* [PATCH v15 0/5] Enable Remote GPIO over RPMSG on i.MX Platform
@ 2026-07-21 20:46 Shenwei Wang
2026-07-21 20:46 ` [PATCH v15 1/5] docs: driver-api: gpio: rpmsg gpio driver over rpmsg bus Shenwei Wang
` (4 more replies)
0 siblings, 5 replies; 9+ messages in thread
From: Shenwei Wang @ 2026-07-21 20:46 UTC (permalink / raw)
To: Linus Walleij, Bartosz Golaszewski, Jonathan Corbet, Rob Herring,
Krzysztof Kozlowski, Conor Dooley, Bjorn Andersson,
Mathieu Poirier, Frank Li, Sascha Hauer
Cc: Shuah Khan, linux-gpio, linux-doc, linux-kernel,
Pengutronix Kernel Team, Fabio Estevam, Shenwei Wang, Peng Fan,
devicetree, linux-remoteproc, imx, linux-arm-kernel, linux-imx,
Arnaud POULIQUEN, b-padhi, Andrew Lunn, Shenwei Wang
Support the remote devices on the remote processor via the RPMSG bus on
i.MX platform.
Changes in v15:
- Update Kconfig description per AndrewD and Julian's feedback
- Enable the GPIO driver even without a DT node per AndrewD's feedback
- Update gpio-rpmsg.rst per Mathieu’s feedback
- Code cleanup according the new gpio-rpmsg.rst and sashiko-bot's review
feedback
Changes in v14:
- Update gpio-rpmsg.rst per Mathieu’s feedback.
- Align the rpmsg-gpio driver with the revised gpio-rpmsg.rst.
- Modify rpmsg-core to enable prefix-based matching of RPMSG device IDs.
Changes in v13:
- drop the support for legacy NXP firmware.
- remove the fixed_up hooks from the rpmsg gpio driver.
- code cleanup.
Changes in v12:
- Fixed the "underline" warning reported by Randy.
Changes in v11:
- Expand RPMSG for the first time per Shuah's review comment.
Changes in v10:
- Update gpio-rpmsg.rst according to Daniel Baluta's review comments.
- Add a kernel CONFIG for fixed up handlers and only enable it on
i.MX products.
- Fixed bugs reported by kernel test robot.
Changes in v9:
- Reuse the gpio-virtio design for command and IRQ type definitions.
- Remove msg_id, version, and vendor fields from the generic protocol.
- Add fixed-up handlers to support legacy firmware.
Changes in v8:
- Add "depends on REMOTEPROC" in Kconfig to fix the build error reported
by the kernel test robot.
- Move the .rst patch before the .yaml patch.
- Handle the "ngpios" DT property based on Andrew's feedback.
Changes in v7:
- Reworked the driver to use the rpmsg_driver framework instead of
platform_driver, based on feedback from Bjorn and Arnaud.
- Updated gpio-rpmsg.yaml and imx_rproc.yaml according to comments from
Rob and Arnaud.
- Further refinements to gpio-rpmsg.yaml per Arnaud's feedback.
Changes in v6:
- make the driver more generic with the actions below:
rename the driver file to gpio-rpmsg.c
remove the imx related info in the function and variable names
rename the imx_rpmsg.h to rpdev_info.h
create a gpio-rpmsg.yaml and refer it in imx_rproc.yaml
- update the gpio-rpmsg.rst according to the feedback from Andrew and
move the source file to driver-api/gpio
- fix the bug reported by Zhongqiu Han
- remove the I2C related info
Changes in v5:
- move the gpio-rpmsg.rst from admin-guide to staging directory after
discussion with Randy Dunlap.
- add include files with some code improvements per Bartosz's comments.
Changes in v4:
- add a documentation to describe the transport protocol per Andrew's
comments.
- add a new handler to get the gpio direction.
Changes in v3:
- fix various format issue and return value check per Peng 's review
comments.
- add the logic to also populate the subnodes which are not in the
device map per Arnaud's request. (in imx_rproc.c)
- update the yaml per Frank's review comments.
Changes in v2:
- re-implemented the gpio driver per Linus Walleij's feedback by using
GPIOLIB_IRQCHIP helper library.
- fix various format issue per Mathieu/Peng 's review comments.
- update the yaml doc per Rob's feedback
Shenwei Wang (5):
docs: driver-api: gpio: rpmsg gpio driver over rpmsg bus
dt-bindings: remoteproc: imx_rproc: Add "rpmsg" subnode support
rpmsg: core: match rpmsg device IDs by prefix
gpio: rpmsg: add generic rpmsg GPIO driver
arm64: dts: imx8ulp: Add rpmsg node under imx_rproc
.../devicetree/bindings/gpio/gpio-rpmsg.yaml | 55 ++
.../bindings/remoteproc/fsl,imx-rproc.yaml | 53 ++
Documentation/driver-api/gpio/gpio-rpmsg.rst | 242 ++++++++
Documentation/driver-api/gpio/index.rst | 1 +
arch/arm64/boot/dts/freescale/imx8ulp.dtsi | 25 +
drivers/gpio/Kconfig | 17 +
drivers/gpio/Makefile | 1 +
drivers/gpio/gpio-rpmsg.c | 587 ++++++++++++++++++
drivers/rpmsg/rpmsg_core.c | 4 +-
9 files changed, 984 insertions(+), 1 deletion(-)
create mode 100644 Documentation/devicetree/bindings/gpio/gpio-rpmsg.yaml
create mode 100644 Documentation/driver-api/gpio/gpio-rpmsg.rst
create mode 100644 drivers/gpio/gpio-rpmsg.c
--
2.43.0
^ permalink raw reply [flat|nested] 9+ messages in thread* [PATCH v15 1/5] docs: driver-api: gpio: rpmsg gpio driver over rpmsg bus 2026-07-21 20:46 [PATCH v15 0/5] Enable Remote GPIO over RPMSG on i.MX Platform Shenwei Wang @ 2026-07-21 20:46 ` Shenwei Wang 2026-07-21 20:46 ` [PATCH v15 2/5] dt-bindings: remoteproc: imx_rproc: Add "rpmsg" subnode support Shenwei Wang ` (3 subsequent siblings) 4 siblings, 0 replies; 9+ messages in thread From: Shenwei Wang @ 2026-07-21 20:46 UTC (permalink / raw) To: Linus Walleij, Bartosz Golaszewski, Jonathan Corbet, Rob Herring, Krzysztof Kozlowski, Conor Dooley, Bjorn Andersson, Mathieu Poirier, Frank Li, Sascha Hauer Cc: Shuah Khan, linux-gpio, linux-doc, linux-kernel, Pengutronix Kernel Team, Fabio Estevam, Shenwei Wang, Peng Fan, devicetree, linux-remoteproc, imx, linux-arm-kernel, linux-imx, Arnaud POULIQUEN, b-padhi, Andrew Lunn From: Shenwei Wang <shenwei.wang@nxp.com> Describes the gpio rpmsg transport protocol over the rpmsg bus between the remote system and Linux. Signed-off-by: Shenwei Wang <shenwei.wang@nxp.com> --- Documentation/driver-api/gpio/gpio-rpmsg.rst | 242 +++++++++++++++++++ Documentation/driver-api/gpio/index.rst | 1 + 2 files changed, 243 insertions(+) create mode 100644 Documentation/driver-api/gpio/gpio-rpmsg.rst diff --git a/Documentation/driver-api/gpio/gpio-rpmsg.rst b/Documentation/driver-api/gpio/gpio-rpmsg.rst new file mode 100644 index 000000000000..9af75cc759ba --- /dev/null +++ b/Documentation/driver-api/gpio/gpio-rpmsg.rst @@ -0,0 +1,242 @@ +.. SPDX-License-Identifier: GPL-2.0-or-later + +GPIO RPMSG (Remote Processor Messaging) Protocol +================================================ + +The GPIO RPMSG transport protocol is used for communication and interaction +with GPIO controllers on remote processors via the RPMSG bus. + +Message Format +-------------- + +The out message to the remote consists of a 8-byte packet with the +following layout: + +.. code-block:: none + + +------+------+------+------+------+------+------+------+ + | 0x00 | 0x01 | 0x02 | 0x03 | 0x04 | 0x05 | 0x06 | 0x07 | + | cmd | line | value | + +------+------+------+------+------+------+------+------+ + +- **cmd**: Little endian. Command type. + +- **line**: Little endian. The GPIO line (pin) index. + +- **value**: Little endian. See details in the command description below. + + +The in message from the remote has the following layout: + +.. code-block:: none + + +------+--------+--------+ + | 0x00 | 0x01 | 0x02 | + | type | payload | + +------+--------+--------+ + +- **type**: Message types. + - 0: Command reply messages. + - 1: Interrupt messages. + +- **payload**: See details below. + +GPIO Commands +------------- + +Commands are specified in the **Cmd** field. + +The SEND message is always sent from Linux to the remote firmware. Each +SEND corresponds to a single REPLY message. The GPIO driver should +serialize messages and determine whether a REPLY message is required. If a +REPLY message is expected but not received within the specified timeout +period (currently 1 second in the Linux driver), the driver should return +-ETIMEDOUT. + +GET_DIRECTION (Cmd=2) +~~~~~~~~~~~~~~~~~~~~~ + +**Request:** + +.. code-block:: none + + +------+------+------+------+------+------+------+------+ + | 0x00 | 0x01 | 0x02 | 0x03 | 0x04 | 0x05 | 0x06 | 0x07 | + | 2 | line | 0 | + +------+------+------+------+------+------+------+------+ + +**Reply:** + +.. code-block:: none + + +------+--------+--------+ + | 0x00 | 0x01 | 0x02 | + | 0 | status | value | + +------+--------+--------+ + +- **status**: + + - 0: Ok + - 1: Error + +- **value**: Direction. + + - 0: None + - 1: Output + - 2: Input + + +SET_DIRECTION (Cmd=3) +~~~~~~~~~~~~~~~~~~~~~ + +**Request:** + +.. code-block:: none + + +------+------+------+------+------+------+------+------+ + | 0x00 | 0x01 | 0x02 | 0x03 | 0x04 | 0x05 | 0x06 | 0x07 | + | 3 | line | value | + +------+------+------+------+------+------+------+------+ + +- **value**: Direction. + + - 0: None + - 1: Output + - 2: Input + +**Reply:** + +.. code-block:: none + + +------+--------+--------+ + | 0x00 | 0x01 | 0x02 | + | 0 | status | 0 | + +------+--------+--------+ + +- **status**: + + - 0: Ok + - 1: Error + + +GET_VALUE (Cmd=4) +~~~~~~~~~~~~~~~~~ + +**Request:** + +.. code-block:: none + + +------+------+------+------+------+------+------+------+ + | 0x00 | 0x01 | 0x02 | 0x03 | 0x04 | 0x05 | 0x06 | 0x07 | + | 4 | line | 0 | + +------+------+------+------+------+------+------+------+ + +**Reply:** + +.. code-block:: none + + +------+--------+--------+ + | 0x00 | 0x01 | 0x02 | + | 0 | status | value | + +------+--------+--------+ + +- **status**: + + - 0: Ok + - 1: Error + +- **value**: Level. + + - 0: Low + - 1: High + + +SET_VALUE (Cmd=5) +~~~~~~~~~~~~~~~~~ + +**Request:** + +.. code-block:: none + + +------+------+------+------+------+------+------+------+ + | 0x00 | 0x01 | 0x02 | 0x03 | 0x04 | 0x05 | 0x06 | 0x07 | + | 5 | line | value | + +------+------+------+------+------+------+------+------+ + +- **value**: Output level. + + - 0: Low + - 1: High + +**Reply:** + +.. code-block:: none + + +------+--------+--------+ + | 0x00 | 0x01 | 0x02 | + | 0 | status | 0 | + +------+--------+--------+ + +- **status**: + + - 0: Ok + - 1: Error + + +SET_IRQ_TYPE (Cmd=6) +~~~~~~~~~~~~~~~~~~~~ + +**Request:** + +.. code-block:: none + + +------+------+------+------+------+------+------+------+ + | 0x00 | 0x01 | 0x02 | 0x03 | 0x04 | 0x05 | 0x06 | 0x07 | + | 6 | line | value | + +------+------+------+------+------+------+------+------+ + +- **value**: IRQ types. + + - 0: Interrupt disabled + - 1: Rising edge trigger + - 2: Falling edge trigger + - 3: Both edge trigger + - 4: High level trigger + - 8: Low level trigger + +**Reply:** + +.. code-block:: none + + +------+--------+--------+ + | 0x00 | 0x01 | 0x02 | + | 0 | status | 0 | + +------+--------+--------+ + +- **status**: + + - 0: Ok + - 1: Error + + +Interrupt Messages +------------------ + +Interrupt messages are sent by the remote core and they have +**Type=1 (GPIO_RPMSG_NOTIFY)**: + +When a GPIO line asserts an interrupt on the remote processor, the firmware +should immediately mask the corresponding interrupt source and send a +notification message to the Linux. Upon completion of the interrupt +handling on the Linux side, the driver should issue a +command **SET_IRQ_TYPE** to the firmware to unmask the interrupt. + +.. code-block:: none + + +------+------+--------+ + | 0x00 | 0x01 | 0x02 | + | 1 | line | + +------+------+--------+ + +- **line**: Little endian. The GPIO line (pin) index. + diff --git a/Documentation/driver-api/gpio/index.rst b/Documentation/driver-api/gpio/index.rst index bee58f709b9a..e5eb1f82f01f 100644 --- a/Documentation/driver-api/gpio/index.rst +++ b/Documentation/driver-api/gpio/index.rst @@ -16,6 +16,7 @@ Contents: drivers-on-gpio bt8xxgpio pca953x + gpio-rpmsg Core ==== -- 2.43.0 ^ permalink raw reply related [flat|nested] 9+ messages in thread
* [PATCH v15 2/5] dt-bindings: remoteproc: imx_rproc: Add "rpmsg" subnode support 2026-07-21 20:46 [PATCH v15 0/5] Enable Remote GPIO over RPMSG on i.MX Platform Shenwei Wang 2026-07-21 20:46 ` [PATCH v15 1/5] docs: driver-api: gpio: rpmsg gpio driver over rpmsg bus Shenwei Wang @ 2026-07-21 20:46 ` Shenwei Wang 2026-07-21 20:57 ` sashiko-bot 2026-07-21 20:46 ` [PATCH v15 3/5] rpmsg: core: match rpmsg device IDs by prefix Shenwei Wang ` (2 subsequent siblings) 4 siblings, 1 reply; 9+ messages in thread From: Shenwei Wang @ 2026-07-21 20:46 UTC (permalink / raw) To: Linus Walleij, Bartosz Golaszewski, Jonathan Corbet, Rob Herring, Krzysztof Kozlowski, Conor Dooley, Bjorn Andersson, Mathieu Poirier, Frank Li, Sascha Hauer Cc: Shuah Khan, linux-gpio, linux-doc, linux-kernel, Pengutronix Kernel Team, Fabio Estevam, Shenwei Wang, Peng Fan, devicetree, linux-remoteproc, imx, linux-arm-kernel, linux-imx, Arnaud POULIQUEN, b-padhi, Andrew Lunn From: Shenwei Wang <shenwei.wang@nxp.com> Remote processors may announce multiple GPIO controllers over an RPMSG channel. These GPIO controllers may require corresponding device tree nodes, especially when acting as providers, to supply phandles for their consumers. Define an RPMSG node to work as a container for a group of RPMSG channels under the imx_rproc node. Each subnode within "rpmsg" represents an individual RPMSG channel. The name of each subnode corresponds to the channel name as defined by the remote processor. All remote devices associated with a given channel are defined as child nodes under the corresponding channel node. Signed-off-by: Shenwei Wang <shenwei.wang@nxp.com> --- .../devicetree/bindings/gpio/gpio-rpmsg.yaml | 55 +++++++++++++++++++ .../bindings/remoteproc/fsl,imx-rproc.yaml | 53 ++++++++++++++++++ 2 files changed, 108 insertions(+) create mode 100644 Documentation/devicetree/bindings/gpio/gpio-rpmsg.yaml diff --git a/Documentation/devicetree/bindings/gpio/gpio-rpmsg.yaml b/Documentation/devicetree/bindings/gpio/gpio-rpmsg.yaml new file mode 100644 index 000000000000..41eb2e149942 --- /dev/null +++ b/Documentation/devicetree/bindings/gpio/gpio-rpmsg.yaml @@ -0,0 +1,55 @@ +# SPDX-License-Identifier: (GPL-2.0-only OR BSD-2-Clause) +%YAML 1.2 +--- +$id: http://devicetree.org/schemas/gpio/gpio-rpmsg.yaml# +$schema: http://devicetree.org/meta-schemas/core.yaml# + +title: Generic RPMSG GPIO Controller + +maintainers: + - Shenwei Wang <shenwei.wang@nxp.com> + +description: + On an AMP platform, some GPIO controllers are exposed by the remote processor + through the RPMSG bus. The RPMSG GPIO transport protocol defines the packet + structure and communication flow between Linux and the remote firmware. Those + controllers are managed via this transport protocol. For more details of the + protocol, check the document below. + Documentation/driver-api/gpio/gpio-rpmsg.rst + +properties: + compatible: + oneOf: + - items: + - enum: + - fsl,rpmsg-gpio + - const: rpmsg-gpio + - const: rpmsg-gpio + + reg: + description: + The reg property represents the index of the GPIO controllers. Since + the driver manages controllers on a remote system, this index tells + the remote system which controller to operate. + maxItems: 1 + + "#gpio-cells": + const: 2 + + gpio-controller: true + + interrupt-controller: true + + "#interrupt-cells": + const: 2 + +required: + - compatible + - reg + - "#gpio-cells" + - gpio-controller + +allOf: + - $ref: /schemas/gpio/gpio.yaml# + +unevaluatedProperties: false diff --git a/Documentation/devicetree/bindings/remoteproc/fsl,imx-rproc.yaml b/Documentation/devicetree/bindings/remoteproc/fsl,imx-rproc.yaml index c18f71b64889..b9b559b186af 100644 --- a/Documentation/devicetree/bindings/remoteproc/fsl,imx-rproc.yaml +++ b/Documentation/devicetree/bindings/remoteproc/fsl,imx-rproc.yaml @@ -88,6 +88,34 @@ properties: This property is to specify the resource id of the remote processor in SoC which supports SCFW + rpmsg: + type: object + additionalProperties: false + description: + Represents the RPMSG bus between Linux and the remote system. Contains + a group of RPMSG channel devices running on the bus. + + properties: + rpmsg-io: + type: object + additionalProperties: false + properties: + '#address-cells': + const: 1 + + '#size-cells': + const: 0 + + patternProperties: + "^gpio@[0-9a-f]+$": + type: object + $ref: /schemas/gpio/gpio-rpmsg.yaml# + unevaluatedProperties: false + + required: + - '#address-cells' + - '#size-cells' + required: - compatible @@ -150,5 +178,30 @@ examples: &mu 3 1>; memory-region = <&vdev0buffer>, <&vdev0vring0>, <&vdev0vring1>, <&rsc_table>; syscon = <&src>; + + rpmsg { + rpmsg-io { + #address-cells = <1>; + #size-cells = <0>; + + gpio@0 { + compatible = "rpmsg-gpio"; + reg = <0>; + gpio-controller; + #gpio-cells = <2>; + #interrupt-cells = <2>; + interrupt-controller; + }; + + gpio@1 { + compatible = "rpmsg-gpio"; + reg = <1>; + gpio-controller; + #gpio-cells = <2>; + #interrupt-cells = <2>; + interrupt-controller; + }; + }; + }; }; ... -- 2.43.0 ^ permalink raw reply related [flat|nested] 9+ messages in thread
* Re: [PATCH v15 2/5] dt-bindings: remoteproc: imx_rproc: Add "rpmsg" subnode support 2026-07-21 20:46 ` [PATCH v15 2/5] dt-bindings: remoteproc: imx_rproc: Add "rpmsg" subnode support Shenwei Wang @ 2026-07-21 20:57 ` sashiko-bot 0 siblings, 0 replies; 9+ messages in thread From: sashiko-bot @ 2026-07-21 20:57 UTC (permalink / raw) To: Shenwei Wang; +Cc: robh, imx, Frank.Li, conor+dt, devicetree Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [Medium] The schema restrictively hardcodes the RPMSG channel subnode name to 'rpmsg-io', contradicting the documented design that allows dynamic channel names. -- --- Patch [2]: [PATCH v15 2/5] dt-bindings: remoteproc: imx_rproc: Add "rpmsg" subnode support --- commit 51724f4669935a1840ef5386c2737af63f1a9066 Author: Shenwei Wang <shenwei.wang@nxp.com> dt-bindings: remoteproc: imx_rproc: Add "rpmsg" subnode support This commit adds an "rpmsg" container node under imx_rproc to manage a group of RPMSG channel devices. Each subnode within "rpmsg" represents an individual RPMSG channel and is intended to be named dynamically based on the channel name defined by the remote processor. > diff --git a/Documentation/devicetree/bindings/remoteproc/fsl,imx-rproc.yaml b/Documentation/devicetree/bindings/remoteproc/fsl,imx-rproc.yaml > index c18f71b648890..b9b559b186aff 100644 > --- a/Documentation/devicetree/bindings/remoteproc/fsl,imx-rproc.yaml > +++ b/Documentation/devicetree/bindings/remoteproc/fsl,imx-rproc.yaml [ ... ] > @@ -88,6 +88,34 @@ properties: > This property is to specify the resource id of the remote processor in SoC > which supports SCFW > > + rpmsg: > + type: object > + additionalProperties: false > + description: > + Represents the RPMSG bus between Linux and the remote system. Contains > + a group of RPMSG channel devices running on the bus. > + > + properties: > + rpmsg-io: > + type: object > + additionalProperties: false [Severity: Medium] The commit message mentions that the name of each subnode corresponds to the channel name as defined by the remote processor. Does this hardcoded property block the use of dynamic channel names? Because the "rpmsg" node sets "additionalProperties: false", any device tree node defining an RPMSG channel with a name other than exactly "rpmsg-io" will fail schema validation. Should this be defined using "patternProperties" or by allowing additional properties for the container node so arbitrary remote processor channel names are permitted? > + properties: > + '#address-cells': > + const: 1 > + > + '#size-cells': > + const: 0 > + > + patternProperties: > + "^gpio@[0-9a-f]+$": > + type: object > + $ref: /schemas/gpio/gpio-rpmsg.yaml# > + unevaluatedProperties: false > + > + required: > + - '#address-cells' > + - '#size-cells' > + > required: > - compatible > -- Sashiko AI review · https://sashiko.dev/#/patchset/20260721204704.400781-1-shenwei.wang@oss.nxp.com?part=2 ^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH v15 3/5] rpmsg: core: match rpmsg device IDs by prefix 2026-07-21 20:46 [PATCH v15 0/5] Enable Remote GPIO over RPMSG on i.MX Platform Shenwei Wang 2026-07-21 20:46 ` [PATCH v15 1/5] docs: driver-api: gpio: rpmsg gpio driver over rpmsg bus Shenwei Wang 2026-07-21 20:46 ` [PATCH v15 2/5] dt-bindings: remoteproc: imx_rproc: Add "rpmsg" subnode support Shenwei Wang @ 2026-07-21 20:46 ` Shenwei Wang 2026-07-21 21:01 ` sashiko-bot 2026-07-21 20:46 ` [PATCH v15 4/5] gpio: rpmsg: add generic rpmsg GPIO driver Shenwei Wang 2026-07-21 20:46 ` [PATCH v15 5/5] arm64: dts: imx8ulp: Add rpmsg node under imx_rproc Shenwei Wang 4 siblings, 1 reply; 9+ messages in thread From: Shenwei Wang @ 2026-07-21 20:46 UTC (permalink / raw) To: Linus Walleij, Bartosz Golaszewski, Jonathan Corbet, Rob Herring, Krzysztof Kozlowski, Conor Dooley, Bjorn Andersson, Mathieu Poirier, Frank Li, Sascha Hauer Cc: Shuah Khan, linux-gpio, linux-doc, linux-kernel, Pengutronix Kernel Team, Fabio Estevam, Shenwei Wang, Peng Fan, devicetree, linux-remoteproc, imx, linux-arm-kernel, linux-imx, Arnaud POULIQUEN, b-padhi, Andrew Lunn From: Shenwei Wang <shenwei.wang@nxp.com> The current rpmsg_id_match() implementation requires an exact string match between the driver id_table entry and the rpmsg device name using strncmp() with RPMSG_NAME_SIZE. This makes it impossible for a driver to match a group of rpmsg devices sharing a common prefix (e.g. dynamically suffixed channel names). Update the matching logic to compare only the length of the id->name string, allowing id_table entries to act as prefixes. This enables drivers to bind to devices whose names start with the specified id->name. The implementation is copied from a reply by Mathieu. Signed-off-by: Shenwei Wang <shenwei.wang@nxp.com> --- drivers/rpmsg/rpmsg_core.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/rpmsg/rpmsg_core.c b/drivers/rpmsg/rpmsg_core.c index 04bfcc75f05b..97a4db52b040 100644 --- a/drivers/rpmsg/rpmsg_core.c +++ b/drivers/rpmsg/rpmsg_core.c @@ -386,7 +386,9 @@ ATTRIBUTE_GROUPS(rpmsg_dev); static inline int rpmsg_id_match(const struct rpmsg_device *rpdev, const struct rpmsg_device_id *id) { - return strncmp(id->name, rpdev->id.name, RPMSG_NAME_SIZE) == 0; + size_t len = strnlen(id->name, RPMSG_NAME_SIZE); + + return strncmp(id->name, rpdev->id.name, len) == 0; } /* match rpmsg channel and rpmsg driver */ -- 2.43.0 ^ permalink raw reply related [flat|nested] 9+ messages in thread
* Re: [PATCH v15 3/5] rpmsg: core: match rpmsg device IDs by prefix 2026-07-21 20:46 ` [PATCH v15 3/5] rpmsg: core: match rpmsg device IDs by prefix Shenwei Wang @ 2026-07-21 21:01 ` sashiko-bot 0 siblings, 0 replies; 9+ messages in thread From: sashiko-bot @ 2026-07-21 21:01 UTC (permalink / raw) To: Shenwei Wang; +Cc: Frank.Li, devicetree, conor+dt, imx, robh Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider: - [High] Global change to prefix matching breaks exact match semantics, causing namespace collisions and incorrect driver binding. - [High] Prefix matching breaks module auto-loading via udev because exported module aliases remain exact matches. -- --- Patch [3]: [PATCH v15 3/5] rpmsg: core: match rpmsg device IDs by prefix --- commit e561ac26959a610ff64bc4d231b963dec9f0caf9 Author: Shenwei Wang <shenwei.wang@nxp.com> rpmsg: core: match rpmsg device IDs by prefix This patch updates rpmsg_id_match to compare only the length of the driver's ID string instead of the full RPMSG_NAME_SIZE. This allows id_table entries to act as prefixes, enabling drivers to bind to dynamically suffixed device names. > diff --git a/drivers/rpmsg/rpmsg_core.c b/drivers/rpmsg/rpmsg_core.c > index 04bfcc75f05b4..97a4db52b0401 100644 > --- a/drivers/rpmsg/rpmsg_core.c > +++ b/drivers/rpmsg/rpmsg_core.c > @@ -386,7 +386,9 @@ ATTRIBUTE_GROUPS(rpmsg_dev); > static inline int rpmsg_id_match(const struct rpmsg_device *rpdev, > const struct rpmsg_device_id *id) > { > - return strncmp(id->name, rpdev->id.name, RPMSG_NAME_SIZE) == 0; > + size_t len = strnlen(id->name, RPMSG_NAME_SIZE); > + > + return strncmp(id->name, rpdev->id.name, len) == 0; [Severity: High] Does changing this to a strict prefix match prevent rpmsg drivers from enforcing an exact name match? If there is a driver for "sensor" and another for "sensor-temp", wouldn't the "sensor" driver incorrectly bind to the "sensor-temp" device if it happens to be evaluated first? It appears the correct architectural way to multiplex multiple identical services in the rpmsg framework is to use the exact same service name (channel name) and distinguish instances using unique source and destination endpoint addresses, rather than dynamically suffixed names. [Severity: High] Will this prefix matching logic break module auto-loading via udev? When the firmware creates a device with a dynamically suffixed name, rpmsg_uevent() emits a uevent containing the full suffixed name: drivers/rpmsg/rpmsg_core.c:rpmsg_uevent() { ... return add_uevent_var(env, "MODALIAS=" RPMSG_DEVICE_MODALIAS_FMT, rpdev->id.name); } However, scripts/mod/file2alias.c generates module aliases based on the exact string in the rpmsg_device_id table, without a trailing wildcard: scripts/mod/file2alias.c:do_rpmsg_entry() { ... module_alias_printf(mod, false, RPMSG_DEVICE_MODALIAS_FMT, *name); ... } Since the module alias lacks a wildcard, userspace tools like modprobe will attempt an exact string match and fail to load the driver for the suffixed device name. > } > > /* match rpmsg channel and rpmsg driver */ -- Sashiko AI review · https://sashiko.dev/#/patchset/20260721204704.400781-1-shenwei.wang@oss.nxp.com?part=3 ^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH v15 4/5] gpio: rpmsg: add generic rpmsg GPIO driver 2026-07-21 20:46 [PATCH v15 0/5] Enable Remote GPIO over RPMSG on i.MX Platform Shenwei Wang ` (2 preceding siblings ...) 2026-07-21 20:46 ` [PATCH v15 3/5] rpmsg: core: match rpmsg device IDs by prefix Shenwei Wang @ 2026-07-21 20:46 ` Shenwei Wang 2026-07-21 21:02 ` sashiko-bot 2026-07-21 20:46 ` [PATCH v15 5/5] arm64: dts: imx8ulp: Add rpmsg node under imx_rproc Shenwei Wang 4 siblings, 1 reply; 9+ messages in thread From: Shenwei Wang @ 2026-07-21 20:46 UTC (permalink / raw) To: Linus Walleij, Bartosz Golaszewski, Jonathan Corbet, Rob Herring, Krzysztof Kozlowski, Conor Dooley, Bjorn Andersson, Mathieu Poirier, Frank Li, Sascha Hauer Cc: Shuah Khan, linux-gpio, linux-doc, linux-kernel, Pengutronix Kernel Team, Fabio Estevam, Shenwei Wang, Peng Fan, devicetree, linux-remoteproc, imx, linux-arm-kernel, linux-imx, Arnaud POULIQUEN, b-padhi, Andrew Lunn, Bartosz Golaszewski From: Shenwei Wang <shenwei.wang@nxp.com> On an AMP platform, the system may include multiple processors: - MCUs running an RTOS - An MPU running Linux These processors communicate via the RPMSG protocol. The driver implements the standard GPIO interface, allowing the Linux side to control GPIO controllers which reside in the remote processor via RPMSG protocol. Cc: Bartosz Golaszewski <brgl@bgdev.pl> Cc: Andrew Lunn <andrew@lunn.ch> Signed-off-by: Shenwei Wang <shenwei.wang@nxp.com> --- drivers/gpio/Kconfig | 17 ++ drivers/gpio/Makefile | 1 + drivers/gpio/gpio-rpmsg.c | 587 ++++++++++++++++++++++++++++++++++++++ 3 files changed, 605 insertions(+) create mode 100644 drivers/gpio/gpio-rpmsg.c diff --git a/drivers/gpio/Kconfig b/drivers/gpio/Kconfig index f03c05288376..9fb8ab4d3616 100644 --- a/drivers/gpio/Kconfig +++ b/drivers/gpio/Kconfig @@ -1954,6 +1954,23 @@ config GPIO_SODAVILLE endmenu +menu "RPMSG GPIO drivers" + depends on RPMSG + +config GPIO_RPMSG + tristate "Generic RPMSG GPIO support" + depends on OF && REMOTEPROC + select GPIOLIB_IRQCHIP + default REMOTEPROC + help + Say Y here to enable GPIO controllers exposed over an RPMSG + communication channel to a remote processor. GPIO operations + and interrupt configuration requests are forwarded to the + remote side through RPMSG, allowing Linux to control GPIOs + implemented by a remote firmware. + +endmenu + menu "SPI GPIO expanders" depends on SPI_MASTER diff --git a/drivers/gpio/Makefile b/drivers/gpio/Makefile index fa14581e3995..89d26f1aaf1c 100644 --- a/drivers/gpio/Makefile +++ b/drivers/gpio/Makefile @@ -159,6 +159,7 @@ obj-$(CONFIG_GPIO_RDC321X) += gpio-rdc321x.o obj-$(CONFIG_GPIO_REALTEK_OTTO) += gpio-realtek-otto.o obj-$(CONFIG_GPIO_REG) += gpio-reg.o obj-$(CONFIG_GPIO_ROCKCHIP) += gpio-rockchip.o +obj-$(CONFIG_GPIO_RPMSG) += gpio-rpmsg.o obj-$(CONFIG_GPIO_RTD) += gpio-rtd.o obj-$(CONFIG_GPIO_RTD1625) += gpio-rtd1625.o obj-$(CONFIG_ARCH_SA1100) += gpio-sa1100.o diff --git a/drivers/gpio/gpio-rpmsg.c b/drivers/gpio/gpio-rpmsg.c new file mode 100644 index 000000000000..5d2d59e6314b --- /dev/null +++ b/drivers/gpio/gpio-rpmsg.c @@ -0,0 +1,587 @@ +// SPDX-License-Identifier: GPL-2.0-only +/* + * Copyright 2026 NXP + * + * The driver exports a standard gpiochip interface to control + * the GPIO controllers via RPMSG on a remote processor. + */ + +#include <linux/completion.h> +#include <linux/device.h> +#include <linux/err.h> +#include <linux/gpio/driver.h> +#include <linux/init.h> +#include <linux/irqdomain.h> +#include <linux/mod_devicetable.h> +#include <linux/module.h> +#include <linux/mutex.h> +#include <linux/of.h> +#include <linux/of_device.h> +#include <linux/of_platform.h> +#include <linux/platform_device.h> +#include <linux/remoteproc.h> +#include <linux/rpmsg.h> +#include <linux/virtio_gpio.h> + +#define GPIOS_PER_PORT_MAX 32 +#define RPMSG_TIMEOUT 1000 + +/* GPIO Receive MSG Type */ +#define GPIO_RPMSG_REPLY 0 +#define GPIO_RPMSG_NOTIFY 1 + +#define CHAN_NAME_PREFIX "rpmsg-io-" +#define GPIO_COMPAT_STR "rpmsg-gpio" + +struct rpmsg_gpio_response { + __u8 type; + union { + /* command reply */ + struct { + __u8 status; + __u8 value; + }; + + /* interrupt notification */ + struct { + __le16 line; + }; + }; +}; + +struct rpmsg_gpio_line { + u8 irq_shutdown; + u8 irq_unmask; + u8 irq_mask; + u32 irq_type; +}; + +struct rpmsg_gpio_port { + struct gpio_chip gc; + struct rpmsg_device *rpdev; + struct virtio_gpio_request *send_msg; + struct rpmsg_gpio_response *recv_msg; + struct completion cmd_complete; + struct mutex lock; + struct work_struct eoi_work; + DECLARE_BITMAP(pending_eoi, GPIOS_PER_PORT_MAX); + u32 ngpios; + u32 idx; + struct rpmsg_gpio_line lines[GPIOS_PER_PORT_MAX]; +}; + +static int rpmsg_gpio_send_message(struct rpmsg_gpio_port *port) +{ + int ret; + + reinit_completion(&port->cmd_complete); + + ret = rpmsg_send(port->rpdev->ept, port->send_msg, sizeof(*port->send_msg)); + if (ret) { + dev_err(&port->rpdev->dev, "rpmsg_send failed: cmd=%d ret=%d\n", + port->send_msg->type, ret); + return ret; + } + + ret = wait_for_completion_timeout(&port->cmd_complete, + msecs_to_jiffies(RPMSG_TIMEOUT)); + if (ret == 0) { + dev_err(&port->rpdev->dev, "rpmsg_send timeout! cmd=%d\n", + port->send_msg->type); + return -ETIMEDOUT; + } + + if (port->recv_msg->status != VIRTIO_GPIO_STATUS_OK) { + dev_err(&port->rpdev->dev, "remote core replies an error: cmd=%d!\n", + port->send_msg->type); + return -EINVAL; + } + + return 0; +} + +static struct virtio_gpio_request * +rpmsg_gpio_msg_prepare(struct rpmsg_gpio_port *port, u16 line, u16 cmd, u32 val) +{ + struct virtio_gpio_request *msg = port->send_msg; + + msg->type = cpu_to_le16(cmd); + msg->gpio = cpu_to_le16(line); + msg->value = cpu_to_le32(val); + + return msg; +} + +static int rpmsg_gpio_get(struct gpio_chip *gc, unsigned int line) +{ + struct rpmsg_gpio_port *port = gpiochip_get_data(gc); + int ret; + + guard(mutex)(&port->lock); + + rpmsg_gpio_msg_prepare(port, line, VIRTIO_GPIO_MSG_GET_VALUE, 0); + + ret = rpmsg_gpio_send_message(port); + return ret ? ret : port->recv_msg->value; +} + +static int rpmsg_gpio_get_direction(struct gpio_chip *gc, unsigned int line) +{ + struct rpmsg_gpio_port *port = gpiochip_get_data(gc); + int ret; + + guard(mutex)(&port->lock); + + rpmsg_gpio_msg_prepare(port, line, VIRTIO_GPIO_MSG_GET_DIRECTION, 0); + + ret = rpmsg_gpio_send_message(port); + if (ret) + return ret; + + switch (port->recv_msg->value) { + case VIRTIO_GPIO_DIRECTION_IN: + return GPIO_LINE_DIRECTION_IN; + case VIRTIO_GPIO_DIRECTION_OUT: + return GPIO_LINE_DIRECTION_OUT; + default: + break; + } + + return -EINVAL; +} + +static int rpmsg_gpio_direction_input(struct gpio_chip *gc, unsigned int line) +{ + struct rpmsg_gpio_port *port = gpiochip_get_data(gc); + + guard(mutex)(&port->lock); + + rpmsg_gpio_msg_prepare(port, line, VIRTIO_GPIO_MSG_SET_DIRECTION, + VIRTIO_GPIO_DIRECTION_IN); + + return rpmsg_gpio_send_message(port); +} + +static int rpmsg_gpio_set(struct gpio_chip *gc, unsigned int line, int val) +{ + struct rpmsg_gpio_port *port = gpiochip_get_data(gc); + + guard(mutex)(&port->lock); + + rpmsg_gpio_msg_prepare(port, line, VIRTIO_GPIO_MSG_SET_VALUE, val); + + return rpmsg_gpio_send_message(port); +} + +static int rpmsg_gpio_direction_output(struct gpio_chip *gc, unsigned int line, int val) +{ + struct rpmsg_gpio_port *port = gpiochip_get_data(gc); + int ret; + + guard(mutex)(&port->lock); + + rpmsg_gpio_msg_prepare(port, line, VIRTIO_GPIO_MSG_SET_VALUE, val); + ret = rpmsg_gpio_send_message(port); + if (ret) + return ret; + + rpmsg_gpio_msg_prepare(port, line, VIRTIO_GPIO_MSG_SET_DIRECTION, + VIRTIO_GPIO_DIRECTION_OUT); + return rpmsg_gpio_send_message(port); +} + +static int gpio_rpmsg_irq_set_type(struct irq_data *d, u32 type) +{ + struct rpmsg_gpio_port *port = irq_data_get_irq_chip_data(d); + u32 line = d->hwirq; + + switch (type) { + case IRQ_TYPE_EDGE_RISING: + type = VIRTIO_GPIO_IRQ_TYPE_EDGE_RISING; + break; + case IRQ_TYPE_EDGE_FALLING: + type = VIRTIO_GPIO_IRQ_TYPE_EDGE_FALLING; + break; + case IRQ_TYPE_EDGE_BOTH: + type = VIRTIO_GPIO_IRQ_TYPE_EDGE_BOTH; + break; + case IRQ_TYPE_LEVEL_LOW: + type = VIRTIO_GPIO_IRQ_TYPE_LEVEL_LOW; + break; + case IRQ_TYPE_LEVEL_HIGH: + type = VIRTIO_GPIO_IRQ_TYPE_LEVEL_HIGH; + break; + default: + dev_err(&port->rpdev->dev, "unsupported irq type: %u\n", type); + return -EINVAL; + } + + port->lines[line].irq_type = type; + + return 0; +} + +/* + * This unmask/mask function is invoked in two situations: + * - when an interrupt is being set up, and + * - after an interrupt has occurred. + * + * The GPIO driver does not access hardware registers directly. + * Instead, it caches all relevant information locally, and then sends + * the accumulated state to the remote system at this stage. + */ +static void gpio_rpmsg_unmask_irq(struct irq_data *d) +{ + struct rpmsg_gpio_port *port = irq_data_get_irq_chip_data(d); + u32 line = d->hwirq; + + port->lines[line].irq_unmask = 1; +} + +static void gpio_rpmsg_mask_irq(struct irq_data *d) +{ + struct rpmsg_gpio_port *port = irq_data_get_irq_chip_data(d); + u32 line = d->hwirq; + + /* + * When an interrupt occurs, the remote system masks the interrupt + * and then sends a notification to Linux. After Linux processes + * that notification, it sends an RPMsg command back to the remote + * system to unmask the interrupt again. + */ + port->lines[line].irq_mask = 1; +} + +static void gpio_rpmsg_irq_shutdown(struct irq_data *d) +{ + struct rpmsg_gpio_port *port = irq_data_get_irq_chip_data(d); + u32 line = d->hwirq; + + port->lines[line].irq_shutdown = 1; +} + +static void gpio_rpmsg_eoi_irq(struct irq_data *d) +{ + struct rpmsg_gpio_port *port = irq_data_get_irq_chip_data(d); + + set_bit(d->hwirq, port->pending_eoi); + schedule_work(&port->eoi_work); +} + +static void gpio_rpmsg_irq_bus_lock(struct irq_data *d) +{ + struct rpmsg_gpio_port *port = irq_data_get_irq_chip_data(d); + + mutex_lock(&port->lock); +} + +static void gpio_rpmsg_irq_bus_sync_unlock(struct irq_data *d) +{ + struct rpmsg_gpio_port *port = irq_data_get_irq_chip_data(d); + u32 line = d->hwirq; + + /* + * For mask irq, do nothing here. + * The remote system will mask interrupt after an interrupt occurs, + * and then send a notification to Linux system. After Linux system + * handles the notification, it sends an rpmsg back to the remote + * system to unmask this interrupt again. + */ + if (port->lines[line].irq_mask && !port->lines[line].irq_unmask) { + port->lines[line].irq_mask = 0; + mutex_unlock(&port->lock); + return; + } + + if (port->lines[line].irq_shutdown) { + rpmsg_gpio_msg_prepare(port, line, VIRTIO_GPIO_MSG_IRQ_TYPE, + VIRTIO_GPIO_IRQ_TYPE_NONE); + port->lines[line].irq_shutdown = 0; + } else { + rpmsg_gpio_msg_prepare(port, line, VIRTIO_GPIO_MSG_IRQ_TYPE, + port->lines[line].irq_type); + + if (port->lines[line].irq_unmask) + port->lines[line].irq_unmask = 0; + } + + rpmsg_gpio_send_message(port); + mutex_unlock(&port->lock); +} + +static const struct irq_chip gpio_rpmsg_irq_chip = { + .name = "rpmsg-gpio", + .irq_mask = gpio_rpmsg_mask_irq, + .irq_unmask = gpio_rpmsg_unmask_irq, + .irq_eoi = gpio_rpmsg_eoi_irq, + .irq_set_type = gpio_rpmsg_irq_set_type, + .irq_shutdown = gpio_rpmsg_irq_shutdown, + .irq_bus_lock = gpio_rpmsg_irq_bus_lock, + .irq_bus_sync_unlock = gpio_rpmsg_irq_bus_sync_unlock, + .flags = IRQCHIP_IMMUTABLE, +}; + +static void gpio_rpmsg_eoi_work(struct work_struct *work) +{ + struct rpmsg_gpio_port *port = + container_of(work, struct rpmsg_gpio_port, eoi_work); + unsigned long pending[BITS_TO_LONGS(GPIOS_PER_PORT_MAX)]; + unsigned int line; + + guard(mutex)(&port->lock); + + bitmap_copy(pending, port->pending_eoi, port->ngpios); + bitmap_zero(port->pending_eoi, port->ngpios); + + for_each_set_bit(line, pending, port->ngpios) { + rpmsg_gpio_msg_prepare(port, line, VIRTIO_GPIO_MSG_IRQ_TYPE, + port->lines[line].irq_type); + + if (rpmsg_gpio_send_message(port)) + dev_err(&port->rpdev->dev, "EOI error for line %u\n", line); + } +} + +static int rpmsg_gpiochip_register(struct rpmsg_device *rpdev, u32 idx, + struct device_node *np, const char *name) +{ + struct rpmsg_gpio_port *port; + struct gpio_irq_chip *girq; + struct gpio_chip *gc; + int ret; + + port = devm_kzalloc(&rpdev->dev, sizeof(*port), GFP_KERNEL); + if (!port) + return -ENOMEM; + + ret = devm_mutex_init(&rpdev->dev, &port->lock); + if (ret) + return ret; + + ret = of_property_read_u32(np, "ngpios", &port->ngpios); + if (ret || port->ngpios > GPIOS_PER_PORT_MAX) + port->ngpios = GPIOS_PER_PORT_MAX; + + port->send_msg = devm_kzalloc(&rpdev->dev, + sizeof(*port->send_msg), + GFP_KERNEL); + + port->recv_msg = devm_kzalloc(&rpdev->dev, + sizeof(*port->recv_msg), + GFP_KERNEL); + if (!port->send_msg || !port->recv_msg) + return -ENOMEM; + + INIT_WORK(&port->eoi_work, gpio_rpmsg_eoi_work); + init_completion(&port->cmd_complete); + port->rpdev = rpdev; + port->idx = idx; + + gc = &port->gc; + gc->owner = THIS_MODULE; + gc->parent = &rpdev->dev; + gc->fwnode = of_fwnode_handle(np); + gc->ngpio = port->ngpios; + gc->base = -1; + gc->label = devm_kasprintf(&rpdev->dev, GFP_KERNEL, "%s-gpio%d", + name, port->idx); + + gc->direction_input = rpmsg_gpio_direction_input; + gc->direction_output = rpmsg_gpio_direction_output; + gc->get_direction = rpmsg_gpio_get_direction; + gc->get = rpmsg_gpio_get; + gc->set = rpmsg_gpio_set; + + girq = &gc->irq; + gpio_irq_chip_set_chip(girq, &gpio_rpmsg_irq_chip); + girq->parent_handler = NULL; + girq->num_parents = 0; + girq->parents = NULL; + girq->default_type = IRQ_TYPE_NONE; + girq->handler = handle_fasteoi_irq; + + dev_set_drvdata(&rpdev->dev, port); + + return devm_gpiochip_add_data(&rpdev->dev, gc, port); +} + +static const char *rpmsg_get_rproc_node_name(struct rpmsg_device *rpdev) +{ + const char *name = NULL; + struct device_node *np; + struct rproc *rproc; + + rproc = rproc_get_by_child(&rpdev->dev); + if (!rproc) + return NULL; + + np = of_node_get(rproc->dev.of_node); + if (!np && rproc->dev.parent) + np = of_node_get(rproc->dev.parent->of_node); + + if (np) { + name = devm_kstrdup(&rpdev->dev, np->name, GFP_KERNEL); + of_node_put(np); + } + + return name; +} + +static struct device_node * +rpmsg_find_child_by_compat_reg(struct device_node *parent, const char *compat, u32 idx) +{ + struct device_node *child; + u32 reg; + + for_each_available_child_of_node(parent, child) { + if (!of_device_is_compatible(child, compat)) + continue; + + if (of_property_read_u32(child, "reg", ®)) + continue; + + if (reg == idx) + return child; + } + + return NULL; +} + +static struct device_node * +rpmsg_get_gpio_ofnode(struct rpmsg_device *rpdev, const char *compat, u32 idx) +{ + struct device_node *np_chan, *np_rproc, *np_rpmsg, *np_io; + struct rproc *rproc; + + rproc = rproc_get_by_child(&rpdev->dev); + if (!rproc) + return NULL; + + np_rproc = of_node_get(rproc->dev.of_node); + if (!np_rproc && rproc->dev.parent) + np_rproc = of_node_get(rproc->dev.parent->of_node); + + if (!np_rproc) + return NULL; + + np_rpmsg = of_get_child_by_name(np_rproc, "rpmsg"); + of_node_put(np_rproc); + if (!np_rpmsg) + return NULL; + + np_io = of_get_child_by_name(np_rpmsg, "rpmsg-io"); + of_node_put(np_rpmsg); + if (!np_io) + return NULL; + + np_chan = rpmsg_find_child_by_compat_reg(np_io, compat, idx); + of_node_put(np_io); + + return np_chan; +} + +static int rpmsg_get_gpio_index(const char *name, const char *prefix) +{ + const char *p; + int base = 10; + int val; + + if (!name) + return -EINVAL; + + /* Ensure correct prefix */ + if (!str_has_prefix(name, prefix)) + return -EINVAL; + + /* Find last '-' */ + p = strrchr(name, '-'); + + if (!p || *(p + 1) == '\0') + return -EINVAL; + + if (p[1] == '0' && (p[2] == 'x' || p[2] == 'X')) + base = 16; + + if (kstrtoint(p + 1, base, &val)) + return -EINVAL; + + return val; +} + +static int rpmsg_gpio_channel_callback(struct rpmsg_device *rpdev, void *data, + int len, void *priv, u32 src) +{ + struct rpmsg_gpio_response *msg = data; + struct rpmsg_gpio_port *port = NULL; + u32 line; + + port = dev_get_drvdata(&rpdev->dev); + + if (!port) { + dev_err(&rpdev->dev, "port is null\n"); + return -EINVAL; + } + + if (msg->type == GPIO_RPMSG_REPLY) { + *port->recv_msg = *msg; + complete(&port->cmd_complete); + } else if (msg->type == GPIO_RPMSG_NOTIFY) { + line = le16_to_cpu(msg->line); + generic_handle_domain_irq_safe(port->gc.irq.domain, line); + } else { + dev_err(&rpdev->dev, "wrong message type (0x%x)\n", msg->type); + } + + return 0; +} + +static int rpmsg_gpio_channel_probe(struct rpmsg_device *rpdev) +{ + struct device *dev = &rpdev->dev; + struct device_node *np; + const char *rproc_name; + int idx; + + idx = rpmsg_get_gpio_index(rpdev->id.name, CHAN_NAME_PREFIX); + if (idx < 0) + return -EINVAL; + + if (!dev->of_node) { + np = rpmsg_get_gpio_ofnode(rpdev, GPIO_COMPAT_STR, idx); + if (np) { + dev->of_node = np; + set_primary_fwnode(dev, of_fwnode_handle(np)); + return -EPROBE_DEFER; + } + } + + rproc_name = rpmsg_get_rproc_node_name(rpdev); + + return rpmsg_gpiochip_register(rpdev, idx, dev->of_node, rproc_name); +} + +static void rpmsg_gpio_channel_remove(struct rpmsg_device *rpdev) +{ + struct rpmsg_gpio_port *port = dev_get_drvdata(&rpdev->dev); + + cancel_work_sync(&port->eoi_work); +} + +static struct rpmsg_device_id rpmsg_gpio_channel_id_table[] = { + { .name = CHAN_NAME_PREFIX }, + { }, +}; +MODULE_DEVICE_TABLE(rpmsg, rpmsg_gpio_channel_id_table); + +static struct rpmsg_driver rpmsg_gpio_channel_client = { + .callback = rpmsg_gpio_channel_callback, + .id_table = rpmsg_gpio_channel_id_table, + .probe = rpmsg_gpio_channel_probe, + .remove = rpmsg_gpio_channel_remove, + .drv.name = KBUILD_MODNAME, +}; +module_rpmsg_driver(rpmsg_gpio_channel_client); + +MODULE_AUTHOR("Shenwei Wang <shenwei.wang@nxp.com>"); +MODULE_DESCRIPTION("generic rpmsg gpio driver"); +MODULE_LICENSE("GPL"); -- 2.43.0 ^ permalink raw reply related [flat|nested] 9+ messages in thread
* Re: [PATCH v15 4/5] gpio: rpmsg: add generic rpmsg GPIO driver 2026-07-21 20:46 ` [PATCH v15 4/5] gpio: rpmsg: add generic rpmsg GPIO driver Shenwei Wang @ 2026-07-21 21:02 ` sashiko-bot 0 siblings, 0 replies; 9+ messages in thread From: sashiko-bot @ 2026-07-21 21:02 UTC (permalink / raw) To: Shenwei Wang; +Cc: robh, imx, conor+dt, devicetree, Frank.Li Thank you for your contribution! Sashiko AI review found 7 potential issue(s) to consider: - [High] Data race between `gpio_rpmsg_eoi_irq()` and `gpio_rpmsg_eoi_work()` causes lost End-Of-Interrupt (EOI) signals. - [High] Explicitly disabling an IRQ fails to mask it on the remote hardware and causes an infinite interrupt storm. - [High] A timeout in `rpmsg_gpio_send_message()` permanently corrupts the request/response synchronization of the RPMSG channel. - [High] Use-After-Free vulnerability due to incorrect teardown ordering between `devm_gpiochip_add_data`, `cancel_work_sync`, and the RPMSG endpoint. - [High] Missing `gc->can_sleep = true` causes "scheduling while atomic" panics. - [Medium] The RPMSG callback does not validate the incoming message length, risking out-of-bounds memory reads. - [Medium] Implicit padding in `struct rpmsg_gpio_response` breaks cross-platform IPC. -- --- Patch [4]: [PATCH v15 4/5] gpio: rpmsg: add generic rpmsg GPIO driver --- commit 1ad498fb1fd9abd6b832044bd985e9e16c8577db Author: Shenwei Wang <shenwei.wang@nxp.com> Subject: gpio: rpmsg: add generic rpmsg GPIO driver On an AMP platform, the system may include multiple processors communicating via the RPMSG protocol. The driver implements the standard GPIO interface, allowing the Linux side to control GPIO controllers which reside in the remote processor via RPMSG protocol. diff --git a/drivers/gpio/gpio-rpmsg.c b/drivers/gpio/gpio-rpmsg.c new file mode 100644 index 0000000000000..5d2d59e6314b5 --- /dev/null +++ b/drivers/gpio/gpio-rpmsg.c @@ -0,0 +1,587 @@ [ ... ] > +struct rpmsg_gpio_response { > + __u8 type; > + union { > + /* command reply */ > + struct { > + __u8 status; > + __u8 value; > + }; > + > + /* interrupt notification */ > + struct { > + __le16 line; > + }; > + }; > +}; [Severity: Medium] Does the implicit padding inserted after type break cross-platform IPC if the remote firmware uses packed structures or a compiler with different padding rules? [ ... ] > +static int rpmsg_gpio_send_message(struct rpmsg_gpio_port *port) > +{ [ ... ] > + ret = wait_for_completion_timeout(&port->cmd_complete, > + msecs_to_jiffies(RPMSG_TIMEOUT)); > + if (ret == 0) { > + dev_err(&port->rpdev->dev, "rpmsg_send timeout! cmd=%d\n", > + port->send_msg->type); > + return -ETIMEDOUT; > + } [Severity: High] If the remote processor replies after this timeout, won't the next request immediately complete using the stale response? Since the protocol lacks transaction IDs, a single delayed response might permanently break the channel synchronization for all future transactions. [ ... ] > +static void gpio_rpmsg_irq_bus_sync_unlock(struct irq_data *d) > +{ > + struct rpmsg_gpio_port *port = irq_data_get_irq_chip_data(d); > + u32 line = d->hwirq; > + > + /* > + * For mask irq, do nothing here. > + * The remote system will mask interrupt after an interrupt occurs, > + * and then send a notification to Linux system. After Linux system > + * handles the notification, it sends an rpmsg back to the remote > + * system to unmask this interrupt again. > + */ > + if (port->lines[line].irq_mask && !port->lines[line].irq_unmask) { > + port->lines[line].irq_mask = 0; > + mutex_unlock(&port->lock); > + return; > + } [Severity: High] When Linux explicitly disables an IRQ via disable_irq(), it sets the mask flag. Will returning early here without sending a hardware mask command cause the remote processor to endlessly send interrupts, creating an interrupt storm? [ ... ] > +static void gpio_rpmsg_eoi_work(struct work_struct *work) > +{ > + struct rpmsg_gpio_port *port = > + container_of(work, struct rpmsg_gpio_port, eoi_work); > + unsigned long pending[BITS_TO_LONGS(GPIOS_PER_PORT_MAX)]; > + unsigned int line; > + > + guard(mutex)(&port->lock); > + > + bitmap_copy(pending, port->pending_eoi, port->ngpios); > + bitmap_zero(port->pending_eoi, port->ngpios); [Severity: High] Can this non-atomic clearing race with gpio_rpmsg_eoi_irq()? If a new interrupt fires and calls set_bit(d->hwirq, port->pending_eoi) between this bitmap_copy() and bitmap_zero(), won't the new end-of-interrupt signal be unconditionally overwritten and lost, locking up that GPIO line? [ ... ] > +static int rpmsg_gpiochip_register(struct rpmsg_device *rpdev, u32 idx, > + struct device_node *np, const char *name) > +{ [ ... ] > + gc->direction_input = rpmsg_gpio_direction_input; > + gc->direction_output = rpmsg_gpio_direction_output; > + gc->get_direction = rpmsg_gpio_get_direction; > + gc->get = rpmsg_gpio_get; > + gc->set = rpmsg_gpio_set; [Severity: High] Since the get and set callbacks wait on a completion and use a mutex (both of which can sleep), should gc->can_sleep be set to true? Without it, gpiolib might allow atomic fast-path accesses, which could trigger scheduling while atomic panics. [ ... ] > +static int rpmsg_gpio_channel_callback(struct rpmsg_device *rpdev, void *data, > + int len, void *priv, u32 src) > +{ > + struct rpmsg_gpio_response *msg = data; > + struct rpmsg_gpio_port *port = NULL; > + u32 line; > + > + port = dev_get_drvdata(&rpdev->dev); > + > + if (!port) { > + dev_err(&rpdev->dev, "port is null\n"); > + return -EINVAL; > + } > + > + if (msg->type == GPIO_RPMSG_REPLY) { > + *port->recv_msg = *msg; [Severity: Medium] Is there a risk of an out-of-bounds read here if the remote processor sends a malformed message smaller than sizeof(struct rpmsg_gpio_response)? [ ... ] > +static void rpmsg_gpio_channel_remove(struct rpmsg_device *rpdev) > +{ > + struct rpmsg_gpio_port *port = dev_get_drvdata(&rpdev->dev); > + > + cancel_work_sync(&port->eoi_work); > +} [Severity: High] Does the use of devm_gpiochip_add_data() during registration cause the GPIO chip to remain active after rpmsg_gpio_channel_remove() completes? If an interrupt arrives right after this cancel_work_sync(), couldn't the work be re-queued and executed on freed memory once devres finally cleans up the port? -- Sashiko AI review · https://sashiko.dev/#/patchset/20260721204704.400781-1-shenwei.wang@oss.nxp.com?part=4 ^ permalink raw reply related [flat|nested] 9+ messages in thread
* [PATCH v15 5/5] arm64: dts: imx8ulp: Add rpmsg node under imx_rproc 2026-07-21 20:46 [PATCH v15 0/5] Enable Remote GPIO over RPMSG on i.MX Platform Shenwei Wang ` (3 preceding siblings ...) 2026-07-21 20:46 ` [PATCH v15 4/5] gpio: rpmsg: add generic rpmsg GPIO driver Shenwei Wang @ 2026-07-21 20:46 ` Shenwei Wang 4 siblings, 0 replies; 9+ messages in thread From: Shenwei Wang @ 2026-07-21 20:46 UTC (permalink / raw) To: Linus Walleij, Bartosz Golaszewski, Jonathan Corbet, Rob Herring, Krzysztof Kozlowski, Conor Dooley, Bjorn Andersson, Mathieu Poirier, Frank Li, Sascha Hauer Cc: Shuah Khan, linux-gpio, linux-doc, linux-kernel, Pengutronix Kernel Team, Fabio Estevam, Shenwei Wang, Peng Fan, devicetree, linux-remoteproc, imx, linux-arm-kernel, linux-imx, Arnaud POULIQUEN, b-padhi, Andrew Lunn From: Shenwei Wang <shenwei.wang@nxp.com> Add the RPMSG bus node along with its GPIO subnodes to the device tree. Enable remote device communication and GPIO control via RPMSG on the i.MX platform. Signed-off-by: Shenwei Wang <shenwei.wang@nxp.com> --- arch/arm64/boot/dts/freescale/imx8ulp.dtsi | 25 ++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/arch/arm64/boot/dts/freescale/imx8ulp.dtsi b/arch/arm64/boot/dts/freescale/imx8ulp.dtsi index c6d1bb9edf38..5a62e0357fa7 100644 --- a/arch/arm64/boot/dts/freescale/imx8ulp.dtsi +++ b/arch/arm64/boot/dts/freescale/imx8ulp.dtsi @@ -190,6 +190,31 @@ scmi_sensor: protocol@15 { cm33: remoteproc-cm33 { compatible = "fsl,imx8ulp-cm33"; status = "disabled"; + + rpmsg { + rpmsg-io { + #address-cells = <1>; + #size-cells = <0>; + + rpmsg_gpioa: gpio@0 { + compatible = "rpmsg-gpio"; + reg = <0>; + gpio-controller; + #gpio-cells = <2>; + #interrupt-cells = <2>; + interrupt-controller; + }; + + rpmsg_gpiob: gpio@1 { + compatible = "rpmsg-gpio"; + reg = <1>; + gpio-controller; + #gpio-cells = <2>; + #interrupt-cells = <2>; + interrupt-controller; + }; + }; + }; }; soc: soc@0 { -- 2.43.0 ^ permalink raw reply related [flat|nested] 9+ messages in thread
end of thread, other threads:[~2026-07-21 21:02 UTC | newest] Thread overview: 9+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-07-21 20:46 [PATCH v15 0/5] Enable Remote GPIO over RPMSG on i.MX Platform Shenwei Wang 2026-07-21 20:46 ` [PATCH v15 1/5] docs: driver-api: gpio: rpmsg gpio driver over rpmsg bus Shenwei Wang 2026-07-21 20:46 ` [PATCH v15 2/5] dt-bindings: remoteproc: imx_rproc: Add "rpmsg" subnode support Shenwei Wang 2026-07-21 20:57 ` sashiko-bot 2026-07-21 20:46 ` [PATCH v15 3/5] rpmsg: core: match rpmsg device IDs by prefix Shenwei Wang 2026-07-21 21:01 ` sashiko-bot 2026-07-21 20:46 ` [PATCH v15 4/5] gpio: rpmsg: add generic rpmsg GPIO driver Shenwei Wang 2026-07-21 21:02 ` sashiko-bot 2026-07-21 20:46 ` [PATCH v15 5/5] arm64: dts: imx8ulp: Add rpmsg node under imx_rproc Shenwei Wang
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox