[PATCH v4 00/10] drm/msm: fix SMMU fault dumps

From: Dmitry Baryshkov

Date: Fri Oct 02 2026 - 20:30:55 EST


In several cases the drm/msm can cause an SMMU fault on modesetting (due
to the display controller still scanning the BO which is being
unmapped). Fix the cases which I stumbled upon, together with the issues
found while chasing them: hardware block pointers surviving the
reservation which handed them out.

Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@xxxxxxxxxxxxxxxx>
---
Changes in v4:
- Take the framebuffer pin lock with guard() instead of unwinding through
labels (Rob)
- Move the fixes of the KMS init error handling, including the unwind of
msm_drm_kms_init() from v3, to a separate series, which this one now
depends on
- Add a retired framebuffer to the pending list and schedule its release
under the same lock, so that msm_crtc_vblank_off() cannot free it in
between, and track whether the vblank is off next to the list rather
than reading crtc->state, which a later commit may have swapped (Sashiko)
- New patches, ahead of the DSPP and DSC ones: clear the CWB and CDM
pointers left by a previous reservation (Sashiko)
- New patch: flush the MDP5 interface before starting the timing engine,
otherwise the first frame after a re-enable is fetched from the
framebuffer scanned out before the disable (db820c)
- Link to v3: https://patch.msgid.link/20260912-fd-kms-fix-smmu-v3-0-a7ddc6fe2032@xxxxxxxxxxxxxxxx

Changes in v3:
- Initialise the framebuffer's lock and dirtyfb count before
drm_framebuffer_init() publishes the framebuffer (Sashiko)
- New patch: unwind msm_drm_kms_init() on failure rather than handing a
half-initialised kms to msm_drm_kms_uninit() (prompted by Sashiko)
- Drop the pin count from the deferred unpin work rather than from
->cleanup_fb(), so a framebuffer scanned out by several crtcs stays
pinned until the last of them has passed a vblank (Sashiko)
- Defer each retired framebuffer with its own drm_vblank_work, as i915
does for cursor framebuffers, instead of a per-crtc drm_flip_work: the
release no longer takes a detour through kms->wq, and nothing needs
setting up or tearing down in the kms init path
- Release the framebuffers still pending on a crtc by hand when its vblank
is switched off; its interface is already disabled by then, so no
further vblank arrives to run the work
- New patch: clear the DSC blocks left by a previous reservation, the same
bug as the DSPP one (Sashiko)
- Link to v2: https://patch.msgid.link/20260908-fd-kms-fix-smmu-v2-0-9391815742a8@xxxxxxxxxxxxxxxx

Changes in v2:
- New patch: lock the framebuffer pin state, it was updated locklessly
(Sashiko)
- Do not defer the release on an inactive crtc, it was leaked there
(Sashiko)
- Flush retired framebuffers from msm_drm_kms_uninit(), before kms->vm is
dropped, and only for crtcs which have a vblank work (Sashiko)
- Clean the flip works up after destroy_workqueue() (Sashiko)
- Fixed the long-standing issue of the msm driver roguely setting
allow_modeset, which started to manifest in timeouts and SMMU errors.
- Link to v1: https://patch.msgid.link/20260903-fd-kms-fix-smmu-v1-0-608d02491666@xxxxxxxxxxxxxxxx

To: Rob Clark <robin.clark@xxxxxxxxxxxxxxxx>
To: Dmitry Baryshkov <lumag@xxxxxxxxxx>
To: Abhinav Kumar <abhinav.kumar@xxxxxxxxx>
To: Jessica Zhang <jesszhan0024@xxxxxxxxx>
To: Sean Paul <sean@xxxxxxxxxx>
To: Marijn Suijten <marijn.suijten@xxxxxxxxxxxxxx>
To: David Airlie <airlied@xxxxxxxxx>
To: Simona Vetter <simona@xxxxxxxx>
To: Antonino Maniscalco <antomani103@xxxxxxxxx>
To: Kalyan Thota <quic_kalyant@xxxxxxxxxxx>
To: Federico Amedeo Izzo <federico@xxxxxxxx>
To: Helen Koike <helen.fornazier@xxxxxxxxx>
To: Vignesh Raman <vignesh.raman@xxxxxxxxxxxxx>
To: Maarten Lankhorst <maarten.lankhorst@xxxxxxxxxxxxxxx>
To: Maxime Ripard <mripard@xxxxxxxxxx>
To: Thomas Zimmermann <tzimmermann@xxxxxxx>
Cc: linux-arm-msm@xxxxxxxxxxxxxxx
Cc: dri-devel@xxxxxxxxxxxxxxxxxxxxx
Cc: freedreno@xxxxxxxxxxxxxxxxxxxxx
Cc: linux-kernel@xxxxxxxxxxxxxxx
Cc: Dmitry Baryshkov <dmitry.baryshkov@xxxxxxxxxxxxxxxx>

---
Dmitry Baryshkov (10):
drm/msm: serialise framebuffer pin state
drm/msm: fix framebuffer pin refcount leak on prepare failure
drm/msm: release scanout framebuffers only after a vblank
drm/msm/mdp5: flush the interface before starting the timing engine
drm/msm/dpu: clear the CWB blocks left by a previous reservation
drm/msm/dpu: clear the CDM block left by a previous reservation
drm/msm/dpu: clear the DSPP pointer when no DSPP is assigned
drm/msm/dpu: clear the DSC blocks left by a previous reservation
drm/msm/dpu: only reassign resources when the encoder is reprogrammed
drm/ci: mark pixel-format tests as passing on SC7180

.../xfails/msm-sc7180-trogdor-kingoftown-fails.txt | 2 -
.../msm-sc7180-trogdor-lazor-limozeen-fails.txt | 2 -
drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c | 36 +++++-
drivers/gpu/drm/msm/disp/dpu1/dpu_encoder.c | 23 ++--
.../gpu/drm/msm/disp/dpu1/dpu_encoder_phys_wb.c | 2 +-
drivers/gpu/drm/msm/disp/dpu1/dpu_plane.c | 3 +-
drivers/gpu/drm/msm/disp/mdp4/mdp4_crtc.c | 4 +-
drivers/gpu/drm/msm/disp/mdp4/mdp4_plane.c | 2 +-
drivers/gpu/drm/msm/disp/mdp5/mdp5_crtc.c | 4 +-
drivers/gpu/drm/msm/disp/mdp5/mdp5_encoder.c | 3 +-
drivers/gpu/drm/msm/disp/mdp5/mdp5_plane.c | 2 +-
drivers/gpu/drm/msm/msm_atomic.c | 17 +--
drivers/gpu/drm/msm/msm_drv.h | 4 +-
drivers/gpu/drm/msm/msm_fb.c | 75 ++++++++---
drivers/gpu/drm/msm/msm_kms.c | 142 +++++++++++++++++++++
drivers/gpu/drm/msm/msm_kms.h | 19 +++
16 files changed, 276 insertions(+), 64 deletions(-)
---
base-commit: 5e4a3f7b262060d70cfdc7889cfe0f4aba9ea3fc
change-id: 20260902-fd-kms-fix-smmu-2d4baaf460b0
prerequisite-change-id: 20260930-msm-kms-destroy-fixes-0f04b1d39b83:v1
prerequisite-patch-id: d7439e7df4daac116217eb0fbbc277974d8dc1c9
prerequisite-patch-id: 6944647055d76b00b161e6a5a30a7f31a80c7256
prerequisite-patch-id: 5519e2e012b2065c08849502118233ccfd61e9d3
prerequisite-patch-id: 09f7ca53872a2ab17488f2bb94a1c2cd4c396781
prerequisite-patch-id: 4872ed1786ce7088e399b89fc8c5ac660dd20426
prerequisite-patch-id: ddd786dced962858ee89ce947eee4cbdbd88fe2e
prerequisite-patch-id: 11dc97f7f4980bdad49123271651749d0a8f8d23
prerequisite-patch-id: 427335a4d98e23f6df1c6d1109c6315a44bf1bc4
prerequisite-patch-id: d994bb94c13b7c8d5da5872844c5a79fa9988de4
prerequisite-patch-id: aa59ee029b6f5b24d6870208ebe8a5464204cad1
prerequisite-patch-id: 259f1da5d7d3146592277db856c44d863d7be84b

Best regards,
--
With best wishes
Dmitry