fb_deferred_io_init() allocates deferred I/O state, populating
info->fbdefio_state, or leaving it NULL if an error occurs.

Currently sh_mobile_lcdc_start() ignores its return value.

Therefore if an error arises in fb_deferred_io_init() (for instance, due
to an allocation failure) info->fbdefio_state is left NULL.

When the file is subsequently opened, fb_open() will dereference a NULL
pointer (calling fb_deferred_io_open()).

Fix this by checking for the error.

Also clear info->fbdefio in that case, so that sh_mobile_lcdc_stop() does
not attempt to clean up deferred I/O state that was never initialised.

Fixes: 56c134f7f1b5 ("fbdev: Track deferred-I/O pages in pageref struct")
Cc: <[email protected]>
Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
---
 drivers/video/fbdev/sh_mobile_lcdcfb.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/drivers/video/fbdev/sh_mobile_lcdcfb.c 
b/drivers/video/fbdev/sh_mobile_lcdcfb.c
index e8324b01700f..1409a5cc736b 100644
--- a/drivers/video/fbdev/sh_mobile_lcdcfb.c
+++ b/drivers/video/fbdev/sh_mobile_lcdcfb.c
@@ -1042,7 +1042,11 @@ static int sh_mobile_lcdc_start(struct 
sh_mobile_lcdc_priv *priv)
                        ch->defio.deferred_io = sh_mobile_lcdc_deferred_io;
                        ch->defio.delay = msecs_to_jiffies(tmp);
                        ch->info->fbdefio = &ch->defio;
-                       fb_deferred_io_init(ch->info);
+                       ret = fb_deferred_io_init(ch->info);
+                       if (ret) {
+                               ch->info->fbdefio = NULL;
+                               return ret;
+                       }
                }
 
                sh_mobile_lcdc_display_on(ch);

-- 
2.55.0

Reply via email to