From: "Cédric Le Goater" <clg@kaod.org>
To: Emmanuel Blot <emmanuel.blot@free.fr>, qemu-devel@nongnu.org
Cc: "Philippe Mathieu-Daudé" <philmd@mailo.com>,
"Peter Maydell" <peter.maydell@linaro.org>,
"Steven Lee" <steven_lee@aspeedtech.com>,
"Jamin Lin" <jamin_lin@aspeedtech.com>,
"Kane Chen" <kane_chen@aspeedtech.com>,
"Andrew Jeffery" <andrew@codeconstruct.com.au>,
"Joel Stanley" <joel@jms.id.au>,
qemu-arm@nongnu.org, "Fabiano Rosas" <farosas@suse.de>,
"Laurent Vivier" <lvivier@redhat.com>,
"Paolo Bonzini" <pbonzini@redhat.com>,
"Thomas Huth" <th.huth+qemu@posteo.eu>,
"Daniel P. Berrangé" <berrange@redhat.com>,
"Emmanuel Blot" <eblot@meta.com>
Subject: Re: [PATCH v2 04/25] hw/sensor: tmp105: enforce the configurable fault queue
Date: Tue, 1 Sep 2026 08:59:02 +0200 [thread overview]
Message-ID: <418366fe-0ae9-433b-b1c1-51edc84f4604@kaod.org> (raw)
In-Reply-To: <20260731-sanmiguel-bmc-locator-v2-4-1266926ba769@free.fr>
On 7/31/26 12:45, Emmanuel Blot wrote:
> The fault-queue depth selected in the configuration register was decoded
> but never consulted, so the ALERT pin tripped on the very first
> out-of-limit conversion regardless of the programmed depth.
>
> Track the consecutive-fault count and only change the ALERT state once
> it reaches the programmed depth; any in-range conversion clears the
> count. The default configuration keeps the previous behaviour. The count
> is migrated through an optional subsection so existing streams stay
> compatible.
>
> Signed-off-by: Emmanuel Blot <emmanuel.blot@free.fr>
> ---
> hw/sensor/tmp105.c | 87 ++++++++++++++++++++++++++++++++++--------------------
> 1 file changed, 55 insertions(+), 32 deletions(-)
>
> diff --git a/hw/sensor/tmp105.c b/hw/sensor/tmp105.c
> index f7d0c738ca..5c77f991cc 100644
> --- a/hw/sensor/tmp105.c
> +++ b/hw/sensor/tmp105.c
> @@ -54,6 +54,7 @@ struct TMP105State {
> int16_t temperature;
> int16_t limit[2];
> int faults;
> + uint8_t fault_count;
> uint8_t alarm;
> /*
> * The TMP105 initially looks for a temperature rising above T_high;
> @@ -78,43 +79,40 @@ static void tmp105_interrupt_update(TMP105State *s)
>
> static void tmp105_alarm_update(TMP105State *s, bool one_shot)
> {
> + bool fault;
> +
> if (FIELD_EX8(s->config, CONFIG, SHUTDOWN_MODE) && !one_shot) {
> return;
> }
>
> - if (FIELD_EX8(s->config, CONFIG, THERMOSTAT_MODE)) {
> - /*
> - * TM == 1 : Interrupt mode. We signal Alert when the
> - * temperature rises above T_high, and expect the guest to clear
> - * it (eg by reading a device register).
> - */
> - if (s->detect_falling) {
> - if (s->temperature < s->limit[0]) {
> - s->alarm = 1;
> - s->detect_falling = false;
> - }
> - } else {
> - if (s->temperature >= s->limit[1]) {
> - s->alarm = 1;
> - s->detect_falling = true;
> - }
> - }
> + /*
> + * A fault is a conversion that lies outside the limit currently being
> + * watched: above T_high while looking for the alarm to trip, below T_low
> + * afterwards.
> + */
> + if (s->detect_falling) {
> + fault = s->temperature < s->limit[0];
> } else {
> - /*
> - * TM == 0 : Comparator mode. We signal Alert when the temperature
> - * rises above T_high, and stop signalling it when the temperature
> - * falls below T_low.
> - */
> + fault = s->temperature >= s->limit[1];
> + }
> +
> + if (!fault) {
> + s->fault_count = 0;
> + } else if (++s->fault_count >= s->faults) {
> + s->fault_count = 0;
> if (s->detect_falling) {
> - if (s->temperature < s->limit[0]) {
> - s->alarm = 0;
> - s->detect_falling = false;
> - }
> + /*
> + * Temperature fell back below T_low. In comparator mode (TM == 0)
> + * the alarm is released; in interrupt mode (TM == 1) it is
> + * asserted again and the guest is expected to clear it by reading
> + * a register.
> + */
> + s->alarm = FIELD_EX8(s->config, CONFIG, THERMOSTAT_MODE);
> + s->detect_falling = false;
> } else {
> - if (s->temperature >= s->limit[1]) {
> - s->alarm = 1;
> - s->detect_falling = true;
> - }
> + /* Temperature rose to or above T_high: assert the alarm. */
> + s->alarm = 1;
> + s->detect_falling = true;
> }
> }
>
> @@ -204,7 +202,12 @@ static void tmp105_write(TMP105State *s)
> }
> s->config = FIELD_DP8(s->buf[0], CONFIG, ONE_SHOT, 0);
> s->faults = tmp105_faultq[FIELD_EX8(s->config, CONFIG, FAULT_QUEUE)];
> - tmp105_alarm_update(s, FIELD_EX8(s->buf[0], CONFIG, ONE_SHOT));
> + if (FIELD_EX8(s->buf[0], CONFIG, ONE_SHOT) &&
> + FIELD_EX8(s->config, CONFIG, SHUTDOWN_MODE)) {
> + tmp105_alarm_update(s, true);
> + } else {
> + tmp105_interrupt_update(s);
> + }
> break;
>
> case TMP105_REG_T_LOW:
> @@ -213,7 +216,7 @@ static void tmp105_write(TMP105State *s)
> s->limit[s->pointer & 1] = (int16_t)
> ((((uint16_t) s->buf[0]) << 8) | (s->buf[1] & 0xf0));
> }
> - tmp105_alarm_update(s, false);
> + tmp105_interrupt_update(s);
> break;
> }
> }
> @@ -281,6 +284,13 @@ static bool detect_falling_needed(void *opaque)
> return s->detect_falling;
> }
>
> +static bool fault_count_needed(void *opaque)
> +{
> + const TMP105State *s = opaque;
> +
> + return s->fault_count != 0;
> +}
> +
> static const VMStateDescription vmstate_tmp105_detect_falling = {
> .name = "TMP105/detect-falling",
> .version_id = 1,
> @@ -292,6 +302,17 @@ static const VMStateDescription vmstate_tmp105_detect_falling = {
> }
> };
>
> +static const VMStateDescription vmstate_tmp105_fault_count = {
> + .name = "TMP105/fault-count",
> + .version_id = 1,
> + .minimum_version_id = 1,
> + .needed = fault_count_needed,
> + .fields = (const VMStateField[]) {
> + VMSTATE_UINT8(fault_count, TMP105State),
> + VMSTATE_END_OF_LIST()
> + }
> +};
> +
> static const VMStateDescription vmstate_tmp105 = {
> .name = "TMP105",
> .version_id = 0,
> @@ -310,6 +331,7 @@ static const VMStateDescription vmstate_tmp105 = {
> },
> .subsections = (const VMStateDescription * const []) {
> &vmstate_tmp105_detect_falling,
> + &vmstate_tmp105_fault_count,
> NULL
> }
> };
> @@ -322,6 +344,7 @@ static void tmp105_reset_hold(Object *obj, ResetType type)
> s->pointer = 0;
> s->config = 0;
> s->faults = tmp105_faultq[FIELD_EX8(s->config, CONFIG, FAULT_QUEUE)];
> + s->fault_count = 0;
> s->alarm = 0;
> s->detect_falling = false;
>
>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Thanks,
C.
next prev parent reply other threads:[~2026-09-01 6:59 UTC|newest]
Thread overview: 74+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 10:44 [PATCH v2 00/25] hw/arm: Facebook SanMiguel BMC and TMP75-family sensors Emmanuel Blot via
2026-07-31 10:44 ` Emmanuel Blot via qemu development
2026-07-31 10:45 ` [PATCH v2 01/25] hw/sensor: tmp105: make device state private to the implementation Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-09-01 6:58 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 02/25] hw/sensor: tmp105: name the parent object field parent_obj Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-09-01 6:58 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 03/25] hw/sensor: tmp105: implement Resettable reset Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-09-01 6:58 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 04/25] hw/sensor: tmp105: enforce the configurable fault queue Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-09-01 6:59 ` Cédric Le Goater [this message]
2026-07-31 10:45 ` [PATCH v2 05/25] hw/sensor: tmp105: describe the temperature property Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-09-01 6:59 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 06/25] hw/arm: aspeed: guard board-local temperature-sensor aliases Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-09-01 6:59 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 07/25] hw/sensor: tmp105: add TMP75, TMP175 and LM75B variants Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-09-01 6:59 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 08/25] tests/qtest: tmp105: cover the ALERT fault queue Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-09-01 6:59 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 09/25] tests/qtest: tmp105: cover the TMP75, TMP175 and LM75B variants Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-09-01 6:59 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 10/25] tests/qtest: tmp105: cover one-shot and fault-queue write immunity Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-09-01 6:59 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 11/25] tests/qtest: tmp105: cover shutdown clearing the ALERT across variants Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-09-01 7:00 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 12/25] hw/arm: sanmiguel: add Facebook SanMiguel BMC machine Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-07-31 10:45 ` [PATCH v2 13/25] hw/arm: sanmiguel: populate EEPROM data Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-09-02 5:50 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 14/25] hw/arm: catalina: use the real TMP75 model Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-09-02 5:50 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 15/25] hw/arm: fuji: use the real TMP75 and LM75B temperature sensors Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-09-02 5:50 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 16/25] tests/functional: aspeed: optionally check the device tree model on boot Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-09-02 5:50 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 17/25] tests/functional: give the set_machine probe VM the test workdir Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-09-02 5:51 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 18/25] tests/functional: add a pure-Python device-locator resolver Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-09-03 14:21 ` Adding /machines/labels (was Re: [PATCH v2 18/25] tests/functional: add a pure-Python device-locator resolver) Cédric Le Goater
2026-09-04 8:22 ` Markus Armbruster
2026-09-05 12:45 ` Mark Cave-Ayland
2026-09-05 15:20 ` Cédric Le Goater
2026-07-31 10:45 ` [PATCH v2 19/25] tests/functional: add a device-locator self-check Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-07-31 10:45 ` [PATCH v2 20/25] tests/functional: aspeed: add hwmon sensor read helpers Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-07-31 10:45 ` [PATCH v2 21/25] tests/functional/arm: sanmiguel: add BMC boot test Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-07-31 10:45 ` [PATCH v2 22/25] tests/functional/arm: catalina: test TMP75 Emmanuel Blot via
2026-07-31 10:45 ` Emmanuel Blot via qemu development
2026-07-31 10:45 ` [PATCH v2 23/25] tests/functional/arm: catalina: test PCA9555 IO expander via QOM Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-07-31 10:45 ` [PATCH v2 24/25] hw/arm: catalina: drive pca9554 io expander input pins externally Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-07-31 10:45 ` [PATCH v2 25/25] tests/functional/arm: catalina: test PCA9554 IO expander via QOM Emmanuel Blot via qemu development
2026-07-31 10:45 ` Emmanuel Blot via
2026-08-31 14:42 ` [PING] Re: [PATCH v2 00/25] hw/arm: Facebook SanMiguel BMC and TMP75-family sensors Emmanuel Blot
2026-09-02 6:19 ` Cédric Le Goater
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=418366fe-0ae9-433b-b1c1-51edc84f4604@kaod.org \
--to=clg@kaod.org \
--cc=andrew@codeconstruct.com.au \
--cc=berrange@redhat.com \
--cc=eblot@meta.com \
--cc=emmanuel.blot@free.fr \
--cc=farosas@suse.de \
--cc=jamin_lin@aspeedtech.com \
--cc=joel@jms.id.au \
--cc=kane_chen@aspeedtech.com \
--cc=lvivier@redhat.com \
--cc=pbonzini@redhat.com \
--cc=peter.maydell@linaro.org \
--cc=philmd@mailo.com \
--cc=qemu-arm@nongnu.org \
--cc=qemu-devel@nongnu.org \
--cc=steven_lee@aspeedtech.com \
--cc=th.huth+qemu@posteo.eu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.