On Wed, Oct 07, 2026 at 08:17:43PM +0800, Guangshuo Li wrote: > After kref_init(), the device_get_match_data() failure path frees the > mailbox channel and sys_controller directly, bypassing the matching > kref_put() for the initial reference. > > Use mpfs_sys_controller_put() on this path so that the initial > reference established by kref_init() is released through the existing > kref release callback. > > Rename the error label to reflect that cleanup is now performed > through the kref helper. > > This issue was found by manual code inspection. > > Fixes: 75ef23397558 ("soc: microchip: mpfs-sys-controller: fix resource leak on probe error") > Signed-off-by: Guangshuo Li > --- > v2: > - Add the missing Signed-off-by tag. > - Rename out_free_channel to out_put as suggested by Felix. Applied, thanks. Cheers, Conor. > > drivers/soc/microchip/mpfs-sys-controller.c | 7 ++++--- > 1 file changed, 4 insertions(+), 3 deletions(-) > > diff --git a/drivers/soc/microchip/mpfs-sys-controller.c b/drivers/soc/microchip/mpfs-sys-controller.c > index 0400a01b2338..ef27e1083f0f 100644 > --- a/drivers/soc/microchip/mpfs-sys-controller.c > +++ b/drivers/soc/microchip/mpfs-sys-controller.c > @@ -159,7 +159,7 @@ static int mpfs_sys_controller_probe(struct platform_device *pdev) > of_data = (struct mpfs_syscon_config *) device_get_match_data(dev); > if (!of_data) { > ret = dev_err_probe(dev, -EINVAL, "Error getting match data\n"); > - goto out_free_channel; > + goto out_put; > } > > for (i = 0; i < of_data->nb_subdevs; i++) { > @@ -173,8 +173,9 @@ static int mpfs_sys_controller_probe(struct platform_device *pdev) > > return 0; > > -out_free_channel: > - mbox_free_channel(sys_controller->chan); > +out_put: > + mpfs_sys_controller_put(sys_controller); > + return ret; > out_free: > kfree(sys_controller); > return ret; > -- > 2.43.0 >