Re: [PATCH v3 02/17] arm64: dts: imx91-11x11-evk: Add board muxes to select between PDM and MQS1
flat view
From: sashiko-bot@kernel.org
Date: 2026-08-24 02:35:13
Also in:
imx
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: Pre-existing issues: - [High] This problem wasn't introduced by this patch, but repeated calls to `mux_pinmux_dt_node_to_map` during probe deferral of the consumer cause unbounded memory leaks on the `pinctrl-multiplexer` provider device. --
--- Patch [2]: [PATCH v3 02/17] arm64: dts: imx91-11x11-evk: Add board muxes to select between PDM and MQS1 ---commit defaefa605b7135d708e20b9a9bb866edaa4e6a1 Author: Chancel Liu [off-list ref] arm64: dts: imx91-11x11-evk: Add board muxes to select between PDM and MQS1 This patch adds GPIO-controlled board muxes to route shared signals between PDM and MQS1, resolving a pin conflict. It introduces the pdm_mqs1_mux and pinctrl-gpiomux nodes, and updates the micfil pinctrl.
quoted hunk ↗ jump to hunk
diff --git a/arch/arm64/boot/dts/freescale/imx91-11x11-evk.dts b/arch/arm64/boot/dts/freescale/imx91-11x11-evk.dts index 5716febb5a50f..4d1ada6a3942b 100644 --- a/arch/arm64/boot/dts/freescale/imx91-11x11-evk.dts +++ b/arch/arm64/boot/dts/freescale/imx91-11x11-evk.dts
[ ... ]
quoted hunk ↗ jump to hunk
@@ -484,7 +503,7 @@ bluetooth { &micfil { pinctrl-names = "default", "sleep"; - pinctrl-0 = <&pinctrl_pdm>; + pinctrl-0 = <&pinctrl_pdm>, <&pdm_fun>;
[Severity: High]
This isn't a bug introduced by this patch, but adding this multiplexer to
the consumer could expose a devres leak in the provider if the consumer
defers probe.
When the micfil consumer evaluates its pinctrl-0 properties, it triggers
mux_pinmux_dt_node_to_map() in drivers/pinctrl/pinctrl-generic-mux.c.
This function allocates resources bound to the provider device rather than
the consumer:
drivers/pinctrl/pinctrl-generic-mux.c:mux_pinmux_dt_node_to_map() {
...
function = devm_kzalloc(pctldev->dev, sizeof(*function), GFP_KERNEL);
...
group_names = devm_kcalloc(pctldev->dev, 1, sizeof(*group_names), GFP_KERNEL);
...
function->mux_state = devm_mux_state_get_from_np(pctldev->dev, NULL, np_config);
...
}
Because these devm_* allocations are bound to pctldev->dev (the provider
device), they are not freed if the micfil consumer defers probe.
Could this result in an unbounded memory and mux state leak on the provider
device for every probe retry?
pinctrl-1 = <&pinctrl_pdm_sleep>; assigned-clocks = <&clk IMX93_CLK_PDM>; assigned-clock-parents = <&clk IMX93_CLK_AUDIO_PLL>;
-- Sashiko AI review · https://sashiko.dev/#/patchset/20260824022020.2812810-1-chancel.liu@oss.nxp.com?part=2