[PATCH v4 1/2] drm/nouveau: Fix memory leak in debugfs init error path

From: liupeng

Date: Fri Oct 09 2026 - 22:20:54 EST


In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously
allocated drm->debugfs is leaked because the function returns the
error code directly.

Fix this by freeing the allocated memory and clearing the pointer on
the error path.

Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs")
Cc: stable@xxxxxxxxxxxxxxx
Reviewed-by: Lyude Paul <lyude@xxxxxxxxxx>
Signed-off-by: liupeng <liupeng01@xxxxxxxxxx>
---
Changes in v4:
- Split the debugfs and hwmon fixes into two separate patches as
requested by Danilo, since they are unrelated fixes with different
Fixes: tags. No functional change to this fix.

drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)

diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
index 47d5579c568d..338421e52f69 100644
--- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
+++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
@@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor *minor)
int
nouveau_debugfs_init(struct nouveau_drm *drm)
{
+ int ret;
+
drm->debugfs = kzalloc_obj(*drm->debugfs);
if (!drm->debugfs)
return -ENOMEM;

- return nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
- NVIF_CLASS_CONTROL, NULL, 0,
- &drm->debugfs->ctrl);
+ ret = nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
+ NVIF_CLASS_CONTROL, NULL, 0,
+ &drm->debugfs->ctrl);
+ if (ret) {
+ kfree(drm->debugfs);
+ drm->debugfs = NULL;
+ }
+
+ return ret;
}

void
--
2.53.0