All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: Prabhakar <prabhakar.csengg@gmail.com>
Cc: "Alexandre Belloni" <alexandre.belloni@bootlin.com>,
	robh@kernel.org, linux-rtc@vger.kernel.org, conor+dt@kernel.org,
	wsa+renesas@sang-engineering.com, devicetree@vger.kernel.org
Subject: Re: [PATCH v4 08/15] rtc: rzn1: Use pm_runtime_put_sync() in rzn1_rtc_disable_hardware()
Date: Wed, 19 Aug 2026 10:51:38 +0000	[thread overview]
Message-ID: <20260819105139.4AB9F1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260819103926.2136712-9-prabhakar.mahadev-lad.rj@bp.renesas.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [Medium] Race condition in rzn1_rtc_set_alarm() leading to spurious hardware interrupts and lockless torn reads of rtc->tm_alarm.
--

--- Patch [8]: [PATCH v4 08/15] rtc: rzn1: Use pm_runtime_put_sync() in rzn1_rtc_disable_hardware() ---
commit dff0f7a5386396694cffd2ad789f85740e53b9b9
Author: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>

rtc: rzn1: Use pm_runtime_put_sync() in rzn1_rtc_disable_hardware()
    
pm_runtime_put() may trigger the idle check after pm_runtime_disable()
is run as part of devm_pm_runtime_enable()'s cleanup action, leaving
runtime PM active.

> diff --git a/drivers/rtc/rtc-rzn1.c b/drivers/rtc/rtc-rzn1.c
> index da7d13337c0da..425d9590c55b9 100644
> --- a/drivers/rtc/rtc-rzn1.c
> +++ b/drivers/rtc/rtc-rzn1.c
> @@ -379,7 +379,7 @@ static void rzn1_rtc_disable_hardware(void *data)
>  	/* Disable all interrupts */
>  	writel(0, rtc->base + RZN1_RTC_CTL1);
>  
> -	pm_runtime_put(dev);
> +	pm_runtime_put_sync(dev);
>  }

[Severity: Medium]
This is a pre-existing issue, but while reviewing this file I noticed a
potential race condition in rzn1_rtc_set_alarm() that could lead to
spurious hardware interrupts and lockless torn reads of rtc->tm_alarm.

If rtc_timer_enqueue() calls __rtc_set_alarm() to replace an existing
alarm with an earlier one without disabling the hardware alarm first, ALME
might still be 1. During this time, rzn1_rtc_set_alarm() sequentially writes
to the registers:

drivers/rtc/rtc-rzn1.c:rzn1_rtc_set_alarm() {
    ...
	writel(bin2bcd(tm->tm_min), rtc->base + RZN1_RTC_ALM);
	writel(bin2bcd(tm->tm_hour), rtc->base + RZN1_RTC_ALH);
	writel(BIT(tm->tm_wday), rtc->base + RZN1_RTC_ALW);

	rtc->tm_alarm = alrm->time;
    ...
}

If the intermediate hybrid state of these registers matches the current
hardware time, would the RTC immediately fire an alarm interrupt?

Concurrently, if the interrupt fires, the IRQ handler reads the potentially
stale or partially updated rtc->tm_alarm structure without locks:

drivers/rtc/rtc-rzn1.c:rzn1_rtc_alarm_irq() {
    ...
	if (rtc->tm_alarm.tm_sec == 0)
		rtc_update_irq(rtc->rtcdev, 1, RTC_AF | RTC_IRQF);
	else
		/* Switch to 1s interrupts */
		set_irq_bits = RZN1_RTC_CTL1_1SE;
    ...
}

Could this result in spurious RTC_AF events sent to userspace or incorrect
toggling of the 1-second interrupt mode?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260819103926.2136712-1-prabhakar.mahadev-lad.rj@bp.renesas.com?part=8

  reply	other threads:[~2026-08-19 10:51 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-19 10:39 [PATCH v4 00/15] Add RTC support for Renesas RZ/T2H and RZ/N2H SoCs Prabhakar
2026-08-19 10:39 ` [PATCH v4 01/15] dt-bindings: rtc: renesas,rzn1-rtc: Add RZ/T2H and RZ/N2H support Prabhakar
2026-08-19 10:48   ` sashiko-bot
2026-08-19 10:39 ` [PATCH v4 02/15] rtc: rzn1: Handle EPROBE_DEFER for optional pps interrupt Prabhakar
2026-08-19 10:46   ` sashiko-bot
2026-08-19 10:39 ` [PATCH v4 03/15] rtc: rzn1: Fix weekday underflow when alarm crosses month boundary Prabhakar
2026-08-19 10:53   ` sashiko-bot
2026-08-19 13:01     ` Wolfram Sang
2026-08-19 12:57   ` Wolfram Sang
2026-08-19 10:39 ` [PATCH v4 04/15] rtc: rzn1: Fix malformed MODULE_AUTHOR string Prabhakar
2026-08-19 10:43   ` sashiko-bot
2026-08-19 10:39 ` [PATCH v4 05/15] rtc: Kconfig: Broaden RTC_DRV_RZN1 dependency to ARCH_RENESAS Prabhakar
2026-08-19 10:44   ` sashiko-bot
2026-08-19 10:39 ` [PATCH v4 06/15] rtc: rzn1: Fix alarm range check truncation on 32-bit systems Prabhakar
2026-08-19 10:50   ` sashiko-bot
2026-08-19 13:05     ` Wolfram Sang
2026-08-19 10:39 ` [PATCH v4 07/15] rtc: rzn1: Replace remove callback with devm_add_action_or_reset() Prabhakar
2026-08-19 10:50   ` sashiko-bot
2026-08-19 13:06     ` Wolfram Sang
2026-08-19 10:39 ` [PATCH v4 08/15] rtc: rzn1: Use pm_runtime_put_sync() in rzn1_rtc_disable_hardware() Prabhakar
2026-08-19 10:51   ` sashiko-bot [this message]
2026-08-19 13:07     ` Wolfram Sang
2026-08-19 10:39 ` [PATCH v4 09/15] rtc: rzn1: Dynamically calculate synchronization delay based on clock rate Prabhakar
2026-08-19 10:47   ` sashiko-bot
2026-08-19 13:08   ` Wolfram Sang
2026-08-19 10:39 ` [PATCH v4 10/15] rtc: rzn1: Use temporary variable for struct device Prabhakar
2026-08-19 10:46   ` sashiko-bot
2026-08-19 10:39 ` [PATCH v4 11/15] rtc: rzn1: Consistently use dev_err_probe() Prabhakar
2026-08-19 10:46   ` sashiko-bot
2026-08-19 10:39 ` [PATCH v4 12/15] rtc: rzn1: use FIELD_PREP/FIELD_GET and GENMASK for register access Prabhakar
2026-08-19 10:49   ` sashiko-bot
2026-08-19 13:09     ` Wolfram Sang
2026-08-19 10:39 ` [PATCH v4 13/15] rtc: rzn1: Add OF match data to gate SUBU " Prabhakar
2026-08-19 10:47   ` sashiko-bot
2026-08-19 13:12   ` Wolfram Sang
2026-08-19 10:39 ` [PATCH v4 14/15] rtc: rzn1: Drop trailing comma from OF match table sentinel Prabhakar
2026-08-19 10:47   ` sashiko-bot
2026-08-19 13:13   ` Wolfram Sang
2026-08-19 10:39 ` [PATCH v4 15/15] rtc: rzn1: Add support for Renesas RZ/T2H and RZ/N2H SoCs Prabhakar
2026-08-19 10:52   ` sashiko-bot
2026-08-19 13:14   ` Wolfram Sang
2026-08-19 13:15 ` [PATCH v4 00/15] Add RTC " Wolfram Sang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260819105139.4AB9F1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=alexandre.belloni@bootlin.com \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=linux-rtc@vger.kernel.org \
    --cc=prabhakar.csengg@gmail.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wsa+renesas@sang-engineering.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.