Re: [PATCH v2 2/2] media: rcar-isp: Fix VSPX reference leaks
From: Jacopo Mondi
Date: Thu Aug 06 2026 - 05:39:00 EST
Hello Linmao Li
On Tue, Aug 04, 2026 at 06:24:31PM +0800, Linmao Li wrote:
> of_parse_phandle() and of_find_device_by_node() both acquire references,
> but the ISPCORE probe never releases them. The device node reference is
> leaked immediately, and the VSPX device reference is leaked on probe
> failures and on driver removal.
>
> Drop the node reference once the platform device has been looked up, and
> release the device reference on the probe error paths and in the remove
> path.
>
> Signed-off-by: Linmao Li <lilinmao@xxxxxxxxxx>
Thanks, looks good to me!
Reviewed-by: Jacopo Mondi <jacopo.mondi@xxxxxxxxxxxxxxxx>
Sakari, Hans, should we collect these two patches as fixes for 7.3 ?
> ---
> drivers/media/platform/renesas/rcar-isp/core.c | 17 +++++++++++++----
> 1 file changed, 13 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/media/platform/renesas/rcar-isp/core.c b/drivers/media/platform/renesas/rcar-isp/core.c
> index 181446ae53779..b5861d0cd0e8b 100644
> --- a/drivers/media/platform/renesas/rcar-isp/core.c
> +++ b/drivers/media/platform/renesas/rcar-isp/core.c
> @@ -820,6 +820,7 @@ static int risp_core_probe_resources(struct rcar_isp_core *core,
> return -ENODEV;
>
> vspx = of_find_device_by_node(of_vspx);
> + of_node_put(of_vspx);
> if (!vspx)
> return -ENODEV;
>
> @@ -828,7 +829,7 @@ static int risp_core_probe_resources(struct rcar_isp_core *core,
>
> ret = vsp1_isp_init(&vspx->dev);
> if (ret < 0)
> - return ret;
> + goto err_put_vspx;
>
> /* Attach to the RPP library
> *
> @@ -839,7 +840,7 @@ static int risp_core_probe_resources(struct rcar_isp_core *core,
> */
> ret = clk_prepare_enable(core->clk);
> if (ret)
> - return ret;
> + goto err_put_vspx;
>
> usleep_range(2000, 4000);
>
> @@ -847,10 +848,16 @@ static int risp_core_probe_resources(struct rcar_isp_core *core,
>
> clk_disable_unprepare(core->clk);
>
> - if (!core->rpp)
> - return -ENODEV;
> + if (!core->rpp) {
> + ret = -ENODEV;
> + goto err_put_vspx;
> + }
>
> return 0;
> +
> +err_put_vspx:
> + put_device(&vspx->dev);
> + return ret;
> }
>
> int risp_core_probe(struct rcar_isp_core *core, struct platform_device *pdev,
> @@ -886,6 +893,7 @@ int risp_core_probe(struct rcar_isp_core *core, struct platform_device *pdev,
> v4l2_device_unregister(&core->v4l2_dev);
> err_destroy_rpp:
> rppx1_destroy(core->rpp);
> + put_device(core->vspx.dev);
> return ret;
> }
>
> @@ -904,4 +912,5 @@ void risp_core_remove(struct rcar_isp_core *core)
>
> mutex_destroy(&core->io_lock);
> rppx1_destroy(core->rpp);
> + put_device(core->vspx.dev);
> }
> --
> 2.25.1
>
>