From nobody Sat Jul 25 19:30:26 2026 Received: from mail-pj1-f52.google.com (mail-pj1-f52.google.com [209.85.216.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BA263448CE0 for ; Tue, 14 Jul 2026 12:33:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784032389; cv=none; b=P6+D5e1dJibtbIvtLlHW8hQgxiV+k15uTLsC7CjlK5J/Y6FD/jdOVw2POVPVucRrurdFSYE0brEcyJSMd3s2mM4UqSEzK86MQi8DgBOlCtq5tzFqoAif7oar4RwX/Z3fbY2keUAY/3yfQVco6MJWqDLMGfjhOrwfXBnOga2QdnI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784032389; c=relaxed/simple; bh=ss4IguDN43TRaOXbeKLoj2YQBQybV50DyiSA6DlyZSY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=mBa26gk2oRSVLmFNNuVKUGtcQagDtWepS7rckAsfS35cKzOUP1sPLrTCzCnNhF8Ex9X+3Eb2DaFBMwqZyV9AEJoebRRP6Lh1JG9/3F32kPo0H/DqfF5lE32LBpNT3dgb7ehauDsHHVBqqxMN4OLShv6owYOofKdXPjIpVk7SpM4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=QIhwmKsI; arc=none smtp.client-ip=209.85.216.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="QIhwmKsI" Received: by mail-pj1-f52.google.com with SMTP id 98e67ed59e1d1-38d489b6b71so4016106a91.0 for ; Tue, 14 Jul 2026 05:33:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784032381; x=1784637181; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=DNvAJagM0h/ttBqvPmQVo9CO+v+pNiBOB9YPIRh2j6k=; b=QIhwmKsIX187O+Ym4dihNE0fO7P6y4qPVVDV0umfmG0qvjszAAfw85MsuG1tX++G1/ eYcEXkt8XCvJXvmGnzUu1H4txdKulCdf3UctiOKZv0qnKLrI3sKxZaxT5NmFhNF/HPfS sonaqbulKxPnhMB35qAMgxoF1VOj0ry/Wz6kcQBsSs9pmZxxaPfV9nKPr6qiOoS+xtwi UNH9stGDDNEQrq9rlWAdKkLhQEQUfrqMV+BKVT4woNNuBd6wFQb9LvoF3pAIO4SWL091 MpA2UApxnuZSTcjN8n6n4PjHmKNa0fX33BotWflWfvzuiveHzCpEyuImdKYXheJnaSVW 0vHA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784032381; x=1784637181; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DNvAJagM0h/ttBqvPmQVo9CO+v+pNiBOB9YPIRh2j6k=; b=isVr8MMK6jTctMTLj32p/9B5yMKpH5dlLeXNsyQHjJEEkK87f/AlC+FgSAE/7huWqK iaOC+WqexNyGWX9Pm9S0NDjymHx4NTBQ0GV9rq0PsiHuUuavCrM54ETnHJLMnbADL2Kj fCJqslyJqyAc8D5iNKO2pacc8y+EIf9hvdBGka2Am7NcKWIQWOlSIQjwhDuZWYym03ua blJ3UhqJGn/RLwnFIXFu2XmqThHYp4e3iZiD4m/LE0DMB0vzHahVdB2lFDwvNIiQDs0G tAMM3+JT/0wEzC4A1DcMEMaKUWCLJx/Ig+kGdzS7n9x3GzSBhSKF6fDt9PLEpWTAyfU1 e0Iw== X-Forwarded-Encrypted: i=1; AHgh+RraD3XkiEBVF1nZZ/01ZnSqEpHpv8XAW1L4/G6Ck9C5ZiKM4Y4EZwGX2Ak4sx6LkF8paniVGWPoZrmxWck=@vger.kernel.org X-Gm-Message-State: AOJu0YwhfLTKDIqaPBg70yCoLwPg72l/ezm4jLHTSi034xtK2Ys4RBJR DPGDEyCctFJYeREqKTZCcFtovNPH8zKjmCM/S2rCExytpWYSBo4vUK2M X-Gm-Gg: AfdE7clzxZRnQXCdfnXcPMoSjUMaakZQtYEtNvMm9/HPeetsQHptR0JSRIAvBD4iOWB fTMckr5wjevXEsx7gOUcBosbpP5pqYxOXmWtJQKkfEVcMx/JvF6gYRouTqXZLohPGoo6BFC1iVb EWhFkF2YhZrraYVqCGsiucH+uS76N4aIfWHNMDujSTI+W3jzQI/p/Xd8w5uMgPOYPuZqPdU9gpZ 0eyiHRR8j2wi5Eaxr2nFEHh6/3XeM8SnwxbsJjXjOUMe1K1MqiVl0Q7BvLaDS3fhaBNxxaeEmoo S/Ij6zB0q9I5fVMHFBa2mIAz+BKcIp4ZoN+/TILXcX6d19dwk0Rfq6NZrFpsuI1iKZcF14sgJCl kWQsCdV+vn07oZu36dWkw78jhGmWT746cIonKnSsBKJT7cgbUfEXEg6pOsD9hc6gDPnEH7bg= X-Received: by 2002:a17:90b:53c6:b0:38d:dfd1:7c1 with SMTP id 98e67ed59e1d1-38e17d96421mr2942124a91.2.1784032381474; Tue, 14 Jul 2026 05:33:01 -0700 (PDT) Received: from lgs.. ([2001:250:5800:1000::f280]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38e172b6d08sm1443513a91.2.2026.07.14.05.32.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 14 Jul 2026 05:33:01 -0700 (PDT) From: Guangshuo Li To: Eddie James , Ninad Palsule , Joel Stanley , Andrew Jeffery , Greg Kroah-Hartman , Alistair Popple , linux-fsi@lists.ozlabs.org, linux-arm-kernel@lists.infradead.org, linux-aspeed@lists.ozlabs.org, linux-kernel@vger.kernel.org Cc: Guangshuo Li Subject: [PATCH] fsi: aspeed: Fix refcount leak on registration failure Date: Tue, 14 Jul 2026 20:30:38 +0800 Message-ID: <20260714123038.1523162-1-lgs201920130244@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" fsi_master_aspeed_probe() allocates aspeed and passes its embedded master device to fsi_master_register(). After the master index is allocated, fsi_master_register() calls device_register(), which initializes master.dev and takes its initial reference. If device registration fails, the reference remains held when fsi_master_register() returns an error. The probe error path then calls kfree(aspeed) directly without dropping the device reference. This leaves the initialized master.dev reference stranded and bypasses aspeed_master_release(). Disable the clock and call put_device() when registration fails after the master index has been allocated. Keep the direct kfree() path for failures that occur before master.dev is initialized. This issue was found by a static analysis tool I am developing. Fixes: 606397d67f41 ("fsi: Add ast2600 master driver") Signed-off-by: Guangshuo Li --- drivers/fsi/fsi-master-aspeed.c | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/drivers/fsi/fsi-master-aspeed.c b/drivers/fsi/fsi-master-aspee= d.c index aa1380cdff33..2a54b6fa3394 100644 --- a/drivers/fsi/fsi-master-aspeed.c +++ b/drivers/fsi/fsi-master-aspeed.c @@ -626,8 +626,12 @@ static int fsi_master_aspeed_probe(struct platform_dev= ice *pdev) aspeed_master_init(aspeed); =20 rc =3D fsi_master_register(&aspeed->master); - if (rc) - goto err_release; + if (rc) { + if (aspeed->master.idx < 0) + goto err_release; + + goto err_put_master; + } =20 /* At this point, fsi_master_register performs the device_initialize(), * and holds the sole reference on master.dev. This means the device @@ -638,6 +642,10 @@ static int fsi_master_aspeed_probe(struct platform_dev= ice *pdev) */ get_device(&aspeed->master.dev); return 0; +err_put_master: + clk_disable_unprepare(aspeed->clk); + put_device(&aspeed->master.dev); + return rc; =20 err_release: clk_disable_unprepare(aspeed->clk); --=20 2.43.0