From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mr85p00im-zteg06021501.me.com (mr85p00im-zteg06021501.me.com [17.58.23.183]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B6E231E0B99 for ; Fri, 13 Dec 2024 12:37:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=17.58.23.183 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1734093479; cv=none; b=FtHzzZu7mYq7SxLtY7Hh8Ym9KAJiyGM9yEi6IvGYw1goaYWLdl8u6bOyXLNMhDs3KZ8T2VMD/tskgWRgBrX+qpMpGqGepMlBKfFE/4kLIA8kI0qrTbgumxKjlYWnr0XW0/1BWqC7O9+OCLsonKoMrzm4eEtbt1sDIUGR0pyMwm0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1734093479; c=relaxed/simple; bh=wlxILsGSDKkH5PDMybeitbVATSCeBlPxUXxnMRYZnWk=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=GE4OVknv8ZOAuHIcvztbcz2Bo/DR7ZrPFRmrbqDXpknbf/u3hd+bvDeuN1S2rp7ivQklzzRWoKvhLgCkSXqn7B03Q2hyX5KsK0Q2M+zCUz9czWHx6hw80tpPnNdtELQHG0xDY8eHL8Sh1B+qP+RxDfaSwCWRjxU5MR60r51pZMU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=icloud.com; spf=pass smtp.mailfrom=icloud.com; dkim=pass (2048-bit key) header.d=icloud.com header.i=@icloud.com header.b=xx+S+tjJ; arc=none smtp.client-ip=17.58.23.183 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=icloud.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=icloud.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=icloud.com header.i=@icloud.com header.b="xx+S+tjJ" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=icloud.com; s=1a1hai; t=1734093477; bh=vHF8DCKQH6/n7GK9DPqqodw58R039f9qaEE0YJ47Wlw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To: x-icloud-hme; b=xx+S+tjJSX/ndp7wqRkmyXmIOfMsUFc6Fnl2LDiY59ajeP8ZyW27AgSD9yvTfWSyy MldnwU25gn/W1ldQHdPsRDjV2fmqHQqKEfRkmgWcrJ48gFz8yqOZVNYG2WPCSIoyC7 igZMOWUQJ6slaTvSbGN7zTeHTSbv7Oe7nVL6pJpcKqpXT7U1mPAfzMGuzda9oE3pza +yp9t4EtLPIvgUDOeTnwYzPkyX01r8okP/t1Iz61Oj5u/FxU74uyAR/quesUSIiFrs 6dP6jz/Jd2V3pnOiBFkI9FG1ZW1CkZsIIkZCIBTGAlKCqcmE01TftTxxF+KMgX5/e6 TUbBV2DTbtR7w== Received: from [192.168.1.26] (mr38p00im-dlb-asmtp-mailmevip.me.com [17.57.152.18]) by mr85p00im-zteg06021501.me.com (Postfix) with ESMTPSA id 10F2A2793FE0; Fri, 13 Dec 2024 12:37:48 +0000 (UTC) From: Zijun Hu Date: Fri, 13 Dec 2024 20:36:45 +0800 Subject: [PATCH v6 5/6] phy: core: Fix an OF node refcount leakage in of_phy_provider_lookup() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20241213-phy_core_fix-v6-5-40ae28f5015a@quicinc.com> References: <20241213-phy_core_fix-v6-0-40ae28f5015a@quicinc.com> In-Reply-To: <20241213-phy_core_fix-v6-0-40ae28f5015a@quicinc.com> To: Vinod Koul , Kishon Vijay Abraham I , Felipe Balbi , Greg Kroah-Hartman , Rob Herring , Arnd Bergmann , Lee Jones Cc: Greg Kroah-Hartman , Lorenzo Pieralisi , =?utf-8?q?Krzysztof_Wilczy=C5=84ski?= , Bjorn Helgaas , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Christophe JAILLET , Johan Hovold , Zijun Hu , stable@vger.kernel.org, linux-phy@lists.infradead.org, linux-kernel@vger.kernel.org, Zijun Hu , Johan Hovold X-Mailer: b4 0.14.2 X-Proofpoint-ORIG-GUID: kkC14_aTfSvXZL-K-AObGaPtXdPiUX68 X-Proofpoint-GUID: kkC14_aTfSvXZL-K-AObGaPtXdPiUX68 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.272,Aquarius:18.0.1057,Hydra:6.0.680,FMLib:17.12.68.34 definitions=2024-12-13_05,2024-12-12_03,2024-11-22_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 spamscore=0 phishscore=0 bulkscore=0 clxscore=1015 mlxlogscore=999 adultscore=0 mlxscore=0 suspectscore=0 malwarescore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2308100000 definitions=main-2412130089 X-Apple-Remote-Links: v=1;h=KCk=;charset=UTF-8 From: Zijun Hu For macro for_each_child_of_node(parent, child), refcount of @child has been increased before entering its loop body, so normally needs to call of_node_put(@child) before returning from the loop body to avoid refcount leakage. of_phy_provider_lookup() has such usage but does not call of_node_put() before returning, so cause leakage of the OF node refcount. Fix by simply calling of_node_put() before returning from the loop body. The APIs affected by this issue are shown below since they indirectly invoke problematic of_phy_provider_lookup(). phy_get() of_phy_get() devm_phy_get() devm_of_phy_get() devm_of_phy_get_by_index() Fixes: 2a4c37016ca9 ("phy: core: Fix of_phy_provider_lookup to return PHY provider for sub node") Cc: stable@vger.kernel.org Reviewed-by: Johan Hovold Signed-off-by: Zijun Hu --- The following kernel mainline commit fixes a similar issue: Commit: b337cc3ce475 ("backlight: lm3509_bl: Fix early returns in for_each_child_of_node()") --- drivers/phy/phy-core.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/phy/phy-core.c b/drivers/phy/phy-core.c index b88fbda6c046174b7abd0a0435ec54763e9f42bc..413f76e2d1744dd8ffb63a6c3a093f5c6cbead7b 100644 --- a/drivers/phy/phy-core.c +++ b/drivers/phy/phy-core.c @@ -145,8 +145,10 @@ static struct phy_provider *of_phy_provider_lookup(struct device_node *node) return phy_provider; for_each_child_of_node(phy_provider->children, child) - if (child == node) + if (child == node) { + of_node_put(child); return phy_provider; + } } return ERR_PTR(-EPROBE_DEFER); -- 2.34.1