fb_deferred_io_init() allocates deferred I/O state, populating
info->fbdefio_state, or leaving it NULL if an error occurs.

Currently picolcd_init_framebuffer() ignores its return value.

Therefore if an error arises in fb_deferred_io_init() (for instance, due
to an allocation failure) info->fbdefio_state is left NULL.

When the file is subsequently opened, fb_open() will dereference a NULL
pointer (calling fb_deferred_io_open()).

Fix this by checking for the error.

Also correct cleanup ordering - defio is initialised after the sysfs file,
so cleanup defio first.

Fixes: 56c134f7f1b5 ("fbdev: Track deferred-I/O pages in pageref struct")
Cc: <[email protected]>
Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
---
 drivers/hid/hid-picolcd_fb.c | 12 +++++++++---
 1 file changed, 9 insertions(+), 3 deletions(-)

diff --git a/drivers/hid/hid-picolcd_fb.c b/drivers/hid/hid-picolcd_fb.c
index 8c28e982e09d..a016dd9ca847 100644
--- a/drivers/hid/hid-picolcd_fb.c
+++ b/drivers/hid/hid-picolcd_fb.c
@@ -531,17 +531,23 @@ int picolcd_init_framebuffer(struct picolcd_data *data)
                goto err_cleanup;
        }
 
-       fb_deferred_io_init(info);
+       error = fb_deferred_io_init(info);
+       if (error) {
+               dev_err(dev, "failed to initialize deferred I/O\n");
+               goto err_sysfs;
+       }
+
        error = register_framebuffer(info);
        if (error) {
                dev_err(dev, "failed to register framebuffer\n");
-               goto err_sysfs;
+               goto err_defio;
        }
        return 0;
 
+err_defio:
+       fb_deferred_io_cleanup(info);
 err_sysfs:
        device_remove_file(dev, &dev_attr_fb_update_rate);
-       fb_deferred_io_cleanup(info);
 err_cleanup:
        data->fb_info    = NULL;
 

-- 
2.55.0

Reply via email to