Re: [PATCH] dmaengine: sprd: Fix runtime PM reference leak in probe

From: Frank Li

Date: Wed Aug 19 2026 - 15:29:33 EST


On Thu, Aug 13, 2026 at 11:31:49PM +0800, Ruoyu Wang wrote:
> pm_runtime_get_sync() increments a device's usage counter even when it
> fails. sprd_dma_probe() currently jumps directly to controller clock
> cleanup on that error, bypassing both pm_runtime_put_noidle() and
> pm_runtime_disable(). This can happen if the preceding unchecked
> pm_runtime_set_active() fails and the following runtime-resume attempt
> also returns an error.
>
> Enter the existing runtime-PM unwind path instead. This drops the
> reference without idling the partially initialized device, disables
> runtime PM, and then releases the controller clocks. The success path
> and propagated error code are unchanged.
>
> This issue was found by a static analysis checker and confirmed by manual
> source review.
>
> Fixes: 9b3b8171f7f4 ("dmaengine: sprd: Add Spreadtrum DMA driver")
> Signed-off-by: Ruoyu Wang <ruoyuw560@xxxxxxxxx>
> ---

Reviewed-by: Frank Li <Frank.Li@xxxxxxx>

> drivers/dma/sprd-dma.c | 3 +--
> 1 file changed, 1 insertion(+), 2 deletions(-)
>
> diff --git a/drivers/dma/sprd-dma.c b/drivers/dma/sprd-dma.c
> index 087fea3af2e411..19b32a23c882de 100644
> --- a/drivers/dma/sprd-dma.c
> +++ b/drivers/dma/sprd-dma.c
> @@ -1212,7 +1212,7 @@ static int sprd_dma_probe(struct platform_device *pdev)
>
> ret = pm_runtime_get_sync(&pdev->dev);
> if (ret < 0)
> - goto err_rpm;
> + goto err_register;
>
> ret = dma_async_device_register(&sdev->dma_dev);
> if (ret < 0) {
> @@ -1234,7 +1234,6 @@ static int sprd_dma_probe(struct platform_device *pdev)
> err_register:
> pm_runtime_put_noidle(&pdev->dev);
> pm_runtime_disable(&pdev->dev);
> -err_rpm:
> sprd_dma_disable(sdev);
> return ret;
> }
> --
> 2.51.0
>