Re: [PATCH] PCI: rcar-gen4: Fix device_node leak in rcar_gen4_pcie_host_msi_addr()

From: Marek Vasut

Date: Mon Sep 21 2026 - 16:51:33 EST


On 9/18/26 11:10 AM, Fuad Tabba wrote:
rcar_gen4_pcie_host_msi_addr() calls of_msi_xlate() with *msi_np NULL,
so it receives the MSI controller node with a reference held, and every
return past the NULL check leaks that reference, the success path
included. Declare msi_node with __free(device_node) so it's put on
every return.

Fixes: 8d6af27c0a73 ("PCI: rcar-gen4: Configure AXIINTC if iMSI-RX is not used")
Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
Closes: https://lore.kernel.org/linux-pci/20260905213855.8D6671F00A3D@xxxxxxxxxxxxxxx/
Signed-off-by: Fuad Tabba <fuad.tabba@xxxxxxxxx>
---
drivers/pci/controller/dwc/pcie-rcar-gen4.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/pci/controller/dwc/pcie-rcar-gen4.c b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
index fbe465a29068f..d61ce802b4614 100644
--- a/drivers/pci/controller/dwc/pcie-rcar-gen4.c
+++ b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
@@ -323,7 +323,7 @@ static struct rcar_gen4_pcie *rcar_gen4_pcie_alloc(struct platform_device *pdev)
static int rcar_gen4_pcie_host_msi_addr(struct dw_pcie_rp *pp, u32 *msi_addr)
{
struct dw_pcie *dw = to_dw_pcie_from_pp(pp);
- struct device_node *msi_node = NULL;
+ struct device_node *msi_node __free(device_node) = NULL;
I think you have to call of_node_put() on msi_node(), so what about this instead ?

"
diff --git a/drivers/pci/controller/dwc/pcie-rcar-gen4.c b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
index 8057c31c0123a..2eb20cff2fcad 100644
--- a/drivers/pci/controller/dwc/pcie-rcar-gen4.c
+++ b/drivers/pci/controller/dwc/pcie-rcar-gen4.c
@@ -382,20 +382,29 @@ static int rcar_gen4_pcie_host_msi_addr(struct dw_pcie_rp *pp, u32 *msi_addr)
return -ENODEV;

/* Check if "msi-parent" or the "msi-map" points to ARM GICv3 ITS. */
- if (!of_device_is_compatible(msi_node, "arm,gic-v3-its"))
- return dev_err_probe(dev, -ENODEV, "Compatible MSI controller not found\n");
+ if (!of_device_is_compatible(msi_node, "arm,gic-v3-its")) {
+ ret = dev_err_probe(dev, -ENODEV, "Compatible MSI controller not found\n");
+ goto exit;
+ }

/* Derive GITS_TRANSLATER address from GICv3 */
ret = of_address_to_resource(msi_node, 0, &res);
- if (ret < 0)
- return dev_err_probe(dev, ret, "MSI controller resources not obtained\n");
+ if (ret < 0) {
+ ret = dev_err_probe(dev, ret, "MSI controller resources not obtained\n");
+ goto exit;
+ }

addr = res.start + GITS_TRANSLATER;
- if (addr >= SZ_4G)
- return dev_err_probe(dev, -EINVAL, "MSI controller address above 32bit range\n");
+ if (addr >= SZ_4G) {
+ ret = dev_err_probe(dev, -EINVAL, "MSI controller address above 32bit range\n");
+ goto exit;
+ }

*msi_addr = addr;
- return 0;
+
+exit:
+ of_node_put(msi_node);
+ return ret;
}

static int rcar_gen4_pcie_host_msi_init(struct dw_pcie_rp *pp)
"

Also, I think drivers/pci/controller/pcie-iproc.c iproc_pcie_msi_enable() needs similar fix ?