komeda_platform_probe() enables runtime PM before publishing the driver
data.  The runtime PM callbacks dereference the driver data, so a
callback running in that window dereferences NULL.

The debugfs register file is created while komeda_dev_create() runs and
its read path calls pm_runtime_get_sync().  The DRM minor is registered
before dev_set_drvdata() as well.  Either path can invoke
komeda_rt_pm_resume() while the driver data is still NULL.

Publish mdrv immediately after komeda_dev_create() succeeds and before
enabling runtime PM.  This guarantees that runtime PM callbacks always
see a fully initialized mdrv->mdev.

Fixes: efb465088518 ("drm/komeda: Add runtime_pm support")
Signed-off-by: Jiale Yao <[email protected]>
---
 drivers/gpu/drm/arm/display/komeda/komeda_drv.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/arm/display/komeda/komeda_drv.c 
b/drivers/gpu/drm/arm/display/komeda/komeda_drv.c
index 67fffab018ae..82efa74199be 100644
--- a/drivers/gpu/drm/arm/display/komeda/komeda_drv.c
+++ b/drivers/gpu/drm/arm/display/komeda/komeda_drv.c
@@ -73,6 +73,8 @@ static int komeda_platform_probe(struct platform_device *pdev)
                goto free_mdrv;
        }
 
+       dev_set_drvdata(dev, mdrv);
+
        pm_runtime_enable(dev);
        if (!pm_runtime_enabled(dev)) {
                err = komeda_dev_resume(mdrv->mdev);
@@ -86,7 +88,6 @@ static int komeda_platform_probe(struct platform_device *pdev)
                goto destroy_mdev;
        }
 
-       dev_set_drvdata(dev, mdrv);
        drm_client_setup(&mdrv->kms->base, NULL);
 
        return 0;
-- 
2.34.1

Reply via email to