From 8d79506120821dfa98786f2bbab86376ab16c15d Mon Sep 17 00:00:00 2001 From: Nilesh Laad Date: Tue, 28 May 2024 13:26:09 +0530 Subject: [PATCH 01/16] disp: msm: dp: parse display_type before connector initialization dp_parser is only available post connector init, so if parser is not available get display_type from devicetree itself and remove redundant code. Change-Id: I2131a257cb4795f52be1706882dce533baf94600 Signed-off-by: Nilesh Laad --- msm/dp/dp_display.c | 7 ++++++- msm/dp/dp_drm.c | 10 ++++++---- msm/dp/dp_parser.c | 11 ++++------- 3 files changed, 16 insertions(+), 12 deletions(-) diff --git a/msm/dp/dp_display.c b/msm/dp/dp_display.c index 99ff3c7d1c74..788c43d1da2e 100644 --- a/msm/dp/dp_display.c +++ b/msm/dp/dp_display.c @@ -3919,6 +3919,7 @@ static int dp_display_get_display_type(struct dp_display *dp_display, const char **display_type) { struct dp_display_private *dp; + struct device_node *of_node; if (!dp_display || !display_type) { pr_err("invalid input\n"); @@ -3928,7 +3929,11 @@ static int dp_display_get_display_type(struct dp_display *dp_display, dp = container_of(dp_display, struct dp_display_private, dp_display); if (dp->parser) *display_type = dp->parser->display_type; - + else { + of_node = dp->pdev->dev.of_node; + *display_type = of_get_property(of_node, "qcom,display-type", + NULL); + } return 0; } diff --git a/msm/dp/dp_drm.c b/msm/dp/dp_drm.c index 6af98873cb38..ad90da674401 100644 --- a/msm/dp/dp_drm.c +++ b/msm/dp/dp_drm.c @@ -471,6 +471,7 @@ int dp_connector_get_info(struct drm_connector *connector, { struct dp_display *display = data; const char *display_type = NULL; + u32 conn_disp_type = SDE_CONNECTOR_PRIMARY; if (!info || !display || !display->drm_dev) { DP_ERR("invalid params\n"); @@ -480,11 +481,11 @@ int dp_connector_get_info(struct drm_connector *connector, info->intf_type = DRM_MODE_CONNECTOR_DisplayPort; display->get_display_type(display, &display_type); - if (display_type){ + if (display_type) { if (!strcmp(display_type, "primary")) - info->display_type = SDE_CONNECTOR_PRIMARY; + conn_disp_type = SDE_CONNECTOR_PRIMARY; else if (!strcmp(display_type, "secondary")) - info->display_type = SDE_CONNECTOR_SECONDARY; + conn_disp_type = SDE_CONNECTOR_SECONDARY; } info->num_of_h_tiles = 1; @@ -495,7 +496,8 @@ int dp_connector_get_info(struct drm_connector *connector, if (display && display->is_edp) { info->intf_type = DRM_MODE_CONNECTOR_eDP; - if(display->ext_hpd_en) + info->display_type = conn_disp_type; + if (display->ext_hpd_en) info->capabilities |= MSM_DISPLAY_CAP_HOT_PLUG; else info->is_connected = true; diff --git a/msm/dp/dp_parser.c b/msm/dp/dp_parser.c index ea5546ea476c..0a138bbe4a1d 100644 --- a/msm/dp/dp_parser.c +++ b/msm/dp/dp_parser.c @@ -178,13 +178,10 @@ static int dp_parser_misc(struct dp_parser *parser) &parser->pixel_base_off[i]); } - parser->display_type = of_get_property(of_node, "qcom,display-type", NULL); - if (!parser->display_type) { - if (parser->is_edp) - parser->display_type = "primary"; - else - parser->display_type = "secondary"; - } + parser->display_type = of_get_property(of_node, "qcom,display-type", + NULL); + if (!parser->display_type) + parser->display_type = "unknown"; parser->panel_notifier_support = of_property_read_bool(of_node, "qcom,panel-notifier-support"); From 52c920054b2cb07d8df4b6e36e4b489ad9d6e348 Mon Sep 17 00:00:00 2001 From: Zeyuan Lu Date: Wed, 11 Sep 2024 17:56:14 +0800 Subject: [PATCH 02/16] disp: config :disable CONFIG_DSI_PARSER for kodiak Disable dsi firmware support on kodiak Change-Id: I223c5ac9c1c7f136137a115f844e5e75c01e433c Signed-off-by: Zeyuan Lu --- config/lahainadisp.conf | 2 +- config/lahainadispconf.h | 3 +-- 2 files changed, 2 insertions(+), 3 deletions(-) diff --git a/config/lahainadisp.conf b/config/lahainadisp.conf index d413be39445f..953a3ef338f8 100644 --- a/config/lahainadisp.conf +++ b/config/lahainadisp.conf @@ -4,7 +4,7 @@ export CONFIG_DRM_MSM_DP=y export CONFIG_DRM_MSM_DP_MST=y export CONFIG_SYNC_FILE=y export CONFIG_DRM_MSM_DSI=y -export CONFIG_DSI_PARSER=y +export CONFIG_DSI_PARSER=n export CONFIG_DRM_SDE_WB=y export CONFIG_DRM_MSM_REGISTER_LOGGING=y export CONFIG_QCOM_MDSS_PLL=y diff --git a/config/lahainadispconf.h b/config/lahainadispconf.h index e72e0a43f1ab..379c456689c8 100644 --- a/config/lahainadispconf.h +++ b/config/lahainadispconf.h @@ -1,6 +1,6 @@ /* SPDX-License-Identifier: GPL-2.0-only */ /* - * Copyright (c) 2020, The Linux Foundation. All rights reserved. + * Copyright (c) 2020, 2024 The Linux Foundation. All rights reserved. */ #define CONFIG_DRM_MSM 1 @@ -9,7 +9,6 @@ #define CONFIG_DRM_MSM_SDE 1 #define CONFIG_SYNC_FILE 1 #define CONFIG_DRM_MSM_DSI 1 -#define CONFIG_DSI_PARSER 1 #define CONFIG_DRM_SDE_WB 1 #define CONFIG_DRM_MSM_REGISTER_LOGGING 1 #define CONFIG_DRM_SDE_EVTLOG_DEBUG 1 From c8f3df8ea4a8674e41969fd0cacabcdfc2facfa1 Mon Sep 17 00:00:00 2001 From: Jinfeng Gu Date: Thu, 22 Aug 2024 15:51:37 +0800 Subject: [PATCH 03/16] disp: msm: dsi: add null pointer check in dsi_display_dev_remove This change add display null pointer check in dsi_display_dev_remove. Change-Id: Ib31756c3b22256d19cbcb508f60de4550e3834e1 Signed-off-by: Jinfeng Gu --- msm/dsi/dsi_display.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/msm/dsi/dsi_display.c b/msm/dsi/dsi_display.c index b75c465340b0..6962049ee8fb 100644 --- a/msm/dsi/dsi_display.c +++ b/msm/dsi/dsi_display.c @@ -6131,6 +6131,10 @@ int dsi_display_dev_remove(struct platform_device *pdev) } display = platform_get_drvdata(pdev); + if (!display || !display->panel_node) { + DSI_ERR("invalid display\n"); + return -EINVAL; + } /* decrement ref count */ of_node_put(display->panel_node); From 94e81e5d2da5953d468542b58feaf0c796413f81 Mon Sep 17 00:00:00 2001 From: Vikas Reddy Pachika Date: Wed, 9 Oct 2024 17:33:19 +0530 Subject: [PATCH 04/16] disp: msm: dsi: fix error path for dsi_display init Handle dsi_display init errors with proper de-init sequence. Change-Id: I7d029980a06c8069264c3b1b2b7a6cdb781e1198 Signed-off-by: Deven Solanki Signed-off-by: Vikas Reddy Pachika --- msm/dsi/dsi_display.c | 16 +++++++++++++--- 1 file changed, 13 insertions(+), 3 deletions(-) diff --git a/msm/dsi/dsi_display.c b/msm/dsi/dsi_display.c index 6962049ee8fb..91682051c5e2 100644 --- a/msm/dsi/dsi_display.c +++ b/msm/dsi/dsi_display.c @@ -1,6 +1,6 @@ // SPDX-License-Identifier: GPL-2.0-only /* - * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. * Copyright (c) 2016-2021, The Linux Foundation. All rights reserved. */ @@ -5971,15 +5971,25 @@ static int dsi_display_init(struct dsi_display *display) if (rc) { DSI_ERR("[%s] failed to enable vregs, rc=%d\n", display->panel->name, rc); - return rc; + goto vreg_fail; } } rc = component_add(&pdev->dev, &dsi_display_comp_ops); - if (rc) + if (rc) { DSI_ERR("component add failed, rc=%d\n", rc); + goto comp_add_fail; + } DSI_DEBUG("component add success: %s\n", display->name); + return rc; + +comp_add_fail: + if (display->panel) + dsi_pwr_enable_regulator(&display->panel->power_info, false); +vreg_fail: + _dsi_display_dev_deinit(display); + end: return rc; } From a74ffcf33b62a7219f0cfbcf5386b236a3714411 Mon Sep 17 00:00:00 2001 From: Vikas Reddy Pachika Date: Fri, 11 Oct 2024 11:33:14 +0530 Subject: [PATCH 05/16] disp: config: fix copyright marking for lahaina config Add qcom license for lahainadispconf.h. Change-Id: I7048ca710377655c80b14213f1897256074fa2b8 Signed-off-by: Vikas Reddy Pachika --- config/lahainadispconf.h | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/config/lahainadispconf.h b/config/lahainadispconf.h index 379c456689c8..3a0210956e2a 100644 --- a/config/lahainadispconf.h +++ b/config/lahainadispconf.h @@ -1,6 +1,7 @@ /* SPDX-License-Identifier: GPL-2.0-only */ /* - * Copyright (c) 2020, 2024 The Linux Foundation. All rights reserved. + * Copyright (c) 2020 The Linux Foundation. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. */ #define CONFIG_DRM_MSM 1 From 2ca80154816040f2d72ad47bc21b08d499496fab Mon Sep 17 00:00:00 2001 From: Vikas Reddy Pachika Date: Fri, 11 Oct 2024 11:33:14 +0530 Subject: [PATCH 06/16] disp: config: fix copyright marking for lahaina config Add qcom license for lahainadispconf.h. Change-Id: I7048ca710377655c80b14213f1897256074fa2b8 Signed-off-by: Vikas Reddy Pachika (cherry picked from commit a74ffcf33b62a7219f0cfbcf5386b236a3714411) --- config/lahainadispconf.h | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/config/lahainadispconf.h b/config/lahainadispconf.h index 379c456689c8..3a0210956e2a 100644 --- a/config/lahainadispconf.h +++ b/config/lahainadispconf.h @@ -1,6 +1,7 @@ /* SPDX-License-Identifier: GPL-2.0-only */ /* - * Copyright (c) 2020, 2024 The Linux Foundation. All rights reserved. + * Copyright (c) 2020 The Linux Foundation. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. */ #define CONFIG_DRM_MSM 1 From dbebbf294b54764127b568c9d64dbcdd98cd5831 Mon Sep 17 00:00:00 2001 From: Venkata Gopi Nagaraju Botlagunta Date: Fri, 3 Jun 2022 16:56:04 +0530 Subject: [PATCH 07/16] disp: msm: dsi: add support for hibernation Set parent to xo clock for link clocks, before we enter suspend, so that framework and hw state are in correct state, when we exit from hibernation. Change-Id: Ib0e2ca6ac57aec566171b2f72e2b6822e2d9fde2 Signed-off-by: Venkata Gopi Nagaraju Botlagunta --- msm/dsi/dsi_display.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/msm/dsi/dsi_display.c b/msm/dsi/dsi_display.c index 91682051c5e2..38c478f94641 100644 --- a/msm/dsi/dsi_display.c +++ b/msm/dsi/dsi_display.c @@ -2716,7 +2716,7 @@ error: return rc; } -#ifdef CONFIG_DEEPSLEEP +#if defined (CONFIG_DEEPSLEEP) || defined (CONFIG_HIBERNATION) int dsi_display_unset_clk_src(struct dsi_display *display) { int rc = 0; From b19d4a3a8e2d7f34a57aefb386ed56327b608def Mon Sep 17 00:00:00 2001 From: Jayasri Sampath Kumaran Date: Wed, 28 Aug 2024 15:46:09 -0400 Subject: [PATCH 08/16] disp: msm: sde: fix kms NULL pointer access in encoder IRQ control A possible kms NULL pointer access is found during CPU vote for IRQ when kms isn't NULL checked before accessing structure members. So, perform kms NULL check before accessing members. Change-Id: I137759ea0723be8580e9166c983d1ba38f4eb281 Signed-off-by: Jayasri Sampath Kumaran (cherry picked from commit 393118f87846d64a10c1d5a32161bcbe012c0667) (cherry picked from commit 17513cad23c67a11431fdfd77a59d5e207352dbc) --- msm/sde/sde_encoder.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/msm/sde/sde_encoder.c b/msm/sde/sde_encoder.c index d2c54c99ab14..5a4006468a59 100644 --- a/msm/sde/sde_encoder.c +++ b/msm/sde/sde_encoder.c @@ -1434,6 +1434,7 @@ static int _sde_encoder_update_rsc_client( void sde_encoder_irq_control(struct drm_encoder *drm_enc, bool enable) { struct sde_encoder_virt *sde_enc; + struct sde_kms *sde_kms = NULL; int i; if (!drm_enc) { @@ -1441,6 +1442,12 @@ void sde_encoder_irq_control(struct drm_encoder *drm_enc, bool enable) return; } + sde_kms = sde_encoder_get_kms(drm_enc); + if (!sde_kms) { + SDE_ERROR("invalid kms\n"); + return; + } + sde_enc = to_sde_encoder_virt(drm_enc); SDE_DEBUG_ENC(sde_enc, "enable:%d\n", enable); @@ -1450,7 +1457,7 @@ void sde_encoder_irq_control(struct drm_encoder *drm_enc, bool enable) if (phys && phys->ops.irq_control) phys->ops.irq_control(phys, enable); } - sde_kms_cpu_vote_for_irq(sde_encoder_get_kms(drm_enc), enable); + sde_kms_cpu_vote_for_irq(sde_kms, enable); } From 95cae124f2d96e55b0af317f90ff68d292490660 Mon Sep 17 00:00:00 2001 From: Prahlad Valluru Date: Thu, 8 May 2025 12:08:42 +0530 Subject: [PATCH 09/16] disp: msm: dp: handle panel_init when host is ready Currently, panel_init is getting executed even when host is already ready. Handle panel_init such that it will be called only as part of host ready. Handle continuous splash case as well. Change-Id: Id022fed099e1e1a87282c58bead839e68f502098 Signed-off-by: Nilesh Laad Signed-off-by: Prahlad Valluru --- msm/dp/dp_display.c | 9 ++++++--- msm/dp/dp_panel.c | 7 +++++-- msm/dp/dp_panel.h | 4 ++-- 3 files changed, 13 insertions(+), 7 deletions(-) diff --git a/msm/dp/dp_display.c b/msm/dp/dp_display.c index 788c43d1da2e..2655f9d236d7 100644 --- a/msm/dp/dp_display.c +++ b/msm/dp/dp_display.c @@ -1,6 +1,6 @@ // SPDX-License-Identifier: GPL-2.0-only /* - * Copyright (c) 2023-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2023-2025 Qualcomm Innovation Center, Inc. All rights reserved. * Copyright (c) 2017-2021, The Linux Foundation. All rights reserved. */ @@ -1185,6 +1185,7 @@ error_ctrl: static int dp_display_panel_ready(struct dp_display_private *dp) { int rc = 0; + bool skip_op = is_skip_required(&dp->dp_display); if (dp->dp_display.is_edp) { rc = dp->power->edp_panel_set_gpio(dp->power, DP_GPIO_EDP_VCC_EN, true); @@ -1202,9 +1203,9 @@ static int dp_display_panel_ready(struct dp_display_private *dp) } return -ETIMEDOUT; } + + dp->panel->init(dp->panel, skip_op); } - if (!dp->dp_display.cont_splash_enabled) - dp->panel->init(dp->panel); return 0; } @@ -1248,6 +1249,8 @@ static int dp_display_host_ready(struct dp_display_private *dp) dp->ctrl->abort(dp->ctrl, false); dp->aux->init(dp->aux, dp->parser->aux_cfg, skip_op); + dp->panel->init(dp->panel, skip_op); + dp_display_state_add(DP_STATE_READY); /* log this as it results from user action of cable connection */ DP_INFO("[OK]\n"); diff --git a/msm/dp/dp_panel.c b/msm/dp/dp_panel.c index 8fc1b13c3e32..a9f65f1aba8c 100644 --- a/msm/dp/dp_panel.c +++ b/msm/dp/dp_panel.c @@ -1,6 +1,6 @@ // SPDX-License-Identifier: GPL-2.0-only /* - * Copyright (c) 2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2023, 2025 Qualcomm Innovation Center, Inc. All rights reserved. * Copyright (c) 2012-2021, The Linux Foundation. All rights reserved. */ @@ -2381,7 +2381,7 @@ error: return rc; } -static int dp_panel_init_panel_info(struct dp_panel *dp_panel) +static int dp_panel_init_panel_info(struct dp_panel *dp_panel, bool skip_op) { int rc = 0; struct dp_panel_private *panel; @@ -2393,6 +2393,9 @@ static int dp_panel_init_panel_info(struct dp_panel *dp_panel) goto end; } + if (skip_op) + goto end; + panel = container_of(dp_panel, struct dp_panel_private, dp_panel); pinfo = &dp_panel->pinfo; diff --git a/msm/dp/dp_panel.h b/msm/dp/dp_panel.h index 3abb41297584..206b62dc32c7 100644 --- a/msm/dp/dp_panel.h +++ b/msm/dp/dp_panel.h @@ -1,6 +1,6 @@ /* SPDX-License-Identifier: GPL-2.0-only */ /* - * Copyright (c) 2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2023, 2025 Qualcomm Innovation Center, Inc. All rights reserved. * Copyright (c) 2012-2020, The Linux Foundation. All rights reserved. */ @@ -162,7 +162,7 @@ struct dp_panel { s64 fec_overhead_fp; - int (*init)(struct dp_panel *dp_panel); + int (*init)(struct dp_panel *dp_panel, bool skip_op); int (*deinit)(struct dp_panel *dp_panel, u32 flags); int (*hw_cfg)(struct dp_panel *dp_panel, bool enable); int (*read_sink_caps)(struct dp_panel *dp_panel, From b749468a5add48e9f20fd3913dbae9243e2bb035 Mon Sep 17 00:00:00 2001 From: Gopi Botlagunta Date: Thu, 17 Apr 2025 18:23:49 +0530 Subject: [PATCH 10/16] disp: msm: sde: get_modes from connector if not present In case of external bridges, modes are not available for setting splash_mode. Add support to get modes supported by the external bridges. Change-Id: Ib17e17bcf1ec91b582da2e0cf5d648b9c366b292 Signed-off-by: Gopi Botlagunta --- msm/sde/sde_kms.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/msm/sde/sde_kms.c b/msm/sde/sde_kms.c index 43c436d6ba3a..7dfad7d8d194 100644 --- a/msm/sde/sde_kms.c +++ b/msm/sde/sde_kms.c @@ -3489,11 +3489,20 @@ static int sde_kms_cont_splash_config(struct msm_kms *kms, mutex_unlock(&dev->mode_config.mutex); return -EINVAL; } - mutex_unlock(&dev->mode_config.mutex); crtc->state->encoder_mask = (1 << drm_encoder_index(encoder)); + /* get supported modes in case of external bridge panels*/ + if (!dsi_display->panel->num_timing_nodes) { + connector->funcs->fill_modes(connector, + dev->mode_config.max_width, + dev->mode_config.max_height); + drm_mode = list_first_entry(&connector->modes, + struct drm_display_mode, head); + } + else + drm_mode = _sde_kms_get_splash_mode(sde_kms, connector, state); - drm_mode = _sde_kms_get_splash_mode(sde_kms, connector, state); + mutex_unlock(&dev->mode_config.mutex); if (!drm_mode) { SDE_ERROR("drm_mode not found; handoff_type:%d\n", sde_kms->splash_data.type); From e5fdc7822ba1274a16742d727e47b14d8c56d835 Mon Sep 17 00:00:00 2001 From: Vishnu Saini Date: Thu, 16 Oct 2025 11:56:23 +0530 Subject: [PATCH 11/16] disp: msm: sde: fix splash resource cleanup for edp Currently, splash_display->encoder is invalid for edp so _sde_kms_release_splash_resource is not releasing the resources. ea245e79821 ("disp: msm: sde: Remove pm vote at time of handoff") partially addressing the issue, but _sde_kms_free_splash_display_data is not called, resulting in smmu mapping not freed. Since iommu framework is not aware of this direct mapping through smmu so any allocations to this iova will fail due to this existing mapping, resulting in mapping and commit failures. Populate splash_display for edp so that cleanup of splash region is proper and revert ea245e79821, which is no longer needed. Change-Id: I5bd2b0d5996f0f91e4b0cf1e4f78e03feee4afe4 Signed-off-by: Vishnu Saini --- msm/sde/sde_kms.c | 29 ++++++++++++++++------------- 1 file changed, 16 insertions(+), 13 deletions(-) diff --git a/msm/sde/sde_kms.c b/msm/sde/sde_kms.c index 7dfad7d8d194..5dd01e54989d 100644 --- a/msm/sde/sde_kms.c +++ b/msm/sde/sde_kms.c @@ -1,5 +1,5 @@ /* - * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * Copyright (c) 2014-2021, The Linux Foundation. All rights reserved. * Copyright (C) 2013 Red Hat * Author: Rob Clark @@ -1255,16 +1255,6 @@ static void _sde_kms_release_splash_resource(struct sde_kms *sde_kms, SDE_EVT32(DRMID(crtc), crtc->state->active, sde_kms->splash_data.num_splash_displays); - /*remove all votes if eDP displays are done with splash*/ - if (dp_display_get_num_of_boot_displays()) { - for (i = 0; i < SDE_POWER_HANDLE_DBUS_ID_MAX; i++) - sde_power_data_bus_set_quota(phandle, i, - SDE_POWER_HANDLE_ENABLE_BUS_AB_QUOTA, - phandle->ib_quota[i]); - pm_runtime_put_sync(sde_kms->dev->dev); - sde_kms->splash_data.num_splash_displays--; - } - for (i = 0; i < MAX_DSI_DISPLAYS; i++) { splash_display = &sde_kms->splash_data.splash_display[i]; if (splash_display->encoder && @@ -3385,7 +3375,7 @@ static int sde_kms_cont_splash_config(struct msm_kms *kms, struct msm_display_info info; struct drm_encoder *encoder = NULL; struct drm_crtc *crtc = NULL; - int i, rc = 0; + int i, rc = 0, splash_index = 0; struct drm_display_mode *drm_mode = NULL; struct drm_device *dev; struct msm_drm_private *priv; @@ -3423,7 +3413,7 @@ static int sde_kms_cont_splash_config(struct msm_kms *kms, DRM_INFO("cont_splash enabled in %d of %d display(s)\n", sde_kms->splash_data.num_splash_displays, - sde_kms->dsi_display_count); + sde_kms->dsi_display_count + sde_kms->dp_display_count); /* dsi */ for (i = 0; i < sde_kms->dsi_display_count; ++i) { @@ -3559,6 +3549,19 @@ static int sde_kms_cont_splash_config(struct msm_kms *kms, break; } + splash_display = &sde_kms->splash_data.splash_display[splash_index]; + if (splash_display->cont_splash_enabled) { + priv = sde_kms->dev->dev_private; + encoder->crtc = priv->crtcs[splash_index]; + splash_display->encoder = encoder; + + SDE_DEBUG("dp-display:%d splash_index:%d crtc id[%d]:%d enc id[%d]:%d\n", + i, splash_index, encoder->crtc->index, encoder->crtc->base.id, + encoder->index, encoder->base.id); + + splash_index++; + } + mutex_lock(&dev->mode_config.mutex); drm_connector_list_iter_begin(dev, &conn_iter); drm_for_each_connector_iter(connector, &conn_iter) { From 6bbef66ce393adf4515b9ce14f0c63568d54526c Mon Sep 17 00:00:00 2001 From: yadwan Date: Tue, 29 Jul 2025 11:04:00 +0800 Subject: [PATCH 12/16] disp: msm: sde: Add change to fix slab out of bounds Non null terminated string from user space can cause out of bound access issue. Hence added a NULL character explicitly in name when received from user space. Change-Id: I6d498f16a59ec2832ddc0951952101859666eacf Signed-off-by: yadwan (cherry picked from commit 7eb70ce3648b8eb8e5340b0bf3c5bb3a7605d811) --- msm/sde/sde_wb.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/msm/sde/sde_wb.c b/msm/sde/sde_wb.c index dcb308fabf84..d6648ad7e2fc 100644 --- a/msm/sde/sde_wb.c +++ b/msm/sde/sde_wb.c @@ -204,6 +204,8 @@ int sde_wb_connector_set_modes(struct sde_wb_device *wb_dev, memset(&dispmode, 0, sizeof(dispmode)); ret = drm_mode_convert_umode(wb_dev->drm_dev, &dispmode, &modeinfo[i]); + /* null terminate the string */ + modeinfo[i].name[DRM_DISPLAY_MODE_LEN - 1] = '\0'; if (ret) { SDE_ERROR( "failed to convert mode %d:\"%s\" %d %d %d %d %d %d %d %d %d %d 0x%x 0x%x status:%d rc:%d\n", From df717747fdf18d12fa0606b64d77b1d8db9c1d08 Mon Sep 17 00:00:00 2001 From: Harini Manikumar Date: Thu, 4 Sep 2025 17:27:06 +0530 Subject: [PATCH 13/16] msm: smmu: Unregister SMMU fault handler before cleanup IOMMU fault handler can be invoked post SMMU destroy which can lead to use-after-free issue. Unregister the SMMU fault handler before freeing SMMU context and unregistering the platform device. Change-Id: I1cddd4a381f16d650258850a3d012d380fbe5ef8 Signed-off-by: Harini Manikumar Signed-off-by: Karthik Veeranki --- msm/msm_smmu.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/msm/msm_smmu.c b/msm/msm_smmu.c index 53f5f926560a..af9ba0ba87f5 100644 --- a/msm/msm_smmu.c +++ b/msm/msm_smmu.c @@ -1,4 +1,5 @@ /* + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * Copyright (c) 2015-2020, The Linux Foundation. All rights reserved. * Copyright (C) 2013 Red Hat * Author: Rob Clark @@ -211,6 +212,10 @@ static void msm_smmu_destroy(struct msm_mmu *mmu) { struct msm_smmu *smmu = to_msm_smmu(mmu); struct platform_device *pdev = to_platform_device(smmu->client_dev); + struct iommu_domain *domain = iommu_get_domain_for_dev(smmu->client_dev); + + if (domain) + iommu_set_fault_handler(domain, NULL, NULL); if (smmu->client_dev) platform_device_unregister(pdev); From 13fa1e24012c0d7e1c98874aa3abe8908c67714d Mon Sep 17 00:00:00 2001 From: Arpit Saini Date: Fri, 10 Oct 2025 16:44:16 +0530 Subject: [PATCH 14/16] disp: msm: dsi: Fix potential data race in ctrl isr Use atomic operations for shared variables to ensure safe concurrent access from both ISR and task context. Change-Id: I72a235007f0b36553f436a900a3e9a91afcd75a4 Signed-off-by: Arpit Saini --- msm/dsi/dsi_ctrl.c | 21 ++++++++++++++------- msm/dsi/dsi_ctrl.h | 8 ++++++-- 2 files changed, 20 insertions(+), 9 deletions(-) diff --git a/msm/dsi/dsi_ctrl.c b/msm/dsi/dsi_ctrl.c index 278e3dcbe921..122fb10c18a5 100644 --- a/msm/dsi/dsi_ctrl.c +++ b/msm/dsi/dsi_ctrl.c @@ -1,7 +1,7 @@ // SPDX-License-Identifier: GPL-2.0-only /* * Copyright (c) 2016-2021, The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. */ #include @@ -229,10 +229,10 @@ static ssize_t debugfs_line_count_read(struct file *file, dsi_ctrl->cmd_trigger_frame); len += scnprintf((buf + len), max_len - len, "Command successful at line: %04x\n", - dsi_ctrl->cmd_success_line); + atomic_read(&dsi_ctrl->cmd_success_line)); len += scnprintf((buf + len), max_len - len, "Command successful at frame: %04x\n", - dsi_ctrl->cmd_success_frame); + atomic_read(&dsi_ctrl->cmd_success_frame)); mutex_unlock(&dsi_ctrl->ctrl_lock); @@ -2889,14 +2889,20 @@ static irqreturn_t dsi_ctrl_isr(int irq, void *ptr) if (status & DSI_CMD_MODE_DMA_DONE) { if (dsi_ctrl->enable_cmd_dma_stats) { - u32 reg = dsi_ctrl->hw.ops.log_line_count(&dsi_ctrl->hw, - dsi_ctrl->cmd_mode); - dsi_ctrl->cmd_success_line = (reg & 0xFFFF); - dsi_ctrl->cmd_success_frame = ((reg >> 16) & 0xFFFF); + if (dsi_ctrl->hw.ops.log_line_count[dsi_ctrl->disp_op]) + reg = + dsi_ctrl->hw.ops.log_line_count[dsi_ctrl->disp_op](&dsi_ctrl->hw, + dsi_ctrl->cmd_mode); + else + reg = 0; + atomic_set(&dsi_ctrl->cmd_success_line, (reg & 0xFFFF)); + atomic_set(&dsi_ctrl->cmd_success_frame, ((reg >> 16) & 0xFFFF)); SDE_EVT32(dsi_ctrl->cell_index, SDE_EVTLOG_FUNC_CASE1, dsi_ctrl->cmd_success_line, dsi_ctrl->cmd_success_frame); } + + atomic64_set(&dsi_ctrl->cmd_success_ts, ktime_get()); atomic_set(&dsi_ctrl->dma_irq_trig, 1); dsi_ctrl_disable_status_interrupt(dsi_ctrl, DSI_SINT_CMD_MODE_DMA_DONE); @@ -3481,6 +3487,7 @@ int dsi_ctrl_cmd_transfer(struct dsi_ctrl *dsi_ctrl, rc); } + cmd->ts = atomic64_read(&dsi_ctrl->cmd_success_ts); dsi_ctrl_update_state(dsi_ctrl, DSI_CTRL_OP_CMD_TX, 0x0); error: diff --git a/msm/dsi/dsi_ctrl.h b/msm/dsi/dsi_ctrl.h index a3290750520b..f66be7fb6b70 100644 --- a/msm/dsi/dsi_ctrl.h +++ b/msm/dsi/dsi_ctrl.h @@ -1,5 +1,6 @@ /* SPDX-License-Identifier: GPL-2.0-only */ /* + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * Copyright (c) 2015-2020, The Linux Foundation. All rights reserved. */ @@ -309,8 +310,11 @@ struct dsi_ctrl { bool cmd_mode; u32 cmd_trigger_line; u32 cmd_trigger_frame; - u32 cmd_success_line; - u32 cmd_success_frame; + atomic_t cmd_success_line; + atomic_t cmd_success_frame; + u32 cmd_engine_refcount; + u32 pending_cmd_flags; + atomic64_t cmd_success_ts; }; /** From df582cc15abb460d6fa57c0f183488b3db673afe Mon Sep 17 00:00:00 2001 From: Gopi Botlagunta Date: Wed, 7 Jan 2026 15:37:06 +0530 Subject: [PATCH 15/16] disp: msm: dsi: Fix potential data race in ctrl isr Use atomic operations for shared variables to ensure safe concurrent access from both ISR and task context. Change-Id: I02d4bde88692d0be7027b158648a3ab8a5704b2d Signed-off-by: Gopi Botlagunta --- msm/dsi/dsi_ctrl.c | 10 +++++----- msm/dsi/dsi_ctrl.h | 5 +++-- 2 files changed, 8 insertions(+), 7 deletions(-) diff --git a/msm/dsi/dsi_ctrl.c b/msm/dsi/dsi_ctrl.c index 278e3dcbe921..5dc027912f13 100644 --- a/msm/dsi/dsi_ctrl.c +++ b/msm/dsi/dsi_ctrl.c @@ -1,7 +1,7 @@ // SPDX-License-Identifier: GPL-2.0-only /* * Copyright (c) 2016-2021, The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. */ #include @@ -229,10 +229,10 @@ static ssize_t debugfs_line_count_read(struct file *file, dsi_ctrl->cmd_trigger_frame); len += scnprintf((buf + len), max_len - len, "Command successful at line: %04x\n", - dsi_ctrl->cmd_success_line); + atomic_read(&dsi_ctrl->cmd_success_line)); len += scnprintf((buf + len), max_len - len, "Command successful at frame: %04x\n", - dsi_ctrl->cmd_success_frame); + atomic_read(&dsi_ctrl->cmd_success_frame)); mutex_unlock(&dsi_ctrl->ctrl_lock); @@ -2891,8 +2891,8 @@ static irqreturn_t dsi_ctrl_isr(int irq, void *ptr) if (dsi_ctrl->enable_cmd_dma_stats) { u32 reg = dsi_ctrl->hw.ops.log_line_count(&dsi_ctrl->hw, dsi_ctrl->cmd_mode); - dsi_ctrl->cmd_success_line = (reg & 0xFFFF); - dsi_ctrl->cmd_success_frame = ((reg >> 16) & 0xFFFF); + atomic_set(&dsi_ctrl->cmd_success_line, (reg & 0xFFFF)); + atomic_set(&dsi_ctrl->cmd_success_frame, ((reg >> 16) & 0xFFFF)); SDE_EVT32(dsi_ctrl->cell_index, SDE_EVTLOG_FUNC_CASE1, dsi_ctrl->cmd_success_line, dsi_ctrl->cmd_success_frame); diff --git a/msm/dsi/dsi_ctrl.h b/msm/dsi/dsi_ctrl.h index a3290750520b..944debaa28a4 100644 --- a/msm/dsi/dsi_ctrl.h +++ b/msm/dsi/dsi_ctrl.h @@ -1,5 +1,6 @@ /* SPDX-License-Identifier: GPL-2.0-only */ /* + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * Copyright (c) 2015-2020, The Linux Foundation. All rights reserved. */ @@ -309,8 +310,8 @@ struct dsi_ctrl { bool cmd_mode; u32 cmd_trigger_line; u32 cmd_trigger_frame; - u32 cmd_success_line; - u32 cmd_success_frame; + atomic_t cmd_success_line; + atomic_t cmd_success_frame; }; /** From a74bd43d86ff4b26a891093ff5bd24b888436fce Mon Sep 17 00:00:00 2001 From: Gopi Botlagunta Date: Wed, 7 Jan 2026 15:37:06 +0530 Subject: [PATCH 16/16] disp: msm: dsi: Fix potential data race in ctrl isr Use atomic operations for shared variables to ensure safe concurrent access from both ISR and task context. Change-Id: I02d4bde88692d0be7027b158648a3ab8a5704b2d Signed-off-by: Gopi Botlagunta --- msm/dsi/dsi_ctrl.c | 10 ++-------- msm/dsi/dsi_ctrl.h | 3 --- 2 files changed, 2 insertions(+), 11 deletions(-) diff --git a/msm/dsi/dsi_ctrl.c b/msm/dsi/dsi_ctrl.c index 122fb10c18a5..988b3e60a462 100644 --- a/msm/dsi/dsi_ctrl.c +++ b/msm/dsi/dsi_ctrl.c @@ -2889,12 +2889,8 @@ static irqreturn_t dsi_ctrl_isr(int irq, void *ptr) if (status & DSI_CMD_MODE_DMA_DONE) { if (dsi_ctrl->enable_cmd_dma_stats) { - if (dsi_ctrl->hw.ops.log_line_count[dsi_ctrl->disp_op]) - reg = - dsi_ctrl->hw.ops.log_line_count[dsi_ctrl->disp_op](&dsi_ctrl->hw, - dsi_ctrl->cmd_mode); - else - reg = 0; + u32 reg = dsi_ctrl->hw.ops.log_line_count(&dsi_ctrl->hw, + dsi_ctrl->cmd_mode); atomic_set(&dsi_ctrl->cmd_success_line, (reg & 0xFFFF)); atomic_set(&dsi_ctrl->cmd_success_frame, ((reg >> 16) & 0xFFFF)); SDE_EVT32(dsi_ctrl->cell_index, SDE_EVTLOG_FUNC_CASE1, @@ -2902,7 +2898,6 @@ static irqreturn_t dsi_ctrl_isr(int irq, void *ptr) dsi_ctrl->cmd_success_frame); } - atomic64_set(&dsi_ctrl->cmd_success_ts, ktime_get()); atomic_set(&dsi_ctrl->dma_irq_trig, 1); dsi_ctrl_disable_status_interrupt(dsi_ctrl, DSI_SINT_CMD_MODE_DMA_DONE); @@ -3487,7 +3482,6 @@ int dsi_ctrl_cmd_transfer(struct dsi_ctrl *dsi_ctrl, rc); } - cmd->ts = atomic64_read(&dsi_ctrl->cmd_success_ts); dsi_ctrl_update_state(dsi_ctrl, DSI_CTRL_OP_CMD_TX, 0x0); error: diff --git a/msm/dsi/dsi_ctrl.h b/msm/dsi/dsi_ctrl.h index f66be7fb6b70..944debaa28a4 100644 --- a/msm/dsi/dsi_ctrl.h +++ b/msm/dsi/dsi_ctrl.h @@ -312,9 +312,6 @@ struct dsi_ctrl { u32 cmd_trigger_frame; atomic_t cmd_success_line; atomic_t cmd_success_frame; - u32 cmd_engine_refcount; - u32 pending_cmd_flags; - atomic64_t cmd_success_ts; }; /**