[ Upstream commit 
d59be579fa932c46b908f37509f319cbd4ca9a68 ]
mdp5_get_global_state runs the risk of hitting a -EDEADLK when acquiring
the modeset lock, but currently mdp5_pipe_release doesn't check for if
an error is returned. Because of this, there is a possibility of
mdp5_pipe_release hitting a NULL dereference error.
To avoid this, let's have mdp5_pipe_release check if
mdp5_get_global_state returns an error and propogate that error.
Changes since v1:
- Separated declaration and initialization of *new_state to avoid
  compiler warning
- Fixed some spelling mistakes in commit message
Changes since v2:
- Return 0 in case where hwpipe is NULL as this is considered normal
  behavior
- Added 2nd patch in series to fix a similar NULL dereference issue in
  mdp5_mixer_release
Reported-by: Tomeu Vizoso <tomeu.vizoso@collabora.com>
Signed-off-by: Jessica Zhang <quic_jesszhan@quicinc.com>
Fixes: 7907a0d77cb4 ("drm/msm/mdp5: Use the new private_obj state")
Reviewed-by: Rob Clark <robdclark@gmail.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Patchwork: https://patchwork.freedesktop.org/patch/485179/
Link: https://lore.kernel.org/r/20220505214051.155-1-quic_jesszhan@quicinc.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
        return 0;
 }
 
-void mdp5_pipe_release(struct drm_atomic_state *s, struct mdp5_hw_pipe *hwpipe)
+int mdp5_pipe_release(struct drm_atomic_state *s, struct mdp5_hw_pipe *hwpipe)
 {
        struct msm_drm_private *priv = s->dev->dev_private;
        struct mdp5_kms *mdp5_kms = to_mdp5_kms(to_mdp_kms(priv->kms));
        struct mdp5_global_state *state = mdp5_get_global_state(s);
-       struct mdp5_hw_pipe_state *new_state = &state->hwpipe;
+       struct mdp5_hw_pipe_state *new_state;
 
        if (!hwpipe)
-               return;
+               return 0;
+
+       if (IS_ERR(state))
+               return PTR_ERR(state);
+
+       new_state = &state->hwpipe;
 
        if (WARN_ON(!new_state->hwpipe_to_plane[hwpipe->idx]))
-               return;
+               return -EINVAL;
 
        DBG("%s: release from plane %s", hwpipe->name,
                new_state->hwpipe_to_plane[hwpipe->idx]->name);
        }
 
        new_state->hwpipe_to_plane[hwpipe->idx] = NULL;
+
+       return 0;
 }
 
 void mdp5_pipe_destroy(struct mdp5_hw_pipe *hwpipe)
 
                     uint32_t caps, uint32_t blkcfg,
                     struct mdp5_hw_pipe **hwpipe,
                     struct mdp5_hw_pipe **r_hwpipe);
-void mdp5_pipe_release(struct drm_atomic_state *s, struct mdp5_hw_pipe *hwpipe);
+int mdp5_pipe_release(struct drm_atomic_state *s, struct mdp5_hw_pipe *hwpipe);
 
 struct mdp5_hw_pipe *mdp5_pipe_init(enum mdp5_pipe pipe,
                uint32_t reg_offset, uint32_t caps);
 
                                mdp5_state->r_hwpipe = NULL;
 
 
-                       mdp5_pipe_release(state->state, old_hwpipe);
-                       mdp5_pipe_release(state->state, old_right_hwpipe);
+                       ret = mdp5_pipe_release(state->state, old_hwpipe);
+                       if (ret)
+                               return ret;
+
+                       ret = mdp5_pipe_release(state->state, old_right_hwpipe);
+                       if (ret)
+                               return ret;
+
                }
        } else {
-               mdp5_pipe_release(state->state, mdp5_state->hwpipe);
-               mdp5_pipe_release(state->state, mdp5_state->r_hwpipe);
+               ret = mdp5_pipe_release(state->state, mdp5_state->hwpipe);
+               if (ret)
+                       return ret;
+
+               ret = mdp5_pipe_release(state->state, mdp5_state->r_hwpipe);
+               if (ret)
+                       return ret;
+
                mdp5_state->hwpipe = mdp5_state->r_hwpipe = NULL;
        }