Re: [PATCH] of/irq: Fix device node refcount leak in of_irq_get_affinity()
From: sashiko-bot@kernel.org
Date: 2026-08-26 11:36:04
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider: Pre-existing issues: - [High] Device node reference count leak when resolving MSI domain RID via 'msi-parent' fallback. - [High] Pre-existing memory leak of device node reference in `gic_irq_get_fwspec_info`. -- commit 105954fbf27e6537ca0c4da266eb89a3c31643fd Author: Fuad Tabba [off-list ref] of/irq: Fix device node refcount leak in of_irq_get_affinity() This commit fixes a device node reference count leak in of_irq_get_affinity(). The of_irq_parse_one() call raises the refcount of the interrupt controller node on success, and of_irq_get_affinity() returns without putting it. The fix drops the reference once irq_populate_fwspec_info() has run.
quoted hunk ↗ jump to hunk
diff --git a/drivers/of/irq.c b/drivers/of/irq.c index 967c191008797..ec035367c9500 100644 --- a/drivers/of/irq.c +++ b/drivers/of/irq.c@@ -563,7 +563,9 @@ const struct cpumask *of_irq_get_affinity(struct device_node *dev, int index) of_phandle_args_to_fwspec(oirq.np, oirq.args, oirq.args_count, &fwspec); - if (irq_populate_fwspec_info(&fwspec, &info)) + rc = irq_populate_fwspec_info(&fwspec, &info); + of_node_put(oirq.np); + if (rc) return NULL; return info.affinity;
[Severity: High] This isn't a bug introduced by this patch, but there appears to be a device node reference count leak when resolving MSI domain RID via msi-parent fallback. drivers/pci/msi/irqdomain.c:pci_msi_domain_get_msi_rid()
of_node = irq_domain_get_of_node(domain); rid = of_node ? of_msi_xlate(&pdev->dev, &of_node, rid) : iort_msi_map_id(&pdev->dev, rid); return rid;
If the mapping falls back to msi-parent in of_msi_xlate(), the un-refcounted of_node pointer is overwritten with a newly refcounted pointer in of_check_msi_parent(): drivers/of/irq.c:of_check_msi_parent()
if (!ret) {
/* Return with a node reference held */
*msi_node = msi_spec.np;
return 0;
}Since pci_msi_domain_get_msi_rid() returns the mapped RID without calling of_node_put() on the updated of_node, does this leak the MSI controller device node on every invocation? [Severity: High] This is a pre-existing issue, but is there also a memory leak of the device node reference in gic_irq_get_fwspec_info()? drivers/irqchip/irq-gic-v3.c:gic_irq_get_fwspec_info()
fw = of_fwnode_handle(of_find_node_by_phandle(fwspec->param[3]));
if (!fw)
return -ENOENT;
for (int i = 0; i < gic_data.nr_parts; i++) {
if (gic_data.parts[i].partition_id == fw) {
mask = &gic_data.parts[i].mask;
break;
}
}
if (!mask)
return -ENOENT;
} else {
mask = cpu_possible_mask;
}
info->affinity = mask;
info->flags = IRQ_FWSPEC_INFO_AFFINITY_VALID;
return 0;The call to of_find_node_by_phandle() acquires a new reference on the device node, but the function returns on various error and success paths without calling of_node_put() to drop it. Does this leak the GIC PPI partition device nodes during IRQ affinity retrieval? -- Sashiko AI review · https://sashiko.dev/#/patchset/20260826112234.1033974-1-fuad.tabba@linux.dev?part=1