Thread (8 messages) 8 messages, 4 authors, 2013-01-04
STALE5015d REVIEWED: 1 (0M)

1 review trailer.

Re: [BUGFIX PATCH] video: mxsfb: fix crash when unblanking the display

From: Juergen Beisert <hidden>
Date: 2012-11-29 13:50:00
Also in: linux-arm-kernel

Hi Lothar,

Lothar Waßmann wrote:
quoted
The VDCTRL4 register does not provide the MXS SET/CLR/TOGGLE feature.
The write in mxsfb_disable_controller() sets the data_cnt for the LCD
DMA to 0 which obviously means the max. count for the LCD DMA and
leads to overwriting arbitrary memory when the display is unblanked.
Overwriting? It should be a reading DMA unit, shouldn't it?
quoted
Note: I already sent this patch in December 2011 but noone picked it up
obviously.

Signed-off-by: Lothar Waßmann <redacted>
---
 drivers/video/mxsfb.c |    3 ++-
 1 files changed, 2 insertions(+), 1 deletions(-)
diff --git a/drivers/video/mxsfb.c b/drivers/video/mxsfb.c
index 49619b4..f2a49ef 100644
--- a/drivers/video/mxsfb.c
+++ b/drivers/video/mxsfb.c
@@ -369,7 +369,8 @@ static void mxsfb_disable_controller(struct fb_info
*fb_info) loop--;
 	}

-	writel(VDCTRL4_SYNC_SIGNALS_ON, host->base + LCDC_VDCTRL4 + REG_CLR);
+	reg = readl(host->base + LCDC_VDCTRL4);
+	writel(reg & ~VDCTRL4_SYNC_SIGNALS_ON, host->base + LCDC_VDCTRL4);

 	clk_disable_unprepare(host->clk);

--
1.7.2.5
ping? 
I'm not sure if the missing SET/CLR feature for this register is a typo in the 
i.MX23/i.MX28 data sheets or if it is intended. Lets assume its the truth 
what they have written:

Acked-by: Juergen Beisert <redacted>

Regards,
Juergen

-- 
Pengutronix e.K.                              | Juergen Beisert             |
Linux Solutions for Science and Industry      | http://www.pengutronix.de/  |
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help