| Age | Commit message (Collapse) | Author |
|
Some firmware advertises Fast BSS Transition and Opportunistic Key
Caching support through the firmware capability string. Track those
capabilities so later roaming offload handling can be enabled only
when firmware reports support.
Assisted-by: GitHub-Copilot-CLI:gpt-5.5
Signed-off-by: Carella Chen <carella.chen@infineon.com>
Signed-off-by: Jason Huang <jason.huang2@infineon.com>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260911065656.1269623-3-Jason.Huang2@infineon.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
|
|
t4ka3_probe() marks the device runtime active and enables runtime PM,
but does not increment the runtime PM usage counter. Nevertheless, the
probe failure path calls pm_runtime_put_noidle(), which has no matching
runtime PM get operation.
pm_runtime_put_noidle() currently does not decrement usage_count when
it is already zero, so the call is ineffective. Remove the unmatched
put to keep the runtime PM reference handling balanced and avoid
misleading cleanup code.
This issue was found by manual code inspection.
Fixes: fd55319692151 ("media: Add t4ka3 camera sensor driver")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
|
|
ov2735_probe() explicitly powers on the sensor before enabling runtime
PM. The probe failure paths call ov2735_power_off(), but the remove path
does not perform the corresponding power-off operation.
The managed runtime PM helpers only clean up the runtime PM state.
devm_pm_runtime_set_active_enabled() disables runtime PM and restores
the suspended state during device resource release, while
devm_pm_runtime_get_noresume() drops the runtime PM usage reference.
Neither helper invokes ov2735_power_off().
As a result, removing the driver after a successful probe can leave the
sensor clock and regulators enabled and the GPIOs in the powered state.
Call ov2735_power_off() from ov2735_remove() to match the successful
ov2735_power_on() performed during probe.
This issue was found by manual code inspection.
Fixes: fa9e6df636fb ("media: i2c: add ov2735 image sensor driver")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
|
|
Now that CONFIG_PROC_SYSCTL is gone, CONFIG_SYSCTL depends on
CONFIG_PROC_FS directly in fs/proc/Kconfig, so the double guard
defined(CONFIG_SYSCTL) && defined(CONFIG_PROC_FS) is redundant.
Simplify to "#ifdef CONFIG_SYSCTL".
Signed-off-by: Oleg Nesterov <oleg@redhat.com>
Signed-off-by: Joel Granados <joel.granados@kernel.org>
|
|
The Elan Digital Systems controller has been obsolete for many years. In
fact, its corresponding driver that was introduced in 2011 only received
one initial commit, but has since then never been actively maintained.
In this regards, we have lately started to receive a lot of AI generated
bug fixes as the driver is a real mess. Rather than continue this path
instead of making a proper rework of the driver, which is what would be
needed, let's just remove the driver altogether.
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Acked-by: Johan Hovold <johan@kernel.org>
Acked-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
|
|
Without ndo_get_vf_config(), userspace tools such as 'ip link show'
cannot query the current VF configuration from the PF.
To support this, extend struct enetc_vf_state to track the per-VF VLAN
and spoofchk settings, and update the corresponding setter callbacks to
persist their state when the hardware is programmed.
enetc_pf_get_vf_config() reads back the persisted state and reports MAC
address, VLAN parameters, spoofchk, and trust state through struct
ifla_vf_info.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-16-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
Let ENETC v4 VFs track PF link status through the PSI-to-VSI messaging
channel. Add two enetc_si_ops hooks, vf_reg_link_status_notifier and
vf_unreg_link_status_notifier, populated only in enetc4_vsi_ops; rev1
hardware is unaffected.
A dedicated MSI-X vector on the VF handles incoming PSI-to-VSI messages.
Its handler schedules a work item on an ordered workqueue that reads the
notification via VSIMSGRR, updates the carrier state and sets congestion
mode from the PF TX PAUSE state in the message. Reading VSIMSGRR also
acknowledges the PF so it can send the next message. The workqueue is
set up in enetc_vf_probe() and torn down in enetc_vf_remove().
On a VF, enetc_phylink_connect() registers the notifier with the PF and
enetc_close() unregisters it. On registration the PF immediately sends
the current link status and then broadcasts every later transition; if
registration fails, fall back to the LS1028A behaviour and assert
carrier unconditionally. Register the notifier only after the Tx/Rx
resources are allocated in enetc_open(), because once registered the PF
may queue si->msg_task via a link-up message. An error unwind cannot
drain that work item, since enetc_open() and the work item both take the
RTNL lock and waiting would deadlock; and as __LINK_STATE_START is set
before ndo_open() runs, netif_running() stays true during the unwind, so
the queued work could still call netif_carrier_on() and leave carrier
'on' after a failed open.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-15-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
An ENETC VF sends MAC filter changes to the PF over the VSI mailbox,
whose send path may sleep for up to 200ms waiting for completion. Since
the legacy ndo_set_rx_mode runs in atomic context, use
ndo_set_rx_mode_async instead, which runs from a workqueue under
rtnl_lock and receives pre-snapshotted unicast and multicast address
lists from the core.
Add two helpers built on the VSI mailbox:
- enetc_vf_set_mac_promisc() sends a promiscuous mode message for a
given filter type (unicast, multicast or both).
- enetc_vf_set_mac_hash_filter() sends the 64-bit MAC hash filter table,
built from the snapshotted address lists.
The callback picks the configuration from the current netdev flags:
- IFF_PROMISC: enable promiscuous mode for both unicast and multicast.
- IFF_ALLMULTI: enable multicast promiscuous mode, disable unicast
promiscuous mode and apply a unicast hash filter.
- otherwise: disable promiscuous mode and apply both unicast and
multicast hash filters.
These requests are subject to the PF-side ENETC_VF_FLAG_TRUSTED check.
For an untrusted VF (the default) the PF denies promiscuous mode and
unicast hash filtering, so only the multicast hash filter is applied,
limited to ENETC_VF_MC_HASH_BITS_MAX buckets. Mark a VF trusted via
'ip link set <pf> vf N trust on' for the full behaviour.
Set IFF_UNICAST_FLT for ENETC v4 VFs so the stack does not needlessly
fall back to full promiscuous mode; whether a unicast hash filter is
actually programmed still depends on the PF trust policy.
Since a denied request always fails, map -EOPNOTSUPP, -EACCES and -EPERM
to 0 so the core does not retry an operation that can never succeed.
ENETC v1 (LS1028A) does not support VF-to-PF MAC filter messaging and
keeps using the legacy ndev ops.
On VF removal, disable promiscuous mode and clear the MAC filters, so
that stale configuration does not persist if the VF is later bound to
another driver.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-14-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
Add VF support for the i.MX94 and i.MX95 platforms. Compared to the
LS1028A ENETC, the VF device ID is updated to 0xef00, so add it to the
VF driver's PCI device ID table. Also add the enetc4 SI ops and VF
driver data, and wire up .sriov_configure for the enetc4 PF driver so
that VFs can be created and torn down on these SoCs.
The number of VFs is not decided by the driver. It is determined by
each ENETC instance's SR-IOV hardware capability, reported through the
PCI SR-IOV TotalVFs field and configured by the SoC integration and
device tree. The driver derives it from pci_sriov_get_totalvfs() in
enetc_init_sriov_resources(); an instance that advertises zero VFs
simply cannot enable SR-IOV. So there is no driver-side revision or
device-ID check bounding the VF count.
For reference, the per-instance VF capability on these SoCs is:
- i.MX95 (v4.1): each ENETC instance supports 2 VFs.
- i.MX94 (v4.3) has two kinds of ENETC:
- standalone ENETC, the same instance type as on i.MX95, but on
i.MX94 it advertises no VFs;
- internal ENETC connected to the CPU port of the NETC switch,
which supports 3 VFs.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-13-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
On ENETC v4, when VF performs a PCI FLR, it resets PSIPMMR[SIn_MAC_UP]
and PSIPMMR[SIn_MAC_MP] bits, which control the unicast and multicast
promiscuous mode for the corresponding SI. The reset (default) value of
these bits enables promiscuous mode, meaning that after a VF FLR, the
SI is left in promiscuous mode regardless of the configuration set by
the PF driver prior to the reset.
This is a potential security vulnerability: a malicious VM could
deliberately trigger a VF FLR to force promiscuous mode on its SI,
allowing it to capture network traffic not destined for that VF.
To mitigate this, make the following changes:
- Add ENETC_VF_FLAG_UC_PROMISC and ENETC_VF_FLAG_MC_PROMISC to
enetc_vf_flags to track the PF-managed promiscuous mode state for each
VF.
- Update enetc_msg_set_vf_mac_promisc_mode() to keep these flags in sync
whenever a VF requests a promiscuous mode change via messaging.
- Update enetc_pf_set_vf_trust() to clear both promisc flags when a VF
is untrusted, so that a subsequent FLR cannot restore promiscuous mode
that the PF has already revoked.
- Add a vf_flr_handler callback to enetc_pf_ops. The ENETC v4
implementation re-applies the tracked UC/MC promiscuous mode settings
to the hardware after each FLR, ensuring the hardware state matches
the PF-managed policy rather than the insecure reset default.
- Add enetc_vf_flr_handler() in enetc_msg.c to detect FLR events via the
PSIIDR register and dispatch to the vf_flr_handler callback. Invoke it
at the start of enetc_msg_task() before processing VF messages.
- Enable FLR interrupts in PSIIER only when a vf_flr_handler callback is
registered, keeping ENETC v1 behavior unchanged.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Reviewed-by: Claudiu Manoil <claudiu.manoil@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-12-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
The PSIIER register controls two categories of interrupt sources:
message-receive (MR) interrupts, which fire when a VF sends a mailbox
message to the PSI, and VF FLR interrupts, which fire when a VF
performs a Function Level Reset.
The current helpers enetc_msg_enable_mr_int() and
enetc_msg_disable_mr_int() use a read-modify-write sequence to update
only the MR bits in PSIIER, intending to preserve any other bits that
may be set. However, VF FLR interrupt support is not yet implemented,
so PSIIER only ever holds MR interrupt bits at this point. The
read-modify-write is therefore unnecessary overhead.
Simplify enetc_disable_psiier_interrupts() to write 0 directly to
PSIIER, disabling all interrupt sources at once, and simplify
enetc_enable_psiier_interrupts() to write the MR mask directly without
reading the current register value first.
Rename both helpers from the MR-specific names to names that reflect
their true scope, i.e. managing all PSIIER interrupt sources rather
than just the MR bits. This prepares the code for a future patch that
adds VF FLR interrupt support, at which point
enetc_enable_psiier_interrupts() will be extended to also set the
corresponding FLR bits.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-11-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
ENETC v4 VF hardware supports MAC address filtering, but the underlying
resources (the PSIPMMR register and per-SI hash filter tables) are owned
by the PF. Add VSI-to-PSI mailbox messages so a VF can request MAC
filter configuration from the PF, using two new command IDs under the
existing MAC filter class (0x20):
1. ENETC_MSG_SET_MAC_HASH_TABLE (cmd_id 3): program the unicast and/or
multicast MAC hash filter table. Unicast filtering is only allowed for
a trusted VF, since it could be used to receive traffic destined for
other SIs. Multicast filtering is allowed even for an untrusted VF,
but limited to ENETC_VF_MC_HASH_BITS_MAX (8) buckets, enough for basic
operation such as IPv6 neighbor discovery and mDNS; a trusted VF may
use all 64 buckets.
2. ENETC_MSG_SET_MAC_PROMISC_MODE (cmd_id 5): enable or disable unicast/
multicast promiscuous mode, and optionally flush the hash filter
table. Enabling promiscuous mode requires a trusted VF; flushing the
table alone does not.
The PSIPMMR register is a shared resource accessed by both
enetc4_pf_set_rx_mode() and the VF message handler via a non-atomic
read-modify-write, so protect these accesses with si->gen_lock to avoid
lost updates on SMP.
When a VF loses trusted status via ndo_set_vf_trust(), clear its unicast
hash filter and disable promiscuous mode so it cannot receive traffic
beyond its allowed scope.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-10-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
The mac_filter array currently resides in struct enetc_pf and is used to
track unicast and multicast MAC address filters for the PF. Since struct
enetc_si is the common structure shared between the PF and VF drivers,
move mac_filter into struct enetc_si to prepare for MAC filter support
in the VF driver.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-9-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
Add .ndo_set_vf_mac() to the enetc v4 driver to configure the MAC
addresses of VFs.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-8-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
Move enetc_pf_set_vf_mac() into enetc-pf-common driver as a generic
interface for both ENETC v1 and v4 PF driver to use.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-7-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
Prepare for moving enetc_pf_set_vf_mac() into the enetc-pf-common driver
by replacing enetc_pf_set_primary_mac_addr() with enetc_set_si_hw_addr().
This makes the VF primary MAC configuration path generic and allows
future enetc v4 PF driver to reuse the same interface.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-6-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
When a VF is driven by DPDK, its user space application needs accurate
link speed information to make correct forwarding and configuration
decisions. Add link speed message support so the PF replies with the
current link speed when it receives a get-link-speed message from a VF.
Use a new message class 0x81 (ENETC_MSG_CLASS_ID_LINK_SPEED). The
PSI-to-VSI message is 16 bits: the high 8 bits are the class ID and the
low 8 bits are the speed code, so up to 255 speed values are supported
(ENETC_MSG_SPEED_MAX = 0xff). Instead of enumerating every speed above
5Gbps, use a formula so future high speeds need no enum or switch
changes:
speed_code = (link_speed - 5000) / 1000 + ENETC_MSG_SPEED_5G
The speed is read via phylink_ethtool_ksettings_get() rather than the
speed passed to the mac_link_up() callback. When the MAC has a PCS
layer, mac_link_up() reports the PCS link speed, which may differ from
the external PHY link speed; phylink_ethtool_ksettings_get() returns the
actual external link speed.
Unlike the link status message (class 0x80), the get-link-speed message
is only permitted for trusted VFs. Reading the speed requires the PF to
take rtnl_lock(), so an untrusted VF spamming this query could cause
rtnl_lock contention and starve routine network configuration on the
host. An untrusted VF therefore receives a permission-deny response; a
VF can be marked trusted via 'ip link set <pf> vf N trust on'.
Note that link speed change notification is not supported yet.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Reviewed-by: Claudiu Manoil <claudiu.manoil@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-5-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
Add a mechanism for VFs to learn the PF link state, using message class
0x80 (ENETC_MSG_CLASS_ID_LINK_STATUS) with three VSI-to-PSI commands:
1. ENETC_MSG_GET_CURRENT_LINK_STATUS: the VF queries the current PF link
status synchronously. This is intended for DPDK-owned VFs and is not
used by the Linux VF driver.
2. ENETC_MSG_REGISTER_LINK_CHANGE_NOTIFIER: the VF registers for link
change notification. The PF then reports the current link status and
notifies the VF on every later link change.
3. ENETC_MSG_UNREGISTER_LINK_CHANGE_NOTIFIER: the VF unregisters.
The PSI-to-VSI notification is 16 bits wide: the upper 8 bits carry the
class ID and the lower 8 bits the class code. Bit 0 of the class code
indicates the link state (1 = down, 0 = up) and bit 1 indicates whether
TX PAUSE is enabled on the PF. The TX PAUSE state is included so a VF
can decide whether to enable congestion mode on its RX BD rings, which
only works when the PF can actually send PAUSE frames.
Notifications are sent through the ENETC_PSIMSGSR register. Since sending
a notification may take a long time, as it polls the per-VF message
status bits, the actual transmission is deferred to an ordered workqueue
rather than running in the phylink link_up/link_down callbacks. The
link_status_ms_mask tracks the VFs registered for notification and is
cleared when SR-IOV is disabled.
Export enetc_pf_notify_vf_link_up() and enetc_pf_notify_vf_link_down()
for the PF phylink callbacks. Through this, VFs can perceive the link
status and report it to upper layers such as the kernel network stack,
containers and virtual machines.
Currently only the ENETC v4 driver supports this feature; v1 does not.
And the SR-IOV feature of ENETC v4 will be added by subsequent patches.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Reviewed-by: Claudiu Manoil <claudiu.manoil@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-4-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
The ENETC PF currently uses msg_task and msg_int_name in struct enetc_pf
to handle VSI-to-PSI mailbox messages via a workqueue and a dedicated
interrupt.
PSI-to-VSI message support will be added to the VF driver, which will
require the same mechanism: a message interrupt and a workqueue handler.
Since struct enetc_si is the common structure shared between PF and VF,
move msg_task and msg_int_name from struct enetc_pf to struct enetc_si
to allow both drivers to use them without duplication.
Also relocate the ENETC_INT_NAME_MAX macro definition ahead of struct
enetc_si so it can be used for the msg_int_name array declaration.
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Reviewed-by: Claudiu Manoil <claudiu.manoil@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-3-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
Some mailbox messages require a higher privilege level to be executed
on behalf of the requesting VF. Introduce a trusted VF flag
(ENETC_VF_FLAG_TRUSTED) and wire up the ndo_set_vf_trust callback via
enetc_pf_set_vf_trust(), which is shared between the enetc and enetc4
PF drivers.
Trust is a PF/host-side policy bound to the VF index, decoupled from
whether SR-IOV is enabled. It may be set on a slot before SR-IOV is
enabled so a trusted VF can apply configuration right at init time,
and it is intentionally preserved across an SR-IOV disable/enable
cycle. The bounds check uses pf->total_vfs, the hardware maximum and
the size of pf->vf_state[], so pre-configuring an uninstantiated slot
is in-bounds. If a slot may be reassigned to another guest, the admin
clears trust with "ip link set <dev> vf <N> trust off".
The first message gated on trust is the VF primary MAC address change.
An untrusted VF that attempts to set its own MAC address will receive a
ENETC_MSG_CLASS_ID_PERMISSION_DENY response and the hardware will not be
programmed. This prevents a malicious VM from setting the VF address to
the MAC address of other VFs or the PF and eavesdropping on the traffic
of other SIs, and it stops a malicious VM from arbitrarily changing the
VF MAC address to achieve MAC address spoofing and bypass security
policies. This does not regress VF bring-up. The PF programs a valid
primary MAC into every VF slot at probe, and the VF loads it from its
own SIPMAR0/1 registers.
Signed-off-by: Claudiu Manoil <claudiu.manoil@nxp.com>
Signed-off-by: Wei Fang <wei.fang@nxp.com>
Link: https://patch.msgid.link/20260909100733.1139689-2-wei.fang@oss.nxp.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
|
|
og01a1b_probe() powers the sensor on explicitly before identifying and
initializing it. After a successful probe, runtime PM is enabled and
pm_runtime_idle() is used to allow the runtime suspend callback to
power the sensor off.
The probe error path explicitly calls og01a1b_power_off(), but the
normal remove path only disables runtime PM. pm_runtime_disable() does
not guarantee that an active device is runtime suspended, so the
sensor can remain powered when the driver is removed. This also leaves
the xvclk enable performed by og01a1b_power_on() unbalanced.
After disabling runtime PM, check whether the device is already
suspended. If it is still active, power the sensor off explicitly and
update the runtime PM state accordingly. Avoid powering it off again
when runtime suspend has already done so.
This issue was found by manual code inspection.
Fixes: a95ffde28783 ("media: i2c: og01a1b: Add support of xvclk supply clock in power management")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
|
|
The error path taken when ar0521_power_on() fails calls
media_entity_cleanup() at the disable label and then falls through to
the entity_cleanup label, where media_entity_cleanup() is called again.
There is no need to clean up the media entity twice. Remove the first
call and let all error paths converge on the common entity_cleanup
label.
This issue was found by manual code inspection.
Fixes: 852b50aeed15 ("media: On Semi AR0521 sensor driver")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
|
|
alvium_probe() increments the runtime PM usage count with
pm_runtime_get_noresume() before enabling runtime PM. The probe error
path correctly balances this reference with pm_runtime_put_noidle(),
but the normal remove path only disables runtime PM.
pm_runtime_disable() does not decrement the usage count, so a
successful probe followed by driver removal leaves the runtime PM
usage count unbalanced.
Add the missing pm_runtime_put_noidle() to the remove path, matching
the existing probe error cleanup.
This issue was found by manual code inspection.
Fixes: 0a7af872915e ("media: i2c: Add support for alvium camera")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
|
|
Use the V4L2 subdev active state API to store the active format.
This simplifies the driver not only by dropping the bridge mbus_format
field, but it also allows dropping the bridge lock, replaced with
the state lock.
Previously, capture accessed bridge private state directly. After
moving to framework-managed state, resolve the format through the
subdev pad API.
The sun6i-csi-bridge hardware does not perform any format conversion.
Enforce identical formats on the sink and source pads in the set_fmt()
and init_state() callbacks.
Signed-off-by: Arash Golgol <arash.golgol@gmail.com>
Reviewed-by: Paul Kocialkowski <paulk@sys-base.io>
Tested-by: Paul Kocialkowski <paulk@sys-base.io>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
|
|
Use the V4L2 subdev active state API to store the active format.
This simplifies the driver not only by dropping the bridge mbus_format
field, but it also allows dropping the bridge lock, replaced with
the state lock.
The sun8i-a83t-mipi-csi2 hardware does not perform any format
conversion. Enforce identical formats on the sink and source pads in
the set_fmt() and init_state() callbacks.
Signed-off-by: Arash Golgol <arash.golgol@gmail.com>
Reviewed-by: Paul Kocialkowski <paulk@sys-base.io>
Tested-by: Paul Kocialkowski <paulk@sys-base.io>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
|
|
Use the V4L2 subdev active state API to store the active format.
This simplifies the driver not only by dropping the bridge mbus_format
field, but it also allows dropping the bridge lock, replaced with
the state lock.
The sun6i-mipi-csi2 hardware does not perform any format conversion.
Enforce identical formats on the sink and source pads in the set_fmt()
and init_state() callbacks.
Signed-off-by: Arash Golgol <arash.golgol@gmail.com>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Reviewed-by: Paul Kocialkowski <paulk@sys-base.io>
Tested-by: Paul Kocialkowski <paulk@sys-base.io>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
|
|
ata_host_register() does not start the ports of the host, it requires
them to have been started already:
/* host must have been started */
if (!(host->flags & ATA_HOST_STARTED)) {
dev_err(host->dev, "BUG: trying to register unstarted host\n");
WARN_ON(1);
return -EINVAL;
}
Fix the kdoc accordingly, and fix the grammar of the last sentence while
at it.
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://lore.kernel.org/r/20260915084127.692494-14-cassel@kernel.org
Signed-off-by: Niklas Cassel <cassel@kernel.org>
|
|
ata_host_start() registers ata_host_stop() as a devres action as soon as
it has succeeded, which hands the release of the host resources over to
devres: ->port_stop() and ->host_stop() are then called by the driver
core when probe() fails.
ata_host_activate() and ahci_host_activate_multi_irqs() can both fail
after ata_host_start() has succeeded, e.g. if devm_request_irq() or
ata_host_register() fails, and they return the error with the devres
action still registered. A driver which releases the host resources in
its probe() error path therefore releases them twice: once itself and
once through ->host_stop().
All ahci-platform drivers are in that situation, e.g. ahci_probe() calls
ahci_platform_disable_resources() while ahci_host_stop() does the same
through devres. This gives refcount underflow warnings from the clk,
regulator and phy cores and, for shared resources, can disable resources
which are still in use by other devices.
Add ata_host_undo_start(), which stops the ports and drops the devres
action without calling ->host_stop(), and call it from both activation
helpers when they fail. Releasing the host resources on failure is then
always left to the caller, which is what all callers having a probe()
error path already assume.
This changes the semantics for the drivers which implement ->host_stop()
while also completely lacking error handling for the activate host call.
Add activate host error handling for sata_qstor and sata_fsl. For
sata_fsl this also means that hcr_base and host_priv are now released
when activating the host fails, which ->host_stop() did not do when
ata_host_start() itself failed.
Note that ata_pci_sff_activate_host() is deliberately left as is: none of
its callers releases the host resources in its probe() error path, they
all rely on ->host_stop() being called by devres, including
ata_pci_init_one(), which releases the devres group of the host itself.
Fixes: 1896b15eddb4 ("ahci_platform: perform platform exit in host_stop() hook")
Cc: stable@vger.kernel.org
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://lore.kernel.org/r/20260915084127.692494-13-cassel@kernel.org
Signed-off-by: Niklas Cassel <cassel@kernel.org>
|
|
ahci_host_activate_multi_irqs() requests one IRQ per port, but it does
not free them when requesting one of them, or when registering the host,
fails. The IRQs are only freed by the driver core, when it releases the
devres of the device after probe() has returned, while the caller of
ahci_host_activate() releases the resources of the host in its probe()
error path, e.g. ahci_probe() disables the clocks, regulators, resets and
PHYs of the host. An IRQ handler running in that window would access the
MMIO of a host which is no longer clocked.
ahci_host_activate_multi_irqs() did free the IRQs until commit
0a142b26921c ("ahci: cleanup ahci_host_activate_multi_irqs"), which
removed the explicit free because devm makes it unnecessary. That is true
for freeing the IRQs as such, but not for the window described above:
devres is only released after probe() has returned, i.e. after the error
path of the caller has released the resources of the host.
Note that this window cannot be hit with the current users: the only user
of AHCI_HFLAG_MULTI_MSI is the AHCI PCI driver, which does not release
any resource in its probe() error path, and the ports of the host are
still frozen, i.e. their interrupts are masked, when ata_host_register()
fails.
Free the IRQs explicitly again, like ata_host_activate() does, so that
the IRQ handlers cannot run once ahci_host_activate() has failed.
Fixes: 0a142b26921c ("ahci: cleanup ahci_host_activate_multi_irqs")
Cc: stable@vger.kernel.org
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://lore.kernel.org/r/20260915084127.692494-12-cassel@kernel.org
Signed-off-by: Niklas Cassel <cassel@kernel.org>
|
|
sata_fsl_host_stop() releases hcr_base and host_priv:
static void sata_fsl_host_stop(struct ata_host *host)
{
struct sata_fsl_host_priv *host_priv = host->private_data;
iounmap(host_priv->hcr_base);
kfree(host_priv);
}
->host_stop() is called by the driver core through the ata_host_stop()
devres action which ata_host_start() registers, so it is called both when
the device is unbound and when probe() fails after the host has been
started.
The error_exit_with_cleanup label of sata_fsl_probe() releases hcr_base
and host_priv as well, and it is reachable from the two
device_create_file() calls which are done after the host has been
activated. In that case sata_fsl_host_stop() runs on an already freed
host_priv, resulting in a use-after-free and a double iounmap()/kfree().
Add a separate error label for the failures happening after the host has
been activated, which only detaches the host and leaves hcr_base and
host_priv to sata_fsl_host_stop().
Note that ata_host_detach() is dropped from error_exit_with_cleanup, as
that label is now only reachable while host is still NULL.
Fixes: 6c8ad7e8cf29 ("sata_fsl: fix UAF in sata_fsl_port_stop when rmmod sata_fsl")
Cc: stable@vger.kernel.org
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://lore.kernel.org/r/20260915084127.692494-11-cassel@kernel.org
Signed-off-by: Niklas Cassel <cassel@kernel.org>
|
|
brcms_free_timer() calls brcms_del_timer() which uses the non-synchronous
cancel_delayed_work() to cancel the timer's underlying delayed work. If
the work callback (_brcms_timer) is already running, cancel_delayed_work()
returns false without waiting, and brcms_free_timer() proceeds to kfree(t)
while the callback still accesses t through container_of().
Add an explicit cancel_delayed_work_sync() after brcms_del_timer() to
guarantee that any in-flight callback has completed before the timer
structure is freed.
Fixes: 5b435de0d786 ("net: wireless: add brcm80211 drivers")
Cc: stable@vger.kernel.org
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260815121043.938414-1-yijiangshan@kylinos.cn
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
|
|
brcmf_txfinalize() decrements pend_8021x_cnt before a lockless
waitqueue_active() check. atomic_dec() does not order the decrement
against the check.
The waiter can therefore observe a nonzero count while the waker observes
an empty queue, losing the final wakeup and delaying key installation
until the 950 ms timeout.
Add smp_mb__after_atomic() to order the decrement before the queue
check. wait_event_timeout() provides the matching barrier. LKMM confirms
that this forbids the lost-wakeup outcome.
Fixes: 21fff75d2fb6 ("brcmfmac: use wait_event_timeout for 8021x pending count")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Acked-by: Arend van Spriel <arend.vanspriel@broadcom.com>
Link: https://patch.msgid.link/20260811082702.44521-1-kmehltretter@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
|
|
git://git.kernel.org/pub/scm/linux/kernel/git/ath/ath
Jeff Johnson says:
==================
ath.git update for v7.3-rc4
In ath12k: revert an undocumented and unapproved DT ABI that was added
during the v7.3 merge window.
In wcn36xx and ath11k: fix preexisting object lifetime issues.
==================
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
|
|
st_ahci_probe_resets() deasserts the "pwr-dwn" reset, but the probe()
error path of st_ahci_probe() only releases the host resources, so the
SATA IP is left powered up when probe() fails after
st_ahci_probe_resets() has succeeded, e.g. when
ahci_platform_enable_resources() fails.
The reset is asserted by st_ahci_host_stop(), however ->host_stop() is
only called through the ata_host_stop() devres action registered by
ata_host_start(), so it does not cover any failure happening before the
host has been started.
Factor the assert out into st_ahci_assert_pwrdwn() and call it when
either ahci_platform_enable_resources() or ahci_platform_init_host()
fails. The "pwr-dwn" reset control is an exclusive one, so asserting it
once more from st_ahci_host_stop() is harmless.
No functional change intended for ->host_stop() and st_ahci_suspend().
Fixes: 76884cb2f7da ("ahci: st: Add support for ST's SATA IP")
Cc: stable@vger.kernel.org
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://lore.kernel.org/r/20260915084127.692494-10-cassel@kernel.org
Signed-off-by: Niklas Cassel <cassel@kernel.org>
|
|
st_ahci_probe_resets() treats any error from devm_reset_control_get() as
"reset control not defined" and continues with a NULL reset control:
drv_data->pwr = devm_reset_control_get(dev, "pwr-dwn");
if (IS_ERR(drv_data->pwr)) {
dev_info(dev, "power reset control not defined\n");
drv_data->pwr = NULL;
}
This also swallows -EPROBE_DEFER, which is returned when the reset
controller providing the reset has not been probed yet. probe() then
continues as if the device tree did not specify any reset, so the resets
of the SATA IP are never deasserted, and st_ahci_configure_oob() and
ahci_platform_init_host() access the MMIO of an IP which is still held in
reset and powered down, which can result in an external abort.
The resets are optional in the binding, as they are not part of its
required properties, so use devm_reset_control_get_optional(), which
returns NULL if the reset is not specified in the device tree, and
propagate all other errors.
Note that an absent reset is now indicated by a NULL reset control
instead of an error, so the "reset control not defined" messages are
dropped.
Fixes: 76884cb2f7da ("ahci: st: Add support for ST's SATA IP")
Cc: stable@vger.kernel.org
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Link: https://lore.kernel.org/r/20260915084127.692494-9-cassel@kernel.org
Signed-off-by: Niklas Cassel <cassel@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
Reviewed-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-39-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-38-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-37-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Tested-by: Biju Das <biju.das.jz@bp.renesas.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-36-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Reviewed-by: Laurent Pinchart <laurent.pinchart+renesas@ideasonboard.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-35-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-34-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Reviewed-by: Lyude Paul <lyude@redhat.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-33-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-32-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-31-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-30-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Tested-by: Manikandan Muralidharan <manikandan.m@microchip.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-29-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The lcdc_csc_init callback was introduced in commit aa71584b323a ("drm:
atmel-hlcdc: add driver ops to differentiate HLCDC and XLCDC IP") and
called only once, at init time, from atmel_hlcdc_plane_init_properties().
commit 81af99cbd9e4 ("drm/atmel-hlcdc: destroy properly the plane state
in the reset callback") then reworked the reset hook to use
atmel_hlcdc_plane_atomic_destroy_state() instead of duplicating the
code. However, it also introduced a new call to lcdc_csc_init in the
reset path that wasn't there before and wasn't mentioned in the commit
log.
Since CSC coefficients are hardware constants that only need to be
written once at init time. This also prevents the conversion to
atomic_create_state, which must not have any hardware side-effect.
Fixes: 81af99cbd9e4 ("drm/atmel-hlcdc: destroy properly the plane state in the reset callback")
Acked-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-28-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-27-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane reset implementation creates a custom state
subclass, but only initializes a pristine state without resetting any
hardware. This is equivalent to what atomic_create_state expects.
Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Reviewed-by: Leo Li <sunpeng.li@amd.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-26-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|
|
The plane only initializes a pristine state in its reset hook
using drm_atomic_helper_plane_reset(), which is equivalent to what
atomic_create_state expects. Convert to it.
The conversion was done using the following Coccinelle semantic patch:
@@
identifier funcs;
symbol drm_atomic_helper_plane_reset;
symbol drm_atomic_helper_plane_create_state;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = drm_atomic_helper_plane_reset,
+ .atomic_create_state = drm_atomic_helper_plane_create_state,
...,
};
@match_struct_reset@
identifier funcs, reset_func;
@@
struct drm_plane_funcs funcs = {
...,
.reset = reset_func,
...,
};
@reset_uses_helpers depends on match_struct_reset@
identifier match_struct_reset.reset_func;
@@
void reset_func(...)
{
<+...
(
__drm_atomic_helper_plane_reset(...);
|
__drm_gem_reset_shadow_plane(...);
)
...+>
}
@match_struct_destroy@
identifier funcs, destroy_func;
@@
struct drm_plane_funcs funcs = {
...,
.atomic_destroy_state = destroy_func,
...,
};
@script:python renamed_func@
old_name << match_struct_reset.reset_func;
new_name;
@@
if old_name.endswith("_reset"):
coccinelle.new_name = old_name.replace("_reset", "_create_state")
else:
coccinelle.new_name = old_name
@update_struct depends on match_struct_reset && reset_uses_helpers@
identifier match_struct_reset.funcs, match_struct_reset.reset_func;
identifier renamed_func.new_name;
@@
struct drm_plane_funcs funcs = {
...,
- .reset = reset_func,
+ .atomic_create_state = new_name,
...,
};
@drop_destroy depends on update_struct && match_struct_destroy@
identifier match_struct_reset.reset_func;
identifier match_struct_destroy.destroy_func;
identifier container_func;
identifier P;
symbol drm_atomic_helper_plane_destroy_state;
symbol __drm_atomic_helper_plane_destroy_state;
@@
void reset_func(struct drm_plane *P)
{
...
(
- if (P->state) {
- <+...
(
- drm_atomic_helper_plane_destroy_state(P, P->state);
|
- __drm_atomic_helper_plane_destroy_state(P->state);
|
- P->funcs->atomic_destroy_state(P, P->state);
|
- destroy_func(P, P->state);
)
- ...+>
- }
|
- drm_WARN_ON_ONCE(P->dev, P->state);
|
- WARN_ON(P->state);
)
...
(
- kfree(P->state);
|
- kfree(container_func(P->state));
|
// kfree is optional
)
(
- P->state = NULL;
|
// plane->state clearing is optional
)
...
}
@drop_destroy_mtk depends on update_struct@
identifier P;
symbol __drm_atomic_helper_plane_destroy_state;
symbol to_mtk_plane_state;
@@
void mtk_plane_reset(struct drm_plane *P)
{
...
- if (P->state) {
- __drm_atomic_helper_plane_destroy_state(P->state);
- ...
- } else {
...
- }
...
}
@transform_nv50_wndw depends on update_struct@
identifier S;
@@
void nv50_wndw_reset(...)
{
...
- if (WARN_ON(!(S = kzalloc_obj(*S))))
+ S = kzalloc_obj(*S);
+ if (WARN_ON(!S))
return;
...
}
@transform_kzalloc depends on update_struct@
identifier match_struct_reset.reset_func;
identifier P, S;
statement ST;
statement list STL;
@@
void reset_func(struct drm_plane *P)
{
<...
S = kzalloc_obj(*S);
(
- if (S)
- {
- STL
- }
+ if (!S) return;
+
+ STL
|
- if (S) ST
+ if (!S) return;
+
+ ST
)
...>
}
@transform_body depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier S, P;
expression PS;
@@
- void reset_func(struct drm_plane *P)
+ struct drm_plane_state *new_name(struct drm_plane *P)
{
...
S = kzalloc_obj(*S);
...
(
if (!S) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (WARN_ON(!S)) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
|
if (S == NULL) {
...
- return;
+ return ERR_PTR(-ENOMEM);
}
)
...
(
- __drm_atomic_helper_plane_reset(P, PS);
+ __drm_atomic_helper_plane_state_init(PS, P);
|
- __drm_gem_reset_shadow_plane(P, PS);
+ __drm_gem_shadow_plane_state_init(P, PS);
)
...
}
@update_early_return depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
<+...
- return;
+ return ERR_PTR(-EINVAL);
...+>
}
@update_return_plane depends on update_struct@
identifier match_struct_reset.reset_func;
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_atomic_helper_plane_state_init(PS, P);
...
+
+ return PS;
}
@update_return_shadow depends on update_struct@
identifier renamed_func.new_name;
identifier P;
expression PS;
@@
struct drm_plane_state *new_name(struct drm_plane *P)
{
...
__drm_gem_shadow_plane_state_init(P, PS);
...
+
+ return &PS->base;
}
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260908-drm-no-more-plane-reset-v4-24-a31b3fcfc989@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
|