← Back to archive

Daily update · Oct 10–11, 2026

Graphics driver fixes: VC4 teardown races, AMD doorbell alignment, Xe and more

A large DRM-focused batch addresses crashes, hangs, memory leaks and display timing issues across a dozen GPU drivers, plus a couple of I2C and EDAC fixes.

In brief

This batch is almost entirely DRM (Direct Rendering Manager) fixes, touching VC4, AMDGPU/AMDKFD, Xe/i915, Nouveau, Panthor, VMware, Imagination, and display helpers. Raspberry Pi's VC4 gets teardown and runtime suspend fixes, AMD gets doorbell alignment and reset-safety improvements, and several drivers get memory-leak or out-of-bounds fixes. Two non-graphics patches address an i2c runtime-PM leak and an EDAC mask change.

Raspberry Pi VC4

Drain hangcheck timer and work on V3D unbind

vc4_v3d_unbind() now drains the hangcheck timer, cancels reset work, and flushes job_done_work before uninstalling the V3D interrupt. Previously a still-armed timer could read V3D registers through a NULL vc4->v3d pointer, and late callbacks could run after the containing vc4_dev was freed.

Why it matters: Prevents use-after-free and NULL-pointer access when unbinding VC4.

94cf5971b1d0

Disable the V3D interrupt across runtime suspend

vc4_irq_disable() masks V3D interrupt sources and synchronizes the IRQ, but on Raspberry Pi 0-3 the ARMCTRL controller has no active state, so a CPU may still run the handler after the GPU is powered down. The driver now disables the interrupt across runtime suspend.

Why it matters: Fixes a race where the V3D handler could run after power-down.

6abc8e4dcfbc

Fix binner slot allocation failing on an idle GPU

Binner slots are returned by job_done work, but the seqno wait could wake before that work ran, leaving the pool full and causing -ENOMEM. The fix makes allocation wait for the actual slot release.

Why it matters: Fixes spurious submit failures under bursts of small GPU jobs.

cca01232d94a

Free the BO cache size list on teardown

vc4_bo_cache_destroy() freed cached BOs but not the size-list nodes, leaking memory on every unbind.

Why it matters: Fixes a memory leak during VC4 teardown.

b41ff8b52927

Use kvmalloc_objs() for the BO cache size list

The BO cache size list grows with the largest BO freed, and using kmalloc could require a high-order allocation that fails under fragmentation. kvmalloc_objs() allows fallback to vmalloc.

Why it matters: Avoids allocation failures and warn_alloc() splats when large BOs are closed.

bca45af5998a

Fix firmware reference leak in vc4_drm_bind()

If aperture_remove_all_conflicting_devices() fails, the previously acquired Raspberry Pi firmware reference was leaked; error handling now puts it before returning.

Why it matters: Fixes a firmware reference leak on VC4 bind failure.

b816da5d5df1

AMDGPU and AMDKFD

Fix direct scanout alpha for some DRM_FORMATs

amdgpu_dm had its own hardcoded list of alpha-capable DRM formats, and it missed some, so direct scanout planes could be rendered opaque. It now checks the format's has_alpha field from DRM core.

Why it matters: Fixes missing alpha blending on affected display formats.

7744262f5d63

Only accept doorbell BOs as user queue doorbells

The user queue doorbell index helper pinned any BO passed in as a doorbell handle into the doorbell domain. A regular BO would be moved and its contents lost, and an importer could do this to a buffer shared from another client. The patch accepts only BOs created in the doorbell domain.

Why it matters: Prevents data loss and cross-client buffer corruption via the userq IOCTL.

7f7c88dbf4d5

Return memdup_user() error for user MQD

The usermode queue MQD creation always translated memdup_user() failures into -ENOMEM, hiding the real error (-EFAULT or -EINTR). It now returns PTR_ERR() and drops the error messages.

Why it matters: Userspace gets accurate error codes and the kernel log is not spammed by invalid IOCTLs.

76ceb6ed610c

Disable self-refresh on tearing flips

Immediate (tearing) flips conflict with PSR/Replay assumptions, so amdgpu_dm now disables panel self-refresh for those flips.

Why it matters: Prevents PSR/Replay state-machine failures when tearing flips are used.

2e54a92e0136

Serialize vblank counter reads against GPU reset

The vblank counter callback read display hardware without holding the reset semaphore, which could race with GPU reset and trigger lockdep assertions. It now takes the semaphore for reading and uses the software vblank count if reset is in progress.

Why it matters: Avoids lockdep warnings and display hardware access while reset is running.

1a6023edfbb5

Copy debugfs register data outside GRBM/SRBM locks

The regs2 debugfs file performed copy_from/to_user() while holding GRBM/SRBM bank selection locks, creating a circular locking dependency with mmap_lock. The copy now happens outside the locks.

Why it matters: Fixes lockdep-detected circular locking when using umr or debugfs register access.

16c64495859f

Align SDMA doorbell base for shader doorbell writes

On GC 9.4.3, 9.4.4 and 9.5.0, shader doorbell writes are routed at 4-index granularity, so odd SDMA engines with unaligned bases could ring the previous engine's doorbell and stall queues. Per-engine bases are now aligned to a 4-index boundary.

Why it matters: Prevents hangs for shader doorbell writes to SDMA queues on those ASICs.

f145d5b3f740

Don't replace a sink mode that shares native totals

The mode-timing logic copied native timing into any requested mode with the same clock, htotal, and vtotal, which also affected real sink modes such as 4096x2160@60 when 3840x2160@60 was preferred. The replacement is now limited to modes amdgpu inserted itself.

Why it matters: Fixes wrong scaling and timing/InfoFrame data for display modes that share native totals.

54c998c55fc9

Fix dma_buf reference leak in get_dmabuf_info

If metadata buffer allocation failed in amdgpu_amdkfd_get_dmabuf_info(), the dma_buf reference taken earlier was leaked. All error paths now go through a cleanup label that calls dma_buf_put().

Why it matters: Fixes a dma_buf reference leak on allocation failure in KFD dmabuf info get.

e6895021a328

Make Mac FB workaround generic

The Apple framebuffer workaround was previously enabled per chip. It now triggers whenever the framebuffer is at address 0 and the subsystem vendor ID is Apple, covering all affected chips.

Why it matters: Applies the existing workaround to current/future AMD GPUs on Apple hardware.

c7f44ec5c4ec

Intel Xe and i915

Honor delay/sleep maximums in xe_mmio_wait32()

xe_mmio_wait32() used udelay() without checking for overflow, and the backoff could grow extremely large. The patch caps the in-loop wait and detects overflow.

Why it matters: Prevents extremely long or wrapped waits in xe_mmio_wait32().

e7ed652b1312

Do not emit Wa_16010904313 twice

Due to a rebase error, Wa_16010904313 was emitted both in the indirect context and in the workaround batch buffer where it should only appear once. The emission location is now passed as a parameter.

Why it matters: Fixes duplicate workaround emission on Xe engines.

f7fc61e66041

Fix shrinker accounting double-subtraction on nested external pins

xe_bo_pin_external() and unpin_external() support nested pins but changed shrinker accounting on every call. A dma-buf pinned multiple times was subtracted from the shrinker's accounting each time, even though its pages were still pinned. Accounting is now done only on the outermost pin and final unpin.

Why it matters: Fixes incorrect shrinker accounting for multi-pinned external BOs.

83d5acca1f4f

Fix stale pinned_link entry when fb-pin performs the final unpin

External pin tracking in xe maintains a pinned_link list. Display framebuffer pins change pin_count without going through the external helpers, so the list could keep a stale entry after the final unpin happened from the fb path.

Why it matters: Fixes stale linked-list state for BOs pinned both externally and as framebuffers.

cf238c067eaa

Fix mailbox header handling

The sysctrl mailbox header was declared __le32 and converted with cpu_to_le32/le32_to_cpu, but the header is always handled as a CPU-order 32-bit value through xe_mmio_read32/write32. On big-endian systems the conversions could be wrong.

Why it matters: Fixes mailbox header handling on big-endian; no change on little-endian.

f0a4447789ef

Cancel client work on i2c remove

xe_i2c_remove() unregistered the adapter but did not cancel i2c->work. A queued work item could instantiate an AMC client after the adapter was released, using freed memory.

Why it matters: Fixes a use-after-free race during Xe i2c removal.

611857adc9e7

Prevent overstepping exec array boundary

In i915 execbuffer slow relocation parsing, the command parser appends VMAs to the exec array, but cleanup used the incremented buffer_count and could kvfree() pointers beyond the original exec array. Cleanup now uses the original exec object count.

Why it matters: Fixes a possible out-of-bounds free in the execbuffer path.

ebe162db6558

Unmask interrupts only when ACTIVE is true

A race between intel_rps_boost() reading ACTIVE state and queued work could unmask RPS PM interrupts after GT park, without holding a PM wakelock. The unmask now only happens when ACTIVE is true.

Why it matters: Fixes a PM wakelock ordering problem seen in selftests.

5346b1cec6af

Other DRM drivers

Fix error check on dw_hdmi_probe() return value

After dw_hdmi_probe(), the TH1520 bridge driver checked the hdmi pointer for IS_ERR() instead of the returned dw_hdmi. The patch checks the correct variable.

Why it matters: Correctly detects probe failure in the TH1520 HDMI bridge driver.

add916cfcec5

Fix remove() callback in th1520-dw-hdmi

The TH1520 remove callback read platform drvdata as a struct dw_hdmi * although it stores struct th1520_hdmi *, and then passed the wrong pointer to dw_hdmi_remove(). It now retrieves th1520_hdmi and passes hdmi->dw_hdmi.

Why it matters: Fixes teardown running on the wrong object in the TH1520 bridge driver.

01c83795d50c

Validate pitch from userspace in vmwgfx

vmwgfx cursor snooping now validates the pitch supplied by userspace along with the box dimensions before copying data from the underlying surface.

Why it matters: Fixes possible out-of-bounds reads with cursor snooping.

21bc51cb89ce

Add blend mode property to vmwgfx

vmwgfx adds support for the blend mode property so the core DRM code stops complaining about an unsupported property.

Why it matters: Stops log spam from the core DRM blend-mode check.

e78a9fb7a40c

Fix unlocked list_del in drm_bridge_add()

drm_bridge_add() removed a bridge from the bridge_lingering_list without holding bridge_lock, even though other list operations and the debugfs walker use the lock. The empty/list_del sequence now runs under bridge_lock.

Why it matters: Fixes a potential list corruption when re-adding a bridge.

b62e3db8cdc1

Fix unlocked list access in drm_bridge_attach()

drm_bridge_attach() inspected bridge->list without bridge_lock, which is a data race with concurrent list mutations. The check is now done under the lock.

Why it matters: Eliminates a data race in bridge attachment warnings.

57889076afd1

Validate userspace queue count against initialized firmware slot count

Panthor validated the userspace queue count only against MAX_CS_PER_CSG, not the number of stream interfaces initialized from firmware data. If firmware reported fewer slots, unprivileged userspace could force access to an uninitialized stream interface.

Why it matters: Prevents a crash when requesting more queues than the firmware initialized.

ec86c43dcfff

Don't mark AUX backlight enabled when enabling failed

If drm_edp_backlight_enable() failed, dp_aux_backlight_update_status() still marked the backlight as enabled, so later brightness changes skipped the enable step. It now returns the error, allowing the next update to retry enabling.

Why it matters: Fixes a panel that stays dark after AUX backlight enable fails.

707ce1025214

Check gsp->rm as well as gsp pointer before gcx ready

On Turing systems where GSP exists but is not used, the GCX-ready check now verifies gsp->rm as well as the gsp pointer.

Why it matters: Prevents a crash on GSP-but-unused Turing configurations.

4d0e27041185

Skip Turing CE workaround object for non-GR channels

The Turing CE workaround object was meant for the old Gallium driver, but it was being assigned to all channels. It now only applies to GR channels.

Why it matters: Fixes async copy engine (CE) operation on Turing.

6ccf996a0dec

Defer setup when fbdev_probe() fails, not just on -EAGAIN

fb_helper only deferred setup when the single-fb probe returned -EAGAIN. Any other fbdev_probe() failure left mode_sets with fb == NULL and no retry. All failures now set deferred_setup.

Why it matters: Lets fbdev emulation retry after transient probe failures.

755c94d178b7

Balance display clock enable on teardown

aspeed_gfx_load() enabled the display clock without disabling it on probe failure or removal. Using devm_clk_get_enabled() fixes error handling and automatic disable/unprepare.

Why it matters: Fixes unbalanced display clock enable on Aspeed GFX teardown.

ecce445c6489

Don't keep connector without a CRTC as connector_state

In gud_pipe_update(), if no connector in the new state had a CRTC, connector_state was left pointing at the last visited connector instead of NULL, skipping the fallback that finds the active connector.

Why it matters: Fixes active connector selection in the GUD USB display driver.

71ec70ea26e3

Fix reference and vm_bo handling in remap()

pvr_vm_gpuva_remap() took a GEM reference for each split part that was never dropped, and linked split parts to the new vm_bo instead of the original object's vm_bo. Both are fixed.

Why it matters: Fixes a memory leak and wrong vm_bo linkage during PVR mappings.

196d4d10c1b3

Size page table preallocation by device address

PVR page-table preallocation used device_addr plus sgt_offset with an exclusive end, which could allocate an extra table or underflow when mappings cross boundaries. Preallocation is now counted from device_addr with an inclusive end.

Why it matters: Fixes page-table preallocation sizing for device mappings.

789f290b2e81

Non-graphics fixes

Release runtime PM reference when set_rate fails

geni_i2c_xfer() took a runtime-PM reference and leaked it if the set_rate() callback failed, leaving the controller resumed indefinitely. The error now goes through the common cleanup path.

Why it matters: Fixes a runtime PM leak on Qualcomm Geni I2C set_rate failure.

ae8364085574

Mask UMC chip select to the four implemented selects

The EDAC amd64 driver changed the UMC chip-select mask from 0x7 to 0x3. All Zen systems have at most four chip selects, and future systems redefine the field the same way.

Why it matters: Keeps EDAC UMC decoding correct on current and future AMD platforms.

7484bc43ba6b

Source commits41 entries +
add916cfcec5

drm/bridge: th1520-dw-hdmi: Fix error check on dw_hdmi_probe() return value

Felix Gu · Mar 20, 2026 · 1 files

01c83795d50c

drm/bridge: th1520-dw-hdmi: Fix remove() callback

Felix Gu · Mar 20, 2026 · 1 files

ec86c43dcfff

drm/panthor: validate userspace queue count against initialized firmware slot count

Osama Abdelkader · Aug 4, 2026 · 1 files

21bc51cb89ce

drm/vmwgfx: validate pitch coming from userspace

Zack Rusin · Aug 9, 2026 · 1 files

b62e3db8cdc1

drm/bridge: Fix unlocked list_del in drm_bridge_add()

Cristian Ciocaltea · Sep 1, 2026 · 1 files

57889076afd1

drm/bridge: Fix unlocked list access in drm_bridge_attach()

Cristian Ciocaltea · Sep 1, 2026 · 1 files

5346b1cec6af

drm/i915/gt: Unmask interrupts only when ACTIVE is true

Krzysztof Karas · Sep 10, 2026 · 1 files

ebe162db6558

drm/i915/gem: Prevent overstepping exec array boundary

Krzysztof Karas · Sep 11, 2026 · 1 files

ecce445c6489

drm/aspeed: Balance the display clock enable on teardown

Myeonghun Pak · Sep 13, 2026 · 1 files

94cf5971b1d0

drm/vc4: drain the hangcheck timer and works on V3D unbind

Fan Wu · Sep 15, 2026 · 1 files

b816da5d5df1

drm/vc4: Fix firmware reference leak in vc4_drm_bind()

Wentao Liang · Sep 16, 2026 · 1 files

e78a9fb7a40c

drm/vmwgfx: Add blend mode property

Ian Forbes · Sep 16, 2026 · 1 files

71ec70ea26e3

drm/gud: don't keep a connector without a CRTC as connector_state

Sajal Gupta · Sep 22, 2026 · 1 files

f0a4447789ef

drm/xe/sysctrl: Fix mailbox header handling

Mallesh Koujalagi · Sep 24, 2026 · 1 files

f145d5b3f740

drm/amdkfd: align SDMA doorbell base for shader doorbell writes

Saleel Kudchadker · Sep 24, 2026 · 2 files

54c998c55fc9

drm/amd/display: Don't replace a sink mode that shares the native totals

Adrian Betschart · Sep 25, 2026 · 2 files

f7fc61e66041

drm/xe: Do not emit Wa_16010904313 twice

Tvrtko Ursulin · Sep 25, 2026 · 1 files

c7f44ec5c4ec

drm/amdgpu: make Mac FB workaround generic

Alex Deucher · Sep 25, 2026 · 1 files

707ce1025214

drm/dp: don't mark the AUX backlight enabled when enabling failed

Oleg Keri · Sep 25, 2026 · 1 files

6abc8e4dcfbc

drm/vc4: Disable the V3D interrupt across runtime suspend

Maíra Canal · Sep 25, 2026 · 2 files

755c94d178b7

drm/fb-helper: defer setup when fbdev_probe() fails, not just on -EAGAIN

Nguyen Ngoc Thang · Sep 27, 2026 · 1 files

e7ed652b1312

drm/xe/mmio: Fix xe_mmio_wait32() to honor delay/sleep maximums

Alan Previn · Sep 29, 2026 · 1 files

7744262f5d63

drm/amd/display: Fix direct scanout alpha on some DRM_FORMATs

Leo Li · Sep 29, 2026 · 1 files

1a6023edfbb5

drm/amdgpu: serialize vblank counter reads against GPU reset

Vitaly Prosyak · Sep 30, 2026 · 1 files

76ceb6ed610c

drm/amdgpu/userq: return the memdup_user() error for the user MQD

Jesse Zhang · Sep 30, 2026 · 1 files

7f7c88dbf4d5

drm/amdgpu/userq: only accept doorbell BOs as queue doorbell

Jesse Zhang · Sep 30, 2026 · 1 files

4d0e27041185

nouveau: check gsp->rm as well as gsp pointer before gcx ready

Dave Airlie · Sep 30, 2026 · 1 files

ae8364085574

i2c: qcom-geni: release runtime PM reference when set_rate fails

Rahul Pon · Sep 30, 2026 · 1 files

2e54a92e0136

drm/amd/display: disable self-refresh on tearing flips

Leo Li · Sep 30, 2026 · 1 files

cca01232d94a

drm/vc4: Fix binner slot allocation failing on an idle GPU

Maíra Canal · Sep 30, 2026 · 5 files

b41ff8b52927

drm/vc4: Free the BO cache size list on teardown

Maíra Canal · Sep 30, 2026 · 1 files

bca45af5998a

drm/vc4: Use kvmalloc_objs() for the BO cache size list

Maíra Canal · Sep 30, 2026 · 1 files

196d4d10c1b3

drm/imagination: Fix reference and vm_bo handling in remap()

Gyeyoung Baek · Oct 1, 2026 · 1 files

789f290b2e81

drm/imagination: Size page table preallocation by device address

Gyeyoung Baek · Oct 1, 2026 · 1 files

16c64495859f

drm/amdgpu: copy debugfs register data outside the GRBM/SRBM locks

Mikhail Gavrilov · Oct 1, 2026 · 1 files

e6895021a328

drm/amdkfd: fix dma_buf reference leak in get_dmabuf_info

Haojie Li · Oct 2, 2026 · 1 files

83d5acca1f4f

drm/xe: Fix shrinker accounting double-subtraction on nested external pins

Thomas Hellström · Oct 2, 2026 · 3 files

cf238c067eaa

drm/xe: Fix stale pinned_link entry when fb-pin performs the final unpin

Thomas Hellström · Oct 2, 2026 · 1 files

7484bc43ba6b

EDAC/amd64: Mask UMC chip select to the four implemented selects

Vishal Badole · Oct 2, 2026 · 1 files

611857adc9e7

drm/xe/i2c: cancel the client work on remove

Fan Wu · Oct 6, 2026 · 1 files

6ccf996a0dec

drm/nouveau: Skip the Turing CE workaround object for non-GR channels

Mary Guillemard · Oct 7, 2026 · 1 files