xref: /linux/drivers/gpu/drm/drm_drv.c (revision 570f7e331f5febb30f1384817463c7e42b65ca7d)
1 /*
2  * Created: Fri Jan 19 10:48:35 2001 by faith@acm.org
3  *
4  * Copyright 2001 VA Linux Systems, Inc., Sunnyvale, California.
5  * All Rights Reserved.
6  *
7  * Author Rickard E. (Rik) Faith <faith@valinux.com>
8  *
9  * Permission is hereby granted, free of charge, to any person obtaining a
10  * copy of this software and associated documentation files (the "Software"),
11  * to deal in the Software without restriction, including without limitation
12  * the rights to use, copy, modify, merge, publish, distribute, sublicense,
13  * and/or sell copies of the Software, and to permit persons to whom the
14  * Software is furnished to do so, subject to the following conditions:
15  *
16  * The above copyright notice and this permission notice (including the next
17  * paragraph) shall be included in all copies or substantial portions of the
18  * Software.
19  *
20  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
21  * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
22  * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.  IN NO EVENT SHALL
23  * PRECISION INSIGHT AND/OR ITS SUPPLIERS BE LIABLE FOR ANY CLAIM, DAMAGES OR
24  * OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
25  * ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
26  * DEALINGS IN THE SOFTWARE.
27  */
28 
29 #include <linux/bitops.h>
30 #include <linux/cgroup_dmem.h>
31 #include <linux/debugfs.h>
32 #include <linux/export.h>
33 #include <linux/fs.h>
34 #include <linux/module.h>
35 #include <linux/moduleparam.h>
36 #include <linux/mount.h>
37 #include <linux/pseudo_fs.h>
38 #include <linux/sched.h>
39 #include <linux/slab.h>
40 #include <linux/sprintf.h>
41 #include <linux/srcu.h>
42 #include <linux/xarray.h>
43 
44 #include <drm/drm_accel.h>
45 #include <drm/drm_bridge.h>
46 #include <drm/drm_cache.h>
47 #include <drm/drm_client_event.h>
48 #include <drm/drm_color_mgmt.h>
49 #include <drm/drm_drv.h>
50 #include <drm/drm_file.h>
51 #include <drm/drm_managed.h>
52 #include <drm/drm_mode_object.h>
53 #include <drm/drm_panic.h>
54 #include <drm/drm_print.h>
55 #include <drm/drm_privacy_screen_machine.h>
56 #include <drm/drm_ras_genl_family.h>
57 
58 #include "drm_crtc_internal.h"
59 #include "drm_internal.h"
60 
61 MODULE_AUTHOR("Gareth Hughes, Leif Delgass, José Fonseca, Jon Smirl");
62 MODULE_DESCRIPTION("DRM shared core routines");
63 MODULE_LICENSE("GPL and additional rights");
64 
65 DEFINE_XARRAY_ALLOC(drm_minors_xa);
66 
67 /*
68  * If the drm core fails to init for whatever reason,
69  * we should prevent any drivers from registering with it.
70  * It's best to check this at drm_dev_init(), as some drivers
71  * prefer to embed struct drm_device into their own device
72  * structure and call drm_dev_init() themselves.
73  */
74 static bool drm_core_init_complete;
75 
76 DEFINE_STATIC_SRCU(drm_unplug_srcu);
77 
78 /*
79  * DRM Minors
80  * A DRM device can provide several char-dev interfaces on the DRM-Major. Each
81  * of them is represented by a drm_minor object. Depending on the capabilities
82  * of the device-driver, different interfaces are registered.
83  *
84  * Minors can be accessed via dev->$minor_name. This pointer is either
85  * NULL or a valid drm_minor pointer and stays valid as long as the device is
86  * valid. This means, DRM minors have the same life-time as the underlying
87  * device. However, this doesn't mean that the minor is active. Minors are
88  * registered and unregistered dynamically according to device-state.
89  */
90 
91 static struct xarray *drm_minor_get_xa(enum drm_minor_type type)
92 {
93 	if (type == DRM_MINOR_PRIMARY || type == DRM_MINOR_RENDER)
94 		return &drm_minors_xa;
95 #if IS_ENABLED(CONFIG_DRM_ACCEL)
96 	else if (type == DRM_MINOR_ACCEL)
97 		return &accel_minors_xa;
98 #endif
99 	else
100 		return ERR_PTR(-EOPNOTSUPP);
101 }
102 
103 static struct drm_minor **drm_minor_get_slot(struct drm_device *dev,
104 					     enum drm_minor_type type)
105 {
106 	switch (type) {
107 	case DRM_MINOR_PRIMARY:
108 		return &dev->primary;
109 	case DRM_MINOR_RENDER:
110 		return &dev->render;
111 	case DRM_MINOR_ACCEL:
112 		return &dev->accel;
113 	default:
114 		BUG();
115 	}
116 }
117 
118 static void drm_minor_alloc_release(struct drm_device *dev, void *data)
119 {
120 	struct drm_minor *minor = data;
121 
122 	WARN_ON(dev != minor->dev);
123 
124 	put_device(minor->kdev);
125 
126 	xa_erase(drm_minor_get_xa(minor->type), minor->index);
127 }
128 
129 /*
130  * DRM used to support 64 devices, for backwards compatibility we need to maintain the
131  * minor allocation scheme where minors 0-63 are primary nodes, 64-127 are control nodes,
132  * and 128-191 are render nodes.
133  * After reaching the limit, we're allocating minors dynamically - first-come, first-serve.
134  * Accel nodes are using a distinct major, so the minors are allocated in continuous 0-MAX
135  * range.
136  */
137 #define DRM_MINOR_LIMIT(t) ({ \
138 	typeof(t) _t = (t); \
139 	_t == DRM_MINOR_ACCEL ? XA_LIMIT(0, ACCEL_MAX_MINORS) : XA_LIMIT(64 * _t, 64 * _t + 63); \
140 })
141 #define DRM_EXTENDED_MINOR_LIMIT XA_LIMIT(192, (1 << MINORBITS) - 1)
142 
143 static int drm_minor_alloc(struct drm_device *dev, enum drm_minor_type type)
144 {
145 	struct drm_minor *minor;
146 	int r;
147 
148 	minor = drmm_kzalloc(dev, sizeof(*minor), GFP_KERNEL);
149 	if (!minor)
150 		return -ENOMEM;
151 
152 	minor->type = type;
153 	minor->dev = dev;
154 
155 	r = xa_alloc(drm_minor_get_xa(type), &minor->index,
156 		     NULL, DRM_MINOR_LIMIT(type), GFP_KERNEL);
157 	if (r == -EBUSY && (type == DRM_MINOR_PRIMARY || type == DRM_MINOR_RENDER))
158 		r = xa_alloc(&drm_minors_xa, &minor->index,
159 			     NULL, DRM_EXTENDED_MINOR_LIMIT, GFP_KERNEL);
160 	if (r < 0)
161 		return r;
162 
163 	r = drmm_add_action_or_reset(dev, drm_minor_alloc_release, minor);
164 	if (r)
165 		return r;
166 
167 	minor->kdev = drm_sysfs_minor_alloc(minor);
168 	if (IS_ERR(minor->kdev))
169 		return PTR_ERR(minor->kdev);
170 
171 	*drm_minor_get_slot(dev, type) = minor;
172 	return 0;
173 }
174 
175 static int drm_minor_register(struct drm_device *dev, enum drm_minor_type type)
176 {
177 	struct drm_minor *minor;
178 	void *entry;
179 	int ret;
180 
181 	DRM_DEBUG("\n");
182 
183 	minor = *drm_minor_get_slot(dev, type);
184 	if (!minor)
185 		return 0;
186 
187 	if (minor->type != DRM_MINOR_ACCEL) {
188 		ret = drm_debugfs_register(minor, minor->index);
189 		if (ret) {
190 			DRM_ERROR("DRM: Failed to initialize /sys/kernel/debug/dri.\n");
191 			goto err_debugfs;
192 		}
193 	}
194 
195 	ret = device_add(minor->kdev);
196 	if (ret)
197 		goto err_debugfs;
198 
199 	/* replace NULL with @minor so lookups will succeed from now on */
200 	entry = xa_store(drm_minor_get_xa(type), minor->index, minor, GFP_KERNEL);
201 	if (xa_is_err(entry)) {
202 		ret = xa_err(entry);
203 		goto err_debugfs;
204 	}
205 	WARN_ON(entry);
206 
207 	DRM_DEBUG("new minor registered %d\n", minor->index);
208 	return 0;
209 
210 err_debugfs:
211 	drm_debugfs_unregister(minor);
212 	return ret;
213 }
214 
215 static void drm_minor_unregister(struct drm_device *dev, enum drm_minor_type type)
216 {
217 	struct drm_minor *minor;
218 
219 	minor = *drm_minor_get_slot(dev, type);
220 	if (!minor || !device_is_registered(minor->kdev))
221 		return;
222 
223 	/* replace @minor with NULL so lookups will fail from now on */
224 	xa_store(drm_minor_get_xa(type), minor->index, NULL, GFP_KERNEL);
225 
226 	device_del(minor->kdev);
227 	dev_set_drvdata(minor->kdev, NULL); /* safety belt */
228 	drm_debugfs_unregister(minor);
229 }
230 
231 /*
232  * Looks up the given minor-ID and returns the respective DRM-minor object. The
233  * refence-count of the underlying device is increased so you must release this
234  * object with drm_minor_release().
235  *
236  * As long as you hold this minor, it is guaranteed that the object and the
237  * minor->dev pointer will stay valid! However, the device may get unplugged and
238  * unregistered while you hold the minor.
239  */
240 struct drm_minor *drm_minor_acquire(struct xarray *minor_xa, unsigned int minor_id)
241 {
242 	struct drm_minor *minor;
243 
244 	xa_lock(minor_xa);
245 	minor = xa_load(minor_xa, minor_id);
246 	if (minor)
247 		drm_dev_get(minor->dev);
248 	xa_unlock(minor_xa);
249 
250 	if (!minor) {
251 		return ERR_PTR(-ENODEV);
252 	} else if (drm_dev_is_unplugged(minor->dev)) {
253 		drm_dev_put(minor->dev);
254 		return ERR_PTR(-ENODEV);
255 	}
256 
257 	return minor;
258 }
259 
260 void drm_minor_release(struct drm_minor *minor)
261 {
262 	drm_dev_put(minor->dev);
263 }
264 
265 /**
266  * DOC: driver instance overview
267  *
268  * A device instance for a drm driver is represented by &struct drm_device. This
269  * is allocated and initialized with devm_drm_dev_alloc(), usually from
270  * bus-specific ->probe() callbacks implemented by the driver. The driver then
271  * needs to initialize all the various subsystems for the drm device like memory
272  * management, vblank handling, modesetting support and initial output
273  * configuration plus obviously initialize all the corresponding hardware bits.
274  * Finally when everything is up and running and ready for userspace the device
275  * instance can be published using drm_dev_register().
276  *
277  * There is also deprecated support for initializing device instances using
278  * bus-specific helpers and the &drm_driver.load callback. But due to
279  * backwards-compatibility needs the device instance have to be published too
280  * early, which requires unpretty global locking to make safe and is therefore
281  * only support for existing drivers not yet converted to the new scheme.
282  *
283  * When cleaning up a device instance everything needs to be done in reverse:
284  * First unpublish the device instance with drm_dev_unregister(). Then clean up
285  * any other resources allocated at device initialization and drop the driver's
286  * reference to &drm_device using drm_dev_put().
287  *
288  * Note that any allocation or resource which is visible to userspace must be
289  * released only when the final drm_dev_put() is called, and not when the
290  * driver is unbound from the underlying physical struct &device. Best to use
291  * &drm_device managed resources with drmm_add_action(), drmm_kmalloc() and
292  * related functions.
293  *
294  * devres managed resources like devm_kmalloc() can only be used for resources
295  * directly related to the underlying hardware device, and only used in code
296  * paths fully protected by drm_dev_enter() and drm_dev_exit().
297  *
298  * Display driver example
299  * ~~~~~~~~~~~~~~~~~~~~~~
300  *
301  * The following example shows a typical structure of a DRM display driver.
302  * The example focus on the probe() function and the other functions that is
303  * almost always present and serves as a demonstration of devm_drm_dev_alloc().
304  *
305  * .. code-block:: c
306  *
307  *	struct driver_device {
308  *		struct drm_device drm;
309  *		void *userspace_facing;
310  *		struct clk *pclk;
311  *	};
312  *
313  *	static const struct drm_driver driver_drm_driver = {
314  *		[...]
315  *	};
316  *
317  *	static int driver_probe(struct platform_device *pdev)
318  *	{
319  *		struct driver_device *priv;
320  *		struct drm_device *drm;
321  *		int ret;
322  *
323  *		priv = devm_drm_dev_alloc(&pdev->dev, &driver_drm_driver,
324  *					  struct driver_device, drm);
325  *		if (IS_ERR(priv))
326  *			return PTR_ERR(priv);
327  *		drm = &priv->drm;
328  *
329  *		ret = drmm_mode_config_init(drm);
330  *		if (ret)
331  *			return ret;
332  *
333  *		priv->userspace_facing = drmm_kzalloc(..., GFP_KERNEL);
334  *		if (!priv->userspace_facing)
335  *			return -ENOMEM;
336  *
337  *		priv->pclk = devm_clk_get(dev, "PCLK");
338  *		if (IS_ERR(priv->pclk))
339  *			return PTR_ERR(priv->pclk);
340  *
341  *		// Further setup, display pipeline etc
342  *
343  *		platform_set_drvdata(pdev, drm);
344  *
345  *		ret = drm_mode_config_create_initial_state(drm);
346  *		if (ret)
347  *			return ret;
348  *
349  *		ret = drm_dev_register(drm);
350  *		if (ret)
351  *			return ret;
352  *
353  *		drm_fbdev_{...}_setup(drm, 32);
354  *
355  *		return 0;
356  *	}
357  *
358  *	// This function is called before the devm_ resources are released
359  *	static int driver_remove(struct platform_device *pdev)
360  *	{
361  *		struct drm_device *drm = platform_get_drvdata(pdev);
362  *
363  *		drm_dev_unregister(drm);
364  *		drm_atomic_helper_shutdown(drm)
365  *
366  *		return 0;
367  *	}
368  *
369  *	// This function is called on kernel restart and shutdown
370  *	static void driver_shutdown(struct platform_device *pdev)
371  *	{
372  *		drm_atomic_helper_shutdown(platform_get_drvdata(pdev));
373  *	}
374  *
375  *	static int __maybe_unused driver_pm_suspend(struct device *dev)
376  *	{
377  *		return drm_mode_config_helper_suspend(dev_get_drvdata(dev));
378  *	}
379  *
380  *	static int __maybe_unused driver_pm_resume(struct device *dev)
381  *	{
382  *		drm_mode_config_helper_resume(dev_get_drvdata(dev));
383  *
384  *		return 0;
385  *	}
386  *
387  *	static const struct dev_pm_ops driver_pm_ops = {
388  *		SET_SYSTEM_SLEEP_PM_OPS(driver_pm_suspend, driver_pm_resume)
389  *	};
390  *
391  *	static struct platform_driver driver_driver = {
392  *		.driver = {
393  *			[...]
394  *			.pm = &driver_pm_ops,
395  *		},
396  *		.probe = driver_probe,
397  *		.remove = driver_remove,
398  *		.shutdown = driver_shutdown,
399  *	};
400  *	module_platform_driver(driver_driver);
401  *
402  * Drivers that want to support device unplugging (USB, DT overlay unload) should
403  * use drm_dev_unplug() instead of drm_dev_unregister(). The driver must protect
404  * regions that is accessing device resources to prevent use after they're
405  * released. This is done using drm_dev_enter() and drm_dev_exit(). There is one
406  * shortcoming however, drm_dev_unplug() marks the drm_device as unplugged before
407  * drm_atomic_helper_shutdown() is called. This means that if the disable code
408  * paths are protected, they will not run on regular driver module unload,
409  * possibly leaving the hardware enabled.
410  */
411 
412 /**
413  * drm_put_dev - Unregister and release a DRM device
414  * @dev: DRM device
415  *
416  * Called at module unload time or when a PCI device is unplugged.
417  *
418  * Cleans up all DRM device, calling drm_lastclose().
419  *
420  * Note: Use of this function is deprecated. It will eventually go away
421  * completely.  Please use drm_dev_unregister() and drm_dev_put() explicitly
422  * instead to make sure that the device isn't userspace accessible any more
423  * while teardown is in progress, ensuring that userspace can't access an
424  * inconsistent state.
425  */
426 void drm_put_dev(struct drm_device *dev)
427 {
428 	DRM_DEBUG("\n");
429 
430 	if (!dev) {
431 		DRM_ERROR("cleanup called no dev\n");
432 		return;
433 	}
434 
435 	drm_dev_unregister(dev);
436 	drm_dev_put(dev);
437 }
438 EXPORT_SYMBOL(drm_put_dev);
439 
440 /**
441  * drm_dev_enter - Enter device critical section
442  * @dev: DRM device
443  * @idx: Pointer to index that will be passed to the matching drm_dev_exit()
444  *
445  * This function marks and protects the beginning of a section that should not
446  * be entered after the device has been unplugged. The section end is marked
447  * with drm_dev_exit(). Calls to this function can be nested.
448  *
449  * Returns:
450  * True if it is OK to enter the section, false otherwise.
451  */
452 bool drm_dev_enter(struct drm_device *dev, int *idx)
453 {
454 	*idx = srcu_read_lock(&drm_unplug_srcu);
455 
456 	if (dev->unplugged) {
457 		srcu_read_unlock(&drm_unplug_srcu, *idx);
458 		return false;
459 	}
460 
461 	return true;
462 }
463 EXPORT_SYMBOL(drm_dev_enter);
464 
465 /**
466  * drm_dev_exit - Exit device critical section
467  * @idx: index returned from drm_dev_enter()
468  *
469  * This function marks the end of a section that should not be entered after
470  * the device has been unplugged.
471  */
472 void drm_dev_exit(int idx)
473 {
474 	srcu_read_unlock(&drm_unplug_srcu, idx);
475 }
476 EXPORT_SYMBOL(drm_dev_exit);
477 
478 /*
479  * Mark the device as unplugged and wait for any in-flight drm_dev_enter()
480  * critical sections to complete.
481  */
482 static void drm_dev_synchronize_unplug(struct drm_device *dev)
483 {
484 	/*
485 	 * After synchronizing any critical read section is guaranteed to see
486 	 * the new value of ->unplugged, and any critical section which might
487 	 * still have seen the old value of ->unplugged is guaranteed to have
488 	 * finished.
489 	 */
490 	dev->unplugged = true;
491 	synchronize_srcu(&drm_unplug_srcu);
492 }
493 
494 /**
495  * drm_dev_unplug - unplug a DRM device
496  * @dev: DRM device
497  *
498  * This unplugs a hotpluggable DRM device, which makes it inaccessible to
499  * userspace operations. Entry-points can use drm_dev_enter() and
500  * drm_dev_exit() to protect device resources in a race free manner. This
501  * essentially unregisters the device like drm_dev_unregister(), but can be
502  * called while there are still open users of @dev.
503  */
504 void drm_dev_unplug(struct drm_device *dev)
505 {
506 	drm_dev_synchronize_unplug(dev);
507 	drm_dev_unregister(dev);
508 
509 	/* Clear all CPU mappings pointing to this device */
510 	unmap_mapping_range(dev->anon_inode->i_mapping, 0, 0, 1);
511 }
512 EXPORT_SYMBOL(drm_dev_unplug);
513 
514 /**
515  * drm_dev_set_dma_dev - set the DMA device for a DRM device
516  * @dev: DRM device
517  * @dma_dev: DMA device or NULL
518  *
519  * Sets the DMA device of the given DRM device. Only required if
520  * the DMA device is different from the DRM device's parent. After
521  * calling this function, the DRM device holds a reference on
522  * @dma_dev. Pass NULL to clear the DMA device.
523  */
524 void drm_dev_set_dma_dev(struct drm_device *dev, struct device *dma_dev)
525 {
526 	dma_dev = get_device(dma_dev);
527 
528 	put_device(dev->dma_dev);
529 	dev->dma_dev = dma_dev;
530 }
531 EXPORT_SYMBOL(drm_dev_set_dma_dev);
532 
533 /*
534  * Available recovery methods for wedged device. To be sent along with device
535  * wedged uevent.
536  */
537 static const char *drm_get_wedge_recovery(unsigned int opt)
538 {
539 	switch (BIT(opt)) {
540 	case DRM_WEDGE_RECOVERY_NONE:
541 		return "none";
542 	case DRM_WEDGE_RECOVERY_REBIND:
543 		return "rebind";
544 	case DRM_WEDGE_RECOVERY_BUS_RESET:
545 		return "bus-reset";
546 	case DRM_WEDGE_RECOVERY_VENDOR:
547 		return "vendor-specific";
548 	default:
549 		return NULL;
550 	}
551 }
552 
553 #define WEDGE_STR_LEN	32
554 #define PID_STR_LEN	15
555 #define COMM_STR_LEN	(TASK_COMM_LEN + 5)
556 
557 /**
558  * drm_dev_wedged_event - generate a device wedged uevent
559  * @dev: DRM device
560  * @method: method(s) to be used for recovery
561  * @info: optional information about the guilty task
562  *
563  * This generates a device wedged uevent for the DRM device specified by @dev.
564  * Recovery @method\(s) of choice will be sent in the uevent environment as
565  * ``WEDGED=<method1>[,..,<methodN>]`` in order of less to more side-effects.
566  * If caller is unsure about recovery or @method is unknown (0),
567  * ``WEDGED=unknown`` will be sent instead.
568  *
569  * Refer to "Device Wedging" chapter in Documentation/gpu/drm-uapi.rst for more
570  * details.
571  *
572  * Returns: 0 on success, negative error code otherwise.
573  */
574 int drm_dev_wedged_event(struct drm_device *dev, unsigned long method,
575 			 struct drm_wedge_task_info *info)
576 {
577 	char event_string[WEDGE_STR_LEN], pid_string[PID_STR_LEN], comm_string[COMM_STR_LEN];
578 	char *envp[] = { event_string, NULL, NULL, NULL };
579 	const char *recovery = NULL;
580 	unsigned int len, opt;
581 
582 	len = scnprintf(event_string, sizeof(event_string), "%s", "WEDGED=");
583 
584 	for_each_set_bit(opt, &method, BITS_PER_TYPE(method)) {
585 		recovery = drm_get_wedge_recovery(opt);
586 		if (drm_WARN_ONCE(dev, !recovery, "invalid recovery method %u\n", opt))
587 			break;
588 
589 		len += scnprintf(event_string + len, sizeof(event_string) - len, "%s,", recovery);
590 	}
591 
592 	if (recovery)
593 		/* Get rid of trailing comma */
594 		event_string[len - 1] = '\0';
595 	else
596 		/* Caller is unsure about recovery, do the best we can at this point. */
597 		snprintf(event_string, sizeof(event_string), "%s", "WEDGED=unknown");
598 
599 	drm_info(dev, "device wedged, %s\n", method == DRM_WEDGE_RECOVERY_NONE ?
600 		 "but no recovery needed" : "needs recovery");
601 
602 	if (info && (info->comm[0] != '\0') && (info->pid >= 0)) {
603 		snprintf(pid_string, sizeof(pid_string), "PID=%u", info->pid);
604 		snprintf(comm_string, sizeof(comm_string), "TASK=%s", info->comm);
605 		envp[1] = pid_string;
606 		envp[2] = comm_string;
607 	}
608 
609 	return kobject_uevent_env(&dev->primary->kdev->kobj, KOBJ_CHANGE, envp);
610 }
611 EXPORT_SYMBOL(drm_dev_wedged_event);
612 
613 /*
614  * DRM internal mount
615  * We want to be able to allocate our own "struct address_space" to control
616  * memory-mappings in VRAM (or stolen RAM, ...). However, core MM does not allow
617  * stand-alone address_space objects, so we need an underlying inode. As there
618  * is no way to allocate an independent inode easily, we need a fake internal
619  * VFS mount-point.
620  *
621  * The drm_fs_inode_new() function allocates a new inode, drm_fs_inode_free()
622  * frees it again. You are allowed to use iget() and iput() to get references to
623  * the inode. But each drm_fs_inode_new() call must be paired with exactly one
624  * drm_fs_inode_free() call (which does not have to be the last iput()).
625  * We use drm_fs_inode_*() to manage our internal VFS mount-point and share it
626  * between multiple inode-users. You could, technically, call
627  * iget() + drm_fs_inode_free() directly after alloc and sometime later do an
628  * iput(), but this way you'd end up with a new vfsmount for each inode.
629  */
630 
631 static int drm_fs_cnt;
632 static struct vfsmount *drm_fs_mnt;
633 
634 static int drm_fs_init_fs_context(struct fs_context *fc)
635 {
636 	return init_pseudo(fc, 0x010203ff) ? 0 : -ENOMEM;
637 }
638 
639 static struct file_system_type drm_fs_type = {
640 	.name		= "drm",
641 	.owner		= THIS_MODULE,
642 	.init_fs_context = drm_fs_init_fs_context,
643 	.kill_sb	= kill_anon_super,
644 };
645 
646 static struct inode *drm_fs_inode_new(void)
647 {
648 	struct inode *inode;
649 	int r;
650 
651 	r = simple_pin_fs(&drm_fs_type, &drm_fs_mnt, &drm_fs_cnt);
652 	if (r < 0) {
653 		DRM_ERROR("Cannot mount pseudo fs: %d\n", r);
654 		return ERR_PTR(r);
655 	}
656 
657 	inode = alloc_anon_inode(drm_fs_mnt->mnt_sb);
658 	if (IS_ERR(inode))
659 		simple_release_fs(&drm_fs_mnt, &drm_fs_cnt);
660 
661 	return inode;
662 }
663 
664 static void drm_fs_inode_free(struct inode *inode)
665 {
666 	if (inode) {
667 		iput(inode);
668 		simple_release_fs(&drm_fs_mnt, &drm_fs_cnt);
669 	}
670 }
671 
672 /**
673  * DOC: component helper usage recommendations
674  *
675  * DRM drivers that drive hardware where a logical device consists of a pile of
676  * independent hardware blocks are recommended to use the :ref:`component helper
677  * library<component>`. For consistency and better options for code reuse the
678  * following guidelines apply:
679  *
680  *  - The entire device initialization procedure should be run from the
681  *    &component_master_ops.master_bind callback, starting with
682  *    devm_drm_dev_alloc(), then binding all components with
683  *    component_bind_all() and finishing with drm_dev_register().
684  *
685  *  - The opaque pointer passed to all components through component_bind_all()
686  *    should point at &struct drm_device of the device instance, not some driver
687  *    specific private structure.
688  *
689  *  - The component helper fills the niche where further standardization of
690  *    interfaces is not practical. When there already is, or will be, a
691  *    standardized interface like &drm_bridge or &drm_panel, providing its own
692  *    functions to find such components at driver load time, like
693  *    drm_of_find_panel_or_bridge(), then the component helper should not be
694  *    used.
695  */
696 
697 static void drm_dev_init_release(struct drm_device *dev, void *res)
698 {
699 	drm_fs_inode_free(dev->anon_inode);
700 
701 	put_device(dev->dma_dev);
702 	dev->dma_dev = NULL;
703 	put_device(dev->dev);
704 	/* Prevent use-after-free in drm_managed_release when debugging is
705 	 * enabled. Slightly awkward, but can't really be helped. */
706 	dev->dev = NULL;
707 	mutex_destroy(&dev->master_mutex);
708 	mutex_destroy(&dev->clientlist_mutex);
709 	mutex_destroy(&dev->filelist_mutex);
710 	mutex_destroy(&dev->gem_lru_mutex);
711 }
712 
713 static int drm_dev_init(struct drm_device *dev,
714 			const struct drm_driver *driver,
715 			struct device *parent)
716 {
717 	struct inode *inode;
718 	int ret;
719 
720 	if (!drm_core_init_complete) {
721 		DRM_ERROR("DRM core is not initialized\n");
722 		return -ENODEV;
723 	}
724 
725 	if (WARN_ON(!parent))
726 		return -EINVAL;
727 
728 	kref_init(&dev->ref);
729 	dev->dev = get_device(parent);
730 	dev->driver = driver;
731 
732 	INIT_LIST_HEAD(&dev->managed.resources);
733 	spin_lock_init(&dev->managed.lock);
734 
735 	/* no per-device feature limits by default */
736 	dev->driver_features = ~0u;
737 
738 	if (drm_core_check_feature(dev, DRIVER_COMPUTE_ACCEL) &&
739 				(drm_core_check_feature(dev, DRIVER_RENDER) ||
740 				drm_core_check_feature(dev, DRIVER_MODESET))) {
741 		DRM_ERROR("DRM driver can't be both a compute acceleration and graphics driver\n");
742 		return -EINVAL;
743 	}
744 
745 	INIT_LIST_HEAD(&dev->filelist);
746 	INIT_LIST_HEAD(&dev->filelist_internal);
747 	INIT_LIST_HEAD(&dev->clientlist);
748 	INIT_LIST_HEAD(&dev->client_sysrq_list);
749 	INIT_LIST_HEAD(&dev->vblank_event_list);
750 
751 	spin_lock_init(&dev->event_lock);
752 	mutex_init(&dev->gem_lru_mutex);
753 	mutex_init(&dev->filelist_mutex);
754 	mutex_init(&dev->clientlist_mutex);
755 	mutex_init(&dev->master_mutex);
756 	raw_spin_lock_init(&dev->mode_config.panic_lock);
757 
758 	ret = drmm_add_action_or_reset(dev, drm_dev_init_release, NULL);
759 	if (ret)
760 		return ret;
761 
762 	inode = drm_fs_inode_new();
763 	if (IS_ERR(inode)) {
764 		ret = PTR_ERR(inode);
765 		DRM_ERROR("Cannot allocate anonymous inode: %d\n", ret);
766 		goto err;
767 	}
768 
769 	dev->anon_inode = inode;
770 
771 	if (drm_core_check_feature(dev, DRIVER_COMPUTE_ACCEL)) {
772 		ret = drm_minor_alloc(dev, DRM_MINOR_ACCEL);
773 		if (ret)
774 			goto err;
775 	} else {
776 		if (drm_core_check_feature(dev, DRIVER_RENDER)) {
777 			ret = drm_minor_alloc(dev, DRM_MINOR_RENDER);
778 			if (ret)
779 				goto err;
780 		}
781 
782 		ret = drm_minor_alloc(dev, DRM_MINOR_PRIMARY);
783 		if (ret)
784 			goto err;
785 	}
786 
787 	if (drm_core_check_feature(dev, DRIVER_GEM)) {
788 		ret = drm_gem_init(dev);
789 		if (ret) {
790 			DRM_ERROR("Cannot initialize graphics execution manager (GEM)\n");
791 			goto err;
792 		}
793 	}
794 
795 	dev->unique = drmm_kstrdup(dev, dev_name(parent), GFP_KERNEL);
796 	if (!dev->unique) {
797 		ret = -ENOMEM;
798 		goto err;
799 	}
800 
801 	drm_debugfs_dev_init(dev);
802 
803 	return 0;
804 
805 err:
806 	drm_managed_release(dev);
807 
808 	return ret;
809 }
810 
811 static void devm_drm_dev_init_release(void *data)
812 {
813 	drm_dev_put(data);
814 }
815 
816 static int devm_drm_dev_init(struct device *parent,
817 			     struct drm_device *dev,
818 			     const struct drm_driver *driver)
819 {
820 	int ret;
821 
822 	ret = drm_dev_init(dev, driver, parent);
823 	if (ret)
824 		return ret;
825 
826 	return devm_add_action_or_reset(parent,
827 					devm_drm_dev_init_release, dev);
828 }
829 
830 void *__devm_drm_dev_alloc(struct device *parent,
831 			   const struct drm_driver *driver,
832 			   size_t size, size_t offset)
833 {
834 	void *container;
835 	struct drm_device *drm;
836 	int ret;
837 
838 	container = kzalloc(size, GFP_KERNEL);
839 	if (!container)
840 		return ERR_PTR(-ENOMEM);
841 
842 	drm = container + offset;
843 	ret = devm_drm_dev_init(parent, drm, driver);
844 	if (ret) {
845 		kfree(container);
846 		return ERR_PTR(ret);
847 	}
848 	drmm_add_final_kfree(drm, container);
849 
850 	return container;
851 }
852 EXPORT_SYMBOL(__devm_drm_dev_alloc);
853 
854 /**
855  * __drm_dev_alloc - Allocation of a &drm_device instance
856  * @parent: Parent device object
857  * @driver: DRM driver
858  * @size: the size of the struct which contains struct drm_device
859  * @offset: the offset of the &drm_device within the container.
860  *
861  * This should *NOT* be by any drivers, but is a dedicated interface for the
862  * corresponding Rust abstraction.
863  *
864  * This is the same as devm_drm_dev_alloc(), but without the corresponding
865  * resource management through the parent device, but not the same as
866  * drm_dev_alloc(), since the latter is the deprecated version, which does not
867  * support subclassing.
868  *
869  * Returns: A pointer to new DRM device, or an ERR_PTR on failure.
870  */
871 void *__drm_dev_alloc(struct device *parent,
872 		      const struct drm_driver *driver,
873 		      size_t size, size_t offset)
874 {
875 	void *container;
876 	struct drm_device *drm;
877 	int ret;
878 
879 	container = kzalloc(size, GFP_KERNEL);
880 	if (!container)
881 		return ERR_PTR(-ENOMEM);
882 
883 	drm = container + offset;
884 	ret = drm_dev_init(drm, driver, parent);
885 	if (ret) {
886 		kfree(container);
887 		return ERR_PTR(ret);
888 	}
889 	drmm_add_final_kfree(drm, container);
890 
891 	return container;
892 }
893 EXPORT_SYMBOL(__drm_dev_alloc);
894 
895 /**
896  * drm_dev_alloc - Allocate new DRM device
897  * @driver: DRM driver to allocate device for
898  * @parent: Parent device object
899  *
900  * This is the deprecated version of devm_drm_dev_alloc(), which does not support
901  * subclassing through embedding the struct &drm_device in a driver private
902  * structure, and which does not support automatic cleanup through devres.
903  *
904  * RETURNS:
905  * Pointer to new DRM device, or ERR_PTR on failure.
906  */
907 struct drm_device *drm_dev_alloc(const struct drm_driver *driver,
908 				 struct device *parent)
909 {
910 	return __drm_dev_alloc(parent, driver, sizeof(struct drm_device), 0);
911 }
912 EXPORT_SYMBOL(drm_dev_alloc);
913 
914 static void drm_dev_release(struct kref *ref)
915 {
916 	struct drm_device *dev = container_of(ref, struct drm_device, ref);
917 
918 	/* Just in case register/unregister was never called */
919 	drm_debugfs_dev_fini(dev);
920 
921 	if (dev->driver->release)
922 		dev->driver->release(dev);
923 
924 	drm_managed_release(dev);
925 
926 	kfree(dev->managed.final_kfree);
927 }
928 
929 /**
930  * drm_dev_get - Take reference of a DRM device
931  * @dev: device to take reference of or NULL
932  *
933  * This increases the ref-count of @dev by one. You *must* already own a
934  * reference when calling this. Use drm_dev_put() to drop this reference
935  * again.
936  *
937  * This function never fails. However, this function does not provide *any*
938  * guarantee whether the device is alive or running. It only provides a
939  * reference to the object and the memory associated with it.
940  */
941 void drm_dev_get(struct drm_device *dev)
942 {
943 	if (dev)
944 		kref_get(&dev->ref);
945 }
946 EXPORT_SYMBOL(drm_dev_get);
947 
948 /**
949  * drm_dev_put - Drop reference of a DRM device
950  * @dev: device to drop reference of or NULL
951  *
952  * This decreases the ref-count of @dev by one. The device is destroyed if the
953  * ref-count drops to zero.
954  */
955 void drm_dev_put(struct drm_device *dev)
956 {
957 	if (dev)
958 		kref_put(&dev->ref, drm_dev_release);
959 }
960 EXPORT_SYMBOL(drm_dev_put);
961 
962 static void drmm_cg_unregister_region(struct drm_device *dev, void *arg)
963 {
964 	dmem_cgroup_unregister_region(arg);
965 }
966 
967 /**
968  * drmm_cgroup_register_region - Register a region of a DRM device to cgroups
969  * @dev: device for region
970  * @region_name: Region name for registering
971  * @init: Initialization parameters for the region.
972  *
973  * This decreases the ref-count of @dev by one. The device is destroyed if the
974  * ref-count drops to zero.
975  */
976 struct dmem_cgroup_region *
977 drmm_cgroup_register_region(struct drm_device *dev, const char *region_name,
978 			    const struct dmem_cgroup_init *init)
979 {
980 	struct dmem_cgroup_region *region;
981 	int ret;
982 
983 	region = dmem_cgroup_register_region(init, "drm/%s/%s", dev->unique, region_name);
984 	if (IS_ERR_OR_NULL(region))
985 		return region;
986 
987 	ret = drmm_add_action_or_reset(dev, drmm_cg_unregister_region, region);
988 	if (ret)
989 		return ERR_PTR(ret);
990 
991 	return region;
992 }
993 EXPORT_SYMBOL_GPL(drmm_cgroup_register_region);
994 
995 static int create_compat_control_link(struct drm_device *dev)
996 {
997 	struct drm_minor *minor;
998 	char *name;
999 	int ret;
1000 
1001 	if (!drm_core_check_feature(dev, DRIVER_MODESET))
1002 		return 0;
1003 
1004 	minor = *drm_minor_get_slot(dev, DRM_MINOR_PRIMARY);
1005 	if (!minor)
1006 		return 0;
1007 
1008 	/*
1009 	 * Some existing userspace out there uses the existing of the controlD*
1010 	 * sysfs files to figure out whether it's a modeset driver. It only does
1011 	 * readdir, hence a symlink is sufficient (and the least confusing
1012 	 * option). Otherwise controlD* is entirely unused.
1013 	 *
1014 	 * Old controlD chardev have been allocated in the range
1015 	 * 64-127.
1016 	 */
1017 	name = kasprintf(GFP_KERNEL, "controlD%d", minor->index + 64);
1018 	if (!name)
1019 		return -ENOMEM;
1020 
1021 	ret = sysfs_create_link(minor->kdev->kobj.parent,
1022 				&minor->kdev->kobj,
1023 				name);
1024 
1025 	kfree(name);
1026 
1027 	return ret;
1028 }
1029 
1030 static void remove_compat_control_link(struct drm_device *dev)
1031 {
1032 	struct drm_minor *minor;
1033 	char *name;
1034 
1035 	if (!drm_core_check_feature(dev, DRIVER_MODESET))
1036 		return;
1037 
1038 	minor = *drm_minor_get_slot(dev, DRM_MINOR_PRIMARY);
1039 	if (!minor)
1040 		return;
1041 
1042 	name = kasprintf(GFP_KERNEL, "controlD%d", minor->index + 64);
1043 	if (!name)
1044 		return;
1045 
1046 	sysfs_remove_link(minor->kdev->kobj.parent, name);
1047 
1048 	kfree(name);
1049 }
1050 
1051 /**
1052  * drm_dev_register - Register DRM device
1053  * @dev: Device to register
1054  * @flags: Flags passed to the driver's .load() function
1055  *
1056  * Register the DRM device @dev with the system, advertise device to user-space
1057  * and start normal device operation. @dev must be initialized via drm_dev_init()
1058  * previously.
1059  *
1060  * Never call this twice on any device!
1061  *
1062  * NOTE: To ensure backward compatibility with existing drivers method this
1063  * function calls the &drm_driver.load method after registering the device
1064  * nodes, creating race conditions. Usage of the &drm_driver.load methods is
1065  * therefore deprecated, drivers must perform all initialization before calling
1066  * drm_dev_register().
1067  *
1068  * RETURNS:
1069  * 0 on success, negative error code on failure.
1070  */
1071 int drm_dev_register(struct drm_device *dev, unsigned long flags)
1072 {
1073 	const struct drm_driver *driver = dev->driver;
1074 	int ret;
1075 
1076 	if (!driver->load)
1077 		drm_mode_config_validate(dev);
1078 
1079 	WARN_ON(!dev->managed.final_kfree);
1080 
1081 	if (drm_dev_needs_global_mutex(dev))
1082 		mutex_lock(&drm_global_mutex);
1083 
1084 	if (drm_core_check_feature(dev, DRIVER_COMPUTE_ACCEL))
1085 		accel_debugfs_register(dev);
1086 	else
1087 		drm_debugfs_dev_register(dev);
1088 
1089 	ret = drm_minor_register(dev, DRM_MINOR_RENDER);
1090 	if (ret)
1091 		goto err_minors;
1092 
1093 	ret = drm_minor_register(dev, DRM_MINOR_PRIMARY);
1094 	if (ret)
1095 		goto err_minors;
1096 
1097 	ret = drm_minor_register(dev, DRM_MINOR_ACCEL);
1098 	if (ret)
1099 		goto err_minors;
1100 
1101 	ret = create_compat_control_link(dev);
1102 	if (ret)
1103 		goto err_minors;
1104 
1105 	dev->registered = true;
1106 	dev->unplugged = false;
1107 
1108 	if (driver->load) {
1109 		ret = driver->load(dev, flags);
1110 		if (ret)
1111 			goto err_minors;
1112 	}
1113 
1114 	if (drm_core_check_feature(dev, DRIVER_MODESET)) {
1115 		ret = drm_modeset_register_all(dev);
1116 		if (ret)
1117 			goto err_unload;
1118 	}
1119 	drm_panic_register(dev);
1120 	drm_client_sysrq_register(dev);
1121 
1122 	DRM_INFO("Initialized %s %d.%d.%d for %s on minor %d\n",
1123 		 driver->name, driver->major, driver->minor,
1124 		 driver->patchlevel,
1125 		 dev->dev ? dev_name(dev->dev) : "virtual device",
1126 		 dev->primary ? dev->primary->index : dev->accel->index);
1127 
1128 	goto out_unlock;
1129 
1130 err_unload:
1131 	if (dev->driver->unload)
1132 		dev->driver->unload(dev);
1133 err_minors:
1134 	/*
1135 	 * If a minor was registered before the failure, userspace could have
1136 	 * opened it and entered a drm_dev_enter() critical section. Ensure all
1137 	 * such sections complete before we clean up.
1138 	 */
1139 	drm_dev_synchronize_unplug(dev);
1140 
1141 	remove_compat_control_link(dev);
1142 	drm_minor_unregister(dev, DRM_MINOR_ACCEL);
1143 	drm_minor_unregister(dev, DRM_MINOR_PRIMARY);
1144 	drm_minor_unregister(dev, DRM_MINOR_RENDER);
1145 out_unlock:
1146 	if (drm_dev_needs_global_mutex(dev))
1147 		mutex_unlock(&drm_global_mutex);
1148 	return ret;
1149 }
1150 EXPORT_SYMBOL(drm_dev_register);
1151 
1152 /**
1153  * drm_dev_unregister - Unregister DRM device
1154  * @dev: Device to unregister
1155  *
1156  * Unregister the DRM device from the system. This does the reverse of
1157  * drm_dev_register() but does not deallocate the device. The caller must call
1158  * drm_dev_put() to drop their final reference, unless it is managed with devres
1159  * (as devices allocated with devm_drm_dev_alloc() are), in which case there is
1160  * already an unwind action registered.
1161  *
1162  * A special form of unregistering for hotpluggable devices is drm_dev_unplug(),
1163  * which can be called while there are still open users of @dev.
1164  *
1165  * This should be called first in the device teardown code to make sure
1166  * userspace can't access the device instance any more.
1167  */
1168 void drm_dev_unregister(struct drm_device *dev)
1169 {
1170 	dev->registered = false;
1171 
1172 	drm_client_sysrq_unregister(dev);
1173 	drm_panic_unregister(dev);
1174 
1175 	drm_client_dev_unregister(dev);
1176 
1177 	if (drm_core_check_feature(dev, DRIVER_MODESET))
1178 		drm_modeset_unregister_all(dev);
1179 
1180 	if (dev->driver->unload)
1181 		dev->driver->unload(dev);
1182 
1183 	remove_compat_control_link(dev);
1184 	drm_minor_unregister(dev, DRM_MINOR_ACCEL);
1185 	drm_minor_unregister(dev, DRM_MINOR_PRIMARY);
1186 	drm_minor_unregister(dev, DRM_MINOR_RENDER);
1187 	drm_debugfs_dev_fini(dev);
1188 }
1189 EXPORT_SYMBOL(drm_dev_unregister);
1190 
1191 /*
1192  * DRM Core
1193  * The DRM core module initializes all global DRM objects and makes them
1194  * available to drivers. Once setup, drivers can probe their respective
1195  * devices.
1196  * Currently, core management includes:
1197  *  - The "DRM-Global" key/value database
1198  *  - Global ID management for connectors
1199  *  - DRM major number allocation
1200  *  - DRM minor management
1201  *  - DRM sysfs class
1202  *  - DRM debugfs root
1203  *
1204  * Furthermore, the DRM core provides dynamic char-dev lookups. For each
1205  * interface registered on a DRM device, you can request minor numbers from DRM
1206  * core. DRM core takes care of major-number management and char-dev
1207  * registration. A stub ->open() callback forwards any open() requests to the
1208  * registered minor.
1209  */
1210 
1211 static int drm_stub_open(struct inode *inode, struct file *filp)
1212 {
1213 	const struct file_operations *new_fops;
1214 	struct drm_minor *minor;
1215 	int err;
1216 
1217 	DRM_DEBUG("\n");
1218 
1219 	minor = drm_minor_acquire(&drm_minors_xa, iminor(inode));
1220 	if (IS_ERR(minor))
1221 		return PTR_ERR(minor);
1222 
1223 	new_fops = fops_get(minor->dev->driver->fops);
1224 	if (!new_fops) {
1225 		err = -ENODEV;
1226 		goto out;
1227 	}
1228 
1229 	replace_fops(filp, new_fops);
1230 	if (filp->f_op->open)
1231 		err = filp->f_op->open(inode, filp);
1232 	else
1233 		err = 0;
1234 
1235 out:
1236 	drm_minor_release(minor);
1237 
1238 	return err;
1239 }
1240 
1241 static const struct file_operations drm_stub_fops = {
1242 	.owner = THIS_MODULE,
1243 	.open = drm_stub_open,
1244 	.llseek = noop_llseek,
1245 };
1246 
1247 static void drm_core_exit(void)
1248 {
1249 	drm_ras_genl_family_unregister();
1250 	drm_privacy_screen_lookup_exit();
1251 	drm_panic_exit();
1252 	accel_core_exit();
1253 	unregister_chrdev(DRM_MAJOR, "drm");
1254 	drm_debugfs_remove_root();
1255 	drm_sysfs_destroy();
1256 	WARN_ON(!xa_empty(&drm_minors_xa));
1257 	drm_connector_ida_destroy();
1258 }
1259 
1260 static int __init drm_core_init(void)
1261 {
1262 	int ret;
1263 
1264 	drm_connector_ida_init();
1265 	drm_memcpy_init_early();
1266 
1267 	ret = drm_sysfs_init();
1268 	if (ret < 0) {
1269 		DRM_ERROR("Cannot create DRM class: %d\n", ret);
1270 		goto error;
1271 	}
1272 
1273 	drm_debugfs_init_root();
1274 	drm_debugfs_bridge_params();
1275 
1276 	ret = register_chrdev(DRM_MAJOR, "drm", &drm_stub_fops);
1277 	if (ret < 0)
1278 		goto error;
1279 
1280 	ret = accel_core_init();
1281 	if (ret < 0)
1282 		goto error;
1283 
1284 	drm_panic_init();
1285 
1286 	drm_privacy_screen_lookup_init();
1287 
1288 	ret = drm_ras_genl_family_register();
1289 	if (ret < 0)
1290 		goto error;
1291 
1292 	drm_core_init_complete = true;
1293 
1294 	DRM_DEBUG("Initialized\n");
1295 	return 0;
1296 
1297 error:
1298 	drm_core_exit();
1299 	return ret;
1300 }
1301 
1302 module_init(drm_core_init);
1303 module_exit(drm_core_exit);
1304