* [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure
@ 2026-10-06 9:14 Anup Vishwakarma
2026-10-06 9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma
` (2 more replies)
0 siblings, 3 replies; 7+ messages in thread
From: Anup Vishwakarma @ 2026-10-06 9:14 UTC (permalink / raw)
To: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla
Cc: Jassi Brar, linux-arm-msm, linux-kernel, Anup Vishwakarma
Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
---
Anup Vishwakarma (2):
mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure
mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure
drivers/mailbox/arm_mhu_db.c | 8 +++-----
drivers/mailbox/qcom-ipcc.c | 2 --
2 files changed, 3 insertions(+), 7 deletions(-)
---
base-commit: bf1ee2bd5c2da8992f33c8950ef194aaff74ed6c
change-id: 20261006-b4-mbox_double_unregister_fix-42d5057d3ad5
Best regards,
--
Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH 1/2] mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure
2026-10-06 9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma
@ 2026-10-06 9:14 ` Anup Vishwakarma
2026-10-06 9:35 ` Mukesh Ojha
2026-10-06 9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma
2026-10-06 9:31 ` [PATCH 0/2] mailbox: " Mukesh Ojha
2 siblings, 1 reply; 7+ messages in thread
From: Anup Vishwakarma @ 2026-10-06 9:14 UTC (permalink / raw)
To: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla
Cc: Jassi Brar, linux-arm-msm, linux-kernel, Anup Vishwakarma
qcom_ipcc_probe() registers the mailbox controller via
devm_mbox_controller_register(), which automatically calls
mbox_controller_unregister() through devres when the device is removed
or probe fails. If devm_request_irq() subsequently fails, the
err_req_irq: label also manually calls mbox_controller_unregister(),
resulting in a double call that corrupts the global mailbox controller
list and causes a kernel panic.
Remove the redundant manual call and rely on devres for cleanup.
Fixes: e9d50e4b4d04 ("mailbox: qcom-ipcc: Dynamic alloc for channel arrangement")
Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
---
drivers/mailbox/qcom-ipcc.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/mailbox/qcom-ipcc.c b/drivers/mailbox/qcom-ipcc.c
index 185b63f724d4..206ad4884987 100644
--- a/drivers/mailbox/qcom-ipcc.c
+++ b/drivers/mailbox/qcom-ipcc.c
@@ -336,8 +336,6 @@ static int qcom_ipcc_probe(struct platform_device *pdev)
return 0;
err_req_irq:
- if (ipcc->num_chans)
- mbox_controller_unregister(&ipcc->mbox);
err_mbox:
irq_domain_remove(ipcc->irq_domain);
--
2.43.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH 2/2] mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure
2026-10-06 9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma
2026-10-06 9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma
@ 2026-10-06 9:14 ` Anup Vishwakarma
2026-10-06 9:30 ` Mukesh Ojha
2026-10-06 9:31 ` [PATCH 0/2] mailbox: " Mukesh Ojha
2 siblings, 1 reply; 7+ messages in thread
From: Anup Vishwakarma @ 2026-10-06 9:14 UTC (permalink / raw)
To: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla
Cc: Jassi Brar, linux-arm-msm, linux-kernel, Anup Vishwakarma
mhu_db_probe() registers the mailbox controller via
devm_mbox_controller_register(), which automatically calls
mbox_controller_unregister() through devres when the device is removed
or probe fails. If devm_request_threaded_irq() subsequently fails in
the channel setup loop, the error path also manually calls
mbox_controller_unregister(), resulting in a double call that corrupts
the global mailbox controller list and causes a kernel panic.
Remove the redundant manual call and rely on devres for cleanup.
Fixes: 7002ca237b21 ("mailbox: arm_mhu: Add ARM MHU doorbell driver")
Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
---
drivers/mailbox/arm_mhu_db.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
diff --git a/drivers/mailbox/arm_mhu_db.c b/drivers/mailbox/arm_mhu_db.c
index a39239e38a47..9668dfdedc78 100644
--- a/drivers/mailbox/arm_mhu_db.c
+++ b/drivers/mailbox/arm_mhu_db.c
@@ -315,12 +315,10 @@ static int mhu_db_probe(struct amba_device *adev, const struct amba_id *id)
mhu->mlink[i].tx_reg = mhu->mlink[i].rx_reg + TX_REG_OFFSET;
err = devm_request_threaded_irq(dev, irq, NULL,
- mhu_db_mbox_rx_handler,
- IRQF_ONESHOT, "mhu_db_link", mhu);
- if (err) {
- mbox_controller_unregister(&mhu->mbox);
+ mhu_db_mbox_rx_handler,
+ IRQF_ONESHOT, "mhu_db_link", mhu);
+ if (err)
return err;
- }
}
dev_info(dev, "ARM MHU Doorbell mailbox registered\n");
--
2.43.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 2/2] mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure
2026-10-06 9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma
@ 2026-10-06 9:30 ` Mukesh Ojha
2026-10-06 11:33 ` Anup Vishwakarma
0 siblings, 1 reply; 7+ messages in thread
From: Mukesh Ojha @ 2026-10-06 9:30 UTC (permalink / raw)
To: Anup Vishwakarma
Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla,
Jassi Brar, linux-arm-msm, linux-kernel
On Tue, Oct 06, 2026 at 02:44:15PM +0530, Anup Vishwakarma wrote:
> mhu_db_probe() registers the mailbox controller via
> devm_mbox_controller_register(), which automatically calls
> mbox_controller_unregister() through devres when the device is removed
> or probe fails. If devm_request_threaded_irq() subsequently fails in
> the channel setup loop, the error path also manually calls
> mbox_controller_unregister(), resulting in a double call that corrupts
> the global mailbox controller list and causes a kernel panic.
>
> Remove the redundant manual call and rely on devres for cleanup.
>
> Fixes: 7002ca237b21 ("mailbox: arm_mhu: Add ARM MHU doorbell driver")
> Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
> ---
> drivers/mailbox/arm_mhu_db.c | 8 +++-----
> 1 file changed, 3 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/mailbox/arm_mhu_db.c b/drivers/mailbox/arm_mhu_db.c
> index a39239e38a47..9668dfdedc78 100644
> --- a/drivers/mailbox/arm_mhu_db.c
> +++ b/drivers/mailbox/arm_mhu_db.c
> @@ -315,12 +315,10 @@ static int mhu_db_probe(struct amba_device *adev, const struct amba_id *id)
> mhu->mlink[i].tx_reg = mhu->mlink[i].rx_reg + TX_REG_OFFSET;
>
> err = devm_request_threaded_irq(dev, irq, NULL,
> - mhu_db_mbox_rx_handler,
> - IRQF_ONESHOT, "mhu_db_link", mhu);
> - if (err) {
> - mbox_controller_unregister(&mhu->mbox);
> + mhu_db_mbox_rx_handler,
> + IRQF_ONESHOT, "mhu_db_link", mhu);
It looks like alignment/indentation is unnecessary changing.
> + if (err)
> return err;
> - }
> }
with the above fix.
Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
--
-Mukesh Ojha
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure
2026-10-06 9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma
2026-10-06 9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma
2026-10-06 9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma
@ 2026-10-06 9:31 ` Mukesh Ojha
2 siblings, 0 replies; 7+ messages in thread
From: Mukesh Ojha @ 2026-10-06 9:31 UTC (permalink / raw)
To: Anup Vishwakarma
Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla,
Jassi Brar, linux-arm-msm, linux-kernel
On Tue, Oct 06, 2026 at 02:44:13PM +0530, Anup Vishwakarma wrote:
> Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
Avoid sending cover-letter if there is nothing in it.
> ---
> Anup Vishwakarma (2):
> mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure
> mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure
>
> drivers/mailbox/arm_mhu_db.c | 8 +++-----
> drivers/mailbox/qcom-ipcc.c | 2 --
> 2 files changed, 3 insertions(+), 7 deletions(-)
> ---
> base-commit: bf1ee2bd5c2da8992f33c8950ef194aaff74ed6c
> change-id: 20261006-b4-mbox_double_unregister_fix-42d5057d3ad5
>
> Best regards,
> --
> Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
>
--
-Mukesh Ojha
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 1/2] mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure
2026-10-06 9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma
@ 2026-10-06 9:35 ` Mukesh Ojha
0 siblings, 0 replies; 7+ messages in thread
From: Mukesh Ojha @ 2026-10-06 9:35 UTC (permalink / raw)
To: Anup Vishwakarma
Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla,
Jassi Brar, linux-arm-msm, linux-kernel
On Tue, Oct 06, 2026 at 02:44:14PM +0530, Anup Vishwakarma wrote:
> qcom_ipcc_probe() registers the mailbox controller via
> devm_mbox_controller_register(), which automatically calls
> mbox_controller_unregister() through devres when the device is removed
> or probe fails. If devm_request_irq() subsequently fails, the
> err_req_irq: label also manually calls mbox_controller_unregister(),
> resulting in a double call that corrupts the global mailbox controller
> list and causes a kernel panic.
>
> Remove the redundant manual call and rely on devres for cleanup.
>
> Fixes: e9d50e4b4d04 ("mailbox: qcom-ipcc: Dynamic alloc for channel arrangement")
> Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
> ---
> drivers/mailbox/qcom-ipcc.c | 2 --
> 1 file changed, 2 deletions(-)
>
> diff --git a/drivers/mailbox/qcom-ipcc.c b/drivers/mailbox/qcom-ipcc.c
> index 185b63f724d4..206ad4884987 100644
> --- a/drivers/mailbox/qcom-ipcc.c
> +++ b/drivers/mailbox/qcom-ipcc.c
> @@ -336,8 +336,6 @@ static int qcom_ipcc_probe(struct platform_device *pdev)
> return 0;
>
> err_req_irq:
Get rid of label as well..
> - if (ipcc->num_chans)
> - mbox_controller_unregister(&ipcc->mbox);
> err_mbox:
> irq_domain_remove(ipcc->irq_domain);
>
>
with the above fix..
Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
--
-Mukesh Ojha
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 2/2] mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure
2026-10-06 9:30 ` Mukesh Ojha
@ 2026-10-06 11:33 ` Anup Vishwakarma
0 siblings, 0 replies; 7+ messages in thread
From: Anup Vishwakarma @ 2026-10-06 11:33 UTC (permalink / raw)
To: Mukesh Ojha
Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla,
Jassi Brar, linux-arm-msm, linux-kernel
On 10/6/2026 3:00 PM, Mukesh Ojha wrote:
> On Tue, Oct 06, 2026 at 02:44:15PM +0530, Anup Vishwakarma wrote:
>> mhu_db_probe() registers the mailbox controller via
>> devm_mbox_controller_register(), which automatically calls
>> mbox_controller_unregister() through devres when the device is removed
>> or probe fails. If devm_request_threaded_irq() subsequently fails in
>> the channel setup loop, the error path also manually calls
>> mbox_controller_unregister(), resulting in a double call that corrupts
>> the global mailbox controller list and causes a kernel panic.
>>
>> Remove the redundant manual call and rely on devres for cleanup.
>>
>> Fixes: 7002ca237b21 ("mailbox: arm_mhu: Add ARM MHU doorbell driver")
>> Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
>> ---
>> drivers/mailbox/arm_mhu_db.c | 8 +++-----
>> 1 file changed, 3 insertions(+), 5 deletions(-)
>>
>> diff --git a/drivers/mailbox/arm_mhu_db.c b/drivers/mailbox/arm_mhu_db.c
>> index a39239e38a47..9668dfdedc78 100644
>> --- a/drivers/mailbox/arm_mhu_db.c
>> +++ b/drivers/mailbox/arm_mhu_db.c
>> @@ -315,12 +315,10 @@ static int mhu_db_probe(struct amba_device *adev, const struct amba_id *id)
>> mhu->mlink[i].tx_reg = mhu->mlink[i].rx_reg + TX_REG_OFFSET;
>>
>> err = devm_request_threaded_irq(dev, irq, NULL,
>> - mhu_db_mbox_rx_handler,
>> - IRQF_ONESHOT, "mhu_db_link", mhu);
>> - if (err) {
>> - mbox_controller_unregister(&mhu->mbox);
>> + mhu_db_mbox_rx_handler,
>> + IRQF_ONESHOT, "mhu_db_link", mhu);
> It looks like alignment/indentation is unnecessary changing.
>
>> + if (err)
>> return err;
>> - }
>> }
> with the above fix.
>
> Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Thanks for the review, Mukesh. Addressed both comments in v2: - Removed
the now-empty err_req_irq: label in qcom-ipcc.c - Restored original
alignment of devm_request_threaded_irq() arguments in arm_mhu_db.c
Best Regards, Anup Vishwakarma
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-10-06 11:33 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06 9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma
2026-10-06 9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma
2026-10-06 9:35 ` Mukesh Ojha
2026-10-06 9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma
2026-10-06 9:30 ` Mukesh Ojha
2026-10-06 11:33 ` Anup Vishwakarma
2026-10-06 9:31 ` [PATCH 0/2] mailbox: " Mukesh Ojha
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®