intel_th: fix MSC output device reference leak

intel_th_output_open() looks up the output device with
bus_find_device_by_devt(), which returns the device with a reference that
must be dropped after use.

commit 95fc36a234 ("intel_th: fix device leak on output open()")
attempted to drop the reference from intel_th_output_release(). However,
a successful open replaces file->f_op with the output driver file
operations before returning, so close runs the output driver release
callback instead.

For MSC outputs, close runs intel_th_msc_release(), which only removes
the per-file iterator and does not drop the device reference taken by
intel_th_output_open(). Consequently, every successful MSC output open
leaks one device reference.

Drop the device reference from intel_th_msc_release(), which is the
release path actually used for MSC output files. Remove the now-unused
intel_th_output_release() callback from intel_th_output_fops.

Fixes: 95fc36a234 ("intel_th: fix device leak on output open()")
Cc: stable <stable@kernel.org>
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Johan Hovold <johan@kernel.org>
Link: https://patch.msgid.link/20260715070851.2077965-1-lgs201920130244@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
Guangshuo Li 2026-07-15 15:08:51 +08:00 committed by Greg Kroah-Hartman
parent 3b231f1e99
commit 761b785a0c
2 changed files with 2 additions and 10 deletions

View File

@ -843,18 +843,8 @@ static int intel_th_output_open(struct inode *inode, struct file *file)
return err;
}
static int intel_th_output_release(struct inode *inode, struct file *file)
{
struct intel_th_device *thdev = file->private_data;
put_device(&thdev->dev);
return 0;
}
static const struct file_operations intel_th_output_fops = {
.open = intel_th_output_open,
.release = intel_th_output_release,
.llseek = noop_llseek,
};

View File

@ -1490,8 +1490,10 @@ static int intel_th_msc_release(struct inode *inode, struct file *file)
{
struct msc_iter *iter = file->private_data;
struct msc *msc = iter->msc;
struct intel_th_device *thdev = msc->thdev;
msc_iter_remove(iter, msc);
put_device(&thdev->dev);
return 0;
}