mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure
@ 2026-10-06  9:14 Anup Vishwakarma
  2026-10-06  9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma
                   ` (2 more replies)
  0 siblings, 3 replies; 7+ messages in thread
From: Anup Vishwakarma @ 2026-10-06  9:14 UTC (permalink / raw)
  To: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla
  Cc: Jassi Brar, linux-arm-msm, linux-kernel, Anup Vishwakarma

Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
---
Anup Vishwakarma (2):
      mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure
      mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure

 drivers/mailbox/arm_mhu_db.c | 8 +++-----
 drivers/mailbox/qcom-ipcc.c  | 2 --
 2 files changed, 3 insertions(+), 7 deletions(-)
---
base-commit: bf1ee2bd5c2da8992f33c8950ef194aaff74ed6c
change-id: 20261006-b4-mbox_double_unregister_fix-42d5057d3ad5

Best regards,
--  
Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>


^ permalink raw reply	[flat|nested] 7+ messages in thread

* [PATCH 1/2] mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure
  2026-10-06  9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma
@ 2026-10-06  9:14 ` Anup Vishwakarma
  2026-10-06  9:35   ` Mukesh Ojha
  2026-10-06  9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma
  2026-10-06  9:31 ` [PATCH 0/2] mailbox: " Mukesh Ojha
  2 siblings, 1 reply; 7+ messages in thread
From: Anup Vishwakarma @ 2026-10-06  9:14 UTC (permalink / raw)
  To: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla
  Cc: Jassi Brar, linux-arm-msm, linux-kernel, Anup Vishwakarma

qcom_ipcc_probe() registers the mailbox controller via
devm_mbox_controller_register(), which automatically calls
mbox_controller_unregister() through devres when the device is removed
or probe fails. If devm_request_irq() subsequently fails, the
err_req_irq: label also manually calls mbox_controller_unregister(),
resulting in a double call that corrupts the global mailbox controller
list and causes a kernel panic.

Remove the redundant manual call and rely on devres for cleanup.

Fixes: e9d50e4b4d04 ("mailbox: qcom-ipcc: Dynamic alloc for channel arrangement")
Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
---
 drivers/mailbox/qcom-ipcc.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/drivers/mailbox/qcom-ipcc.c b/drivers/mailbox/qcom-ipcc.c
index 185b63f724d4..206ad4884987 100644
--- a/drivers/mailbox/qcom-ipcc.c
+++ b/drivers/mailbox/qcom-ipcc.c
@@ -336,8 +336,6 @@ static int qcom_ipcc_probe(struct platform_device *pdev)
 	return 0;
 
 err_req_irq:
-	if (ipcc->num_chans)
-		mbox_controller_unregister(&ipcc->mbox);
 err_mbox:
 	irq_domain_remove(ipcc->irq_domain);
 

-- 
2.43.0


^ permalink raw reply	[flat|nested] 7+ messages in thread

* [PATCH 2/2] mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure
  2026-10-06  9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma
  2026-10-06  9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma
@ 2026-10-06  9:14 ` Anup Vishwakarma
  2026-10-06  9:30   ` Mukesh Ojha
  2026-10-06  9:31 ` [PATCH 0/2] mailbox: " Mukesh Ojha
  2 siblings, 1 reply; 7+ messages in thread
From: Anup Vishwakarma @ 2026-10-06  9:14 UTC (permalink / raw)
  To: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla
  Cc: Jassi Brar, linux-arm-msm, linux-kernel, Anup Vishwakarma

mhu_db_probe() registers the mailbox controller via
devm_mbox_controller_register(), which automatically calls
mbox_controller_unregister() through devres when the device is removed
or probe fails. If devm_request_threaded_irq() subsequently fails in
the channel setup loop, the error path also manually calls
mbox_controller_unregister(), resulting in a double call that corrupts
the global mailbox controller list and causes a kernel panic.

Remove the redundant manual call and rely on devres for cleanup.

Fixes: 7002ca237b21 ("mailbox: arm_mhu: Add ARM MHU doorbell driver")
Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
---
 drivers/mailbox/arm_mhu_db.c | 8 +++-----
 1 file changed, 3 insertions(+), 5 deletions(-)

diff --git a/drivers/mailbox/arm_mhu_db.c b/drivers/mailbox/arm_mhu_db.c
index a39239e38a47..9668dfdedc78 100644
--- a/drivers/mailbox/arm_mhu_db.c
+++ b/drivers/mailbox/arm_mhu_db.c
@@ -315,12 +315,10 @@ static int mhu_db_probe(struct amba_device *adev, const struct amba_id *id)
 		mhu->mlink[i].tx_reg = mhu->mlink[i].rx_reg + TX_REG_OFFSET;
 
 		err = devm_request_threaded_irq(dev, irq, NULL,
-						mhu_db_mbox_rx_handler,
-						IRQF_ONESHOT, "mhu_db_link", mhu);
-		if (err) {
-			mbox_controller_unregister(&mhu->mbox);
+					mhu_db_mbox_rx_handler,
+					IRQF_ONESHOT, "mhu_db_link", mhu);
+		if (err)
 			return err;
-		}
 	}
 
 	dev_info(dev, "ARM MHU Doorbell mailbox registered\n");

-- 
2.43.0


^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 2/2] mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure
  2026-10-06  9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma
@ 2026-10-06  9:30   ` Mukesh Ojha
  2026-10-06 11:33     ` Anup Vishwakarma
  0 siblings, 1 reply; 7+ messages in thread
From: Mukesh Ojha @ 2026-10-06  9:30 UTC (permalink / raw)
  To: Anup Vishwakarma
  Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla,
	Jassi Brar, linux-arm-msm, linux-kernel

On Tue, Oct 06, 2026 at 02:44:15PM +0530, Anup Vishwakarma wrote:
> mhu_db_probe() registers the mailbox controller via
> devm_mbox_controller_register(), which automatically calls
> mbox_controller_unregister() through devres when the device is removed
> or probe fails. If devm_request_threaded_irq() subsequently fails in
> the channel setup loop, the error path also manually calls
> mbox_controller_unregister(), resulting in a double call that corrupts
> the global mailbox controller list and causes a kernel panic.
> 
> Remove the redundant manual call and rely on devres for cleanup.
> 
> Fixes: 7002ca237b21 ("mailbox: arm_mhu: Add ARM MHU doorbell driver")
> Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
> ---
>  drivers/mailbox/arm_mhu_db.c | 8 +++-----
>  1 file changed, 3 insertions(+), 5 deletions(-)
> 
> diff --git a/drivers/mailbox/arm_mhu_db.c b/drivers/mailbox/arm_mhu_db.c
> index a39239e38a47..9668dfdedc78 100644
> --- a/drivers/mailbox/arm_mhu_db.c
> +++ b/drivers/mailbox/arm_mhu_db.c
> @@ -315,12 +315,10 @@ static int mhu_db_probe(struct amba_device *adev, const struct amba_id *id)
>  		mhu->mlink[i].tx_reg = mhu->mlink[i].rx_reg + TX_REG_OFFSET;
>  
>  		err = devm_request_threaded_irq(dev, irq, NULL,
> -						mhu_db_mbox_rx_handler,
> -						IRQF_ONESHOT, "mhu_db_link", mhu);
> -		if (err) {
> -			mbox_controller_unregister(&mhu->mbox);
> +					mhu_db_mbox_rx_handler,
> +					IRQF_ONESHOT, "mhu_db_link", mhu);

It looks like alignment/indentation is unnecessary changing.

> +		if (err)
>  			return err;
> -		}
>  	}

with the above fix.

Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>

-- 
-Mukesh Ojha

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure
  2026-10-06  9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma
  2026-10-06  9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma
  2026-10-06  9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma
@ 2026-10-06  9:31 ` Mukesh Ojha
  2 siblings, 0 replies; 7+ messages in thread
From: Mukesh Ojha @ 2026-10-06  9:31 UTC (permalink / raw)
  To: Anup Vishwakarma
  Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla,
	Jassi Brar, linux-arm-msm, linux-kernel

On Tue, Oct 06, 2026 at 02:44:13PM +0530, Anup Vishwakarma wrote:
> Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>


Avoid sending cover-letter if there is nothing in it.

> ---
> Anup Vishwakarma (2):
>       mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure
>       mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure
> 
>  drivers/mailbox/arm_mhu_db.c | 8 +++-----
>  drivers/mailbox/qcom-ipcc.c  | 2 --
>  2 files changed, 3 insertions(+), 7 deletions(-)
> ---
> base-commit: bf1ee2bd5c2da8992f33c8950ef194aaff74ed6c
> change-id: 20261006-b4-mbox_double_unregister_fix-42d5057d3ad5
> 
> Best regards,
> --  
> Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
> 

-- 
-Mukesh Ojha

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 1/2] mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure
  2026-10-06  9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma
@ 2026-10-06  9:35   ` Mukesh Ojha
  0 siblings, 0 replies; 7+ messages in thread
From: Mukesh Ojha @ 2026-10-06  9:35 UTC (permalink / raw)
  To: Anup Vishwakarma
  Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla,
	Jassi Brar, linux-arm-msm, linux-kernel

On Tue, Oct 06, 2026 at 02:44:14PM +0530, Anup Vishwakarma wrote:
> qcom_ipcc_probe() registers the mailbox controller via
> devm_mbox_controller_register(), which automatically calls
> mbox_controller_unregister() through devres when the device is removed
> or probe fails. If devm_request_irq() subsequently fails, the
> err_req_irq: label also manually calls mbox_controller_unregister(),
> resulting in a double call that corrupts the global mailbox controller
> list and causes a kernel panic.
> 
> Remove the redundant manual call and rely on devres for cleanup.
> 
> Fixes: e9d50e4b4d04 ("mailbox: qcom-ipcc: Dynamic alloc for channel arrangement")
> Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
> ---
>  drivers/mailbox/qcom-ipcc.c | 2 --
>  1 file changed, 2 deletions(-)
> 
> diff --git a/drivers/mailbox/qcom-ipcc.c b/drivers/mailbox/qcom-ipcc.c
> index 185b63f724d4..206ad4884987 100644
> --- a/drivers/mailbox/qcom-ipcc.c
> +++ b/drivers/mailbox/qcom-ipcc.c
> @@ -336,8 +336,6 @@ static int qcom_ipcc_probe(struct platform_device *pdev)
>  	return 0;
>  
>  err_req_irq:

Get rid of label as well..

> -	if (ipcc->num_chans)
> -		mbox_controller_unregister(&ipcc->mbox);
>  err_mbox:
>  	irq_domain_remove(ipcc->irq_domain);
>  
> 

with the above fix..

Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>

-- 
-Mukesh Ojha

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH 2/2] mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure
  2026-10-06  9:30   ` Mukesh Ojha
@ 2026-10-06 11:33     ` Anup Vishwakarma
  0 siblings, 0 replies; 7+ messages in thread
From: Anup Vishwakarma @ 2026-10-06 11:33 UTC (permalink / raw)
  To: Mukesh Ojha
  Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla,
	Jassi Brar, linux-arm-msm, linux-kernel


On 10/6/2026 3:00 PM, Mukesh Ojha wrote:
> On Tue, Oct 06, 2026 at 02:44:15PM +0530, Anup Vishwakarma wrote:
>> mhu_db_probe() registers the mailbox controller via
>> devm_mbox_controller_register(), which automatically calls
>> mbox_controller_unregister() through devres when the device is removed
>> or probe fails. If devm_request_threaded_irq() subsequently fails in
>> the channel setup loop, the error path also manually calls
>> mbox_controller_unregister(), resulting in a double call that corrupts
>> the global mailbox controller list and causes a kernel panic.
>>
>> Remove the redundant manual call and rely on devres for cleanup.
>>
>> Fixes: 7002ca237b21 ("mailbox: arm_mhu: Add ARM MHU doorbell driver")
>> Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
>> ---
>>   drivers/mailbox/arm_mhu_db.c | 8 +++-----
>>   1 file changed, 3 insertions(+), 5 deletions(-)
>>
>> diff --git a/drivers/mailbox/arm_mhu_db.c b/drivers/mailbox/arm_mhu_db.c
>> index a39239e38a47..9668dfdedc78 100644
>> --- a/drivers/mailbox/arm_mhu_db.c
>> +++ b/drivers/mailbox/arm_mhu_db.c
>> @@ -315,12 +315,10 @@ static int mhu_db_probe(struct amba_device *adev, const struct amba_id *id)
>>   		mhu->mlink[i].tx_reg = mhu->mlink[i].rx_reg + TX_REG_OFFSET;
>>   
>>   		err = devm_request_threaded_irq(dev, irq, NULL,
>> -						mhu_db_mbox_rx_handler,
>> -						IRQF_ONESHOT, "mhu_db_link", mhu);
>> -		if (err) {
>> -			mbox_controller_unregister(&mhu->mbox);
>> +					mhu_db_mbox_rx_handler,
>> +					IRQF_ONESHOT, "mhu_db_link", mhu);
> It looks like alignment/indentation is unnecessary changing.
>
>> +		if (err)
>>   			return err;
>> -		}
>>   	}
> with the above fix.
>
> Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>

Thanks for the review, Mukesh. Addressed both comments in v2: - Removed 
the now-empty err_req_irq: label in qcom-ipcc.c - Restored original 
alignment of devm_request_threaded_irq() arguments in arm_mhu_db.c

Best Regards, Anup Vishwakarma


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-10-06 11:33 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06  9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma
2026-10-06  9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma
2026-10-06  9:35   ` Mukesh Ojha
2026-10-06  9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma
2026-10-06  9:30   ` Mukesh Ojha
2026-10-06 11:33     ` Anup Vishwakarma
2026-10-06  9:31 ` [PATCH 0/2] mailbox: " Mukesh Ojha

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®