From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-dy1-f181.google.com (mail-dy1-f181.google.com [74.125.82.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DF5923ACF0E for ; Thu, 8 Oct 2026 19:18:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791487112; cv=none; b=V+4+u7A1lRHVuqXERdCC1yTpxDwHcaSYFaK3zzz7vbHLw0RXuqlKTvLi8XJ/05DDW9U07Yfs0YCeiTyFuezZp8eyJIGtnwuc3PXFaZKOFKCKo6oeHEpTHP7uloWc6IQ8eL7FNf0h7KTBg6UdUp9fUbPug5B9yGhiVkpiWPrj5lw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791487112; c=relaxed/simple; bh=amUxH7dplBRK8duZIHd9DmmDP5zoeolOwFlBY/V0V8E=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MWqU5lU9Jrr0Hk8fYc7/RF3t+2W2XzTI8NGc8UW28Fv3qmC+KMcT4p/6zBh7G2TR9sYV6iKPeIh5/DWEXb5LmETcfIIbESs6JkvqWHQj2RtyjnRAzsSuHKVWZBqnxqjYVnwi/G/ObRYJjtEPOdXe8YFYbNQ/IKlK+C3oNEMmPfM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=Hs+SSw/p; arc=none smtp.client-ip=74.125.82.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="Hs+SSw/p" Received: by mail-dy1-f181.google.com with SMTP id 5a478bee46e88-35154cb9de2so4960137eec.1 for ; Thu, 08 Oct 2026 12:18:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1791487110; x=1792091910; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=a14qc72yQKkzCAZ2CAoTwipNnd9qGKItgjyfXX9xZAw=; b=Hs+SSw/p9qwN620ghvtdqdOQg0XSA8oWw6ui4jXXwEzxfjP12jOKkruaq6Y9ZvN86H xEdM05WCjb13YC4A4nyo3GK70Fiwrx2WDkDkDaM0CyrV5DjD1BhywdbcNG1umJGtoeef 9CUEZUDUmGE/Da5r+xEsDo6CxdifP7BkyG60fq/Db4pbqCCqqG51RFd1nMPI5OmdpMJl VqmzEb8hUTU2MOIGP/M4jyImzWht+RiVd3EcQ+d5vKzpPJF138/dgFvBXIBFFO3u7fjA fLt9csy1setfzcRuYsReXsxwiRBtXrT+Tzj1jM9Poihw0rHrhvz8kSCnUo0L3m6oFEbZ WaZA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791487110; x=1792091910; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=a14qc72yQKkzCAZ2CAoTwipNnd9qGKItgjyfXX9xZAw=; b=S2TVq1UZEL50blqynaqe0xfVIj+Ckz8xLfiYYDz7YabWQSX8G52jR78JUw0QAZ2fcO RTh1ei1gSXGcfI/PfdzWMwDG19tvA39k70zmZbsoy5L1AILYyWe62XG2QmeW9skYONZk h5xV3i4OwEPjAn6+1PlkxzC5Oc4KOp2bTfKrpenoGcpOQ1xo1T2BRCLJrrmYkCnP0b7I Lf5iEiBcDol9KFkejO8NSvLyE94McFNjmyfunL+GfRiZMH2BvHtNtho4S+GXXEQ5nbD2 l2u6x00eMQOQtq8cyUtHe5pmnItTh+e/hZOicvGSoTs0yX9CxaivFOwWu/a/om5uL9i+ yClw== X-Forwarded-Encrypted: i=1; AKwUvBz1q/d2p8O2dil96vcnbIjv/La5H3ojBZcDNEp7dOvLgmcJg6eJONdagZ5kfFd0TB1aMzz/1Rcm9Gu/@vger.kernel.org X-Gm-Message-State: AFq9FYKkfRKNhMbF1NGpOhfEqIQa7J8u/NboYtLtedFX5S6lC6RBzLQP hexGnaLRcGGXf6Wma+RMzCAw4QLd89rbYeCiE5Qv/8060DLe4eZTnT6VFKLIwRvPRiw= X-Gm-Gg: AYBFou2QdLYHwHPioD1uhrHBorjJgKU5bShPO9949vdtQm0pUWvAc+P8WiMQaEAFDg9 /sGc6TdsYGrwQtrievZ/uLpYclkTjq4G4iLwyOy3g3FP/OReMSpx4fUPiZxc4+GMbYtZaw9+pIM 84hkEiGn0xL/lk4SQHFFt1qMsC8SoyEYZx+i/B4GI9LrnCMQMpVcryaik+Ey1hbEq1J1wSKIGdN g4FJZmg8gz6UYGV/ZqEvjfQzUv8yom/7pEIxMHMxnWuPD5CmG7Ny3lakX/+pF8R5DXdT0TAaFg1 ZDzedjNp4v0E3vEVGPIwDJJHPpXe3oWO8Dpy0OkhLoSWqnH1qjjjLpIalXTsjSCNgg2Bx/u4j3e V3n5iscf4mwLzoBCmpkOLDnApQs90cktd/bFpUCHM2EohyKljK1zw6R9+dOVbuj5hGErUuFeW9v FBtsFqYsNHBxDPHXOjg5YhqnzJujNok+plj7TagXD9pVvfcKOmE/oehAf4/y7tzMsEPGi9uO0xS G96YPLgRQk6aUYu/N/CGkc9BkI6P/yBuMa7/VW9aqgxpnhqaj7PYboeqXlERQnyFj/pCGU= X-Received: by 2002:a05:7300:8819:b0:33c:e72:5b3b with SMTP id 5a478bee46e88-3535f3cbcd4mr464739eec.25.1791487109863; Thu, 08 Oct 2026 12:18:29 -0700 (PDT) Received: from localhost.localdomain ([2603:8001:5f01:8bab:bc88:5ec1:4f8a:5b23]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3537c841579sm117933eec.4.2026.10.08.12.18.28 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 08 Oct 2026 12:18:29 -0700 (PDT) From: Artem Dinaburg To: stable@vger.kernel.org Cc: Artem Dinaburg , Greg Kroah-Hartman , Sasha Levin , Marco Scardovi , Bartosz Golaszewski , Linus Walleij , Bartosz Golaszewski , Andy Shevchenko , Heiko Stuebner , linux-gpio@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-rockchip@lists.infradead.org, linux-kernel@vger.kernel.org, Linus Walleij , Bartosz Golaszewski , jay.xu@rock-chips.com Subject: [PATCH 6.6.y 1/2] gpio: rockchip: teardown bugs and resource leaks Date: Thu, 8 Oct 2026 15:18:20 -0400 Message-ID: <20261008191824.98662-2-artem@trailofbits.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20261008191824.98662-1-artem@trailofbits.com> References: <20261008191824.98662-1-artem@trailofbits.com> Precedence: bulk X-Mailing-List: linux-gpio@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Marco Scardovi [ Upstream commit 9500077678230e36d22bf16d2b9539c13e59a801 ] Address several teardown issues and resource leaks in the driver's remove path and error handling: 1. Debounce clock reference leak: The debounce clock (bank->db_clk) is obtained using of_clk_get() which increments the clock's reference count, but clk_put() is never called. Register a devm action to cleanly release it on unbind. Note that of_clk_get(..., 1) remains necessary over devm_clk_get() because the DT binding does not define clock-names, precluding name-based lookup. 2. Unregistered chained IRQ handler: The chained IRQ handler is not disconnected in remove(). If a stray interrupt fires after the driver is removed, the kernel attempts to execute a stale handler, leading to a panic. Fix this by clearing the handler in remove(). 3. IRQ domain leak: The linear IRQ domain and its generic chips are allocated manually during probe but never removed. Remove the IRQ domain during driver teardown to free the associated generic chips and mappings. [ Backport to 6.6.y: For 6.6.y, send with 1c1e0fc88d6e (CVE-2026-53226) so generic chips are explicitly removed before irq_domain_remove(). 6.1.y lacks irq_domain_remove_generic_chips(), so it needs a separately reviewed older generic-chip teardown backport. ] Fixes: 936ee2675eee ("gpio/rockchip: add driver for rockchip gpio") Assisted-by: Antigravity:gemini-3.5-flash Signed-off-by: Marco Scardovi Link: https://patch.msgid.link/20260526171050.12785-3-scardracs@disroot.org [Bartosz: don't emit an error message on devres allocation failure] Signed-off-by: Bartosz Golaszewski Assisted-by: LLM Signed-off-by: Artem Dinaburg --- This is patch 1 of 2 in the ordered 6.6.y backport series. This change addresses CVE-2026-64241. Releases the debounce-clock reference, disconnects the chained IRQ handler, and removes the IRQ domain during driver teardown. The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y. drivers/gpio/gpio-rockchip.c | 17 ++++++++++++++++- 1 file changed, 16 insertions(+), 1 deletion(-) diff --git a/drivers/gpio/gpio-rockchip.c b/drivers/gpio/gpio-rockchip.c index ff9a4b8611d7..e0e4f3ed5fdd 100644 --- a/drivers/gpio/gpio-rockchip.c +++ b/drivers/gpio/gpio-rockchip.c @@ -629,10 +629,17 @@ static int rockchip_gpiolib_register(struct rockchip_pin_bank *bank) return ret; } +static void rockchip_clk_put(void *data) +{ + struct clk *clk = data; + + clk_put(clk); +} + static int rockchip_get_bank_data(struct rockchip_pin_bank *bank) { struct resource res; - int id = 0; + int id = 0, ret; if (of_address_to_resource(bank->of_node, 0, &res)) { dev_err(bank->dev, "cannot find IO resource for bank\n"); @@ -662,6 +669,11 @@ static int rockchip_get_bank_data(struct rockchip_pin_bank *bank) dev_err(bank->dev, "cannot find debounce clk\n"); return -EINVAL; } + + ret = devm_add_action_or_reset(bank->dev, rockchip_clk_put, + bank->db_clk); + if (ret) + return ret; } else { bank->gpio_regs = &gpio_regs_v1; bank->gpio_type = GPIO_TYPE_V1; @@ -773,6 +785,9 @@ static int rockchip_gpio_remove(struct platform_device *pdev) { struct rockchip_pin_bank *bank = platform_get_drvdata(pdev); + irq_set_chained_handler_and_data(bank->irq, NULL, NULL); + if (bank->domain) + irq_domain_remove(bank->domain); gpiochip_remove(&bank->gpio_chip); return 0; -- 2.39.5