From a05adbb9b30115ef7d04668d35650f311458dd2d Mon Sep 17 00:00:00 2001 From: Jamie Gibbons Date: Mon, 18 May 2026 15:17:09 +0100 Subject: [PATCH 1/4] mailbox: mpfs-mbox: fix MMIO mapping calculation Correct the MMIO mapping size calculation, which previously relied on an invalid start/end subtraction. This change corrects a functional bug and cleans up the driver without altering its behavior. Fixes: 111e9bf6a5ac ("mailbox: add PolarFire SoC mailbox driver") Signed-off-by: Jamie Gibbons Reviewed-by: Conor Dooley --- drivers/mailbox/mpfs-mbox.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/mailbox/mpfs-mbox.c b/drivers/mailbox/mpfs-mbox.c index 55238847ecd..4a9465c7a72 100644 --- a/drivers/mailbox/mpfs-mbox.c +++ b/drivers/mailbox/mpfs-mbox.c @@ -145,7 +145,7 @@ static int mpfs_mbox_probe(struct udevice *dev) return ret; }; - mbox->ctrl_base = devm_ioremap(dev, regs.start, regs.start - regs.end); + mbox->ctrl_base = devm_ioremap(dev, res.start, resource_size(&res)); ret = ofnode_read_resource(node, 2, ®s); if (ret) { @@ -153,7 +153,7 @@ static int mpfs_mbox_probe(struct udevice *dev) return ret; }; - mbox->mbox_base = devm_ioremap(dev, regs.start, regs.start - regs.end); + mbox->mbox_base = devm_ioremap(dev, res.start, resource_size(&res)); mbox->dev = dev; dev_set_priv(dev, mbox); From 1173e02c9880d9f7d1bf15308490493332b03a61 Mon Sep 17 00:00:00 2001 From: Jamie Gibbons Date: Mon, 18 May 2026 15:17:10 +0100 Subject: [PATCH 2/4] mailbox: mpfs-mbox: fix Driver Model private data handling MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The MPFS mailbox driver declares priv_auto but also allocates a second private data structure in the legacy probe path and overwrites the device’s private pointer using dev_set_priv(). This results in leaking the auto-allocated private data and replacing the driver’s private state mid-probe, which is incorrect usage of the U-Boot Driver Model and can lead to undefined behavior. Remove the redundant allocation and dev_set_priv() call so that the driver consistently uses the auto-allocated private data provided by U-Boot. Fixes: 111e9bf6a5ac ("mailbox: add PolarFire SoC mailbox driver") Signed-off-by: Jamie Gibbons Reviewed-by: Conor Dooley --- drivers/mailbox/mpfs-mbox.c | 5 ----- 1 file changed, 5 deletions(-) diff --git a/drivers/mailbox/mpfs-mbox.c b/drivers/mailbox/mpfs-mbox.c index 4a9465c7a72..2e20b08307c 100644 --- a/drivers/mailbox/mpfs-mbox.c +++ b/drivers/mailbox/mpfs-mbox.c @@ -135,10 +135,6 @@ static int mpfs_mbox_probe(struct udevice *dev) node = dev_ofnode(dev); - mbox = devm_kzalloc(dev, sizeof(*mbox), GFP_KERNEL); - if (!mbox) - return -ENOMEM; - ret = ofnode_read_resource(node, 0, ®s); if (ret) { dev_err(dev, "No reg property for controller base\n"); @@ -156,7 +152,6 @@ static int mpfs_mbox_probe(struct udevice *dev) mbox->mbox_base = devm_ioremap(dev, res.start, resource_size(&res)); mbox->dev = dev; - dev_set_priv(dev, mbox); mbox->chan->con_priv = mbox; return 0; From 763435d0e3124539dc36c730c3832a1b4162d3f7 Mon Sep 17 00:00:00 2001 From: Jamie Gibbons Date: Mon, 18 May 2026 15:17:11 +0100 Subject: [PATCH 3/4] mailbox: mpfs-mbox: fix driver bug and cleanup Remove an unused and invalid struct mbox_chan pointer from the private data and fix incorrect memory handling in the probe path, where the private data structure was allocated. This change corrects a functional bugs and cleans up the driver without altering its behavior. Fixes: 111e9bf6a5ac ("mailbox: add PolarFire SoC mailbox driver") Signed-off-by: Jamie Gibbons Reviewed-by: Conor Dooley --- drivers/mailbox/mpfs-mbox.c | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/drivers/mailbox/mpfs-mbox.c b/drivers/mailbox/mpfs-mbox.c index 2e20b08307c..08c51c96718 100644 --- a/drivers/mailbox/mpfs-mbox.c +++ b/drivers/mailbox/mpfs-mbox.c @@ -37,13 +37,12 @@ struct mpfs_mbox { struct udevice *dev; void __iomem *ctrl_base; void __iomem *mbox_base; - struct mbox_chan *chan; }; static bool mpfs_mbox_busy(struct mbox_chan *chan) { struct mpfs_mbox *mbox = dev_get_priv(chan->dev); - uint16_t status; + u32 status; status = readl(mbox->ctrl_base + SERVICES_SR_OFFSET); @@ -152,7 +151,6 @@ static int mpfs_mbox_probe(struct udevice *dev) mbox->mbox_base = devm_ioremap(dev, res.start, resource_size(&res)); mbox->dev = dev; - mbox->chan->con_priv = mbox; return 0; } From 6c128738240d7e3a6020676501ad382af3359f3e Mon Sep 17 00:00:00 2001 From: Jamie Gibbons Date: Mon, 18 May 2026 15:17:12 +0100 Subject: [PATCH 4/4] mailbox: mpfs-mbox: support new syscon based devicetree configuration The original PolarFire SoC mailbox devicetree bindings described the control/status and interrupt registers as standalone reg regions of the mailbox device. This was incorrect, as these registers are shared system control blocks and should instead be modeled as syscon devices. Linux has since corrected this by introducing syscon-based bindings for the MPFS mailbox and updating the mailbox driver to access the control and interrupt registers via syscon/regmap. U-Boot, however, continued to expect the legacy binding, causing mailbox access to fail when using Linux-aligned devicetrees. Update the U-Boot MPFS mailbox driver to support the new syscon-based bindings by resolving the control and sysreg syscon nodes and accessing the registers through regmap. Support for the legacy mailbox binding is retained for backwards compatibility with existing firmware-provided devicetrees. This brings the U-Boot mailbox driver in line with the corrected hardware description and matches the behavior of the Linux mailbox driver. Signed-off-by: Jamie Gibbons Reviewed-by: Conor Dooley --- drivers/mailbox/Kconfig | 2 + drivers/mailbox/mpfs-mbox.c | 99 +++++++++++++++++++++++++++---------- 2 files changed, 74 insertions(+), 27 deletions(-) diff --git a/drivers/mailbox/Kconfig b/drivers/mailbox/Kconfig index f45e611c966..1d9e284cfd1 100644 --- a/drivers/mailbox/Kconfig +++ b/drivers/mailbox/Kconfig @@ -32,6 +32,8 @@ config MPFS_MBOX bool "Enable MPFS system controller support" depends on DM_MAILBOX && ARCH_RV64I select DEVRES + depends on SYSCON + depends on REGMAP help Enable support for the mailboxes that provide a communication channel with the system controller integrated on PolarFire SoC. diff --git a/drivers/mailbox/mpfs-mbox.c b/drivers/mailbox/mpfs-mbox.c index 08c51c96718..b1ce377525e 100644 --- a/drivers/mailbox/mpfs-mbox.c +++ b/drivers/mailbox/mpfs-mbox.c @@ -13,19 +13,21 @@ #include #include #include -#include #include #include #include -#include -#include +#include +#include #include #include -#include #include +#include +#include #define SERVICES_CR_OFFSET 0x50u #define SERVICES_SR_OFFSET 0x54u +#define MESSAGE_INT_OFFSET 0x18cu +#define MAILBOX_REG_OFFSET 0x800u #define SERVICE_CR_REQ_MASK 0x1u #define SERVICE_SR_BUSY_MASK 0x2u @@ -35,8 +37,10 @@ struct mpfs_mbox { struct udevice *dev; - void __iomem *ctrl_base; void __iomem *mbox_base; + void __iomem *int_reg; + struct regmap *control_scb; + struct regmap *sysreg_scb; }; static bool mpfs_mbox_busy(struct mbox_chan *chan) @@ -44,7 +48,7 @@ static bool mpfs_mbox_busy(struct mbox_chan *chan) struct mpfs_mbox *mbox = dev_get_priv(chan->dev); u32 status; - status = readl(mbox->ctrl_base + SERVICES_SR_OFFSET); + regmap_read(mbox->control_scb, SERVICES_SR_OFFSET, &status); return status & SERVICE_SR_BUSY_MASK; } @@ -79,14 +83,15 @@ static int mpfs_mbox_send(struct mbox_chan *chan, const void *data) cmd_shifted = msg->cmd_opcode << SERVICE_CR_COMMAND_SHIFT; cmd_shifted |= SERVICE_CR_REQ_MASK; - writel(cmd_shifted, mbox->ctrl_base + SERVICES_CR_OFFSET); + + regmap_write(mbox->control_scb, SERVICES_CR_OFFSET, cmd_shifted); do { - value = readl(mbox->ctrl_base + SERVICES_CR_OFFSET); + regmap_read(mbox->control_scb, SERVICES_CR_OFFSET, &value); } while (SERVICE_CR_REQ_MASK == (value & SERVICE_CR_REQ_MASK)); do { - value = readl(mbox->ctrl_base + SERVICES_SR_OFFSET); + regmap_read(mbox->control_scb, SERVICES_SR_OFFSET, &value); } while (SERVICE_SR_BUSY_MASK == (value & SERVICE_SR_BUSY_MASK)); msg->response->resp_status = (value >> SERVICE_SR_STATUS_SHIFT); @@ -117,6 +122,11 @@ static int mpfs_mbox_recv(struct mbox_chan *chan, void *data) for (idx = 0; idx < response->resp_size; idx++) *((u8 *)(response->resp_msg) + idx) = readb(mbox->mbox_base + msg->resp_offset + idx); + if (mbox->sysreg_scb) + regmap_write(mbox->sysreg_scb, MESSAGE_INT_OFFSET, 0); + else + writel_relaxed(0, mbox->int_reg); + return 0; } @@ -125,34 +135,69 @@ static const struct mbox_ops mpfs_mbox_ops = { .recv = mpfs_mbox_recv, }; -static int mpfs_mbox_probe(struct udevice *dev) +/* + * Use global compatible lookup instead of phandles, as U-Boot may run + * with a reduced or firmware-provided device tree where mailbox syscon + * phandle properties are not guaranteed to be present. + */ +static int mpfs_mbox_syscon_probe(struct udevice *dev, struct mpfs_mbox *mbox) { - struct mpfs_mbox *mbox; - struct resource regs; ofnode node; + + node = ofnode_by_compatible(ofnode_null(), "microchip,mpfs-control-scb"); + if (!ofnode_valid(node)) + return -ENODEV; + + mbox->control_scb = syscon_node_to_regmap(node); + if (IS_ERR(mbox->control_scb)) + return PTR_ERR(mbox->control_scb); + + node = ofnode_by_compatible(ofnode_null(), "microchip,mpfs-sysreg-scb"); + if (!ofnode_valid(node)) + return -ENODEV; + + mbox->sysreg_scb = syscon_node_to_regmap(node); + if (IS_ERR(mbox->sysreg_scb)) + return PTR_ERR(mbox->sysreg_scb); + + mbox->mbox_base = dev_read_addr_ptr(dev); + if (!mbox->mbox_base) + return -EINVAL; + + return 0; +} + +static int mpfs_mbox_legacy_probe(struct udevice *dev, struct mpfs_mbox *mbox) +{ int ret; - node = dev_ofnode(dev); - - ret = ofnode_read_resource(node, 0, ®s); - if (ret) { - dev_err(dev, "No reg property for controller base\n"); + ret = regmap_init_mem_index(dev_ofnode(dev), &mbox->control_scb, 0); + if (ret) return ret; - }; - mbox->ctrl_base = devm_ioremap(dev, res.start, resource_size(&res)); + mbox->mbox_base = dev_read_addr_index_ptr(dev, 2); + if (!mbox->mbox_base) + mbox->mbox_base = dev_read_addr_index_ptr(dev, 0) + MAILBOX_REG_OFFSET; - ret = ofnode_read_resource(node, 2, ®s); - if (ret) { - dev_err(dev, "No reg property for mailbox base\n"); - return ret; - }; + mbox->int_reg = dev_read_addr_index_ptr(dev, 1); + if (!mbox->int_reg) + return -EINVAL; - mbox->mbox_base = devm_ioremap(dev, res.start, resource_size(&res)); + return 0; +} + +static int mpfs_mbox_probe(struct udevice *dev) +{ + struct mpfs_mbox *mbox = dev_get_priv(dev); + int ret; mbox->dev = dev; - return 0; + ret = mpfs_mbox_syscon_probe(dev, mbox); + if (!ret) + return 0; + + return mpfs_mbox_legacy_probe(dev, mbox); } static const struct udevice_id mpfs_mbox_ids[] = { @@ -167,4 +212,4 @@ U_BOOT_DRIVER(mpfs_mbox) = { .probe = mpfs_mbox_probe, .priv_auto = sizeof(struct mpfs_mbox), .ops = &mpfs_mbox_ops, -}; +}; \ No newline at end of file