From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BA02D559CB4 for ; Wed, 9 Sep 2026 12:41:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.51 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788957678; cv=none; b=lVgVb0+0geVfn1xlItKf9IPWF4ozRi+KGe0UVsUZGcF4o9wdhBShI2i05Z/8Tj3EsSFahIFgznIPYvWhgxDDIFx48g59OhdPhXnTFXXYa/0tclC3IM+3hTkSKIk3sYmjkq5fWujl6m2QvAMItNxgiggoD2HPkDpnDB3DobCV+Wg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788957678; c=relaxed/simple; bh=rz21cPiefGvfWvJLlO3lj7TeKXl8/4O7jWhsTpXvNoU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=hmPU/LSjJbgRYNe/OkHeZKxstYYmGgoyDlyXpgds037Q+7Glw/mfR6XDWc+ZiL0mk3LKyl+IUZ5h2QIDCGNvqp4pnVjYswWNZPdSXThktb8MzNv/igBQIF4MXe1S6Yjhivuq2rfhixmyzUqiVSLusFZ1iocA3ZdpCY3ir5ZoaLc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=krlU2reB; arc=none smtp.client-ip=209.85.128.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="krlU2reB" Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-49b392ccaacso84199865e9.2 for ; Wed, 09 Sep 2026 05:41:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788957673; x=1789562473; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=U++xriGSV8Y0IeslzQ+0/UgYXYPu5RhMaCi/7ZCxAIs=; b=krlU2reBd6zDI/IfX3IPNfC9s/WbtqL46DubLRn01nPqadmvuA8mfYNnhJ0eEsvydV N8Rhyi1ePAxGwkTRVtML0ufSqFVDGyJp/3gb1dOQcF2HON2qUQChdJ2apb9biGzzU/az YFzQPxrM551a/Y/VtUTFgOeQShvfXrobQEVuYWdK/Wf5AE9wVVvainbB7yFrOyP7AhMj CMZ48r/OnXb/dYtND4cQvYLUNMiBd8QjHCpowox7GhpMn0mHd2Vdn3OjW+yqJ5e6+U7l 4nL7SRZ5vr7knp3jNqTPFncPS5jnBMC8m8XUIPWDSoVZnaapzGdTXHixjqwGUjP7mGcm DQ+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788957673; x=1789562473; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=U++xriGSV8Y0IeslzQ+0/UgYXYPu5RhMaCi/7ZCxAIs=; b=VCct8AU2nF1wKRwF2yw92kYDHZzeNZqcmkKv20CpoZbovRXyPw723G1Y+PkHF4dZy5 zox2FwCd71+MgFYQ/6PSwz5yejKnSRHKMnK1S36enNg5L7V2GdIws5mxKz7TxDa/Vbp6 KonwHHDcHGRxYyDWuoLiowTO5mALhbVNcFrhmDGb+XMz/qd0yLsw1ndBotAEitSkCe4N B85R67Joie+9dSOYbdqTxmZTpRbPlDZbSGhPzuHejGXXXXbRCgydyqZPdgiHnrgkyo5D FK+O12YMtwsR+4SisVmOKS58rFsZpa3Jiu1AAHr+vWZzF4j0kbRP95sKV9ckUvcXU0rx R0Xg== X-Forwarded-Encrypted: i=1; AKwUvBwun8ifskdAL0LO63wXg3I1vDPNXm/c203X8hHzI+ecqzCkdfq+mlhghBrP7+v6SnmDS9f2JRrm3T4YlTQ=@vger.kernel.org X-Gm-Message-State: AFuF++kHsiTcqmVvZWGq/1CS5y1hhPeERAjzUuAcyfP7ZvmuGIuyNvSC YzV+Mr/nwELHS4YsCsTkm+J4seF2PJmTlaDAaro3iMLfhEDnb85ofK5I X-Gm-Gg: AYBFou1jlGGigSjaSAK3NuG4qAc2R+cMJSju4pX3yn8gRED7A8gGHMPgZqNMSMdOOdM vZPXxv2FK9rgkxtXcmfsdN/Q4rtohEVDCOWnA1fLq8tlXrciX3C9v0uEFLr4VBXLs5Ud6vjwhsV 7x3CoW5Pk3wlLls/RP0veSuos6FB5TdOi9cFSofbnDQaxhHQVQ2vLEKE6k9flLTsypq8EAi/RHk CjEWJq1UYueUy8BA6Ou5UBTvok4TcMxZdnKC+Cz/rbqRBCK7ydkssbzxpHbg/0e9Fxmw08sPBWZ Tf5Z85BUkRCaiXT6leJ+GXJwfTR2vUGCi2QBKg4j5hlgJdNSP79ILhtxhFhNEMm1zzyHlMgOl5n UhDU1n64G6cXEuIGw8pi68OkU13IpMkBZ3r9lDboav30ynNDgmg0tNtlIflzfJImfgnCj8HllkU bVVOwSWHiHdfDkmp0PbdAsiRiT0J72f7/bF4fip37LxOSY1lhcJ3K2p7GwHKHT6DqUk35qWpe+C ujG+3xZ7E8D/HFDx8nw19mdByg87SB7u3M7k6YeHtqD8wkApiQX9ROUuOGU5bX6e6pBBS4g6PXr rA6aOodXIZ/LMiUihAinL2gTrKU8UQ+6jAAJog== X-Received: by 2002:a05:600c:a01:b0:499:7219:122f with SMTP id 5b1f17b1804b1-49cf8222d53mr350888445e9.4.1788957672359; Wed, 09 Sep 2026 05:41:12 -0700 (PDT) Received: from PC-Davide.homenet.telecomitalia.it (host-79-24-252-102.retail.telecomitalia.it. [79.24.252.102]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49d1fd8a566sm53006285e9.1.2026.09.09.05.41.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 05:41:10 -0700 (PDT) From: Davide Bonatto To: Alexey Brodkin , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org (open list:DRM DRIVERS), linux-kernel@vger.kernel.org (open list) Cc: Davide Bonatto Subject: [PATCH v4] drm/tiny: arcpgu: Replace simple display pipe with regular atomic helpers Date: Wed, 9 Sep 2026 14:41:05 +0200 Message-ID: <20260909124108.168371-1-bonatto.davide@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260909092455.131962-1-bonatto.davide@gmail.com> References: <20260909092455.131962-1-bonatto.davide@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The drm_simple_display_pipe helper is considered legacy/deprecated in favor of explicitly managing individual plane, CRTC, and encoder objects using standard atomic helpers. Migrate arcpgu to initialize its primary plane, CRTC, and encoder explicitly, and route mode validation, enable, and disable hooks through drm_crtc_helper_funcs, and plane updates through drm_plane_helper_funcs. Signed-off-by: Davide Bonatto --- v4: - Use drm_atomic_get_plane_state() in CRTC .atomic_check to ensure the primary plane state is attached and locked, avoiding false -EINVAL rejections and broken partial atomic commits. v3: - Add CRTC .atomic_check hook to validate primary plane presence and avoid NULL pointer dereference in arc_pgu_set_pxl_fmt(). - Pass framebuffer explicitly to arc_pgu_mode_set() and read plane state via drm_atomic_get_new_plane_state() in CRTC enable to prevent UAF. - Keep CRTC global enable bit intact during plane disable to avoid hardware state desync. v2: - Add .prepare_fb callback to support implicit synchronization. - Add .atomic_check using drm_atomic_helper_check_plane_state() to validate hardware scaling/clipping constraints. - Implement arc_pgu_plane_atomic_disable() to stop DMA and clear buffer address register, preventing hardware DMA scanout UAF. drivers/gpu/drm/tiny/arcpgu.c | 194 +++++++++++++++++++++++++++------- 1 file changed, 156 insertions(+), 38 deletions(-) diff --git a/drivers/gpu/drm/tiny/arcpgu.c b/drivers/gpu/drm/tiny/arcpgu.c index c93d61ac0bb7..adda40692733 100644 --- a/drivers/gpu/drm/tiny/arcpgu.c +++ b/drivers/gpu/drm/tiny/arcpgu.c @@ -5,6 +5,8 @@ * Copyright (C) 2016 Synopsys, Inc. (www.synopsys.com) */ +#include "drm/drm_gem_atomic_helper.h" + #include #include @@ -23,6 +25,8 @@ #include #include #include +#include +#include #include #include #include @@ -52,13 +56,17 @@ struct arcpgu_drm_private { struct drm_device drm; void __iomem *regs; struct clk *clk; - struct drm_simple_display_pipe pipe; + struct drm_plane plane; + struct drm_crtc crtc; + struct drm_encoder encoder; struct drm_connector sim_conn; }; #define dev_to_arcpgu(x) container_of(x, struct arcpgu_drm_private, drm) -#define pipe_to_arcpgu_priv(x) container_of(x, struct arcpgu_drm_private, pipe) +#define crtc_to_arcpgu_priv(x) container_of(x, struct arcpgu_drm_private, crtc) + +#define plane_to_arcpgu(x) container_of(x, struct arcpgu_drm_private, plane) static inline void arc_pgu_write(struct arcpgu_drm_private *arcpgu, unsigned int reg, u32 value) @@ -115,14 +123,19 @@ static const u32 arc_pgu_supported_formats[] = { DRM_FORMAT_ARGB8888, }; -static void arc_pgu_set_pxl_fmt(struct arcpgu_drm_private *arcpgu) +static void arc_pgu_set_pxl_fmt(struct arcpgu_drm_private *arcpgu, + const struct drm_framebuffer *fb) { - const struct drm_framebuffer *fb = arcpgu->pipe.plane.state->fb; - uint32_t pixel_format = fb->format->format; + u32 pixel_format; u32 format = DRM_FORMAT_INVALID; int i; u32 reg_ctrl; + if (!fb) + return; + + pixel_format = fb->format->format; + for (i = 0; i < ARRAY_SIZE(arc_pgu_supported_formats); i++) { if (arc_pgu_supported_formats[i] == pixel_format) format = arc_pgu_supported_formats[i]; @@ -139,10 +152,10 @@ static void arc_pgu_set_pxl_fmt(struct arcpgu_drm_private *arcpgu) arc_pgu_write(arcpgu, ARCPGU_REG_CTRL, reg_ctrl); } -static enum drm_mode_status arc_pgu_mode_valid(struct drm_simple_display_pipe *pipe, - const struct drm_display_mode *mode) +static enum drm_mode_status arc_pgu_crtc_mode_valid(struct drm_crtc *crtc, + const struct drm_display_mode *mode) { - struct arcpgu_drm_private *arcpgu = pipe_to_arcpgu_priv(pipe); + struct arcpgu_drm_private *arcpgu = crtc_to_arcpgu_priv(crtc); long rate, clk_rate = mode->clock * 1000; long diff = clk_rate / 200; /* +-0.5% allowed by HDMI spec */ @@ -153,9 +166,10 @@ static enum drm_mode_status arc_pgu_mode_valid(struct drm_simple_display_pipe *p return MODE_NOCLOCK; } -static void arc_pgu_mode_set(struct arcpgu_drm_private *arcpgu) +static void arc_pgu_mode_set(struct arcpgu_drm_private *arcpgu, + const struct drm_framebuffer *fb) { - struct drm_display_mode *m = &arcpgu->pipe.crtc.state->adjusted_mode; + struct drm_display_mode *m = &arcpgu->crtc.state->adjusted_mode; u32 val; arc_pgu_write(arcpgu, ARCPGU_REG_FMT, @@ -189,54 +203,133 @@ static void arc_pgu_mode_set(struct arcpgu_drm_private *arcpgu) arc_pgu_write(arcpgu, ARCPGU_REG_STRIDE, 0); arc_pgu_write(arcpgu, ARCPGU_REG_START_SET, 1); - arc_pgu_set_pxl_fmt(arcpgu); + arc_pgu_set_pxl_fmt(arcpgu, fb); clk_set_rate(arcpgu->clk, m->crtc_clock * 1000); } -static void arc_pgu_enable(struct drm_simple_display_pipe *pipe, - struct drm_crtc_state *crtc_state, - struct drm_plane_state *plane_state) +static void arc_pgu_crtc_atomic_enable(struct drm_crtc *crtc, + struct drm_atomic_commit *state) { - struct arcpgu_drm_private *arcpgu = pipe_to_arcpgu_priv(pipe); + struct arcpgu_drm_private *arcpgu = crtc_to_arcpgu_priv(crtc); + struct drm_plane_state *plane_state = + drm_atomic_get_new_plane_state(state, &arcpgu->plane); + const struct drm_framebuffer *fb = plane_state ? plane_state->fb : NULL; - arc_pgu_mode_set(arcpgu); + arc_pgu_mode_set(arcpgu, fb); clk_prepare_enable(arcpgu->clk); arc_pgu_write(arcpgu, ARCPGU_REG_CTRL, arc_pgu_read(arcpgu, ARCPGU_REG_CTRL) | - ARCPGU_CTRL_ENABLE_MASK); + ARCPGU_CTRL_ENABLE_MASK); } -static void arc_pgu_disable(struct drm_simple_display_pipe *pipe) +static void arc_pgu_crtc_atomic_disable(struct drm_crtc *crtc, + struct drm_atomic_commit *state) { - struct arcpgu_drm_private *arcpgu = pipe_to_arcpgu_priv(pipe); + struct arcpgu_drm_private *arcpgu = crtc_to_arcpgu_priv(crtc); clk_disable_unprepare(arcpgu->clk); arc_pgu_write(arcpgu, ARCPGU_REG_CTRL, - arc_pgu_read(arcpgu, ARCPGU_REG_CTRL) & - ~ARCPGU_CTRL_ENABLE_MASK); + arc_pgu_read(arcpgu, ARCPGU_REG_CTRL) & + ~ARCPGU_CTRL_ENABLE_MASK); } -static void arc_pgu_update(struct drm_simple_display_pipe *pipe, - struct drm_plane_state *state) +static void arc_pgu_plane_atomic_update(struct drm_plane *plane, + struct drm_atomic_commit *state) { - struct arcpgu_drm_private *arcpgu; + struct arcpgu_drm_private *arcpgu = plane_to_arcpgu(plane); + struct drm_plane_state *new_plane_state = drm_atomic_get_new_plane_state(state, plane); struct drm_gem_dma_object *gem; - if (!pipe->plane.state->fb) + if (!new_plane_state->fb) return; - arcpgu = pipe_to_arcpgu_priv(pipe); - gem = drm_fb_dma_get_gem_obj(pipe->plane.state->fb, 0); + gem = drm_fb_dma_get_gem_obj(new_plane_state->fb, 0); arc_pgu_write(arcpgu, ARCPGU_REG_BUF0_ADDR, gem->dma_addr); } -static const struct drm_simple_display_pipe_funcs arc_pgu_pipe_funcs = { - .update = arc_pgu_update, - .mode_valid = arc_pgu_mode_valid, - .enable = arc_pgu_enable, - .disable = arc_pgu_disable, +static void arc_pgu_plane_atomic_disable(struct drm_plane *plane, + struct drm_atomic_commit *state) +{ + struct arcpgu_drm_private *arcpgu = plane_to_arcpgu(plane); + + arc_pgu_write(arcpgu, ARCPGU_REG_BUF0_ADDR, 0); +} + +static int arc_pgu_plane_atomic_check(struct drm_plane *plane, + struct drm_atomic_commit *state) +{ + struct drm_plane_state *new_plane_state = drm_atomic_get_new_plane_state(state, plane); + struct drm_crtc_state *crtc_state; + + if (!new_plane_state->crtc) + return 0; + + crtc_state = drm_atomic_get_new_crtc_state(state, new_plane_state->crtc); + if (!crtc_state) + return -EINVAL; + + return drm_atomic_helper_check_plane_state(new_plane_state, crtc_state, + DRM_PLANE_NO_SCALING, + DRM_PLANE_NO_SCALING, + false, true); +} + +static int arc_pgu_crtc_atomic_check(struct drm_crtc *crtc, + struct drm_atomic_commit *state) +{ + struct drm_crtc_state *crct_state = drm_atomic_get_new_crtc_state(state, crtc); + struct arcpgu_drm_private *arcpgu = crtc_to_arcpgu_priv(crtc); + struct drm_plane_state *plane_state; + + if (!crct_state->enable) + return 0; + + plane_state = drm_atomic_get_new_plane_state(state, &arcpgu->plane); + if (IS_ERR(plane_state)) + return PTR_ERR(plane_state); + + if (!plane_state->fb) + return -EINVAL; + + return 0; +} + +static const struct drm_crtc_helper_funcs arc_pgu_crtc_helper_funcs = { + .mode_valid = arc_pgu_crtc_mode_valid, + .atomic_enable = arc_pgu_crtc_atomic_enable, + .atomic_disable = arc_pgu_crtc_atomic_disable, + .atomic_check = arc_pgu_crtc_atomic_check, +}; + +static const struct drm_crtc_funcs arc_pgu_crtc_funcs = { + .reset = drm_atomic_helper_crtc_reset, + .destroy = drm_crtc_cleanup, + .set_config = drm_atomic_helper_set_config, + .page_flip = drm_atomic_helper_page_flip, + .atomic_duplicate_state = drm_atomic_helper_crtc_duplicate_state, + .atomic_destroy_state = drm_atomic_helper_crtc_destroy_state, +}; + +static const struct drm_plane_helper_funcs arc_pgu_plane_helper_funcs = { + .atomic_update = arc_pgu_plane_atomic_update, + .prepare_fb = drm_gem_plane_helper_prepare_fb, + .atomic_check = arc_pgu_plane_atomic_check, + .atomic_disable = arc_pgu_plane_atomic_disable, +}; + +static const struct drm_plane_funcs arc_pgu_plane_funcs = { + .update_plane = drm_atomic_helper_update_plane, + .disable_plane = drm_atomic_helper_disable_plane, + .destroy = drm_plane_cleanup, + .reset = drm_atomic_helper_plane_reset, + .atomic_duplicate_state = drm_atomic_helper_plane_duplicate_state, + .atomic_destroy_state = drm_atomic_helper_plane_destroy_state, +}; + +static const struct drm_encoder_funcs arc_pgu_encoder_funcs = { + .destroy = drm_encoder_cleanup }; static const struct drm_mode_config_funcs arcpgu_drm_modecfg_funcs = { @@ -301,13 +394,38 @@ static int arcpgu_load(struct arcpgu_drm_private *arcpgu) return ret; } - ret = drm_simple_display_pipe_init(drm, &arcpgu->pipe, &arc_pgu_pipe_funcs, - arc_pgu_supported_formats, - ARRAY_SIZE(arc_pgu_supported_formats), - NULL, connector); + ret = drm_universal_plane_init(drm, &arcpgu->plane, 0, + &arc_pgu_plane_funcs, arc_pgu_supported_formats, + ARRAY_SIZE(arc_pgu_supported_formats), NULL, + DRM_PLANE_TYPE_PRIMARY, NULL); + + if (ret) + return ret; + + drm_plane_helper_add(&arcpgu->plane, &arc_pgu_plane_helper_funcs); + + ret = drm_crtc_init_with_planes(drm, &arcpgu->crtc, &arcpgu->plane, NULL, + &arc_pgu_crtc_funcs, NULL); + + if (ret) + return ret; + + drm_crtc_helper_add(&arcpgu->crtc, &arc_pgu_crtc_helper_funcs); + + ret = drm_encoder_init(drm, &arcpgu->encoder, &arc_pgu_encoder_funcs, + DRM_MODE_ENCODER_NONE, NULL); + if (ret) return ret; + arcpgu->encoder.possible_crtcs = drm_crtc_mask(&arcpgu->crtc); + + if (connector) { + ret = drm_connector_attach_encoder(connector, &arcpgu->encoder); + if (ret) + return ret; + } + if (encoder_node) { /* Locate drm bridge from the hdmi encoder DT node */ struct drm_bridge *bridge __free(drm_bridge_put) = @@ -315,7 +433,7 @@ static int arcpgu_load(struct arcpgu_drm_private *arcpgu) if (!bridge) return -EPROBE_DEFER; - ret = drm_simple_display_pipe_attach_bridge(&arcpgu->pipe, bridge); + ret = drm_bridge_attach(&arcpgu->encoder, bridge, NULL, 0); if (ret) return ret; } @@ -342,7 +460,7 @@ static int arcpgu_show_pxlclock(struct seq_file *m, void *arg) struct drm_device *drm = node->minor->dev; struct arcpgu_drm_private *arcpgu = dev_to_arcpgu(drm); unsigned long clkrate = clk_get_rate(arcpgu->clk); - unsigned long mode_clock = arcpgu->pipe.crtc.mode.crtc_clock * 1000; + unsigned long mode_clock = arcpgu->crtc.mode.crtc_clock * 1000; seq_printf(m, "hw : %lu\n", clkrate); seq_printf(m, "mode: %lu\n", mode_clock); -- 2.43.0