All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Lakshay Piplani" <lakshay.piplani@nxp.com>
Cc: linux-i3c@lists.infradead.org, robh@kernel.org,
	Frank.Li@kernel.org, conor+dt@kernel.org,
	devicetree@vger.kernel.org,
	"Alexandre Belloni" <alexandre.belloni@bootlin.com>
Subject: Re: [PATCH v18 1/8] i3c: master: Add APIs for I3C hub support
Date: Thu, 03 Sep 2026 06:34:23 +0000	[thread overview]
Message-ID: <20260903063424.75BFA1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260903062108.2712296-2-lakshay.piplani@nxp.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Ignored return value of i3c_master_reattach_i3c_dev_locked leads to dynamic address collision.
--

commit d579609388ce2e1b2127e5830b25d39229bf1664
Author: Aman Kumar Pandey <aman.kumarpandey@nxp.com>

i3c: master: Add APIs for I3C hub support

This commit adds CCC helpers, address slot helpers, and locking functions
to prepare for I3C hub support. It also enables registering virtual masters
with an explicit firmware node.

> diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c
> index afcd7a21a3e66..9ea4726495ff6 100644
> --- a/drivers/i3c/master.c
> +++ b/drivers/i3c/master.c

[ ... ]

> @@ -422,11 +434,18 @@ static void i3c_bus_set_addr_slot_status_mask(struct i3c_bus *bus, u16 addr,
>  	*ptr |= ((unsigned long)status & mask) << (bitpos % BITS_PER_LONG);
>  }
>  
> -static void i3c_bus_set_addr_slot_status(struct i3c_bus *bus, u16 addr,
> -					 enum i3c_addr_slot_status status)
> +/**
> + * i3c_bus_set_addr_slot_status() - Set I3C bus address slot status
> + * @bus: I3C bus.
> + * @addr: I3C address to update.
> + * @status: Address slot status to set.
> + */
> +void i3c_bus_set_addr_slot_status(struct i3c_bus *bus, u16 addr,
> +				  enum i3c_addr_slot_status status)
>  {
>  	i3c_bus_set_addr_slot_status_mask(bus, addr, status, I3C_ADDR_SLOT_STATUS_MASK);
>  }
> +EXPORT_SYMBOL_GPL(i3c_bus_set_addr_slot_status);

[Severity: High]
This is a pre-existing issue, but while reviewing this patch and how address
slots are managed, I noticed a logic flaw in __i3c_master_add_i3c_dev_locked() 
that could lead to dynamic address collisions.

If a device is expected to have a specific dynamic address, it attempts to
apply it:

	if (!ret) {
		old_dyn_addr = newdev->info.dyn_addr;
		newdev->info.dyn_addr = expected_dyn_addr;
		i3c_master_reattach_i3c_dev_locked(newdev, old_dyn_addr);
	} else {
		dev_err(&master->dev,
			"Failed to assign reserved/old address to device...");

The return value of i3c_master_reattach_i3c_dev_locked() is discarded here. 
If reattachment fails, that function cleans up by releasing the addresses:

	if (master->ops->reattach_i3c_dev) {
		ret = master->ops->reattach_i3c_dev(dev, old_dyn_addr);
		if (ret) {
			i3c_master_put_i3c_addrs(dev);
			return ret;
		}
	}

This means the address is marked as I3C_ADDR_SLOT_FREE in the bus addrslots. 
However, because the failure is ignored in __i3c_master_add_i3c_dev_locked(),
the device remains active in the bus list. A subsequently added device 
(e.g., via hot-join) could then be assigned this exact same address, causing 
an electrical collision on the bus.

Should we be checking the return value of i3c_master_reattach_i3c_dev_locked()
and detaching the device or reverting the address state if it fails?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260903062108.2712296-1-lakshay.piplani@nxp.com?part=1

-- 
linux-i3c mailing list
linux-i3c@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-i3c

WARNING: multiple messages have this Message-ID (diff)
From: sashiko-bot@kernel.org
To: "Lakshay Piplani" <lakshay.piplani@nxp.com>
Cc: linux-i3c@lists.infradead.org, robh@kernel.org,
	Frank.Li@kernel.org, conor+dt@kernel.org,
	devicetree@vger.kernel.org,
	"Alexandre Belloni" <alexandre.belloni@bootlin.com>
Subject: Re: [PATCH v18 1/8] i3c: master: Add APIs for I3C hub support
Date: Thu, 03 Sep 2026 06:34:23 +0000	[thread overview]
Message-ID: <20260903063424.75BFA1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260903062108.2712296-2-lakshay.piplani@nxp.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Ignored return value of i3c_master_reattach_i3c_dev_locked leads to dynamic address collision.
--

commit d579609388ce2e1b2127e5830b25d39229bf1664
Author: Aman Kumar Pandey <aman.kumarpandey@nxp.com>

i3c: master: Add APIs for I3C hub support

This commit adds CCC helpers, address slot helpers, and locking functions
to prepare for I3C hub support. It also enables registering virtual masters
with an explicit firmware node.

> diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c
> index afcd7a21a3e66..9ea4726495ff6 100644
> --- a/drivers/i3c/master.c
> +++ b/drivers/i3c/master.c

[ ... ]

> @@ -422,11 +434,18 @@ static void i3c_bus_set_addr_slot_status_mask(struct i3c_bus *bus, u16 addr,
>  	*ptr |= ((unsigned long)status & mask) << (bitpos % BITS_PER_LONG);
>  }
>  
> -static void i3c_bus_set_addr_slot_status(struct i3c_bus *bus, u16 addr,
> -					 enum i3c_addr_slot_status status)
> +/**
> + * i3c_bus_set_addr_slot_status() - Set I3C bus address slot status
> + * @bus: I3C bus.
> + * @addr: I3C address to update.
> + * @status: Address slot status to set.
> + */
> +void i3c_bus_set_addr_slot_status(struct i3c_bus *bus, u16 addr,
> +				  enum i3c_addr_slot_status status)
>  {
>  	i3c_bus_set_addr_slot_status_mask(bus, addr, status, I3C_ADDR_SLOT_STATUS_MASK);
>  }
> +EXPORT_SYMBOL_GPL(i3c_bus_set_addr_slot_status);

[Severity: High]
This is a pre-existing issue, but while reviewing this patch and how address
slots are managed, I noticed a logic flaw in __i3c_master_add_i3c_dev_locked() 
that could lead to dynamic address collisions.

If a device is expected to have a specific dynamic address, it attempts to
apply it:

	if (!ret) {
		old_dyn_addr = newdev->info.dyn_addr;
		newdev->info.dyn_addr = expected_dyn_addr;
		i3c_master_reattach_i3c_dev_locked(newdev, old_dyn_addr);
	} else {
		dev_err(&master->dev,
			"Failed to assign reserved/old address to device...");

The return value of i3c_master_reattach_i3c_dev_locked() is discarded here. 
If reattachment fails, that function cleans up by releasing the addresses:

	if (master->ops->reattach_i3c_dev) {
		ret = master->ops->reattach_i3c_dev(dev, old_dyn_addr);
		if (ret) {
			i3c_master_put_i3c_addrs(dev);
			return ret;
		}
	}

This means the address is marked as I3C_ADDR_SLOT_FREE in the bus addrslots. 
However, because the failure is ignored in __i3c_master_add_i3c_dev_locked(),
the device remains active in the bus list. A subsequently added device 
(e.g., via hot-join) could then be assigned this exact same address, causing 
an electrical collision on the bus.

Should we be checking the return value of i3c_master_reattach_i3c_dev_locked()
and detaching the device or reverting the address state if it fails?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260903062108.2712296-1-lakshay.piplani@nxp.com?part=1

  reply	other threads:[~2026-09-03  6:34 UTC|newest]

Thread overview: 50+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03  6:21 [PATCH v18 0/8] Add support for NXP P3H2x4x I3C hub driver Lakshay Piplani
2026-09-03  6:21 ` Lakshay Piplani
2026-09-03  6:21 ` [PATCH v18 1/8] i3c: master: Add APIs for I3C hub support Lakshay Piplani
2026-09-03  6:21   ` Lakshay Piplani
2026-09-03  6:34   ` sashiko-bot [this message]
2026-09-03  6:34     ` sashiko-bot
2026-09-03  6:21 ` [PATCH v18 2/8] i3c: master: Add controller-only device operation helpers Lakshay Piplani
2026-09-03  6:21   ` Lakshay Piplani
2026-09-03  6:35   ` sashiko-bot
2026-09-03  6:35     ` sashiko-bot
2026-09-04 19:52   ` Frank Li
2026-09-04 19:52     ` Frank Li
2026-09-03  6:21 ` [PATCH v18 3/8] dt-bindings: i3c: Add NXP P3H2x4x i3c-hub support Lakshay Piplani
2026-09-03  6:21   ` Lakshay Piplani
2026-09-09  6:07   ` Krzysztof Kozlowski
2026-09-09  6:07     ` Krzysztof Kozlowski
2026-09-09  7:08     ` [EXT] " Lakshay Piplani
2026-09-09  7:08       ` Lakshay Piplani
2026-09-09  7:14       ` Krzysztof Kozlowski
2026-09-09  7:14         ` Krzysztof Kozlowski
2026-09-09  8:32         ` Lakshay Piplani
2026-09-09  8:32           ` Lakshay Piplani
2026-09-11  9:22           ` Lakshay Piplani
2026-09-11  9:22             ` Lakshay Piplani
2026-09-03  6:21 ` [PATCH v18 4/8] mfd: p3h2x4x: Add driver for NXP P3H2x4x i3c hub and on-die regulator Lakshay Piplani
2026-09-03  6:21   ` Lakshay Piplani
2026-09-03  6:35   ` sashiko-bot
2026-09-03  6:35     ` sashiko-bot
2026-09-11  9:31   ` Lakshay Piplani
2026-09-11  9:31     ` Lakshay Piplani
2026-09-03  6:21 ` [PATCH v18 5/8] regulator: p3h2x4x: Add driver for on-die regulators in NXP P3H2x4x i3c hub Lakshay Piplani
2026-09-03  6:21   ` Lakshay Piplani
2026-09-03  6:31   ` sashiko-bot
2026-09-03  6:31     ` sashiko-bot
2026-09-03  6:21 ` [PATCH v18 6/8] i3c: hub: Add support for the I3C interface in the I3C hub Lakshay Piplani
2026-09-03  6:21   ` Lakshay Piplani
2026-09-03  6:38   ` sashiko-bot
2026-09-03  6:38     ` sashiko-bot
2026-09-04 20:05   ` Frank Li
2026-09-04 20:05     ` Frank Li
2026-09-03  6:21 ` [PATCH v18 7/8] i3c: hub: p3h2x4x: Add support for NXP P3H2x4x I3C hub functionality Lakshay Piplani
2026-09-03  6:21   ` Lakshay Piplani
2026-09-04 20:10   ` Frank Li
2026-09-04 20:10     ` Frank Li
2026-09-03  6:21 ` [PATCH v18 8/8] i3c: hub: p3h2x4x: Add SMBus slave mode support Lakshay Piplani
2026-09-03  6:21   ` Lakshay Piplani
2026-09-03  6:41   ` sashiko-bot
2026-09-03  6:41     ` sashiko-bot
2026-09-04 20:12   ` Frank Li
2026-09-04 20:12     ` Frank Li

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260903063424.75BFA1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=alexandre.belloni@bootlin.com \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=lakshay.piplani@nxp.com \
    --cc=linux-i3c@lists.infradead.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.