accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer

The management mailbox channel cleanup helpers can be called from
error handling paths when mgmt_chann has already been destroyed.

Add NULL checks to xdna_mailbox_free_channel() and
xdna_mailbox_stop_channel() so the cleanup path safely returns instead
of dereferencing a NULL mailbox channel pointer.

Fixes: b87f920b93 ("accel/amdxdna: Support hardware mailbox")
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Max Zhen <max.zhen@amd.com>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260416201106.1046072-1-lizhi.hou@amd.com
This commit is contained in:
Max Zhen 2026-04-16 13:11:06 -07:00 committed by Lizhi Hou
parent d8c33b9c4b
commit 506255d46b

View File

@ -496,6 +496,9 @@ struct mailbox_channel *xdna_mailbox_alloc_channel(struct mailbox *mb)
void xdna_mailbox_free_channel(struct mailbox_channel *mb_chann)
{
if (!mb_chann)
return;
destroy_workqueue(mb_chann->work_q);
kfree(mb_chann);
}
@ -542,6 +545,9 @@ void xdna_mailbox_stop_channel(struct mailbox_channel *mb_chann)
struct mailbox_msg *mb_msg;
unsigned long msg_id;
if (!mb_chann)
return;
/* Disable an irq and wait. This might sleep. */
free_irq(mb_chann->msix_irq, mb_chann);