fb_deferred_io_init() allocates deferred I/O state, populating
info->fbdefio_state, or leaving it NULL if an error occurs.

Currently dlfb_ops_open() ignores its return value.

Therefore if an error arises in fb_deferred_io_init() (for instance, due to
an allocation failure) info->fbdefio_state is left NULL.

fb_open() will then dereference a NULL pointer (calling
fb_deferred_io_open()) as soon as dlfb_ops_open() returns.

Additionally, if the allocation of info->fbdefio itself fails,
dlfb_ops_open() sets info->fbdefio to NULL and invokes
fb_deferred_io_init() regardless, hitting BUG_ON(!fbdefio).

Fix this by only invoking fb_deferred_io_init() if the allocation
succeeded, and checking for the error.

The driver already supports operating without deferred I/O, so in either
case fall back to that by setting info->fbdefio to NULL.

The ignored return value was introduced in commit 56c134f7f1b5 ("fbdev:
Track deferred-I/O pages in pageref struct").

However, the BUG_ON() issue originates from the earlier
commit 5bea1fbf9423 ("staging: udlfb: fix incorrect fb_defio
implementation for multiple framebuffers"), so target that for the fix.

Fixes: 5bea1fbf9423 ("staging: udlfb: fix incorrect fb_defio implementation for 
multiple framebuffers")
Cc: <[email protected]>
Signed-off-by: Lorenzo Stoakes (ARM) <[email protected]>
---
 drivers/video/fbdev/udlfb.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/drivers/video/fbdev/udlfb.c b/drivers/video/fbdev/udlfb.c
index e78d6f95c9c5..5fbad9355e57 100644
--- a/drivers/video/fbdev/udlfb.c
+++ b/drivers/video/fbdev/udlfb.c
@@ -947,10 +947,13 @@ static int dlfb_ops_open(struct fb_info *info, int user)
                        fbdefio->delay = DL_DEFIO_WRITE_DELAY;
                        fbdefio->sort_pagereflist = true;
                        fbdefio->deferred_io = dlfb_dpy_deferred_io;
-               }
 
-               info->fbdefio = fbdefio;
-               fb_deferred_io_init(info);
+                       info->fbdefio = fbdefio;
+                       if (fb_deferred_io_init(info)) {
+                               kfree(fbdefio);
+                               info->fbdefio = NULL;
+                       }
+               }
        }
 
        dev_dbg(info->dev, "open, user=%d fb_info=%p count=%d\n",

-- 
2.55.0

Reply via email to