Re: [PATCH 2/2] mailbox: qcom-cpucp: handle NULL data in send_data callback

Konrad Dybcio <[email protected]>
Newsgroups dev.linux.lists.linux-rt-devel,org.kernel.vger.linux-arm-msm,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On 8/6/26 9:03 AM, Jia Yang wrote:
> mailbox_clear_channel() calls mbox_send_message() with NULL data to
> notify the remote side that the RX channel has been cleared.
> qcom_cpucp_mbox_send_data() blindly dereferenced the data pointer,
> causing a NULL pointer dereference kernel panic when invoked from
> this path under PREEMPT_RT.
> 
> Add an explicit NULL check and return early without writing to the
> TX register, which is the correct behaviour for a channel-clear
> notification.
> 
> Fixes: 0e2a9a03106c ("mailbox: Add support for QTI CPUCP mailbox controller")
> Signed-off-by: Jia Yang <[email protected]>
> ---
>  drivers/mailbox/qcom-cpucp-mbox.c | 8 ++++++++
>  1 file changed, 8 insertions(+)
> 
> diff --git a/drivers/mailbox/qcom-cpucp-mbox.c b/drivers/mailbox/qcom-cpucp-mbox.c
> index 0f7fe189e8b1..298b357c0f9a 100644
> --- a/drivers/mailbox/qcom-cpucp-mbox.c
> +++ b/drivers/mailbox/qcom-cpucp-mbox.c
> @@ -117,6 +117,14 @@ static int qcom_cpucp_mbox_send_data(struct mbox_chan *chan, void *data)
>  	unsigned long chan_id = channel_number(chan);
>  	u32 *val = data;
>  
> +	/*
> +	 * mailbox_clear_channel() calls mbox_send_message() with NULL data to
> +	 * signal the remote side that the channel has been cleared.  Nothing
> +	 * needs to be written to the TX register in that case, so just return.
> +	 */
> +	if (!val)
> +		return 0;

Is this a bug in the scmi driver itself? Is a message with val=0 valid
as far as our mailbox is concerned?

Konrad
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.