[PATCH v2] clocksource/drivers/timer-imx-gpt: fix resource leak on init error paths
From: Haotian Zhang
Date: Thu Oct 08 2026 - 22:28:34 EST
mxc_timer_init_dt() maps the timer registers with of_iomap() and obtains
the ipg and per clocks with of_clk_get_by_name(), but every error path
jumps to err_kfree, which only frees the imx_timer structure. The
ioremap'd mapping, the clock references and the mapping created by
irq_of_parse_and_map() are leaked when irq_of_parse_and_map() or
_mxc_timer_init() fails.
Release the ioremap mapping when irq_of_parse_and_map() fails, and drop
the clock references and the IRQ mapping when _mxc_timer_init() fails.
_mxc_timer_init() can fail after mxc_clocksource_init() has registered
the sched_clock and the clocksource, and after mxc_clockevent_init() has
registered the clock event device. Those subsystems keep using
imxtm->base and imxtm, so neither the mapping nor imxtm itself may be
released on that path; request_irq() cannot have succeeded there, so
disposing the IRQ mapping is safe.
Fixes: 8051a993ce22 ("clocksource/drivers/timer-imx-gpt: Fix potential memory leak")
Assisted-by: DeepSeek-V4.1-Flash
Suggested-by: Frank Li <Frank.li@xxxxxxxxxxx>
Signed-off-by: Haotian Zhang <vulab@xxxxxxxxxxx>
---
Changes in v2:
- Dispose the IRQ mapping and drop the clock references when
_mxc_timer_init() fails, instead of leaking the IRQ mapping.
- Do not unmap imxtm->base nor free imxtm on that path: the sched_clock,
the clocksource and the clock event device may already have been
registered and keep using them.
drivers/clocksource/timer-imx-gpt.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
diff --git a/drivers/clocksource/timer-imx-gpt.c b/drivers/clocksource/timer-imx-gpt.c
index 8335bd7f8c6c..8050f3b449ba 100644
--- a/drivers/clocksource/timer-imx-gpt.c
+++ b/drivers/clocksource/timer-imx-gpt.c
@@ -441,7 +441,7 @@ static int __init mxc_timer_init_dt(struct device_node *np, enum imx_gpt_type t
imxtm->irq = irq_of_parse_and_map(np, 0);
if (imxtm->irq <= 0) {
ret = -EINVAL;
- goto err_kfree;
+ goto err_unmap;
}
imxtm->clk_ipg = of_clk_get_by_name(np, "ipg");
@@ -455,12 +455,22 @@ static int __init mxc_timer_init_dt(struct device_node *np, enum imx_gpt_type t
ret = _mxc_timer_init(imxtm);
if (ret)
- goto err_kfree;
+ goto err_irq;
initialized = 1;
return 0;
+err_irq:
+ if (!IS_ERR_OR_NULL(imxtm->clk_per))
+ clk_put(imxtm->clk_per);
+ if (!IS_ERR_OR_NULL(imxtm->clk_ipg))
+ clk_put(imxtm->clk_ipg);
+ irq_dispose_mapping(imxtm->irq);
+ return ret;
+
+err_unmap:
+ iounmap(imxtm->base);
err_kfree:
kfree(imxtm);
return ret;
--
2.25.1