dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
  • * [PATCH AUTOSEL 5.0 078/262] drm/amd/display: Fix reference counting for struct dc_sink.
           [not found] <20190327180158.10245-1-sashal@kernel.org>
           [not found] ` <20190327180158.10245-1-sashal-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org>
    @ 2019-03-27 17:58 ` Sasha Levin
      2019-03-27 17:59 ` [PATCH AUTOSEL 5.0 114/262] drm/amd/display: Clear stream->mode_changed after commit Sasha Levin
                       ` (13 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 17:58 UTC (permalink / raw)
      To: linux-kernel, stable
      Cc: Alex Deucher, Sasha Levin, dri-devel, amd-gfx,
    	Mathias Fröhlich
    
    From: Mathias Fröhlich <Mathias.Froehlich@web.de>
    
    [ Upstream commit dcd5fb82ffb484124203aa339733663ac0b059f3 ]
    
    Reference counting in amdgpu_dm_connector for amdgpu_dm_connector::dc_sink
    and amdgpu_dm_connector::dc_em_sink as well as in dc_link::local_sink seems
    to be out of shape. Thus make reference counting consistent for these
    members and just plain increment the reference count when the variable
    gets assigned and decrement when the pointer is set to zero or replaced.
    Also simplify reference counting in selected function sopes to be sure the
    reference is released in any case. In some cases add NULL pointer check
    before dereferencing.
    At a hand full of places a comment is placed to stat that the reference
    increment happened already somewhere else.
    
    This actually fixes the following kernel bug on my system when enabling
    display core in amdgpu. There are some more similar bug reports around,
    so it probably helps at more places.
    
       kernel BUG at mm/slub.c:294!
       invalid opcode: 0000 [#1] SMP PTI
       CPU: 9 PID: 1180 Comm: Xorg Not tainted 5.0.0-rc1+ #2
       Hardware name: Supermicro X10DAi/X10DAI, BIOS 3.0a 02/05/2018
       RIP: 0010:__slab_free+0x1e2/0x3d0
       Code: 8b 54 24 30 48 89 4c 24 28 e8 da fb ff ff 4c 8b 54 24 28 85 c0 0f 85 67 fe ff ff 48 8d 65 d8 5b 41 5c 41 5d 41 5e 41 5f 5d c3 <0f> 0b 49 3b 5c 24 28 75 ab 48 8b 44 24 30 49 89 4c 24 28 49 89 44
       RSP: 0018:ffffb0978589fa90 EFLAGS: 00010246
       RAX: ffff92f12806c400 RBX: 0000000080200019 RCX: ffff92f12806c400
       RDX: ffff92f12806c400 RSI: ffffdd6421a01a00 RDI: ffff92ed2f406e80
       RBP: ffffb0978589fb40 R08: 0000000000000001 R09: ffffffffc0ee4748
       R10: ffff92f12806c400 R11: 0000000000000001 R12: ffffdd6421a01a00
       R13: ffff92f12806c400 R14: ffff92ed2f406e80 R15: ffffdd6421a01a20
       FS:  00007f4170be0ac0(0000) GS:ffff92ed2fb40000(0000) knlGS:0000000000000000
       CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
       CR2: 0000562818aaa000 CR3: 000000045745a002 CR4: 00000000003606e0
       DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
       DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
       Call Trace:
        ? drm_dbg+0x87/0x90 [drm]
        dc_stream_release+0x28/0x50 [amdgpu]
        amdgpu_dm_connector_mode_valid+0xb4/0x1f0 [amdgpu]
        drm_helper_probe_single_connector_modes+0x492/0x6b0 [drm_kms_helper]
        drm_mode_getconnector+0x457/0x490 [drm]
        ? drm_connector_property_set_ioctl+0x60/0x60 [drm]
        drm_ioctl_kernel+0xa9/0xf0 [drm]
        drm_ioctl+0x201/0x3a0 [drm]
        ? drm_connector_property_set_ioctl+0x60/0x60 [drm]
        amdgpu_drm_ioctl+0x49/0x80 [amdgpu]
        do_vfs_ioctl+0xa4/0x630
        ? __sys_recvmsg+0x83/0xa0
        ksys_ioctl+0x60/0x90
        __x64_sys_ioctl+0x16/0x20
        do_syscall_64+0x5b/0x160
        entry_SYSCALL_64_after_hwframe+0x44/0xa9
       RIP: 0033:0x7f417110809b
       Code: 0f 1e fa 48 8b 05 ed bd 0c 00 64 c7 00 26 00 00 00 48 c7 c0 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa b8 10 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d bd bd 0c 00 f7 d8 64 89 01 48
       RSP: 002b:00007ffdd8d1c268 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
       RAX: ffffffffffffffda RBX: 0000562818a8ebc0 RCX: 00007f417110809b
       RDX: 00007ffdd8d1c2a0 RSI: 00000000c05064a7 RDI: 0000000000000012
       RBP: 00007ffdd8d1c2a0 R08: 0000562819012280 R09: 0000000000000007
       R10: 0000000000000000 R11: 0000000000000246 R12: 00000000c05064a7
       R13: 0000000000000012 R14: 0000000000000012 R15: 00007ffdd8d1c2a0
       Modules linked in: nfsv4 dns_resolver nfs lockd grace fscache fuse vfat fat amdgpu intel_rapl sb_edac x86_pkg_temp_thermal intel_powerclamp coretemp kvm_intel kvm irqbypass crct10dif_pclmul chash gpu_sched crc32_pclmul snd_hda_codec_realtek ghash_clmulni_intel amd_iommu_v2 iTCO_wdt iTCO_vendor_support ttm snd_hda_codec_generic snd_hda_codec_hdmi ledtrig_audio snd_hda_intel drm_kms_helper snd_hda_codec intel_cstate snd_hda_core drm snd_hwdep snd_seq snd_seq_device intel_uncore snd_pcm intel_rapl_perf snd_timer snd soundcore ioatdma pcspkr intel_wmi_thunderbolt mxm_wmi i2c_i801 lpc_ich pcc_cpufreq auth_rpcgss sunrpc igb crc32c_intel i2c_algo_bit dca wmi hid_cherry analog gameport joydev
    
    This patch is based on agd5f/drm-next-5.1-wip. This patch does not require
    all of that, but agd5f/drm-next-5.1-wip contains at least one more dc_sink
    counting fix that I could spot.
    
    Signed-off-by: Mathias Fröhlich <Mathias.Froehlich@web.de>
    Reviewed-by: Leo Li <sunpeng.li@amd.com>
    Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     .../gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 43 +++++++++++++++----
     .../display/amdgpu_dm/amdgpu_dm_mst_types.c   |  1 +
     drivers/gpu/drm/amd/display/dc/core/dc_link.c |  1 +
     3 files changed, 37 insertions(+), 8 deletions(-)
    
    diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
    index 636d14a60952..6d77fd966dbd 100644
    --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
    +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
    @@ -886,6 +886,7 @@ static void emulated_link_detect(struct dc_link *link)
     		return;
     	}
     
    +	/* dc_sink_create returns a new reference */
     	link->local_sink = sink;
     
     	edid_status = dm_helpers_read_local_edid(
    @@ -952,6 +953,8 @@ static int dm_resume(void *handle)
     		if (aconnector->fake_enable && aconnector->dc_link->local_sink)
     			aconnector->fake_enable = false;
     
    +		if (aconnector->dc_sink)
    +			dc_sink_release(aconnector->dc_sink);
     		aconnector->dc_sink = NULL;
     		amdgpu_dm_update_connector_after_detect(aconnector);
     		mutex_unlock(&aconnector->hpd_lock);
    @@ -1061,6 +1064,8 @@ amdgpu_dm_update_connector_after_detect(struct amdgpu_dm_connector *aconnector)
     
     
     	sink = aconnector->dc_link->local_sink;
    +	if (sink)
    +		dc_sink_retain(sink);
     
     	/*
     	 * Edid mgmt connector gets first update only in mode_valid hook and then
    @@ -1085,21 +1090,24 @@ amdgpu_dm_update_connector_after_detect(struct amdgpu_dm_connector *aconnector)
     				 * to it anymore after disconnect, so on next crtc to connector
     				 * reshuffle by UMD we will get into unwanted dc_sink release
     				 */
    -				if (aconnector->dc_sink != aconnector->dc_em_sink)
    -					dc_sink_release(aconnector->dc_sink);
    +				dc_sink_release(aconnector->dc_sink);
     			}
     			aconnector->dc_sink = sink;
    +			dc_sink_retain(aconnector->dc_sink);
     			amdgpu_dm_update_freesync_caps(connector,
     					aconnector->edid);
     		} else {
     			amdgpu_dm_update_freesync_caps(connector, NULL);
    -			if (!aconnector->dc_sink)
    +			if (!aconnector->dc_sink) {
     				aconnector->dc_sink = aconnector->dc_em_sink;
    -			else if (aconnector->dc_sink != aconnector->dc_em_sink)
     				dc_sink_retain(aconnector->dc_sink);
    +			}
     		}
     
     		mutex_unlock(&dev->mode_config.mutex);
    +
    +		if (sink)
    +			dc_sink_release(sink);
     		return;
     	}
     
    @@ -1107,8 +1115,10 @@ amdgpu_dm_update_connector_after_detect(struct amdgpu_dm_connector *aconnector)
     	 * TODO: temporary guard to look for proper fix
     	 * if this sink is MST sink, we should not do anything
     	 */
    -	if (sink && sink->sink_signal == SIGNAL_TYPE_DISPLAY_PORT_MST)
    +	if (sink && sink->sink_signal == SIGNAL_TYPE_DISPLAY_PORT_MST) {
    +		dc_sink_release(sink);
     		return;
    +	}
     
     	if (aconnector->dc_sink == sink) {
     		/*
    @@ -1117,6 +1127,8 @@ amdgpu_dm_update_connector_after_detect(struct amdgpu_dm_connector *aconnector)
     		 */
     		DRM_DEBUG_DRIVER("DCHPD: connector_id=%d: dc_sink didn't change.\n",
     				aconnector->connector_id);
    +		if (sink)
    +			dc_sink_release(sink);
     		return;
     	}
     
    @@ -1138,6 +1150,7 @@ amdgpu_dm_update_connector_after_detect(struct amdgpu_dm_connector *aconnector)
     			amdgpu_dm_update_freesync_caps(connector, NULL);
     
     		aconnector->dc_sink = sink;
    +		dc_sink_retain(aconnector->dc_sink);
     		if (sink->dc_edid.length == 0) {
     			aconnector->edid = NULL;
     			drm_dp_cec_unset_edid(&aconnector->dm_dp_aux.aux);
    @@ -1158,11 +1171,15 @@ amdgpu_dm_update_connector_after_detect(struct amdgpu_dm_connector *aconnector)
     		amdgpu_dm_update_freesync_caps(connector, NULL);
     		drm_connector_update_edid_property(connector, NULL);
     		aconnector->num_modes = 0;
    +		dc_sink_release(aconnector->dc_sink);
     		aconnector->dc_sink = NULL;
     		aconnector->edid = NULL;
     	}
     
     	mutex_unlock(&dev->mode_config.mutex);
    +
    +	if (sink)
    +		dc_sink_release(sink);
     }
     
     static void handle_hpd_irq(void *param)
    @@ -2908,6 +2925,7 @@ create_stream_for_sink(struct amdgpu_dm_connector *aconnector,
     		}
     	} else {
     		sink = aconnector->dc_sink;
    +		dc_sink_retain(sink);
     	}
     
     	stream = dc_create_stream_for_sink(sink);
    @@ -2974,8 +2992,7 @@ create_stream_for_sink(struct amdgpu_dm_connector *aconnector,
     		stream->ignore_msa_timing_param = true;
     
     finish:
    -	if (sink && sink->sink_signal == SIGNAL_TYPE_VIRTUAL && aconnector->base.force != DRM_FORCE_ON)
    -		dc_sink_release(sink);
    +	dc_sink_release(sink);
     
     	return stream;
     }
    @@ -3233,6 +3250,14 @@ static void amdgpu_dm_connector_destroy(struct drm_connector *connector)
     		dm->backlight_dev = NULL;
     	}
     #endif
    +
    +	if (aconnector->dc_em_sink)
    +		dc_sink_release(aconnector->dc_em_sink);
    +	aconnector->dc_em_sink = NULL;
    +	if (aconnector->dc_sink)
    +		dc_sink_release(aconnector->dc_sink);
    +	aconnector->dc_sink = NULL;
    +
     	drm_dp_cec_unregister_connector(&aconnector->dm_dp_aux.aux);
     	drm_connector_unregister(connector);
     	drm_connector_cleanup(connector);
    @@ -3330,10 +3355,12 @@ static void create_eml_sink(struct amdgpu_dm_connector *aconnector)
     		(edid->extensions + 1) * EDID_LENGTH,
     		&init_params);
     
    -	if (aconnector->base.force == DRM_FORCE_ON)
    +	if (aconnector->base.force == DRM_FORCE_ON) {
     		aconnector->dc_sink = aconnector->dc_link->local_sink ?
     		aconnector->dc_link->local_sink :
     		aconnector->dc_em_sink;
    +		dc_sink_retain(aconnector->dc_sink);
    +	}
     }
     
     static void handle_edid_mgmt(struct amdgpu_dm_connector *aconnector)
    diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c
    index 1b0d209d8367..3b95a637b508 100644
    --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c
    +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_mst_types.c
    @@ -239,6 +239,7 @@ static int dm_dp_mst_get_modes(struct drm_connector *connector)
     			&init_params);
     
     		dc_sink->priv = aconnector;
    +		/* dc_link_add_remote_sink returns a new reference */
     		aconnector->dc_sink = dc_sink;
     
     		if (aconnector->dc_sink)
    diff --git a/drivers/gpu/drm/amd/display/dc/core/dc_link.c b/drivers/gpu/drm/amd/display/dc/core/dc_link.c
    index b0265dbebd4c..583eb367850f 100644
    --- a/drivers/gpu/drm/amd/display/dc/core/dc_link.c
    +++ b/drivers/gpu/drm/amd/display/dc/core/dc_link.c
    @@ -792,6 +792,7 @@ bool dc_link_detect(struct dc_link *link, enum dc_detect_reason reason)
     		sink->dongle_max_pix_clk = sink_caps.max_hdmi_pixel_clock;
     		sink->converter_disable_audio = converter_disable_audio;
     
    +		/* dc_sink_create returns a new reference */
     		link->local_sink = sink;
     
     		edid_status = dm_helpers_read_local_edid(
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 114/262] drm/amd/display: Clear stream->mode_changed after commit
           [not found] <20190327180158.10245-1-sashal@kernel.org>
           [not found] ` <20190327180158.10245-1-sashal-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org>
      2019-03-27 17:58 ` [PATCH AUTOSEL 5.0 078/262] drm/amd/display: Fix reference counting for struct dc_sink Sasha Levin
    @ 2019-03-27 17:59 ` Sasha Levin
      2019-03-27 17:59 ` [PATCH AUTOSEL 5.0 135/262] drm/sched: Fix entities with 0 rqs Sasha Levin
                       ` (12 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 17:59 UTC (permalink / raw)
      To: linux-kernel, stable
      Cc: Alex Deucher, Sasha Levin, dri-devel, Nicholas Kazlauskas,
    	amd-gfx
    
    From: Nicholas Kazlauskas <nicholas.kazlauskas@amd.com>
    
    [ Upstream commit d8d2f174bcc2c26c3485c70e0c6fe22b27bce739 ]
    
    [Why]
    The stream->mode_changed flag can persist in the following sequence
    of atomic commits:
    
    Commit 1:
    Enable CRTC0 (mode_changed = true), Enable CRTC1 (mode_changed = true)
    
    Commit 2:
    Disable CRTC1 (mode_changed = false)
    
    In this sequence we want to keep the exiting CRTC0 but it's not in the
    atomic state for the commit since it hasn't been modified. In this case
    the stream->mode_changed flag persists as true and we don't re-program
    the planes for the existing stream.
    
    [How]
    The flag needs to be cleared and it makes the most sense to do it within
    DC after the state has been committed. Nothing following dc_commit_state
    should think that the stream's mode has changed.
    
    Signed-off-by: Nicholas Kazlauskas <nicholas.kazlauskas@amd.com>
    Reviewed-by: Leo Li <sunpeng.li@amd.com>
    Acked-by: Tony Cheng <Tony.Cheng@amd.com>
    Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/gpu/drm/amd/display/dc/core/dc.c | 3 +++
     1 file changed, 3 insertions(+)
    
    diff --git a/drivers/gpu/drm/amd/display/dc/core/dc.c b/drivers/gpu/drm/amd/display/dc/core/dc.c
    index 5fd52094d459..1f92e7e8e3d3 100644
    --- a/drivers/gpu/drm/amd/display/dc/core/dc.c
    +++ b/drivers/gpu/drm/amd/display/dc/core/dc.c
    @@ -1078,6 +1078,9 @@ static enum dc_status dc_commit_state_no_check(struct dc *dc, struct dc_state *c
     	/* pplib is notified if disp_num changed */
     	dc->hwss.optimize_bandwidth(dc, context);
     
    +	for (i = 0; i < context->stream_count; i++)
    +		context->streams[i]->mode_changed = false;
    +
     	dc_release_state(dc->current_state);
     
     	dc->current_state = context;
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 135/262] drm/sched: Fix entities with 0 rqs.
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (2 preceding siblings ...)
      2019-03-27 17:59 ` [PATCH AUTOSEL 5.0 114/262] drm/amd/display: Clear stream->mode_changed after commit Sasha Levin
    @ 2019-03-27 17:59 ` Sasha Levin
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 147/262] drm: allow render capable master with DRM_AUTH ioctls Sasha Levin
                       ` (11 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 17:59 UTC (permalink / raw)
      To: linux-kernel, stable; +Cc: Alex Deucher, Sasha Levin, dri-devel
    
    From: Bas Nieuwenhuizen <bas@basnieuwenhuizen.nl>
    
    [ Upstream commit 1decbf6bb0b4dc56c9da6c5e57b994ebfc2be3aa ]
    
    Some blocks in amdgpu can have 0 rqs.
    
    Job creation already fails with -ENOENT when entity->rq is NULL,
    so jobs cannot be pushed. Without a rq there is no scheduler to
    pop jobs, and rq selection already does the right thing with a
    list of length 0.
    
    So the operations we need to fix are:
      - Creation, do not set rq to rq_list[0] if the list can have length 0.
      - Do not flush any jobs when there is no rq.
      - On entity destruction handle the rq = NULL case.
      - on set_priority, do not try to change the rq if it is NULL.
    
    Signed-off-by: Bas Nieuwenhuizen <bas@basnieuwenhuizen.nl>
    Reviewed-by: Christian König <christian.koenig@amd.com>
    Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/gpu/drm/scheduler/sched_entity.c | 39 ++++++++++++++++--------
     1 file changed, 26 insertions(+), 13 deletions(-)
    
    diff --git a/drivers/gpu/drm/scheduler/sched_entity.c b/drivers/gpu/drm/scheduler/sched_entity.c
    index e2942c9a11a7..35ddbec1375a 100644
    --- a/drivers/gpu/drm/scheduler/sched_entity.c
    +++ b/drivers/gpu/drm/scheduler/sched_entity.c
    @@ -52,12 +52,12 @@ int drm_sched_entity_init(struct drm_sched_entity *entity,
     {
     	int i;
     
    -	if (!(entity && rq_list && num_rq_list > 0 && rq_list[0]))
    +	if (!(entity && rq_list && (num_rq_list == 0 || rq_list[0])))
     		return -EINVAL;
     
     	memset(entity, 0, sizeof(struct drm_sched_entity));
     	INIT_LIST_HEAD(&entity->list);
    -	entity->rq = rq_list[0];
    +	entity->rq = NULL;
     	entity->guilty = guilty;
     	entity->num_rq_list = num_rq_list;
     	entity->rq_list = kcalloc(num_rq_list, sizeof(struct drm_sched_rq *),
    @@ -67,6 +67,10 @@ int drm_sched_entity_init(struct drm_sched_entity *entity,
     
     	for (i = 0; i < num_rq_list; ++i)
     		entity->rq_list[i] = rq_list[i];
    +
    +	if (num_rq_list)
    +		entity->rq = rq_list[0];
    +
     	entity->last_scheduled = NULL;
     
     	spin_lock_init(&entity->rq_lock);
    @@ -165,6 +169,9 @@ long drm_sched_entity_flush(struct drm_sched_entity *entity, long timeout)
     	struct task_struct *last_user;
     	long ret = timeout;
     
    +	if (!entity->rq)
    +		return 0;
    +
     	sched = entity->rq->sched;
     	/**
     	 * The client will not queue more IBs during this fini, consume existing
    @@ -264,20 +271,24 @@ static void drm_sched_entity_kill_jobs(struct drm_sched_entity *entity)
      */
     void drm_sched_entity_fini(struct drm_sched_entity *entity)
     {
    -	struct drm_gpu_scheduler *sched;
    +	struct drm_gpu_scheduler *sched = NULL;
     
    -	sched = entity->rq->sched;
    -	drm_sched_rq_remove_entity(entity->rq, entity);
    +	if (entity->rq) {
    +		sched = entity->rq->sched;
    +		drm_sched_rq_remove_entity(entity->rq, entity);
    +	}
     
     	/* Consumption of existing IBs wasn't completed. Forcefully
     	 * remove them here.
     	 */
     	if (spsc_queue_peek(&entity->job_queue)) {
    -		/* Park the kernel for a moment to make sure it isn't processing
    -		 * our enity.
    -		 */
    -		kthread_park(sched->thread);
    -		kthread_unpark(sched->thread);
    +		if (sched) {
    +			/* Park the kernel for a moment to make sure it isn't processing
    +			 * our enity.
    +			 */
    +			kthread_park(sched->thread);
    +			kthread_unpark(sched->thread);
    +		}
     		if (entity->dependency) {
     			dma_fence_remove_callback(entity->dependency,
     						  &entity->cb);
    @@ -362,9 +373,11 @@ void drm_sched_entity_set_priority(struct drm_sched_entity *entity,
     	for (i = 0; i < entity->num_rq_list; ++i)
     		drm_sched_entity_set_rq_priority(&entity->rq_list[i], priority);
     
    -	drm_sched_rq_remove_entity(entity->rq, entity);
    -	drm_sched_entity_set_rq_priority(&entity->rq, priority);
    -	drm_sched_rq_add_entity(entity->rq, entity);
    +	if (entity->rq) {
    +		drm_sched_rq_remove_entity(entity->rq, entity);
    +		drm_sched_entity_set_rq_priority(&entity->rq, priority);
    +		drm_sched_rq_add_entity(entity->rq, entity);
    +	}
     
     	spin_unlock(&entity->rq_lock);
     }
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 147/262] drm: allow render capable master with DRM_AUTH ioctls
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (3 preceding siblings ...)
      2019-03-27 17:59 ` [PATCH AUTOSEL 5.0 135/262] drm/sched: Fix entities with 0 rqs Sasha Levin
    @ 2019-03-27 18:00 ` Sasha Levin
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 168/262] fbdev: fbmem: fix memory access if logo is bigger than the screen Sasha Levin
                       ` (10 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:00 UTC (permalink / raw)
      To: linux-kernel, stable; +Cc: Emil Velikov, intel-gfx, Sasha Levin, dri-devel
    
    From: Emil Velikov <emil.velikov@collabora.com>
    
    [ Upstream commit 8059add0478e29cb641936011a8fcc9ce9fd80be ]
    
    There are cases (in mesa and applications) where one would open the
    primary node without properly authenticating the client.
    
    Sometimes we don't check if the authentication succeeds, but there's
    also cases we simply forget to do it.
    
    The former was a case for Mesa where it did not not check the return
    value of drmGetMagic() [1]. That was fixed recently although, there's
    the question of older drivers or other apps that exbibit this behaviour.
    
    While omitting the call results in issues as seen in [2] and [3].
    
    In the libva case, libva itself doesn't authenticate the DRM client and
    the vaGetDisplayDRM documentation doesn't mention if the app should
    either.
    
    As of today, the official vainfo utility doesn't authenticate.
    
    To workaround issues like these, some users resort to running their apps
    under sudo. Which admittedly isn't always a good idea.
    
    Since any DRIVER_RENDER driver has sufficient isolation between clients,
    we can use that, for unauthenticated [primary node] ioctls that require
    DRM_AUTH. But only if the respective ioctl is tagged as DRM_RENDER_ALLOW.
    
    v2:
    - Rework/simplify if check (Daniel V)
    - Add examples to commit messages, elaborate. (Daniel V)
    
    v3:
    - Use single unlikely (Daniel V)
    
    [1] https://gitlab.freedesktop.org/mesa/mesa/blob/2bc1f5c2e70fe3b4d41f060af9859bc2a94c5b62/src/egl/drivers/dri2/platform_wayland.c#L1136
    [2] https://lists.freedesktop.org/archives/libva/2016-July/004185.html
    [3] https://gitlab.freedesktop.org/mesa/kmscube/issues/1
    Testcase: igt/core_unauth_vs_render
    Cc: intel-gfx@lists.freedesktop.org
    Signed-off-by: Emil Velikov <emil.velikov@collabora.com>
    Reviewed-by: Daniel Vetter <daniel.vetter@ffwll.ch>
    Link: https://patchwork.freedesktop.org/patch/msgid/20190114085408.15933-2-emil.l.velikov@gmail.com
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/gpu/drm/drm_ioctl.c | 20 ++++++++++++++++----
     1 file changed, 16 insertions(+), 4 deletions(-)
    
    diff --git a/drivers/gpu/drm/drm_ioctl.c b/drivers/gpu/drm/drm_ioctl.c
    index 7e6746b2d704..8c1d38a82366 100644
    --- a/drivers/gpu/drm/drm_ioctl.c
    +++ b/drivers/gpu/drm/drm_ioctl.c
    @@ -508,6 +508,13 @@ int drm_version(struct drm_device *dev, void *data,
     	return err;
     }
     
    +static inline bool
    +drm_render_driver_and_ioctl(const struct drm_device *dev, u32 flags)
    +{
    +	return drm_core_check_feature(dev, DRIVER_RENDER) &&
    +		(flags & DRM_RENDER_ALLOW);
    +}
    +
     /**
      * drm_ioctl_permit - Check ioctl permissions against caller
      *
    @@ -522,14 +529,19 @@ int drm_version(struct drm_device *dev, void *data,
      */
     int drm_ioctl_permit(u32 flags, struct drm_file *file_priv)
     {
    +	const struct drm_device *dev = file_priv->minor->dev;
    +
     	/* ROOT_ONLY is only for CAP_SYS_ADMIN */
     	if (unlikely((flags & DRM_ROOT_ONLY) && !capable(CAP_SYS_ADMIN)))
     		return -EACCES;
     
    -	/* AUTH is only for authenticated or render client */
    -	if (unlikely((flags & DRM_AUTH) && !drm_is_render_client(file_priv) &&
    -		     !file_priv->authenticated))
    -		return -EACCES;
    +	/* AUTH is only for master ... */
    +	if (unlikely((flags & DRM_AUTH) && drm_is_primary_client(file_priv))) {
    +		/* authenticated ones, or render capable on DRM_RENDER_ALLOW. */
    +		if (!file_priv->authenticated &&
    +		    !drm_render_driver_and_ioctl(dev, flags))
    +			return -EACCES;
    +	}
     
     	/* MASTER is only for master or control clients */
     	if (unlikely((flags & DRM_MASTER) &&
    -- 
    2.19.1
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 168/262] fbdev: fbmem: fix memory access if logo is bigger than the screen
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (4 preceding siblings ...)
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 147/262] drm: allow render capable master with DRM_AUTH ioctls Sasha Levin
    @ 2019-03-27 18:00 ` Sasha Levin
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 170/262] drm: rcar-du: add missing of_node_put Sasha Levin
                       ` (9 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:00 UTC (permalink / raw)
      To: linux-kernel, stable
      Cc: Sasha Levin, linux-fbdev, Bartlomiej Zolnierkiewicz,
    	Manfred Schlaegl, Daniel Vetter, Martin Kepplinger, dri-devel
    
    From: Manfred Schlaegl <manfred.schlaegl@ginzinger.com>
    
    [ Upstream commit a5399db139cb3ad9b8502d8b1bd02da9ce0b9df0 ]
    
    There is no clipping on the x or y axis for logos larger that the framebuffer
    size. Therefore: a logo bigger than screen size leads to invalid memory access:
    
    [    1.254664] Backtrace:
    [    1.254728] [<c02714e0>] (cfb_imageblit) from [<c026184c>] (fb_show_logo+0x620/0x684)
    [    1.254763]  r10:00000003 r9:00027fd8 r8:c6a40000 r7:c6a36e50 r6:00000000 r5:c06b81e4
    [    1.254774]  r4:c6a3e800
    [    1.254810] [<c026122c>] (fb_show_logo) from [<c026c1e4>] (fbcon_switch+0x3fc/0x46c)
    [    1.254842]  r10:c6a3e824 r9:c6a3e800 r8:00000000 r7:c6a0c000 r6:c070b014 r5:c6a3e800
    [    1.254852]  r4:c6808c00
    [    1.254889] [<c026bde8>] (fbcon_switch) from [<c029c8f8>] (redraw_screen+0xf0/0x1e8)
    [    1.254918]  r10:00000000 r9:00000000 r8:00000000 r7:00000000 r6:c070d5a0 r5:00000080
    [    1.254928]  r4:c6808c00
    [    1.254961] [<c029c808>] (redraw_screen) from [<c029d264>] (do_bind_con_driver+0x194/0x2e4)
    [    1.254991]  r9:00000000 r8:00000000 r7:00000014 r6:c070d5a0 r5:c070d5a0 r4:c070d5a0
    
    So prevent displaying a logo bigger than screen size and avoid invalid
    memory access.
    
    Signed-off-by: Manfred Schlaegl <manfred.schlaegl@ginzinger.com>
    Signed-off-by: Martin Kepplinger <martin.kepplinger@ginzinger.com>
    Cc: Daniel Vetter <daniel.vetter@ffwll.ch>
    Signed-off-by: Bartlomiej Zolnierkiewicz <b.zolnierkie@samsung.com>
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/video/fbdev/core/fbmem.c | 3 +++
     1 file changed, 3 insertions(+)
    
    diff --git a/drivers/video/fbdev/core/fbmem.c b/drivers/video/fbdev/core/fbmem.c
    index cb43a2258c51..4721491e6c8c 100644
    --- a/drivers/video/fbdev/core/fbmem.c
    +++ b/drivers/video/fbdev/core/fbmem.c
    @@ -431,6 +431,9 @@ static void fb_do_show_logo(struct fb_info *info, struct fb_image *image,
     {
     	unsigned int x;
     
    +	if (image->width > info->var.xres || image->height > info->var.yres)
    +		return;
    +
     	if (rotate == FB_ROTATE_UR) {
     		for (x = 0;
     		     x < num && image->dx + image->width <= info->var.xres;
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 170/262] drm: rcar-du: add missing of_node_put
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (5 preceding siblings ...)
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 168/262] fbdev: fbmem: fix memory access if logo is bigger than the screen Sasha Levin
    @ 2019-03-27 18:00 ` Sasha Levin
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 188/262] drm/vkms: Bugfix racing hrtimer vblank handle Sasha Levin
                       ` (8 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:00 UTC (permalink / raw)
      To: linux-kernel, stable
      Cc: Sasha Levin, Julia Lawall, Laurent Pinchart, linux-renesas-soc,
    	dri-devel
    
    From: Julia Lawall <julia.lawall@lip6.fr>
    
    [ Upstream commit 4c6d8fc20b09f9684743afd72e4dbc3f15524479 ]
    
    Add an of_node_put when the result of of_graph_get_remote_port_parent is
    not available.
    
    Add a second of_node_put if no encoder is selected (encoder remains NULL).
    
    The semantic match that finds the first problem is as follows
    (http://coccinelle.lip6.fr):
    
    // <smpl>
    @r exists@
    local idexpression e;
    expression x;
    @@
    e = of_graph_get_remote_port_parent(...);
    ... when != x = e
        when != true e == NULL
        when != of_node_put(e)
        when != of_fwnode_handle(e)
    (
    return e;
    |
    *return ...;
    )
    // </smpl>
    
    Signed-off-by: Julia Lawall <Julia.Lawall@lip6.fr>
    Reviewed-by: Laurent Pinchart <laurent.pinchart+renesas@ideasonboard.com>
    Reviewed-by: Kieran Bingham <kieran.bingham+renesas@ideasonboard.com>
    Signed-off-by: Laurent Pinchart <laurent.pinchart+renesas@ideasonboard.com>
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/gpu/drm/rcar-du/rcar_du_kms.c | 2 ++
     1 file changed, 2 insertions(+)
    
    diff --git a/drivers/gpu/drm/rcar-du/rcar_du_kms.c b/drivers/gpu/drm/rcar-du/rcar_du_kms.c
    index 9c7007d45408..f9a90ff24e6d 100644
    --- a/drivers/gpu/drm/rcar-du/rcar_du_kms.c
    +++ b/drivers/gpu/drm/rcar-du/rcar_du_kms.c
    @@ -331,6 +331,7 @@ static int rcar_du_encoders_init_one(struct rcar_du_device *rcdu,
     		dev_dbg(rcdu->dev,
     			"connected entity %pOF is disabled, skipping\n",
     			entity);
    +		of_node_put(entity);
     		return -ENODEV;
     	}
     
    @@ -366,6 +367,7 @@ static int rcar_du_encoders_init_one(struct rcar_du_device *rcdu,
     		dev_warn(rcdu->dev,
     			 "no encoder found for endpoint %pOF, skipping\n",
     			 ep->local_node);
    +		of_node_put(entity);
     		return -ENODEV;
     	}
     
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 188/262] drm/vkms: Bugfix racing hrtimer vblank handle
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (6 preceding siblings ...)
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 170/262] drm: rcar-du: add missing of_node_put Sasha Levin
    @ 2019-03-27 18:00 ` Sasha Levin
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 189/262] drm/vkms: Bugfix extra vblank frame Sasha Levin
                       ` (7 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:00 UTC (permalink / raw)
      To: linux-kernel, stable
      Cc: Sasha Levin, Shayenne Moura, dri-devel, Rodrigo Siqueira,
    	Daniel Vetter
    
    From: Shayenne Moura <shayenneluzmoura@gmail.com>
    
    [ Upstream commit ba420afab565bdc7b028ddd4f222260f2de7a1db ]
    
    When the vblank irq happens, kernel time subsystem executes
    `vkms_vblank_simulate`. In parallel or not, it prepares all stuff
    necessary to the next vblank with arm, and it must flush these stuff
    before the next vblank irq. However, vblank counter is ahead when arm is
    executed in parallel with handle vblank.
    
    CPU 0:					CPU 1:
     |					 |
    atomic_commit_tail is ongoing		 |
     |					 |
     |					hrtimer: vkms_vblank_simulate()
     |					 |
     |					drm_crtc_handle_vblank()
     |					 |
    drm_crtc_arm_vblank()			 |
     |					 |
    ->get_vblank_timestamp()		 |
     |					 |
     |					hrtimer_forward_now()
    
    Then, we should guarantee that the vblank interval time is correct (not
    changed) before finish the vblank handle.
    
    Fix the bug including the call to `hrtimer_forward_now()` in the same
    lock of `drm_crtc_handle_vblank()` to ensure that the timestamp update
    is correct when finish the vblank handle.
    
    Signed-off-by: Shayenne Moura <shayenneluzmoura@gmail.com>
    Signed-off-by: Daniel Vetter <daniel.vetter@intel.com>
    Reviewed-by: Rodrigo Siqueira <rodrigosiqueiramelo@gmail.com>
    Signed-off-by: Rodrigo Siqueira <rodrigosiqueiramelo@gmail.com>
    Link: https://patchwork.freedesktop.org/patch/msgid/e2e4b8f3a5cab7b2dba75bf1930f86b0a4ee08c9.1548856186.git.shayenneluzmoura@gmail.com
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/gpu/drm/vkms/vkms_crtc.c | 18 ++++++------------
     1 file changed, 6 insertions(+), 12 deletions(-)
    
    diff --git a/drivers/gpu/drm/vkms/vkms_crtc.c b/drivers/gpu/drm/vkms/vkms_crtc.c
    index eb56ee893761..53ab49408a98 100644
    --- a/drivers/gpu/drm/vkms/vkms_crtc.c
    +++ b/drivers/gpu/drm/vkms/vkms_crtc.c
    @@ -4,13 +4,17 @@
     #include <drm/drm_atomic_helper.h>
     #include <drm/drm_crtc_helper.h>
     
    -static void _vblank_handle(struct vkms_output *output)
    +static enum hrtimer_restart vkms_vblank_simulate(struct hrtimer *timer)
     {
    +	struct vkms_output *output = container_of(timer, struct vkms_output,
    +						  vblank_hrtimer);
     	struct drm_crtc *crtc = &output->crtc;
     	struct vkms_crtc_state *state = to_vkms_crtc_state(crtc->state);
    +	int ret_overrun;
     	bool ret;
     
     	spin_lock(&output->lock);
    +
     	ret = drm_crtc_handle_vblank(crtc);
     	if (!ret)
     		DRM_ERROR("vkms failure on handling vblank");
    @@ -31,19 +35,9 @@ static void _vblank_handle(struct vkms_output *output)
     			DRM_WARN("failed to queue vkms_crc_work_handle");
     	}
     
    -	spin_unlock(&output->lock);
    -}
    -
    -static enum hrtimer_restart vkms_vblank_simulate(struct hrtimer *timer)
    -{
    -	struct vkms_output *output = container_of(timer, struct vkms_output,
    -						  vblank_hrtimer);
    -	int ret_overrun;
    -
    -	_vblank_handle(output);
    -
     	ret_overrun = hrtimer_forward_now(&output->vblank_hrtimer,
     					  output->period_ns);
    +	spin_unlock(&output->lock);
     
     	return HRTIMER_RESTART;
     }
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 189/262] drm/vkms: Bugfix extra vblank frame
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (7 preceding siblings ...)
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 188/262] drm/vkms: Bugfix racing hrtimer vblank handle Sasha Levin
    @ 2019-03-27 18:00 ` Sasha Levin
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 204/262] backlight: pwm_bl: Use gpiod_get_value_cansleep() to get initial state Sasha Levin
                       ` (6 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:00 UTC (permalink / raw)
      To: linux-kernel, stable
      Cc: Sasha Levin, Shayenne Moura, dri-devel, Rodrigo Siqueira,
    	Daniel Vetter
    
    From: Shayenne Moura <shayenneluzmoura@gmail.com>
    
    [ Upstream commit def35e7c592616bc09be328de8795e5e624a3cf8 ]
    
    kms_flip tests are breaking on vkms when simulate vblank because vblank
    event sequence count returns one extra frame after arm vblank event to
    make a page flip.
    
    When vblank interrupt happens, userspace processes the vblank event and
    issues the next page flip command. Kernel calls queue_work to call
    commit_planes and arm the new page flip. The next vblank picks up the
    newly armed vblank event and vblank interrupt happens again.
    
    The arm and vblank event are asynchronous, then, on the next vblank, we
    receive x+2 from `get_vblank_timestamp`, instead x+1, although timestamp
    and vblank seqno matches.
    
    Function `get_vblank_timestamp` is reached by 2 ways:
    
      - from `drm_mode_page_flip_ioctl`: driver is doing one atomic
        operation to synchronize planes in the same output. There is no
        vblank simulation, the `drm_crtc_arm_vblank_event` function adds 1
        on vblank count, and the variable in_vblank_irq is false
      - from `vkms_vblank_simulate`: since the driver is doing a vblank
        simulation, the variable in_vblank_irq is true.
    
    Fix this problem subtracting one vblank period from vblank_time when
    `get_vblank_timestamp` is called from trace `drm_mode_page_flip_ioctl`,
    i.e., is not a real vblank interrupt, and getting the timestamp and
    vblank seqno when it is a real vblank interrupt.
    
    The reason for all this is that get_vblank_timestamp always supplies the
    timestamp for the next vblank event. The hrtimer is the vblank
    simulator, and it needs the correct previous value to present the next
    vblank. Since this is how hw timestamp registers work and what the
    vblank core expects.
    
    Signed-off-by: Shayenne Moura <shayenneluzmoura@gmail.com>
    Signed-off-by: Daniel Vetter <daniel.vetter@intel.com>
    Reviewed-by: Rodrigo Siqueira <rodrigosiqueiramelo@gmail.com>
    Signed-off-by: Rodrigo Siqueira <rodrigosiqueiramelo@gmail.com>
    Link: https://patchwork.freedesktop.org/patch/msgid/171e6e1c239cbca0c3df7183ed8acdfeeace9cf4.1548856186.git.shayenneluzmoura@gmail.com
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/gpu/drm/vkms/vkms_crtc.c | 3 +++
     1 file changed, 3 insertions(+)
    
    diff --git a/drivers/gpu/drm/vkms/vkms_crtc.c b/drivers/gpu/drm/vkms/vkms_crtc.c
    index 53ab49408a98..a0bef7de9df7 100644
    --- a/drivers/gpu/drm/vkms/vkms_crtc.c
    +++ b/drivers/gpu/drm/vkms/vkms_crtc.c
    @@ -75,6 +75,9 @@ bool vkms_get_vblank_timestamp(struct drm_device *dev, unsigned int pipe,
     
     	*vblank_time = output->vblank_hrtimer.node.expires;
     
    +	if (!in_vblank_irq)
    +		*vblank_time -= output->period_ns;
    +
     	return true;
     }
     
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 204/262] backlight: pwm_bl: Use gpiod_get_value_cansleep() to get initial state
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (8 preceding siblings ...)
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 189/262] drm/vkms: Bugfix extra vblank frame Sasha Levin
    @ 2019-03-27 18:00 ` Sasha Levin
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 207/262] drm/amd/display: Enable vblank interrupt during CRC capture Sasha Levin
                       ` (5 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:00 UTC (permalink / raw)
      To: linux-kernel, stable
      Cc: Sasha Levin, linux-pwm, linux-fbdev, dri-devel, Chen-Yu Tsai,
    	Lee Jones
    
    From: Chen-Yu Tsai <wens@csie.org>
    
    [ Upstream commit cec2b18832e26bc866bef2be22eff4e25bbc4034 ]
    
    gpiod_get_value() gives out a warning if access to the underlying gpiochip
    requires sleeping, which is common for I2C based chips:
    
        WARNING: CPU: 0 PID: 77 at drivers/gpio/gpiolib.c:2500 gpiod_get_value+0xd0/0x100
        Modules linked in:
        CPU: 0 PID: 77 Comm: kworker/0:2 Not tainted 4.14.0-rc3-00589-gf32897915d48-dirty #90
        Hardware name: Allwinner sun4i/sun5i Families
        Workqueue: events deferred_probe_work_func
        [<c010ec50>] (unwind_backtrace) from [<c010b784>] (show_stack+0x10/0x14)
        [<c010b784>] (show_stack) from [<c0797224>] (dump_stack+0x88/0x9c)
        [<c0797224>] (dump_stack) from [<c0125b08>] (__warn+0xe8/0x100)
        [<c0125b08>] (__warn) from [<c0125bd0>] (warn_slowpath_null+0x20/0x28)
        [<c0125bd0>] (warn_slowpath_null) from [<c037069c>] (gpiod_get_value+0xd0/0x100)
        [<c037069c>] (gpiod_get_value) from [<c03778d0>] (pwm_backlight_probe+0x238/0x508)
        [<c03778d0>] (pwm_backlight_probe) from [<c0411a2c>] (platform_drv_probe+0x50/0xac)
        [<c0411a2c>] (platform_drv_probe) from [<c0410224>] (driver_probe_device+0x238/0x2e8)
        [<c0410224>] (driver_probe_device) from [<c040e820>] (bus_for_each_drv+0x44/0x94)
        [<c040e820>] (bus_for_each_drv) from [<c040ff0c>] (__device_attach+0xb0/0x114)
        [<c040ff0c>] (__device_attach) from [<c040f4f8>] (bus_probe_device+0x84/0x8c)
        [<c040f4f8>] (bus_probe_device) from [<c040f944>] (deferred_probe_work_func+0x50/0x14c)
        [<c040f944>] (deferred_probe_work_func) from [<c013be84>] (process_one_work+0x1ec/0x414)
        [<c013be84>] (process_one_work) from [<c013ce5c>] (worker_thread+0x2b0/0x5a0)
        [<c013ce5c>] (worker_thread) from [<c0141908>] (kthread+0x14c/0x154)
        [<c0141908>] (kthread) from [<c0107ab0>] (ret_from_fork+0x14/0x24)
    
    This was missed in commit 0c9501f823a4 ("backlight: pwm_bl: Handle gpio
    that can sleep"). The code was then moved to a separate function in
    commit 7613c922315e ("backlight: pwm_bl: Move the checks for initial power
    state to a separate function").
    
    The only usage of gpiod_get_value() is during the probe stage, which is
    safe to sleep in. Switch to gpiod_get_value_cansleep().
    
    Fixes: 0c9501f823a4 ("backlight: pwm_bl: Handle gpio that can sleep")
    Signed-off-by: Chen-Yu Tsai <wens@csie.org>
    Acked-by: Maxime Ripard <maxime.ripard@bootlin.com>
    Acked-by: Daniel Thompson <daniel.thompson@linaro.org>
    Signed-off-by: Lee Jones <lee.jones@linaro.org>
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/video/backlight/pwm_bl.c | 2 +-
     1 file changed, 1 insertion(+), 1 deletion(-)
    
    diff --git a/drivers/video/backlight/pwm_bl.c b/drivers/video/backlight/pwm_bl.c
    index feb90764a811..53b8ceea9bde 100644
    --- a/drivers/video/backlight/pwm_bl.c
    +++ b/drivers/video/backlight/pwm_bl.c
    @@ -435,7 +435,7 @@ static int pwm_backlight_initial_power_state(const struct pwm_bl_data *pb)
     	 */
     
     	/* if the enable GPIO is disabled, do not enable the backlight */
    -	if (pb->enable_gpio && gpiod_get_value(pb->enable_gpio) == 0)
    +	if (pb->enable_gpio && gpiod_get_value_cansleep(pb->enable_gpio) == 0)
     		return FB_BLANK_POWERDOWN;
     
     	/* The regulator is disabled, do not enable the backlight */
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 207/262] drm/amd/display: Enable vblank interrupt during CRC capture
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (9 preceding siblings ...)
      2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 204/262] backlight: pwm_bl: Use gpiod_get_value_cansleep() to get initial state Sasha Levin
    @ 2019-03-27 18:01 ` Sasha Levin
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 220/262] drm/vkms: Fix flush_work() without INIT_WORK() Sasha Levin
                       ` (4 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:01 UTC (permalink / raw)
      To: linux-kernel, stable
      Cc: Alex Deucher, Sasha Levin, dri-devel, Nicholas Kazlauskas,
    	amd-gfx
    
    From: Nicholas Kazlauskas <nicholas.kazlauskas@amd.com>
    
    [ Upstream commit 428da2bdb05d76c48d0bd8fbfa2e4c102685be08 ]
    
    [Why]
    In order to read CRC events when CRC capture is enabled the vblank
    interrput handler needs to be running for the CRTC. The handler is
    enabled while there is an active vblank reference.
    
    When running IGT tests there will often be no active vblank reference
    but the test expects to read a CRC value. This is valid usage (and
    works on i915 since they have a CRC interrupt handler) so the reference
    to the vblank should be grabbed while capture is active.
    
    This issue was found running:
    
    igt@kms_plane_multiple@atomic-pipe-b-tiling-none
    
    The pipe-b is the only one in the initial commit and was not previously
    active so no vblank reference is grabbed. The vblank interrupt is
    not enabled and the test times out.
    
    [How]
    Keep a reference to the vblank as long as CRC capture is enabled.
    If userspace never explicitly disables it then the reference is
    also dropped when removing the CRTC from the context (stream = NULL).
    
    Signed-off-by: Nicholas Kazlauskas <nicholas.kazlauskas@amd.com>
    Reviewed-by: Harry Wentland <Harry.Wentland@amd.com>
    Reviewed-by: Sun peng Li <Sunpeng.Li@amd.com>
    Acked-by: Leo Li <sunpeng.li@amd.com>
    Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     .../gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 14 ++++++-
     .../drm/amd/display/amdgpu_dm/amdgpu_dm_crc.c | 42 +++++++++----------
     2 files changed, 34 insertions(+), 22 deletions(-)
    
    diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
    index 0040605cace8..83c8a0407537 100644
    --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
    +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
    @@ -4997,10 +4997,22 @@ static int amdgpu_dm_atomic_commit(struct drm_device *dev,
     	 */
     	for_each_oldnew_crtc_in_state(state, crtc, old_crtc_state, new_crtc_state, i) {
     		struct dm_crtc_state *dm_old_crtc_state = to_dm_crtc_state(old_crtc_state);
    +		struct dm_crtc_state *dm_new_crtc_state = to_dm_crtc_state(new_crtc_state);
     		struct amdgpu_crtc *acrtc = to_amdgpu_crtc(crtc);
     
    -		if (drm_atomic_crtc_needs_modeset(new_crtc_state) && dm_old_crtc_state->stream)
    +		if (drm_atomic_crtc_needs_modeset(new_crtc_state)
    +		    && dm_old_crtc_state->stream) {
    +			/*
    +			 * CRC capture was enabled but not disabled.
    +			 * Release the vblank reference.
    +			 */
    +			if (dm_new_crtc_state->crc_enabled) {
    +				drm_crtc_vblank_put(crtc);
    +				dm_new_crtc_state->crc_enabled = false;
    +			}
    +
     			manage_dm_interrupts(adev, acrtc, false);
    +		}
     	}
     	/*
     	 * Add check here for SoC's that support hardware cursor plane, to
    diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crc.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crc.c
    index f088ac585978..26b651148c67 100644
    --- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crc.c
    +++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_crc.c
    @@ -66,6 +66,7 @@ int amdgpu_dm_crtc_set_crc_source(struct drm_crtc *crtc, const char *src_name)
     {
     	struct dm_crtc_state *crtc_state = to_dm_crtc_state(crtc->state);
     	struct dc_stream_state *stream_state = crtc_state->stream;
    +	bool enable;
     
     	enum amdgpu_dm_pipe_crc_source source = dm_parse_crc_source(src_name);
     
    @@ -80,28 +81,27 @@ int amdgpu_dm_crtc_set_crc_source(struct drm_crtc *crtc, const char *src_name)
     		return -EINVAL;
     	}
     
    +	enable = (source == AMDGPU_DM_PIPE_CRC_SOURCE_AUTO);
    +
    +	if (!dc_stream_configure_crc(stream_state->ctx->dc, stream_state,
    +				     enable, enable))
    +		return -EINVAL;
    +
     	/* When enabling CRC, we should also disable dithering. */
    -	if (source == AMDGPU_DM_PIPE_CRC_SOURCE_AUTO) {
    -		if (dc_stream_configure_crc(stream_state->ctx->dc,
    -					    stream_state,
    -					    true, true)) {
    -			crtc_state->crc_enabled = true;
    -			dc_stream_set_dither_option(stream_state,
    -						    DITHER_OPTION_TRUN8);
    -		}
    -		else
    -			return -EINVAL;
    -	} else {
    -		if (dc_stream_configure_crc(stream_state->ctx->dc,
    -					    stream_state,
    -					    false, false)) {
    -			crtc_state->crc_enabled = false;
    -			dc_stream_set_dither_option(stream_state,
    -						    DITHER_OPTION_DEFAULT);
    -		}
    -		else
    -			return -EINVAL;
    -	}
    +	dc_stream_set_dither_option(stream_state,
    +				    enable ? DITHER_OPTION_TRUN8
    +					   : DITHER_OPTION_DEFAULT);
    +
    +	/*
    +	 * Reading the CRC requires the vblank interrupt handler to be
    +	 * enabled. Keep a reference until CRC capture stops.
    +	 */
    +	if (!crtc_state->crc_enabled && enable)
    +		drm_crtc_vblank_get(crtc);
    +	else if (crtc_state->crc_enabled && !enable)
    +		drm_crtc_vblank_put(crtc);
    +
    +	crtc_state->crc_enabled = enable;
     
     	/* Reset crc_skipped on dm state */
     	crtc_state->crc_skip_count = 0;
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 220/262] drm/vkms: Fix flush_work() without INIT_WORK().
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (10 preceding siblings ...)
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 207/262] drm/amd/display: Enable vblank interrupt during CRC capture Sasha Levin
    @ 2019-03-27 18:01 ` Sasha Levin
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 241/262] drm: Auto-set allow_fb_modifiers when given modifiers at plane init Sasha Levin
                       ` (3 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:01 UTC (permalink / raw)
      To: linux-kernel, stable; +Cc: Tetsuo Handa, Daniel Vetter, dri-devel, Sasha Levin
    
    From: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
    
    [ Upstream commit b30b61ff6b1dc37f276cf56a8328b80086a3ffca ]
    
    syzbot is hitting a lockdep warning [1] because flush_work() is called
    without INIT_WORK() after kzalloc() at vkms_atomic_crtc_reset().
    
    Commit 6c234fe37c57627a ("drm/vkms: Implement CRC debugfs API") added
    INIT_WORK() to only vkms_atomic_crtc_duplicate_state() side. Assuming
    that lifecycle of crc_work is appropriately managed, fix this problem
    by adding INIT_WORK() to vkms_atomic_crtc_reset() side.
    
    [1] https://syzkaller.appspot.com/bug?id=a5954455fcfa51c29ca2ab55b203076337e1c770
    
    Reported-and-tested-by: syzbot <syzbot+12f1b031b6da017e34f8@syzkaller.appspotmail.com>
    Signed-off-by: Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
    Reviewed-by: Shayenne Moura <shayenneluzmoura@gmail.com>
    Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch>
    Link: https://patchwork.freedesktop.org/patch/msgid/1547829823-9877-1-git-send-email-penguin-kernel@I-love.SAKURA.ne.jp
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/gpu/drm/vkms/vkms_crtc.c | 1 +
     1 file changed, 1 insertion(+)
    
    diff --git a/drivers/gpu/drm/vkms/vkms_crtc.c b/drivers/gpu/drm/vkms/vkms_crtc.c
    index a0bef7de9df7..1054f535178a 100644
    --- a/drivers/gpu/drm/vkms/vkms_crtc.c
    +++ b/drivers/gpu/drm/vkms/vkms_crtc.c
    @@ -95,6 +95,7 @@ static void vkms_atomic_crtc_reset(struct drm_crtc *crtc)
     	vkms_state = kzalloc(sizeof(*vkms_state), GFP_KERNEL);
     	if (!vkms_state)
     		return;
    +	INIT_WORK(&vkms_state->crc_work, vkms_crc_work_handle);
     
     	crtc->state = &vkms_state->base;
     	crtc->state->crtc = crtc;
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 241/262] drm: Auto-set allow_fb_modifiers when given modifiers at plane init
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (11 preceding siblings ...)
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 220/262] drm/vkms: Fix flush_work() without INIT_WORK() Sasha Levin
    @ 2019-03-27 18:01 ` Sasha Levin
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 248/262] drm/fb-helper: fix leaks in error path of drm_fb_helper_fbdev_setup Sasha Levin
                       ` (2 subsequent siblings)
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:01 UTC (permalink / raw)
      To: linux-kernel, stable
      Cc: Paul Kocialkowski, Maxime Ripard, dri-devel, Sasha Levin
    
    From: Paul Kocialkowski <paul.kocialkowski@bootlin.com>
    
    [ Upstream commit 890880ddfdbe256083170866e49c87618b706ac7 ]
    
    When drivers pass non-empty lists of modifiers for initializing their
    planes, we can infer that they allow framebuffer modifiers and set the
    driver's allow_fb_modifiers mode config element.
    
    In case the allow_fb_modifiers element was not set (some drivers tend
    to set them after registering planes), the modifiers will still be
    registered but won't be available to userspace unless the flag is set
    later. However in that case, the IN_FORMATS blob won't be created.
    
    In order to avoid this case and generally reduce the trouble associated
    with the flag, always set allow_fb_modifiers when a non-empty list of
    format modifiers is passed at plane init.
    
    Reviewed-by: Daniel Vetter <daniel.vetter@ffwll.ch>
    Signed-off-by: Paul Kocialkowski <paul.kocialkowski@bootlin.com>
    Signed-off-by: Maxime Ripard <maxime.ripard@bootlin.com>
    Link: https://patchwork.freedesktop.org/patch/msgid/20190104085610.5829-1-paul.kocialkowski@bootlin.com
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/gpu/drm/drm_plane.c | 3 +++
     1 file changed, 3 insertions(+)
    
    diff --git a/drivers/gpu/drm/drm_plane.c b/drivers/gpu/drm/drm_plane.c
    index 5f650d8fc66b..4cfb56893b7f 100644
    --- a/drivers/gpu/drm/drm_plane.c
    +++ b/drivers/gpu/drm/drm_plane.c
    @@ -220,6 +220,9 @@ int drm_universal_plane_init(struct drm_device *dev, struct drm_plane *plane,
     			format_modifier_count++;
     	}
     
    +	if (format_modifier_count)
    +		config->allow_fb_modifiers = true;
    +
     	plane->modifier_count = format_modifier_count;
     	plane->modifiers = kmalloc_array(format_modifier_count,
     					 sizeof(format_modifiers[0]),
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 248/262] drm/fb-helper: fix leaks in error path of drm_fb_helper_fbdev_setup
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (12 preceding siblings ...)
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 241/262] drm: Auto-set allow_fb_modifiers when given modifiers at plane init Sasha Levin
    @ 2019-03-27 18:01 ` Sasha Levin
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 256/262] drm: Reorder set_property_atomic to avoid returning with an active ww_ctx Sasha Levin
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 257/262] drm/dp/mst: Configure no_stop_bit correctly for remote i2c xfers Sasha Levin
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:01 UTC (permalink / raw)
      To: linux-kernel, stable; +Cc: Sasha Levin, Peter Wu, dri-devel
    
    From: Peter Wu <peter@lekensteyn.nl>
    
    [ Upstream commit 00eb5b0da8d27b3c944bfc959c3344d665caae26 ]
    
    After drm_fb_helper_fbdev_setup calls drm_fb_helper_init,
    "dev->fb_helper" will be initialized (and thus drm_fb_helper_fini will
    have some effect). After that, drm_fb_helper_initial_config is called
    which may call the "fb_probe" driver callback.
    
    This driver callback may call drm_fb_helper_defio_init (as is done by
    drm_fb_helper_generic_probe) or set a framebuffer (as is done by bochs)
    as documented. These are normally cleaned up on exit by
    drm_fb_helper_fbdev_teardown which also calls drm_fb_helper_fini.
    
    If an error occurs after "fb_probe", but before setup is complete, then
    calling just drm_fb_helper_fini will leak resources. This was triggered
    by df2052cc922 ("bochs: convert to drm_fb_helper_fbdev_setup/teardown"):
    
        [   50.008030] bochsdrmfb: enable CONFIG_FB_LITTLE_ENDIAN to support this framebuffer
        [   50.009436] bochs-drm 0000:00:02.0: [drm:drm_fb_helper_fbdev_setup] *ERROR* fbdev: Failed to set configuration (ret=-38)
        [   50.011456] [drm] Initialized bochs-drm 1.0.0 20130925 for 0000:00:02.0 on minor 2
        [   50.013604] WARNING: CPU: 1 PID: 1 at drivers/gpu/drm/drm_mode_config.c:477 drm_mode_config_cleanup+0x280/0x2a0
        [   50.016175] CPU: 1 PID: 1 Comm: swapper/0 Tainted: G                T 4.20.0-rc7 #1
        [   50.017732] EIP: drm_mode_config_cleanup+0x280/0x2a0
        ...
        [   50.023155] Call Trace:
        [   50.023155]  ? bochs_kms_fini+0x1e/0x30
        [   50.023155]  ? bochs_unload+0x18/0x40
    
    This can be reproduced with QEMU and CONFIG_FB_LITTLE_ENDIAN=n.
    
    Link: https://lkml.kernel.org/r/20181221083226.GI23332@shao2-debian
    Link: https://lkml.kernel.org/r/20181223004315.GA11455@al
    Fixes: 8741216396b2 ("drm/fb-helper: Add drm_fb_helper_fbdev_setup/teardown()")
    Reported-by: kernel test robot <rong.a.chen@intel.com>
    Cc: Noralf Trønnes <noralf@tronnes.org>
    Signed-off-by: Peter Wu <peter@lekensteyn.nl>
    Reviewed-by: Noralf Trønnes <noralf@tronnes.org>
    Signed-off-by: Noralf Trønnes <noralf@tronnes.org>
    Link: https://patchwork.freedesktop.org/patch/msgid/20181223005507.28328-1-peter@lekensteyn.nl
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/gpu/drm/drm_fb_helper.c | 2 +-
     1 file changed, 1 insertion(+), 1 deletion(-)
    
    diff --git a/drivers/gpu/drm/drm_fb_helper.c b/drivers/gpu/drm/drm_fb_helper.c
    index 70fc8e356b18..edd8cb497f3b 100644
    --- a/drivers/gpu/drm/drm_fb_helper.c
    +++ b/drivers/gpu/drm/drm_fb_helper.c
    @@ -2891,7 +2891,7 @@ int drm_fb_helper_fbdev_setup(struct drm_device *dev,
     	return 0;
     
     err_drm_fb_helper_fini:
    -	drm_fb_helper_fini(fb_helper);
    +	drm_fb_helper_fbdev_teardown(dev);
     
     	return ret;
     }
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 256/262] drm: Reorder set_property_atomic to avoid returning with an active ww_ctx
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (13 preceding siblings ...)
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 248/262] drm/fb-helper: fix leaks in error path of drm_fb_helper_fbdev_setup Sasha Levin
    @ 2019-03-27 18:01 ` Sasha Levin
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 257/262] drm/dp/mst: Configure no_stop_bit correctly for remote i2c xfers Sasha Levin
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:01 UTC (permalink / raw)
      To: linux-kernel, stable
      Cc: Sasha Levin, David Airlie, Daniel Vetter, dri-devel, Sean Paul
    
    From: Chris Wilson <chris@chris-wilson.co.uk>
    
    [ Upstream commit 227ad6d957898a88b1746e30234ece64d305f066 ]
    
    Delay the drm_modeset_acquire_init() until after we check for an
    allocation failure so that we can return immediately upon error without
    having to unwind.
    
    WARNING: lock held when returning to user space!
    4.20.0+ #174 Not tainted
    ------------------------------------------------
    syz-executor556/8153 is leaving the kernel with locks still held!
    1 lock held by syz-executor556/8153:
      #0: 000000005100c85c (crtc_ww_class_acquire){+.+.}, at:
    set_property_atomic+0xb3/0x330 drivers/gpu/drm/drm_mode_object.c:462
    
    Reported-by: syzbot+6ea337c427f5083ebdf2@syzkaller.appspotmail.com
    Fixes: 144a7999d633 ("drm: Handle properties in the core for atomic drivers")
    Signed-off-by: Chris Wilson <chris@chris-wilson.co.uk>
    Cc: Daniel Vetter <daniel.vetter@ffwll.ch>
    Cc: Maarten Lankhorst <maarten.lankhorst@linux.intel.com>
    Cc: Sean Paul <sean@poorly.run>
    Cc: David Airlie <airlied@linux.ie>
    Cc: <stable@vger.kernel.org> # v4.14+
    Reviewed-by: Maarten Lankhorst <maarten.lankhorst@linux.intel.com>
    Link: https://patchwork.freedesktop.org/patch/msgid/20181230122842.21917-1-chris@chris-wilson.co.uk
    
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/gpu/drm/drm_mode_object.c | 1 +
     1 file changed, 1 insertion(+)
    
    diff --git a/drivers/gpu/drm/drm_mode_object.c b/drivers/gpu/drm/drm_mode_object.c
    index 004191d01772..15b919f90c5a 100644
    --- a/drivers/gpu/drm/drm_mode_object.c
    +++ b/drivers/gpu/drm/drm_mode_object.c
    @@ -465,6 +465,7 @@ static int set_property_atomic(struct drm_mode_object *obj,
     
     	drm_modeset_acquire_init(&ctx, 0);
     	state->acquire_ctx = &ctx;
    +
     retry:
     	if (prop == state->dev->mode_config.dpms_property) {
     		if (obj->type != DRM_MODE_OBJECT_CONNECTOR) {
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread
  • * [PATCH AUTOSEL 5.0 257/262] drm/dp/mst: Configure no_stop_bit correctly for remote i2c xfers
           [not found] <20190327180158.10245-1-sashal@kernel.org>
                       ` (14 preceding siblings ...)
      2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 256/262] drm: Reorder set_property_atomic to avoid returning with an active ww_ctx Sasha Levin
    @ 2019-03-27 18:01 ` Sasha Levin
      15 siblings, 0 replies; 21+ messages in thread
    From: Sasha Levin @ 2019-03-27 18:01 UTC (permalink / raw)
      To: linux-kernel, stable; +Cc: Sasha Levin, Brian Vincent, dri-devel
    
    From: Ville Syrjälä <ville.syrjala@linux.intel.com>
    
    [ Upstream commit c978ae9bde582e82a04c63a4071701691dd8b35c ]
    
    We aren't supposed to force a stop+start between every i2c msg
    when performing multi message transfers. This should eg. cause
    the DDC segment address to be reset back to 0 between writing
    the segment address and reading the actual EDID extension block.
    
    To quote the E-DDC spec:
    "... this standard requires that the segment pointer be
     reset to 00h when a NO ACK or a STOP condition is received."
    
    Since we're going to touch this might as well consult the
    I2C_M_STOP flag to determine whether we want to force the stop
    or not.
    
    Cc: Brian Vincent <brainn@gmail.com>
    References: https://bugs.freedesktop.org/show_bug.cgi?id=108081
    Signed-off-by: Ville Syrjälä <ville.syrjala@linux.intel.com>
    Link: https://patchwork.freedesktop.org/patch/msgid/20180928180403.22499-1-ville.syrjala@linux.intel.com
    Reviewed-by: Dhinakaran Pandiyan <dhinakaran.pandiyan@intel.com>
    Signed-off-by: Sasha Levin <sashal@kernel.org>
    ---
     drivers/gpu/drm/drm_dp_mst_topology.c | 1 +
     1 file changed, 1 insertion(+)
    
    diff --git a/drivers/gpu/drm/drm_dp_mst_topology.c b/drivers/gpu/drm/drm_dp_mst_topology.c
    index 529414556962..1a244c53252c 100644
    --- a/drivers/gpu/drm/drm_dp_mst_topology.c
    +++ b/drivers/gpu/drm/drm_dp_mst_topology.c
    @@ -3286,6 +3286,7 @@ static int drm_dp_mst_i2c_xfer(struct i2c_adapter *adapter, struct i2c_msg *msgs
     		msg.u.i2c_read.transactions[i].i2c_dev_id = msgs[i].addr;
     		msg.u.i2c_read.transactions[i].num_bytes = msgs[i].len;
     		msg.u.i2c_read.transactions[i].bytes = msgs[i].buf;
    +		msg.u.i2c_read.transactions[i].no_stop_bit = !(msgs[i].flags & I2C_M_STOP);
     	}
     	msg.u.i2c_read.read_i2c_device_id = msgs[num - 1].addr;
     	msg.u.i2c_read.num_bytes_read = msgs[num - 1].len;
    -- 
    2.19.1
    
    _______________________________________________
    dri-devel mailing list
    dri-devel@lists.freedesktop.org
    https://lists.freedesktop.org/mailman/listinfo/dri-devel
    
    ^ permalink raw reply related	[flat|nested] 21+ messages in thread

  • end of thread, other threads:[~2019-03-28 10:04 UTC | newest]
    
    Thread overview: 21+ messages (download: mbox.gz follow: Atom feed
    -- links below jump to the message on this page --
         [not found] <20190327180158.10245-1-sashal@kernel.org>
         [not found] ` <20190327180158.10245-1-sashal-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org>
    2019-03-27 17:58   ` [PATCH AUTOSEL 5.0 070/262] drm/amd/display: Pass app_tf by value rather than by reference Sasha Levin
    2019-03-28 10:04     ` Pavel Machek
    2019-03-27 18:00   ` [PATCH AUTOSEL 5.0 171/262] drm/amd/display: Don't re-program planes for DPMS changes Sasha Levin
    2019-03-27 18:00   ` [PATCH AUTOSEL 5.0 175/262] drm/amd/display: Disconnect mpcc when changing tg Sasha Levin
    2019-03-27 18:00   ` [PATCH AUTOSEL 5.0 194/262] drm/msm/dpu: Convert to a chained irq chip Sasha Levin
    2019-03-27 18:01   ` [PATCH AUTOSEL 5.0 242/262] drm/nouveau: Stop using drm_crtc_force_disable Sasha Levin
    2019-03-27 17:58 ` [PATCH AUTOSEL 5.0 078/262] drm/amd/display: Fix reference counting for struct dc_sink Sasha Levin
    2019-03-27 17:59 ` [PATCH AUTOSEL 5.0 114/262] drm/amd/display: Clear stream->mode_changed after commit Sasha Levin
    2019-03-27 17:59 ` [PATCH AUTOSEL 5.0 135/262] drm/sched: Fix entities with 0 rqs Sasha Levin
    2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 147/262] drm: allow render capable master with DRM_AUTH ioctls Sasha Levin
    2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 168/262] fbdev: fbmem: fix memory access if logo is bigger than the screen Sasha Levin
    2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 170/262] drm: rcar-du: add missing of_node_put Sasha Levin
    2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 188/262] drm/vkms: Bugfix racing hrtimer vblank handle Sasha Levin
    2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 189/262] drm/vkms: Bugfix extra vblank frame Sasha Levin
    2019-03-27 18:00 ` [PATCH AUTOSEL 5.0 204/262] backlight: pwm_bl: Use gpiod_get_value_cansleep() to get initial state Sasha Levin
    2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 207/262] drm/amd/display: Enable vblank interrupt during CRC capture Sasha Levin
    2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 220/262] drm/vkms: Fix flush_work() without INIT_WORK() Sasha Levin
    2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 241/262] drm: Auto-set allow_fb_modifiers when given modifiers at plane init Sasha Levin
    2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 248/262] drm/fb-helper: fix leaks in error path of drm_fb_helper_fbdev_setup Sasha Levin
    2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 256/262] drm: Reorder set_property_atomic to avoid returning with an active ww_ctx Sasha Levin
    2019-03-27 18:01 ` [PATCH AUTOSEL 5.0 257/262] drm/dp/mst: Configure no_stop_bit correctly for remote i2c xfers Sasha Levin
    

    This is a public inbox, see mirroring instructions
    for how to clone and mirror all data and code used for this inbox