On 2026/09/24 12:00 PM, Jyoti Gupta wrote:
> mpic_alloc() allocates struct mpic (and optionally the protected
> sources bitmap) but does not free them when mpic_setup_error_int() or
> irq_domain_create_linear() fails, leaking the memory.
>
> Initialise mpic to NULL and free the bitmap and the mpic in the common
> error path before dropping the device node reference. The register
> mappings are not released here.
>
> Signed-off-by: Jyoti Gupta <[email protected]>
I see a couple of problems with this patch:
1. The patch does not apply. Both "git apply" and "git am" fail on this patch.
I think the context lines around the irq_domain_create_linear() call have
tabs converted to spaces, which causes the context match to fail.
❯ git apply
./20260924_jyoti_powerpc_mpic_fix_memory_leak_of_mpic_on_error_paths.mbx
--check --verbose
Checking patch arch/powerpc/sysdev/mpic.c...
error: while searching for:
intvec_top,
&mpic_host_ops, mpic);
/*
* FIXME: The code leaks the MPIC object and mappings here; this
* is very unlikely to fail but it ought to be fixed anyways.
*/
if (mpic->irqhost == NULL)
goto err_of_node_put;
error: patch failed: arch/powerpc/sysdev/mpic.c:1488
error: arch/powerpc/sysdev/mpic.c: patch does not apply
Please regenerate with:
git format-patch -1
and verify with:
git apply --check <patch>
before resending.
2. The mpic_setup_error_int() leak is not actually fixed. The commit message
says both mpic_setup_error_int() and irq_domain_create_linear() failure paths
are fixed, but the former still does a bare return NULL:
if (fsl_version >= 0x401) {
ret = mpic_setup_error_int(mpic, intvec_top - 13);
if (ret)
return NULL; /* <-- still leaks mpic and mpic->protected */
}
This needs to become:
if (ret)
goto err_of_node_put;
Thanks,
Amit
> ---
> arch/powerpc/sysdev/mpic.c | 9 ++++-----
> 1 file changed, 4 insertions(+), 5 deletions(-)
>
> diff --git a/arch/powerpc/sysdev/mpic.c b/arch/powerpc/sysdev/mpic.c
> index 6e8fa94985f3..e777b33f170d 100644
> --- a/arch/powerpc/sysdev/mpic.c
> +++ b/arch/powerpc/sysdev/mpic.c
> @@ -1221,7 +1221,7 @@ struct mpic * __init mpic_alloc(struct device_node
> *node,
> const char *name)
> {
> int i, psize, intvec_top;
> - struct mpic *mpic;
> + struct mpic *mpic = NULL;
> u32 greg_feature;
> const char *vers;
> const u32 *psrc;
> @@ -1488,10 +1488,6 @@ struct mpic * __init mpic_alloc(struct device_node
> *node,
> intvec_top,
> &mpic_host_ops, mpic);
>
> - /*
> - * FIXME: The code leaks the MPIC object and mappings here; this
> - * is very unlikely to fail but it ought to be fixed anyways.
> - */
> if (mpic->irqhost == NULL)
> goto err_of_node_put;
>
> @@ -1527,6 +1523,9 @@ struct mpic * __init mpic_alloc(struct device_node
> *node,
> return mpic;
>
> err_of_node_put:
> + if (mpic)
> + bitmap_free(mpic->protected);
> + kfree(mpic);
> of_node_put(node);
> return NULL;
> }
> --
> 2.55.0
>
>