#779603 xserver-xorg-video-intel: Xorg crashes when unplugging external display on kernel 3.19

#779603#5
Date:
2015-03-02 23:01:30 UTC
From:
To:
Dear Maintainer,

Unplugging an external monitor (VGA, HDMI) causes Xorg to crash with
SEGFAULT when running Linux kernel version 3.19 from experimental on
Debian Jessie. Hotplug is also broken (external display only works if
it's already plugged in when Xorg starts). Both problems are fixes
upstream with the Intel driver version 2.99.17, which is also available
in experimental.

I am attaching a patch that backports the fix for the crash. I
understand that the problem only affects those running a bleeding-edge
kernel from experimental, and that the driver from the same release
fixes the problem, so it might not be worth merging this. Nevertheless,
I would think that it's a good idea to document the problem.

What follows is the backtrace, the patch fixes the problem which occurs
in frame 9, and then the system info. The patch will come in the
following email.

Kind regards,
Luca Boccassi


(gdb) bt full
#0  0x00007fbea7b07107 in __GI_raise (sig=sig@entry=6)
at ../nptl/sysdeps/unix/sysv/linux/raise.c:56
        resultvar = 0
        pid = 5862
        selftid = 5862
#1  0x00007fbea7b084e8 in __GI_abort () at abort.c:89
        save_stage = 2
        act = {__sigaction_handler = {sa_handler = 0x7fbeab9b16b0,
sa_sigaction = 0x7fbeab9b16b0}, sa_mask = {__val = {3, 140736622040560,
140456868216327, 1, 0, 0, 140456833682728, 1, 140736622040560,
              140456899564112, 140456868242213, 0, 140456833872816,
140456874926528, 140736622040320, 0}}, sa_flags = -1416131168,
sa_restorer = 0x7fbea9da1980}
        sigs = {__val = {32, 0 <repeats 15 times>}}
#2  0x00007fbea9f9a62e in OsAbort () at ../../os/utils.c:1361
No locals.
#3  0x00007fbea9e754dc in ddxGiveUp (error=error@entry=EXIT_ERR_ABORT)
at ../../../../hw/xfree86/common/xf86Init.c:1088
        i = <optimized out>
#4  0x00007fbea9e75596 in AbortDDX (error=error@entry=EXIT_ERR_ABORT)
at ../../../../hw/xfree86/common/xf86Init.c:1132
        i = <optimized out>
#5  0x00007fbea9f9fef2 in AbortServer () at ../../os/log.c:783
No locals.
#6  0x00007fbea9fa0d5d in FatalError (f=f@entry=0x7fbea9fcbb28 "Caught
signal %d (%s). Server aborting\n") at ../../os/log.c:924
        args = {{gp_offset = 24, fp_offset = 48, overflow_arg_area =
0x7fffcc5d16e0, reg_save_area = 0x7fffcc5d1610}}
        args2 = {{gp_offset = 8, fp_offset = 48, overflow_arg_area =
0x7fffcc5d16e0, reg_save_area = 0x7fffcc5d1610}}
        beenhere = 1
#7  0x00007fbea9f97f7c in OsSigHandler (signo=11, sip=<optimized out>,
unused=<optimized out>) at ../../os/osinit.c:147
        unused = <optimized out>
        sip = <optimized out>
        signo = 11
#8  <signal handler called>
No locals.
#9  intel_output_dpms (output=0x7fbeab9b12b0, dpms=3)
at ../../../src/uxa/intel_display.c:1107
        intel_output = 0x7fbeab9b16b0
        koutput = 0x0
        mode = 0x7fbeab9ad250
        i = 0
#10 0x00007fbea9eac26c in xf86DisableUnusedFunctions
(pScrn=0x7fbeab99e410) at ../../../../hw/xfree86/modes/xf86Crtc.c:2985
        output = <optimized out>
        xf86_config = 0x7fbeab9ad2d0
        o = 4
        c = <optimized out>
#11 0x00007fbea9eb5d79 in xf86RandR12CrtcSet (pScreen=0x7fbeab99de40,
randr_crtc=0x7fbeabcc2920, randr_mode=0x0, x=0, y=0, rotation=<optimized
out>, num_randr_outputs=0, randr_outputs=0x0)
    at ../../../../hw/xfree86/modes/xf86RandR12.c:1237
        pScrn = 0x7fbeab99e410
        config = 0x7fbeab9ad2d0
        crtc = 0x7fbeab9ae170
        transform = 0x0
        changed = <optimized out>
        o = <optimized out>
        ro = <optimized out>
        save_crtcs = 0x7fbeabd987e0
        save_enabled = 1
#12 0x00007fbea9ef6ecd in RRCrtcSet (crtc=0x7fbeabcc2920, mode=0x3,
x=-1478011320, y=0, rotation=5888, numOutputs=-1415899312, outputs=0x0)
at ../../randr/rrcrtc.c:574
        ret = 0
        crtcChanged = 0
#13 0x00007fbea9ef8354 in ProcRRSetCrtcConfig (client=0x7fbeab9b3bf0)
at ../../randr/rrcrtc.c:1173
        stuff = 0x7fbeac7657c4
---Type <return> to continue, or q <return> to quit---
        rep = {type = 96 '`', status = 32 ' ', sequenceNumber = 52317,
length = 32767, newTimestamp = 3428655136, pad1 = 32767, pad2 =
2879077360, pad3 = 32702, pad4 = 131072, pad5 = 0}
        pScreen = 0x7fffcc5d1fd0
        pScrPriv = 0x7fbeabcc1f00
        crtc = 0x7fbeabcc2920
        mode = 0x0
        numOutputs = 0
        rotation = 1
        ret = -1541250496
        status = 0 '\000'
#14 0x00007fbea9e343f7 in Dispatch () at ../../dix/dispatch.c:432
        clientReady = 0x7fbeac69a260
        result = <optimized out>
        client = 0x7fbeab9b3bf0
        nready = 0
        icheck = 0x7fbeaa22fd70 <checkForInput>
        start_tick = 145
#15 0x00007fbea9e38596 in dix_main (argc=18, argv=0x7fffcc5d22b8,
envp=<optimized out>) at ../../dix/main.c:296
        i = <optimized out>
        alwaysCheckForInput = {0, 1}
#16 0x00007fbea7af3b45 in __libc_start_main (main=0x7fbea9e228e0 <main>,
argc=18, argv=0x7fffcc5d22b8, init=<optimized out>, fini=<optimized
out>, rtld_fini=<optimized out>, stack_end=0x7fffcc5d22a8)
    at libc-start.c:287
        result = <optimized out>
        unwind_buf = {cancel_jmp_buf = {{jmp_buf = {0,
719415314683997775, 140456870684901, 140736622043824, 0, 0,
-719317203467948465, -682665652669043121}, mask_was_saved = 0}}, priv =
{pad = {0x0, 0x0,
              0x7fbea9fa4b10 <__libc_csu_init>, 0x7fffcc5d22b8}, data =
{prev = 0x0, cleanup = 0x0, canceltype = -1443214576}}}
        not_first_call = <optimized out>
#17 0x00007fbea9e2290e in _start ()
No symbol table info available.
(gdb) frame 9
#9  intel_output_dpms (output=0x7fbeab9b12b0, dpms=3)
at ../../../src/uxa/intel_display.c:1107
1107	in ../../../src/uxa/intel_display.c
(gdb) print koutput
$2 = (drmModeConnectorPtr) 0x0

#779603#10
Date:
2015-03-02 23:04:25 UTC
From:
To:
Cherry picked from commit:

commit 908520a7dacade8b6716e7c30549847464a33a81
Author: Dave Airlie <airlied@redhat.com>
Date:   Wed Sep 3 10:43:21 2014 +1000

    uxa: add MST support.

Signed-off-by: Luca Boccassi <luca.boccassi@gmail.com>
---
 src/uxa/intel_display.c | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/src/uxa/intel_display.c b/src/uxa/intel_display.c
index b4f7e87..d584741 100644
--- a/src/uxa/intel_display.c
+++ b/src/uxa/intel_display.c
@@ -468,6 +468,9 @@ intel_crtc_apply(xf86CrtcPtr crtc)
                        continue;

                intel_output = output->driver_private;
+               if (!intel_output->mode_output)
+                       return FALSE;
+
                output_ids[output_count] =
                        intel_output->mode_output->connector_id;
                output_count++;
@@ -924,6 +927,11 @@ intel_output_attach_edid(xf86OutputPtr output)
        xf86MonPtr mon = NULL;
        int i;

+       if (!koutput) {
+               xf86OutputSetEDID(output, mon);
+               return;
+       }
+
        /* look for an EDID property */
        for (i = 0; i < koutput->count_props; i++) {
                drmModePropertyPtr props;
@@ -1013,6 +1021,9 @@ intel_output_get_modes(xf86OutputPtr output)

        intel_output_attach_edid(output);

+       if (!koutput)
+               return;
+
        /* modes should already be available */
        for (i = 0; i < koutput->count_modes; i++) {
                DisplayModePtr Mode;
@@ -1104,6 +1115,9 @@ intel_output_dpms(xf86OutputPtr output, int dpms)
        struct intel_mode *mode = intel_output->mode;
        int i;

+       if (!koutput)
+               return;
+
        for (i = 0; i < koutput->count_props; i++) {
                drmModePropertyPtr props;