4d4c2d8991
Sergey Suloev reported a crash happening in drm_client_dev_hotplug()
when fbdev had failed to register.
[ 9.124598] vc4_hdmi 3f902000.hdmi: ASoC: Failed to create component debugfs directory
[ 9.147667] vc4_hdmi 3f902000.hdmi: vc4-hdmi-hifi <-> 3f902000.hdmi mapping ok
[ 9.155184] vc4_hdmi 3f902000.hdmi: ASoC: no DMI vendor name!
[ 9.166544] vc4-drm soc:gpu: bound 3f902000.hdmi (ops vc4_hdmi_ops [vc4])
[ 9.173840] vc4-drm soc:gpu: bound 3f806000.vec (ops vc4_vec_ops [vc4])
[ 9.181029] vc4-drm soc:gpu: bound 3f004000.txp (ops vc4_txp_ops [vc4])
[ 9.188519] vc4-drm soc:gpu: bound 3f400000.hvs (ops vc4_hvs_ops [vc4])
[ 9.195690] vc4-drm soc:gpu: bound 3f206000.pixelvalve (ops vc4_crtc_ops [vc4])
[ 9.203523] vc4-drm soc:gpu: bound 3f207000.pixelvalve (ops vc4_crtc_ops [vc4])
[ 9.215032] vc4-drm soc:gpu: bound 3f807000.pixelvalve (ops vc4_crtc_ops [vc4])
[ 9.274785] vc4-drm soc:gpu: bound 3fc00000.v3d (ops vc4_v3d_ops [vc4])
[ 9.290246] [drm] Initialized vc4 0.0.0 20140616 for soc:gpu on minor 0
[ 9.297464] [drm] Supports vblank timestamp caching Rev 2 (21.10.2013).
[ 9.304600] [drm] Driver supports precise vblank timestamp query.
[ 9.382856] vc4-drm soc:gpu: [drm:drm_fb_helper_fbdev_setup [drm_kms_helper]] *ERROR* Failed to set fbdev configuration
[ 10.404937] Unable to handle kernel paging request at virtual address 00330a656369768a
[ 10.441620] [00330a656369768a] address between user and kernel address ranges
[ 10.449087] Internal error: Oops: 96000004 [#1] PREEMPT SMP
[ 10.454762] Modules linked in: brcmfmac vc4 drm_kms_helper cfg80211 drm rfkill smsc95xx brcmutil usbnet drm_panel_orientation_quirks raspberrypi_hwmon bcm2835_dma crc32_ce pwm_bcm2835 bcm2835_rng virt_dma rng_core i2c_bcm2835 ip_tables x_tables ipv6
[ 10.477296] CPU: 2 PID: 45 Comm: kworker/2:1 Not tainted 4.19.0-rc5 #3
[ 10.483934] Hardware name: Raspberry Pi 3 Model B Rev 1.2 (DT)
[ 10.489966] Workqueue: events output_poll_execute [drm_kms_helper]
[ 10.596515] Process kworker/2:1 (pid: 45, stack limit = 0x000000007e8924dc)
[ 10.603590] Call trace:
[ 10.606259] drm_client_dev_hotplug+0x5c/0xb0 [drm]
[ 10.611303] drm_kms_helper_hotplug_event+0x30/0x40 [drm_kms_helper]
[ 10.617849] output_poll_execute+0xc4/0x1e0 [drm_kms_helper]
[ 10.623616] process_one_work+0x1c8/0x318
[ 10.627695] worker_thread+0x48/0x428
[ 10.631420] kthread+0xf8/0x128
[ 10.634615] ret_from_fork+0x10/0x18
[ 10.638255] Code: 54000220 f9401261 aa1303e0 b4000141 (f9400c21)
[ 10.644456] ---[ end trace c75b4a4b0e141908 ]---
The reason for this is that drm_fbdev_cma_init() removes the drm_client
when fbdev registration fails, but it doesn't remove the client from the
drm_device client list. So the client list now has a pointer that points
into the unknown and we have a 'use after free' situation.
Split drm_client_new() into drm_client_init() and drm_client_add() to fix
removal in the error path.
Fixes: 894a677f4b
("drm/cma-helper: Use the generic fbdev emulation")
Reported-by: Sergey Suloev <ssuloev@orpaltech.com>
Cc: Stefan Wahren <stefan.wahren@i2se.com>
Cc: Eric Anholt <eric@anholt.net>
Cc: Daniel Vetter <daniel.vetter@ffwll.ch>
Signed-off-by: Noralf Trønnes <noralf@tronnes.org>
Reviewed-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Link: https://patchwork.freedesktop.org/patch/msgid/20181001194536.57756-1-noralf@tronnes.org
254 lines
7.3 KiB
C
254 lines
7.3 KiB
C
/*
|
|
* drm kms/fb cma (contiguous memory allocator) helper functions
|
|
*
|
|
* Copyright (C) 2012 Analog Device Inc.
|
|
* Author: Lars-Peter Clausen <lars@metafoo.de>
|
|
*
|
|
* Based on udl_fbdev.c
|
|
* Copyright (C) 2012 Red Hat
|
|
*
|
|
* This program is free software; you can redistribute it and/or
|
|
* modify it under the terms of the GNU General Public License
|
|
* as published by the Free Software Foundation; either version 2
|
|
* of the License, or (at your option) any later version.
|
|
* This program is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*/
|
|
|
|
#include <drm/drmP.h>
|
|
#include <drm/drm_client.h>
|
|
#include <drm/drm_fb_helper.h>
|
|
#include <drm/drm_framebuffer.h>
|
|
#include <drm/drm_gem_cma_helper.h>
|
|
#include <drm/drm_gem_framebuffer_helper.h>
|
|
#include <drm/drm_fb_cma_helper.h>
|
|
#include <drm/drm_print.h>
|
|
#include <linux/module.h>
|
|
|
|
struct drm_fbdev_cma {
|
|
struct drm_fb_helper fb_helper;
|
|
};
|
|
|
|
/**
|
|
* DOC: framebuffer cma helper functions
|
|
*
|
|
* Provides helper functions for creating a cma (contiguous memory allocator)
|
|
* backed framebuffer.
|
|
*
|
|
* drm_gem_fb_create() is used in the &drm_mode_config_funcs.fb_create
|
|
* callback function to create a cma backed framebuffer.
|
|
*
|
|
* An fbdev framebuffer backed by cma is also available by calling
|
|
* drm_fb_cma_fbdev_init(). drm_fb_cma_fbdev_fini() tears it down.
|
|
*/
|
|
|
|
static inline struct drm_fbdev_cma *to_fbdev_cma(struct drm_fb_helper *helper)
|
|
{
|
|
return container_of(helper, struct drm_fbdev_cma, fb_helper);
|
|
}
|
|
|
|
/**
|
|
* drm_fb_cma_get_gem_obj() - Get CMA GEM object for framebuffer
|
|
* @fb: The framebuffer
|
|
* @plane: Which plane
|
|
*
|
|
* Return the CMA GEM object for given framebuffer.
|
|
*
|
|
* This function will usually be called from the CRTC callback functions.
|
|
*/
|
|
struct drm_gem_cma_object *drm_fb_cma_get_gem_obj(struct drm_framebuffer *fb,
|
|
unsigned int plane)
|
|
{
|
|
struct drm_gem_object *gem;
|
|
|
|
gem = drm_gem_fb_get_obj(fb, plane);
|
|
if (!gem)
|
|
return NULL;
|
|
|
|
return to_drm_gem_cma_obj(gem);
|
|
}
|
|
EXPORT_SYMBOL_GPL(drm_fb_cma_get_gem_obj);
|
|
|
|
/**
|
|
* drm_fb_cma_get_gem_addr() - Get physical address for framebuffer
|
|
* @fb: The framebuffer
|
|
* @state: Which state of drm plane
|
|
* @plane: Which plane
|
|
* Return the CMA GEM address for given framebuffer.
|
|
*
|
|
* This function will usually be called from the PLANE callback functions.
|
|
*/
|
|
dma_addr_t drm_fb_cma_get_gem_addr(struct drm_framebuffer *fb,
|
|
struct drm_plane_state *state,
|
|
unsigned int plane)
|
|
{
|
|
struct drm_gem_cma_object *obj;
|
|
dma_addr_t paddr;
|
|
|
|
obj = drm_fb_cma_get_gem_obj(fb, plane);
|
|
if (!obj)
|
|
return 0;
|
|
|
|
paddr = obj->paddr + fb->offsets[plane];
|
|
paddr += fb->format->cpp[plane] * (state->src_x >> 16);
|
|
paddr += fb->pitches[plane] * (state->src_y >> 16);
|
|
|
|
return paddr;
|
|
}
|
|
EXPORT_SYMBOL_GPL(drm_fb_cma_get_gem_addr);
|
|
|
|
/**
|
|
* drm_fb_cma_fbdev_init() - Allocate and initialize fbdev emulation
|
|
* @dev: DRM device
|
|
* @preferred_bpp: Preferred bits per pixel for the device.
|
|
* @dev->mode_config.preferred_depth is used if this is zero.
|
|
* @max_conn_count: Maximum number of connectors.
|
|
* @dev->mode_config.num_connector is used if this is zero.
|
|
*
|
|
* Returns:
|
|
* Zero on success or negative error code on failure.
|
|
*/
|
|
int drm_fb_cma_fbdev_init(struct drm_device *dev, unsigned int preferred_bpp,
|
|
unsigned int max_conn_count)
|
|
{
|
|
struct drm_fbdev_cma *fbdev_cma;
|
|
|
|
/* dev->fb_helper will indirectly point to fbdev_cma after this call */
|
|
fbdev_cma = drm_fbdev_cma_init(dev, preferred_bpp, max_conn_count);
|
|
if (IS_ERR(fbdev_cma))
|
|
return PTR_ERR(fbdev_cma);
|
|
|
|
return 0;
|
|
}
|
|
EXPORT_SYMBOL_GPL(drm_fb_cma_fbdev_init);
|
|
|
|
/**
|
|
* drm_fb_cma_fbdev_fini() - Teardown fbdev emulation
|
|
* @dev: DRM device
|
|
*/
|
|
void drm_fb_cma_fbdev_fini(struct drm_device *dev)
|
|
{
|
|
if (dev->fb_helper)
|
|
drm_fbdev_cma_fini(to_fbdev_cma(dev->fb_helper));
|
|
}
|
|
EXPORT_SYMBOL_GPL(drm_fb_cma_fbdev_fini);
|
|
|
|
static const struct drm_fb_helper_funcs drm_fb_cma_helper_funcs = {
|
|
.fb_probe = drm_fb_helper_generic_probe,
|
|
};
|
|
|
|
/**
|
|
* drm_fbdev_cma_init() - Allocate and initializes a drm_fbdev_cma struct
|
|
* @dev: DRM device
|
|
* @preferred_bpp: Preferred bits per pixel for the device
|
|
* @max_conn_count: Maximum number of connectors
|
|
*
|
|
* Returns a newly allocated drm_fbdev_cma struct or a ERR_PTR.
|
|
*/
|
|
struct drm_fbdev_cma *drm_fbdev_cma_init(struct drm_device *dev,
|
|
unsigned int preferred_bpp, unsigned int max_conn_count)
|
|
{
|
|
struct drm_fbdev_cma *fbdev_cma;
|
|
struct drm_fb_helper *fb_helper;
|
|
int ret;
|
|
|
|
fbdev_cma = kzalloc(sizeof(*fbdev_cma), GFP_KERNEL);
|
|
if (!fbdev_cma)
|
|
return ERR_PTR(-ENOMEM);
|
|
|
|
fb_helper = &fbdev_cma->fb_helper;
|
|
|
|
ret = drm_client_init(dev, &fb_helper->client, "fbdev", NULL);
|
|
if (ret)
|
|
goto err_free;
|
|
|
|
ret = drm_fb_helper_fbdev_setup(dev, fb_helper, &drm_fb_cma_helper_funcs,
|
|
preferred_bpp, max_conn_count);
|
|
if (ret)
|
|
goto err_client_put;
|
|
|
|
drm_client_add(&fb_helper->client);
|
|
|
|
return fbdev_cma;
|
|
|
|
err_client_put:
|
|
drm_client_release(&fb_helper->client);
|
|
err_free:
|
|
kfree(fbdev_cma);
|
|
|
|
return ERR_PTR(ret);
|
|
}
|
|
EXPORT_SYMBOL_GPL(drm_fbdev_cma_init);
|
|
|
|
/**
|
|
* drm_fbdev_cma_fini() - Free drm_fbdev_cma struct
|
|
* @fbdev_cma: The drm_fbdev_cma struct
|
|
*/
|
|
void drm_fbdev_cma_fini(struct drm_fbdev_cma *fbdev_cma)
|
|
{
|
|
drm_fb_helper_unregister_fbi(&fbdev_cma->fb_helper);
|
|
/* All resources have now been freed by drm_fbdev_fb_destroy() */
|
|
}
|
|
EXPORT_SYMBOL_GPL(drm_fbdev_cma_fini);
|
|
|
|
/**
|
|
* drm_fbdev_cma_restore_mode() - Restores initial framebuffer mode
|
|
* @fbdev_cma: The drm_fbdev_cma struct, may be NULL
|
|
*
|
|
* This function is usually called from the &drm_driver.lastclose callback.
|
|
*/
|
|
void drm_fbdev_cma_restore_mode(struct drm_fbdev_cma *fbdev_cma)
|
|
{
|
|
if (fbdev_cma)
|
|
drm_fb_helper_restore_fbdev_mode_unlocked(&fbdev_cma->fb_helper);
|
|
}
|
|
EXPORT_SYMBOL_GPL(drm_fbdev_cma_restore_mode);
|
|
|
|
/**
|
|
* drm_fbdev_cma_hotplug_event() - Poll for hotpulug events
|
|
* @fbdev_cma: The drm_fbdev_cma struct, may be NULL
|
|
*
|
|
* This function is usually called from the &drm_mode_config.output_poll_changed
|
|
* callback.
|
|
*/
|
|
void drm_fbdev_cma_hotplug_event(struct drm_fbdev_cma *fbdev_cma)
|
|
{
|
|
if (fbdev_cma)
|
|
drm_fb_helper_hotplug_event(&fbdev_cma->fb_helper);
|
|
}
|
|
EXPORT_SYMBOL_GPL(drm_fbdev_cma_hotplug_event);
|
|
|
|
/**
|
|
* drm_fbdev_cma_set_suspend - wrapper around drm_fb_helper_set_suspend
|
|
* @fbdev_cma: The drm_fbdev_cma struct, may be NULL
|
|
* @state: desired state, zero to resume, non-zero to suspend
|
|
*
|
|
* Calls drm_fb_helper_set_suspend, which is a wrapper around
|
|
* fb_set_suspend implemented by fbdev core.
|
|
*/
|
|
void drm_fbdev_cma_set_suspend(struct drm_fbdev_cma *fbdev_cma, bool state)
|
|
{
|
|
if (fbdev_cma)
|
|
drm_fb_helper_set_suspend(&fbdev_cma->fb_helper, state);
|
|
}
|
|
EXPORT_SYMBOL(drm_fbdev_cma_set_suspend);
|
|
|
|
/**
|
|
* drm_fbdev_cma_set_suspend_unlocked - wrapper around
|
|
* drm_fb_helper_set_suspend_unlocked
|
|
* @fbdev_cma: The drm_fbdev_cma struct, may be NULL
|
|
* @state: desired state, zero to resume, non-zero to suspend
|
|
*
|
|
* Calls drm_fb_helper_set_suspend, which is a wrapper around
|
|
* fb_set_suspend implemented by fbdev core.
|
|
*/
|
|
void drm_fbdev_cma_set_suspend_unlocked(struct drm_fbdev_cma *fbdev_cma,
|
|
bool state)
|
|
{
|
|
if (fbdev_cma)
|
|
drm_fb_helper_set_suspend_unlocked(&fbdev_cma->fb_helper,
|
|
state);
|
|
}
|
|
EXPORT_SYMBOL(drm_fbdev_cma_set_suspend_unlocked);
|