From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 86DDE52122F; Wed, 30 Sep 2026 17:45:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790790340; cv=none; b=gr0c1OiN+8IL3b/0htZ/v41hWN0JblILTUuxxSUSPdqemqm7AcqW380CAUKTuPcYw5NFiqJSaxyLq/x3v+6TkeunFCbgosyTlVZpEXB2yHnJQSMiRejpkSdBq3sy9hWt72ZgirImmib/nw110dfxeb07Zqz+0s2EPwDuQbiU+nw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790790340; c=relaxed/simple; bh=95PZZzqtRKOlYfsyuEPsA3Lc0zhhKXkSmJ5bsOuCXms=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=dnDf2AMZF9Krv6ozNvlCkCXmYpdwNrA6VKELvVcgNuVUB/vaR58n8zXNnKSsQW6vsNPbP/tj14Hrci2ehHcylqcZY9sB937XlhGJ+Lw7QkaASgFPoOC0y9hdbf3Wo1pmderVrunkhbqbm/R8Ara0dP9n0ArGD6Zwy5uwylZCorw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=DoI/8Ew9; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="DoI/8Ew9" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D80AA1F000FF; Wed, 30 Sep 2026 17:45:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790790338; bh=+L/NQ3lLBNBILcJb9SBPWpfaOdn9AkNp29Ctk+rNuEo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=DoI/8Ew9qNXAFIK9agY4p6Ukr5vFHM6qh2KcKlxHOUcKP8b6B8feePLkwmsO/BbKp K7QQfU6BwXDpC3qP/ffbEdJDDg3rVnL1WqA7qHwBxPRFAW3EGirf4tk/+n2kNi7okg 8+pRs/bab7ZhB9D/L1ulYyXEmsHofAdlIY3m5pQ0= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Konrad Dybcio , Liu Zhenlong , Vladimir Zapolskiy , Andi Shyti , Sasha Levin Subject: [PATCH 6.12 795/877] i2c: qcom-cci: fix device_node refcount leak in cci_probe()/cci_remove() Date: Wed, 30 Sep 2026 17:28:26 +0200 Message-ID: <20260930152431.872331176@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Liu Zhenlong [ Upstream commit 7362a1553eb09a8cdf8be7e509bd5309a8342486 ] The of_node_put() matching of_node_get() runs after i2c_del_adapter(), whose trailing memset() zeroes adap->dev and thus adap->dev.of_node, making the put a no-op and leaking the node on every adapter removal and error cleanup. Use a devm action: the pointer is captured at registration, out of reach of that memset(), and devres runs the put once on probe failure and detach, replacing the three manual of_node_put() calls. The setup loop uses the scoped iterator form so the child node is released automatically if devm_add_action_or_reset() fails mid-loop. Suggested-by: Konrad Dybcio Fixes: 02a4a69667a2 ("i2c: qcom-cci: don't put a device tree node before i2c_add_adapter()") Assisted-by: Claude:claude-opus-5 Signed-off-by: Liu Zhenlong Cc: # v5.17+ Reviewed-by: Vladimir Zapolskiy Reviewed-by: Konrad Dybcio Signed-off-by: Andi Shyti Link: https://patch.msgid.link/20260818175750.4205-1-dragonliu2018@gmail.com Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- drivers/i2c/busses/i2c-qcom-cci.c | 20 +++++++++++--------- 1 file changed, 11 insertions(+), 9 deletions(-) --- a/drivers/i2c/busses/i2c-qcom-cci.c +++ b/drivers/i2c/busses/i2c-qcom-cci.c @@ -520,10 +520,14 @@ static const struct dev_pm_ops qcom_cci_ SET_RUNTIME_PM_OPS(cci_suspend_runtime, cci_resume_runtime, NULL) }; +static void cci_put_of_node(void *data) +{ + of_node_put(data); +} + static int cci_probe(struct platform_device *pdev) { struct device *dev = &pdev->dev; - struct device_node *child; struct resource *r; struct cci *cci; int ret, i; @@ -539,7 +543,7 @@ static int cci_probe(struct platform_dev if (!cci->data) return -ENOENT; - for_each_available_child_of_node(dev->of_node, child) { + for_each_available_child_of_node_scoped(dev->of_node, child) { struct cci_master *master; u32 idx; @@ -560,6 +564,9 @@ static int cci_probe(struct platform_dev master->adap.algo = &cci_algo; master->adap.dev.parent = dev; master->adap.dev.of_node = of_node_get(child); + ret = devm_add_action_or_reset(dev, cci_put_of_node, child); + if (ret) + return ret; master->master = idx; master->cci = cci; @@ -631,10 +638,8 @@ static int cci_probe(struct platform_dev continue; ret = i2c_add_adapter(&cci->master[i].adap); - if (ret < 0) { - of_node_put(cci->master[i].adap.dev.of_node); + if (ret < 0) goto error_i2c; - } } return 0; @@ -644,10 +649,8 @@ error_i2c: pm_runtime_dont_use_autosuspend(dev); for (--i ; i >= 0; i--) { - if (cci->master[i].cci) { + if (cci->master[i].cci) i2c_del_adapter(&cci->master[i].adap); - of_node_put(cci->master[i].adap.dev.of_node); - } } error: disable_irq(cci->irq); @@ -665,7 +668,6 @@ static void cci_remove(struct platform_d for (i = 0; i < cci->data->num_masters; i++) { if (cci->master[i].cci) { i2c_del_adapter(&cci->master[i].adap); - of_node_put(cci->master[i].adap.dev.of_node); cci_halt(cci, i); } }