resource_find_free_secondary_pipe_legacy() returns NULL when no free
pipe is available, but the result is only passed to ASSERT() (a
WARN_ON_ONCE() that does not stop execution) and then dereferenced in
split_stream_across_pipes() and dcn_bw_calc_rq_dlg_ttu().

The sibling resource callers (dcn10/dcn20/dcn201) already NULL-check
this function's result. Do the same here and skip the split when no
free pipe is available.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: 74c49c7ac14f ("drm/amdgpu/display: Add calcs code for DCN")
Signed-off-by: Dmitriy Chumachenko <[email protected]>
---
 drivers/gpu/drm/amd/display/dc/dml/calcs/dcn_calcs.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/amd/display/dc/dml/calcs/dcn_calcs.c 
b/drivers/gpu/drm/amd/display/dc/dml/calcs/dcn_calcs.c
index 61553e24d53e..de54807ade43 100644
--- a/drivers/gpu/drm/amd/display/dc/dml/calcs/dcn_calcs.c
+++ b/drivers/gpu/drm/amd/display/dc/dml/calcs/dcn_calcs.c
@@ -1261,10 +1261,12 @@ bool dcn_validate_bandwidth(
                                                /* pipe not split previously 
needs split */
                                                hsplit_pipe = 
resource_find_free_secondary_pipe_legacy(&context->res_ctx, pool, pipe);
                                                ASSERT(hsplit_pipe);
-                                               
split_stream_across_pipes(&context->res_ctx, pool, pipe, hsplit_pipe);
+                                               if (hsplit_pipe)
+                                                       
split_stream_across_pipes(&context->res_ctx, pool, pipe, hsplit_pipe);
                                        }
 
-                                       dcn_bw_calc_rq_dlg_ttu(dc, v, 
hsplit_pipe, input_idx);
+                                       if (hsplit_pipe)
+                                               dcn_bw_calc_rq_dlg_ttu(dc, v, 
hsplit_pipe, input_idx);
                                } else if (hsplit_pipe && 
hsplit_pipe->plane_state == pipe->plane_state) {
                                        /* merge previously split pipe */
                                        pipe->bottom_pipe = 
hsplit_pipe->bottom_pipe;
-- 
2.49.0

Reply via email to