* [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure
@ 2026-09-14 13:29 Cong Nguyen
2026-09-14 13:54 ` sashiko-bot
2026-09-16 7:49 ` [Linux-stm32] " Antonio Borneo
0 siblings, 2 replies; 3+ messages in thread
From: Cong Nguyen @ 2026-09-14 13:29 UTC (permalink / raw)
To: Alexandre Belloni
Cc: Maxime Coquelin, Alexandre Torgue, Linus Walleij, Valentin Caron,
linux-rtc, linux-stm32, linux-arm-kernel, linux-kernel
stm32_rtc_probe() enables rtc_ck/pclk early and unwinds them through
the err: label on every later failure -- except a failing
devm_pinctrl_register_and_init() or pinctrl_enable(), which both
return directly, leaking both clocks. -EPROBE_DEFER is a routine
outcome from pinctrl lookups during boot, so each deferred retry
leaks another reference.
Route both through the existing err: label, matching every other
post-enable failure path in this function.
Fixes: 16ad2bc09efb ("rtc: stm32: add pinctrl and pinmux interfaces")
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
---
drivers/rtc/rtc-stm32.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/rtc/rtc-stm32.c b/drivers/rtc/rtc-stm32.c
index d4ebf3eb54aa..e7a942f6c190 100644
--- a/drivers/rtc/rtc-stm32.c
+++ b/drivers/rtc/rtc-stm32.c
@@ -1175,12 +1175,16 @@ static int stm32_rtc_probe(struct platform_device *pdev)
stm32_rtc_clean_outs(rtc);
ret = devm_pinctrl_register_and_init(&pdev->dev, &stm32_rtc_pdesc, rtc, &pctl);
- if (ret)
- return dev_err_probe(&pdev->dev, ret, "pinctrl register failed");
+ if (ret) {
+ dev_err_probe(&pdev->dev, ret, "pinctrl register failed");
+ goto err;
+ }
ret = pinctrl_enable(pctl);
- if (ret)
- return dev_err_probe(&pdev->dev, ret, "pinctrl enable failed");
+ if (ret) {
+ dev_err_probe(&pdev->dev, ret, "pinctrl enable failed");
+ goto err;
+ }
/*
* If INITS flag is reset (calendar year field set to 0x00), calendar
--
2.25.1
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure
2026-09-14 13:29 [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure Cong Nguyen
@ 2026-09-14 13:54 ` sashiko-bot
2026-09-16 7:49 ` [Linux-stm32] " Antonio Borneo
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-14 13:54 UTC (permalink / raw)
To: Cong Nguyen; +Cc: linux-rtc, Alexandre Belloni
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Routing pinctrl failures to the manual clock cleanup path creates a critical window where devm-managed resources (IRQ, RTC device) remain active while hardware clocks are disabled, risking a synchronous external abort (bus fault).
--
commit 813d70ca28c122c9814bc7903a9c96494f127aea
Author: Cong Nguyen <congnt264@gmail.com>
rtc: stm32: fix clock leak on pinctrl probe failure
This commit addresses a clock leak during pinctrl probe failure. It updates
the error handling paths for devm_pinctrl_register_and_init() and
pinctrl_enable() to route through the existing err label, ensuring rtc_ck
and pclk are unwound properly.
> diff --git a/drivers/rtc/rtc-stm32.c b/drivers/rtc/rtc-stm32.c
> index d4ebf3eb54aa9..e7a942f6c1906 100644
> --- a/drivers/rtc/rtc-stm32.c
> +++ b/drivers/rtc/rtc-stm32.c
[ ... ]
> @@ -1175,12 +1175,16 @@ static int stm32_rtc_probe(struct platform_device *pdev)
> stm32_rtc_clean_outs(rtc);
>
> ret = devm_pinctrl_register_and_init(&pdev->dev, &stm32_rtc_pdesc, rtc, &pctl);
> - if (ret)
> - return dev_err_probe(&pdev->dev, ret, "pinctrl register failed");
> + if (ret) {
> + dev_err_probe(&pdev->dev, ret, "pinctrl register failed");
> + goto err;
[Severity: High]
Does this new error path create a window for a synchronous external abort?
When pinctrl initialization fails (for example, returning -EPROBE_DEFER),
this now jumps to the err label where rtc_ck and pclk are manually disabled.
However, the RTC device and the alarm IRQ were registered earlier in the
probe function using devres-managed functions:
stm32_rtc_probe()
rtc->rtc_dev = devm_rtc_device_register(...);
ret = devm_request_threaded_irq(..., stm32_rtc_alarm_irq, ...);
Because devres resources are not released until after the probe function
returns, there is a window where the clocks are disabled but the IRQ handler
and RTC device remain active.
Could the still-registered IRQ fire during this cleanup window? If that
happens, or if userspace accesses the RTC device, driver callbacks like
stm32_rtc_alarm_irq() might attempt to access hardware registers without
the APB clock enabled, resulting in a bus fault.
> + }
>
> ret = pinctrl_enable(pctl);
> - if (ret)
> - return dev_err_probe(&pdev->dev, ret, "pinctrl enable failed");
> + if (ret) {
> + dev_err_probe(&pdev->dev, ret, "pinctrl enable failed");
> + goto err;
> + }
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260914132914.2371788-1-congnt264@gmail.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [Linux-stm32] [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure
2026-09-14 13:29 [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure Cong Nguyen
2026-09-14 13:54 ` sashiko-bot
@ 2026-09-16 7:49 ` Antonio Borneo
1 sibling, 0 replies; 3+ messages in thread
From: Antonio Borneo @ 2026-09-16 7:49 UTC (permalink / raw)
To: Cong Nguyen, Alexandre Belloni
Cc: linux-rtc, Linus Walleij, linux-kernel, Maxime Coquelin,
linux-stm32, linux-arm-kernel
On Mon, 2026-09-14 at 20:29 +0700, Cong Nguyen wrote:
> stm32_rtc_probe() enables rtc_ck/pclk early and unwinds them through
> the err: label on every later failure -- except a failing
> devm_pinctrl_register_and_init() or pinctrl_enable(), which both
> return directly, leaking both clocks. -EPROBE_DEFER is a routine
> outcome from pinctrl lookups during boot, so each deferred retry
> leaks another reference.
>
> Route both through the existing err: label, matching every other
> post-enable failure path in this function.
>
> Fixes: 16ad2bc09efb ("rtc: stm32: add pinctrl and pinmux interfaces")
> Assisted-by: Claude:claude-opus-4
Shouldn't it be
Assisted-by: LLM
accordingly to commit 816d9992d9ed in latest
Documentation/process/coding-assistants.rst ?
> Signed-off-by: Cong Nguyen <congnt264@gmail.com>
> ---
Apart from the comment above,
Reviewed-by: Antonio Borneo <antonio.borneo@foss.st.com>
Thanks!
Antonio
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-16 7:50 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-14 13:29 [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure Cong Nguyen
2026-09-14 13:54 ` sashiko-bot
2026-09-16 7:49 ` [Linux-stm32] " Antonio Borneo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox