[PATCH 0/2] mailbox: qcom-cpucp: fix two PREEMPT_RT bugs in IRQ handler
From: Jia Yang
Date: Thu Aug 06 2026 - 03:06:29 EST
This series fixes two bugs in the qcom-cpucp mailbox driver that cause
kernel instability under PREEMPT_RT.
The first patch fixes a self-deadlock: the IRQ handler calls
mbox_chan_received_data() while holding chan->lock. Under PREEMPT_RT,
spin_lock_irqsave() is converted to an rt_spinlock (rtmutex-based). The
callback chain triggered by mbox_chan_received_data() re-acquires the
same lock, causing a permanent deadlock. The fix moves the callback
invocation to after the lock is released.
The second patch fixes a NULL pointer dereference that was masked by
the first bug: mailbox_clear_channel() calls mbox_send_message() with
NULL data, and qcom_cpucp_mbox_send_data() dereferences it without a
NULL check.
Both bugs were reproduced on Kaanapali (SM8850) with CONFIG_PREEMPT_RT=y.
Signed-off-by: Jia Yang <jia.yang@xxxxxxxxxxxxxxxx>
---
Jia Yang (2):
mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler
mailbox: qcom-cpucp: handle NULL data in send_data callback
drivers/mailbox/qcom-cpucp-mbox.c | 25 ++++++++++++++++++++++---
1 file changed, 22 insertions(+), 3 deletions(-)
---
base-commit: 3df25501ceec0d590d3ad416b571563beb364fb7
change-id: 20260806-mailbox-qcom-cpucp-preempt-rt-fix-36472b46a378
Best regards,
--
Jia Yang <jia.yang@xxxxxxxxxxxxxxxx>