From e5fdc7822ba1274a16742d727e47b14d8c56d835 Mon Sep 17 00:00:00 2001 From: Vishnu Saini Date: Thu, 16 Oct 2025 11:56:23 +0530 Subject: [PATCH 1/3] disp: msm: sde: fix splash resource cleanup for edp Currently, splash_display->encoder is invalid for edp so _sde_kms_release_splash_resource is not releasing the resources. ea245e79821 ("disp: msm: sde: Remove pm vote at time of handoff") partially addressing the issue, but _sde_kms_free_splash_display_data is not called, resulting in smmu mapping not freed. Since iommu framework is not aware of this direct mapping through smmu so any allocations to this iova will fail due to this existing mapping, resulting in mapping and commit failures. Populate splash_display for edp so that cleanup of splash region is proper and revert ea245e79821, which is no longer needed. Change-Id: I5bd2b0d5996f0f91e4b0cf1e4f78e03feee4afe4 Signed-off-by: Vishnu Saini --- msm/sde/sde_kms.c | 29 ++++++++++++++++------------- 1 file changed, 16 insertions(+), 13 deletions(-) diff --git a/msm/sde/sde_kms.c b/msm/sde/sde_kms.c index 7dfad7d8d194..5dd01e54989d 100644 --- a/msm/sde/sde_kms.c +++ b/msm/sde/sde_kms.c @@ -1,5 +1,5 @@ /* - * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * Copyright (c) 2014-2021, The Linux Foundation. All rights reserved. * Copyright (C) 2013 Red Hat * Author: Rob Clark @@ -1255,16 +1255,6 @@ static void _sde_kms_release_splash_resource(struct sde_kms *sde_kms, SDE_EVT32(DRMID(crtc), crtc->state->active, sde_kms->splash_data.num_splash_displays); - /*remove all votes if eDP displays are done with splash*/ - if (dp_display_get_num_of_boot_displays()) { - for (i = 0; i < SDE_POWER_HANDLE_DBUS_ID_MAX; i++) - sde_power_data_bus_set_quota(phandle, i, - SDE_POWER_HANDLE_ENABLE_BUS_AB_QUOTA, - phandle->ib_quota[i]); - pm_runtime_put_sync(sde_kms->dev->dev); - sde_kms->splash_data.num_splash_displays--; - } - for (i = 0; i < MAX_DSI_DISPLAYS; i++) { splash_display = &sde_kms->splash_data.splash_display[i]; if (splash_display->encoder && @@ -3385,7 +3375,7 @@ static int sde_kms_cont_splash_config(struct msm_kms *kms, struct msm_display_info info; struct drm_encoder *encoder = NULL; struct drm_crtc *crtc = NULL; - int i, rc = 0; + int i, rc = 0, splash_index = 0; struct drm_display_mode *drm_mode = NULL; struct drm_device *dev; struct msm_drm_private *priv; @@ -3423,7 +3413,7 @@ static int sde_kms_cont_splash_config(struct msm_kms *kms, DRM_INFO("cont_splash enabled in %d of %d display(s)\n", sde_kms->splash_data.num_splash_displays, - sde_kms->dsi_display_count); + sde_kms->dsi_display_count + sde_kms->dp_display_count); /* dsi */ for (i = 0; i < sde_kms->dsi_display_count; ++i) { @@ -3559,6 +3549,19 @@ static int sde_kms_cont_splash_config(struct msm_kms *kms, break; } + splash_display = &sde_kms->splash_data.splash_display[splash_index]; + if (splash_display->cont_splash_enabled) { + priv = sde_kms->dev->dev_private; + encoder->crtc = priv->crtcs[splash_index]; + splash_display->encoder = encoder; + + SDE_DEBUG("dp-display:%d splash_index:%d crtc id[%d]:%d enc id[%d]:%d\n", + i, splash_index, encoder->crtc->index, encoder->crtc->base.id, + encoder->index, encoder->base.id); + + splash_index++; + } + mutex_lock(&dev->mode_config.mutex); drm_connector_list_iter_begin(dev, &conn_iter); drm_for_each_connector_iter(connector, &conn_iter) { From 6bbef66ce393adf4515b9ce14f0c63568d54526c Mon Sep 17 00:00:00 2001 From: yadwan Date: Tue, 29 Jul 2025 11:04:00 +0800 Subject: [PATCH 2/3] disp: msm: sde: Add change to fix slab out of bounds Non null terminated string from user space can cause out of bound access issue. Hence added a NULL character explicitly in name when received from user space. Change-Id: I6d498f16a59ec2832ddc0951952101859666eacf Signed-off-by: yadwan (cherry picked from commit 7eb70ce3648b8eb8e5340b0bf3c5bb3a7605d811) --- msm/sde/sde_wb.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/msm/sde/sde_wb.c b/msm/sde/sde_wb.c index dcb308fabf84..d6648ad7e2fc 100644 --- a/msm/sde/sde_wb.c +++ b/msm/sde/sde_wb.c @@ -204,6 +204,8 @@ int sde_wb_connector_set_modes(struct sde_wb_device *wb_dev, memset(&dispmode, 0, sizeof(dispmode)); ret = drm_mode_convert_umode(wb_dev->drm_dev, &dispmode, &modeinfo[i]); + /* null terminate the string */ + modeinfo[i].name[DRM_DISPLAY_MODE_LEN - 1] = '\0'; if (ret) { SDE_ERROR( "failed to convert mode %d:\"%s\" %d %d %d %d %d %d %d %d %d %d 0x%x 0x%x status:%d rc:%d\n", From df717747fdf18d12fa0606b64d77b1d8db9c1d08 Mon Sep 17 00:00:00 2001 From: Harini Manikumar Date: Thu, 4 Sep 2025 17:27:06 +0530 Subject: [PATCH 3/3] msm: smmu: Unregister SMMU fault handler before cleanup IOMMU fault handler can be invoked post SMMU destroy which can lead to use-after-free issue. Unregister the SMMU fault handler before freeing SMMU context and unregistering the platform device. Change-Id: I1cddd4a381f16d650258850a3d012d380fbe5ef8 Signed-off-by: Harini Manikumar Signed-off-by: Karthik Veeranki --- msm/msm_smmu.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/msm/msm_smmu.c b/msm/msm_smmu.c index 53f5f926560a..af9ba0ba87f5 100644 --- a/msm/msm_smmu.c +++ b/msm/msm_smmu.c @@ -1,4 +1,5 @@ /* + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * Copyright (c) 2015-2020, The Linux Foundation. All rights reserved. * Copyright (C) 2013 Red Hat * Author: Rob Clark @@ -211,6 +212,10 @@ static void msm_smmu_destroy(struct msm_mmu *mmu) { struct msm_smmu *smmu = to_msm_smmu(mmu); struct platform_device *pdev = to_platform_device(smmu->client_dev); + struct iommu_domain *domain = iommu_get_domain_for_dev(smmu->client_dev); + + if (domain) + iommu_set_fault_handler(domain, NULL, NULL); if (smmu->client_dev) platform_device_unregister(pdev);