Commit 56c134f7f1b5 ("fbdev: Track deferred-I/O pages in pageref struct")
converted fb_deferred_io_init() from a void function to one returning an
error value.

However a number of callers don't seem to have been apprised of the fact
and continue to treat it like a void function.

This is problematic, as upon allocation failure, struct
fb_info->fbdefio_state is NULL.

That means when a subsequent operation is performed upon the driver, for
instance opening the file, a NULL pointer dereference occurs.

Update all of the remaining drivers which fail to check this to do so.

This issue was discovered as part of a separate series which updated logic
belonging to ssd1307fb.

Also fix up a separate issue with a BUG_ON() occurring on allocation
failure for udlfb and smcufx.

Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
---
Lorenzo Stoakes (ARM) (6):
      fbdev: ssd1307fb: check for fb_deferred_io_init() error
      fbdev: xen-fbfront: check for fb_deferred_io_init() error
      HID: picoLCD: check for fb_deferred_io_init() error
      fbdev: udlfb: check for fb_deferred_io_init() error
      fbdev: smscufx: check for fb_deferred_io_init() error
      fbdev: sh_mobile_lcdc: check for fb_deferred_io_init() error

 drivers/hid/hid-picolcd_fb.c           | 12 +++++++++---
 drivers/video/fbdev/sh_mobile_lcdcfb.c |  6 +++++-
 drivers/video/fbdev/smscufx.c          |  9 ++++++---
 drivers/video/fbdev/ssd1307fb.c        |  6 +++++-
 drivers/video/fbdev/udlfb.c            |  9 ++++++---
 drivers/video/fbdev/xen-fbfront.c      |  7 ++++++-
 6 files changed, 37 insertions(+), 12 deletions(-)
---
base-commit: 6812ce4e4379ffc99c52401ec28f0d7ffbc36206
change-id: 20260926-fix-fbdefio-error-handling-ab135b0193cb

Best regards,
-- 
Lorenzo Stoakes (ARM) <[email protected]>

Reply via email to