On Mon, Sep 21, 2026 at 04:49:52PM +0530, Mahadevan P wrote: > drm_atomic_helper_shutdown() disables all CRTCs but leaves output > polling and IRQ-driven hot-plug detection running. On reboot, a late > DP hot-plug-detect (HPD) IRQ can fire after apps_smmu has already > disabled translation for the display subsystem, causing the HPD > thread to kick off a new modeset that drives DPU/DP hardware and DMA > through a stale IOMMU mapping. > > drm_atomic_helper_shutdown() disables all CRTCs first, but a pending > HPD IRQ thread wakes up afterwards, reads the DPCD, and fires an > unsolicited hotplug event that triggers a second atomic commit > turning the display back on -- right as the IOMMU is disabling > translation: > > systemd-shutdown[1]: Rebooting. > msm_dpu: drm_atomic_commit: committing (shutdown disabling CRTCs) > arm-smmu 3da0000.iommu: disabling translation > msm_dpu: drm_dp_read_dpcd_caps (late HPD IRQ thread wakes up) > msm_dpu: drm_sysfs_connector_hotplug_event: DP-1 hotplug event > msm_dpu: drm_client_modeset_probe: DP-1 found preferred mode > msm_dpu: drm_atomic_commit: committing (unsolicited, re-enables display) > dpu_crtc_commit_kickoff: crtc94 first commit > arm-smmu 15200000.iommu: disabling translation > > Call drm_kms_helper_poll_disable() to tear this down: it stops the > output poll worker and calls each connector's > &drm_connector_helper_funcs.disable_hpd, which for HPD-capable bridges > masks the interrupt in hardware and then waits for an in-flight HPD > handler under bridge->hpd_mutex. Suspend the in-kernel clients as > well, so that a hotplug event which still gets through is recorded in > client->hotplug_pending instead of being probed and committed. > > Reported on Qualcomm platforms such as lemans-evk and monaco-evk > during reboot stress testing. > > Assisted-by: LLM > Signed-off-by: Mahadevan P <[email protected]>
Acked-by: Dmitry Baryshkov <[email protected]> Though I'd really wait for somebody with deeper understanding of this part to review it. -- With best wishes Dmitry
