RE: [PATCH v2] net: ethernet: renesas: rswitch: fix device_node refcount leak in rswitch_get_port_node()

Michael Dege <[email protected]>
Newsgroups org.kernel.vger.linux-renesas-soc,org.kernel.vger.netdev
Message-ID <TY4PR01MB14282297556165468224837C682A72@TY4PR01MB14282.jpnprd01.prod.outlook.com>
Hello Manush,

Were you able to test this on real HW?

I am currently on a different code base and device (X5H). I have tested it with your original 
patch and with v2 of the patch. 

Patch v1 works fine; patch v2 does not work.

Best regards,

Michael

> -----Original Message-----
> From: manushprajwal <[email protected]>
> Sent: Friday, August 14, 2026 9:04 PM
> To: Yoshihiro Shimoda <[email protected]>
> Cc: Andrew Lunn <[email protected]>; [email protected]; Eric Dumazet <[email protected]>;
> Jakub Kicinski <[email protected]>; Paolo Abeni <[email protected]>; [email protected]; linux-
> [email protected]; Manush Prajwal <[email protected]>
> Subject: [PATCH v2] net: ethernet: renesas: rswitch: fix device_node refcount leak in
> rswitch_get_port_node()
> 
> From: Manush Prajwal <[email protected]>
> 
> On an of_property_read_u32() failure, rswitch_get_port_node() set port to NULL and jumped to the out
> label before releasing the reference the
> for_each_available_child_of_node() iterator was holding on it. Once port was overwritten with NULL,
> that reference could never be released since out: only put "ports", the parent node.
> 
> Rework the function around for_each_available_child_of_node_scoped()
> instead of adding a manual of_node_put(), so the iterator's reference is dropped automatically on
> every exit path. Since port is the function's return value, take an explicit reference with
> of_node_get() on the match before breaking out of the loop.
> 
> Signed-off-by: Manush Prajwal <[email protected]>
> ---
> v2: Rework using for_each_available_child_of_node_scoped() instead of
>     a manual of_node_put(), per Andrew Lunn's review.
> 
>  drivers/net/ethernet/renesas/rswitch_main.c | 20 +++++++++-----------
>  1 file changed, 9 insertions(+), 11 deletions(-)
> 
> diff --git a/drivers/net/ethernet/renesas/rswitch_main.c b/drivers/net/ethernet/renesas/rswitch_main.c
> index 6fe9648163..ffdc42f430 100644
> --- a/drivers/net/ethernet/renesas/rswitch_main.c
> +++ b/drivers/net/ethernet/renesas/rswitch_main.c
> @@ -1303,8 +1303,8 @@
>  /* Call of_node_put(port) after done */  static struct device_node *rswitch_get_port_node(struct
> rswitch_device *rdev)  {
> -	struct device_node *ports, *port;
> -	int err = 0;
> +	struct device_node *ports;
> +	struct device_node *port = NULL;
>  	u32 index;
> 
>  	ports = of_get_child_by_name(rdev->ndev->dev.parent->of_node,
> @@ -1312,17 +1312,15 @@ static struct device_node *rswitch_get_port_node(struct rswitch_device *rdev)
>  	if (!ports)
>  		return NULL;
> 
> -	for_each_available_child_of_node(ports, port) {
> -		err = of_property_read_u32(port, "reg", &index);
> -		if (err < 0) {
> -			port = NULL;
> -			goto out;
> -		}
> -		if (index == rdev->etha->index)
> +	for_each_available_child_of_node_scoped(ports, child) {
> +		if (of_property_read_u32(child, "reg", &index))
> +			break;
> +		if (index == rdev->etha->index) {
> +			port = of_node_get(child);
>  			break;
> +		}
>  	}
> 
> -out:
>  	of_node_put(ports);
> 
>  	return port;
> --
> 2.46.2.windows.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.