Commit 56c134f7f1b5 ("fbdev: Track deferred-I/O pages in pageref struct")
converted fb_deferred_io_init() from a void function to one returning an
error value.However a number of callers don't seem to have been apprised of the fact and continue to treat it like a void function. This is problematic, as upon allocation failure, struct fb_info->fbdefio_state is NULL. That means when a subsequent operation is performed upon the driver, for instance opening the file, a NULL pointer dereference occurs. Update all of the remaining drivers which fail to check this to do so. This issue was discovered as part of a separate series which updated logic belonging to ssd1307fb. Also fix up a separate issue with a BUG_ON() occurring on allocation failure for udlfb and smcufx. Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]> --- Lorenzo Stoakes (ARM) (6): fbdev: ssd1307fb: check for fb_deferred_io_init() error fbdev: xen-fbfront: check for fb_deferred_io_init() error HID: picoLCD: check for fb_deferred_io_init() error fbdev: udlfb: check for fb_deferred_io_init() error fbdev: smscufx: check for fb_deferred_io_init() error fbdev: sh_mobile_lcdc: check for fb_deferred_io_init() error drivers/hid/hid-picolcd_fb.c | 12 +++++++++--- drivers/video/fbdev/sh_mobile_lcdcfb.c | 6 +++++- drivers/video/fbdev/smscufx.c | 9 ++++++--- drivers/video/fbdev/ssd1307fb.c | 6 +++++- drivers/video/fbdev/udlfb.c | 9 ++++++--- drivers/video/fbdev/xen-fbfront.c | 7 ++++++- 6 files changed, 37 insertions(+), 12 deletions(-) --- base-commit: 6812ce4e4379ffc99c52401ec28f0d7ffbc36206 change-id: 20260926-fix-fbdefio-error-handling-ab135b0193cb Best regards, -- Lorenzo Stoakes (ARM) <[email protected]>
