drm_mode_set_config_internal():
> fb = set->fb;
> ret = crtc->funcs->set_config(set);
> drm_crtc_helper_set_config():
> old_fb = set->crtc->fb;
> set->crtc->fb = set->fb;
> if (!drm_crtc_helper_set_mode(set->crtc, set->mode,
> set->x, set->y,
> old_fb)) {
> drm_helper_disable_unused_functions(dev);
> drm_helper_disable_unused_functions():
> list_for_each_entry(crtc, &dev->mode_config.crtc_list, head) {
> crtc->enabled = drm_helper_crtc_in_use(crtc);
> if (!crtc->enabled) {
> crtc->fb = NULL;
> }
> }
> back to drm_mode_set_config_internal():
> if (ret == 0) {
> if (fb)
> drm_framebuffer_reference(fb);
> back to drm_mode_setcrtc():
> if (fb)
> drm_framebuffer_unreference(fb);
>
> Assuming success all the way through, what happens when a CRTC is unused
> is:
>
> 1. We obtain a reference in drm_mode_setcrtc() via the lookup.
> 2. We set the mode
> 3. In trying to set the mode, we discover that all connectors for the CRTC
> are in the disconnected state, and so we disable the CRTC
> 4. We set crtc->fb to NULL
> 5. back in drm_mode_set_config_internal(), we take a reference on the
> framebuffer irrespective of this.
> 6. back in drm_mode_setcrtc(), we drop the original reference caused by
> the lookup.
>
> We now have a framebuffer with a reference count incremented by one but
> no actual reference to it - the CRTC's reference is completely lost by
> the action of drm_helper_disable_unused_functions().
>
> You could argue that it's something the driver should deal with - fine,
> but what if it only implements the DPMS method? Should it drop a
> reference to the framebuffer when DPMS instructs it to turn off? Surely
> not, because that means when DPMS turns stuff back on you're missing a
> refcount.
>
> Are drivers required to implement a disable function and cater for the
> imbalance in the upper layers of code? If so, this is not a clean
> design.
Yep, if your driver grabs additional references (underlying gem object,
pinning, whatever) you need to wire up your own ->disable hook to drop
those. Note that for truly dumb kms drivers which only ever allocate an
fb, the upper layer actually _does_ take care of all the refcounting.
Also note the crtc helpers in drm_crtc_helper.c are purely optional. The
real drm core -> driver interface is all contained in drm_crtc.c. And crtc
helpers do make a few critical design assumptions about how your hw works
(and there's a bit room for api cleanup, I agree on that). So if they
simply don't work out for you no one will get upset if you roll your own
modeset infrastructure. And in drm/i915 we've had to do just that since
the impedance mismatch between crtc helper assumptions and what our hw
needed grew to big (and in really fundamental ways, not just a bit of
interface ugliness like you're seeing here).
-Daniel
--
Daniel Vetter
Software Engineer, Intel Corporation
+41 (0) 79 365 57 48 - http://blog.ffwll.ch
next prev parent reply other threads:[~2013-06-14 13:53 UTC|newest]
Thread overview: 60+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-06-09 19:06 [RFC v2 0/8] rmk's Dove DRM/TDA19988 Cubox driver Russell King - ARM Linux
2013-06-09 19:29 ` [PATCH RFC 2/8] DRM: Armada: Add Armada DRM driver Russell King
2013-06-10 11:10 ` Sebastian Hesselbarth
2013-06-10 21:48 ` Russell King - ARM Linux
2013-06-10 21:56 ` Sebastian Hesselbarth
2013-06-10 15:57 ` Rob Clark
2013-06-10 17:06 ` Russell King - ARM Linux
2013-06-10 19:59 ` Rob Clark
2013-06-10 20:08 ` Russell King - ARM Linux
2013-06-10 21:01 ` Rob Clark
2013-06-10 21:15 ` Russell King - ARM Linux
2013-06-10 22:49 ` Rob Clark
2013-06-10 22:56 ` Russell King - ARM Linux
2013-06-10 23:17 ` Rob Clark
2013-06-10 23:24 ` Dave Airlie
2013-06-10 23:35 ` Rob Clark
2013-06-10 23:36 ` Russell King - ARM Linux
2013-06-10 23:48 ` Dave Airlie
2013-06-10 23:56 ` Russell King - ARM Linux
2013-06-12 13:48 ` Russell King - ARM Linux
2013-06-12 13:56 ` Rob Clark
2013-06-12 16:49 ` Russell King - ARM Linux
2013-06-12 17:05 ` Russell King - ARM Linux
2013-06-12 19:40 ` Russell King - ARM Linux
2013-06-12 23:00 ` Russell King - ARM Linux
2013-06-13 0:17 ` Rob Clark
2013-06-13 11:19 ` Russell King - ARM Linux
2013-06-13 11:50 ` Russell King - ARM Linux
2013-06-13 13:03 ` Russell King - ARM Linux
2013-06-14 14:23 ` Daniel Vetter
2013-06-14 14:42 ` Russell King - ARM Linux
2013-06-14 19:50 ` Daniel Vetter
2013-06-14 22:15 ` Russell King - ARM Linux
2013-06-14 22:36 ` Daniel Vetter
2013-06-14 13:53 ` Daniel Vetter [this message]
2013-06-14 14:27 ` Russell King - ARM Linux
2013-06-13 12:52 ` Rob Clark
2013-06-13 12:58 ` Daniel Vetter
2013-06-12 20:04 ` Rob Clark
2013-06-10 23:38 ` Russell King - ARM Linux
2013-06-10 23:49 ` Rob Clark
2013-06-10 22:01 ` Daniel Vetter
2013-06-10 22:32 ` Russell King - ARM Linux
2013-06-10 23:12 ` Rob Clark
2013-06-11 7:33 ` Daniel Vetter
2013-06-11 8:08 ` Ville Syrjälä
2013-06-10 21:38 ` Russell King - ARM Linux
2013-06-09 19:30 ` [PATCH RFC 3/8] drm/i2c: nxp-tda998x: fix EDID reading on TDA19988 devices Russell King
2013-06-09 19:31 ` [PATCH RFC 4/8] drm/i2c: nxp-tda998x: ensure VIP output mux is properly set Russell King
2013-06-09 19:32 ` [PATCH RFC 5/8] drm/i2c: nxp-tda998x: fix npix/nline programming Russell King
2013-06-09 20:02 ` Sebastian Hesselbarth
2013-06-09 19:34 ` [PATCH RFC 6/8] drm/i2c: nxp-tda998x: prepare for video input configuration Russell King
2013-06-09 19:35 ` [PATCH RFC 7/8] drm/i2c: nxp-tda998x: add video and audio " Russell King
2013-06-09 19:36 ` [PATCH RFC 8/8] DRM: Armada: add support for drm tda19988 driver Russell King
2013-06-09 19:43 ` [RFC v2 0/8] rmk's Dove DRM/TDA19988 Cubox driver Russell King - ARM Linux
2013-06-10 22:47 ` [RFC v3 0/4] " Russell King - ARM Linux
2013-06-10 22:48 ` [PATCH RFC v3 1/4] DRM: Armada: Add Armada DRM driver Russell King
2013-06-10 22:49 ` [PATCH RFC v3 2/4] DRM: Armada: Add support for hardware cursors Russell King
2013-06-10 22:50 ` [PATCH RFC v3 3/4] DRM: Armada: convert Armada hardware cursor support to RGB+transparency Russell King
2013-06-10 22:51 ` [PATCH RFC v3 4/4] DRM: Armada: convert hardware cursor support to 64x32 or 32x64 ARGB Russell King
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20130614135341.GJ23483@phenom.ffwll.local \
--to=daniel@ffwll.ch \
--cc=dri-devel@lists.freedesktop.org \
--cc=jason@lakedaemon.net \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux@arm.linux.org.uk \
--cc=robdclark@gmail.com \
--cc=sebastian.hesselbarth@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox