[PATCH] soc: mediatek: mtk-devapc: release IRQ before unmapping registers

Myeonghun Pak mhun512 at gmail.com
Fri Oct 2 13:20:28 PDT 2026


The managed IRQ remains registered until devres cleanup after remove
returns, but remove explicitly unmaps the registers used by its handler.

An interrupt handler already in flight when stop_devapc() is called can
continue accessing ctx->infra_base after iounmap().

Release and synchronize the IRQ before unmapping the register region.

This issue was identified during our ongoing static-analysis research
while reviewing kernel code.

Fixes: c9c0036c1990 ("soc: mediatek: mtk-devapc: Fix leaking IO map on driver remove")
Assisted-by: LLM
Cc: stable at vger.kernel.org
Signed-off-by: Myeonghun Pak <mhun512 at gmail.com>
---
 drivers/soc/mediatek/mtk-devapc.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/soc/mediatek/mtk-devapc.c b/drivers/soc/mediatek/mtk-devapc.c
index f54c966138b5b8bda32c383d179a57c78172bf52..57ffe49c99eeb9b0989bd5eefa557a0a7dddbf18 100644
--- a/drivers/soc/mediatek/mtk-devapc.c
+++ b/drivers/soc/mediatek/mtk-devapc.c
@@ -54,6 +54,7 @@ struct mtk_devapc_context {
 	void __iomem *infra_base;
 	struct clk *infra_clk;
 	const struct mtk_devapc_data *data;
+	unsigned int irq;
 };
 
 static void clear_vio_status(struct mtk_devapc_context *ctx)
@@ -289,6 +290,7 @@ static int mtk_devapc_probe(struct platform_device *pdev)
 	if (ret)
 		goto err;
 
+	ctx->irq = devapc_irq;
 	platform_set_drvdata(pdev, ctx);
 
 	start_devapc(ctx);
@@ -305,6 +307,7 @@ static void mtk_devapc_remove(struct platform_device *pdev)
 	struct mtk_devapc_context *ctx = platform_get_drvdata(pdev);
 
 	stop_devapc(ctx);
+	devm_free_irq(&pdev->dev, ctx->irq, ctx);
 	iounmap(ctx->infra_base);
 }
 



More information about the Linux-mediatek mailing list