From: jassisinghbrar@gmail.com
To: linux-kernel@vger.kernel.org
Cc: arnd@arndb.de, dianders@chromium.org,
Jassi Brar <jassisinghbrar@gmail.com>
Subject: [PATCH] RFC: mailbox: Fix NULL message support in mbox_send_message()
Date: Tue, 10 Mar 2026 18:46:16 -0500 [thread overview]
Message-ID: <20260310234616.334498-1-jassisinghbrar@gmail.com> (raw)
From: Jassi Brar <jassisinghbrar@gmail.com>
The active_req field serves double duty as both the "is a TX in
flight" flag (NULL means idle) and the storage for the in-flight
message pointer. When a client sends NULL via mbox_send_message(),
active_req is set to NULL, which the framework misinterprets as
"no active request." This breaks the TX state machine by:
- tx_tick() short-circuits on (!mssg), skipping the tx_done
callback and the tx_complete completion
- txdone_hrtimer() skips the channel entirely since active_req
is NULL, so poll-based TX-done detection never fires.
Fix this by introducing a MBOX_NO_MSG sentinel value that means
"no active request," freeing NULL to be valid message data. The
sentinel is internal to the mailbox core and is never exposed to
controller drivers or clients.
The only tradeoff is that 'MBOX_NO_MSG' can not be used as a message
by clients.
Signed-off-by: Jassi Brar <jassisinghbrar@gmail.com>
---
drivers/mailbox/mailbox.c | 15 +++++++++------
1 file changed, 9 insertions(+), 6 deletions(-)
diff --git a/drivers/mailbox/mailbox.c b/drivers/mailbox/mailbox.c
index 617ba505691d..d06f6d49deaf 100644
--- a/drivers/mailbox/mailbox.c
+++ b/drivers/mailbox/mailbox.c
@@ -20,6 +20,9 @@
#include "mailbox.h"
+/* Sentinel value distinguishing "no active request" from "NULL message data" */
+#define MBOX_NO_MSG ((void *)-1)
+
static LIST_HEAD(mbox_cons);
static DEFINE_MUTEX(con_mutex);
@@ -52,7 +55,7 @@ static void msg_submit(struct mbox_chan *chan)
int err = -EBUSY;
scoped_guard(spinlock_irqsave, &chan->lock) {
- if (!chan->msg_count || chan->active_req)
+ if (!chan->msg_count || chan->active_req != MBOX_NO_MSG)
break;
count = chan->msg_count;
@@ -87,13 +90,13 @@ static void tx_tick(struct mbox_chan *chan, int r)
scoped_guard(spinlock_irqsave, &chan->lock) {
mssg = chan->active_req;
- chan->active_req = NULL;
+ chan->active_req = MBOX_NO_MSG;
}
/* Submit next message */
msg_submit(chan);
- if (!mssg)
+ if (mssg == MBOX_NO_MSG)
return;
/* Notify the client */
@@ -114,7 +117,7 @@ static enum hrtimer_restart txdone_hrtimer(struct hrtimer *hrtimer)
for (i = 0; i < mbox->num_chans; i++) {
struct mbox_chan *chan = &mbox->chans[i];
- if (chan->active_req && chan->cl) {
+ if (chan->active_req != MBOX_NO_MSG && chan->cl) {
txdone = chan->mbox->ops->last_tx_done(chan);
if (txdone)
tx_tick(chan, 0);
@@ -319,7 +322,7 @@ static int __mbox_bind_client(struct mbox_chan *chan, struct mbox_client *cl)
scoped_guard(spinlock_irqsave, &chan->lock) {
chan->msg_free = 0;
chan->msg_count = 0;
- chan->active_req = NULL;
+ chan->active_req = MBOX_NO_MSG;
chan->cl = cl;
init_completion(&chan->tx_complete);
@@ -477,7 +480,7 @@ void mbox_free_channel(struct mbox_chan *chan)
/* The queued TX requests are simply aborted, no callbacks are made */
scoped_guard(spinlock_irqsave, &chan->lock) {
chan->cl = NULL;
- chan->active_req = NULL;
+ chan->active_req = MBOX_NO_MSG;
if (chan->txdone_method == TXDONE_BY_ACK)
chan->txdone_method = TXDONE_BY_POLL;
}
--
2.43.0
next reply other threads:[~2026-03-10 23:46 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-10 23:46 jassisinghbrar [this message]
2026-03-10 23:52 ` Doug Anderson
2026-03-10 23:58 ` Jassi Brar
2026-03-11 0:15 ` Doug Anderson
2026-03-11 0:45 ` Jassi Brar
2026-03-11 1:59 ` Doug Anderson
2026-03-11 3:41 ` Jassi Brar
2026-03-12 20:59 ` Doug Anderson
2026-03-13 8:44 ` Joonwon Kang
2026-03-13 16:19 ` Doug Anderson
2026-03-17 2:21 ` Jassi Brar
2026-03-12 10:19 ` [PATCH] RFC: mailbox: Fix NULL message support in Joonwon Kang
2026-03-12 7:34 ` Joonwon Kang
2026-03-13 10:12 ` [PATCH] RFC: mailbox: Fix NULL message support in mbox_send_message() Joonwon Kang
2026-03-13 16:23 ` Doug Anderson
2026-03-17 3:12 ` Jassi Brar
2026-03-17 5:03 ` Joonwon Kang
2026-03-20 21:03 ` Doug Anderson
2026-03-21 16:11 ` Jassi Brar
2026-03-26 7:31 ` Joonwon Kang
2026-03-27 18:29 ` Jassi Brar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260310234616.334498-1-jassisinghbrar@gmail.com \
--to=jassisinghbrar@gmail.com \
--cc=arnd@arndb.de \
--cc=dianders@chromium.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®