From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f201.google.com (mail-pl1-f201.google.com [209.85.214.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 290B73815D4 for ; Tue, 31 Mar 2026 10:08:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774951700; cv=none; b=LaY0WJTmsknmaZJ8vhIqgdE3GXUHwPLp3hGyefinsDBsFDQpBBEQLA01xlkp3eEZiogff6gBL4tV5lDF82+DQyT77ThjaDXkJIWG02BhePFwF3cGtkKfeYufHvObgDiF4gNpBVmcMf7u21oZQUonnYL1EZm7GYCddI7Cn8n+lnE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1774951700; c=relaxed/simple; bh=fdyz3sQwTAF8Q/yImsa76DtuGgO7WvOPsahbhG4ssIk=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=YKKYtl3qjytiAYnBt6XgT/YNLf1Uq/lrJ0sLIoqhjyeUCLHGJWX3w7i0ZrEsfDDV4G37m/hKqn9YQTcHxLzxub/lFeqzYaAd7eX3XKWabQJIm8U0WFJoYIhJRH/i25ZcmQaIBHKd1OpqP562g1Wjmdoi210fUo+QRbXejLZ5gBE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--joonwonkang.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=pC3ztFIH; arc=none smtp.client-ip=209.85.214.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--joonwonkang.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="pC3ztFIH" Received: by mail-pl1-f201.google.com with SMTP id d9443c01a7336-2b24af7ca99so31714615ad.1 for ; Tue, 31 Mar 2026 03:08:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1774951698; x=1775556498; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=BnoxrHI8V0kV/guwSoufvxK8u0LFfCUgHXBF1SjK/iY=; b=pC3ztFIHTKXS9tOtmpEBxIDA+9uE19FGK7dJbuHp2L3FevBxcgiI2qj8KGSrkmjMOQ J1KalaOYoY3m89SvGvzFyMn3ySb5A26UEGv43DYULlqcdlaG9F6KTkNpyy2W3mvbMYPf rC0ilhDCRhmQUvgri4AwOQkpXHIeOYMtqEuJSaCXMoHDd+r1fodgxiuXehsLS+pmbiul 1GhKlPqprZOAaFGv5vf/JK+xN9IaAze1+vh1YjCgK8TkrMY+0a5SRFQnHWr9kOUJccHo IZa714eOM/P78qBUKzFvn56MDYP54DUKWOLuTTscVuuUs6os24aCA+4FearaGorrD5SI jpXg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1774951698; x=1775556498; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=BnoxrHI8V0kV/guwSoufvxK8u0LFfCUgHXBF1SjK/iY=; b=emd473fiNeMz/z9CgmqlzR1/3A0Uoo7ufRXO7x3kIrXi07R1GiGHUWM1CE/njrAb37 yWJumWlsCafhnLmzcWxGB/VUS7W3J+PCfrdXvDfc0iFVCKjZ+dFevmtqkE6l4WdWlTD7 P3wjkSxeUnO1xEtkYhXiivrP0n0gByIYqkY3HKrppTnHgwExhHBK2Dut/RoZ48IfMPft sVG/8lRLhuNHsXYynIkv5+mkAT3H7ivevQimRSRmW7GCDob5HAbPdls+W3jEIAUSr8Is 2IveiHNkPKQ4J6A68DVfOgM3/JQqd+v+HA3tAz90gh5OX4SJi5CSZ4SUiKgHxXOUu9VT QJOw== X-Forwarded-Encrypted: i=1; AJvYcCWrucBs9Mr4jR+3syOqnktULNmOpRsub0haUgmmr5C81CRuZdeZDaiZ5aP+vYzErwbcsg7/g8N5zhMZzuY=@vger.kernel.org X-Gm-Message-State: AOJu0YxhiaT3UMNaCGQ/TMgsvuCXPN/eCFn7vgUYSt8HBVWhyd0X3Ox4 PGRUPe4+OnciU+RDgZ/mInOrsVb8TRzXgFHArtq4FMkXkhiOPAKSWTbQ4BbDHRwlk6EDXBN3HYO oVN/F3gUFqO0YYXzScKyn4b/XxA== X-Received: from plbi10.prod.google.com ([2002:a17:903:20ca:b0:2b2:4844:461e]) (user=joonwonkang job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:2284:b0:2b2:51ed:4524 with SMTP id d9443c01a7336-2b251ed5756mr74227035ad.43.1774951698207; Tue, 31 Mar 2026 03:08:18 -0700 (PDT) Date: Tue, 31 Mar 2026 10:08:16 +0000 In-Reply-To: <20260327220040.53326-1-jassisinghbrar@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260327220040.53326-1-jassisinghbrar@gmail.com> X-Mailer: git-send-email 2.53.0.1018.g2bb0e51243-goog Message-ID: <20260331100816.2222507-1-joonwonkang@google.com> Subject: Re: [PATCH] mailbox: Fix NULL message support in mbox_send_message() From: Joonwon Kang To: jassisinghbrar@gmail.com Cc: andersson@kernel.org, dianders@chromium.org, joonwonkang@google.com, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, maz@kernel.org, shawn.guo@linaro.org, tglx@kernel.org Content-Type: text/plain; charset="UTF-8" > The active_req field serves double duty as both the "is a TX in > flight" flag (NULL means idle) and the storage for the in-flight > message pointer. When a client sends NULL via mbox_send_message(), > active_req is set to NULL, which the framework misinterprets as > "no active request". This breaks the TX state machine by: > > - tx_tick() short-circuits on (!mssg), skipping the tx_done > callback and the tx_complete completion > - txdone_hrtimer() skips the channel entirely since active_req > is NULL, so poll-based TX-done detection never fires. > > Fix this by introducing a MBOX_NO_MSG sentinel value that means > "no active request," freeing NULL to be valid message data. The > sentinel is defined in the subsystem-internal mailbox.h so that > controller drivers within drivers/mailbox/ can reference it, but > it is not exposed to clients outside the subsystem. > > Fifteen in-tree callers send NULL (doorbell-style IPCs on Qualcomm, > Tegra, TI, Xilinx, i.MX, SCMI, and PCC platforms). All were > audited for regression: > > - Most already work around the bug via knows_txdone=true with a > manual mbox_client_txdone() call, making the framework's > tracking irrelevant. These are unaffected. > > - Poll-based callers (Xilinx zynqmp/r5) are strictly better off: > the poll timer now correctly detects NULL-active channels > instead of silently skipping them. > > - irq-qcom-mpm.c was a pre-existing bug -- the only Qualcomm > caller that omitted the knows_txdone + mbox_client_txdone() > pattern. Fixed in a companion commit ("irqchip/qcom-mpm: Fix > missing mailbox TX done acknowledgment"). > > - No caller sets both a tx_done callback and sends NULL, nor > combines tx_block=true with NULL sends, so the newly reachable > callback/completion paths are never exercised. > > Also update tegra-hsp's flush callback, which directly inspects > active_req to wait for the channel to drain: the old "!= NULL" > check becomes "!= MBOX_NO_MSG", otherwise flush spins until > timeout since the sentinel is non-NULL. > > The only tradeoff is that 'MBOX_NO_MSG' can not be used as a message > by clients. > > Reported-by: Joonwon Kang > Reviewed-by: Douglas Anderson > Signed-off-by: Jassi Brar Do you have plans to backport this patch to other stable versions? If not, I can send the backport for you to the stable versions that are in my needs. Thanks, Joonwon Kang