* [PATCH 0/4] pinctrl: free maps on DT mapping failures
@ 2026-09-24 11:18 Jiale Yao
2026-09-24 11:18 ` [PATCH 1/4] pinctrl: sprd: free maps on DT map failure Jiale Yao
` (3 more replies)
0 siblings, 4 replies; 8+ messages in thread
From: Jiale Yao @ 2026-09-24 11:18 UTC (permalink / raw)
To: Geert Uytterhoeven, Linus Walleij, Orson Zhai, Baolin Wang,
Chunyan Zhang, Thierry Reding, Jonathan Hunter,
Krzysztof Kozlowski, linux-renesas-soc, linux-gpio, linux-kernel,
linux-tegra
Cc: Jiale Yao
Several pinctrl drivers reserve map storage before appending mux and
configuration entries while translating device tree nodes. If a later
operation fails, their error paths free only temporary configuration data
and leave the partially built map allocated.
Commit 17007cd700601777d9ee203a13d97e64ece3a10f fixed the same cleanup
problem in the generic mapping helper. These drivers use their own mapping
callbacks and need equivalent error handling.
Free the accumulated map and clear the output parameters on every failure
path in the Spreadtrum, Renesas RZ/N1, Tegra XUSB, and Samsung drivers.
Each patch changes one driver and remains independently buildable.
Jiale Yao (4):
pinctrl: sprd: free maps on DT map failure
pinctrl: renesas: rzn1: free maps on DT map failure
pinctrl: tegra: xusb: free maps on DT map failure
pinctrl: samsung: free maps on DT map failure
drivers/pinctrl/renesas/pinctrl-rzn1.c | 10 +++++++--
drivers/pinctrl/samsung/pinctrl-samsung.c | 26 ++++++++++++++--------
drivers/pinctrl/sprd/pinctrl-sprd.c | 6 +++++
drivers/pinctrl/tegra/pinctrl-tegra-xusb.c | 8 ++++++-
4 files changed, 38 insertions(+), 12 deletions(-)
--
2.34.1
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 1/4] pinctrl: sprd: free maps on DT map failure
2026-09-24 11:18 [PATCH 0/4] pinctrl: free maps on DT mapping failures Jiale Yao
@ 2026-09-24 11:18 ` Jiale Yao
2026-09-29 6:08 ` Baolin Wang
2026-09-24 11:18 ` [PATCH 2/4] pinctrl: renesas: rzn1: " Jiale Yao
` (2 subsequent siblings)
3 siblings, 1 reply; 8+ messages in thread
From: Jiale Yao @ 2026-09-24 11:18 UTC (permalink / raw)
To: Geert Uytterhoeven, Linus Walleij, Orson Zhai, Baolin Wang,
Chunyan Zhang, Thierry Reding, Jonathan Hunter,
Krzysztof Kozlowski, linux-renesas-soc, linux-gpio, linux-kernel,
linux-tegra
Cc: Jiale Yao
sprd_dt_node_to_map() reserves map storage before adding mux and
configuration entries. If a later operation fails, the error path only
frees the temporary configurations and leaves the map allocation reachable
through the output pointer.
Free the partially built map and clear the output parameters on failure.
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/pinctrl/sprd/pinctrl-sprd.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/pinctrl/sprd/pinctrl-sprd.c b/drivers/pinctrl/sprd/pinctrl-sprd.c
index 16cf9d15f247..218ac5236e95 100644
--- a/drivers/pinctrl/sprd/pinctrl-sprd.c
+++ b/drivers/pinctrl/sprd/pinctrl-sprd.c
@@ -326,6 +326,12 @@ static int sprd_dt_node_to_map(struct pinctrl_dev *pctldev,
out:
kfree(configs);
+ if (ret < 0) {
+ pinctrl_utils_free_map(pctldev, *map, *num_maps);
+ *map = NULL;
+ *num_maps = 0;
+ }
+
return ret;
}
--
2.34.1
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 2/4] pinctrl: renesas: rzn1: free maps on DT map failure
2026-09-24 11:18 [PATCH 0/4] pinctrl: free maps on DT mapping failures Jiale Yao
2026-09-24 11:18 ` [PATCH 1/4] pinctrl: sprd: free maps on DT map failure Jiale Yao
@ 2026-09-24 11:18 ` Jiale Yao
2026-09-28 13:19 ` Geert Uytterhoeven
2026-09-24 11:18 ` [PATCH 3/4] pinctrl: tegra: xusb: " Jiale Yao
2026-09-24 11:18 ` [PATCH 4/4] pinctrl: samsung: " Jiale Yao
3 siblings, 1 reply; 8+ messages in thread
From: Jiale Yao @ 2026-09-24 11:18 UTC (permalink / raw)
To: Geert Uytterhoeven, Linus Walleij, Orson Zhai, Baolin Wang,
Chunyan Zhang, Thierry Reding, Jonathan Hunter,
Krzysztof Kozlowski, linux-renesas-soc, linux-gpio, linux-kernel,
linux-tegra
Cc: Jiale Yao
rzn1_dt_node_to_map_one() appends mappings for each DT node. If a
node fails after map storage has been reserved, the top-level callback
returns without releasing mappings built for the current and previous
nodes.
Free the accumulated map and clear the output parameters on every error
path.
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/pinctrl/renesas/pinctrl-rzn1.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/pinctrl/renesas/pinctrl-rzn1.c b/drivers/pinctrl/renesas/pinctrl-rzn1.c
index fb874867dbfb..1b977504d26e 100644
--- a/drivers/pinctrl/renesas/pinctrl-rzn1.c
+++ b/drivers/pinctrl/renesas/pinctrl-rzn1.c
@@ -411,15 +411,21 @@ static int rzn1_dt_node_to_map(struct pinctrl_dev *pctldev,
ret = rzn1_dt_node_to_map_one(pctldev, np, map, num_maps);
if (ret < 0)
- return ret;
+ goto err_free_map;
for_each_child_of_node_scoped(np, child) {
ret = rzn1_dt_node_to_map_one(pctldev, child, map, num_maps);
if (ret < 0)
- return ret;
+ goto err_free_map;
}
return 0;
+
+err_free_map:
+ pinctrl_utils_free_map(pctldev, *map, *num_maps);
+ *map = NULL;
+ *num_maps = 0;
+ return ret;
}
static const struct pinctrl_ops rzn1_pctrl_ops = {
--
2.34.1
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 3/4] pinctrl: tegra: xusb: free maps on DT map failure
2026-09-24 11:18 [PATCH 0/4] pinctrl: free maps on DT mapping failures Jiale Yao
2026-09-24 11:18 ` [PATCH 1/4] pinctrl: sprd: free maps on DT map failure Jiale Yao
2026-09-24 11:18 ` [PATCH 2/4] pinctrl: renesas: rzn1: " Jiale Yao
@ 2026-09-24 11:18 ` Jiale Yao
2026-09-24 11:18 ` [PATCH 4/4] pinctrl: samsung: " Jiale Yao
3 siblings, 0 replies; 8+ messages in thread
From: Jiale Yao @ 2026-09-24 11:18 UTC (permalink / raw)
To: Geert Uytterhoeven, Linus Walleij, Orson Zhai, Baolin Wang,
Chunyan Zhang, Thierry Reding, Jonathan Hunter,
Krzysztof Kozlowski, linux-renesas-soc, linux-gpio, linux-kernel,
linux-tegra
Cc: Jiale Yao
tegra_xusb_padctl_parse_subnode() can append mappings before a later
child or configuration operation fails. The top-level callback currently
returns the error while retaining all mappings allocated for earlier
children.
Free the accumulated map and clear the output parameters on failure.
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/pinctrl/tegra/pinctrl-tegra-xusb.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/pinctrl/tegra/pinctrl-tegra-xusb.c b/drivers/pinctrl/tegra/pinctrl-tegra-xusb.c
index c6a51bb21215..8873d7068867 100644
--- a/drivers/pinctrl/tegra/pinctrl-tegra-xusb.c
+++ b/drivers/pinctrl/tegra/pinctrl-tegra-xusb.c
@@ -248,10 +248,16 @@ static int tegra_xusb_padctl_dt_node_to_map(struct pinctrl_dev *pinctrl,
&reserved_maps,
num_maps);
if (err < 0)
- return err;
+ goto err_free_map;
}
return 0;
+
+err_free_map:
+ pinctrl_utils_free_map(pinctrl, *maps, *num_maps);
+ *maps = NULL;
+ *num_maps = 0;
+ return err;
}
static const struct pinctrl_ops tegra_xusb_padctl_pinctrl_ops = {
--
2.34.1
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 4/4] pinctrl: samsung: free maps on DT map failure
2026-09-24 11:18 [PATCH 0/4] pinctrl: free maps on DT mapping failures Jiale Yao
` (2 preceding siblings ...)
2026-09-24 11:18 ` [PATCH 3/4] pinctrl: tegra: xusb: " Jiale Yao
@ 2026-09-24 11:18 ` Jiale Yao
3 siblings, 0 replies; 8+ messages in thread
From: Jiale Yao @ 2026-09-24 11:18 UTC (permalink / raw)
To: Geert Uytterhoeven, Linus Walleij, Orson Zhai, Baolin Wang,
Chunyan Zhang, Thierry Reding, Jonathan Hunter,
Krzysztof Kozlowski, linux-renesas-soc, linux-gpio, linux-kernel,
linux-tegra
Cc: Jiale Yao
samsung_dt_subnode_to_map() can reserve map storage before adding
configuration entries. The no-child path returns its error directly, and
the child path frees mappings without clearing the output parameters.
Use one error path that frees the accumulated map and clears the output
parameters for both cases.
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
drivers/pinctrl/samsung/pinctrl-samsung.c | 26 +++++++++++++++--------
1 file changed, 17 insertions(+), 9 deletions(-)
diff --git a/drivers/pinctrl/samsung/pinctrl-samsung.c b/drivers/pinctrl/samsung/pinctrl-samsung.c
index 5ecc9ed4c44d..4b202fbbcb80 100644
--- a/drivers/pinctrl/samsung/pinctrl-samsung.c
+++ b/drivers/pinctrl/samsung/pinctrl-samsung.c
@@ -259,22 +259,30 @@ static int samsung_dt_node_to_map(struct pinctrl_dev *pctldev,
*map = NULL;
*num_maps = 0;
- if (!of_get_child_count(np_config))
- return samsung_dt_subnode_to_map(drvdata, pctldev->dev,
- np_config, map,
- &reserved_maps,
- num_maps);
+ if (!of_get_child_count(np_config)) {
+ ret = samsung_dt_subnode_to_map(drvdata, pctldev->dev,
+ np_config, map, &reserved_maps,
+ num_maps);
+ if (ret < 0)
+ goto err_free_map;
+
+ return 0;
+ }
for_each_child_of_node_scoped(np_config, np) {
ret = samsung_dt_subnode_to_map(drvdata, pctldev->dev, np, map,
&reserved_maps, num_maps);
- if (ret < 0) {
- samsung_dt_free_map(pctldev, *map, *num_maps);
- return ret;
- }
+ if (ret < 0)
+ goto err_free_map;
}
return 0;
+
+err_free_map:
+ samsung_dt_free_map(pctldev, *map, *num_maps);
+ *map = NULL;
+ *num_maps = 0;
+ return ret;
}
#ifdef CONFIG_DEBUG_FS
--
2.34.1
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH 2/4] pinctrl: renesas: rzn1: free maps on DT map failure
2026-09-24 11:18 ` [PATCH 2/4] pinctrl: renesas: rzn1: " Jiale Yao
@ 2026-09-28 13:19 ` Geert Uytterhoeven
2026-09-29 8:07 ` jiale yao
0 siblings, 1 reply; 8+ messages in thread
From: Geert Uytterhoeven @ 2026-09-28 13:19 UTC (permalink / raw)
To: Jiale Yao
Cc: Linus Walleij, Orson Zhai, Baolin Wang, Chunyan Zhang,
Thierry Reding, Jonathan Hunter, Krzysztof Kozlowski,
linux-renesas-soc, linux-gpio, linux-kernel, linux-tegra
Hi Jiale,
On Thu, 24 Sept 2026 at 13:19, Jiale Yao <yaojiale02@163.com> wrote:
> rzn1_dt_node_to_map_one() appends mappings for each DT node. If a
> node fails after map storage has been reserved, the top-level callback
> returns without releasing mappings built for the current and previous
> nodes.
>
> Free the accumulated map and clear the output parameters on every error
> path.
>
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
Thanks for your patch!
> --- a/drivers/pinctrl/renesas/pinctrl-rzn1.c
> +++ b/drivers/pinctrl/renesas/pinctrl-rzn1.c
> @@ -411,15 +411,21 @@ static int rzn1_dt_node_to_map(struct pinctrl_dev *pctldev,
>
> ret = rzn1_dt_node_to_map_one(pctldev, np, map, num_maps);
> if (ret < 0)
> - return ret;
> + goto err_free_map;
>
> for_each_child_of_node_scoped(np, child) {
> ret = rzn1_dt_node_to_map_one(pctldev, child, map, num_maps);
> if (ret < 0)
> - return ret;
> + goto err_free_map;
> }
>
> return 0;
> +
> +err_free_map:
> + pinctrl_utils_free_map(pctldev, *map, *num_maps);
Nice catch!
> + *map = NULL;
> + *num_maps = 0;
Is the resetting actually needed?
Only pinctrl-generic.c, pinctrl-sprd.c, and pinctrl-tegra-xusb.c seem
to do that.
> + return ret;
> }
>
> static const struct pinctrl_ops rzn1_pctrl_ops = {
Gr{oetje,eeting}s,
Geert
--
Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org
In personal conversations with technical people, I call myself a hacker. But
when I'm talking to journalists I just say "programmer" or something like that.
-- Linus Torvalds
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH 1/4] pinctrl: sprd: free maps on DT map failure
2026-09-24 11:18 ` [PATCH 1/4] pinctrl: sprd: free maps on DT map failure Jiale Yao
@ 2026-09-29 6:08 ` Baolin Wang
0 siblings, 0 replies; 8+ messages in thread
From: Baolin Wang @ 2026-09-29 6:08 UTC (permalink / raw)
To: Jiale Yao, Geert Uytterhoeven, Linus Walleij, Orson Zhai,
Chunyan Zhang, Thierry Reding, Jonathan Hunter,
Krzysztof Kozlowski, linux-renesas-soc, linux-gpio, linux-kernel,
linux-tegra
On 9/24/26 7:18 PM, Jiale Yao wrote:
> sprd_dt_node_to_map() reserves map storage before adding mux and
> configuration entries. If a later operation fails, the error path only
> frees the temporary configurations and leaves the map allocation reachable
> through the output pointer.
>
> Free the partially built map and clear the output parameters on failure.
>
> Signed-off-by: Jiale Yao <yaojiale02@163.com>
> ---
LGTM. Please add the Fixes tag:
Fixes: 41d32cfce1ae ("pinctrl: sprd: Add Spreadtrum pin control driver")
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
> drivers/pinctrl/sprd/pinctrl-sprd.c | 6 ++++++
> 1 file changed, 6 insertions(+)
>
> diff --git a/drivers/pinctrl/sprd/pinctrl-sprd.c b/drivers/pinctrl/sprd/pinctrl-sprd.c
> index 16cf9d15f247..218ac5236e95 100644
> --- a/drivers/pinctrl/sprd/pinctrl-sprd.c
> +++ b/drivers/pinctrl/sprd/pinctrl-sprd.c
> @@ -326,6 +326,12 @@ static int sprd_dt_node_to_map(struct pinctrl_dev *pctldev,
>
> out:
> kfree(configs);
> + if (ret < 0) {
> + pinctrl_utils_free_map(pctldev, *map, *num_maps);
> + *map = NULL;
> + *num_maps = 0;
> + }
> +
> return ret;
> }
>
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re:Re: [PATCH 2/4] pinctrl: renesas: rzn1: free maps on DT map failure
2026-09-28 13:19 ` Geert Uytterhoeven
@ 2026-09-29 8:07 ` jiale yao
0 siblings, 0 replies; 8+ messages in thread
From: jiale yao @ 2026-09-29 8:07 UTC (permalink / raw)
To: Geert Uytterhoeven
Cc: Linus Walleij, Orson Zhai, Baolin Wang, Chunyan Zhang,
Thierry Reding, Jonathan Hunter, Krzysztof Kozlowski,
linux-renesas-soc, linux-gpio, linux-kernel, linux-tegra
Hi Geert,
At 2026-09-28 21:19:48, "Geert Uytterhoeven" <geert@linux-m68k.org> wrote:
>Hi Jiale,
>
>On Thu, 24 Sept 2026 at 13:19, Jiale Yao <yaojiale02@163.com> wrote:
>> rzn1_dt_node_to_map_one() appends mappings for each DT node. If a
>> node fails after map storage has been reserved, the top-level callback
>> returns without releasing mappings built for the current and previous
>> nodes.
>>
>> Free the accumulated map and clear the output parameters on every error
>> path.
>>
>> Signed-off-by: Jiale Yao <yaojiale02@163.com>
>
>Thanks for your patch!
>
>> --- a/drivers/pinctrl/renesas/pinctrl-rzn1.c
>> +++ b/drivers/pinctrl/renesas/pinctrl-rzn1.c
>> @@ -411,15 +411,21 @@ static int rzn1_dt_node_to_map(struct pinctrl_dev *pctldev,
>>
>> ret = rzn1_dt_node_to_map_one(pctldev, np, map, num_maps);
>> if (ret < 0)
>> - return ret;
>> + goto err_free_map;
>>
>> for_each_child_of_node_scoped(np, child) {
>> ret = rzn1_dt_node_to_map_one(pctldev, child, map, num_maps);
>> if (ret < 0)
>> - return ret;
>> + goto err_free_map;
>> }
>>
>> return 0;
>> +
>> +err_free_map:
>> + pinctrl_utils_free_map(pctldev, *map, *num_maps);
>
>Nice catch!
>
>> + *map = NULL;
>> + *num_maps = 0;
>
>Is the resetting actually needed?
>Only pinctrl-generic.c, pinctrl-sprd.c, and pinctrl-tegra-xusb.c seem
>to do that
No, the resetting is not needed, as the caller does not inspect the
output parameters when dt_node_to_map() returns an error.
I'll drop both assignments and update the commit message in v2.
.
>
>> + return ret;
>> }
>>
>> static const struct pinctrl_ops rzn1_pctrl_ops = {
>
>Gr{oetje,eeting}s,
>
> Geert
>
>
>--
>Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org
>
>In personal conversations with technical people, I call myself a hacker. But
>when I'm talking to journalists I just say "programmer" or something like that.
> -- Linus Torvalds
Jiale
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-09-29 8:07 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-24 11:18 [PATCH 0/4] pinctrl: free maps on DT mapping failures Jiale Yao
2026-09-24 11:18 ` [PATCH 1/4] pinctrl: sprd: free maps on DT map failure Jiale Yao
2026-09-29 6:08 ` Baolin Wang
2026-09-24 11:18 ` [PATCH 2/4] pinctrl: renesas: rzn1: " Jiale Yao
2026-09-28 13:19 ` Geert Uytterhoeven
2026-09-29 8:07 ` jiale yao
2026-09-24 11:18 ` [PATCH 3/4] pinctrl: tegra: xusb: " Jiale Yao
2026-09-24 11:18 ` [PATCH 4/4] pinctrl: samsung: " Jiale Yao
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®