Linux RTC
 help / color / mirror / Atom feed
* [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure
@ 2026-09-14 13:29 Cong Nguyen
  2026-09-14 13:54 ` sashiko-bot
  2026-09-16  7:49 ` [Linux-stm32] " Antonio Borneo
  0 siblings, 2 replies; 3+ messages in thread
From: Cong Nguyen @ 2026-09-14 13:29 UTC (permalink / raw)
  To: Alexandre Belloni
  Cc: Maxime Coquelin, Alexandre Torgue, Linus Walleij, Valentin Caron,
	linux-rtc, linux-stm32, linux-arm-kernel, linux-kernel

stm32_rtc_probe() enables rtc_ck/pclk early and unwinds them through
the err: label on every later failure -- except a failing
devm_pinctrl_register_and_init() or pinctrl_enable(), which both
return directly, leaking both clocks. -EPROBE_DEFER is a routine
outcome from pinctrl lookups during boot, so each deferred retry
leaks another reference.

Route both through the existing err: label, matching every other
post-enable failure path in this function.

Fixes: 16ad2bc09efb ("rtc: stm32: add pinctrl and pinmux interfaces")
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
---
 drivers/rtc/rtc-stm32.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/drivers/rtc/rtc-stm32.c b/drivers/rtc/rtc-stm32.c
index d4ebf3eb54aa..e7a942f6c190 100644
--- a/drivers/rtc/rtc-stm32.c
+++ b/drivers/rtc/rtc-stm32.c
@@ -1175,12 +1175,16 @@ static int stm32_rtc_probe(struct platform_device *pdev)
 	stm32_rtc_clean_outs(rtc);
 
 	ret = devm_pinctrl_register_and_init(&pdev->dev, &stm32_rtc_pdesc, rtc, &pctl);
-	if (ret)
-		return dev_err_probe(&pdev->dev, ret, "pinctrl register failed");
+	if (ret) {
+		dev_err_probe(&pdev->dev, ret, "pinctrl register failed");
+		goto err;
+	}
 
 	ret = pinctrl_enable(pctl);
-	if (ret)
-		return dev_err_probe(&pdev->dev, ret, "pinctrl enable failed");
+	if (ret) {
+		dev_err_probe(&pdev->dev, ret, "pinctrl enable failed");
+		goto err;
+	}
 
 	/*
 	 * If INITS flag is reset (calendar year field set to 0x00), calendar
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure
  2026-09-14 13:29 [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure Cong Nguyen
@ 2026-09-14 13:54 ` sashiko-bot
  2026-09-16  7:49 ` [Linux-stm32] " Antonio Borneo
  1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-14 13:54 UTC (permalink / raw)
  To: Cong Nguyen; +Cc: linux-rtc, Alexandre Belloni

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Routing pinctrl failures to the manual clock cleanup path creates a critical window where devm-managed resources (IRQ, RTC device) remain active while hardware clocks are disabled, risking a synchronous external abort (bus fault).
--

commit 813d70ca28c122c9814bc7903a9c96494f127aea
Author: Cong Nguyen <congnt264@gmail.com>

rtc: stm32: fix clock leak on pinctrl probe failure

This commit addresses a clock leak during pinctrl probe failure. It updates
the error handling paths for devm_pinctrl_register_and_init() and
pinctrl_enable() to route through the existing err label, ensuring rtc_ck
and pclk are unwound properly.

> diff --git a/drivers/rtc/rtc-stm32.c b/drivers/rtc/rtc-stm32.c
> index d4ebf3eb54aa9..e7a942f6c1906 100644
> --- a/drivers/rtc/rtc-stm32.c
> +++ b/drivers/rtc/rtc-stm32.c

[ ... ]

> @@ -1175,12 +1175,16 @@ static int stm32_rtc_probe(struct platform_device *pdev)
>  	stm32_rtc_clean_outs(rtc);
>  
>  	ret = devm_pinctrl_register_and_init(&pdev->dev, &stm32_rtc_pdesc, rtc, &pctl);
> -	if (ret)
> -		return dev_err_probe(&pdev->dev, ret, "pinctrl register failed");
> +	if (ret) {
> +		dev_err_probe(&pdev->dev, ret, "pinctrl register failed");
> +		goto err;

[Severity: High]
Does this new error path create a window for a synchronous external abort?

When pinctrl initialization fails (for example, returning -EPROBE_DEFER),
this now jumps to the err label where rtc_ck and pclk are manually disabled.

However, the RTC device and the alarm IRQ were registered earlier in the
probe function using devres-managed functions:

stm32_rtc_probe()
    rtc->rtc_dev = devm_rtc_device_register(...);
    ret = devm_request_threaded_irq(..., stm32_rtc_alarm_irq, ...);

Because devres resources are not released until after the probe function
returns, there is a window where the clocks are disabled but the IRQ handler
and RTC device remain active.

Could the still-registered IRQ fire during this cleanup window? If that
happens, or if userspace accesses the RTC device, driver callbacks like
stm32_rtc_alarm_irq() might attempt to access hardware registers without
the APB clock enabled, resulting in a bus fault.

> +	}
>  
>  	ret = pinctrl_enable(pctl);
> -	if (ret)
> -		return dev_err_probe(&pdev->dev, ret, "pinctrl enable failed");
> +	if (ret) {
> +		dev_err_probe(&pdev->dev, ret, "pinctrl enable failed");
> +		goto err;
> +	}

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260914132914.2371788-1-congnt264@gmail.com?part=1

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [Linux-stm32] [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure
  2026-09-14 13:29 [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure Cong Nguyen
  2026-09-14 13:54 ` sashiko-bot
@ 2026-09-16  7:49 ` Antonio Borneo
  1 sibling, 0 replies; 3+ messages in thread
From: Antonio Borneo @ 2026-09-16  7:49 UTC (permalink / raw)
  To: Cong Nguyen, Alexandre Belloni
  Cc: linux-rtc, Linus Walleij, linux-kernel, Maxime Coquelin,
	linux-stm32, linux-arm-kernel

On Mon, 2026-09-14 at 20:29 +0700, Cong Nguyen wrote:
> stm32_rtc_probe() enables rtc_ck/pclk early and unwinds them through
> the err: label on every later failure -- except a failing
> devm_pinctrl_register_and_init() or pinctrl_enable(), which both
> return directly, leaking both clocks. -EPROBE_DEFER is a routine
> outcome from pinctrl lookups during boot, so each deferred retry
> leaks another reference.
> 
> Route both through the existing err: label, matching every other
> post-enable failure path in this function.
> 
> Fixes: 16ad2bc09efb ("rtc: stm32: add pinctrl and pinmux interfaces")
> Assisted-by: Claude:claude-opus-4

Shouldn't it be
Assisted-by: LLM
accordingly to commit 816d9992d9ed in latest
Documentation/process/coding-assistants.rst ?

> Signed-off-by: Cong Nguyen <congnt264@gmail.com>
> ---

Apart from the comment above,

Reviewed-by: Antonio Borneo <antonio.borneo@foss.st.com>

Thanks!
Antonio

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-16  7:50 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-14 13:29 [PATCH] rtc: stm32: fix clock leak on pinctrl probe failure Cong Nguyen
2026-09-14 13:54 ` sashiko-bot
2026-09-16  7:49 ` [Linux-stm32] " Antonio Borneo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox