* [PATCHv2] rtc: stmp3xxx: use devm_platform_ioremap_resource()
@ 2026-07-28 0:53 Rosen Penev
2026-07-28 1:04 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: Rosen Penev @ 2026-07-28 0:53 UTC (permalink / raw)
To: linux-rtc
Cc: Alexandre Belloni, Maxime Coquelin, Alexandre Torgue,
moderated list:ARM/STM32 ARCHITECTURE,
moderated list:ARM/STM32 ARCHITECTURE, open list
Replace the open-coded platform_get_resource() plus devm_ioremap()
sequence with a single devm_platform_ioremap_resource() call, which folds
the resource lookup and mapping into one step and returns an ERR_PTR on
failure, checked with IS_ERR() and propagated via PTR_ERR().
Move the mapping ahead of the devm_kzalloc() so that an error or deferred
probe is handled before the rtc_data allocation, avoiding needless work.
The fsl,stmp3xxx-rtc nodes in imx23.dtsi (reg = <0x8005c000 0x2000>) and
imx28.dtsi (reg = <0x80056000 0x2000>) each provide a single
non-overlapping IORESOURCE_MEM window, so the region reservation now
performed by devm_platform_ioremap_resource() introduces no conflict.
Remove irq_alarm from private struct. It's only used in _probe. Also add
check for platform_get_irq() errors.
Assisted-by: opencode:hy3-free
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
v2: add platform_get_irq error check
drivers/rtc/rtc-stmp3xxx.c | 32 ++++++++++++--------------------
1 file changed, 12 insertions(+), 20 deletions(-)
diff --git a/drivers/rtc/rtc-stmp3xxx.c b/drivers/rtc/rtc-stmp3xxx.c
index 7afcd14aeee5..e789458ba96a 100644
--- a/drivers/rtc/rtc-stmp3xxx.c
+++ b/drivers/rtc/rtc-stmp3xxx.c
@@ -56,7 +56,6 @@
struct stmp3xxx_rtc_data {
struct rtc_device *rtc;
void __iomem *io;
- int irq_alarm;
};
#if IS_ENABLED(CONFIG_STMP3XXX_RTC_WATCHDOG)
@@ -245,29 +244,25 @@ static void stmp3xxx_rtc_remove(struct platform_device *pdev)
static int stmp3xxx_rtc_probe(struct platform_device *pdev)
{
struct stmp3xxx_rtc_data *rtc_data;
- struct resource *r;
+ void __iomem *io;
u32 rtc_stat;
u32 pers0_set, pers0_clr;
u32 crystalfreq = 0;
int err;
+ irq_alarm = platform_get_irq(pdev, 0);
+ if (irq_alarm < 0)
+ return irq_alarm;
+
+ io = devm_platform_ioremap_resource(pdev, 0);
+ if (IS_ERR(io))
+ return PTR_ERR(io);
+
rtc_data = devm_kzalloc(&pdev->dev, sizeof(*rtc_data), GFP_KERNEL);
if (!rtc_data)
return -ENOMEM;
- r = platform_get_resource(pdev, IORESOURCE_MEM, 0);
- if (!r) {
- dev_err(&pdev->dev, "failed to get resource\n");
- return -ENXIO;
- }
-
- rtc_data->io = devm_ioremap(&pdev->dev, r->start, resource_size(r));
- if (!rtc_data->io) {
- dev_err(&pdev->dev, "ioremap failed\n");
- return -EIO;
- }
-
- rtc_data->irq_alarm = platform_get_irq(pdev, 0);
+ rtc_data->io = io;
rtc_stat = readl(rtc_data->io + STMP3XXX_RTC_STAT);
if (!(rtc_stat & STMP3XXX_RTC_STAT_RTC_PRESENT)) {
@@ -354,13 +349,10 @@ static int stmp3xxx_rtc_probe(struct platform_device *pdev)
if (IS_ERR(rtc_data->rtc))
return PTR_ERR(rtc_data->rtc);
- err = devm_request_irq(&pdev->dev, rtc_data->irq_alarm,
+ err = devm_request_irq(&pdev->dev, irq_alarm,
stmp3xxx_rtc_interrupt, 0, "RTC alarm", &pdev->dev);
- if (err) {
- dev_err(&pdev->dev, "Cannot claim IRQ%d\n",
- rtc_data->irq_alarm);
+ if (err)
return err;
- }
rtc_data->rtc->ops = &stmp3xxx_rtc_ops;
rtc_data->rtc->range_max = U32_MAX;
--
2.55.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCHv2] rtc: stmp3xxx: use devm_platform_ioremap_resource()
2026-07-28 0:53 [PATCHv2] rtc: stmp3xxx: use devm_platform_ioremap_resource() Rosen Penev
@ 2026-07-28 1:04 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-07-28 1:04 UTC (permalink / raw)
To: Rosen Penev; +Cc: Alexandre Belloni, linux-rtc
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
New issues:
- [Low] The local variable `irq_alarm` is used in `stmp3xxx_rtc_probe()` without being declared.
Pre-existing issues:
- [High] The dynamically registered child watchdog device is not unregistered when the RTC driver is unbound, leading to a NULL pointer dereference.
- [High] Incorrect devm cleanup order creates a race condition where a pending interrupt can trigger a Use-After-Free by re-queueing an already-canceled work object.
--
--- Patch [1]: [PATCHv2] rtc: stmp3xxx: use devm_platform_ioremap_resource() ---
commit 9966c4bcfecfb31f7bf74af8e9b176bb32e74820
Author: Rosen Penev <rosenp@gmail.com>
rtc: stmp3xxx: use devm_platform_ioremap_resource()
This patch refactors the driver to use devm_platform_ioremap_resource()
instead of open-coding the resource lookup and mapping. It moves the
mapping ahead of the data allocation to handle deferred probes earlier.
It also removes irq_alarm from the private struct and adds an error
check for platform_get_irq().
> diff --git a/drivers/rtc/rtc-stmp3xxx.c b/drivers/rtc/rtc-stmp3xxx.c
> index 7afcd14aeee56..e789458ba96a6 100644
> --- a/drivers/rtc/rtc-stmp3xxx.c
> +++ b/drivers/rtc/rtc-stmp3xxx.c
> @@ -245,29 +244,25 @@ static void stmp3xxx_rtc_remove(struct platform_device *pdev)
> static int stmp3xxx_rtc_probe(struct platform_device *pdev)
> {
> struct stmp3xxx_rtc_data *rtc_data;
> - struct resource *r;
> + void __iomem *io;
> u32 rtc_stat;
> u32 pers0_set, pers0_clr;
> u32 crystalfreq = 0;
> int err;
>
> + irq_alarm = platform_get_irq(pdev, 0);
[Severity: Low]
Does this regression introduce a build failure?
The variable irq_alarm was removed from the private struct stmp3xxx_rtc_data,
but it is used here without being declared as a local int variable first.
> + if (irq_alarm < 0)
> + return irq_alarm;
> +
> + io = devm_platform_ioremap_resource(pdev, 0);
[ ... ]
> @@ -354,13 +349,10 @@ static int stmp3xxx_rtc_probe(struct platform_device *pdev)
> if (IS_ERR(rtc_data->rtc))
> return PTR_ERR(rtc_data->rtc);
>
> - err = devm_request_irq(&pdev->dev, rtc_data->irq_alarm,
> + err = devm_request_irq(&pdev->dev, irq_alarm,
> stmp3xxx_rtc_interrupt, 0, "RTC alarm", &pdev->dev);
[Severity: High]
This isn't a bug introduced by this patch, but does this devm initialization
order create a use-after-free race condition during driver unbind?
The IRQ is requested via devm_request_irq() before the RTC device is
registered via devm_rtc_register_device() further down in probe.
During driver removal, devres cleans up in reverse order: the RTC device is
unregistered first (which cancels the irqwork), and the IRQ is freed second.
If a pending hardware interrupt fires in the window between these two steps,
could stmp3xxx_rtc_interrupt() unconditionally call rtc_update_irq(), which
re-queues the irqwork on an RTC device that is about to be freed?
> - if (err) {
> - dev_err(&pdev->dev, "Cannot claim IRQ%d\n",
> - rtc_data->irq_alarm);
> + if (err)
> return err;
> - }
>
> rtc_data->rtc->ops = &stmp3xxx_rtc_ops;
> rtc_data->rtc->range_max = U32_MAX;
[Severity: High]
This is a pre-existing issue, but does the dynamically registered watchdog
device leak on driver unbind?
Looking at stmp3xxx_wdt_register() called at the end of stmp3xxx_rtc_probe(),
the watchdog child device is manually added with platform_device_add(), but
stmp3xxx_rtc_remove() doesn't appear to call platform_device_unregister()
to clean this up.
If the RTC driver is unbound via sysfs, the parent device's drvdata is
cleared and devm resources are freed. Because the child watchdog device
remains active, could a subsequent access via stmp3xxx_wdt_set_timeout()
dereference the now-NULL parent drvdata and crash the system?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260728005303.574936-1-rosenp@gmail.com?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-07-28 1:04 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-28 0:53 [PATCHv2] rtc: stmp3xxx: use devm_platform_ioremap_resource() Rosen Penev
2026-07-28 1:04 ` sashiko-bot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.