From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f54.google.com (mail-pj1-f54.google.com [209.85.216.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D94CD42A15E for ; Sat, 15 Aug 2026 18:13:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.54 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786817593; cv=none; b=nTfMTv3etaI0KAKtKZAXx17JPhav8OGR/m9aFoMmRQvrd6NrqtNvq3S9C4PzMbKp4G0400SzmFPJCnPZeSFlupvpGHc+g2XjKEk7jeK7pUvz1G5GjK67JIaQYluCycP47aglXAdhxms6PO2MvrSaCzCJB1ELJNvyqw1cJqN+LIg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786817593; c=relaxed/simple; bh=t3t7eK6kze1JhppxfIkpcARg5SYY1S80ibdnXdinBHg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=P7p5t7Jk2VsQmQ8VcibB8p8fQihxrwNgUKLKENMBeZJifcCXyToXWeNiJGXbQ9+A340QAfIijMHB0W44v9r75VgWphwC4Sin6mLhAWKI2x6J0VWnpxmLG0/2tFJYf/UXAYwMcORxDPh3iqY/QCDqNpsb41rk4MSl/JtAqah8VXo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Ha73oWMX; arc=none smtp.client-ip=209.85.216.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Ha73oWMX" Received: by mail-pj1-f54.google.com with SMTP id 98e67ed59e1d1-383b4a3755fso2131753a91.3 for ; Sat, 15 Aug 2026 11:13:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786817582; x=1787422382; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=i7/QgzN5wyVgDaVsVdjpFdimGVN0rJBMi0oSVa7MqkE=; b=Ha73oWMXcWU8QZFT0AT5zV4KcfoCPUdgWcozoJ7227IyIEcMOfy31xDO4GIG9/fHvk XOQrSpvi7EAdo3e5f0XI7VAbbyliI5+VdCp5Q2n/ZYp5lgdK554l3rWSuHjA9PXnsdRJ d2Wpzn0w17Kh37BYlLAiMNNvTnjOd7lImPYE2su7mzPs8YJTn/NEzoiK+haGiKCeqTfv mkOFXzrBudRr5RgZmAfn3LJHcpOZ/B1kHXdXUSdvuzq6lsQFwkOBB+dodLbxpjSDXoaY BvQ6bmeXUY5bMe3dzUZffdzfbueXlhVAwlLeo0cjgx273vHwisLi0Edi3eAwe8+YQ9vt AMQA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786817582; x=1787422382; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=i7/QgzN5wyVgDaVsVdjpFdimGVN0rJBMi0oSVa7MqkE=; b=n6yNoOaEY5xu+L6kDiAhOSCqefaKPzKlKWJ0vmQXib6W6lFUxnIbNbvnwdsVOV3spV hpFGLytqWsTBtWKMQ15ej2U1nbei3km32X9jqGW4iSmSyF6+lZWwY7xIPzzhfblh3nIx 7ih9UdfYUos9kTaXeZ5jWhTe9fGfSwpeKhW7L1bG4bfIpfhdrGbGJiJ1mV5v5Bt5G/mO us65C709XoAeomkyNF0chZ89k5KD8WHxW5G+FpDyib1z2t0r69jUc90h9oco4mnVek2O WiY1BupcqbM5YeLtWRSthOZ0uaZpavmijFpK0sz6da3+0xz9GlDBznvOVRs9LGV9wOJU rKAg== X-Forwarded-Encrypted: i=1; AHgh+RozaNIvVBX9AHF11teyyICm18uWdLDcsm5jUYtSz4UrQACPZZoeExTy2BonhZ4yqWFD44pQfVTDlexT3eg=@vger.kernel.org X-Gm-Message-State: AOJu0YyHuvS2w2n4BpLYM/Z7+8XnAo3M++uVIyKUrhvinUpqMjGt760Y YELzPHRzWpjKI51i4A4h4ttVWSU4tcvJSAnkvev2IQOlBR2XgrkcAlWO X-Gm-Gg: AR+sD11RPo96oPR2iF9ns9dSGbLzouhftBjcldZf6HLv6sOxdo/2S9mMESQn5V8OLZu qtu4hvIc3DQbuQ2/DEBzuMj6m1Q++clkVFX0gdWyanuRXq65MBbU843Q2yMCyoRWrPrs2fcTIg/ j14lHzBhPYWTJupEXHVh72Os6/ntjjvCLfYcVjfBzy5bSqNK+Ixxt34QA0HfGFem7FXsYMrePJe cG2rp/LB/GbLGHAlJMa1mBb0nX9cA/TLr4ocYrhGzHecxGbwS97nueICtZjGHLnBoe3t99yyHlp evDdSWqT+v0gxAUsb2/33incilSa8A3A9JjSGnEU/ZqqgIsefN9vHDefLUdWvzt241fMPOJavC/ EBNv4URtlt+/D9RV6g8JwCSOWc/WZaASPOs+x9KBxNuwGZP/HbLBRGftX4bTcNlHfbvzsnhj8Vl tPyfPqtRVMMsgDhoT1A+xWPTRALfzwGEZX+9YIMZOLc1hePujV0iqGKw1O30jl2xFJj8N+cLLl3 +tB9/89O3PsQsZVbRUjyJOmTD4= X-Received: by 2002:a17:90b:2747:b0:38e:2f21:3bb5 with SMTP id 98e67ed59e1d1-3933baa0da9mr17205808a91.21.1786817581938; Sat, 15 Aug 2026 11:13:01 -0700 (PDT) Received: from localhost.localdomain ([240a:4280:4800:6ace:25e8:2607:e94d:caaf]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-394eb7539d3sm7304254a91.15.2026.08.15.11.12.53 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sat, 15 Aug 2026 11:13:01 -0700 (PDT) From: Liu Zhenlong To: andi.shyti@kernel.org, chris.packham@alliedtelesis.co.nz, jochen@scram.de, maddy@linux.ibm.com, vz@mleia.com, piotr.wojtaszczyk@timesys.com Cc: mpe@ellerman.id.uk, npiggin@gmail.com, chleroy@kernel.org, grant.likely@secretlab.ca, neelegup@linux.vnet.ibm.com, benh@kernel.crashing.org, wsa@kernel.org, stigge@antcom.de, linux-i2c@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Liu Zhenlong , stable@vger.kernel.org Subject: [PATCH 2/5] i2c: cpm: fix device_node refcount leak in cpm_i2c_probe()/cpm_i2c_remove() Date: Sun, 16 Aug 2026 02:12:01 +0800 Message-ID: <20260815181204.2321-3-dragonliu2018@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260815181204.2321-1-dragonliu2018@gmail.com> References: <20260815181204.2321-1-dragonliu2018@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit cpm_i2c_probe() calls of_node_get() to take an extra reference on the platform device's of_node when assigning it to the adapter device, but neither the probe error paths nor cpm_i2c_remove() drops it. device_release() does not call of_node_put() and i2c_adapter_dev_release() only completes a struct, so the extra reference is never released, leaking the device_node on every probe failure and every adapter removal. Add the matching of_node_put() to the probe error cleanup (out_free, which covers both the cpm_i2c_setup() and i2c_add_numbered_adapter() failure paths, neither of which runs i2c_del_adapter()) and to cpm_i2c_remove(). In cpm_i2c_remove(), i2c_del_adapter() clears adap->dev with memset() at the end (commit bd4bc3dbded9 ("i2c: Clear i2c_adapter.dev on adapter removal")), which zeroes adap->dev.of_node before of_node_put() runs. Cache the pointer before calling i2c_del_adapter(), the same approach used in i2c-mux (i2c_mux_del_adapters) and mtd (commit 56570bdad5e3 ("mtd: core: Fix refcount error in del_mtd_device()")). Compile-tested with gcc-powerpc-linux-gnu on tqm8xx defconfig; no hardware available for runtime testing. Fixes: 9fd049927ccb ("of/i2c: Generalize OF support") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Signed-off-by: Liu Zhenlong --- drivers/i2c/busses/i2c-cpm.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/i2c/busses/i2c-cpm.c b/drivers/i2c/busses/i2c-cpm.c index 2cb6a233d313..08e33db32f14 100644 --- a/drivers/i2c/busses/i2c-cpm.c +++ b/drivers/i2c/busses/i2c-cpm.c @@ -671,6 +671,7 @@ static int cpm_i2c_probe(struct platform_device *ofdev) out_shut: cpm_i2c_shutdown(cpm); out_free: + of_node_put(cpm->adap.dev.of_node); kfree(cpm); return result; @@ -679,9 +680,11 @@ static int cpm_i2c_probe(struct platform_device *ofdev) static void cpm_i2c_remove(struct platform_device *ofdev) { struct cpm_i2c *cpm = platform_get_drvdata(ofdev); + struct device_node *node = cpm->adap.dev.of_node; i2c_del_adapter(&cpm->adap); + of_node_put(node); cpm_i2c_shutdown(cpm); kfree(cpm); -- 2.55.0