Daily update · Oct 10–11, 2026
Graphics driver fixes: VC4 teardown races, AMD doorbell alignment, Xe and more
A large DRM-focused batch addresses crashes, hangs, memory leaks and display timing issues across a dozen GPU drivers, plus a couple of I2C and EDAC fixes.
In brief
This batch is almost entirely DRM (Direct Rendering Manager) fixes, touching VC4, AMDGPU/AMDKFD, Xe/i915, Nouveau, Panthor, VMware, Imagination, and display helpers. Raspberry Pi's VC4 gets teardown and runtime suspend fixes, AMD gets doorbell alignment and reset-safety improvements, and several drivers get memory-leak or out-of-bounds fixes. Two non-graphics patches address an i2c runtime-PM leak and an EDAC mask change.
Raspberry Pi VC4
Drain hangcheck timer and work on V3D unbind
vc4_v3d_unbind() now drains the hangcheck timer, cancels reset work, and flushes job_done_work before uninstalling the V3D interrupt. Previously a still-armed timer could read V3D registers through a NULL vc4->v3d pointer, and late callbacks could run after the containing vc4_dev was freed.
Why it matters: Prevents use-after-free and NULL-pointer access when unbinding VC4.
Disable the V3D interrupt across runtime suspend
vc4_irq_disable() masks V3D interrupt sources and synchronizes the IRQ, but on Raspberry Pi 0-3 the ARMCTRL controller has no active state, so a CPU may still run the handler after the GPU is powered down. The driver now disables the interrupt across runtime suspend.
Why it matters: Fixes a race where the V3D handler could run after power-down.
Fix binner slot allocation failing on an idle GPU
Binner slots are returned by job_done work, but the seqno wait could wake before that work ran, leaving the pool full and causing -ENOMEM. The fix makes allocation wait for the actual slot release.
Why it matters: Fixes spurious submit failures under bursts of small GPU jobs.
Free the BO cache size list on teardown
vc4_bo_cache_destroy() freed cached BOs but not the size-list nodes, leaking memory on every unbind.
Why it matters: Fixes a memory leak during VC4 teardown.
Use kvmalloc_objs() for the BO cache size list
The BO cache size list grows with the largest BO freed, and using kmalloc could require a high-order allocation that fails under fragmentation. kvmalloc_objs() allows fallback to vmalloc.
Why it matters: Avoids allocation failures and warn_alloc() splats when large BOs are closed.
Fix firmware reference leak in vc4_drm_bind()
If aperture_remove_all_conflicting_devices() fails, the previously acquired Raspberry Pi firmware reference was leaked; error handling now puts it before returning.
Why it matters: Fixes a firmware reference leak on VC4 bind failure.
AMDGPU and AMDKFD
Fix direct scanout alpha for some DRM_FORMATs
amdgpu_dm had its own hardcoded list of alpha-capable DRM formats, and it missed some, so direct scanout planes could be rendered opaque. It now checks the format's has_alpha field from DRM core.
Why it matters: Fixes missing alpha blending on affected display formats.
Only accept doorbell BOs as user queue doorbells
The user queue doorbell index helper pinned any BO passed in as a doorbell handle into the doorbell domain. A regular BO would be moved and its contents lost, and an importer could do this to a buffer shared from another client. The patch accepts only BOs created in the doorbell domain.
Why it matters: Prevents data loss and cross-client buffer corruption via the userq IOCTL.
Return memdup_user() error for user MQD
The usermode queue MQD creation always translated memdup_user() failures into -ENOMEM, hiding the real error (-EFAULT or -EINTR). It now returns PTR_ERR() and drops the error messages.
Why it matters: Userspace gets accurate error codes and the kernel log is not spammed by invalid IOCTLs.
Disable self-refresh on tearing flips
Immediate (tearing) flips conflict with PSR/Replay assumptions, so amdgpu_dm now disables panel self-refresh for those flips.
Why it matters: Prevents PSR/Replay state-machine failures when tearing flips are used.
Serialize vblank counter reads against GPU reset
The vblank counter callback read display hardware without holding the reset semaphore, which could race with GPU reset and trigger lockdep assertions. It now takes the semaphore for reading and uses the software vblank count if reset is in progress.
Why it matters: Avoids lockdep warnings and display hardware access while reset is running.
Copy debugfs register data outside GRBM/SRBM locks
The regs2 debugfs file performed copy_from/to_user() while holding GRBM/SRBM bank selection locks, creating a circular locking dependency with mmap_lock. The copy now happens outside the locks.
Why it matters: Fixes lockdep-detected circular locking when using umr or debugfs register access.
Align SDMA doorbell base for shader doorbell writes
On GC 9.4.3, 9.4.4 and 9.5.0, shader doorbell writes are routed at 4-index granularity, so odd SDMA engines with unaligned bases could ring the previous engine's doorbell and stall queues. Per-engine bases are now aligned to a 4-index boundary.
Why it matters: Prevents hangs for shader doorbell writes to SDMA queues on those ASICs.
Don't replace a sink mode that shares native totals
The mode-timing logic copied native timing into any requested mode with the same clock, htotal, and vtotal, which also affected real sink modes such as 4096x2160@60 when 3840x2160@60 was preferred. The replacement is now limited to modes amdgpu inserted itself.
Why it matters: Fixes wrong scaling and timing/InfoFrame data for display modes that share native totals.
Fix dma_buf reference leak in get_dmabuf_info
If metadata buffer allocation failed in amdgpu_amdkfd_get_dmabuf_info(), the dma_buf reference taken earlier was leaked. All error paths now go through a cleanup label that calls dma_buf_put().
Why it matters: Fixes a dma_buf reference leak on allocation failure in KFD dmabuf info get.
Make Mac FB workaround generic
The Apple framebuffer workaround was previously enabled per chip. It now triggers whenever the framebuffer is at address 0 and the subsystem vendor ID is Apple, covering all affected chips.
Why it matters: Applies the existing workaround to current/future AMD GPUs on Apple hardware.
Intel Xe and i915
Honor delay/sleep maximums in xe_mmio_wait32()
xe_mmio_wait32() used udelay() without checking for overflow, and the backoff could grow extremely large. The patch caps the in-loop wait and detects overflow.
Why it matters: Prevents extremely long or wrapped waits in xe_mmio_wait32().
Do not emit Wa_16010904313 twice
Due to a rebase error, Wa_16010904313 was emitted both in the indirect context and in the workaround batch buffer where it should only appear once. The emission location is now passed as a parameter.
Why it matters: Fixes duplicate workaround emission on Xe engines.
Fix shrinker accounting double-subtraction on nested external pins
xe_bo_pin_external() and unpin_external() support nested pins but changed shrinker accounting on every call. A dma-buf pinned multiple times was subtracted from the shrinker's accounting each time, even though its pages were still pinned. Accounting is now done only on the outermost pin and final unpin.
Why it matters: Fixes incorrect shrinker accounting for multi-pinned external BOs.
Fix stale pinned_link entry when fb-pin performs the final unpin
External pin tracking in xe maintains a pinned_link list. Display framebuffer pins change pin_count without going through the external helpers, so the list could keep a stale entry after the final unpin happened from the fb path.
Why it matters: Fixes stale linked-list state for BOs pinned both externally and as framebuffers.
Fix mailbox header handling
The sysctrl mailbox header was declared __le32 and converted with cpu_to_le32/le32_to_cpu, but the header is always handled as a CPU-order 32-bit value through xe_mmio_read32/write32. On big-endian systems the conversions could be wrong.
Why it matters: Fixes mailbox header handling on big-endian; no change on little-endian.
Cancel client work on i2c remove
xe_i2c_remove() unregistered the adapter but did not cancel i2c->work. A queued work item could instantiate an AMC client after the adapter was released, using freed memory.
Why it matters: Fixes a use-after-free race during Xe i2c removal.
Prevent overstepping exec array boundary
In i915 execbuffer slow relocation parsing, the command parser appends VMAs to the exec array, but cleanup used the incremented buffer_count and could kvfree() pointers beyond the original exec array. Cleanup now uses the original exec object count.
Why it matters: Fixes a possible out-of-bounds free in the execbuffer path.
Unmask interrupts only when ACTIVE is true
A race between intel_rps_boost() reading ACTIVE state and queued work could unmask RPS PM interrupts after GT park, without holding a PM wakelock. The unmask now only happens when ACTIVE is true.
Why it matters: Fixes a PM wakelock ordering problem seen in selftests.
Other DRM drivers
Fix error check on dw_hdmi_probe() return value
After dw_hdmi_probe(), the TH1520 bridge driver checked the hdmi pointer for IS_ERR() instead of the returned dw_hdmi. The patch checks the correct variable.
Why it matters: Correctly detects probe failure in the TH1520 HDMI bridge driver.
Fix remove() callback in th1520-dw-hdmi
The TH1520 remove callback read platform drvdata as a struct dw_hdmi * although it stores struct th1520_hdmi *, and then passed the wrong pointer to dw_hdmi_remove(). It now retrieves th1520_hdmi and passes hdmi->dw_hdmi.
Why it matters: Fixes teardown running on the wrong object in the TH1520 bridge driver.
Validate pitch from userspace in vmwgfx
vmwgfx cursor snooping now validates the pitch supplied by userspace along with the box dimensions before copying data from the underlying surface.
Why it matters: Fixes possible out-of-bounds reads with cursor snooping.
Add blend mode property to vmwgfx
vmwgfx adds support for the blend mode property so the core DRM code stops complaining about an unsupported property.
Why it matters: Stops log spam from the core DRM blend-mode check.
Fix unlocked list_del in drm_bridge_add()
drm_bridge_add() removed a bridge from the bridge_lingering_list without holding bridge_lock, even though other list operations and the debugfs walker use the lock. The empty/list_del sequence now runs under bridge_lock.
Why it matters: Fixes a potential list corruption when re-adding a bridge.
Fix unlocked list access in drm_bridge_attach()
drm_bridge_attach() inspected bridge->list without bridge_lock, which is a data race with concurrent list mutations. The check is now done under the lock.
Why it matters: Eliminates a data race in bridge attachment warnings.
Validate userspace queue count against initialized firmware slot count
Panthor validated the userspace queue count only against MAX_CS_PER_CSG, not the number of stream interfaces initialized from firmware data. If firmware reported fewer slots, unprivileged userspace could force access to an uninitialized stream interface.
Why it matters: Prevents a crash when requesting more queues than the firmware initialized.
Don't mark AUX backlight enabled when enabling failed
If drm_edp_backlight_enable() failed, dp_aux_backlight_update_status() still marked the backlight as enabled, so later brightness changes skipped the enable step. It now returns the error, allowing the next update to retry enabling.
Why it matters: Fixes a panel that stays dark after AUX backlight enable fails.
Check gsp->rm as well as gsp pointer before gcx ready
On Turing systems where GSP exists but is not used, the GCX-ready check now verifies gsp->rm as well as the gsp pointer.
Why it matters: Prevents a crash on GSP-but-unused Turing configurations.
Skip Turing CE workaround object for non-GR channels
The Turing CE workaround object was meant for the old Gallium driver, but it was being assigned to all channels. It now only applies to GR channels.
Why it matters: Fixes async copy engine (CE) operation on Turing.
Defer setup when fbdev_probe() fails, not just on -EAGAIN
fb_helper only deferred setup when the single-fb probe returned -EAGAIN. Any other fbdev_probe() failure left mode_sets with fb == NULL and no retry. All failures now set deferred_setup.
Why it matters: Lets fbdev emulation retry after transient probe failures.
Balance display clock enable on teardown
aspeed_gfx_load() enabled the display clock without disabling it on probe failure or removal. Using devm_clk_get_enabled() fixes error handling and automatic disable/unprepare.
Why it matters: Fixes unbalanced display clock enable on Aspeed GFX teardown.
Don't keep connector without a CRTC as connector_state
In gud_pipe_update(), if no connector in the new state had a CRTC, connector_state was left pointing at the last visited connector instead of NULL, skipping the fallback that finds the active connector.
Why it matters: Fixes active connector selection in the GUD USB display driver.
Fix reference and vm_bo handling in remap()
pvr_vm_gpuva_remap() took a GEM reference for each split part that was never dropped, and linked split parts to the new vm_bo instead of the original object's vm_bo. Both are fixed.
Why it matters: Fixes a memory leak and wrong vm_bo linkage during PVR mappings.
Size page table preallocation by device address
PVR page-table preallocation used device_addr plus sgt_offset with an exclusive end, which could allocate an extra table or underflow when mappings cross boundaries. Preallocation is now counted from device_addr with an inclusive end.
Why it matters: Fixes page-table preallocation sizing for device mappings.
Non-graphics fixes
Release runtime PM reference when set_rate fails
geni_i2c_xfer() took a runtime-PM reference and leaked it if the set_rate() callback failed, leaving the controller resumed indefinitely. The error now goes through the common cleanup path.
Why it matters: Fixes a runtime PM leak on Qualcomm Geni I2C set_rate failure.
Mask UMC chip select to the four implemented selects
The EDAC amd64 driver changed the UMC chip-select mask from 0x7 to 0x3. All Zen systems have at most four chip selects, and future systems redefine the field the same way.
Why it matters: Keeps EDAC UMC decoding correct on current and future AMD platforms.
Source commits41 entries +
drm/bridge: th1520-dw-hdmi: Fix error check on dw_hdmi_probe() return value
Felix Gu · Mar 20, 2026 · 1 files
drm/bridge: th1520-dw-hdmi: Fix remove() callback
Felix Gu · Mar 20, 2026 · 1 files
drm/panthor: validate userspace queue count against initialized firmware slot count
Osama Abdelkader · Aug 4, 2026 · 1 files
drm/vmwgfx: validate pitch coming from userspace
Zack Rusin · Aug 9, 2026 · 1 files
drm/bridge: Fix unlocked list_del in drm_bridge_add()
Cristian Ciocaltea · Sep 1, 2026 · 1 files
drm/bridge: Fix unlocked list access in drm_bridge_attach()
Cristian Ciocaltea · Sep 1, 2026 · 1 files
drm/i915/gt: Unmask interrupts only when ACTIVE is true
Krzysztof Karas · Sep 10, 2026 · 1 files
drm/i915/gem: Prevent overstepping exec array boundary
Krzysztof Karas · Sep 11, 2026 · 1 files
drm/aspeed: Balance the display clock enable on teardown
Myeonghun Pak · Sep 13, 2026 · 1 files
drm/vc4: drain the hangcheck timer and works on V3D unbind
Fan Wu · Sep 15, 2026 · 1 files
drm/vc4: Fix firmware reference leak in vc4_drm_bind()
Wentao Liang · Sep 16, 2026 · 1 files
drm/vmwgfx: Add blend mode property
Ian Forbes · Sep 16, 2026 · 1 files
drm/gud: don't keep a connector without a CRTC as connector_state
Sajal Gupta · Sep 22, 2026 · 1 files
drm/xe/sysctrl: Fix mailbox header handling
Mallesh Koujalagi · Sep 24, 2026 · 1 files
drm/amdkfd: align SDMA doorbell base for shader doorbell writes
Saleel Kudchadker · Sep 24, 2026 · 2 files
drm/amd/display: Don't replace a sink mode that shares the native totals
Adrian Betschart · Sep 25, 2026 · 2 files
drm/xe: Do not emit Wa_16010904313 twice
Tvrtko Ursulin · Sep 25, 2026 · 1 files
drm/amdgpu: make Mac FB workaround generic
Alex Deucher · Sep 25, 2026 · 1 files
drm/dp: don't mark the AUX backlight enabled when enabling failed
Oleg Keri · Sep 25, 2026 · 1 files
drm/vc4: Disable the V3D interrupt across runtime suspend
Maíra Canal · Sep 25, 2026 · 2 files
drm/fb-helper: defer setup when fbdev_probe() fails, not just on -EAGAIN
Nguyen Ngoc Thang · Sep 27, 2026 · 1 files
drm/xe/mmio: Fix xe_mmio_wait32() to honor delay/sleep maximums
Alan Previn · Sep 29, 2026 · 1 files
drm/amd/display: Fix direct scanout alpha on some DRM_FORMATs
Leo Li · Sep 29, 2026 · 1 files
drm/amdgpu: serialize vblank counter reads against GPU reset
Vitaly Prosyak · Sep 30, 2026 · 1 files
drm/amdgpu/userq: return the memdup_user() error for the user MQD
Jesse Zhang · Sep 30, 2026 · 1 files
drm/amdgpu/userq: only accept doorbell BOs as queue doorbell
Jesse Zhang · Sep 30, 2026 · 1 files
nouveau: check gsp->rm as well as gsp pointer before gcx ready
Dave Airlie · Sep 30, 2026 · 1 files
i2c: qcom-geni: release runtime PM reference when set_rate fails
Rahul Pon · Sep 30, 2026 · 1 files
drm/amd/display: disable self-refresh on tearing flips
Leo Li · Sep 30, 2026 · 1 files
drm/vc4: Fix binner slot allocation failing on an idle GPU
Maíra Canal · Sep 30, 2026 · 5 files
drm/vc4: Free the BO cache size list on teardown
Maíra Canal · Sep 30, 2026 · 1 files
drm/vc4: Use kvmalloc_objs() for the BO cache size list
Maíra Canal · Sep 30, 2026 · 1 files
drm/imagination: Fix reference and vm_bo handling in remap()
Gyeyoung Baek · Oct 1, 2026 · 1 files
drm/imagination: Size page table preallocation by device address
Gyeyoung Baek · Oct 1, 2026 · 1 files
drm/amdgpu: copy debugfs register data outside the GRBM/SRBM locks
Mikhail Gavrilov · Oct 1, 2026 · 1 files
drm/amdkfd: fix dma_buf reference leak in get_dmabuf_info
Haojie Li · Oct 2, 2026 · 1 files
drm/xe: Fix shrinker accounting double-subtraction on nested external pins
Thomas Hellström · Oct 2, 2026 · 3 files
drm/xe: Fix stale pinned_link entry when fb-pin performs the final unpin
Thomas Hellström · Oct 2, 2026 · 1 files
EDAC/amd64: Mask UMC chip select to the four implemented selects
Vishal Badole · Oct 2, 2026 · 1 files
drm/xe/i2c: cancel the client work on remove
Fan Wu · Oct 6, 2026 · 1 files
drm/nouveau: Skip the Turing CE workaround object for non-GR channels
Mary Guillemard · Oct 7, 2026 · 1 files