On 8/15/26 21:12, Liu Zhenlong wrote:
i2c_pnx_probe() calls of_node_get() to take an extra reference on the platform device's of_node when assigning it to the adapter device, but none of the probe error paths nor i2c_pnx_remove() drops it.device_release() does not call of_node_put() and i2c_adapter_dev_release() only completes a struct, so the extra reference is never released, leaking the device_node on every probe failure and every adapter removal. Add the matching of_node_put() to all probe error paths (the three early return paths before clk_prepare_enable(), and the out_clock label which covers the wait_reset(), platform_get_irq(), devm_request_irq() and i2c_add_numbered_adapter() failure paths; dev is devm_kzalloc'ed so adapter.dev.of_node is NULL and of_node_put() is a no-op when CONFIG_OF is not set) and to i2c_pnx_remove(). In i2c_pnx_remove(), i2c_del_adapter() clears adap->dev with memset() at the end (commit bd4bc3dbded9 ("i2c: Clear i2c_adapter.dev on adapter removal")), which zeroes adap->dev.of_node before of_node_put() runs. Cache the pointer before calling i2c_del_adapter(), the same approach used in i2c-mux (i2c_mux_del_adapters) and mtd (commit 56570bdad5e3 ("mtd: core: Fix refcount error in del_mtd_device()")). Compile-tested with gcc on arm64 defconfig using COMPILE_TEST; no hardware available for runtime testing. Fixes: b41a216dafe4 ("i2c: Add device tree support to i2c-pnx.c") Cc: [email protected] Assisted-by: Claude:claude-opus-5 Signed-off-by: Liu Zhenlong <[email protected]>
Reviewed-by: Vladimir Zapolskiy <[email protected]> -- Best wishes, Vladimir
