Re: [PATCH] leds: lp50xx: use scoped loop to fix fwnode reference leak in lp50xx_probe_dt()

From: Griffin Kroah-Hartman

Date: Fri Oct 02 2026 - 08:44:27 EST


On 10/1/26 6:44 AM, Manush Prajwal wrote:

In lp50xx_probe_dt(), fwnode_for_each_child_node(child, led_node) iterates
over each sub-LED child node. If fwnode_property_read_u32() for "reg" fails
or if multi_index >= LP50XX_LEDS_PER_MODULE, the function returns -EINVAL
without dropping the reference count of led_node, leaking the fwnode.

Use fwnode_for_each_child_node_scoped() to automatically release led_node
on all exit paths, eliminating the refcount leak as well as the manual
fwnode_handle_put(led_node) on the "color" property failure path, and
remove the now unnecessary function-scope led_node variable declaration.

Fixes: 193910c2c54e ("leds: lp50xx: Add the LP50XX family of the RGB LED driver")
Signed-off-by: Manush Prajwal <manushprajwal555@xxxxxxxxx>
---
drivers/leds/leds-lp50xx.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)

diff --git a/drivers/leds/leds-lp50xx.c b/drivers/leds/leds-lp50xx.c
index 20bfb315b..d542eedd4 100644
--- a/drivers/leds/leds-lp50xx.c
+++ b/drivers/leds/leds-lp50xx.c
@@ -458,7 +458,6 @@ static int lp50xx_probe_leds(struct fwnode_handle *child, struct lp50xx *priv,
static int lp50xx_probe_dt(struct lp50xx *priv)
{
- struct fwnode_handle *led_node = NULL;
struct led_init_data init_data = {};
struct led_classdev *led_cdev;
struct mc_subled *mc_led_info;
@@ -505,12 +504,11 @@ static int lp50xx_probe_dt(struct lp50xx *priv)
if (!mc_led_info)
return -ENOMEM;
- fwnode_for_each_child_node(child, led_node) {
+ fwnode_for_each_child_node_scoped(child, led_node) {
int multi_index;
ret = fwnode_property_read_u32(led_node, "color",
&color_id);
if (ret) {
- fwnode_handle_put(led_node);
dev_err(priv->dev, "Cannot read color\n");
return ret;
}


Reviewed-by: Griffin Kroah-Hartman <griffin@xxxxxxxxx>