From: sashiko-bot@kernel.org
To: "Cong Nguyen" <congnt264@gmail.com>
Cc: "Alexandre Belloni" <alexandre.belloni@bootlin.com>,
linux-rtc@vger.kernel.org
Subject: Re: [PATCH] rtc: pxa: fix IRQ leak on probe failure after pxa_rtc_open()
Date: Mon, 14 Sep 2026 12:54:43 +0000 [thread overview]
Message-ID: <20260914125443.73F981F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260914124037.2204337-1-congnt264@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] The driver incorrectly registers two separate RTC class devices for the same hardware, leading to uncoordinated concurrent access and register corruption.
--
commit 0b0a0ee3975e585ff222c5362ed76732cdee7bd2
Author: Cong Nguyen <congnt264@gmail.com>
rtc: pxa: fix IRQ leak on probe failure after pxa_rtc_open()
This commit addresses an IRQ leak in pxa_rtc_probe() where the 1Hz and alarm
IRQs requested by pxa_rtc_open() are not released if sa1100_rtc_init() or
devm_rtc_device_register() fail later in the probe sequence. It routes
failures through a new err_release label to properly call pxa_rtc_release().
> diff --git a/drivers/rtc/rtc-pxa.c b/drivers/rtc/rtc-pxa.c
> index 62ee6b8f9bcd6..e01e683c2f615 100644
> --- a/drivers/rtc/rtc-pxa.c
> +++ b/drivers/rtc/rtc-pxa.c
[ ... ]
> @@ -347,7 +349,7 @@ static int __init pxa_rtc_probe(struct platform_device *pdev)
> ret = sa1100_rtc_init(pdev, sa1100_rtc);
> if (ret) {
> dev_err(dev, "Unable to init SA1100 RTC sub-device\n");
> - return ret;
> + goto err_release;
> }
>
> rtsr_clear_bits(pxa_rtc, RTSR_PIALE | RTSR_RDALE1 | RTSR_HZE);
> @@ -357,12 +359,16 @@ static int __init pxa_rtc_probe(struct platform_device *pdev)
> if (IS_ERR(pxa_rtc->rtc)) {
[Severity: High]
This is a pre-existing issue, but does this lead to uncoordinated concurrent
access and register corruption?
Looking at drivers/rtc/rtc-pxa.c:pxa_rtc_probe(), the code first delegates
to sa1100_rtc_init(), which registers a primary RTC class device and
initializes its own spinlock (info->lock).
Then pxa_rtc_probe() registers a second concurrent RTC class device
(pxa_rtc->rtc) with a completely independent spinlock (pxa_rtc->lock) for
the exact same hardware registers.
Concurrent userspace interactions (via ioctls on /dev/rtc0 and /dev/rtc1)
will race during read-modify-write operations on the hardware. Could this
cause data corruption of shared RTC hardware registers (like RTSR),
inconsistent state, and incorrect interrupt routing since events only
update one of the devices?
> ret = PTR_ERR(pxa_rtc->rtc);
> dev_err(dev, "Failed to register RTC device -> %d\n", ret);
> - return ret;
> + goto err_release;
> }
>
> device_init_wakeup(dev, true);
>
> return 0;
> +
> +err_release:
> + pxa_rtc_release(dev);
> + return ret;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260914124037.2204337-1-congnt264@gmail.com?part=1
prev parent reply other threads:[~2026-09-14 12:54 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 12:40 [PATCH] rtc: pxa: fix IRQ leak on probe failure after pxa_rtc_open() Cong Nguyen
2026-09-14 12:54 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260914125443.73F981F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=alexandre.belloni@bootlin.com \
--cc=congnt264@gmail.com \
--cc=linux-rtc@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox