1. 04 9月, 2013 1 次提交
  2. 02 9月, 2013 2 次提交
    • D
      drm: fix DRM_IOCTL_MODE_GETFB handle-leak · 101b96f3
      David Herrmann 提交于
      DRM_IOCTL_MODE_GETFB is used to retrieve information about a given
      framebuffer ID. It is a read-only helper and was thus declassified for
      unprivileged access in:
      
        commit a14b1b42
        Author: Mandeep Singh Baines <mandeep.baines@gmail.com>
        Date:   Fri Jan 20 12:11:16 2012 -0800
      
            drm: remove master fd restriction on mode setting getters
      
      However, alongside width, height and stride information,
      DRM_IOCTL_MODE_GETFB also passes back a handle to the underlying buffer of
      the framebuffer. This handle allows users to mmap() it and read or write
      into it. Obviously, this should be restricted to DRM-Master.
      
      With the current setup, *any* process with access to /dev/dri/card0 (which
      means any process with access to hardware-accelerated rendering) can
      access the current screen framebuffer and modify it ad libitum.
      
      For backwards-compatibility reasons we want to keep the
      DRM_IOCTL_MODE_GETFB call unprivileged. Besides, it provides quite useful
      information regarding screen setup. So we simply test whether the caller
      is the current DRM-Master and if not, we return 0 as handle, which is
      always invalid. A following DRM_IOCTL_GEM_CLOSE on this handle will fail
      with EINVAL, but we accept this. Users shouldn't test for errors during
      GEM_CLOSE, anyway. And it is still better as a failing MODE_GETFB call.
      
      v2: add capable(CAP_SYS_ADMIN) check for compatibility with i-g-t
      
      Cc: <stable@vger.kernel.org>
      Signed-off-by: NDavid Herrmann <dh.herrmann@gmail.com>
      Reviewed-by: NChris Wilson <chris@chris-wilson.co.uk>
      Signed-off-by: NDave Airlie <airlied@redhat.com>
      101b96f3
    • S
      drm: Add drm_bridge · 3b336ec4
      Sean Paul 提交于
      This patch adds the notion of a drm_bridge. A bridge is a chained
      device which hangs off an encoder. The drm driver using the bridge
      should provide the association between encoder and bridge. Once a
      bridge is associated with an encoder, it will participate in mode
      set, and dpms (via the enable/disable hooks).
      Signed-off-by: NSean Paul <seanpaul@chromium.org>
      Acked-by: NDaniel Vetter <daniel.vetter@ffwll.ch>
      Reviewed-by: NRob Clark <robdclark@gmail.com>
      Signed-off-by: NDave Airlie <airlied@redhat.com>
      3b336ec4
  3. 30 8月, 2013 2 次提交
  4. 21 8月, 2013 2 次提交
  5. 19 8月, 2013 1 次提交
  6. 28 6月, 2013 1 次提交
    • D
      drm: add hotspot support for cursors. · 4c813d4d
      Dave Airlie 提交于
      So it looks like for virtual hw cursors on QXL we need to inform
      the "hw" device what the cursor hotspot parameters are. This
      makes sense if you think the host has to draw the cursor and interpret
      clicks from it. However the current modesetting interface doesn't support
      passing the hotspot information from userspace.
      
      This implements a new cursor ioctl, that takes the hotspot info as well,
      userspace can try calling the new interface and if it gets -ENOSYS it means
      its on an older kernel and can just fallback.
      Reviewed-by: NDaniel Vetter <daniel.vetter@ffwll.ch>
      Signed-off-by: NDave Airlie <airlied@redhat.com>
      4c813d4d
  7. 25 6月, 2013 2 次提交
    • D
      drm: fix fb leak in setcrtc · 5cef29aa
      Daniel Vetter 提交于
      Drivers are allowed (actually have to) disable unrelated crtcs in
      their ->set_config callback (when we steal all the connectors from
      that crtc). If they do that they'll clear crtc->fb to NULL.
      
      Which results in a refcount leak, since the drm core is keeping track
      of that reference.
      
      To fix this track the old fb of all crtcs and adjust references for
      all of them. Of course, since we only hold an additional reference for
      the fb for the current crtc we need to increase refcounts before we
      drop the old one.
      
      This approach has the benefit that it inches us a bit closer to an
      atomic modeset world, where we want to update the config of all crtcs
      in one step.
      
      This regression has been introduce in the framebuffer refcount
      conversion, specifically in
      
      commit b0d12325
      Author: Daniel Vetter <daniel.vetter@ffwll.ch>
      Date:   Tue Dec 11 01:07:12 2012 +0100
      
          drm: refcounting for crtc framebuffers
      Reported-by: NRussell King <linux@arm.linux.org.uk>
      Cc: Russell King <linux@arm.linux.org.uk>
      Cc: stable@vger.kernel.org
      Signed-off-by: NDaniel Vetter <daniel.vetter@ffwll.ch>
      Signed-off-by: NDave Airlie <airlied@redhat.com>
      5cef29aa
    • D
      drm: check that ->set_config properly updates the fb · cc85e121
      Daniel Vetter 提交于
      Historically drm lacked fb refcounting, so the updating of crtc->fb
      was done by the lower levels at a point convenient to get their own
      refcounting (e.g. refcounts for the underlying gem bo, pinning
      refcounts) right. With the introduction of refcounted fbs the drm core
      handled the fb refcounts, but still relied on drivers to update the
      crtc->fb pointer (this approach required the least invasive changes in
      drivers).
      
      Enforce this contract with a WARN_ON.
      Signed-off-by: NDaniel Vetter <daniel.vetter@ffwll.ch>
      Signed-off-by: NDave Airlie <airlied@redhat.com>
      cc85e121
  8. 17 6月, 2013 3 次提交
  9. 11 6月, 2013 4 次提交
  10. 13 5月, 2013 1 次提交
  11. 03 5月, 2013 1 次提交
  12. 30 4月, 2013 2 次提交
    • V
      drm: Kill user_modes list and the associated ioctls · c55b6b3d
      Ville Syrjälä 提交于
      There is no way to use modes added to the user_modes list. We never
      look at the contents of said list in the kernel, and the only operations
      userspace can do are attach and detach. So the only "benefit" of this
      interface is wasting kernel memory.
      
      Fortunately it seems no real user space application ever used these
      ioctls. So just kill them.
      
      Also remove the prototypes for the non-existing drm_mode_addmode_ioctl()
      and drm_mode_rmmode_ioctl() functions.
      
      v2: Use drm_noop instead of completely removing the ioctls
      Signed-off-by: NVille Syrjälä <ville.syrjala@linux.intel.com>
      Signed-off-by: NDave Airlie <airlied@redhat.com>
      c55b6b3d
    • V
      drm: Silence some sparse warnings · ea9cbb06
      Ville Syrjälä 提交于
      drivers/gpu/drm/drm_pci.c:155:5: warning: symbol 'drm_pci_set_busid' was not declared. Should it be static?
      drivers/gpu/drm/drm_pci.c:197:5: warning: symbol 'drm_pci_set_unique' was not declared. Should it be static?
      drivers/gpu/drm/drm_pci.c:269:5: warning: symbol 'drm_pci_agp_init' was not declared. Should it be static?
      
      drivers/gpu/drm/drm_crtc.c:181:1: warning: symbol 'drm_get_dirty_info_name' was not declared. Should it be static?
      drivers/gpu/drm/drm_crtc.c:1123:5: warning: symbol 'drm_mode_group_init' was not declared. Should it be static?
      
      drivers/gpu/drm/drm_modes.c:918:6: warning: symbol 'drm_mode_validate_clocks' was not declared. Should it be static?
      Signed-off-by: NVille Syrjälä <ville.syrjala@linux.intel.com>
      Signed-off-by: NDave Airlie <airlied@redhat.com>
      ea9cbb06
  13. 22 4月, 2013 1 次提交
  14. 16 4月, 2013 1 次提交
  15. 12 4月, 2013 1 次提交
  16. 28 3月, 2013 1 次提交
  17. 28 2月, 2013 2 次提交
  18. 22 2月, 2013 1 次提交
  19. 20 2月, 2013 3 次提交
  20. 18 2月, 2013 1 次提交
  21. 14 2月, 2013 1 次提交
    • D
      drm: review locking for drm_fb_helper_restore_fbdev_mode · 6aed8ec3
      Daniel Vetter 提交于
      ... it's required. Fix up exynos and the cma helper, and add a
      corresponding WARN_ON to drm_fb_helper_restore_fbdev_mode.
      
      Note that tegra calls the fbdev cma helper restore function also from
      it's driver-load callback. Which is a bit against current practice,
      since usually the call is only from ->lastclose, and initial setup is
      done by drm_fb_helper_initial_config.
      
      Also add the relevant drm DocBook entry.
      
      v2: Add promised WARN to restore_fbdev_mode.
      Reviewed-by: NRob Clark <robdclark@gmail.com>
      Signed-off-by: NDaniel Vetter <daniel.vetter@ffwll.ch>
      6aed8ec3
  22. 21 1月, 2013 6 次提交
    • D
      drm: don't hold crtc mutexes for connector ->detect callbacks · 7b24056b
      Daniel Vetter 提交于
      The coup de grace of the entire journey. No more dropped frames every
      10s on my testbox!
      
      I've tried to audit all ->detect and ->get_modes callbacks, but things
      became a bit fuzzy after trying to piece together the umpteenth
      implemenation. Afaict most drivers just have bog-standard output
      register frobbing with a notch of i2c edid reading, nothing which
      could potentially race with the newly concurrent pageflip/set_cursor
      code. The big exception is load-detection code which requires a
      running pipe, but radeon/nouveau seem to to this without touching any
      state which can be observed from page_flip (e.g. disabled crtcs
      temporarily getting enabled and so a pageflip succeeding).
      
      The only special case I could find is the i915 load detect code. That
      uses the normal modeset interface to enable the load-detect crtc, and
      so userspace could try to squeeze in a pageflip on the load-detect
      pipe. So we need to grab the relevant crtc mutex in there, to avoid
      the temporary crtc enabling to sneak out and be visible to userspace.
      
      Note that the sysfs files already stopped grabbing the per-crtc locks,
      since I didn't want to bother with doing a interruptible
      modeset_lock_all. But since there's very little in-between breakage
      (essentially just the ability for userspace to pageflip on load-detect
      crtcs when it shouldn't on the i915 driver) I figured I don't need to
      bother.
      Reviewed-by: NRob Clark <rob@ti.com>
      Signed-off-by: NDaniel Vetter <daniel.vetter@ffwll.ch>
      7b24056b
    • D
      drm: only grab the crtc lock for pageflips · b4d5e7d1
      Daniel Vetter 提交于
      The pagelip ioctl itself is rather simply, so the hard work for this
      patch is auditing all the drivers:
      
      - exynos: Pageflip is protect with dev->struct_mutex and ...
        synchronous. But nothing fancy going on, besides a check whether the
        crtc is enabled, which should probably be somewhere in the drm core
        so that we have unified behaviour across all drivers.
      
      - i915: hw-state is protected with dev->struct_mutex, the delayed
        unpin work together with the other stuff the pageflip complete irq
        handler needs is protected by the event_lock spinlock.
      
      - nouveau: With the pin/unpin functions fixed, everything looks safe:
        A bit of ttm wrestling and refcounting, and a few channel accesses.
        The later are either already proteced sufficiently, or are now safe
        with the channel locking introduced to make cursor updates safe.
      
      - radeon: The irq_get/put functions look a bit race, since the
        atomic_inc/dec isn't protect with locks. Otoh they're all per-crtc,
        so we should be safe with per-crtc locking from the drm core. Then
        there's tons of per-crtc register access, which could potentially go
        through the indirect reg acces. But that's fixed to make cursor
        updates concurrent. Bookeeping for the drm even is also protected
        with the even_lock, which also protects against the pageflip irq
        handler since radeon hw seems to have no way to queue these up
        asynchronously. Otherwise just a bit of ttm-based buffer handling
        and fencing, which is now safe with the previous patch to hold
        bdev->fence_lock while grabbing the ttm fence.
      
      - shmob: Only one crtc. That's an easy one ...
      
      - vmwgfx: As usual a bit special with tons different things:
        - Flippable check using is_implicit and num_implicit. Changes to
          those seem to be nicely covered with the global modeset lock, so
          we should be fine.
        - Some dirty cliprect handling stuff, or at least that is my guess.
          Looks like it's fine since either it's per-crtc, invariant or
          (like the execbuf stuff launched) protected otherwise.
        - Adding the actual flip to the fence_event list. On a quick look
          this seems to have solid locking in place, too.
        ... but generally this is all way over my head.
      
      - imx: Impressive display of races between the page_flip
        implementation and the irq handler. Also, ipu_drm_set_base which
        gets eventually called from the irq handler to update the display
        base isn't really protected against concurrent set_config calls from
        process context.  In any case, going for per-crtc locking won't make
        this worse, so nothing to do.
      
      - omap: The new async callback code merged into 3.8 seems to have
        solid locking in place, and there doesn't seem to be any shared
        state at risk. Especially since the callbacks still use
        modeset_lock_all and are so not converted.
      
      v2: Update omapdrm analysis to 3.8 code per the discussion with Rob
      Clark.
      Reviewed-by: NRob Clark <rob@ti.com>
      Signed-off-by: NDaniel Vetter <daniel.vetter@ffwll.ch>
      b4d5e7d1
    • D
      drm: optimize drm_framebuffer_remove · b62584e3
      Daniel Vetter 提交于
      Now that all framebuffer usage is properly refcounted, we are no
      longer required to hold the modeset locks while dropping the last
      reference. Hence implemented a fastpath which avoids the potential
      stalls associated with grabbing mode_config.lock for the case where
      there's no other reference around.
      
      Explain in a big comment why it is safe. Also update kerneldocs with
      the new locking rules around drm_framebuffer_remove.
      Reviewed-by: NRob Clark <rob@ti.com>
      Signed-off-by: NDaniel Vetter <daniel.vetter@ffwll.ch>
      b62584e3
    • D
      drm: refcounting for crtc framebuffers · b0d12325
      Daniel Vetter 提交于
      With the prep patch to encapsulate ->set_crtc calls, this is now
      rather easy. Hooray for inconsistent semantics between ->set_crtc and
      ->page_flip, where the driver callback is supposed to update the fb
      pointer, and ->update_plane, where the drm core does the same.
      
      Also, since the drm core functions check crtc->fb before calling into
      driver callbacks, we can't really reduce the critical sections
      protected by the mode_config locks.
      Reviewed-by: NRob Clark <rob@ti.com>
      Signed-off-by: NDaniel Vetter <daniel.vetter@ffwll.ch>
      b0d12325
    • D
      drm: refcounting for sprite framebuffers · 6c2a7532
      Daniel Vetter 提交于
      Now plane->fb holds a reference onto it's framebuffer. Nothing too
      fancy going on here:
      - Extract __drm_framebuffer_unreference to be called when we know
        we're not dropping the last reference, e.g. useful in the fb cleanup
        code.
      - Reduce the locked sections in the set_plane ioctl to only protect
        plane->fb/plane->crtc and the driver callback (i.e. hw state).
        Everything either doesn't disappear (crtc, plane) or is refcounted
        (fb), and all the data we check is invariant over the respective
        object's lifetimes.
      Reviewed-by: NRob Clark <rob@ti.com>
      Signed-off-by: NDaniel Vetter <daniel.vetter@ffwll.ch>
      6c2a7532
    • D
      drm: fb refcounting for dirtyfb_ioctl · 4ccf097f
      Daniel Vetter 提交于
      We only need to ensure that the fb stays around for long enough. While
      at it, only grab the modeset locks when we need them (since most
      drivers don't implement the dirty callback, this should help jitter
      and stalls when using the generic modeset driver).
      Reviewed-by: NRob Clark <rob@ti.com>
      Signed-off-by: NDaniel Vetter <daniel.vetter@ffwll.ch>
      4ccf097f