* [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure
@ 2026-10-06 9:14 Anup Vishwakarma
2026-10-06 9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma
` (2 more replies)
0 siblings, 3 replies; 7+ messages in thread
From: Anup Vishwakarma @ 2026-10-06 9:14 UTC (permalink / raw)
To: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla
Cc: Jassi Brar, linux-arm-msm, linux-kernel, Anup Vishwakarma
Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
---
Anup Vishwakarma (2):
mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure
mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure
drivers/mailbox/arm_mhu_db.c | 8 +++-----
drivers/mailbox/qcom-ipcc.c | 2 --
2 files changed, 3 insertions(+), 7 deletions(-)
---
base-commit: bf1ee2bd5c2da8992f33c8950ef194aaff74ed6c
change-id: 20261006-b4-mbox_double_unregister_fix-42d5057d3ad5
Best regards,
--
Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 7+ messages in thread* [PATCH 1/2] mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure 2026-10-06 9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma @ 2026-10-06 9:14 ` Anup Vishwakarma 2026-10-06 9:35 ` Mukesh Ojha 2026-10-06 9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma 2026-10-06 9:31 ` [PATCH 0/2] mailbox: " Mukesh Ojha 2 siblings, 1 reply; 7+ messages in thread From: Anup Vishwakarma @ 2026-10-06 9:14 UTC (permalink / raw) To: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla Cc: Jassi Brar, linux-arm-msm, linux-kernel, Anup Vishwakarma qcom_ipcc_probe() registers the mailbox controller via devm_mbox_controller_register(), which automatically calls mbox_controller_unregister() through devres when the device is removed or probe fails. If devm_request_irq() subsequently fails, the err_req_irq: label also manually calls mbox_controller_unregister(), resulting in a double call that corrupts the global mailbox controller list and causes a kernel panic. Remove the redundant manual call and rely on devres for cleanup. Fixes: e9d50e4b4d04 ("mailbox: qcom-ipcc: Dynamic alloc for channel arrangement") Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com> --- drivers/mailbox/qcom-ipcc.c | 2 -- 1 file changed, 2 deletions(-) diff --git a/drivers/mailbox/qcom-ipcc.c b/drivers/mailbox/qcom-ipcc.c index 185b63f724d4..206ad4884987 100644 --- a/drivers/mailbox/qcom-ipcc.c +++ b/drivers/mailbox/qcom-ipcc.c @@ -336,8 +336,6 @@ static int qcom_ipcc_probe(struct platform_device *pdev) return 0; err_req_irq: - if (ipcc->num_chans) - mbox_controller_unregister(&ipcc->mbox); err_mbox: irq_domain_remove(ipcc->irq_domain); -- 2.43.0 ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 1/2] mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure 2026-10-06 9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma @ 2026-10-06 9:35 ` Mukesh Ojha 0 siblings, 0 replies; 7+ messages in thread From: Mukesh Ojha @ 2026-10-06 9:35 UTC (permalink / raw) To: Anup Vishwakarma Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla, Jassi Brar, linux-arm-msm, linux-kernel On Tue, Oct 06, 2026 at 02:44:14PM +0530, Anup Vishwakarma wrote: > qcom_ipcc_probe() registers the mailbox controller via > devm_mbox_controller_register(), which automatically calls > mbox_controller_unregister() through devres when the device is removed > or probe fails. If devm_request_irq() subsequently fails, the > err_req_irq: label also manually calls mbox_controller_unregister(), > resulting in a double call that corrupts the global mailbox controller > list and causes a kernel panic. > > Remove the redundant manual call and rely on devres for cleanup. > > Fixes: e9d50e4b4d04 ("mailbox: qcom-ipcc: Dynamic alloc for channel arrangement") > Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com> > --- > drivers/mailbox/qcom-ipcc.c | 2 -- > 1 file changed, 2 deletions(-) > > diff --git a/drivers/mailbox/qcom-ipcc.c b/drivers/mailbox/qcom-ipcc.c > index 185b63f724d4..206ad4884987 100644 > --- a/drivers/mailbox/qcom-ipcc.c > +++ b/drivers/mailbox/qcom-ipcc.c > @@ -336,8 +336,6 @@ static int qcom_ipcc_probe(struct platform_device *pdev) > return 0; > > err_req_irq: Get rid of label as well.. > - if (ipcc->num_chans) > - mbox_controller_unregister(&ipcc->mbox); > err_mbox: > irq_domain_remove(ipcc->irq_domain); > > with the above fix.. Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com> -- -Mukesh Ojha ^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH 2/2] mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure 2026-10-06 9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma 2026-10-06 9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma @ 2026-10-06 9:14 ` Anup Vishwakarma 2026-10-06 9:30 ` Mukesh Ojha 2026-10-06 9:31 ` [PATCH 0/2] mailbox: " Mukesh Ojha 2 siblings, 1 reply; 7+ messages in thread From: Anup Vishwakarma @ 2026-10-06 9:14 UTC (permalink / raw) To: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla Cc: Jassi Brar, linux-arm-msm, linux-kernel, Anup Vishwakarma mhu_db_probe() registers the mailbox controller via devm_mbox_controller_register(), which automatically calls mbox_controller_unregister() through devres when the device is removed or probe fails. If devm_request_threaded_irq() subsequently fails in the channel setup loop, the error path also manually calls mbox_controller_unregister(), resulting in a double call that corrupts the global mailbox controller list and causes a kernel panic. Remove the redundant manual call and rely on devres for cleanup. Fixes: 7002ca237b21 ("mailbox: arm_mhu: Add ARM MHU doorbell driver") Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com> --- drivers/mailbox/arm_mhu_db.c | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/drivers/mailbox/arm_mhu_db.c b/drivers/mailbox/arm_mhu_db.c index a39239e38a47..9668dfdedc78 100644 --- a/drivers/mailbox/arm_mhu_db.c +++ b/drivers/mailbox/arm_mhu_db.c @@ -315,12 +315,10 @@ static int mhu_db_probe(struct amba_device *adev, const struct amba_id *id) mhu->mlink[i].tx_reg = mhu->mlink[i].rx_reg + TX_REG_OFFSET; err = devm_request_threaded_irq(dev, irq, NULL, - mhu_db_mbox_rx_handler, - IRQF_ONESHOT, "mhu_db_link", mhu); - if (err) { - mbox_controller_unregister(&mhu->mbox); + mhu_db_mbox_rx_handler, + IRQF_ONESHOT, "mhu_db_link", mhu); + if (err) return err; - } } dev_info(dev, "ARM MHU Doorbell mailbox registered\n"); -- 2.43.0 ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 2/2] mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure 2026-10-06 9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma @ 2026-10-06 9:30 ` Mukesh Ojha 2026-10-06 11:33 ` Anup Vishwakarma 0 siblings, 1 reply; 7+ messages in thread From: Mukesh Ojha @ 2026-10-06 9:30 UTC (permalink / raw) To: Anup Vishwakarma Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla, Jassi Brar, linux-arm-msm, linux-kernel On Tue, Oct 06, 2026 at 02:44:15PM +0530, Anup Vishwakarma wrote: > mhu_db_probe() registers the mailbox controller via > devm_mbox_controller_register(), which automatically calls > mbox_controller_unregister() through devres when the device is removed > or probe fails. If devm_request_threaded_irq() subsequently fails in > the channel setup loop, the error path also manually calls > mbox_controller_unregister(), resulting in a double call that corrupts > the global mailbox controller list and causes a kernel panic. > > Remove the redundant manual call and rely on devres for cleanup. > > Fixes: 7002ca237b21 ("mailbox: arm_mhu: Add ARM MHU doorbell driver") > Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com> > --- > drivers/mailbox/arm_mhu_db.c | 8 +++----- > 1 file changed, 3 insertions(+), 5 deletions(-) > > diff --git a/drivers/mailbox/arm_mhu_db.c b/drivers/mailbox/arm_mhu_db.c > index a39239e38a47..9668dfdedc78 100644 > --- a/drivers/mailbox/arm_mhu_db.c > +++ b/drivers/mailbox/arm_mhu_db.c > @@ -315,12 +315,10 @@ static int mhu_db_probe(struct amba_device *adev, const struct amba_id *id) > mhu->mlink[i].tx_reg = mhu->mlink[i].rx_reg + TX_REG_OFFSET; > > err = devm_request_threaded_irq(dev, irq, NULL, > - mhu_db_mbox_rx_handler, > - IRQF_ONESHOT, "mhu_db_link", mhu); > - if (err) { > - mbox_controller_unregister(&mhu->mbox); > + mhu_db_mbox_rx_handler, > + IRQF_ONESHOT, "mhu_db_link", mhu); It looks like alignment/indentation is unnecessary changing. > + if (err) > return err; > - } > } with the above fix. Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com> -- -Mukesh Ojha ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 2/2] mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure 2026-10-06 9:30 ` Mukesh Ojha @ 2026-10-06 11:33 ` Anup Vishwakarma 0 siblings, 0 replies; 7+ messages in thread From: Anup Vishwakarma @ 2026-10-06 11:33 UTC (permalink / raw) To: Mukesh Ojha Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla, Jassi Brar, linux-arm-msm, linux-kernel On 10/6/2026 3:00 PM, Mukesh Ojha wrote: > On Tue, Oct 06, 2026 at 02:44:15PM +0530, Anup Vishwakarma wrote: >> mhu_db_probe() registers the mailbox controller via >> devm_mbox_controller_register(), which automatically calls >> mbox_controller_unregister() through devres when the device is removed >> or probe fails. If devm_request_threaded_irq() subsequently fails in >> the channel setup loop, the error path also manually calls >> mbox_controller_unregister(), resulting in a double call that corrupts >> the global mailbox controller list and causes a kernel panic. >> >> Remove the redundant manual call and rely on devres for cleanup. >> >> Fixes: 7002ca237b21 ("mailbox: arm_mhu: Add ARM MHU doorbell driver") >> Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com> >> --- >> drivers/mailbox/arm_mhu_db.c | 8 +++----- >> 1 file changed, 3 insertions(+), 5 deletions(-) >> >> diff --git a/drivers/mailbox/arm_mhu_db.c b/drivers/mailbox/arm_mhu_db.c >> index a39239e38a47..9668dfdedc78 100644 >> --- a/drivers/mailbox/arm_mhu_db.c >> +++ b/drivers/mailbox/arm_mhu_db.c >> @@ -315,12 +315,10 @@ static int mhu_db_probe(struct amba_device *adev, const struct amba_id *id) >> mhu->mlink[i].tx_reg = mhu->mlink[i].rx_reg + TX_REG_OFFSET; >> >> err = devm_request_threaded_irq(dev, irq, NULL, >> - mhu_db_mbox_rx_handler, >> - IRQF_ONESHOT, "mhu_db_link", mhu); >> - if (err) { >> - mbox_controller_unregister(&mhu->mbox); >> + mhu_db_mbox_rx_handler, >> + IRQF_ONESHOT, "mhu_db_link", mhu); > It looks like alignment/indentation is unnecessary changing. > >> + if (err) >> return err; >> - } >> } > with the above fix. > > Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com> Thanks for the review, Mukesh. Addressed both comments in v2: - Removed the now-empty err_req_irq: label in qcom-ipcc.c - Restored original alignment of devm_request_threaded_irq() arguments in arm_mhu_db.c Best Regards, Anup Vishwakarma ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure 2026-10-06 9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma 2026-10-06 9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma 2026-10-06 9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma @ 2026-10-06 9:31 ` Mukesh Ojha 2 siblings, 0 replies; 7+ messages in thread From: Mukesh Ojha @ 2026-10-06 9:31 UTC (permalink / raw) To: Anup Vishwakarma Cc: Manivannan Sadhasivam, Jassi Brar, Huang Yiwei, Sudeep Holla, Jassi Brar, linux-arm-msm, linux-kernel On Tue, Oct 06, 2026 at 02:44:13PM +0530, Anup Vishwakarma wrote: > Signed-off-by: Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com> Avoid sending cover-letter if there is nothing in it. > --- > Anup Vishwakarma (2): > mailbox: qcom-ipcc: Remove redundant mbox_controller_unregister() on probe failure > mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure > > drivers/mailbox/arm_mhu_db.c | 8 +++----- > drivers/mailbox/qcom-ipcc.c | 2 -- > 2 files changed, 3 insertions(+), 7 deletions(-) > --- > base-commit: bf1ee2bd5c2da8992f33c8950ef194aaff74ed6c > change-id: 20261006-b4-mbox_double_unregister_fix-42d5057d3ad5 > > Best regards, > -- > Anup Vishwakarma <anup.vishwakarma@oss.qualcomm.com> > -- -Mukesh Ojha ^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-10-06 11:33 UTC | newest] Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2026-10-06 9:14 [PATCH 0/2] mailbox: Remove redundant mbox_controller_unregister() on probe failure Anup Vishwakarma 2026-10-06 9:14 ` [PATCH 1/2] mailbox: qcom-ipcc: " Anup Vishwakarma 2026-10-06 9:35 ` Mukesh Ojha 2026-10-06 9:14 ` [PATCH 2/2] mailbox: arm_mhu_db: " Anup Vishwakarma 2026-10-06 9:30 ` Mukesh Ojha 2026-10-06 11:33 ` Anup Vishwakarma 2026-10-06 9:31 ` [PATCH 0/2] mailbox: " Mukesh Ojha
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®