* [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms
@ 2026-08-03 18:05 Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 01/22] drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach Sebastian Reichel
` (21 more replies)
0 siblings, 22 replies; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel, Sashiko, Krzysztof Kozlowski
This patch series updates the Synopsys Designware DisplayPort bridge
together with the only existing user: The Rockchip RK3576/RK3588:
1. Follow-up bridges (PHY, USB-C connector)
This is needed to get USB-C DP AltMode working; I've followed
the Qualcomm driver as reference
2. Runtime PM
The initial driver has been upstreamed without RPM; add it to
avoid wasting power when nothing is plugged
3. Audio
The initial driver has been upstreamed without audio support;
this adds all missing bits for audio with single stream transport
To properly make use of the bridge code the following USBDP PHY series
is also needed:
https://lore.kernel.org/all/20260714-rockchip-usbdp-cleanup-v13-0-6cb3e769d4c5@collabora.com/
This series can be applied without the USBDP side. In that case USB-C
support won't work as the mainline USBDP side does not register as a
DRM bridge. As upstream DT binding for USBDP does not yet support
proper ports, no such board should be upstream.
Boards using the DP controller for native DP connectors (or HDMI
bridges), currently directly link to the connector/hdmi bridge. These
are not affected by the USBDP changes and should keep working in any
case. The difference is, that this series the DRM side is aware of the
link. I don't have any of those boards, so this code path is untested.
I added a dedicated bridge callback for out-of-band hotplug events,
which is separate from the hotplug_notify. I have a feeling, that
there might be a better solution, but haven't found it. Please comment.
Changes in v9:
- Link to v8: https://patch.msgid.link/20260731-synopsys-dw-dp-improvements-v8-0-ac1e6a75782f@collabora.com
- Add yet another patch, which fixes missing resorce cleanups when
dw_dp_link_enable() runs into errors (Sashiko)
- Acquire audio_lock guard in dw_dp_audio_mute_stream (Sashiko)
- Ensure dp->bridge.dev is set in dw_dp_hpd_work (Sashiko)
- Error out if hardware returns more bytes then requested by
DP AUX transfer (Sashiko)
- The other Sashiko problems reported on v8 are false positives
as far as I can tell
Changes in v8:
- Link to v7: https://patch.msgid.link/20260728-synopsys-dw-dp-improvements-v7-0-b7640fa8cf48@collabora.com
- Add new patch moving DP AUX bridge registration into
bridge_attach/detach callbacks, which simplifies cleanup and ensures
it is (un)registered at the right point in time (Sashiko)
- Update Fix incorrect resource lifetimes in bind callback patch to
ensure at the end of the probe, the device is fully functional,
also only register the bridge once all necessary bits are available
as it is in theory reachable at this point (Sashiko)
- Update the patch cancelling HPD worker to simply use
devm_work_autocancel() as a result of this rework
- Add a new patch describing why the reset line state is not explicitly
changed (Sashiko)
- Merge the two patches for the AUX transfer timeout handling to avoid a
temporary race condition and synchronize IRQs after the reset to fix
yet another race condition (Sashiko)
- Add a new patch to properly support short I2C reads (Sashiko)
- Rework Runtime PM handling again, so that the OOB handling is done
before the 100ms sleep. Also ensure it is enabled at the right point
in time after the cleanup changes. (Sashiko)
- Add new patch to drop useless reservation for SDP slot 0, which
fix a race condition (Sashiko)
- Also restore audio mute status when audio functionality is restored
after atomic disable/enable cycle (Sashiko)
- Setup SDP audio frame channel_allocation according to information
received from ALSA (Sashko)
- Sashiko feedback ignored by me and that may or may not appear again
in this version as Sashiko does not seem to properly take the whole
series into account and thus probably ignores the changelog
* A divide-by-zero vulnerability exists in dw_dp_video_enable when
processing a display mode with a clock value of 1; I believe this
clock cannot drive a real mode
* I2C-over-AUX reply status (NACK/DEFER) is silently discarded,
causing deferred I2C transactions to falsely succeed and return
garbage data; this is a false positive. It seems Sashiko got
confused by the bit patterns. Nothing is discarded.
* Potential Use-After-Free of the connector and encoder due to missing
DRM device reference in OOB hotplug event handling; Sashiko
missed that drm_for_each_bridge_in_chain() is now the renamed
drm_for_each_bridge_in_chain_scoped().
* Missing runtime PM acquisition in out-of-band HPD callbacks leads to
SError crashes once runtime PM is enabled; Sashiko failed to
notice that Runtime PM is only introduced in a later patch
* Calling a sleeping function (msleep) from a runtime PM resume
callback that is reachable from an atomic commit path; Sashiko
failed to understand that atomic DRM functions may sleep
* Missing system sleep callbacks prevent the device and its power
domain from suspending during system sleep for native DP
configurations; this needs separate investigation considering
system sleep is broken on recent Rockchip platforms (same error
appears a few times)
* There is a bunch of pre-existing issues that are fixed later
in the series
Changes in v7:
- Link to v6: https://lore.kernel.org/r/20260724-synopsys-dw-dp-improvements-v6-0-041d99a19c4e@collabora.com
- Move drm_bridge_add() to probe and only attach it in the bind
function, as the object is re-used and not fully cleared by
drm_bridge_remove (Sashiko)
- Add a new patch resetting the DP AUX sub-controller on message
timeout to have decent error recovery (Sashiko)
- Fix dp_dp_rockchip_get_vo_grf -> dw_dp_rockchip_get_vo_grf (Sashiko)
- Introduce pm_active in the PM runtime patch, to early exit
on atomic_disable when atomic_enable failed to get runtime
PM enabled (Sashiko)
- Introduce drm_bound in the PM runtime patch, which is (un)set
when the driver is bound to a DRM encoder and used to enable
IRQ enabling in the runtime PM handlers. This in turn protects
the system of potential spurious interrupts. (Sashiko)
- In the audio patch, fix support for hotplug with a running
audio stream. (Sashiko)
- To avoid further blowing up the series, I've decided not to
act on these "pre-existing" issues reported by Sashiko. I
think it makes sense to handle them separately:
* Short HPD and Long HPD events share a single boolean state
variable, causing critical hot plug events to be lost if
interrupts arrive in quick succession.
* DP AUX lifetime complains (registered too early / unregistered
too late); reported multiple times
* The driver fails to support DP AUX short reads, incorrectly
rejecting them with -EBUSY instead of returning the number
of bytes successfully transferred, which breaks I2C-over-AUX.
- Collected Reviewed-by from Krzysztof Kozlowski on the
DT binding patch
Changes in v6:
- Link to v5: https://lore.kernel.org/r/20260724-synopsys-dw-dp-improvements-v5-0-9445c2e87441@collabora.com
- Fix overlong commit message in mutex patch
- Update MEDIA_BUS_FMT_FIXED patch, to use input format as output format
when output format is MEDIA_BUS_FMT_FIXED (Sashiko)
- Drop patch moving dw_dp_bridge_atomic_get_output_bus_fmts (no longer
needed)
- Reword the comment about platforms other than RK3576 and RK3588
shouldn't get the VO GRF from the USBDP to make it more obvious
that no such platform exist at the moment and thus the alternative
path will not be implemented at this point in time (Sashiko)
- Update the runtime PM code to have much better error handling
as well as support for platforms not using runtime PM (Sashiko)
- Update the runtime PM code to keep the device suspended when
probed, but unbound as a nice side effect
- Fix error handling for dw_dp_audio_infoframe_send() in audio
patch (Sashiko)
- Fix typo in sample width check in audio patch (Sashiko)
- Improve cleanup of SDP in audio patch (Sashiko)
Changes in v5:
- Link to v4: https://lore.kernel.org/r/20260721-synopsys-dw-dp-improvements-v4-0-f0f4a4ede712@collabora.com
- Add new patch to cancel pending HPD work on unbind (Sashiko)
- Add new patch to add missing mutex cleanups on module removal (Sashiko)
- Add new patch moving dw_dp_bridge_atomic_get_output_bus_fmts
- Update MEDIA_BUS_FMT_FIXED patch to avoid fixed RGB888 format
and instead use whatever works for the negotiated bandwidth (Sashiko)
- Add more error checking for runtime PM patches (Sashiko)
- Ensure runtime PM is held in interrupt handler (Sashiko)
- Fix usbc_mode logic inversion for runtime PM in unbind (Sashiko)
- Move sleep for HPD_HOT_PLUG from hotplug handler to runtime
resume function; no need to sleep when runtime PM is kept
active and runtime PM resume is a slow operation anyways. (Sashiko)
- Add new patch to protect sdp_reg_bank from concurrent access (Sashiko)
- Add new patch to use regmap_set_bits in dw_dp_send_sdp()
- Update DT binding patch to be all about the selected solution and
mention the ABI break
- Clear SDP in the audio patch on unprepare (Sashiko)
- Add a comment, that only 1,2 or 8 channels are supported (Sashiko)
- Error out on unsupported sample_width (Sashiko)
- Fix missing error check for clock enable (Sashiko)
Changes in PATCHv4:
- Link to v3: https://lore.kernel.org/all/20260612-synopsys-dw-dp-improvements-v3-0-dc61e6352508@collabora.com/
- Drop "Simplify driver data setting" (effectively reverted later on)
- Add "Fix incorrect resource lifetimes in bind callback", which
affects all following patches quite a bit (Sashiko)
- Update "Add follow-up bridge support" to mention that fatal errors
are fine (Sashiko)
- Update "Add out-of-band HPD notify handler" to use
drm_for_each_bridge_in_chain() instead of
drm_for_each_bridge_in_chain_scoped() required after rebase to
latest drm-misc-next
- Add 100ms sleep in hpd detect functions after runtime resume in the
"Add Runtime PM support" patch (Andy Yan)
- Keep runtime PM enabled if DP is used without USB-C to avoid missing
HPD signals in "Add Runtime PM support" patch (Andy Yan)
- Update patch description of DT binding patch and drop RFC tag
- Use pm_runtime_resume_and_get() in the audio startup function, which
allows easy error handling (Sashiko)
- Avoid updating audio_interface in the audio prepare function when
an error related early exit happens (Sashiko)
- Add error handling for clock prepare calls in audio prepare function
(Sashiko)
Changes in PATCHv3:
- Link to v2: https://lore.kernel.org/r/20260501-synopsys-dw-dp-improvements-v2-0-d7e7f6bac77f@collabora.com
- Collect Reviewed-by on "Simplify driver data setting" patch (Andy Yan)
- Use of_drm_get_bridge_by_endpoint instead of devm_drm_of_get_bridge (Luca Ceresoli)
- Use FIELD_PREP_WM16 instead of FIELD_PREP_WM16_CONST (Chaoyi Chen)
- Rebase to latest drm-misc-next (Dropped Cristian's patches)
Changes in PATCHv2:
* Link to v1: https://lore.kernel.org/r/20260326-synopsys-dw-dp-improvements-v1-0-501849162290@collabora.com
* rebased to latest drm-misc-next
* prepended the Patches from Cristian's cleanup series, as they also
needed a rebase and should be merged first
https://lore.kernel.org/dri-devel/20260327-drm-rk-fixes-v3-0-fd2e6900c08c@collabora.com/
* fix issue with the audio stream (un)prepare handling in last patch
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
Sebastian Reichel (22):
drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach
drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback
drm/bridge: synopsys: dw-dp: Fix error handling in dw_dp_link_enable()
drm/bridge: synopsys: dw-dp: Cancel pending HPD work
drm/bridge: synopsys: dw-dp: Document missing reset line deassert
drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal
drm/bridge: synopsys: dw-dp: Fix AUX transfer timeout race condition
drm/bridge: synopsys: dw-dp: Fix support for short I2C reads
drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid
drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED
drm/bridge: synopsys: dw-dp: Add follow-up bridge support
drm/bridge: Add out-of-band HPD notify handler
drm/bridge: synopsys: dw-dp: Support software triggered OOB HPD
drm/rockchip: dw_dp: Implement out-of-band HPD handling
drm/bridge: synopsys: dw-dp: Add Runtime PM support
drm/rockchip: dw_dp: Add runtime PM support
drm/bridge: synopsys: dw-dp: Protect sdp_reg_bank from concurrent access
drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot
drm/bridge: synopsys: dw-dp: Clear only enabled SDPs on atomic disable
drm/bridge: synopsys: dw-dp: Use regmap_set_bits in dw_dp_send_sdp
dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells
drm/bridge: synopsys: dw-dp: Add audio support
.../bindings/display/rockchip/rockchip,dw-dp.yaml | 9 +-
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 798 ++++++++++++++++++---
drivers/gpu/drm/display/drm_bridge_connector.c | 6 +
drivers/gpu/drm/rockchip/dw_dp-rockchip.c | 190 ++++-
include/drm/bridge/dw_dp.h | 13 +-
include/drm/drm_bridge.h | 14 +
6 files changed, 916 insertions(+), 114 deletions(-)
---
base-commit: 173dceaed68eef074b77278bd92e6fdb4e09606d
change-id: 20260325-synopsys-dw-dp-improvements-7da2e98df1dd
Best regards,
--
Sebastian Reichel <sebastian.reichel@collabora.com>
^ permalink raw reply [flat|nested] 36+ messages in thread
* [PATCH v9 01/22] drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:35 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 02/22] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback Sebastian Reichel
` (20 subsequent siblings)
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel, Sashiko
Unregister the DP AUX device at the right spot as documented in the
drm_dp_aux_register() function description. This helps that it is
only accessed when the DRM device is ready and the bridge is powered
and initialized (further fixes are required for that).
Fixes: 86eecc3a9c2e ("drm/bridge: synopsys: Add DW DPTX Controller support library")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 55 +++++++++++++++++++++------------
1 file changed, 35 insertions(+), 20 deletions(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 3445c82e6f50..112a49911309 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -1813,7 +1813,36 @@ static struct drm_bridge_state *dw_dp_bridge_atomic_duplicate_state(struct drm_b
return &state->base;
}
+static int dw_dp_bridge_attach(struct drm_bridge *bridge,
+ struct drm_encoder *encoder,
+ enum drm_bridge_attach_flags flags)
+{
+ struct dw_dp *dp = bridge_to_dp(bridge);
+ struct device *dev = dp->dev;
+ int ret;
+
+ dp->aux.dev = dev;
+ dp->aux.drm_dev = encoder->dev;
+ dp->aux.name = dev_name(dev);
+ dp->aux.transfer = dw_dp_aux_transfer;
+
+ ret = drm_dp_aux_register(&dp->aux);
+ if (ret)
+ dev_err(dev, "Aux register failed: %d\n", ret);
+
+ return ret;
+}
+
+static void dw_dp_bridge_detach(struct drm_bridge *bridge)
+{
+ struct dw_dp *dp = bridge_to_dp(bridge);
+
+ drm_dp_aux_unregister(&dp->aux);
+}
+
static const struct drm_bridge_funcs dw_dp_bridge_funcs = {
+ .attach = dw_dp_bridge_attach,
+ .detach = dw_dp_bridge_detach,
.atomic_duplicate_state = dw_dp_bridge_atomic_duplicate_state,
.atomic_destroy_state = drm_atomic_helper_bridge_destroy_state,
.atomic_create_state = drm_atomic_helper_bridge_create_state,
@@ -2044,20 +2073,10 @@ struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
if (ret)
return ERR_PTR(ret);
- dp->aux.dev = dev;
- dp->aux.drm_dev = encoder->dev;
- dp->aux.name = dev_name(dev);
- dp->aux.transfer = dw_dp_aux_transfer;
- ret = drm_dp_aux_register(&dp->aux);
- if (ret) {
- dev_err_probe(dev, ret, "Aux register failed\n");
- return ERR_PTR(ret);
- }
-
ret = drm_bridge_attach(encoder, bridge, NULL, DRM_BRIDGE_ATTACH_NO_CONNECTOR);
if (ret) {
dev_err_probe(dev, ret, "Failed to attach bridge\n");
- goto unregister_aux;
+ return ERR_PTR(ret);
}
dw_dp_init_hw(dp);
@@ -2065,37 +2084,33 @@ struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
ret = phy_init(dp->phy);
if (ret) {
dev_err_probe(dev, ret, "phy init failed\n");
- goto unregister_aux;
+ return ERR_PTR(ret);
}
ret = devm_add_action_or_reset(dev, dw_dp_phy_exit, dp);
if (ret)
- goto unregister_aux;
+ return ERR_PTR(ret);
dp->irq = platform_get_irq(pdev, 0);
if (dp->irq < 0) {
ret = dp->irq;
- goto unregister_aux;
+ return ERR_PTR(ret);
}
ret = devm_request_threaded_irq(dev, dp->irq, NULL, dw_dp_irq,
IRQF_ONESHOT, dev_name(dev), dp);
if (ret) {
dev_err_probe(dev, ret, "failed to request irq\n");
- goto unregister_aux;
+ return ERR_PTR(ret);
}
return dp;
-
-unregister_aux:
- drm_dp_aux_unregister(&dp->aux);
- return ERR_PTR(ret);
}
EXPORT_SYMBOL_GPL(dw_dp_bind);
void dw_dp_unbind(struct dw_dp *dp)
{
- drm_dp_aux_unregister(&dp->aux);
+ /* nothing to do */
}
EXPORT_SYMBOL_GPL(dw_dp_unbind);
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 02/22] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 01/22] drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:27 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 03/22] drm/bridge: synopsys: dw-dp: Fix error handling in dw_dp_link_enable() Sebastian Reichel
` (19 subsequent siblings)
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel, Sashiko
Currently the Synopsys DesignWare DP controller driver's bind function
requests lots of resources using device managed functions. These are
free'd on driver removal instead of at unbind time. Fix this discrepancy
by introducing a new probe helper function and moving over the whole
bind function. This results in a fully functional DRM bridge once probe
succeeded. The only thing still happening when the component is bound
is the bridge attachment, which requires the encoder.
Fixes: 86eecc3a9c2e ("drm/bridge: synopsys: Add DW DPTX Controller support library")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 72 +++++++++++++++++--------------
drivers/gpu/drm/rockchip/dw_dp-rockchip.c | 53 +++++++++++++----------
include/drm/bridge/dw_dp.h | 5 ++-
3 files changed, 74 insertions(+), 56 deletions(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 112a49911309..06997208945e 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -1895,6 +1895,9 @@ static void dw_dp_hpd_work(struct work_struct *work)
long_hpd = dp->hotplug.long_hpd;
mutex_unlock(&dp->irq_lock);
+ if (!dp->bridge.dev)
+ return;
+
dev_dbg(dp->dev, "[drm] Get hpd irq - %s\n", long_hpd ? "long" : "short");
if (!long_hpd) {
@@ -1983,6 +1986,26 @@ static const struct regmap_config dw_dp_regmap_config = {
.rd_table = &dw_dp_readable_table,
};
+int dw_dp_bind(struct dw_dp *dp, struct drm_encoder *encoder)
+{
+ struct drm_bridge *bridge = &dp->bridge;
+ struct device *dev = dp->dev;
+ int ret;
+
+ ret = drm_bridge_attach(encoder, bridge, NULL, DRM_BRIDGE_ATTACH_NO_CONNECTOR);
+ if (ret)
+ return dev_err_probe(dev, ret, "Failed to attach bridge\n");
+
+ return 0;
+}
+EXPORT_SYMBOL_GPL(dw_dp_bind);
+
+void dw_dp_unbind(struct dw_dp *dp)
+{
+ /* nothing to do */
+}
+EXPORT_SYMBOL_GPL(dw_dp_unbind);
+
static void dw_dp_phy_exit(void *data)
{
struct dw_dp *dp = data;
@@ -1990,13 +2013,12 @@ static void dw_dp_phy_exit(void *data)
phy_exit(dp->phy);
}
-struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
- const struct dw_dp_plat_data *plat_data)
+struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_data *plat_data)
{
- struct platform_device *pdev = to_platform_device(dev);
- struct dw_dp *dp;
+ struct device *dev = &pdev->dev;
struct drm_bridge *bridge;
void __iomem *res;
+ struct dw_dp *dp;
int ret;
dp = devm_drm_bridge_alloc(dev, struct dw_dp, bridge, &dw_dp_bridge_funcs);
@@ -2005,9 +2027,8 @@ struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
dp->dev = dev;
dp->pixel_mode = plat_data->pixel_mode;
-
dp->plat_data.max_link_rate = plat_data->max_link_rate;
- bridge = &dp->bridge;
+
mutex_init(&dp->irq_lock);
INIT_WORK(&dp->hpd_work, dw_dp_hpd_work);
init_completion(&dp->complete);
@@ -2064,21 +2085,6 @@ struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
return ERR_CAST(dp->rstc);
}
- bridge->of_node = dev->of_node;
- bridge->ops = DRM_BRIDGE_OP_DETECT | DRM_BRIDGE_OP_EDID | DRM_BRIDGE_OP_HPD;
- bridge->type = DRM_MODE_CONNECTOR_DisplayPort;
- bridge->ycbcr_420_allowed = true;
-
- ret = devm_drm_bridge_add(dev, bridge);
- if (ret)
- return ERR_PTR(ret);
-
- ret = drm_bridge_attach(encoder, bridge, NULL, DRM_BRIDGE_ATTACH_NO_CONNECTOR);
- if (ret) {
- dev_err_probe(dev, ret, "Failed to attach bridge\n");
- return ERR_PTR(ret);
- }
-
dw_dp_init_hw(dp);
ret = phy_init(dp->phy);
@@ -2091,11 +2097,19 @@ struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
if (ret)
return ERR_PTR(ret);
- dp->irq = platform_get_irq(pdev, 0);
- if (dp->irq < 0) {
- ret = dp->irq;
+ bridge = &dp->bridge;
+ bridge->of_node = dev->of_node;
+ bridge->ops = DRM_BRIDGE_OP_DETECT | DRM_BRIDGE_OP_EDID | DRM_BRIDGE_OP_HPD;
+ bridge->type = DRM_MODE_CONNECTOR_DisplayPort;
+ bridge->ycbcr_420_allowed = true;
+
+ ret = devm_drm_bridge_add(dev, bridge);
+ if (ret)
return ERR_PTR(ret);
- }
+
+ dp->irq = platform_get_irq(pdev, 0);
+ if (dp->irq < 0)
+ return ERR_PTR(dp->irq);
ret = devm_request_threaded_irq(dev, dp->irq, NULL, dw_dp_irq,
IRQF_ONESHOT, dev_name(dev), dp);
@@ -2106,13 +2120,7 @@ struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
return dp;
}
-EXPORT_SYMBOL_GPL(dw_dp_bind);
-
-void dw_dp_unbind(struct dw_dp *dp)
-{
- /* nothing to do */
-}
-EXPORT_SYMBOL_GPL(dw_dp_unbind);
+EXPORT_SYMBOL_GPL(dw_dp_probe);
MODULE_AUTHOR("Andy Yan <andyshrk@163.com>");
MODULE_DESCRIPTION("DW DP Core Library");
diff --git a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
index b23efb153c9e..005938dc66c9 100644
--- a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
@@ -26,7 +26,7 @@
struct rockchip_dw_dp {
struct dw_dp *base;
struct device *dev;
- struct rockchip_encoder encoder;
+ struct rockchip_encoder *encoder;
};
static int dw_dp_encoder_atomic_check(struct drm_encoder *encoder,
@@ -73,37 +73,28 @@ static const struct drm_encoder_helper_funcs dw_dp_encoder_helper_funcs = {
static int dw_dp_rockchip_bind(struct device *dev, struct device *master, void *data)
{
- struct platform_device *pdev = to_platform_device(dev);
- const struct dw_dp_plat_data *plat_data;
+ struct rockchip_dw_dp *dp = dev_get_drvdata(dev);
struct drm_device *drm_dev = data;
- struct rockchip_dw_dp *dp;
struct drm_encoder *encoder;
struct drm_connector *connector;
int ret;
- dp = drmm_kzalloc(drm_dev, sizeof(*dp), GFP_KERNEL);
- if (!dp)
+ dp->encoder = drmm_kzalloc(drm_dev, sizeof(*dp->encoder), GFP_KERNEL);
+ if (!dp->encoder)
return -ENOMEM;
- dp->dev = dev;
- platform_set_drvdata(pdev, dp);
-
- plat_data = of_device_get_match_data(dev);
- if (!plat_data)
- return -ENODEV;
-
- encoder = &dp->encoder.encoder;
+ encoder = &dp->encoder->encoder;
encoder->possible_crtcs = drm_of_find_possible_crtcs(drm_dev, dev->of_node);
- rockchip_drm_encoder_set_crtc_endpoint_id(&dp->encoder, dev->of_node, 0, 0);
+ rockchip_drm_encoder_set_crtc_endpoint_id(dp->encoder, dev->of_node, 0, 0);
ret = drmm_encoder_init(drm_dev, encoder, NULL, DRM_MODE_ENCODER_TMDS, NULL);
if (ret)
return ret;
drm_encoder_helper_add(encoder, &dw_dp_encoder_helper_funcs);
- dp->base = dw_dp_bind(dev, encoder, plat_data);
- if (IS_ERR(dp->base))
- return PTR_ERR(dp->base);
+ ret = dw_dp_bind(dp->base, encoder);
+ if (ret)
+ return ret;
connector = drm_bridge_connector_init(drm_dev, encoder);
if (IS_ERR(connector)) {
@@ -128,12 +119,30 @@ static const struct component_ops dw_dp_rockchip_component_ops = {
.unbind = dw_dp_rockchip_unbind,
};
-static int dw_dp_probe(struct platform_device *pdev)
+static int dw_dp_rockchip_probe(struct platform_device *pdev)
{
+ const struct dw_dp_plat_data *plat_data;
+ struct device *dev = &pdev->dev;
+ struct rockchip_dw_dp *dp;
+
+ plat_data = of_device_get_match_data(dev);
+ if (!plat_data)
+ return -ENODEV;
+
+ dp = devm_kzalloc(dev, sizeof(*dp), GFP_KERNEL);
+ if (!dp)
+ return -ENOMEM;
+ platform_set_drvdata(pdev, dp);
+ dp->dev = dev;
+
+ dp->base = dw_dp_probe(pdev, plat_data);
+ if (IS_ERR(dp->base))
+ return PTR_ERR(dp->base);
+
return component_add(&pdev->dev, &dw_dp_rockchip_component_ops);
}
-static void dw_dp_remove(struct platform_device *pdev)
+static void dw_dp_rockchip_remove(struct platform_device *pdev)
{
component_del(&pdev->dev, &dw_dp_rockchip_component_ops);
}
@@ -161,8 +170,8 @@ static const struct of_device_id dw_dp_of_match[] = {
MODULE_DEVICE_TABLE(of, dw_dp_of_match);
struct platform_driver dw_dp_driver = {
- .probe = dw_dp_probe,
- .remove = dw_dp_remove,
+ .probe = dw_dp_rockchip_probe,
+ .remove = dw_dp_rockchip_remove,
.driver = {
.name = "dw-dp",
.of_match_table = dw_dp_of_match,
diff --git a/include/drm/bridge/dw_dp.h b/include/drm/bridge/dw_dp.h
index 22105c3e8e4d..a82412a9e769 100644
--- a/include/drm/bridge/dw_dp.h
+++ b/include/drm/bridge/dw_dp.h
@@ -22,7 +22,8 @@ struct dw_dp_plat_data {
u8 pixel_mode;
};
-struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
- const struct dw_dp_plat_data *plat_data);
+int dw_dp_bind(struct dw_dp *dp, struct drm_encoder *encoder);
void dw_dp_unbind(struct dw_dp *dp);
+
+struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_data *plat_data);
#endif /* __DW_DP__ */
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 03/22] drm/bridge: synopsys: dw-dp: Fix error handling in dw_dp_link_enable()
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 01/22] drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 02/22] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:25 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 04/22] drm/bridge: synopsys: dw-dp: Cancel pending HPD work Sebastian Reichel
` (18 subsequent siblings)
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel, Sashiko
Add missing error handling in dw_dp_link_enable(), which failed to
release resources it already requested before hitting an error.
Fixes: 86eecc3a9c2e ("drm/bridge: synopsys: Add DW DPTX Controller support library")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 06997208945e..e332d66b8057 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -1636,10 +1636,19 @@ static int dw_dp_link_enable(struct dw_dp *dp)
ret = drm_dp_link_power_up(&dp->aux, dp->link.revision);
if (ret < 0)
- return ret;
+ goto err_phy_power_off;
ret = dw_dp_link_train(dp);
+ if (ret < 0)
+ goto err_link_power_down;
+
+ return 0;
+
+err_link_power_down:
+ drm_dp_link_power_down(&dp->aux, dp->link.revision);
+err_phy_power_off:
+ phy_power_off(dp->phy);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 04/22] drm/bridge: synopsys: dw-dp: Cancel pending HPD work
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (2 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 03/22] drm/bridge: synopsys: dw-dp: Fix error handling in dw_dp_link_enable() Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:35 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 05/22] drm/bridge: synopsys: dw-dp: Document missing reset line deassert Sebastian Reichel
` (17 subsequent siblings)
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel, Sashiko
There is a race condition during device removal: If the HPD interrupt
started an HPD worker exactly when the device is removed, the worker
thread might access invalid resources. Avoid this by stopping any
pending work immediately after disabling the interrupt.
Fixes: 86eecc3a9c2e ("drm/bridge: synopsys: Add DW DPTX Controller support library")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index e332d66b8057..278953a8549a 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -8,6 +8,7 @@
*/
#include <linux/bitfield.h>
#include <linux/clk.h>
+#include <linux/devm-helpers.h>
#include <linux/iopoll.h>
#include <linux/irq.h>
#include <linux/media-bus-format.h>
@@ -2039,7 +2040,6 @@ struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_
dp->plat_data.max_link_rate = plat_data->max_link_rate;
mutex_init(&dp->irq_lock);
- INIT_WORK(&dp->hpd_work, dw_dp_hpd_work);
init_completion(&dp->complete);
res = devm_platform_ioremap_resource(pdev, 0);
@@ -2120,6 +2120,10 @@ struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_
if (dp->irq < 0)
return ERR_PTR(dp->irq);
+ ret = devm_work_autocancel(dev, &dp->hpd_work, dw_dp_hpd_work);
+ if (ret)
+ return ERR_PTR(ret);
+
ret = devm_request_threaded_irq(dev, dp->irq, NULL, dw_dp_irq,
IRQF_ONESHOT, dev_name(dev), dp);
if (ret) {
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 05/22] drm/bridge: synopsys: dw-dp: Document missing reset line deassert
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (3 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 04/22] drm/bridge: synopsys: dw-dp: Cancel pending HPD work Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 06/22] drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal Sebastian Reichel
` (16 subsequent siblings)
21 siblings, 0 replies; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel, Sashiko
If the driver uses devm_reset_control_get_exclusive_deasserted() instead
of devm_reset_control_get() and thus automatically deasserts during
probe, the SoC will hang when the device is unbound.
This does not happen, when runtime PM is being used (not yet supported
in mainline), which suggests the power-domain involved requires this reset
line to be deasserted.
Even with runtime PM there is no gurantee that the power-domain is
disabled as it is shared. Considering the power-domain does not have
the reset dependency described in DT, document the problem but leave
things in the current state until a better solution is found as the
reset line is deasserted by default on all supported platforms.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 278953a8549a..facd1c479992 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -2088,6 +2088,10 @@ struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_
return ERR_CAST(dp->hdcp_clk);
}
+ /*
+ * This reset line is deasserted by default; asserting it hangs the SoC if the
+ * related power-domain is still active.
+ */
dp->rstc = devm_reset_control_get(dev, NULL);
if (IS_ERR(dp->rstc)) {
dev_err_probe(dev, PTR_ERR(dp->rstc), "failed to get reset control\n");
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 06/22] drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (4 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 05/22] drm/bridge: synopsys: dw-dp: Document missing reset line deassert Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:27 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 07/22] drm/bridge: synopsys: dw-dp: Fix AUX transfer timeout race condition Sebastian Reichel
` (15 subsequent siblings)
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel, Sashiko
The driver is currently missing to fully clean up after itself. Ensure
that the mutex is cleaned up.
Fixes: 86eecc3a9c2e ("drm/bridge: synopsys: Add DW DPTX Controller support library")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index facd1c479992..af3fa7886429 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -2039,9 +2039,12 @@ struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_
dp->pixel_mode = plat_data->pixel_mode;
dp->plat_data.max_link_rate = plat_data->max_link_rate;
- mutex_init(&dp->irq_lock);
init_completion(&dp->complete);
+ ret = devm_mutex_init(dev, &dp->irq_lock);
+ if (ret)
+ return ERR_PTR(ret);
+
res = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(res))
return ERR_CAST(res);
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 07/22] drm/bridge: synopsys: dw-dp: Fix AUX transfer timeout race condition
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (5 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 06/22] drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 08/22] drm/bridge: synopsys: dw-dp: Fix support for short I2C reads Sebastian Reichel
` (14 subsequent siblings)
21 siblings, 0 replies; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel, Sashiko
The DP AUX transfer method uses a completion triggered by an interrupt,
which can timeout. If the function runs into the timeout and the
interrupt fires afterwards, the following DP aux transfer completion
would trigger immediately without waiting for the interrupt. This in
turn means the next one would also be broken and so on.
Fix this potential issue by re-initializing the completion directly
before sending the AUX command.
As this is racy (the interrupt might arrive between the completion
re-init and the new command being programmed), also reset the AUX
controller on timeouts and synchronize pending interrupts to gurantee
that there are no pending AUX transfers when the dw_dp_aux_transfer()
returns.
Due to lack of a sink, which generates AUX timeouts, this change is
effectively untested.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 86eecc3a9c2e ("drm/bridge: synopsys: Add DW DPTX Controller support library")
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index af3fa7886429..8b587a4c5e93 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -1466,6 +1466,8 @@ static ssize_t dw_dp_aux_transfer(struct drm_dp_aux *aux,
if (WARN_ON(msg->size > 16))
return -E2BIG;
+ reinit_completion(&dp->complete);
+
switch (msg->request & ~DP_AUX_I2C_MOT) {
case DP_AUX_NATIVE_WRITE:
case DP_AUX_I2C_WRITE:
@@ -1492,6 +1494,12 @@ static ssize_t dw_dp_aux_transfer(struct drm_dp_aux *aux,
status = wait_for_completion_timeout(&dp->complete, timeout);
if (!status) {
dev_err(dp->dev, "timeout waiting for AUX reply\n");
+ regmap_update_bits(dp->regmap, DW_DP_SOFT_RESET_CTRL,
+ AUX_RESET, FIELD_PREP(AUX_RESET, 1));
+ usleep_range(10, 20);
+ regmap_update_bits(dp->regmap, DW_DP_SOFT_RESET_CTRL,
+ AUX_RESET, FIELD_PREP(AUX_RESET, 0));
+ synchronize_irq(dp->irq);
return -ETIMEDOUT;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 08/22] drm/bridge: synopsys: dw-dp: Fix support for short I2C reads
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (6 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 07/22] drm/bridge: synopsys: dw-dp: Fix AUX transfer timeout race condition Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 09/22] drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid Sebastian Reichel
` (13 subsequent siblings)
21 siblings, 0 replies; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel, Sashiko
The transfer functions returns the amount of bytes read for
DP_AUX_I2C_READ. By returning -EBUSY for short reads, the caller has
less information available what is going wrong and possibly simply
resends the read request. On sinks not supporting long reads, this will
simply run into the same issue again.
Instead it makes more sense to return the data from the short read with
the length information, which allows drm_dp_i2c_do_msg() to read data in
smaller chunks and succeed in the end.
Due to lack of a sink, which only supports short reads, this change is
effectively untested.
Fixes: 86eecc3a9c2e ("drm/bridge: synopsys: Add DW DPTX Controller support library")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 8b587a4c5e93..22a244de08aa 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -1513,7 +1513,7 @@ static ssize_t dw_dp_aux_transfer(struct drm_dp_aux *aux,
if (msg->request & DP_AUX_I2C_READ) {
size_t count = FIELD_GET(AUX_BYTES_READ, value) - 1;
- if (count != msg->size)
+ if (!count || count > msg->size)
return -EBUSY;
ret = dw_dp_aux_read_data(dp, msg->buffer, count);
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 09/22] drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (7 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 08/22] drm/bridge: synopsys: dw-dp: Fix support for short I2C reads Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:35 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 10/22] drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED Sebastian Reichel
` (12 subsequent siblings)
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel, Sashiko
If dw_dp_bandwidth_ok() returns false for all formats, *num_output_fmts
might end up becoming 0. In this case functions calling it assume that
nothing needs to be free'd, so free output_fmts within the function to
avoid leaking memory.
Fixes: 86eecc3a9c2e ("drm/bridge: synopsys: Add DW DPTX Controller support library")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 22a244de08aa..bde938b0d116 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -1813,6 +1813,11 @@ static u32 *dw_dp_bridge_atomic_get_output_bus_fmts(struct drm_bridge *bridge,
output_fmts[j++] = fmt->bus_format;
}
+ if (j == 0) {
+ kfree(output_fmts);
+ output_fmts = NULL;
+ }
+
*num_output_fmts = j;
return output_fmts;
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 10/22] drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (8 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 09/22] drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:43 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 11/22] drm/bridge: synopsys: dw-dp: Add follow-up bridge support Sebastian Reichel
` (11 subsequent siblings)
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
Add support for MEDIA_BUS_FMT_FIXED, which is e.g. requested for USB-C
DP chains as the last bridge in the chain (aux-hpd-bridge) does not
implement atomic_get_output_bus_fmts(), which results in the generic
drm_atomic_bridge_chain_select_bus_fmts() code using MEDIA_BUS_FMT_FIXED
instead. For decent support of this, two areas are changed:
1. In atomic_check, resolving MEDIA_BUS_FMT_FIXED output format by
using the negotiated input format.
2. Implementing a custom .atomic_get_input_bus_fmts hook that, on
MEDIA_BUS_FMT_FIXED, advertises all bandwidth-validated formats
from dw_dp_bridge_atomic_get_output_bus_fmts(). This lets the
upstream encoder negotiate the best mutually supported format.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 34 +++++++++++++++++++++++++++++++--
1 file changed, 32 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index bde938b0d116..e60dab0d3b9d 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -1537,6 +1537,7 @@ static int dw_dp_bridge_atomic_check(struct drm_bridge *bridge,
struct drm_connector_state *conn_state)
{
struct drm_display_mode *adjusted_mode = &crtc_state->adjusted_mode;
+ unsigned int out_bus_format = bridge_state->output_bus_cfg.format;
struct dw_dp *dp = bridge_to_dp(bridge);
struct dw_dp_bridge_state *state;
const struct dw_dp_output_format *fmt;
@@ -1547,7 +1548,10 @@ static int dw_dp_bridge_atomic_check(struct drm_bridge *bridge,
state = to_dw_dp_bridge_state(bridge_state);
mode = &state->mode;
- fmt = dw_dp_get_output_format(bridge_state->output_bus_cfg.format);
+ if (out_bus_format == MEDIA_BUS_FMT_FIXED)
+ out_bus_format = bridge_state->input_bus_cfg.format;
+
+ fmt = dw_dp_get_output_format(out_bus_format);
if (!fmt)
return -EINVAL;
@@ -1823,6 +1827,32 @@ static u32 *dw_dp_bridge_atomic_get_output_bus_fmts(struct drm_bridge *bridge,
return output_fmts;
}
+static u32 *
+dw_dp_bridge_atomic_get_input_bus_fmts(struct drm_bridge *bridge,
+ struct drm_bridge_state *bridge_state,
+ struct drm_crtc_state *crtc_state,
+ struct drm_connector_state *conn_state,
+ u32 output_fmt,
+ unsigned int *num_input_fmts)
+{
+ /*
+ * MEDIA_BUS_FMT_FIXED means the downstream bridge does not constrain
+ * the bus format. In that case, advertise all formats supported by the
+ * DP link so the upstream encoder can negotiate the best match.
+ */
+ if (output_fmt == MEDIA_BUS_FMT_FIXED)
+ return dw_dp_bridge_atomic_get_output_bus_fmts(bridge,
+ bridge_state,
+ crtc_state,
+ conn_state,
+ num_input_fmts);
+
+ return drm_atomic_helper_bridge_propagate_bus_fmt(bridge, bridge_state,
+ crtc_state, conn_state,
+ output_fmt,
+ num_input_fmts);
+}
+
static struct drm_bridge_state *dw_dp_bridge_atomic_duplicate_state(struct drm_bridge *bridge)
{
struct dw_dp_bridge_state *state;
@@ -1869,7 +1899,7 @@ static const struct drm_bridge_funcs dw_dp_bridge_funcs = {
.atomic_duplicate_state = dw_dp_bridge_atomic_duplicate_state,
.atomic_destroy_state = drm_atomic_helper_bridge_destroy_state,
.atomic_create_state = drm_atomic_helper_bridge_create_state,
- .atomic_get_input_bus_fmts = drm_atomic_helper_bridge_propagate_bus_fmt,
+ .atomic_get_input_bus_fmts = dw_dp_bridge_atomic_get_input_bus_fmts,
.atomic_get_output_bus_fmts = dw_dp_bridge_atomic_get_output_bus_fmts,
.atomic_check = dw_dp_bridge_atomic_check,
.mode_valid = dw_dp_bridge_mode_valid,
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 11/22] drm/bridge: synopsys: dw-dp: Add follow-up bridge support
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (9 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 10/22] drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 12/22] drm/bridge: Add out-of-band HPD notify handler Sebastian Reichel
` (10 subsequent siblings)
21 siblings, 0 replies; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
Add support to use USB-C connectors with the DP altmode helper code on
devicetree based platforms. To get this working there must be a DRM
bridge chain from the DisplayPort controller to the USB-C connector.
E.g. on Rockchip RK3576:
root@rk3576 # cat /sys/kernel/debug/dri/0/encoder-0/bridges
bridge[0]: dw_dp_bridge_funcs
refcount: 7
type: [10] DP
OF: /soc/dp@27e40000:rockchip,rk3576-dp
ops: [0x47] detect edid hpd
bridge[1]: drm_aux_bridge_funcs
refcount: 4
type: [0] Unknown
OF: /soc/phy@2b010000:rockchip,rk3576-usbdp-phy
ops: [0x0]
bridge[2]: drm_aux_hpd_bridge_funcs
refcount: 5
type: [10] DP
OF: /soc/i2c@2ac50000/typec-portc@22/connector:usb-c-connector
ops: [0x4] hpd
It's fine to fatally error out when there is no follow-up bridge
as the Rockchip Designware Displayport controller is the only
user of the bridge helper and has the port marked as required
in its binding.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 22 +++++++++++++++++++++-
1 file changed, 21 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index e60dab0d3b9d..577ec42c94a4 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -330,6 +330,8 @@ struct dw_dp {
struct dw_dp_plat_data plat_data;
u8 pixel_mode;
+ struct drm_bridge *next_bridge;
+
DECLARE_BITMAP(sdp_reg_bank, SDP_REG_BANK_SIZE);
};
@@ -2049,13 +2051,31 @@ int dw_dp_bind(struct dw_dp *dp, struct drm_encoder *encoder)
if (ret)
return dev_err_probe(dev, ret, "Failed to attach bridge\n");
+ dp->next_bridge = of_drm_get_bridge_by_endpoint(dev->of_node, 1, 0);
+ if (IS_ERR(dp->next_bridge)) {
+ ret = PTR_ERR(dp->next_bridge);
+ return dev_err_probe(dev, ret, "failed to get follow-up bridge.\n");
+ }
+
+ ret = drm_bridge_attach(encoder, dp->next_bridge, bridge,
+ DRM_BRIDGE_ATTACH_NO_CONNECTOR);
+ if (ret) {
+ dev_err_probe(dev, ret, "Failed to attach next bridge\n");
+ goto put_next_bridge;
+ }
+
return 0;
+
+put_next_bridge:
+ drm_bridge_put(dp->next_bridge);
+
+ return ret;
}
EXPORT_SYMBOL_GPL(dw_dp_bind);
void dw_dp_unbind(struct dw_dp *dp)
{
- /* nothing to do */
+ drm_bridge_put(dp->next_bridge);
}
EXPORT_SYMBOL_GPL(dw_dp_unbind);
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 12/22] drm/bridge: Add out-of-band HPD notify handler
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (10 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 11/22] drm/bridge: synopsys: dw-dp: Add follow-up bridge support Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 13/22] drm/bridge: synopsys: dw-dp: Support software triggered OOB HPD Sebastian Reichel
` (9 subsequent siblings)
21 siblings, 0 replies; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
For DP bridges, that can be used for DP AltMode, it might be necessary
to enforce HPD status. There is an existing ->oob_hotplug_event() on
the DRM connector, but it currently just calls into hpd_notify().
As DP bridge drivers usually also implement .detect and that also
generates calls into hpd_notify, this is a bad place to force the
HPD status as the follow-up detect call might force it off again
resulting in all follow-up calls to the detection routine also
failing.
Avoid this by having a dedicated function for OOB events.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/display/drm_bridge_connector.c | 6 ++++++
include/drm/drm_bridge.h | 14 ++++++++++++++
2 files changed, 20 insertions(+)
diff --git a/drivers/gpu/drm/display/drm_bridge_connector.c b/drivers/gpu/drm/display/drm_bridge_connector.c
index 8b54069fa53a..632cc3ae3b54 100644
--- a/drivers/gpu/drm/display/drm_bridge_connector.c
+++ b/drivers/gpu/drm/display/drm_bridge_connector.c
@@ -180,6 +180,12 @@ static void drm_bridge_connector_oob_hotplug_event(struct drm_connector *connect
struct drm_bridge_connector *bridge_connector =
to_drm_bridge_connector(connector);
+ /* Notify all bridges in the pipeline of hotplug events. */
+ drm_for_each_bridge_in_chain(bridge_connector->encoder, bridge) {
+ if (bridge->funcs->oob_notify)
+ bridge->funcs->oob_notify(bridge, connector, status);
+ }
+
drm_bridge_connector_handle_hpd(bridge_connector, status);
}
diff --git a/include/drm/drm_bridge.h b/include/drm/drm_bridge.h
index 58fff047f43b..713652fca033 100644
--- a/include/drm/drm_bridge.h
+++ b/include/drm/drm_bridge.h
@@ -540,6 +540,20 @@ struct drm_bridge_funcs {
*/
void (*hpd_disable)(struct drm_bridge *bridge);
+ /**
+ * @oob_notify:
+ *
+ * Notify the bridge of out of band hot plug detection.
+ *
+ * This callback is optional, it may be implemented by bridges that
+ * need to be notified of display connection or disconnection for
+ * internal reasons. One use case is to force the DP controllers HPD
+ * signal for USB-C DP AltMode.
+ */
+ void (*oob_notify)(struct drm_bridge *bridge,
+ struct drm_connector *connector,
+ enum drm_connector_status status);
+
/**
* @hdmi_tmds_char_rate_valid:
*
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 13/22] drm/bridge: synopsys: dw-dp: Support software triggered OOB HPD
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (11 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 12/22] drm/bridge: Add out-of-band HPD notify handler Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 14/22] drm/rockchip: dw_dp: Implement out-of-band HPD handling Sebastian Reichel
` (8 subsequent siblings)
21 siblings, 0 replies; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
Add support for USB-C DP AltMode out-of-band hotplug handling. The
handling itself is implemented in the platform specific driver as the
registers to force HPD state are not part of the Designware DisplayPort
IP itself. Instead the platform integration might provide the necessary
functionality to mux the HPD signal.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 38 +++++++++++++++++++++++++++++++++
include/drm/bridge/dw_dp.h | 3 +++
2 files changed, 41 insertions(+)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 577ec42c94a4..7b8a9855ceae 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -1895,6 +1895,19 @@ static void dw_dp_bridge_detach(struct drm_bridge *bridge)
drm_dp_aux_unregister(&dp->aux);
}
+static void dw_dp_bridge_oob_notify(struct drm_bridge *bridge,
+ struct drm_connector *connector,
+ enum drm_connector_status status)
+{
+ bool hpd_high = status != connector_status_disconnected;
+ struct dw_dp *dp = bridge_to_dp(bridge);
+
+ if (dp->plat_data.hpd_sw_cfg)
+ dp->plat_data.hpd_sw_cfg(dp->plat_data.data, hpd_high);
+ else
+ dev_err_once(dp->dev, "Missing platform handler for OOB HPD handling\n");
+}
+
static const struct drm_bridge_funcs dw_dp_bridge_funcs = {
.attach = dw_dp_bridge_attach,
.detach = dw_dp_bridge_detach,
@@ -1909,6 +1922,7 @@ static const struct drm_bridge_funcs dw_dp_bridge_funcs = {
.atomic_disable = dw_dp_bridge_atomic_disable,
.detect = dw_dp_bridge_detect,
.edid_read = dw_dp_bridge_edid_read,
+ .oob_notify = dw_dp_bridge_oob_notify,
};
static int dw_dp_link_retrain(struct dw_dp *dp)
@@ -2041,6 +2055,19 @@ static const struct regmap_config dw_dp_regmap_config = {
.rd_table = &dw_dp_readable_table,
};
+static bool dw_dp_is_routed_to_usb_c(struct drm_encoder *encoder)
+{
+ struct drm_bridge *last_bridge __free(drm_bridge_put) = NULL;
+ struct fwnode_handle *fwnode;
+
+ last_bridge = drm_bridge_chain_get_last_bridge(encoder);
+ if (!last_bridge)
+ return false;
+
+ fwnode = of_fwnode_handle(last_bridge->of_node);
+ return fwnode_device_is_compatible(fwnode, "usb-c-connector");
+}
+
int dw_dp_bind(struct dw_dp *dp, struct drm_encoder *encoder)
{
struct drm_bridge *bridge = &dp->bridge;
@@ -2064,6 +2091,13 @@ int dw_dp_bind(struct dw_dp *dp, struct drm_encoder *encoder)
goto put_next_bridge;
}
+ if (dw_dp_is_routed_to_usb_c(encoder)) {
+ dev_dbg(dev, "USB-C mode\n");
+
+ if (dp->plat_data.hpd_sw_sel)
+ dp->plat_data.hpd_sw_sel(dp->plat_data.data, 1);
+ }
+
return 0;
put_next_bridge:
@@ -2100,6 +2134,10 @@ struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_
dp->dev = dev;
dp->pixel_mode = plat_data->pixel_mode;
+
+ dp->plat_data.hpd_sw_sel = plat_data->hpd_sw_sel;
+ dp->plat_data.hpd_sw_cfg = plat_data->hpd_sw_cfg;
+ dp->plat_data.data = plat_data->data;
dp->plat_data.max_link_rate = plat_data->max_link_rate;
init_completion(&dp->complete);
diff --git a/include/drm/bridge/dw_dp.h b/include/drm/bridge/dw_dp.h
index a82412a9e769..79b2cdf0df99 100644
--- a/include/drm/bridge/dw_dp.h
+++ b/include/drm/bridge/dw_dp.h
@@ -20,6 +20,9 @@ enum {
struct dw_dp_plat_data {
u32 max_link_rate;
u8 pixel_mode;
+ void *data;
+ void (*hpd_sw_sel)(void *data, bool hpd);
+ void (*hpd_sw_cfg)(void *data, bool hpd);
};
int dw_dp_bind(struct dw_dp *dp, struct drm_encoder *encoder);
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 14/22] drm/rockchip: dw_dp: Implement out-of-band HPD handling
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (12 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 13/22] drm/bridge: synopsys: dw-dp: Support software triggered OOB HPD Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:46 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 15/22] drm/bridge: synopsys: dw-dp: Add Runtime PM support Sebastian Reichel
` (7 subsequent siblings)
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
Implement out-of-band hotplug handling, which will be used to receive
external hotplug information from the USB-C state machine. This is
currently handled by the USBDP PHY, which brings quite some trouble
as the register being accessed requires the power-domain from the DP
controller. Thus this patch prevents massive SError problems once
runtime PM is enabled. Apart from that it avoids custom TypeC HPD
info parsing in the USBDP PHY driver.
In contrast to the USBDP PHY this does not just enable the hotplug
signal when a DP AltMode capable adapter is plugged in, but instead
properly detects if a cable is plugged in for things like USB-C to
HDMI adapters.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/rockchip/dw_dp-rockchip.c | 118 ++++++++++++++++++++++++++++--
1 file changed, 113 insertions(+), 5 deletions(-)
diff --git a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
index 005938dc66c9..d516b3910b51 100644
--- a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
@@ -7,9 +7,12 @@
*/
#include <linux/component.h>
+#include <linux/hw_bitfield.h>
#include <linux/media-bus-format.h>
+#include <linux/mfd/syscon.h>
#include <linux/of_device.h>
#include <linux/platform_device.h>
+#include <linux/regmap.h>
#include <linux/videodev2.h>
#include <drm/bridge/dw_dp.h>
@@ -23,12 +26,48 @@
#include "rockchip_drm_drv.h"
+#define ROCKCHIP_MAX_CTRLS 2
+
+#define ROCKCHIP_VO_GRF_DP_SINK_HPD_SEL BIT(10)
+#define ROCKCHIP_VO_GRF_DP_SINK_HPD_CFG BIT(11)
+
+struct rockchip_dw_dp_plat_data {
+ u8 num_ctrls;
+ u32 ctrl_ids[ROCKCHIP_MAX_CTRLS];
+ u32 max_link_rate;
+ u8 pixel_mode;
+ u32 hpd_reg[ROCKCHIP_MAX_CTRLS];
+};
+
struct rockchip_dw_dp {
struct dw_dp *base;
struct device *dev;
+ const struct rockchip_dw_dp_plat_data *pdata;
+ struct regmap *vo_grf;
struct rockchip_encoder *encoder;
+ int id;
};
+static void dw_dp_rockchip_hpd_sw_sel(void *data, bool force_hpd_from_sw)
+{
+ struct rockchip_dw_dp *dp = data;
+ u32 hpd_reg = dp->pdata->hpd_reg[dp->id];
+
+ regmap_write(dp->vo_grf, hpd_reg,
+ FIELD_PREP_WM16(ROCKCHIP_VO_GRF_DP_SINK_HPD_SEL, force_hpd_from_sw));
+}
+
+static void dw_dp_rockchip_hpd_sw_cfg(void *data, bool hpd)
+{
+ struct rockchip_dw_dp *dp = data;
+ u32 hpd_reg = dp->pdata->hpd_reg[dp->id];
+
+ dev_dbg(dp->dev, "Force HPD connected=%s\n", str_yes_no(hpd));
+
+ regmap_write(dp->vo_grf, hpd_reg,
+ FIELD_PREP_WM16(ROCKCHIP_VO_GRF_DP_SINK_HPD_CFG, hpd));
+}
+
static int dw_dp_encoder_atomic_check(struct drm_encoder *encoder,
struct drm_crtc_state *crtc_state,
struct drm_connector_state *conn_state)
@@ -71,6 +110,35 @@ static const struct drm_encoder_helper_funcs dw_dp_encoder_helper_funcs = {
.atomic_check = dw_dp_encoder_atomic_check,
};
+static struct regmap *dw_dp_rockchip_get_vo_grf(struct rockchip_dw_dp *dp)
+{
+ struct device_node *np = dev_of_node(dp->dev);
+ struct of_phandle_args args;
+ struct regmap *regmap;
+ int ret;
+
+ ret = of_parse_phandle_with_args(np, "phys", "#phy-cells", 0, &args);
+ if (ret)
+ return ERR_PTR(-ENODEV);
+
+ /*
+ * Limit this workaround to RK3576 and RK3588, potential future platforms
+ * reusing the driver should just add a VO GRF phandle in the DisplayPort
+ * controller DT node.
+ */
+ if (!of_device_is_compatible(args.np, "rockchip,rk3576-usbdp-phy") &&
+ !of_device_is_compatible(args.np, "rockchip,rk3588-usbdp-phy")) {
+ regmap = ERR_PTR(-ENODEV);
+ goto out_put_node;
+ }
+
+ regmap = syscon_regmap_lookup_by_phandle(args.np, "rockchip,vo-grf");
+
+out_put_node:
+ of_node_put(args.np);
+ return regmap;
+}
+
static int dw_dp_rockchip_bind(struct device *dev, struct device *master, void *data)
{
struct rockchip_dw_dp *dp = dev_get_drvdata(dev);
@@ -121,19 +189,53 @@ static const struct component_ops dw_dp_rockchip_component_ops = {
static int dw_dp_rockchip_probe(struct platform_device *pdev)
{
- const struct dw_dp_plat_data *plat_data;
+ const struct rockchip_dw_dp_plat_data *plat_data_const;
+ struct dw_dp_plat_data *plat_data;
struct device *dev = &pdev->dev;
struct rockchip_dw_dp *dp;
+ struct resource *res;
+ int id;
- plat_data = of_device_get_match_data(dev);
- if (!plat_data)
+ plat_data_const = device_get_match_data(dev);
+ if (!plat_data_const)
return -ENODEV;
+ plat_data = devm_kzalloc(dev, sizeof(*plat_data), GFP_KERNEL);
+ if (!plat_data)
+ return -ENOMEM;
+
dp = devm_kzalloc(dev, sizeof(*dp), GFP_KERNEL);
if (!dp)
return -ENOMEM;
platform_set_drvdata(pdev, dp);
dp->dev = dev;
+ dp->pdata = plat_data_const;
+
+ res = platform_get_mem_or_io(pdev, 0);
+ if (!res)
+ return -ENODEV;
+
+ /* find the DisplayPort ID from the io address */
+ dp->id = -ENODEV;
+ for (id = 0; id < plat_data_const->num_ctrls; id++) {
+ if (res->start == plat_data_const->ctrl_ids[id]) {
+ dp->id = id;
+ break;
+ }
+ }
+
+ if (dp->id < 0)
+ return dp->id;
+
+ dp->vo_grf = dw_dp_rockchip_get_vo_grf(dp);
+ if (IS_ERR(dp->vo_grf))
+ return PTR_ERR(dp->vo_grf);
+
+ plat_data->max_link_rate = plat_data_const->max_link_rate;
+ plat_data->pixel_mode = plat_data_const->pixel_mode;
+ plat_data->hpd_sw_sel = dw_dp_rockchip_hpd_sw_sel;
+ plat_data->hpd_sw_cfg = dw_dp_rockchip_hpd_sw_cfg;
+ plat_data->data = dp;
dp->base = dw_dp_probe(pdev, plat_data);
if (IS_ERR(dp->base))
@@ -147,14 +249,20 @@ static void dw_dp_rockchip_remove(struct platform_device *pdev)
component_del(&pdev->dev, &dw_dp_rockchip_component_ops);
}
-static const struct dw_dp_plat_data rk3588_dp_plat_data = {
+static const struct rockchip_dw_dp_plat_data rk3588_dp_plat_data = {
+ .num_ctrls = 2,
+ .ctrl_ids = {0xfde50000, 0xfde60000},
.max_link_rate = 810000,
.pixel_mode = DW_DP_MP_QUAD_PIXEL,
+ .hpd_reg = {0x0000, 0x0008},
};
-static const struct dw_dp_plat_data rk3576_dp_plat_data = {
+static const struct rockchip_dw_dp_plat_data rk3576_dp_plat_data = {
+ .num_ctrls = 1,
+ .ctrl_ids = {0x27e40000},
.max_link_rate = 810000,
.pixel_mode = DW_DP_MP_DUAL_PIXEL,
+ .hpd_reg = {0x0000},
};
static const struct of_device_id dw_dp_of_match[] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 15/22] drm/bridge: synopsys: dw-dp: Add Runtime PM support
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (13 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 14/22] drm/rockchip: dw_dp: Implement out-of-band HPD handling Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:55 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 16/22] drm/rockchip: dw_dp: Add runtime " Sebastian Reichel
` (6 subsequent siblings)
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
Add runtime PM stubs to the Synopsys DesignWare DisplayPort bridge
driver. Support is not enabled automatically and must be hooked up
in the platform specific glue code.
The early bits of the dw_dp_probe function are split into a new
function called dw_dp_alloc, so that the platform driver can assign
it before running dw_dp_probe. This is necessary because the runtime
PM resume/suspend events land at the platform driver and must be
forwarded to the helper once runtime PM is enabled in the middle
of the probe function.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 233 ++++++++++++++++++++++++++------
include/drm/bridge/dw_dp.h | 7 +-
2 files changed, 201 insertions(+), 39 deletions(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 7b8a9855ceae..501b28abeca2 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -329,6 +329,9 @@ struct dw_dp {
struct dw_dp_link link;
struct dw_dp_plat_data plat_data;
u8 pixel_mode;
+ bool usbc_mode;
+ bool usbc_hpd;
+ bool pm_active;
struct drm_bridge *next_bridge;
@@ -1468,6 +1471,11 @@ static ssize_t dw_dp_aux_transfer(struct drm_dp_aux *aux,
if (WARN_ON(msg->size > 16))
return -E2BIG;
+ PM_RUNTIME_ACQUIRE_AUTOSUSPEND(dp->dev, pm);
+ ret = PM_RUNTIME_ACQUIRE_ERR(&pm);
+ if (ret)
+ return ret;
+
reinit_completion(&dp->complete);
switch (msg->request & ~DP_AUX_I2C_MOT) {
@@ -1675,6 +1683,13 @@ static void dw_dp_bridge_atomic_enable(struct drm_bridge *bridge,
struct drm_connector_state *conn_state;
int ret;
+ ret = pm_runtime_get_active(dp->dev, RPM_TRANSPARENT);
+ if (ret) {
+ dev_err(dp->dev, "runtime PM failure\n");
+ return;
+ }
+ dp->pm_active = true;
+
connector = drm_atomic_get_new_connector_for_encoder(state, bridge->encoder);
if (!connector) {
dev_err(dp->dev, "failed to get connector\n");
@@ -1725,10 +1740,15 @@ static void dw_dp_bridge_atomic_disable(struct drm_bridge *bridge,
{
struct dw_dp *dp = bridge_to_dp(bridge);
+ if (!dp->pm_active)
+ return;
+ dp->pm_active = false;
+
dw_dp_video_disable(dp);
dw_dp_link_disable(dp);
bitmap_zero(dp->sdp_reg_bank, SDP_REG_BANK_SIZE);
dw_dp_reset(dp);
+ pm_runtime_put_autosuspend(dp->dev);
}
static bool dw_dp_hpd_detect_link(struct dw_dp *dp, struct drm_connector *connector)
@@ -1749,6 +1769,10 @@ static enum drm_connector_status dw_dp_bridge_detect(struct drm_bridge *bridge,
{
struct dw_dp *dp = bridge_to_dp(bridge);
+ PM_RUNTIME_ACQUIRE_AUTOSUSPEND(dp->dev, pm);
+ if (PM_RUNTIME_ACQUIRE_ERR(&pm))
+ return connector_status_disconnected;
+
if (!dw_dp_hpd_detect(dp))
return connector_status_disconnected;
@@ -1901,6 +1925,14 @@ static void dw_dp_bridge_oob_notify(struct drm_bridge *bridge,
{
bool hpd_high = status != connector_status_disconnected;
struct dw_dp *dp = bridge_to_dp(bridge);
+ int ret;
+
+ dp->usbc_hpd = hpd_high;
+
+ PM_RUNTIME_ACQUIRE_AUTOSUSPEND(dp->dev, pm);
+ ret = PM_RUNTIME_ACQUIRE_ERR(&pm);
+ if (ret)
+ return;
if (dp->plat_data.hpd_sw_cfg)
dp->plat_data.hpd_sw_cfg(dp->plat_data.data, hpd_high);
@@ -1960,6 +1992,11 @@ static void dw_dp_hpd_work(struct work_struct *work)
bool long_hpd;
int ret;
+ PM_RUNTIME_ACQUIRE_AUTOSUSPEND(dp->dev, pm);
+ ret = PM_RUNTIME_ACQUIRE_ERR(&pm);
+ if (ret)
+ return;
+
mutex_lock(&dp->irq_lock);
long_hpd = dp->hotplug.long_hpd;
mutex_unlock(&dp->irq_lock);
@@ -2074,14 +2111,21 @@ int dw_dp_bind(struct dw_dp *dp, struct drm_encoder *encoder)
struct device *dev = dp->dev;
int ret;
- ret = drm_bridge_attach(encoder, bridge, NULL, DRM_BRIDGE_ATTACH_NO_CONNECTOR);
+ ret = pm_runtime_get_active(dp->dev, RPM_TRANSPARENT);
if (ret)
- return dev_err_probe(dev, ret, "Failed to attach bridge\n");
+ return ret;
+
+ ret = drm_bridge_attach(encoder, bridge, NULL, DRM_BRIDGE_ATTACH_NO_CONNECTOR);
+ if (ret) {
+ dev_err_probe(dev, ret, "Failed to attach bridge\n");
+ goto put_runtime_pm;
+ }
dp->next_bridge = of_drm_get_bridge_by_endpoint(dev->of_node, 1, 0);
if (IS_ERR(dp->next_bridge)) {
ret = PTR_ERR(dp->next_bridge);
- return dev_err_probe(dev, ret, "failed to get follow-up bridge.\n");
+ dev_err_probe(dev, ret, "failed to get follow-up bridge.\n");
+ goto put_runtime_pm;
}
ret = drm_bridge_attach(encoder, dp->next_bridge, bridge,
@@ -2091,11 +2135,15 @@ int dw_dp_bind(struct dw_dp *dp, struct drm_encoder *encoder)
goto put_next_bridge;
}
- if (dw_dp_is_routed_to_usb_c(encoder)) {
- dev_dbg(dev, "USB-C mode\n");
+ dp->usbc_mode = dw_dp_is_routed_to_usb_c(encoder);
+
+ if (dp->plat_data.hpd_sw_sel)
+ dp->plat_data.hpd_sw_sel(dp->plat_data.data, dp->usbc_mode);
- if (dp->plat_data.hpd_sw_sel)
- dp->plat_data.hpd_sw_sel(dp->plat_data.data, 1);
+ /* USB-C has out-of-band hotplug detection, so device may runtime suspend */
+ if (dp->usbc_mode) {
+ dev_dbg(dev, "USB-C mode\n");
+ pm_runtime_put_autosuspend(dp->dev);
}
return 0;
@@ -2103,6 +2151,9 @@ int dw_dp_bind(struct dw_dp *dp, struct drm_encoder *encoder)
put_next_bridge:
drm_bridge_put(dp->next_bridge);
+put_runtime_pm:
+ pm_runtime_put_autosuspend(dp->dev);
+
return ret;
}
EXPORT_SYMBOL_GPL(dw_dp_bind);
@@ -2110,6 +2161,9 @@ EXPORT_SYMBOL_GPL(dw_dp_bind);
void dw_dp_unbind(struct dw_dp *dp)
{
drm_bridge_put(dp->next_bridge);
+
+ if (!dp->usbc_mode)
+ pm_runtime_put_autosuspend(dp->dev);
}
EXPORT_SYMBOL_GPL(dw_dp_unbind);
@@ -2120,76 +2174,125 @@ static void dw_dp_phy_exit(void *data)
phy_exit(dp->phy);
}
-struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_data *plat_data)
+static void dw_dp_manual_suspend(void *data)
+{
+ struct dw_dp *dp = data;
+
+ dw_dp_runtime_suspend(dp);
+}
+
+static void dw_dp_irq_free(void *data)
+{
+ struct dw_dp *dp = data;
+
+ /* ignore error as the interrupt needs to be free'd in any case */
+ PM_RUNTIME_ACQUIRE_AUTOSUSPEND(dp->dev, pm);
+
+ free_irq(dp->irq, dp);
+ dp->irq = -1;
+}
+
+static int dw_dp_irq_request(struct dw_dp *dp, int irq)
+{
+ int ret;
+
+ PM_RUNTIME_ACQUIRE_AUTOSUSPEND(dp->dev, pm);
+
+ ret = PM_RUNTIME_ACQUIRE_ERR(&pm);
+ if (ret)
+ return ret;
+
+ ret = request_threaded_irq(irq, NULL, dw_dp_irq,
+ IRQF_ONESHOT, dev_name(dp->dev), dp);
+ if (ret)
+ return dev_err_probe(dp->dev, ret, "failed to request irq\n");
+
+ dp->irq = irq;
+
+ return devm_add_action_or_reset(dp->dev, dw_dp_irq_free, dp);
+}
+
+struct dw_dp *dw_dp_alloc(struct platform_device *pdev, const struct dw_dp_plat_data *plat_data)
{
struct device *dev = &pdev->dev;
- struct drm_bridge *bridge;
- void __iomem *res;
struct dw_dp *dp;
- int ret;
dp = devm_drm_bridge_alloc(dev, struct dw_dp, bridge, &dw_dp_bridge_funcs);
if (IS_ERR(dp))
return ERR_CAST(dp);
dp->dev = dev;
+ dp->irq = -1;
dp->pixel_mode = plat_data->pixel_mode;
dp->plat_data.hpd_sw_sel = plat_data->hpd_sw_sel;
dp->plat_data.hpd_sw_cfg = plat_data->hpd_sw_cfg;
dp->plat_data.data = plat_data->data;
dp->plat_data.max_link_rate = plat_data->max_link_rate;
+ dp->plat_data.autosuspend_delay = plat_data->autosuspend_delay;
init_completion(&dp->complete);
+ return dp;
+}
+EXPORT_SYMBOL_GPL(dw_dp_alloc);
+
+int dw_dp_probe(struct dw_dp *dp)
+{
+ struct device *dev = dp->dev;
+ struct platform_device *pdev = to_platform_device(dev);
+ struct drm_bridge *bridge;
+ void __iomem *res;
+ int irq, ret;
+
ret = devm_mutex_init(dev, &dp->irq_lock);
if (ret)
- return ERR_PTR(ret);
+ return ret;
res = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(res))
- return ERR_CAST(res);
+ return PTR_ERR(res);
dp->regmap = devm_regmap_init_mmio(dev, res, &dw_dp_regmap_config);
if (IS_ERR(dp->regmap)) {
dev_err_probe(dev, PTR_ERR(dp->regmap), "failed to create regmap\n");
- return ERR_CAST(dp->regmap);
+ return PTR_ERR(dp->regmap);
}
dp->phy = devm_of_phy_get(dev, dev->of_node, NULL);
if (IS_ERR(dp->phy)) {
dev_err_probe(dev, PTR_ERR(dp->phy), "failed to get phy\n");
- return ERR_CAST(dp->phy);
+ return PTR_ERR(dp->phy);
}
- dp->apb_clk = devm_clk_get_enabled(dev, "apb");
+ dp->apb_clk = devm_clk_get(dev, "apb");
if (IS_ERR(dp->apb_clk)) {
dev_err_probe(dev, PTR_ERR(dp->apb_clk), "failed to get apb clock\n");
- return ERR_CAST(dp->apb_clk);
+ return PTR_ERR(dp->apb_clk);
}
- dp->aux_clk = devm_clk_get_enabled(dev, "aux");
+ dp->aux_clk = devm_clk_get(dev, "aux");
if (IS_ERR(dp->aux_clk)) {
dev_err_probe(dev, PTR_ERR(dp->aux_clk), "failed to get aux clock\n");
- return ERR_CAST(dp->aux_clk);
+ return PTR_ERR(dp->aux_clk);
}
dp->i2s_clk = devm_clk_get_optional(dev, "i2s");
if (IS_ERR(dp->i2s_clk)) {
dev_err_probe(dev, PTR_ERR(dp->i2s_clk), "failed to get i2s clock\n");
- return ERR_CAST(dp->i2s_clk);
+ return PTR_ERR(dp->i2s_clk);
}
dp->spdif_clk = devm_clk_get_optional(dev, "spdif");
if (IS_ERR(dp->spdif_clk)) {
dev_err_probe(dev, PTR_ERR(dp->spdif_clk), "failed to get spdif clock\n");
- return ERR_CAST(dp->spdif_clk);
+ return PTR_ERR(dp->spdif_clk);
}
dp->hdcp_clk = devm_clk_get(dev, "hdcp");
if (IS_ERR(dp->hdcp_clk)) {
dev_err_probe(dev, PTR_ERR(dp->hdcp_clk), "failed to get hdcp clock\n");
- return ERR_CAST(dp->hdcp_clk);
+ return PTR_ERR(dp->hdcp_clk);
}
/*
@@ -2199,20 +2302,34 @@ struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_
dp->rstc = devm_reset_control_get(dev, NULL);
if (IS_ERR(dp->rstc)) {
dev_err_probe(dev, PTR_ERR(dp->rstc), "failed to get reset control\n");
- return ERR_CAST(dp->rstc);
+ return PTR_ERR(dp->rstc);
}
- dw_dp_init_hw(dp);
+ if (dp->plat_data.autosuspend_delay > 0) {
+ pm_runtime_use_autosuspend(dev);
+ pm_runtime_set_autosuspend_delay(dev, dp->plat_data.autosuspend_delay);
+ ret = devm_pm_runtime_enable(dev);
+ if (ret)
+ return ret;
+ }
+
+ if (!pm_runtime_enabled(dev)) {
+ dw_dp_runtime_resume(dp);
+
+ ret = devm_add_action_or_reset(dev, dw_dp_manual_suspend, dp);
+ if (ret)
+ return ret;
+ }
ret = phy_init(dp->phy);
if (ret) {
dev_err_probe(dev, ret, "phy init failed\n");
- return ERR_PTR(ret);
+ return ret;
}
ret = devm_add_action_or_reset(dev, dw_dp_phy_exit, dp);
if (ret)
- return ERR_PTR(ret);
+ return ret;
bridge = &dp->bridge;
bridge->of_node = dev->of_node;
@@ -2222,26 +2339,66 @@ struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_
ret = devm_drm_bridge_add(dev, bridge);
if (ret)
- return ERR_PTR(ret);
-
- dp->irq = platform_get_irq(pdev, 0);
- if (dp->irq < 0)
- return ERR_PTR(dp->irq);
+ return ret;
ret = devm_work_autocancel(dev, &dp->hpd_work, dw_dp_hpd_work);
if (ret)
- return ERR_PTR(ret);
+ return ret;
+
+ irq = platform_get_irq(pdev, 0);
+ if (irq < 0)
+ return irq;
+
+ return dw_dp_irq_request(dp, irq);
+}
+EXPORT_SYMBOL_GPL(dw_dp_probe);
+
+int dw_dp_runtime_suspend(struct dw_dp *dp)
+{
+ if (dp->irq >= 0)
+ disable_irq(dp->irq);
+
+ clk_disable_unprepare(dp->aux_clk);
+ clk_disable_unprepare(dp->apb_clk);
+
+ return 0;
+}
+EXPORT_SYMBOL_GPL(dw_dp_runtime_suspend);
+
+int dw_dp_runtime_resume(struct dw_dp *dp)
+{
+ int ret;
+
+ ret = clk_prepare_enable(dp->apb_clk);
+ if (ret)
+ return ret;
- ret = devm_request_threaded_irq(dev, dp->irq, NULL, dw_dp_irq,
- IRQF_ONESHOT, dev_name(dev), dp);
+ ret = clk_prepare_enable(dp->aux_clk);
if (ret) {
- dev_err_probe(dev, ret, "failed to request irq\n");
- return ERR_PTR(ret);
+ clk_disable_unprepare(dp->apb_clk);
+ return ret;
}
- return dp;
+ if (dp->plat_data.hpd_sw_sel)
+ dp->plat_data.hpd_sw_sel(dp->plat_data.data, dp->usbc_mode);
+ if (dp->plat_data.hpd_sw_cfg)
+ dp->plat_data.hpd_sw_cfg(dp->plat_data.data, dp->usbc_hpd);
+
+ dw_dp_init_hw(dp);
+
+ if (dp->irq >= 0) {
+ /*
+ * HPD_HOT_PLUG bit is asserted only after the sink holds HPD
+ * high for at least 100ms.
+ */
+ msleep(110);
+
+ enable_irq(dp->irq);
+ }
+
+ return 0;
}
-EXPORT_SYMBOL_GPL(dw_dp_probe);
+EXPORT_SYMBOL_GPL(dw_dp_runtime_resume);
MODULE_AUTHOR("Andy Yan <andyshrk@163.com>");
MODULE_DESCRIPTION("DW DP Core Library");
diff --git a/include/drm/bridge/dw_dp.h b/include/drm/bridge/dw_dp.h
index 79b2cdf0df99..1e23180b565e 100644
--- a/include/drm/bridge/dw_dp.h
+++ b/include/drm/bridge/dw_dp.h
@@ -18,6 +18,7 @@ enum {
};
struct dw_dp_plat_data {
+ int autosuspend_delay;
u32 max_link_rate;
u8 pixel_mode;
void *data;
@@ -28,5 +29,9 @@ struct dw_dp_plat_data {
int dw_dp_bind(struct dw_dp *dp, struct drm_encoder *encoder);
void dw_dp_unbind(struct dw_dp *dp);
-struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_data *plat_data);
+struct dw_dp *dw_dp_alloc(struct platform_device *pdev, const struct dw_dp_plat_data *plat_data);
+int dw_dp_probe(struct dw_dp *dp);
+
+int dw_dp_runtime_suspend(struct dw_dp *dp);
+int dw_dp_runtime_resume(struct dw_dp *dp);
#endif /* __DW_DP__ */
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 16/22] drm/rockchip: dw_dp: Add runtime PM support
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (14 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 15/22] drm/bridge: synopsys: dw-dp: Add Runtime PM support Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:58 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 17/22] drm/bridge: synopsys: dw-dp: Protect sdp_reg_bank from concurrent access Sebastian Reichel
` (5 subsequent siblings)
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
Add support for runtime PM to the Rockchip RK3576/3588 Synopsys
DesignWare DisplayPort driver.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/rockchip/dw_dp-rockchip.c | 29 +++++++++++++++++++++++++++--
1 file changed, 27 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
index d516b3910b51..dde3881efad8 100644
--- a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
@@ -12,6 +12,7 @@
#include <linux/mfd/syscon.h>
#include <linux/of_device.h>
#include <linux/platform_device.h>
+#include <linux/pm_runtime.h>
#include <linux/regmap.h>
#include <linux/videodev2.h>
@@ -194,7 +195,7 @@ static int dw_dp_rockchip_probe(struct platform_device *pdev)
struct device *dev = &pdev->dev;
struct rockchip_dw_dp *dp;
struct resource *res;
- int id;
+ int id, ret;
plat_data_const = device_get_match_data(dev);
if (!plat_data_const)
@@ -231,16 +232,21 @@ static int dw_dp_rockchip_probe(struct platform_device *pdev)
if (IS_ERR(dp->vo_grf))
return PTR_ERR(dp->vo_grf);
+ plat_data->autosuspend_delay = 500;
plat_data->max_link_rate = plat_data_const->max_link_rate;
plat_data->pixel_mode = plat_data_const->pixel_mode;
plat_data->hpd_sw_sel = dw_dp_rockchip_hpd_sw_sel;
plat_data->hpd_sw_cfg = dw_dp_rockchip_hpd_sw_cfg;
plat_data->data = dp;
- dp->base = dw_dp_probe(pdev, plat_data);
+ dp->base = dw_dp_alloc(pdev, plat_data);
if (IS_ERR(dp->base))
return PTR_ERR(dp->base);
+ ret = dw_dp_probe(dp->base);
+ if (ret)
+ return ret;
+
return component_add(&pdev->dev, &dw_dp_rockchip_component_ops);
}
@@ -249,6 +255,24 @@ static void dw_dp_rockchip_remove(struct platform_device *pdev)
component_del(&pdev->dev, &dw_dp_rockchip_component_ops);
}
+static int dw_dp_rockchip_runtime_suspend(struct device *dev)
+{
+ struct rockchip_dw_dp *dp = dev_get_drvdata(dev);
+
+ return dw_dp_runtime_suspend(dp->base);
+}
+
+static int dw_dp_rockchip_runtime_resume(struct device *dev)
+{
+ struct rockchip_dw_dp *dp = dev_get_drvdata(dev);
+
+ return dw_dp_runtime_resume(dp->base);
+}
+
+static const struct dev_pm_ops dw_dp_pm_ops = {
+ RUNTIME_PM_OPS(dw_dp_rockchip_runtime_suspend, dw_dp_rockchip_runtime_resume, NULL)
+};
+
static const struct rockchip_dw_dp_plat_data rk3588_dp_plat_data = {
.num_ctrls = 2,
.ctrl_ids = {0xfde50000, 0xfde60000},
@@ -283,5 +307,6 @@ struct platform_driver dw_dp_driver = {
.driver = {
.name = "dw-dp",
.of_match_table = dw_dp_of_match,
+ .pm = pm_ptr(&dw_dp_pm_ops),
},
};
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 17/22] drm/bridge: synopsys: dw-dp: Protect sdp_reg_bank from concurrent access
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (15 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 16/22] drm/rockchip: dw_dp: Add runtime " Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 18/22] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot Sebastian Reichel
` (4 subsequent siblings)
21 siblings, 0 replies; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
Right now sdp_reg_bank is only used during atomic enable/disable and
thus there is no risk of two threads accidently claiming the same bit.
This changes once more SDP users (like audio support) are added, so
introduce a mutex to protect concurrent access to the bitmap.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 24 +++++++++++++++++-------
1 file changed, 17 insertions(+), 7 deletions(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 501b28abeca2..19b6c11f672f 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -323,6 +323,8 @@ struct dw_dp {
struct dw_dp_hotplug hotplug;
/* Serialize hpd status access */
struct mutex irq_lock;
+ /* Serialize sdp_reg_bank access */
+ struct mutex sdp_lock;
struct drm_dp_aux aux;
@@ -1048,11 +1050,13 @@ static int dw_dp_send_sdp(struct dw_dp *dp, struct dw_dp_sdp *sdp)
u32 reg;
int i, nr;
- nr = find_first_zero_bit(dp->sdp_reg_bank, SDP_REG_BANK_SIZE);
- if (nr < SDP_REG_BANK_SIZE)
- set_bit(nr, dp->sdp_reg_bank);
- else
- return -EBUSY;
+ scoped_guard(mutex, &dp->sdp_lock) {
+ nr = find_first_zero_bit(dp->sdp_reg_bank, SDP_REG_BANK_SIZE);
+ if (nr < SDP_REG_BANK_SIZE)
+ set_bit(nr, dp->sdp_reg_bank);
+ else
+ return -EBUSY;
+ }
reg = DW_DP_SDP_REGISTER_BANK + nr * 9 * 4;
@@ -1702,7 +1706,8 @@ static void dw_dp_bridge_atomic_enable(struct drm_bridge *bridge,
return;
}
- set_bit(0, dp->sdp_reg_bank);
+ scoped_guard(mutex, &dp->sdp_lock)
+ set_bit(0, dp->sdp_reg_bank);
ret = dw_dp_link_enable(dp);
if (ret < 0) {
@@ -1746,7 +1751,8 @@ static void dw_dp_bridge_atomic_disable(struct drm_bridge *bridge,
dw_dp_video_disable(dp);
dw_dp_link_disable(dp);
- bitmap_zero(dp->sdp_reg_bank, SDP_REG_BANK_SIZE);
+ scoped_guard(mutex, &dp->sdp_lock)
+ bitmap_zero(dp->sdp_reg_bank, SDP_REG_BANK_SIZE);
dw_dp_reset(dp);
pm_runtime_put_autosuspend(dp->dev);
}
@@ -2249,6 +2255,10 @@ int dw_dp_probe(struct dw_dp *dp)
if (ret)
return ret;
+ ret = devm_mutex_init(dev, &dp->sdp_lock);
+ if (ret)
+ return ret;
+
res = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(res))
return PTR_ERR(res);
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 18/22] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (16 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 17/22] drm/bridge: synopsys: dw-dp: Protect sdp_reg_bank from concurrent access Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 19:02 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 19/22] drm/bridge: synopsys: dw-dp: Clear only enabled SDPs on atomic disable Sebastian Reichel
` (3 subsequent siblings)
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
The origin of this reservation is unclear, but it is a problem in the
atomic_enable code since it potentially races with the audio SDP
reservation once that feature is added. I suppose it was either meant to
be bitmap_zero(), but that is obviously not needed (and would also be a
problem for audio support) or some left-over development code before the
VSC SDP slot was allocated automatically.
From my tests SDP slot 0 works fine and can be used. If SDP slot 0
really needs to be reserved for some reason, the bit should be set in
the probe function to ensure there are no race conditions.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 3 ---
1 file changed, 3 deletions(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 19b6c11f672f..05d3485a4d8d 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -1706,9 +1706,6 @@ static void dw_dp_bridge_atomic_enable(struct drm_bridge *bridge,
return;
}
- scoped_guard(mutex, &dp->sdp_lock)
- set_bit(0, dp->sdp_reg_bank);
-
ret = dw_dp_link_enable(dp);
if (ret < 0) {
dev_err(dp->dev, "failed to enable link: %d\n", ret);
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 19/22] drm/bridge: synopsys: dw-dp: Clear only enabled SDPs on atomic disable
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (17 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 18/22] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 20/22] drm/bridge: synopsys: dw-dp: Use regmap_set_bits in dw_dp_send_sdp Sebastian Reichel
` (2 subsequent siblings)
21 siblings, 0 replies; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
dw_dp_bridge_atomic_disable() bulk-cleared the whole SDP register bank
allocation bitmap via bitmap_zero() resulting in the loss of all
tracking information. This results in a slot potentially being handed
out again by dw_dp_send_sdp(), which is still considered to be held
by the previous owner. Then the previous owner might free up the wrong
SDP later on.
Instead of bulk clearing the tracking information, the new
implementation only clears the SDPs actually configured during
dw_dp_bridge_atomic_enable() instead of the entire bank. The
introduced functionality for that will also be used by the to-be-added
audio infrastructure.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 27 +++++++++++++++++++++++----
1 file changed, 23 insertions(+), 4 deletions(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 05d3485a4d8d..d8c6a99e93b8 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -337,6 +337,7 @@ struct dw_dp {
struct drm_bridge *next_bridge;
+ int vsc_sdp_nr;
DECLARE_BITMAP(sdp_reg_bank, SDP_REG_BANK_SIZE);
};
@@ -1078,7 +1079,19 @@ static int dw_dp_send_sdp(struct dw_dp *dp, struct dw_dp_sdp *sdp)
EN_HORIZONTAL_SDP << nr,
EN_HORIZONTAL_SDP << nr);
- return 0;
+ return nr;
+}
+
+static void dw_dp_clear_sdp(struct dw_dp *dp, int nr)
+{
+ regmap_clear_bits(dp->regmap, DW_DP_SDP_VERTICAL_CTRL,
+ EN_VERTICAL_SDP << nr);
+
+ regmap_clear_bits(dp->regmap, DW_DP_SDP_HORIZONTAL_CTRL,
+ EN_HORIZONTAL_SDP << nr);
+
+ scoped_guard(mutex, &dp->sdp_lock)
+ clear_bit(nr, dp->sdp_reg_bank);
}
static int dw_dp_send_vsc_sdp(struct dw_dp *dp)
@@ -1396,7 +1409,7 @@ static int dw_dp_video_enable(struct dw_dp *dp)
FIELD_PREP(VIDEO_STREAM_ENABLE, 1));
if (dw_dp_video_need_vsc_sdp(dp))
- dw_dp_send_vsc_sdp(dp);
+ dp->vsc_sdp_nr = dw_dp_send_vsc_sdp(dp);
return 0;
}
@@ -1748,8 +1761,12 @@ static void dw_dp_bridge_atomic_disable(struct drm_bridge *bridge,
dw_dp_video_disable(dp);
dw_dp_link_disable(dp);
- scoped_guard(mutex, &dp->sdp_lock)
- bitmap_zero(dp->sdp_reg_bank, SDP_REG_BANK_SIZE);
+
+ if (dp->vsc_sdp_nr >= 0) {
+ dw_dp_clear_sdp(dp, dp->vsc_sdp_nr);
+ dp->vsc_sdp_nr = -1;
+ }
+
dw_dp_reset(dp);
pm_runtime_put_autosuspend(dp->dev);
}
@@ -2338,6 +2355,8 @@ int dw_dp_probe(struct dw_dp *dp)
if (ret)
return ret;
+ dp->vsc_sdp_nr = -1;
+
bridge = &dp->bridge;
bridge->of_node = dev->of_node;
bridge->ops = DRM_BRIDGE_OP_DETECT | DRM_BRIDGE_OP_EDID | DRM_BRIDGE_OP_HPD;
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 20/22] drm/bridge: synopsys: dw-dp: Use regmap_set_bits in dw_dp_send_sdp
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (18 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 19/22] drm/bridge: synopsys: dw-dp: Clear only enabled SDPs on atomic disable Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 21/22] dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 22/22] drm/bridge: synopsys: dw-dp: Add audio support Sebastian Reichel
21 siblings, 0 replies; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
Simplify dw_dp_send_sdp() a little bit by making use of
regmap_set_bits.
No functional change intended.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 10 ++++------
1 file changed, 4 insertions(+), 6 deletions(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index d8c6a99e93b8..5d10a60d265d 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -1070,14 +1070,12 @@ static int dw_dp_send_sdp(struct dw_dp *dp, struct dw_dp_sdp *sdp)
FIELD_PREP(SDP_REGS, get_unaligned_le32(payload)));
if (sdp->flags & DW_DP_SDP_VERTICAL_INTERVAL)
- regmap_update_bits(dp->regmap, DW_DP_SDP_VERTICAL_CTRL,
- EN_VERTICAL_SDP << nr,
- EN_VERTICAL_SDP << nr);
+ regmap_set_bits(dp->regmap, DW_DP_SDP_VERTICAL_CTRL,
+ EN_VERTICAL_SDP << nr);
if (sdp->flags & DW_DP_SDP_HORIZONTAL_INTERVAL)
- regmap_update_bits(dp->regmap, DW_DP_SDP_HORIZONTAL_CTRL,
- EN_HORIZONTAL_SDP << nr,
- EN_HORIZONTAL_SDP << nr);
+ regmap_set_bits(dp->regmap, DW_DP_SDP_HORIZONTAL_CTRL,
+ EN_HORIZONTAL_SDP << nr);
return nr;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 21/22] dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (19 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 20/22] drm/bridge: synopsys: dw-dp: Use regmap_set_bits in dw_dp_send_sdp Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 19:06 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 22/22] drm/bridge: synopsys: dw-dp: Add audio support Sebastian Reichel
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel, Krzysztof Kozlowski
The RK3588 and RK3576 DesignWare DisplayPort controllers both have two
possible DAI interfaces: I2S and S/PDIF. Thus an argument is needed to
to select the right interface.
In addition to that the RK3576 DisplayPort controller is configured
with Multi Stream Transport (MST) enabled for up to 3 displays and
thus has a total of 6 DAI interfaces (I2S and S/PDIF for each possible
stream). Meanwhile the RK3588 does not support MST and thus has only 2
DAI interfaces.
The binding update from this patch has only been tested with the simple
single stream transport (SST) setup as the Linux driver does not yet
support MST. Once MST support is added, the plan is to simply add more
numbers to the argument, so that it looks like this for RK3576:
0 = I2S on stream 0,
1 = S/PDIF on stream 0
2 = I2S on stream 1,
3 = S/PDIF on stream 1
4 = I2S on stream 2,
5 = S/PDIF on stream 2
As the arguments are not part of the binding itself the audio side
is also ready for MST after this change.
Switching '#sound-dai-cells' from 0 to 1 without keeping compatibility
is an ABI break. The rationale for going that way is, that there is not
a single known driver implementation for the current binding. It's also
unclear how the current binding would be used (only support I2S or
S/PDIF for stream 0?). The mainline rk3588 DTS include sets it to 0, but
does not have any soundcard using the DAI. This will be fixed up
separately. The RK3576 does not set it at all.
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
.../devicetree/bindings/display/rockchip/rockchip,dw-dp.yaml | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/Documentation/devicetree/bindings/display/rockchip/rockchip,dw-dp.yaml b/Documentation/devicetree/bindings/display/rockchip/rockchip,dw-dp.yaml
index 2b0d9e23e943..c4f8959dd65d 100644
--- a/Documentation/devicetree/bindings/display/rockchip/rockchip,dw-dp.yaml
+++ b/Documentation/devicetree/bindings/display/rockchip/rockchip,dw-dp.yaml
@@ -25,7 +25,7 @@ description: |
* Supports up to 8/10 bits per color component
* Supports RBG, YCbCr4:4:4, YCbCr4:2:2, YCbCr4:2:0
* Pixel clock up to 594MHz
- * I2S, SPDIF audio interface
+ * I2S, S/PDIF audio interface
properties:
compatible:
@@ -46,7 +46,7 @@ properties:
- description: DisplayPort AUX clock
- description: HDCP clock
- description: I2S interface clock
- - description: SPDIF interfce clock
+ - description: S/PDIF interfce clock
clock-names:
minItems: 3
@@ -83,7 +83,8 @@ properties:
maxItems: 1
"#sound-dai-cells":
- const: 0
+ const: 1
+ description: 0 for I2S, 1 for S/PDIF
required:
- compatible
@@ -144,7 +145,7 @@ examples:
resets = <&cru SRST_DP0>;
phys = <&usbdp_phy0 PHY_TYPE_DP>;
power-domains = <&power RK3588_PD_VO0>;
- #sound-dai-cells = <0>;
+ #sound-dai-cells = <1>;
ports {
#address-cells = <1>;
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* [PATCH v9 22/22] drm/bridge: synopsys: dw-dp: Add audio support
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
` (20 preceding siblings ...)
2026-08-03 18:05 ` [PATCH v9 21/22] dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells Sebastian Reichel
@ 2026-08-03 18:05 ` Sebastian Reichel
2026-08-03 19:11 ` sashiko-bot
21 siblings, 1 reply; 36+ messages in thread
From: Sebastian Reichel @ 2026-08-03 18:05 UTC (permalink / raw)
To: Sandy Huang, Heiko Stübner, Andy Yan, Maarten Lankhorst,
Maxime Ripard, Thomas Zimmermann, Andrzej Hajda, Neil Armstrong,
Robert Foss, Laurent Pinchart, Jonas Karlman, Jernej Skrabec,
Rob Herring, Krzysztof Kozlowski, Conor Dooley, David Airlie,
Simona Vetter, Dmitry Baryshkov, Luca Ceresoli, Philipp Zabel
Cc: Cristian Ciocaltea, Damon Ding, Dmitry Baryshkov, Alexey Charkov,
dri-devel, linux-rockchip, linux-kernel, devicetree, kernel,
linux-arm-kernel, Sebastian Reichel
Implement audio support for the Synopsys DesignWare DisplayPort
controller.
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 307 +++++++++++++++++++++++++++++++-
1 file changed, 306 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 5d10a60d265d..53f1863c46a0 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -24,17 +24,21 @@
#include <drm/drm_bridge.h>
#include <drm/drm_bridge_connector.h>
#include <drm/display/drm_dp_helper.h>
+#include <drm/display/drm_hdmi_audio_helper.h>
#include <drm/drm_edid.h>
#include <drm/drm_of.h>
#include <drm/drm_print.h>
#include <drm/drm_probe_helper.h>
#include <drm/drm_simple_kms_helper.h>
+#include <sound/hdmi-codec.h>
+
#define DW_DP_VERSION_NUMBER 0x0000
#define DW_DP_VERSION_TYPE 0x0004
#define DW_DP_ID 0x0008
#define DW_DP_CONFIG_REG1 0x0100
+#define AUDIO_SELECT GENMASK(2, 1)
#define DW_DP_CONFIG_REG2 0x0104
#define DW_DP_CONFIG_REG3 0x0108
@@ -111,6 +115,10 @@
#define HBR_MODE_ENABLE BIT(10)
#define AUDIO_DATA_WIDTH GENMASK(9, 5)
#define AUDIO_DATA_IN_EN GENMASK(4, 1)
+#define AUDIO_DATA_IN_EN_CHANNEL12 BIT(0)
+#define AUDIO_DATA_IN_EN_CHANNEL34 BIT(1)
+#define AUDIO_DATA_IN_EN_CHANNEL56 BIT(2)
+#define AUDIO_DATA_IN_EN_CHANNEL78 BIT(3)
#define AUDIO_INF_SELECT BIT(0)
#define DW_DP_SDP_VERTICAL_CTRL 0x0500
@@ -254,6 +262,8 @@
#define SDP_REG_BANK_SIZE 16
+#define DW_DP_SDP_VERSION 0x12
+
struct dw_dp_link_caps {
bool enhanced_framing;
bool tps3_supported;
@@ -306,6 +316,19 @@ struct dw_dp_hotplug {
bool long_hpd;
};
+enum dw_dp_audio_interface_support {
+ DW_DP_AUDIO_I2S_ONLY = 0,
+ DW_DP_AUDIO_SPDIF_ONLY = 1,
+ DW_DP_AUDIO_I2S_AND_SPDIF = 2,
+ DW_DP_AUDIO_NONE = 3,
+};
+
+enum dw_dp_audio_interface {
+ DW_DP_AUDIO_I2S = 0,
+ DW_DP_AUDIO_SPDIF = 1,
+ DW_DP_AUDIO_UNUSED,
+};
+
struct dw_dp {
struct drm_bridge bridge;
struct device *dev;
@@ -321,10 +344,18 @@ struct dw_dp {
int irq;
struct work_struct hpd_work;
struct dw_dp_hotplug hotplug;
+ enum dw_dp_audio_interface audio_interface;
+ int audio_channels;
+ int audio_channel_allocation;
+ int audio_sample_width;
+ bool audio_muted;
+ int audio_sdp_nr;
/* Serialize hpd status access */
struct mutex irq_lock;
/* Serialize sdp_reg_bank access */
struct mutex sdp_lock;
+ /* Serialize audio state */
+ struct mutex audio_lock;
struct drm_dp_aux aux;
@@ -1690,6 +1721,254 @@ static int dw_dp_link_enable(struct dw_dp *dp)
return ret;
}
+static int dw_dp_audio_infoframe_send(struct dw_dp *dp)
+{
+ struct hdmi_audio_infoframe frame;
+ struct dw_dp_sdp sdp;
+ int ret;
+
+ ret = hdmi_audio_infoframe_init(&frame);
+ if (ret < 0)
+ return ret;
+
+ frame.coding_type = HDMI_AUDIO_CODING_TYPE_STREAM;
+ frame.sample_frequency = HDMI_AUDIO_SAMPLE_FREQUENCY_STREAM;
+ frame.sample_size = HDMI_AUDIO_SAMPLE_SIZE_STREAM;
+ frame.channels = dp->audio_channels;
+ frame.channel_allocation = dp->audio_channel_allocation;
+
+ ret = hdmi_audio_infoframe_pack_for_dp(&frame, &sdp.base, DW_DP_SDP_VERSION);
+ if (ret < 0)
+ return ret;
+
+ sdp.flags = DW_DP_SDP_VERTICAL_INTERVAL;
+
+ return dw_dp_send_sdp(dp, &sdp);
+}
+
+static void __dw_dp_audio_disable(struct dw_dp *dp)
+{
+ if (dp->audio_sdp_nr >= 0) {
+ dw_dp_clear_sdp(dp, dp->audio_sdp_nr);
+ dp->audio_sdp_nr = -1;
+ }
+
+ regmap_clear_bits(dp->regmap, DW_DP_SDP_VERTICAL_CTRL,
+ EN_AUDIO_STREAM_SDP | EN_AUDIO_TIMESTAMP_SDP);
+ regmap_clear_bits(dp->regmap, DW_DP_SDP_HORIZONTAL_CTRL,
+ EN_AUDIO_STREAM_SDP);
+
+ regmap_clear_bits(dp->regmap, DW_DP_AUD_CONFIG1, AUDIO_DATA_IN_EN);
+
+ if (dp->audio_interface == DW_DP_AUDIO_SPDIF)
+ clk_disable_unprepare(dp->spdif_clk);
+ else if (dp->audio_interface == DW_DP_AUDIO_I2S)
+ clk_disable_unprepare(dp->i2s_clk);
+
+ dp->audio_interface = DW_DP_AUDIO_UNUSED;
+}
+
+static int __dw_dp_audio_enable(struct dw_dp *dp)
+{
+ u8 audio_data_in_en;
+
+ switch (dp->audio_channels) {
+ case 1:
+ case 2:
+ audio_data_in_en = AUDIO_DATA_IN_EN_CHANNEL12;
+ break;
+ case 8:
+ audio_data_in_en = AUDIO_DATA_IN_EN_CHANNEL12 |
+ AUDIO_DATA_IN_EN_CHANNEL34 |
+ AUDIO_DATA_IN_EN_CHANNEL56 |
+ AUDIO_DATA_IN_EN_CHANNEL78;
+ break;
+ default:
+ return -EINVAL;
+ }
+
+ regmap_update_bits(dp->regmap, DW_DP_AUD_CONFIG1,
+ AUDIO_DATA_IN_EN | NUM_CHANNELS | AUDIO_DATA_WIDTH |
+ AUDIO_INF_SELECT | HBR_MODE_ENABLE | AUDIO_MUTE,
+ FIELD_PREP(AUDIO_DATA_IN_EN, audio_data_in_en) |
+ FIELD_PREP(NUM_CHANNELS, dp->audio_channels - 1) |
+ FIELD_PREP(AUDIO_DATA_WIDTH, dp->audio_sample_width) |
+ FIELD_PREP(AUDIO_INF_SELECT, dp->audio_interface) |
+ FIELD_PREP(HBR_MODE_ENABLE, 0) |
+ FIELD_PREP(AUDIO_MUTE, dp->audio_muted));
+
+ /* Wait for inf switch */
+ usleep_range(20, 40);
+
+ /*
+ * Send audio stream during vertical and horizontal blanking periods.
+ * Send out audio timestamp SDP once per video frame during the vertical
+ * blanking period
+ */
+ regmap_update_bits(dp->regmap, DW_DP_SDP_VERTICAL_CTRL,
+ EN_AUDIO_STREAM_SDP | EN_AUDIO_TIMESTAMP_SDP,
+ FIELD_PREP(EN_AUDIO_STREAM_SDP, 1) |
+ FIELD_PREP(EN_AUDIO_TIMESTAMP_SDP, 1));
+ regmap_update_bits(dp->regmap, DW_DP_SDP_HORIZONTAL_CTRL,
+ EN_AUDIO_STREAM_SDP,
+ FIELD_PREP(EN_AUDIO_STREAM_SDP, 1));
+
+ if (dp->audio_sdp_nr >= 0) {
+ dw_dp_clear_sdp(dp, dp->audio_sdp_nr);
+ dp->audio_sdp_nr = -1;
+ }
+
+ dp->audio_sdp_nr = dw_dp_audio_infoframe_send(dp);
+ if (dp->audio_sdp_nr < 0)
+ return dp->audio_sdp_nr;
+
+ return 0;
+}
+
+static int dw_dp_audio_startup(struct drm_bridge *bridge,
+ struct drm_connector *connector)
+{
+ struct dw_dp *dp = bridge_to_dp(bridge);
+
+ dev_dbg(dp->dev, "audio startup\n");
+
+ return pm_runtime_get_active(dp->dev, RPM_TRANSPARENT);
+}
+
+static void dw_dp_audio_unprepare(struct drm_bridge *bridge,
+ struct drm_connector *connector)
+{
+ struct dw_dp *dp = bridge_to_dp(bridge);
+
+ guard(mutex)(&dp->audio_lock);
+
+ __dw_dp_audio_disable(dp);
+}
+
+static int dw_dp_audio_prepare(struct drm_bridge *bridge,
+ struct drm_connector *connector,
+ struct hdmi_codec_daifmt *daifmt,
+ struct hdmi_codec_params *params)
+{
+ struct dw_dp *dp = bridge_to_dp(bridge);
+ u8 supported_audio_interfaces;
+ enum dw_dp_audio_interface audio_interface;
+ u32 cfg1;
+ int ret;
+
+ guard(mutex)(&dp->audio_lock);
+
+ /*
+ * prepare might be called multiple times, so release the clocks
+ * from previous calls to keep the calls in balance.
+ */
+ if (dp->audio_interface != DW_DP_AUDIO_UNUSED)
+ __dw_dp_audio_disable(dp);
+
+ /* The hardware is limited to 1,2 or 8 channels */
+ switch (params->cea.channels) {
+ case 1:
+ case 2:
+ case 8:
+ break;
+ default:
+ dev_err(dp->dev, "invalid audio channels %d\n", params->cea.channels);
+ return -EINVAL;
+ }
+
+ if (params->sample_width < 16 || params->sample_width > 24) {
+ dev_err(dp->dev, "invalid data sample width %d\n", params->sample_width);
+ return -EINVAL;
+ }
+
+ switch (daifmt->fmt) {
+ case HDMI_SPDIF:
+ audio_interface = DW_DP_AUDIO_SPDIF;
+ break;
+ case HDMI_I2S:
+ /*
+ * It is recommended to use SPDIF instead of I2S, since I2S mode requires
+ * manually inserting PCUV control bits from userspace and this is done
+ * automatically in hardware for SPDIF mode.
+ */
+ audio_interface = DW_DP_AUDIO_I2S;
+ break;
+ default:
+ dev_err(dp->dev, "invalid DAI format %d\n", daifmt->fmt);
+ return -EINVAL;
+ }
+
+ regmap_read(dp->regmap, DW_DP_CONFIG_REG1, &cfg1);
+ supported_audio_interfaces = FIELD_GET(AUDIO_SELECT, cfg1);
+
+ if (supported_audio_interfaces != DW_DP_AUDIO_I2S_AND_SPDIF &&
+ supported_audio_interfaces != audio_interface) {
+ dev_err(dp->dev, "unsupported DAI %d\n", daifmt->fmt);
+ return -EINVAL;
+ }
+
+ ret = clk_prepare_enable(dp->spdif_clk);
+ if (ret)
+ return ret;
+
+ ret = clk_prepare_enable(dp->i2s_clk);
+ if (ret) {
+ clk_disable_unprepare(dp->spdif_clk);
+ return ret;
+ }
+
+ if (audio_interface == DW_DP_AUDIO_I2S)
+ clk_disable_unprepare(dp->spdif_clk);
+ else if (audio_interface == DW_DP_AUDIO_SPDIF)
+ clk_disable_unprepare(dp->i2s_clk);
+
+ dp->audio_channels = params->cea.channels;
+ dp->audio_channel_allocation = params->cea.channel_allocation;
+ dp->audio_sample_width = params->sample_width;
+ dp->audio_interface = audio_interface;
+
+ ret = __dw_dp_audio_enable(dp);
+ if (ret < 0) {
+ dev_err(dp->dev, "failed to enable audio\n");
+ __dw_dp_audio_disable(dp);
+ return ret;
+ }
+
+ dev_dbg(dp->dev, "audio prepare with %d channels using DAI=%d\n",
+ dp->audio_channels, dp->audio_interface);
+
+ return 0;
+}
+
+static void dw_dp_audio_shutdown(struct drm_bridge *bridge,
+ struct drm_connector *connector)
+{
+ struct dw_dp *dp = bridge_to_dp(bridge);
+
+ dev_dbg(dp->dev, "audio shutdown\n");
+
+ dw_dp_audio_unprepare(bridge, connector);
+ pm_runtime_put_autosuspend(dp->dev);
+}
+
+static int dw_dp_audio_mute_stream(struct drm_bridge *bridge,
+ struct drm_connector *connector,
+ bool enable, int direction)
+{
+ struct dw_dp *dp = bridge_to_dp(bridge);
+
+ dev_dbg(dp->dev, "audio %smute\n", enable ? "" : "un");
+
+ guard(mutex)(&dp->audio_lock);
+
+ dp->audio_muted = enable;
+
+ regmap_update_bits(dp->regmap, DW_DP_AUD_CONFIG1, AUDIO_MUTE,
+ FIELD_PREP(AUDIO_MUTE, enable));
+
+ return 0;
+}
+
static void dw_dp_bridge_atomic_enable(struct drm_bridge *bridge,
struct drm_atomic_commit *state)
{
@@ -1728,6 +2007,14 @@ static void dw_dp_bridge_atomic_enable(struct drm_bridge *bridge,
dev_err(dp->dev, "failed to enable video: %d\n", ret);
return;
}
+
+ scoped_guard(mutex, &dp->audio_lock) {
+ if (dp->audio_interface != DW_DP_AUDIO_UNUSED) {
+ ret = __dw_dp_audio_enable(dp);
+ if (ret < 0)
+ dev_err(dp->dev, "failed to restore audio: %d\n", ret);
+ }
+ }
}
static void dw_dp_reset(struct dw_dp *dp)
@@ -1973,6 +2260,11 @@ static const struct drm_bridge_funcs dw_dp_bridge_funcs = {
.detect = dw_dp_bridge_detect,
.edid_read = dw_dp_bridge_edid_read,
.oob_notify = dw_dp_bridge_oob_notify,
+
+ .dp_audio_startup = dw_dp_audio_startup,
+ .dp_audio_prepare = dw_dp_audio_prepare,
+ .dp_audio_shutdown = dw_dp_audio_shutdown,
+ .dp_audio_mute_stream = dw_dp_audio_mute_stream,
};
static int dw_dp_link_retrain(struct dw_dp *dp)
@@ -2271,6 +2563,10 @@ int dw_dp_probe(struct dw_dp *dp)
if (ret)
return ret;
+ ret = devm_mutex_init(dev, &dp->audio_lock);
+ if (ret)
+ return ret;
+
res = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(res))
return PTR_ERR(res);
@@ -2354,12 +2650,21 @@ int dw_dp_probe(struct dw_dp *dp)
return ret;
dp->vsc_sdp_nr = -1;
+ dp->audio_interface = DW_DP_AUDIO_UNUSED;
+ dp->audio_sdp_nr = -1;
bridge = &dp->bridge;
bridge->of_node = dev->of_node;
- bridge->ops = DRM_BRIDGE_OP_DETECT | DRM_BRIDGE_OP_EDID | DRM_BRIDGE_OP_HPD;
+ bridge->ops = DRM_BRIDGE_OP_DP_AUDIO |
+ DRM_BRIDGE_OP_DETECT |
+ DRM_BRIDGE_OP_EDID |
+ DRM_BRIDGE_OP_HPD;
bridge->type = DRM_MODE_CONNECTOR_DisplayPort;
bridge->ycbcr_420_allowed = true;
+ bridge->hdmi_audio_dev = dev;
+ bridge->hdmi_audio_max_i2s_playback_channels = 8;
+ bridge->hdmi_audio_dai_port = 1;
+ bridge->hdmi_audio_spdif_playback = true;
ret = devm_drm_bridge_add(dev, bridge);
if (ret)
--
2.53.0
^ permalink raw reply related [flat|nested] 36+ messages in thread
* Re: [PATCH v9 03/22] drm/bridge: synopsys: dw-dp: Fix error handling in dw_dp_link_enable()
2026-08-03 18:05 ` [PATCH v9 03/22] drm/bridge: synopsys: dw-dp: Fix error handling in dw_dp_link_enable() Sebastian Reichel
@ 2026-08-03 18:25 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 18:25 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: devicetree, dri-devel, conor+dt, robh
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [High] The patch introduces a double-free bug by adding error path cleanups (`phy_power_off()` and `drm_dp_link_power_down()`) in `dw_dp_link_enable()`. Because `atomic_enable` returns `void` and cannot abort a commit, the DRM core unconditionally invokes `atomic_disable` later, executing a second cleanup.
Pre-existing issues:
- [High] A preexisting bug where `phy_power_off()` is called on atomic disable even if `phy_power_on()` failed in `dw_dp_link_enable()`, corrupting the PHY power state and regulator counts.
--
--- Patch [3]: [PATCH v9 03/22] drm/bridge: synopsys: dw-dp: Fix error handling in dw_dp_link_enable() ---
commit 37d17812be83d5554aca9b8d15486591d59db100
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/bridge: synopsys: dw-dp: Fix error handling in dw_dp_link_enable()
This commit adds missing error handling in dw_dp_link_enable(), which
failed to release resources it already requested before hitting an error.
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> index 06997208945ed..e332d66b80571 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> @@ -1636,10 +1636,19 @@ static int dw_dp_link_enable(struct dw_dp *dp)
>
[Severity: High]
This is a pre-existing issue, but does the same unbalanced power state
happen if phy_power_on() fails?
Looking at dw_dp_link_enable(), which executes just before this hunk:
ret = phy_power_on(dp->phy);
if (ret)
return ret;
If phy_power_on() fails, we return early. However, because atomic_enable()
returns void and cannot abort a commit, the DRM core will still
unconditionally call dw_dp_link_disable() later:
dw_dp_link_disable() {
...
phy_power_off(dp->phy);
}
Will this unconditional cleanup drop the phy power count to -1, permanently
breaking subsequent power on attempts because the next phy_power_on()
will only increment the count to 0 and skip hardware initialization?
> ret = drm_dp_link_power_up(&dp->aux, dp->link.revision);
> if (ret < 0)
> - return ret;
> + goto err_phy_power_off;
>
> ret = dw_dp_link_train(dp);
> + if (ret < 0)
> + goto err_link_power_down;
> +
> + return 0;
> +
> +err_link_power_down:
> + drm_dp_link_power_down(&dp->aux, dp->link.revision);
>
> +err_phy_power_off:
> + phy_power_off(dp->phy);
[Severity: High]
Will this explicit rollback result in phy_power_off() being called twice?
Since the DRM core will unconditionally invoke atomic_disable() later
when the commit fails, dw_dp_link_disable() will execute and perform
its own cleanup:
dw_dp_link_disable() {
...
if (dw_dp_hpd_detect(dp))
drm_dp_link_power_down(&dp->aux, dp->link.revision);
...
phy_power_off(dp->phy);
}
Doing the cleanup here in the error path means these functions will be
called a second time.
Can this double cleanup cause the phy power count to drop to -1, resulting
in the same permanent breakage of the display pipeline described above?
> return ret;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=3
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 06/22] drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal
2026-08-03 18:05 ` [PATCH v9 06/22] drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal Sebastian Reichel
@ 2026-08-03 18:27 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 18:27 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: dri-devel, robh, conor+dt, devicetree
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
Pre-existing issues:
- [High] Missing Completion Reinitialization causes permanent link training desynchronization on timeouts.
- [High] Concurrent hardware modification between the HPD worker and non-blocking atomic commits leads to hardware state corruption.
- [Medium] Hotplug events can be lost due to overwriting the single boolean tracking variable `dp->hotplug.long_hpd` before the worker processes it.
--
--- Patch [6]: [PATCH v9 06/22] drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal ---
commit d8b2520d774bd92589d70544eca3e846bc879920
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal
The driver is currently missing to fully clean up after itself. Ensure
that the mutex is cleaned up.
Reported-by: Sashiko <sashiko-bot@kernel.org>
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> index facd1c4799923..af3fa7886429b 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> @@ -2039,9 +2039,12 @@ struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_
> dp->pixel_mode = plat_data->pixel_mode;
> dp->plat_data.max_link_rate = plat_data->max_link_rate;
>
> - mutex_init(&dp->irq_lock);
> init_completion(&dp->complete);
[Severity: High]
This isn't a bug introduced by this patch, but while looking at the
completion initialization, I noticed a potential regression.
If dw_dp_aux_transfer() times out and returns -ETIMEDOUT, and a delayed
hardware reply or spurious IRQ later completes the completion:
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_aux_transfer() {
...
regmap_write(dp->regmap, DW_DP_AUX_CMD, value);
status = wait_for_completion_timeout(&dp->complete, timeout);
...
}
Would a subsequent call to dw_dp_aux_transfer() immediately consume the stale
completion since reinit_completion() is not called before the transfer?
Could this lead to garbage DPCD reads and permanent link training failure?
>
> + ret = devm_mutex_init(dev, &dp->irq_lock);
> + if (ret)
> + return ERR_PTR(ret);
> +
> res = devm_platform_ioremap_resource(pdev, 0);
> if (IS_ERR(res))
> return ERR_CAST(res);
[Severity: Medium]
This is a pre-existing issue, but could hotplug events be lost if a short
pulse overwrites the state before the worker processes it?
If a monitor is plugged in and asserts a long HPD pulse, and a short HPD
pulse occurs before the worker executes:
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_handle_hpd_event() {
...
if (value & HPD_IRQ) {
dev_dbg(dp->dev, "IRQ from the HPD\n");
dp->hotplug.long_hpd = false;
regmap_write(dp->regmap, DW_DP_HPD_STATUS, HPD_IRQ);
}
...
}
Does this overwrite the boolean flag, causing the worker to branch incorrectly
and skip the hotplug notification?
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_hpd_work() {
...
if (!long_hpd) {
if (dw_dp_needs_link_retrain(dp)) {
ret = dw_dp_link_retrain(dp);
...
}
[Severity: High]
This is a pre-existing issue, but I am wondering if there is a concurrent
hardware modification regression between the HPD worker and non-blocking
atomic commits.
The worker relies on connection_mutex, which DRM does not hold during
asynchronous atomic hardware commits:
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_link_retrain() {
...
for (;;) {
ret = drm_modeset_lock(&dev->mode_config.connection_mutex, &ctx);
if (ret != -EDEADLK)
break;
drm_modeset_backoff(&ctx);
}
...
}
Concurrently, dw_dp_bridge_atomic_enable() executes in the commit worker
without connection_mutex:
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_bridge_atomic_enable() {
...
ret = dw_dp_link_enable(dp);
if (ret < 0) {
...
}
Could both paths attempt to modify PHY and DPCD registers simultaneously,
leading to hardware corruption or link training failures?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=6
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 02/22] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback
2026-08-03 18:05 ` [PATCH v9 02/22] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback Sebastian Reichel
@ 2026-08-03 18:27 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 18:27 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: robh, dri-devel, devicetree, conor+dt
Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:
Pre-existing issues:
- [High] Missing `cancel_work_sync(&dp->hpd_work)` causes a use-after-free of `dp` on driver removal.
- [High] Lockless TOCTOU check of `dp->bridge.dev` in `dw_dp_hpd_work` causes Use-After-Free or NULL pointer dereference on unbind.
- [High] Unhandled interrupt sources in `dw_dp_irq()` can lead to an interrupt storm.
- [High] Sleeping functions are called from an atomic context path (`atomic_disable`).
--
--- Patch [2]: [PATCH v9 02/22] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback ---
commit 639a2b7137e1fc5209a35b30731a14a632ba6684
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
Subject: drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback
Currently the Synopsys DesignWare DP controller driver's bind function
requests lots of resources using device managed functions. These are
free'd on driver removal instead of at unbind time. Fix this discrepancy
by introducing a new probe helper function and moving over the whole
bind function. This results in a fully functional DRM bridge once probe
succeeded.
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> index 112a499113095..06997208945ed 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> @@ -1895,6 +1895,9 @@ static void dw_dp_hpd_work(struct work_struct *work)
> long_hpd = dp->hotplug.long_hpd;
> mutex_unlock(&dp->irq_lock);
>
> + if (!dp->bridge.dev)
> + return;
> +
[Severity: High]
This is a pre-existing issue, but does this lockless check create a race
condition?
If drm_bridge_detach() executes concurrently and clears bridge->dev, can
this work function still proceed and pass a NULL or freed drm_device pointer
to drm_helper_hpd_irq_event()?
> dev_dbg(dp->dev, "[drm] Get hpd irq - %s\n", long_hpd ? "long" : "short");
>
> if (!long_hpd) {
[ ... ]
> @@ -2005,9 +2027,8 @@ struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
>
> dp->dev = dev;
> dp->pixel_mode = plat_data->pixel_mode;
> -
> dp->plat_data.max_link_rate = plat_data->max_link_rate;
> - bridge = &dp->bridge;
> +
> mutex_init(&dp->irq_lock);
> INIT_WORK(&dp->hpd_work, dw_dp_hpd_work);
[Severity: High]
This is a pre-existing issue, but does this workqueue lack a cleanup step?
Since dp->hpd_work is initialized here but doesn't have a corresponding
devm action to cancel it on teardown, could a pending work item execute
after the dp structure is freed during driver unbind, resulting in a
use-after-free?
[ ... ]
[Severity: High]
This is a pre-existing issue, but can unhandled interrupt sources cause an
interrupt storm?
Looking at dw_dp_irq():
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_irq() {
...
if (value & HPD_EVENT)
dw_dp_handle_hpd_event(dp);
if (value & AUX_REPLY_EVENT) {
regmap_write(dp->regmap, DW_DP_GENERAL_INTERRUPT, AUX_REPLY_EVENT);
complete(&dp->complete);
}
return IRQ_HANDLED;
}
If an interrupt source other than HPD_EVENT or AUX_REPLY_EVENT fires (such
as HDCP_EVENT), the handler returns IRQ_HANDLED without clearing the event
in DW_DP_GENERAL_INTERRUPT. Will this keep the IRQ line asserted and
continuously re-enter the handler?
[Severity: High]
This is a pre-existing issue, but are sleeping functions being called from
atomic context?
The DRM documentation indicates that atomic disable callbacks run in atomic
context during non-blocking commits.
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_bridge_atomic_disable() {
...
dw_dp_reset(dp);
}
And dw_dp_reset() unconditionally calls sleeping functions:
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_reset() {
...
disable_irq(dp->irq);
...
usleep_range(10, 20);
...
regmap_read_poll_timeout(...);
}
Could this lead to kernel warnings or system instability when non-blocking
atomic commits occur?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=2
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 09/22] drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid
2026-08-03 18:05 ` [PATCH v9 09/22] drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid Sebastian Reichel
@ 2026-08-03 18:35 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 18:35 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: conor+dt, dri-devel, robh, devicetree
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] The DRM core's bridge bus format negotiation protocol contains a memory leak when a driver returns an allocated format array but 0 valid formats. This problem wasn't introduced by this patch, but this patch adds a driver-local workaround instead of fixing the core API.
--
--- Patch [9]: [PATCH v9 09/22] drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid ---
commit 91ba4a99e0fef78bbe1a7632011fef0a483a9e57
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid
This commit modifies dw_dp_bridge_atomic_get_output_bus_fmts() to free
the allocated output_fmts array if the number of valid formats is 0,
avoiding a memory leak.
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> index 22a244de08aa1..bde938b0d116d 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> @@ -1813,6 +1813,11 @@ static u32 *dw_dp_bridge_atomic_get_output_bus_fmts(struct drm_bridge *bridge,
> output_fmts[j++] = fmt->bus_format;
> }
>
> + if (j == 0) {
> + kfree(output_fmts);
> + output_fmts = NULL;
> + }
> +
[Severity: High]
This isn't a bug introduced by this patch, but should this memory leak be
fixed in the DRM core instead of adding a driver-local workaround?
Looking at the DRM core's bridge bus format negotiation protocol in
drivers/gpu/drm/drm_bridge.c, the core leaks the array when a driver returns
an allocated format array but 0 valid formats:
drivers/gpu/drm/drm_bridge.c:drm_atomic_bridge_chain_select_bus_fmts() {
...
out_bus_fmts = funcs->atomic_get_output_bus_fmts(last_bridge,
last_bridge_state,
crtc_state,
conn_state,
&num_out_bus_fmts);
if (!num_out_bus_fmts)
return -ENOTSUPP;
...
}
The core returns an error immediately without calling kfree(out_bus_fmts),
silently leaking the dynamically allocated array.
The same issue appears in select_bus_fmt_recursive() for
atomic_get_input_bus_fmts:
drivers/gpu/drm/drm_bridge.c:select_bus_fmt_recursive() {
...
in_bus_fmts = cur_bridge->funcs->atomic_get_input_bus_fmts(cur_bridge,
cur_state,
crtc_state,
conn_state,
out_bus_fmt,
&num_in_bus_fmts);
if (!num_in_bus_fmts)
return -ENOTSUPP;
...
}
Would it be better to fix the core API to handle freeing the array when
num_out_bus_fmts or num_in_bus_fmts is 0, rather than patching each
individual bridge driver?
> *num_output_fmts = j;
>
> return output_fmts;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=9
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 01/22] drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach
2026-08-03 18:05 ` [PATCH v9 01/22] drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach Sebastian Reichel
@ 2026-08-03 18:35 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 18:35 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: dri-devel, devicetree, robh, conor+dt
Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:
New issues:
- [High] Moving `drm_dp_aux_unregister()` to the bridge `detach` callback defers it to the DRM device lifecycle, causing a Use-After-Free when the physical device is unbound.
Pre-existing issues:
- [High] Missing `reinit_completion()` before starting an AUX transfer can cause subsequent transfers to falsely complete after a timeout.
- [High] Using `devm_*` allocations in the component bind callback causes resource leaks and prevents successful rebinding.
- [High] The driver schedules `hpd_work` but never cancels it during unbind or device removal, leading to a Use-After-Free.
--
--- Patch [1]: [PATCH v9 01/22] drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach ---
commit cf33bafacfb642286c8ee7eb20855f566f32f630
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
Subject: drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach
This commit moves the registration and unregistration of the DP AUX device
from the bind/unbind phases to the bridge attach/detach phases. This ensures
that the AUX device is only accessed when the DRM device is ready.
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> @@ -1813,7 +1813,36 @@ static struct drm_bridge_state *dw_dp_bridge_atomic_duplicate_state(struct drm_b
> return &state->base;
> }
>
> +static int dw_dp_bridge_attach(struct drm_bridge *bridge,
> + struct drm_encoder *encoder,
> + enum drm_bridge_attach_flags flags)
> +{
> + struct dw_dp *dp = bridge_to_dp(bridge);
> + struct device *dev = dp->dev;
> + int ret;
> +
> + dp->aux.dev = dev;
> + dp->aux.drm_dev = encoder->dev;
> + dp->aux.name = dev_name(dev);
> + dp->aux.transfer = dw_dp_aux_transfer;
[Severity: High]
This is a pre-existing issue, but does dw_dp_aux_transfer() incorrectly
handle completions?
Looking at dw_dp_aux_transfer(), the code waits for a completion without
clearing any previously pending completion state:
status = wait_for_completion_timeout(&dp->complete, timeout);
If a previous hardware timeout occurred (returning 0), and the hardware later
finishes the transfer, the interrupt handler will call complete(&dp->complete).
Because reinit_completion() is not called before the next transfer, the
subsequent wait_for_completion_timeout() could instantly consume the leftover
completion and return true without waiting, reading stale or invalid status
from the hardware.
> +
> + ret = drm_dp_aux_register(&dp->aux);
> + if (ret)
> + dev_err(dev, "Aux register failed: %d\n", ret);
> +
> + return ret;
> +}
> +
> +static void dw_dp_bridge_detach(struct drm_bridge *bridge)
> +{
> + struct dw_dp *dp = bridge_to_dp(bridge);
> +
> + drm_dp_aux_unregister(&dp->aux);
> +}
[Severity: High]
Could deferring drm_dp_aux_unregister() to the DRM device lifecycle lead to a
use-after-free when the physical device is unbound?
If a userspace process keeps the DRM device FD open, the DRM device remains
active even after the DW-DP physical device is unbound via sysfs. This triggers
devres to run for the unbound physical device, freeing dp->regmap and disabling
clocks.
Because drm_dp_aux_unregister() was moved to dw_dp_bridge_detach(), the AUX
device remains registered. If a userspace process initiates an I2C/AUX transfer
on the still-registered device node, it will call dw_dp_aux_transfer() which
dereferences the freed dp->regmap.
[ ... ]
> @@ -2065,37 +2084,33 @@ struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
[ ... ]
> ret = devm_request_threaded_irq(dev, dp->irq, NULL, dw_dp_irq,
> IRQF_ONESHOT, dev_name(dev), dp);
[Severity: High]
This is a pre-existing issue, but does using devm_request_threaded_irq() in the
component bind callback cause resource leaks and prevent successful rebinding?
Component bind callbacks run when the master DRM device is bound. If the DRM
master is unbound, dw_dp_unbind() is called, but devres does not run because
the component platform device itself wasn't removed.
When the DRM master is bound again, dw_dp_bind() will run and attempt to
request the same exclusive IRQ, which may fail with -EBUSY and leak the prior
allocations, preventing the display pipeline from functioning.
> if (ret) {
> dev_err_probe(dev, ret, "failed to request irq\n");
> - goto unregister_aux;
> + return ERR_PTR(ret);
> }
>
> return dp;
> -
> -unregister_aux:
> - drm_dp_aux_unregister(&dp->aux);
> - return ERR_PTR(ret);
> }
> EXPORT_SYMBOL_GPL(dw_dp_bind);
>
> void dw_dp_unbind(struct dw_dp *dp)
> {
> - drm_dp_aux_unregister(&dp->aux);
> + /* nothing to do */
> }
[Severity: High]
This is a pre-existing issue, but does dw_dp_unbind() need to call
cancel_work_sync(&dp->hpd_work) before the component is unbound?
The interrupt handler schedules dp->hpd_work. If an HPD interrupt fires right
before the IRQ is disabled by devres or during component unbind, the work is
queued.
When devres frees dp->regmap, and dw_dp_hpd_work() eventually executes, it
calls dw_dp_hpd_detect() which accesses the freed dp->regmap, resulting in a
use-after-free.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=1
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 04/22] drm/bridge: synopsys: dw-dp: Cancel pending HPD work
2026-08-03 18:05 ` [PATCH v9 04/22] drm/bridge: synopsys: dw-dp: Cancel pending HPD work Sebastian Reichel
@ 2026-08-03 18:35 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 18:35 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: devicetree, conor+dt, robh, dri-devel
Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:
Pre-existing issues:
- [High] The patch uses `devm_work_autocancel()` to stop the HPD worker, but relies on devres cleanup which executes during device removal rather than component unbind, leaving a TOCTOU race window where the worker can access freed memory.
- [High] Bridge registration occurs before probe completion, leading to potential Use-After-Free if a subsequent probe step fails.
- [High] Sleeping delay and polling functions are called from atomic context in `dw_dp_bridge_atomic_disable()`.
- [Medium] Unbounded loop in `dw_dp_link_clock_recovery` can cause a kernel thread hang.
--
--- Patch [4]: [PATCH v9 04/22] drm/bridge: synopsys: dw-dp: Cancel pending HPD work ---
commit c38b05d3219e4122c1777f880ab0fd447f213375
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/bridge: synopsys: dw-dp: Cancel pending HPD work
There is a race condition during device removal: If the HPD interrupt
started an HPD worker exactly when the device is removed, the worker
thread might access invalid resources. Avoid this by stopping any
pending work immediately after disabling the interrupt.
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> index e332d66b80571..278953a8549a2 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
[ ... ]
> @@ -2120,6 +2120,10 @@ struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_
> if (dp->irq < 0)
> return ERR_PTR(dp->irq);
>
[Severity: High]
This is a pre-existing issue, but can this error path lead to a
use-after-free?
Just before this block in dw_dp_probe(), the bridge is registered globally:
ret = devm_drm_bridge_add(dev, bridge);
if (ret)
return ERR_PTR(ret);
If a subsequent step like devm_work_autocancel() or
devm_request_threaded_irq() fails, the probe aborts and devres cleans up
the allocated memory. If another driver discovers and references the bridge
between registration and this failure, will it dereference freed memory?
> + ret = devm_work_autocancel(dev, &dp->hpd_work, dw_dp_hpd_work);
> + if (ret)
> + return ERR_PTR(ret);
> +
[Severity: High]
This isn't a bug introduced by this patch, but does this fix fully resolve
the race condition during component unbind?
The patch uses devm_work_autocancel() to stop the HPD worker during device
removal (devres cleanup). However, dw_dp_unbind() is currently empty and
does not disable the IRQ or cancel the work:
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_unbind() {
/* nothing to do */
}
If the component master unbinds, it initiates the destruction of the DRM
device while the worker might still be scheduled. The worker locklessly reads
dp->bridge.dev:
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_hpd_work() {
...
if (!dp->bridge.dev)
return;
...
}
This creates a time-of-check to time-of-use race with drm_bridge_detach(),
which clears the device pointer. Could this lead to a use-after-free when
the worker proceeds to use the freed DRM device in dw_dp_link_retrain()?
> ret = devm_request_threaded_irq(dev, dp->irq, NULL, dw_dp_irq,
> IRQF_ONESHOT, dev_name(dev), dp);
> if (ret) {
While reviewing this file, I noticed a couple of other pre-existing issues
that might need attention:
[Severity: Medium]
This is a pre-existing issue, but I noticed a potential unbounded loop
in dw_dp_link_clock_recovery():
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_link_clock_recovery() {
...
for (;;) {
...
adj_changed = dw_dp_link_get_adjustments(link, status);
if (!adj_changed)
tries++;
else
tries = 0;
if (tries == 5)
break;
}
}
If a non-compliant or malicious DP sink continually alternates its
adjustment requests, dw_dp_link_get_adjustments() will continuously
return true. Since tries is repeatedly reset to 0, does this prevent
the loop from ever exiting and cause a kernel thread hang?
[Severity: High]
This isn't a bug introduced by this patch, but does the bridge disable
sequence sleep in atomic context?
During a DRM atomic commit, drm_atomic_helper_commit_tail() runs in an
atomic context. It disables bridges, calling dw_dp_bridge_atomic_disable(),
which calls dw_dp_reset() unconditionally:
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_bridge_atomic_disable() {
...
dw_dp_reset(dp);
pm_runtime_put_autosuspend(dp->dev);
}
Inside dw_dp_reset(), the code calls sleeping functions:
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_reset() {
...
usleep_range(10, 20);
...
regmap_read_poll_timeout(dp->regmap, DW_DP_HPD_STATUS, val,
FIELD_GET(HPD_HOT_PLUG, val), 200, 200000);
}
Can this violation of kernel locking rules lead to warnings and potential
deadlocks during an atomic mode-set or display disable sequence?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=4
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 10/22] drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED
2026-08-03 18:05 ` [PATCH v9 10/22] drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED Sebastian Reichel
@ 2026-08-03 18:43 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 18:43 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: robh, conor+dt, dri-devel, devicetree
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] dw_dp_bridge_atomic_get_input_bus_fmts blindly propagates unsupported formats, breaking bus format negotiation fallback.
--
--- Patch [10]: [PATCH v9 10/22] drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED ---
commit 536f8f5a7df863a273e0062b67fbc6ca7b57d8a8
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED
Add support for MEDIA_BUS_FMT_FIXED, which is requested for USB-C DP
chains when the last bridge does not implement atomic_get_output_bus_fmts().
This resolves the output format by using the negotiated input format in
atomic_check and implements a custom atomic_get_input_bus_fmts hook.
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> index bde938b0d116d..e60dab0d3b9dd 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
[ ... ]
> @@ -1823,6 +1827,32 @@ static u32 *dw_dp_bridge_atomic_get_output_bus_fmts(struct drm_bridge *bridge,
> return output_fmts;
> }
>
> +static u32 *
> +dw_dp_bridge_atomic_get_input_bus_fmts(struct drm_bridge *bridge,
> + struct drm_bridge_state *bridge_state,
> + struct drm_crtc_state *crtc_state,
> + struct drm_connector_state *conn_state,
> + u32 output_fmt,
> + unsigned int *num_input_fmts)
> +{
> + /*
> + * MEDIA_BUS_FMT_FIXED means the downstream bridge does not constrain
> + * the bus format. In that case, advertise all formats supported by the
> + * DP link so the upstream encoder can negotiate the best match.
> + */
> + if (output_fmt == MEDIA_BUS_FMT_FIXED)
> + return dw_dp_bridge_atomic_get_output_bus_fmts(bridge,
> + bridge_state,
> + crtc_state,
> + conn_state,
> + num_input_fmts);
> +
> + return drm_atomic_helper_bridge_propagate_bus_fmt(bridge, bridge_state,
> + crtc_state, conn_state,
> + output_fmt,
> + num_input_fmts);
> +}
[Severity: High]
This is a pre-existing issue, but since we are adding a custom
dw_dp_bridge_atomic_get_input_bus_fmts() hook here, does this code blindly
propagate downstream formats even if they aren't supported by the dw-dp
hardware?
If a downstream bridge proposes an unsupported preferred bus format,
propagating it directly via drm_atomic_helper_bridge_propagate_bus_fmt() makes
the format negotiation succeed prematurely. It seems this would skip testing
any valid fallback formats.
Later during the modeset, this results in a complete failure (a black screen)
when dw_dp_bridge_atomic_check() checks if the negotiated format is actually
supported:
dw_dp_bridge_atomic_check() {
...
fmt = dw_dp_get_output_format(out_bus_format);
if (!fmt)
return -EINVAL;
}
Should this new hook check if output_fmt is supported by dw-dp (e.g., verifying
it exists in dw_dp_output_formats) before propagating it, to allow the bridge
chain to properly negotiate a fallback format?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=10
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 14/22] drm/rockchip: dw_dp: Implement out-of-band HPD handling
2026-08-03 18:05 ` [PATCH v9 14/22] drm/rockchip: dw_dp: Implement out-of-band HPD handling Sebastian Reichel
@ 2026-08-03 18:46 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 18:46 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: devicetree, conor+dt, robh, dri-devel
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] Unpowered Register Access (SError) in OOB HPD callbacks.
- [Medium] Unreachable fallback logic in `dw_dp_rockchip_get_vo_grf`.
- [Medium] Physical IO address truncation due to `u32` typing in `ctrl_ids`.
--
--- Patch [14]: [PATCH v9 14/22] drm/rockchip: dw_dp: Implement out-of-band HPD handling ---
commit 48b6797379434de3ea2e6ba62d355e782a42ada0
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/rockchip: dw_dp: Implement out-of-band HPD handling
This patch implements out-of-band hotplug handling to receive external
hotplug information from the USB-C state machine via the vo_grf regmap.
It aims to avoid SError problems when runtime PM is enabled.
> diff --git a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
> index 005938dc66c9f..d516b3910b516 100644
> --- a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
> +++ b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
[ ... ]
> @@ -23,12 +26,48 @@
>
> #include "rockchip_drm_drv.h"
>
> +#define ROCKCHIP_MAX_CTRLS 2
> +
> +#define ROCKCHIP_VO_GRF_DP_SINK_HPD_SEL BIT(10)
> +#define ROCKCHIP_VO_GRF_DP_SINK_HPD_CFG BIT(11)
> +
> +struct rockchip_dw_dp_plat_data {
> + u8 num_ctrls;
> + u32 ctrl_ids[ROCKCHIP_MAX_CTRLS];
[Severity: Medium]
Will this truncate physical IO addresses on 64-bit architectures?
The ctrl_ids array stores base IO addresses using u32, but in
dw_dp_rockchip_probe() this is compared against the 64-bit
resource_size_t res->start:
if (res->start == plat_data_const->ctrl_ids[id]) {
If a future variant maps the DP controller above the 4GB boundary,
the upper 32 bits of the address will be lost, causing the hardware
controller ID lookup to fail.
> + u32 max_link_rate;
> + u8 pixel_mode;
> + u32 hpd_reg[ROCKCHIP_MAX_CTRLS];
> +};
> +
> struct rockchip_dw_dp {
> struct dw_dp *base;
> struct device *dev;
> + const struct rockchip_dw_dp_plat_data *pdata;
> + struct regmap *vo_grf;
> struct rockchip_encoder *encoder;
> + int id;
> };
>
> +static void dw_dp_rockchip_hpd_sw_sel(void *data, bool force_hpd_from_sw)
> +{
> + struct rockchip_dw_dp *dp = data;
> + u32 hpd_reg = dp->pdata->hpd_reg[dp->id];
> +
> + regmap_write(dp->vo_grf, hpd_reg,
> + FIELD_PREP_WM16(ROCKCHIP_VO_GRF_DP_SINK_HPD_SEL, force_hpd_from_sw));
[Severity: High]
Does this code risk triggering an SError by accessing unpowered registers?
The commit message states that accessing the vo_grf register requires the DP
controller power domain to be active. Since this function is called during
initialization and the driver enables runtime PM with autosuspend, the write
might execute against an unpowered register domain. Should this acquire a PM
runtime reference via pm_runtime_get_sync(dp->dev) first?
> +}
> +
> +static void dw_dp_rockchip_hpd_sw_cfg(void *data, bool hpd)
> +{
> + struct rockchip_dw_dp *dp = data;
> + u32 hpd_reg = dp->pdata->hpd_reg[dp->id];
> +
> + dev_dbg(dp->dev, "Force HPD connected=%s\n", str_yes_no(hpd));
> +
> + regmap_write(dp->vo_grf, hpd_reg,
> + FIELD_PREP_WM16(ROCKCHIP_VO_GRF_DP_SINK_HPD_CFG, hpd));
[Severity: High]
Similarly, because this out-of-band hotplug notification is triggered
asynchronously by the Type-C controller, could the DP controller be suspended
when this executes? This seems to risk triggering the exact SError the patch
intended to fix if a wake up isn't performed before the regmap write.
> +}
> +
[ ... ]
> @@ -71,6 +110,35 @@ static const struct drm_encoder_helper_funcs dw_dp_encoder_helper_funcs = {
> .atomic_check = dw_dp_encoder_atomic_check,
> };
>
> +static struct regmap *dw_dp_rockchip_get_vo_grf(struct rockchip_dw_dp *dp)
> +{
> + struct device_node *np = dev_of_node(dp->dev);
> + struct of_phandle_args args;
> + struct regmap *regmap;
> + int ret;
> +
> + ret = of_parse_phandle_with_args(np, "phys", "#phy-cells", 0, &args);
> + if (ret)
> + return ERR_PTR(-ENODEV);
> +
> + /*
> + * Limit this workaround to RK3576 and RK3588, potential future platforms
> + * reusing the driver should just add a VO GRF phandle in the DisplayPort
> + * controller DT node.
> + */
> + if (!of_device_is_compatible(args.np, "rockchip,rk3576-usbdp-phy") &&
> + !of_device_is_compatible(args.np, "rockchip,rk3588-usbdp-phy")) {
> + regmap = ERR_PTR(-ENODEV);
> + goto out_put_node;
> + }
[Severity: Medium]
Will this unconditionally fail for future platforms instead of attempting
the fallback mechanism?
The comment above states that future platforms should add a VO GRF phandle
in the DP controller DT node. However, this logic explicitly returns -ENODEV
if the phy isn't one of the hardcoded compatible strings, without ever parsing
the rockchip,vo-grf phandle from the DisplayPort node.
> +
> + regmap = syscon_regmap_lookup_by_phandle(args.np, "rockchip,vo-grf");
> +
> +out_put_node:
> + of_node_put(args.np);
> + return regmap;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=14
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 15/22] drm/bridge: synopsys: dw-dp: Add Runtime PM support
2026-08-03 18:05 ` [PATCH v9 15/22] drm/bridge: synopsys: dw-dp: Add Runtime PM support Sebastian Reichel
@ 2026-08-03 18:55 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 18:55 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: dri-devel, robh, conor+dt, devicetree
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
New issues:
- [High] Asynchronous runtime PM puts are used during device teardown, racing with pm_runtime_disable() and leaving the device explicitly powered on.
- [High] Sleeping functions are invoked synchronously from an atomic context during bridge atomic enable.
Pre-existing issues:
- [High] Unbalanced resource handling (double-free of phy power and underflow) during failed atomic enable.
--
--- Patch [15]: [PATCH v9 15/22] drm/bridge: synopsys: dw-dp: Add Runtime PM support ---
commit 2b85362372523d505a6d2f6be68c1219a8790052
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/bridge: synopsys: dw-dp: Add Runtime PM support
Add runtime PM stubs to the Synopsys DesignWare DisplayPort bridge
driver. Support is not enabled automatically and must be hooked up
in the platform specific glue code.
The early bits of the dw_dp_probe function are split into a new
function called dw_dp_alloc, so that the platform driver can assign
it before running dw_dp_probe. This is necessary because the runtime
PM resume/suspend events land at the platform driver and must be
forwarded to the helper once runtime PM is enabled in the middle
of the probe function.
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> index 7b8a9855ceae0..501b28abeca24 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
[ ... ]
> @@ -1675,6 +1683,13 @@ static void dw_dp_bridge_atomic_enable(struct drm_bridge *bridge,
> struct drm_connector_state *conn_state;
> int ret;
>
> + ret = pm_runtime_get_active(dp->dev, RPM_TRANSPARENT);
> + if (ret) {
> + dev_err(dp->dev, "runtime PM failure\n");
> + return;
> + }
> + dp->pm_active = true;
> +
[Severity: High]
Does this synchronous runtime PM resume call sleep while in an atomic context?
The DRM core invokes dw_dp_bridge_atomic_enable() during atomic commits, which
runs in an atomic context for non-blocking commits.
If the device is suspended, pm_runtime_get_active() can synchronously execute
dw_dp_runtime_resume(), which calls clk_prepare_enable() and msleep():
drivers/gpu/drm/bridge/synopsys/dw-dp.c:dw_dp_runtime_resume() {
...
msleep(110);
...
}
Could this lead to kernel warnings for scheduling while atomic, or potential
deadlocks?
> connector = drm_atomic_get_new_connector_for_encoder(state, bridge->encoder);
> if (!connector) {
> dev_err(dp->dev, "failed to get connector\n");
> return;
> }
[Severity: High]
This isn't a bug introduced by this patch, but does this early return cause an
unbalanced resource cleanup if the link enable fails?
If the connector is NULL, the function returns early without clearing
dp->pm_active. Likewise, if dw_dp_link_enable() fails later in the function, it
cleans up by calling phy_power_off() and returns early, leaving dp->pm_active
set to true.
Later, the DRM core invokes dw_dp_bridge_atomic_disable() which sees
dp->pm_active == true and proceeds to call dw_dp_link_disable(), which
unconditionally calls phy_power_off() and drm_dp_link_power_down().
Could this result in a double-free of the phy power or an underflow of the
power count?
[ ... ]
> @@ -2110,6 +2161,9 @@ EXPORT_SYMBOL_GPL(dw_dp_bind);
> void dw_dp_unbind(struct dw_dp *dp)
> {
> drm_bridge_put(dp->next_bridge);
> +
> + if (!dp->usbc_mode)
> + pm_runtime_put_autosuspend(dp->dev);
> }
> EXPORT_SYMBOL_GPL(dw_dp_unbind);
[Severity: High]
Can this asynchronous put race with device teardown?
During component teardown, pm_runtime_put_autosuspend() queues an asynchronous
suspend. However, pm_runtime_disable() cancels pending asynchronous suspend
requests. Will this leave the device permanently active? Should a synchronous
put like pm_runtime_put_sync() be used here instead?
[ ... ]
> @@ -2120,76 +2174,125 @@ static void dw_dp_phy_exit(void *data)
> phy_exit(dp->phy);
> }
>
> -struct dw_dp *dw_dp_probe(struct platform_device *pdev, const struct dw_dp_plat_data *plat_data)
> +static void dw_dp_manual_suspend(void *data)
> +{
> + struct dw_dp *dp = data;
> +
> + dw_dp_runtime_suspend(dp);
> +}
> +
> +static void dw_dp_irq_free(void *data)
> +{
> + struct dw_dp *dp = data;
> +
> + /* ignore error as the interrupt needs to be free'd in any case */
> + PM_RUNTIME_ACQUIRE_AUTOSUSPEND(dp->dev, pm);
> +
> + free_irq(dp->irq, dp);
> + dp->irq = -1;
> +}
[Severity: High]
Similarly, does this asynchronous put in dw_dp_irq_free() race with
pm_runtime_disable() during devm cleanup?
When devm triggers cleanup on driver unbind or probe failure, it invokes
dw_dp_irq_free() which uses PM_RUNTIME_ACQUIRE_AUTOSUSPEND to release the
reference asynchronously. The next step in devm cleanup is usually
devm_pm_runtime_enable() unwinding, which calls pm_runtime_disable().
Could this cancel the pending suspend request and result in a power and
clock resource leak?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=15
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 16/22] drm/rockchip: dw_dp: Add runtime PM support
2026-08-03 18:05 ` [PATCH v9 16/22] drm/rockchip: dw_dp: Add runtime " Sebastian Reichel
@ 2026-08-03 18:58 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 18:58 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: robh, devicetree, conor+dt, dri-devel
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [Medium] Asynchronous autosuspend on driver removal is cancelled by devres-managed pm_runtime_disable(), leaving the hardware powered on and clocks enabled.
Pre-existing issues:
- [High] Missing system sleep PM operations prevents hardware reinitialization on system resume and leaks power during sleep for non-USB-C displays.
--
--- Patch [16]: [PATCH v9 16/22] drm/rockchip: dw_dp: Add runtime PM support ---
commit 92f08187a6106df5f97a5c7538b516c59d21ea4a
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/rockchip: dw_dp: Add runtime PM support
Add support for runtime PM to the Rockchip RK3576/3588 Synopsys
DesignWare DisplayPort driver.
> --- a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
> +++ b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
[ ... ]
> @@ -249,6 +255,24 @@ static void dw_dp_rockchip_remove(struct platform_device *pdev)
> component_del(&pdev->dev, &dw_dp_rockchip_component_ops);
> }
[Severity: Medium]
Will this leave the hardware powered on and clocks enabled after driver unload?
When component_del() is called, the unbind path eventually calls dw_dp_unbind()
which asynchronously drops the PM reference using pm_runtime_put_autosuspend().
After dw_dp_rockchip_remove() returns, the devres cleanup sequence runs and
calls pm_runtime_disable() (registered via devm_pm_runtime_enable() during
probe). Because pm_runtime_disable() unconditionally cancels pending
autosuspend timers and async works, does this cancel the suspend operation
before it can execute and leave the device permanently in the RPM_ACTIVE state?
Would it be safer to ensure a synchronous suspend happens during the remove
path to prevent this leak?
> +
> +static int dw_dp_rockchip_runtime_suspend(struct device *dev)
> +{
> + struct rockchip_dw_dp *dp = dev_get_drvdata(dev);
> +
> + return dw_dp_runtime_suspend(dp->base);
> +}
> +
> +static int dw_dp_rockchip_runtime_resume(struct device *dev)
> +{
> + struct rockchip_dw_dp *dp = dev_get_drvdata(dev);
> +
> + return dw_dp_runtime_resume(dp->base);
> +}
> +
> +static const struct dev_pm_ops dw_dp_pm_ops = {
> + RUNTIME_PM_OPS(dw_dp_rockchip_runtime_suspend, dw_dp_rockchip_runtime_resume, NULL)
> +};
[Severity: High]
This isn't a bug introduced by this patch, but could the lack of system sleep
callbacks in dw_dp_pm_ops prevent hardware reinitialization on system resume?
For non-USB-C displays, the driver holds a runtime PM reference indefinitely
to maintain active hotplug detection. During system suspend (S3), the DRM core
disables the display pipeline which drops one reference, but the usage count
remains at 1, so the device is not runtime suspended.
Since dw_dp_pm_ops lacks system sleep callbacks (like pm_runtime_force_suspend
and pm_runtime_force_resume), does the PM core fail to synchronously suspend
the device?
If the system forcefully cuts power during S3, the hardware state is lost.
Upon system resume, the runtime PM framework still considers the device
RPM_ACTIVE, so a subsequent pm_runtime_get_sync() during pipeline enable
might not trigger dw_dp_runtime_resume(). Does this leave the hardware
uninitialized and result in a blank display?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=16
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 18/22] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot
2026-08-03 18:05 ` [PATCH v9 18/22] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot Sebastian Reichel
@ 2026-08-03 19:02 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 19:02 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: dri-devel, devicetree, robh, conor+dt
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Unbalanced resource lifecycle operations on error paths in dw_dp_bridge_atomic_enable
--
--- Patch [18]: [PATCH v9 18/22] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot ---
commit 7167a1f6669c417c9c943c6894f5b2a33b32f0bf
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot
This commit removes the reservation of the first SDP slot in the atomic_enable
path. The reservation was unclear in origin and could race with audio SDP
reservation features.
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> index 19b6c11f672f9..05d3485a4d8db 100644
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> @@ -1706,9 +1706,6 @@ static void dw_dp_bridge_atomic_enable(struct drm_bridge *bridge,
> return;
> }
>
> - scoped_guard(mutex, &dp->sdp_lock)
> - set_bit(0, dp->sdp_reg_bank);
> -
> ret = dw_dp_link_enable(dp);
> if (ret < 0) {
> dev_err(dp->dev, "failed to enable link: %d\n", ret);
[Severity: High]
Does this error path leave dp->pm_active = true while the PHY is powered off?
If dw_dp_link_enable() fails, it cleans up by calling phy_power_off():
dw_dp_link_enable() {
...
err_phy_power_off:
phy_power_off(dp->phy);
return ret;
}
However, when we return early here, dp->pm_active remains true. Because the
DRM core considers the atomic commit successful even if the bridge enable
callback returns early, a subsequent mode-set or display-off operation will
invoke dw_dp_bridge_atomic_disable().
Because dp->pm_active is true, the disable path proceeds to call
dw_dp_link_disable(), which unconditionally calls phy_power_off() again:
dw_dp_bridge_atomic_disable() {
if (!dp->pm_active)
return;
dp->pm_active = false;
...
dw_dp_link_disable(dp);
}
dw_dp_link_disable() {
...
phy_power_off(dp->phy);
...
}
Can this unbalanced phy_power_off() cause the PHY power count to go negative,
causing subsequent power-on attempts to silently fail?
This same unbalanced teardown could also occur earlier in this function if
drm_atomic_get_new_connector_for_encoder() or
drm_atomic_get_new_connector_state() return NULL, as dp->pm_active is set to
true before those checks.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=18
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 21/22] dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells
2026-08-03 18:05 ` [PATCH v9 21/22] dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells Sebastian Reichel
@ 2026-08-03 19:06 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 19:06 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: dri-devel, conor+dt, robh, devicetree
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] Changing the `#sound-dai-cells` constraint to `const: 1` breaks `dtbs_check` for existing in-tree device trees.
--
--- Patch [21]: [PATCH v9 21/22] dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells ---
commit 843ed61619d9c1e4f037cc1104f1104af5111210
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells
This commit updates the device tree binding for the Rockchip DesignWare
DisplayPort controllers to support multiple DAI interfaces (I2S and S/PDIF).
It changes the #sound-dai-cells property constraint from 0 to 1 to allow
selecting the appropriate audio interface.
> diff --git a/Documentation/devicetree/bindings/display/rockchip/rockchip,dw-dp.yaml b/Documentation/devicetree/bindings/display/rockchip/rockchip,dw-dp.yaml
> index 2b0d9e23e9432..c4f8959dd65da 100644
> --- a/Documentation/devicetree/bindings/display/rockchip/rockchip,dw-dp.yaml
> +++ b/Documentation/devicetree/bindings/display/rockchip/rockchip,dw-dp.yaml
[ ... ]
> @@ -83,7 +83,8 @@ properties:
> maxItems: 1
>
> "#sound-dai-cells":
> - const: 0
> + const: 1
> + description: 0 for I2S, 1 for S/PDIF
[Severity: Low]
Does this strict constraint change break dtbs_check for existing in-tree
device trees?
While the commit message notes this is an ABI break and that the mainline
rk3588 DTS will be fixed up separately, changing this directly to const: 1
causes validation warnings for existing boards.
Would it be better to temporarily allow both values using an enum: [0, 1]
during the transition to preserve CI and bisectability until the dts updates
are merged?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=21
^ permalink raw reply [flat|nested] 36+ messages in thread
* Re: [PATCH v9 22/22] drm/bridge: synopsys: dw-dp: Add audio support
2026-08-03 18:05 ` [PATCH v9 22/22] drm/bridge: synopsys: dw-dp: Add audio support Sebastian Reichel
@ 2026-08-03 19:11 ` sashiko-bot
0 siblings, 0 replies; 36+ messages in thread
From: sashiko-bot @ 2026-08-03 19:11 UTC (permalink / raw)
To: Sebastian Reichel; +Cc: conor+dt, devicetree, robh, dri-devel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] The result of regmap_read() is used without checking its return value, potentially leading to the use of uninitialized stack memory.
--
--- Patch [22]: [PATCH v9 22/22] drm/bridge: synopsys: dw-dp: Add audio support ---
commit f36ed9436eafc188ce4405c443eb47147a26dbd1
Author: Sebastian Reichel <sebastian.reichel@collabora.com>
drm/bridge: synopsys: dw-dp: Add audio support
This commit implements audio support for the Synopsys DesignWare DisplayPort
controller.
> diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> --- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
> +++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
[ ... ]
> @@ -1690,6 +1721,254 @@ static int dw_dp_link_enable(struct dw_dp *dp)
[ ... ]
> +static int dw_dp_audio_prepare(struct drm_bridge *bridge,
> + struct drm_connector *connector,
> + struct hdmi_codec_daifmt *daifmt,
> + struct hdmi_codec_params *params)
> +{
> + struct dw_dp *dp = bridge_to_dp(bridge);
> + u8 supported_audio_interfaces;
> + enum dw_dp_audio_interface audio_interface;
> + u32 cfg1;
> + int ret;
[ ... ]
> + switch (daifmt->fmt) {
> + case HDMI_SPDIF:
> + audio_interface = DW_DP_AUDIO_SPDIF;
> + break;
> + case HDMI_I2S:
> + /*
> + * It is recommended to use SPDIF instead of I2S, since I2S mode requires
> + * manually inserting PCUV control bits from userspace and this is done
> + * automatically in hardware for SPDIF mode.
> + */
> + audio_interface = DW_DP_AUDIO_I2S;
> + break;
> + default:
> + dev_err(dp->dev, "invalid DAI format %d\n", daifmt->fmt);
> + return -EINVAL;
> + }
> +
> + regmap_read(dp->regmap, DW_DP_CONFIG_REG1, &cfg1);
> + supported_audio_interfaces = FIELD_GET(AUDIO_SELECT, cfg1);
[Severity: Medium]
Is it possible for regmap_read() to fail here? If the read operation fails,
cfg1 would remain uninitialized, causing FIELD_GET() to operate on
uninitialized stack memory.
Should the return value of regmap_read() be checked before accessing cfg1?
> +
> + if (supported_audio_interfaces != DW_DP_AUDIO_I2S_AND_SPDIF &&
> + supported_audio_interfaces != audio_interface) {
> + dev_err(dp->dev, "unsupported DAI %d\n", daifmt->fmt);
> + return -EINVAL;
> + }
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260803-synopsys-dw-dp-improvements-v9-0-2e6e46135312@collabora.com?part=22
^ permalink raw reply [flat|nested] 36+ messages in thread
end of thread, other threads:[~2026-08-03 19:11 UTC | newest]
Thread overview: 36+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-03 18:05 [PATCH v9 00/22] Synopsys DisplayPort Controller improvements for Rockchip platforms Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 01/22] drm/bridge: synopsys: dw-dp: Register DP AUX on bridge attach Sebastian Reichel
2026-08-03 18:35 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 02/22] drm/bridge: synopsys: dw-dp: Fix incorrect resource lifetimes in bind callback Sebastian Reichel
2026-08-03 18:27 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 03/22] drm/bridge: synopsys: dw-dp: Fix error handling in dw_dp_link_enable() Sebastian Reichel
2026-08-03 18:25 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 04/22] drm/bridge: synopsys: dw-dp: Cancel pending HPD work Sebastian Reichel
2026-08-03 18:35 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 05/22] drm/bridge: synopsys: dw-dp: Document missing reset line deassert Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 06/22] drm/bridge: synopsys: dw-dp: Add missing mutex cleanups on module removal Sebastian Reichel
2026-08-03 18:27 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 07/22] drm/bridge: synopsys: dw-dp: Fix AUX transfer timeout race condition Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 08/22] drm/bridge: synopsys: dw-dp: Fix support for short I2C reads Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 09/22] drm/bridge: synopsys: dw-dp: Free output_fmts when none are valid Sebastian Reichel
2026-08-03 18:35 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 10/22] drm/bridge: synopsys: dw-dp: Support MEDIA_BUS_FMT_FIXED Sebastian Reichel
2026-08-03 18:43 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 11/22] drm/bridge: synopsys: dw-dp: Add follow-up bridge support Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 12/22] drm/bridge: Add out-of-band HPD notify handler Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 13/22] drm/bridge: synopsys: dw-dp: Support software triggered OOB HPD Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 14/22] drm/rockchip: dw_dp: Implement out-of-band HPD handling Sebastian Reichel
2026-08-03 18:46 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 15/22] drm/bridge: synopsys: dw-dp: Add Runtime PM support Sebastian Reichel
2026-08-03 18:55 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 16/22] drm/rockchip: dw_dp: Add runtime " Sebastian Reichel
2026-08-03 18:58 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 17/22] drm/bridge: synopsys: dw-dp: Protect sdp_reg_bank from concurrent access Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 18/22] drm/bridge: synopsys: dw-dp: Drop useless reservation of first slot Sebastian Reichel
2026-08-03 19:02 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 19/22] drm/bridge: synopsys: dw-dp: Clear only enabled SDPs on atomic disable Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 20/22] drm/bridge: synopsys: dw-dp: Use regmap_set_bits in dw_dp_send_sdp Sebastian Reichel
2026-08-03 18:05 ` [PATCH v9 21/22] dt-bindings: display: rockchip: dw-dp: Fix sound DAI cells Sebastian Reichel
2026-08-03 19:06 ` sashiko-bot
2026-08-03 18:05 ` [PATCH v9 22/22] drm/bridge: synopsys: dw-dp: Add audio support Sebastian Reichel
2026-08-03 19:11 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox