[PATCH] bcma: fix device node refcount leak in bcma_of_get_irq()
From: Haotian Zhang
Date: Thu Oct 08 2026 - 14:34:55 EST
bcma_of_get_irq() parses the interrupt specifier with
bcma_of_irq_parse(), which on success returns with the refcount of
out_irq.np increased by one, owned by the caller. The function then
passes out_irq to irq_create_of_mapping(), which does not consume that
reference, and returns without ever calling of_node_put(), leaking one
reference to the interrupt parent node on every successful call.
Release the out_irq.np reference after irq_create_of_mapping(), matching
irq_of_parse_and_map().
Fixes: 71783576b534 ("bcma: get IRQ numbers from dt")
Assisted-by: DeepSeek-V4.1-Flash
Signed-off-by: Haotian Zhang <vulab@xxxxxxxxxxx>
---
drivers/bcma/main.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/bcma/main.c b/drivers/bcma/main.c
index 72f045e6ed51..0a7f6ef6434b 100644
--- a/drivers/bcma/main.c
+++ b/drivers/bcma/main.c
@@ -182,6 +182,7 @@ static unsigned int bcma_of_get_irq(struct device *parent,
struct bcma_device *core, int num)
{
struct of_phandle_args out_irq;
+ unsigned int irq;
int ret;
if (!IS_ENABLED(CONFIG_OF_IRQ) || !parent->of_node)
@@ -194,7 +195,10 @@ static unsigned int bcma_of_get_irq(struct device *parent,
return 0;
}
- return irq_create_of_mapping(&out_irq);
+ irq = irq_create_of_mapping(&out_irq);
+ of_node_put(out_irq.np);
+
+ return irq;
}
static void bcma_of_fill_device(struct device *parent,
--
2.25.1