From: Marek Vasut <marek.vasut@mailbox.org>
To: Fuad Tabba <fuad.tabba@linux.dev>,
Manivannan Sadhasivam <mani@kernel.org>,
Yoshihiro Shimoda <yoshihiro.shimoda.uh@renesas.com>
Cc: "Lorenzo Pieralisi" <lpieralisi@kernel.org>,
"Krzysztof Wilczyński" <kwilczynski@kernel.org>,
"Rob Herring" <robh@kernel.org>,
"Bjorn Helgaas" <bhelgaas@google.com>,
"Geert Uytterhoeven" <geert+renesas@glider.be>,
"Magnus Damm" <magnus.damm@gmail.com>,
linux-pci@vger.kernel.org, linux-renesas-soc@vger.kernel.org,
linux-kernel@vger.kernel.org, "Will Deacon" <will@kernel.org>,
"Fuad Tabba" <tabba@google.com>
Subject: Re: [PATCH] PCI: rcar-gen4: Fix device_node leak in rcar_gen4_pcie_host_msi_addr()
Date: Mon, 21 Sep 2026 22:47:30 +0200 [thread overview]
Message-ID: <95685b0e-21dd-4446-8fef-c5664cea4057@mailbox.org> (raw)
In-Reply-To: <20260918091052.2825315-1-fuad.tabba@linux.dev>
On 9/18/26 11:10 AM, Fuad Tabba wrote:
> rcar_gen4_pcie_host_msi_addr() calls of_msi_xlate() with *msi_np NULL,
> so it receives the MSI controller node with a reference held, and every
> return past the NULL check leaks that reference, the success path
> included. Declare msi_node with __free(device_node) so it's put on
> every return.
>
> Fixes: 8d6af27c0a73 ("PCI: rcar-gen4: Configure AXIINTC if iMSI-RX is not used")
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: https://lore.kernel.org/linux-pci/20260905213855.8D6671F00A3D@smtp.kernel.org/
> Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
> ---
> drivers/pci/controller/dwc/pcie-rcar-gen4.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/pci/controller/dwc/pcie-rcar-gen4.c b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
> index fbe465a29068f..d61ce802b4614 100644
> --- a/drivers/pci/controller/dwc/pcie-rcar-gen4.c
> +++ b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
> @@ -323,7 +323,7 @@ static struct rcar_gen4_pcie *rcar_gen4_pcie_alloc(struct platform_device *pdev)
> static int rcar_gen4_pcie_host_msi_addr(struct dw_pcie_rp *pp, u32 *msi_addr)
> {
> struct dw_pcie *dw = to_dw_pcie_from_pp(pp);
> - struct device_node *msi_node = NULL;
> + struct device_node *msi_node __free(device_node) = NULL;
I think you have to call of_node_put() on msi_node(), so what about this
instead ?
"
diff --git a/drivers/pci/controller/dwc/pcie-rcar-gen4.c
b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
index 8057c31c0123a..2eb20cff2fcad 100644
--- a/drivers/pci/controller/dwc/pcie-rcar-gen4.c
+++ b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
@@ -382,20 +382,29 @@ static int rcar_gen4_pcie_host_msi_addr(struct
dw_pcie_rp *pp, u32 *msi_addr)
return -ENODEV;
/* Check if "msi-parent" or the "msi-map" points to ARM GICv3 ITS. */
- if (!of_device_is_compatible(msi_node, "arm,gic-v3-its"))
- return dev_err_probe(dev, -ENODEV, "Compatible MSI controller not
found\n");
+ if (!of_device_is_compatible(msi_node, "arm,gic-v3-its")) {
+ ret = dev_err_probe(dev, -ENODEV, "Compatible MSI controller not
found\n");
+ goto exit;
+ }
/* Derive GITS_TRANSLATER address from GICv3 */
ret = of_address_to_resource(msi_node, 0, &res);
- if (ret < 0)
- return dev_err_probe(dev, ret, "MSI controller resources not
obtained\n");
+ if (ret < 0) {
+ ret = dev_err_probe(dev, ret, "MSI controller resources not obtained\n");
+ goto exit;
+ }
addr = res.start + GITS_TRANSLATER;
- if (addr >= SZ_4G)
- return dev_err_probe(dev, -EINVAL, "MSI controller address above
32bit range\n");
+ if (addr >= SZ_4G) {
+ ret = dev_err_probe(dev, -EINVAL, "MSI controller address above 32bit
range\n");
+ goto exit;
+ }
*msi_addr = addr;
- return 0;
+
+exit:
+ of_node_put(msi_node);
+ return ret;
}
static int rcar_gen4_pcie_host_msi_init(struct dw_pcie_rp *pp)
"
Also, I think drivers/pci/controller/pcie-iproc.c
iproc_pcie_msi_enable() needs similar fix ?
next prev parent reply other threads:[~2026-09-21 20:47 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 9:10 Fuad Tabba
2026-09-21 20:47 ` Marek Vasut [this message]
2026-09-22 6:38 ` Fuad Tabba
2026-09-22 18:07 ` Marek Vasut
2026-09-22 21:11 ` Fuad Tabba
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=95685b0e-21dd-4446-8fef-c5664cea4057@mailbox.org \
--to=marek.vasut@mailbox.org \
--cc=bhelgaas@google.com \
--cc=fuad.tabba@linux.dev \
--cc=geert+renesas@glider.be \
--cc=kwilczynski@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=linux-renesas-soc@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=magnus.damm@gmail.com \
--cc=mani@kernel.org \
--cc=robh@kernel.org \
--cc=tabba@google.com \
--cc=will@kernel.org \
--cc=yoshihiro.shimoda.uh@renesas.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®