From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2826C3314D0 for ; Sat, 15 Aug 2026 18:12:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.50 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786817551; cv=none; b=ePoLe5le0UiG51kFKL8JMvzq+w7Pv0zaJV6HSdgobLaZtuaP0fjRuvpAuf5wnIPVBeUvHtseIDfzVyz8jNVBAPvU0q1OZvXYiIvCk7E7K0a0yVtgiLa/b5OLKvVxhYOR5ecDMh8Qo6ja+t/Rcoba9f2jpZFUYn4dD7pBD083guQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786817551; c=relaxed/simple; bh=0lPA8fpgk92Xyi4hgB6/GLpBaTVSWp7tfnnMHrTba/s=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=fDaeTUcmsp6uzbB24aqi47ivay3n6/c/7p/L159bJeoqFavMAbLvYijcPB7flzLxRtSJG4rteQfew/euJ7I9kYGI38hpKauFWggsdetfqQv4hFg9BMj20dux7VYBYbV54PHJpn3nAop81GsXEAB2C4EuhX+nRRJ3+cnOnlPCKTE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=qSdRmCOt; arc=none smtp.client-ip=209.85.216.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="qSdRmCOt" Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-38f620399a0so1806939a91.2 for ; Sat, 15 Aug 2026 11:12:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786817549; x=1787422349; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=xW2LYIDQQYDFwK3J1a0pZQU3BluSHf7AesdfpfaEO4A=; b=qSdRmCOtbiFiBoTz7aW17qWt8nvfyWqyrx+DOkUxTn3C3BIM3101Zo60mPp5Sbhp5x +zPrdqLX74uiePJWnXoAKl9GzbkPdCgQx/qy1DM+nnfaGK8dsmpPV2Z2y0QCpZ3wdXPi BdN20Mu9intyoRARGlVNvJIhxA9A1n5lJryEGHSLORaDdU0Q6XX/BnUvXwDHRAlthYut eB4RvkULBqPejCsw+WUJKGUqllnNy6A/AgPPyRWof4Uq87fzU8MybnnRTu9VgIFeAyDx rI67ZdTKKEXdrDy2f9PYaFV1bJRpiDZbi4RntBKFLyyfqoWoAFzsyhMat9Y1JMsqKDpG S/Sg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786817549; x=1787422349; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=xW2LYIDQQYDFwK3J1a0pZQU3BluSHf7AesdfpfaEO4A=; b=AupUNnMAOxGw/Nv9SjmE/7x9stLnZ4Xvfk5Nz1BlN/S1fIs0zZWuYRBV0NvCMfE7p2 b7hLih9k+h5vb8ZmuLyJkWCtqepj+jgJB92bPcoRe//kYy93PY8xJsWCOmz2wkVZRl4c t7ucODs9O1LlW4kvMVhR+URl/e7U+YfUEDL5kn0dUogcy6P8ODj1/CwHX9+rB4VaTmtj /+ThvcA+UCL13lx+SoJmypOIMeHWLHrZsaDqerKZa+U050UWm6MWc1qhpLsITkmFioez JHu2SsOh6VNqoJRRO2WlEk+w4PwCGNTcdpCqVjpdcOkhwcmoVmuFU5oCRAXM8uVI+JE7 vEmg== X-Forwarded-Encrypted: i=1; AHgh+RpQDDkk8tg6/X7j5Oh8A0hcXcyecUQCR1wPYLChMf/HlZnVoGQ8tgTWdhzWBG2/BPRuwFnBGj1ImV8ls5U=@vger.kernel.org X-Gm-Message-State: AOJu0YxYHEj020JtJo/aZ20uXqVmIvZGS1LOSB8wqkLKHDPLrq0OrLGl EOa/k7jLNOpt0XFAxgGcTY+6NQONwWjh2fXDCcI1l5BOdXAdVBhRe/uX X-Gm-Gg: AR+sD10XnFbmbcud2oxo62kZcrvgygzTxph9rBt38CuENrfMzhQ3MUlJxn/t1ryfakx 7N5JeHZFw3fHdVVC6qU8bJv1RDm0AYRgQ53bbdd8TbXrmHFq+MSgVMgJN1HzTLKaW2/OPfhyNQ4 sEud8n6aVYjC/QbPnVv4nYAo0i3PGEzkDcatWeZnouFI5jQplK5ib6jUIkbuPxs82TD3quunjTL 7ur1g43wQ8PYP3D6NXpiev3+nE3Gs7sxkmKJDfMm6fmFR1FDxSmnyRknqfZ0xVGqL6RdTSEzFco fNO+wdIsCmgYwvs1qBmlS791/HFUOLyj77f8npQmNkyZWcQlHePf0xX3NRG+oR08oCjcXzRMp/K pI5i3fbWXM8QchI0PktPa8uAQDlD+XN6oYIUxPa1tYoU9JeImi3Fwe1kRFzHz/xyXMYTm5miKQj +FTOLdxbjiv2nIgUYmoFYWfpldu9rQtYpz9jmunjYCyX1Szpofs4vTR4SO2MfDXjur01NklVc8r j1UBAC764BpzqdKbmeHUNo3v/Q= X-Received: by 2002:a17:90b:4ec6:b0:38d:e658:5959 with SMTP id 98e67ed59e1d1-3933b80052cmr15988255a91.5.1786817549396; Sat, 15 Aug 2026 11:12:29 -0700 (PDT) Received: from localhost.localdomain ([240a:4280:4800:6ace:25e8:2607:e94d:caaf]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-394eb7539d3sm7304254a91.15.2026.08.15.11.12.22 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sat, 15 Aug 2026 11:12:28 -0700 (PDT) From: Liu Zhenlong To: andi.shyti@kernel.org, chris.packham@alliedtelesis.co.nz, jochen@scram.de, maddy@linux.ibm.com, vz@mleia.com, piotr.wojtaszczyk@timesys.com Cc: mpe@ellerman.id.uk, npiggin@gmail.com, chleroy@kernel.org, grant.likely@secretlab.ca, neelegup@linux.vnet.ibm.com, benh@kernel.crashing.org, wsa@kernel.org, stigge@antcom.de, linux-i2c@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Liu Zhenlong , stable@vger.kernel.org. Subject: [PATCH 0/5] i2c: fix device_node refcount leaks in 5 bus drivers Date: Sun, 16 Aug 2026 02:11:59 +0800 Message-ID: <20260815181204.2321-1-dragonliu2018@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit This series fixes device_node refcount leaks in 5 i2c bus drivers that share the same bug pattern: adap->dev.of_node = of_node_get(pdev->dev.of_node); Each driver calls of_node_get() to take an extra reference on the platform device's of_node when assigning it to the adapter device, but none of them drop it in the probe error paths nor in the remove() callback. device_release() does not call of_node_put(), and i2c_adapter_dev_release() only completes a struct, so the extra reference is never released, leaking the device_node on every probe failure and every adapter removal. Additionally, in the remove() callbacks, i2c_del_adapter() clears adap->dev with memset() at the end (commit bd4bc3dbded9 ("i2c: Clear i2c_adapter.dev on adapter removal")), which zeroes adap->dev.of_node before of_node_put() runs, turning it into a no-op. The fix caches the pointer before calling i2c_del_adapter(), the same approach used in i2c-mux (i2c_mux_del_adapters) and mtd (commit 56570bdad5e3 ("mtd: core: Fix refcount error in del_mtd_device()")). A related fix for the i2c-qcom-cci driver has already been submitted separately: https://lore.kernel.org/linux-i2c/20260815140931.53297-1-dragonliu2018@gmail.com/ These 5 drivers are the remaining i2c bus drivers that use of_node_get() on the adapter device; all other drivers either assign of_node directly (without taking an extra reference) or don't use Device Tree at all. Each patch has its own Fixes: tag pointing to the commit that introduced of_node_get() in the respective driver, and requests stable backport via Cc: stable@vger.kernel.org. Compile-tested with gcc on arm64 defconfig using COMPILE_TEST; no hardware available for runtime testing. Liu Zhenlong (5): i2c: mpc: fix device_node refcount leak in fsl_i2c_probe()/fsl_i2c_remove() i2c: cpm: fix device_node refcount leak in cpm_i2c_probe()/cpm_i2c_remove() i2c: ibm_iic: fix device_node refcount leak in iic_probe()/iic_remove() i2c: opal: fix device_node refcount leak in i2c_opal_probe/remove() i2c: pnx: fix device_node refcount leak in i2c_pnx_probe()/i2c_pnx_remove() drivers/i2c/busses/i2c-cpm.c | 3 +++ drivers/i2c/busses/i2c-ibm_iic.c | 4 ++++ drivers/i2c/busses/i2c-mpc.c | 6 +++++- drivers/i2c/busses/i2c-opal.c | 6 +++++- drivers/i2c/busses/i2c-pnx.c | 15 ++++++++++++--- 5 files changed, 29 insertions(+), 5 deletions(-) -- 2.55.0