Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: "Abdurrahman Hussain" <abdurrahman@nexthop.ai>
To: "Andi Shyti" <andi.shyti@kernel.org>,
	"Abdurrahman Hussain" <abdurrahman@nexthop.ai>
Cc: "Michal Simek" <michal.simek@amd.com>,
	"Wolfram Sang" <wsa+renesas@sang-engineering.com>,
	"Raviteja Narayanam" <raviteja.narayanam@xilinx.com>,
	"Wolfram Sang" <wsa@kernel.org>,
	"Manikanta Guntupalli" <manikanta.guntupalli@amd.com>,
	"Shubhrajyoti Datta" <shubhrajyoti.datta@amd.com>,
	<linux-arm-kernel@lists.infradead.org>,
	<linux-i2c@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
	<stable@vger.kernel.org>
Subject: Re: [PATCH v6 1/3] i2c: xiic: preserve PEC byte length in SMBus block read setup
Date: Thu, 24 Sep 2026 17:09:10 -0700	[thread overview]
Message-ID: <DLNYLDZ4WO92.16A9I7PRTH3WL@nexthop.ai> (raw)
In-Reply-To: <arWC6PFh3YVgU1Pd@zenone.zhora.eu>

Hi Andi,

On Thu Sep 24, 2026 at 1:09 PM PDT, Andi Shyti wrote:
> what if rxmsg is 1? Before this could never happen because we
> were checking for rxmsg_len == 0 or 1 and we were ending up here
> for values greater than 1.
>
> In patch 2 you fix things, but we don't want to have dependencies
> between patches.
>

Confirmed. The widened condition makes the else branch reachable with
rxmsg_len < 2, where rfd_set = rxmsg_len - 2 wraps the u8. Traced on
hardware against a zero-length block read, sweeping pec_len:

  pec_len:             0    1     2      3
  v6 patch 1 rfd_set:  0    0    254    254
  v7 patch 1 rfd_set:  0    0     0      1

It doesn't actually hang on my boards -- 254 lands in the 4-bit RFD
field as 14, and both slaves I have keep clocking past the end of the
block, so the FIFO still reaches 15. The programmed value is wrong
regardless.

Restoring the old "(rxmsg_len == 1) || (rxmsg_len == 0)" isn't right
either: pec_len isn't limited to 0 or 1, because i2c-dev sets msg->len
from caller-supplied buf[0]. At rxmsg_len == 1, pec_len == 2 the padded
branch would record smbus_actual_len = 4 while draining only 3.

So v7 moves the bounds into patch 1, where the arithmetic is introduced:

  - the guard becomes (rxmsg_len + pec_len > IIC_RX_FIFO_DEPTH), which
    is what keeps rfd_set inside the 4-bit field;
  - the else branch becomes rfd_set = rxmsg_len + pec_len - 2, identical
    to the old expression at pec_len == 0 and unable to underflow, since
    the padded branch already takes everything below MIN_LEN total.

Patch 2 is then just - 2 to - 1. Resulting tree is identical to v6.

I also finally exercised the atomic trim you asked for in v5, by routing
transfers through xiic_xfer_atomic: it fires, and block lengths 0 to 32
read back correctly on that path.

Two notes from the per-patch run. Unpatched, pmbus_core creates no mfr_*
files for these devices and every PEC block read returns -EIO; with the
series they read correctly. But patch 1 alone isn't observable
end-to-end (patch 3's -EIO masks it), and patch 2 changes nothing I can
measure on my two slaves -- its bug needs one that NACKs promptly rather
than streaming.

While I have your attention: the other xiic patch, "i2c: xiic: restore
non-managed runtime PM to fix clk WARN flood", is still unapplied. Andy
acked it on 10 Sep and the review comment it had is closed. It fixes a
regression from my own 50c63491ff26, which is in both v7.1 and v7.2, so
7.3-rcX would be a good target if it looks right to you.

  https://patch.msgid.link/20260821-i2c-xiic-restore-runtime-pm-teardown-v7-1-954e06765144@nexthop.ai

Unrelated, for later: smbus_block_read is only cleared in the BNB
handler, which the atomic path never reaches.

Abdurrahman



  reply	other threads:[~2026-09-25  0:09 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24  1:45 [PATCH v6 0/3] i2c: xiic: fix SMBus block read and PEC support Abdurrahman Hussain
2026-09-24  1:45 ` [PATCH v6 1/3] i2c: xiic: preserve PEC byte length in SMBus block read setup Abdurrahman Hussain
2026-09-24 20:09   ` Andi Shyti
2026-09-25  0:09     ` Abdurrahman Hussain [this message]
2026-09-24  1:45 ` [PATCH v6 2/3] i2c: xiic: defer RX_FULL until all trailing bytes are in FIFO Abdurrahman Hussain
2026-09-24  1:45 ` [PATCH v6 3/3] i2c: xiic: don't clobber msg->len to signal block-read completion Abdurrahman Hussain

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DLNYLDZ4WO92.16A9I7PRTH3WL@nexthop.ai \
    --to=abdurrahman@nexthop.ai \
    --cc=andi.shyti@kernel.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-i2c@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=manikanta.guntupalli@amd.com \
    --cc=michal.simek@amd.com \
    --cc=raviteja.narayanam@xilinx.com \
    --cc=shubhrajyoti.datta@amd.com \
    --cc=stable@vger.kernel.org \
    --cc=wsa+renesas@sang-engineering.com \
    --cc=wsa@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox