Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

drm: Undo damage to page_flip_ioctl

I screwed up rebasing of my patch in

commit 43968d7b806d7a7e021261294c583a216fddf0e5
Author: Daniel Vetter <daniel.vetter@ffwll.ch>
Date: Wed Sep 21 10:59:24 2016 +0200

drm: Extract drm_plane.[hc]

which meant on error paths drm_crtc_vblank_put could be called without
a get, leading to an underrun of the refcount.

Bugzilla: https://bugs.freedesktop.org/show_bug.cgi?id=98020
Reported-and-tested-by: Andy Furniss <adf.lists@gmail.com>
Cc: Sean Paul <seanpaul@chromium.org>
Cc: Michel Dänzer <michel@daenzer.net>
Signed-off-by: Daniel Vetter <daniel.vetter@ffwll.ch>
Link: http://patchwork.freedesktop.org/patch/msgid/20161003082827.11586-1-daniel.vetter@ffwll.ch
Signed-off-by: Dave Airlie <airlied@redhat.com>

authored by

Daniel Vetter and committed by
Dave Airlie
2adb29b1 e86fa21b

+39 -42
+39 -42
drivers/gpu/drm/drm_plane.c
··· 783 783 if (!crtc) 784 784 return -ENOENT; 785 785 786 + if (crtc->funcs->page_flip_target) { 787 + u32 current_vblank; 788 + int r; 789 + 790 + r = drm_crtc_vblank_get(crtc); 791 + if (r) 792 + return r; 793 + 794 + current_vblank = drm_crtc_vblank_count(crtc); 795 + 796 + switch (page_flip->flags & DRM_MODE_PAGE_FLIP_TARGET) { 797 + case DRM_MODE_PAGE_FLIP_TARGET_ABSOLUTE: 798 + if ((int)(target_vblank - current_vblank) > 1) { 799 + DRM_DEBUG("Invalid absolute flip target %u, " 800 + "must be <= %u\n", target_vblank, 801 + current_vblank + 1); 802 + drm_crtc_vblank_put(crtc); 803 + return -EINVAL; 804 + } 805 + break; 806 + case DRM_MODE_PAGE_FLIP_TARGET_RELATIVE: 807 + if (target_vblank != 0 && target_vblank != 1) { 808 + DRM_DEBUG("Invalid relative flip target %u, " 809 + "must be 0 or 1\n", target_vblank); 810 + drm_crtc_vblank_put(crtc); 811 + return -EINVAL; 812 + } 813 + target_vblank += current_vblank; 814 + break; 815 + default: 816 + target_vblank = current_vblank + 817 + !(page_flip->flags & DRM_MODE_PAGE_FLIP_ASYNC); 818 + break; 819 + } 820 + } else if (crtc->funcs->page_flip == NULL || 821 + (page_flip->flags & DRM_MODE_PAGE_FLIP_TARGET)) { 822 + return -EINVAL; 823 + } 824 + 786 825 drm_modeset_lock_crtc(crtc, crtc->primary); 787 826 if (crtc->primary->fb == NULL) { 788 827 /* The framebuffer is currently unbound, presumably ··· 831 792 ret = -EBUSY; 832 793 goto out; 833 794 } 834 - 835 - if (crtc->funcs->page_flip == NULL) 836 - goto out; 837 795 838 796 fb = drm_framebuffer_lookup(dev, page_flip->fb_id); 839 797 if (!fb) { ··· 875 839 } 876 840 877 841 crtc->primary->old_fb = crtc->primary->fb; 878 - if (crtc->funcs->page_flip_target) { 879 - u32 current_vblank; 880 - int r; 881 - 882 - r = drm_crtc_vblank_get(crtc); 883 - if (r) 884 - return r; 885 - 886 - current_vblank = drm_crtc_vblank_count(crtc); 887 - 888 - switch (page_flip->flags & DRM_MODE_PAGE_FLIP_TARGET) { 889 - case DRM_MODE_PAGE_FLIP_TARGET_ABSOLUTE: 890 - if ((int)(target_vblank - current_vblank) > 1) { 891 - DRM_DEBUG("Invalid absolute flip target %u, " 892 - "must be <= %u\n", target_vblank, 893 - current_vblank + 1); 894 - drm_crtc_vblank_put(crtc); 895 - return -EINVAL; 896 - } 897 - break; 898 - case DRM_MODE_PAGE_FLIP_TARGET_RELATIVE: 899 - if (target_vblank != 0 && target_vblank != 1) { 900 - DRM_DEBUG("Invalid relative flip target %u, " 901 - "must be 0 or 1\n", target_vblank); 902 - drm_crtc_vblank_put(crtc); 903 - return -EINVAL; 904 - } 905 - target_vblank += current_vblank; 906 - break; 907 - default: 908 - target_vblank = current_vblank + 909 - !(page_flip->flags & DRM_MODE_PAGE_FLIP_ASYNC); 910 - break; 911 - } 912 - } else if (crtc->funcs->page_flip == NULL || 913 - (page_flip->flags & DRM_MODE_PAGE_FLIP_TARGET)) { 914 - return -EINVAL; 915 - } 916 - 917 842 if (crtc->funcs->page_flip_target) 918 843 ret = crtc->funcs->page_flip_target(crtc, fb, e, 919 844 page_flip->flags,