An asynchronous cursor update swaps the new framebuffer into the live
plane state. However, the driver reads both old_fb and new_fb from the
live state before this swap. When an enabled cursor changes buffers, the
address-update condition is therefore false and the hardware continues
scanning the previous buffer.

Read new_fb from the new plane state before swapping the framebuffer
references. This updates the hardware address when the framebuffer
changes while retaining the existing behavior for cursor movement.

Verified on a Loongson 3A5000 with LS7A2000 using 32x32 and 64x64 legacy
cursor updates. Callback counters and read-only register observations
confirmed the asynchronous path, the stale address before the change,
and the new address afterward. Same-framebuffer movement and cursor
disable/re-enable also passed, with the primary framebuffer and mode
unchanged.

AI assistance was used to investigate the existing report, prepare the
fix and test tools, run the build and hardware comparison, and draft
this message.

Reported-by: kernel test robot <[email protected]>
Closes: https://lore.kernel.org/r/[email protected]/
Fixes: f39db26c5428 ("drm: Add kms driver for loongson display controller")
Cc: [email protected]
Assisted-by: LLM
Signed-off-by: Evanshenf <[email protected]>
---
 drivers/gpu/drm/loongson/lsdc_plane.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/loongson/lsdc_plane.c 
b/drivers/gpu/drm/loongson/lsdc_plane.c
index bcc0ffa..7b9c65c 100644
--- a/drivers/gpu/drm/loongson/lsdc_plane.c
+++ b/drivers/gpu/drm/loongson/lsdc_plane.c
@@ -230,7 +230,7 @@ static void lsdc_cursor_plane_atomic_async_update(struct 
drm_plane *plane,
 
        new_state = drm_atomic_get_new_plane_state(state, plane);
 
-       new_fb = plane->state->fb;
+       new_fb = new_state->fb;
 
        plane->state->crtc_x = new_state->crtc_x;
        plane->state->crtc_y = new_state->crtc_y;

base-commit: bca45af5998a05f34b13a2ef11e639bac9c62643
-- 
2.43.0

Reply via email to