Thread (4 messages) 4 messages, 3 authors, 2026-08-26

Re: [PATCH] of/irq: Fix device node refcount leak in of_irq_get_affinity()

From: sashiko-bot@kernel.org
Date: 2026-08-26 11:36:04

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

Pre-existing issues:
- [High] Device node reference count leak when resolving MSI domain RID via 'msi-parent' fallback.
- [High] Pre-existing memory leak of device node reference in `gic_irq_get_fwspec_info`.
--

commit 105954fbf27e6537ca0c4da266eb89a3c31643fd
Author: Fuad Tabba [off-list ref]

of/irq: Fix device node refcount leak in of_irq_get_affinity()

This commit fixes a device node reference count leak in of_irq_get_affinity().
The of_irq_parse_one() call raises the refcount of the interrupt controller
node on success, and of_irq_get_affinity() returns without putting it. The
fix drops the reference once irq_populate_fwspec_info() has run.
quoted hunk ↗ jump to hunk
diff --git a/drivers/of/irq.c b/drivers/of/irq.c
index 967c191008797..ec035367c9500 100644
--- a/drivers/of/irq.c
+++ b/drivers/of/irq.c
@@ -563,7 +563,9 @@ const struct cpumask *of_irq_get_affinity(struct device_node *dev, int index)
 	of_phandle_args_to_fwspec(oirq.np, oirq.args, oirq.args_count,
 				  &fwspec);
 
-	if (irq_populate_fwspec_info(&fwspec, &info))
+	rc = irq_populate_fwspec_info(&fwspec, &info);
+	of_node_put(oirq.np);
+	if (rc)
 		return NULL;
 
 	return info.affinity;
[Severity: High]
This isn't a bug introduced by this patch, but there appears to be a
device node reference count leak when resolving MSI domain RID via
msi-parent fallback.

drivers/pci/msi/irqdomain.c:pci_msi_domain_get_msi_rid()
	of_node = irq_domain_get_of_node(domain);
	rid = of_node ? of_msi_xlate(&pdev->dev, &of_node, rid) :
			iort_msi_map_id(&pdev->dev, rid);

	return rid;
If the mapping falls back to msi-parent in of_msi_xlate(), the
un-refcounted of_node pointer is overwritten with a newly refcounted
pointer in of_check_msi_parent():

drivers/of/irq.c:of_check_msi_parent()
	if (!ret) {
		/* Return with a node reference held */
		*msi_node = msi_spec.np;
		return 0;
	}
Since pci_msi_domain_get_msi_rid() returns the mapped RID without calling
of_node_put() on the updated of_node, does this leak the MSI controller
device node on every invocation?

[Severity: High]
This is a pre-existing issue, but is there also a memory leak of the
device node reference in gic_irq_get_fwspec_info()?

drivers/irqchip/irq-gic-v3.c:gic_irq_get_fwspec_info()
		fw = of_fwnode_handle(of_find_node_by_phandle(fwspec->param[3]));
		if (!fw)
			return -ENOENT;

		for (int i = 0; i < gic_data.nr_parts; i++) {
			if (gic_data.parts[i].partition_id == fw) {
				mask = &gic_data.parts[i].mask;
				break;
			}
		}

		if (!mask)
			return -ENOENT;
	} else {
		mask = cpu_possible_mask;
	}

	info->affinity = mask;
	info->flags = IRQ_FWSPEC_INFO_AFFINITY_VALID;

	return 0;
The call to of_find_node_by_phandle() acquires a new reference on the
device node, but the function returns on various error and success paths
without calling of_node_put() to drop it. Does this leak the GIC PPI
partition device nodes during IRQ affinity retrieval?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260826112234.1033974-1-fuad.tabba@linux.dev?part=1
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help