Re: [PATCH 2/2] mailbox: arm_mhu_db: Remove redundant mbox_controller_unregister() on probe failure

From: Anup Vishwakarma

Date: Tue Oct 06 2026 - 07:34:12 EST



On 10/6/2026 3:00 PM, Mukesh Ojha wrote:
On Tue, Oct 06, 2026 at 02:44:15PM +0530, Anup Vishwakarma wrote:
mhu_db_probe() registers the mailbox controller via
devm_mbox_controller_register(), which automatically calls
mbox_controller_unregister() through devres when the device is removed
or probe fails. If devm_request_threaded_irq() subsequently fails in
the channel setup loop, the error path also manually calls
mbox_controller_unregister(), resulting in a double call that corrupts
the global mailbox controller list and causes a kernel panic.

Remove the redundant manual call and rely on devres for cleanup.

Fixes: 7002ca237b21 ("mailbox: arm_mhu: Add ARM MHU doorbell driver")
Signed-off-by: Anup Vishwakarma <anup.vishwakarma@xxxxxxxxxxxxxxxx>
---
drivers/mailbox/arm_mhu_db.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)

diff --git a/drivers/mailbox/arm_mhu_db.c b/drivers/mailbox/arm_mhu_db.c
index a39239e38a47..9668dfdedc78 100644
--- a/drivers/mailbox/arm_mhu_db.c
+++ b/drivers/mailbox/arm_mhu_db.c
@@ -315,12 +315,10 @@ static int mhu_db_probe(struct amba_device *adev, const struct amba_id *id)
mhu->mlink[i].tx_reg = mhu->mlink[i].rx_reg + TX_REG_OFFSET;
err = devm_request_threaded_irq(dev, irq, NULL,
- mhu_db_mbox_rx_handler,
- IRQF_ONESHOT, "mhu_db_link", mhu);
- if (err) {
- mbox_controller_unregister(&mhu->mbox);
+ mhu_db_mbox_rx_handler,
+ IRQF_ONESHOT, "mhu_db_link", mhu);
It looks like alignment/indentation is unnecessary changing.

+ if (err)
return err;
- }
}
with the above fix.

Reviewed-by: Mukesh Ojha <mukesh.ojha@xxxxxxxxxxxxxxxx>

Thanks for the review, Mukesh. Addressed both comments in v2: - Removed the now-empty err_req_irq: label in qcom-ipcc.c - Restored original alignment of devm_request_threaded_irq() arguments in arm_mhu_db.c

Best Regards, Anup Vishwakarma