* Re: [PATCH] bus: arm-cci: fix device_node refcount leak in cci_probe_ports()
[not found] <6a887550.f7f62383.10ed1b.5875@mx.google.com>
@ 2026-08-24 7:00 ` Markus Elfring
2026-08-24 11:48 ` Robin Murphy
0 siblings, 1 reply; 4+ messages in thread
From: Markus Elfring @ 2026-08-24 7:00 UTC (permalink / raw)
To: Manush Prajwal, linux-arm-kernel, Arnd Bergmann,
Lorenzo Pieralisi, Robin Murphy
Cc: LKML, kernel-janitors, Kees Cook, Punit Agrawal, Will Deacon
> cci_probe_ports() has two device_node refcount bugs in its
> for_each_available_child_of_node() loop over "cp":
…
How do you think about to add any tags (like “Fixes” and “Cc”) accordingly?
See also:
* https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/process/submitting-patches.rst?h=v7.2-rc5#n145
* https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/process/stable-kernel-rules.rst?h=v7.2-rc5#n34
Regards,
Markus
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] bus: arm-cci: fix device_node refcount leak in cci_probe_ports()
2026-08-24 7:00 ` [PATCH] bus: arm-cci: fix device_node refcount leak in cci_probe_ports() Markus Elfring
@ 2026-08-24 11:48 ` Robin Murphy
2026-08-24 12:00 ` Markus Elfring
0 siblings, 1 reply; 4+ messages in thread
From: Robin Murphy @ 2026-08-24 11:48 UTC (permalink / raw)
To: Markus Elfring; +Cc: LKML, kernel-janitors, linux-arm-kernel, Manush Prajwal
On 2026-08-24 8:00 am, Markus Elfring wrote:
>> cci_probe_ports() has two device_node refcount bugs in its
>> for_each_available_child_of_node() loop over "cp":
> …
>
> How do you think about to add any tags (like “Fixes” and “Cc”) accordingly?
No.
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/process/stable-kernel-rules.rst?h=v7.2-rc5#n15
>
> See also:
> * https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/process/submitting-patches.rst?h=v7.2-rc5#n145
> * https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/process/stable-kernel-rules.rst?h=v7.2-rc5#n34
>
> Regards,
> Markus
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] bus: arm-cci: fix device_node refcount leak in cci_probe_ports()
2026-08-24 11:48 ` Robin Murphy
@ 2026-08-24 12:00 ` Markus Elfring
0 siblings, 0 replies; 4+ messages in thread
From: Markus Elfring @ 2026-08-24 12:00 UTC (permalink / raw)
To: Robin Murphy, Manush Prajwal, linux-arm-kernel; +Cc: LKML, kernel-janitors
>>> cci_probe_ports() has two device_node refcount bugs in its
>>> for_each_available_child_of_node() loop over "cp":
>> …
>>
>> How do you think about to add any tags (like “Fixes” and “Cc”) accordingly?
>
> No.
>
> https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/process/stable-kernel-rules.rst?h=v7.2-rc5#n15
Have you got special imaginations for the bug severity?
Regards,
Markus
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH] bus: arm-cci: fix device_node refcount leak in cci_probe_ports()
@ 2026-08-13 11:10 Manush Prajwal
0 siblings, 0 replies; 4+ messages in thread
From: Manush Prajwal @ 2026-08-13 11:10 UTC (permalink / raw)
To: linux-arm-kernel; +Cc: linux-kernel, Manush Prajwal
When the number of matching child nodes reaches nb_cci_ports,
cci_probe_ports() breaks out of the for_each_available_child_of_node()
loop without releasing the reference held on the current node. Every
other exit from this loop iteration either continues (handled by the
iterator) or stores the node into ports[i].dn; this early break is the
only path that drops the last handle to the node without a matching
of_node_put(). Add it before the break.
Signed-off-by: Manush Prajwal <manushprajwal555@gmail.com>
---
drivers/bus/arm-cci.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/bus/arm-cci.c b/drivers/bus/arm-cci.c
index 7f2baf0571..5ab3d74c9a 100644
--- a/drivers/bus/arm-cci.c
+++ b/drivers/bus/arm-cci.c
@@ -461,8 +461,10 @@ static int cci_probe_ports(struct device_node *np)
i = nb_ace + nb_ace_lite;
- if (i >= nb_cci_ports)
+ if (i >= nb_cci_ports) {
+ of_node_put(cp);
break;
+ }
if (of_property_read_string(cp, "interface-type",
&match_str)) {
--
2.46.2.windows.1
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-24 12:00 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <6a887550.f7f62383.10ed1b.5875@mx.google.com>
2026-08-24 7:00 ` [PATCH] bus: arm-cci: fix device_node refcount leak in cci_probe_ports() Markus Elfring
2026-08-24 11:48 ` Robin Murphy
2026-08-24 12:00 ` Markus Elfring
2026-08-13 11:10 Manush Prajwal
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®