From: Jonathan Cameron <jic23@kernel.org>
To: Andy Shevchenko <andriy.shevchenko@intel.com>
Cc: Ethan Tidmore <ethantidmore06@gmail.com>,
linusw@kernel.org, dlechner@baylibre.com, nuno.sa@analog.com,
andy@kernel.org, linux-iio@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH] iio: gyro: mpu3050: Fix resource leak
Date: Sun, 22 Feb 2026 16:30:29 +0000 [thread overview]
Message-ID: <20260222163029.14c3f8b3@jic23-huawei> (raw)
In-Reply-To: <aZrjbmU8Vt98Sjwr@smile.fi.intel.com>
On Sun, 22 Feb 2026 13:07:26 +0200
Andy Shevchenko <andriy.shevchenko@intel.com> wrote:
> On Fri, Feb 20, 2026 at 02:05:22PM -0600, Ethan Tidmore wrote:
> > The interrupt handler is setup but only a few lines down if
> > iio_trigger_register() fails the function returns without properly
> > releasing the handler:
> >
> > ret = request_threaded_irq(irq,
> > mpu3050_irq_handler,
> > mpu3050_irq_thread,
> > irq_trig,
> > mpu3050->trig->name,
> > mpu3050->trig);
> >
> > ...
> >
> > ret = iio_trigger_register(mpu3050->trig);
> > if (ret)
> > return ret;
> >
> > indio_dev->trig = iio_trigger_get(mpu3050->trig);
> >
> > return 0;
> > }
> >
> > Change request_threaded_irq() to devm_request_threaded_irq() to resolve
> > resource leak and use current API.
> >
> > Detected by Smatch:
> > drivers/iio/gyro/mpu3050-core.c:1128 mpu3050_trigger_probe() warn:
> > 'irq' from request_threaded_irq() not released on lines: 1124.
>
> ...
>
> > + ret = devm_request_threaded_irq(dev,
> > + irq,
> > + mpu3050_irq_handler,
> > + mpu3050_irq_thread,
> > + irq_trig,
> > + mpu3050->trig->name,
> > + mpu3050->trig);
> > if (ret) {
> > dev_err(dev, "can't get IRQ %d, error %d\n", irq, ret);
> > return ret;
>
> Now this prints two messages on the error path...
>
This driver is a bit of a mess wrt to devm already and the change here makes
things worse. Rule for devm (to make it easy to reason about) is you use it
on everything until a particular point in probe when you switch to not using
it for anything. Mix and match leads to subtle race conditions.
Now, today the mix and match is there but on memory allocations which tend
to be safe to release late (though not recommended to do so!) this adds
irqs to that mix.
So your patch is fixing a real issue, but I think we should be looking to
clean up the other related issues around it.
As a side note, the indio_dev->trig should not be set after iio_device_register()
That's one reason almost all drivers register triggers before the device.
Also the free_irq() you are dropping is out of sequence wrt to
iio_triggered_buffer_cleanup()
If you want to take this driver on I'd suggest it needs a more complex and general
conversion to devm.
Alternative is just fix the problem you've identified but not using devm_
but instead use goto and a manual free_irq() call in the error path.
Thanks,
Jonathan
prev parent reply other threads:[~2026-02-22 16:30 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-02-20 20:05 Ethan Tidmore
2026-02-22 11:07 ` Andy Shevchenko
2026-02-22 16:30 ` Jonathan Cameron [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260222163029.14c3f8b3@jic23-huawei \
--to=jic23@kernel.org \
--cc=andriy.shevchenko@intel.com \
--cc=andy@kernel.org \
--cc=dlechner@baylibre.com \
--cc=ethantidmore06@gmail.com \
--cc=linusw@kernel.org \
--cc=linux-iio@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nuno.sa@analog.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®