Re: [PATCH] pinctrl: core: fix pin name leak on radix_tree_insert() error path

From: Sergey Shtylyov

Date: Fri Oct 09 2026 - 11:58:55 EST


On 10/9/26 8:45 AM, Haotian Zhang wrote:

> pinctrl_register_one_pin() allocates pindesc->name with kasprintf() when
> the pin has no static name, and marks it with pindesc->dynamic_name. If
> the subsequent radix_tree_insert() fails, the function jumps to the
> failed label, which only calls kfree(pindesc) and never frees the
> dynamically allocated name, leaking it.
>
> Since the insertion failed, the pin is not in the radix tree, so the
> caller's pinctrl_free_pindescs() cleanup cannot find it and cannot
> release the name either.
>
> Release pindesc->name on the failed path when it was dynamically
> allocated.
>
> Fixes: ecfe9a015d3e ("pinctrl: core: handle radix_tree_insert() errors in pinctrl_register_one_pin()")
> Assisted-by: DeepSeek-V4.1-Flash
> Signed-off-by: Haotian Zhang <vulab@xxxxxxxxxxx>
Oops, my fault indeed! :-( If you want, you can add my:
Reviewed-by: Sergey Shtylyov <s.shtylyov@xxxxxx>

[...]

> diff --git a/drivers/pinctrl/core.c b/drivers/pinctrl/core.c
> index 1675dd36bd5c..3a1d1ff871ef 100644
> --- a/drivers/pinctrl/core.c
> +++ b/drivers/pinctrl/core.c
> @@ -249,6 +249,8 @@ static int pinctrl_register_one_pin(struct pinctrl_dev *pctldev,
> return 0;
>
> failed:
> + if (pindesc->dynamic_name)
> + kfree(pindesc->name);

You may as well add another label here -- for the 1st *goto*...

> kfree(pindesc);
> return error;
> }
[...]
MBR, Sergey