Devicetree
 help / color / mirror / Atom feed
* [PATCH v2 0/2] dmaengine: apple-admac: Add support for M3 generation
@ 2026-07-29 11:46 Sasha Finkelstein
  2026-07-29 11:46 ` [PATCH v2 1/2] dt-bindings: dma: apple,admac: Add M3 generation ADMACs Sasha Finkelstein
  2026-07-29 11:46 ` [PATCH v2 2/2] dmaengine: apple-admac: " Sasha Finkelstein
  0 siblings, 2 replies; 4+ messages in thread
From: Sasha Finkelstein @ 2026-07-29 11:46 UTC (permalink / raw)
  To: Sven Peter, Janne Grunau, Vinod Koul, Frank Li, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley, Martin Povišer
  Cc: asahi, linux-arm-kernel, dmaengine, devicetree, linux-kernel,
	Sasha Finkelstein, Joshua Peisach

The ADMACs present in M3 series devices (t8122 and t603x SoCs) need
additional register writes in order to function correctly. Add a new
compatible chain for those, and change the driver to do the write.

To simplify the merge strategy, the device tree entries will be sent
in a future patch series.

Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
Changes in v2:
- Typo fix
- Link to v1: https://patch.msgid.link/20260725-t603x-admac-v1-0-6a4dec023f02@chaosmail.tech

---
Sasha Finkelstein (2):
      dt-bindings: dma: apple,admac: Add M3 generation ADMACs
      dmaengine: apple-admac: Add M3 generation ADMACs

 Documentation/devicetree/bindings/dma/apple,admac.yaml | 10 ++++++++--
 drivers/dma/apple-admac.c                              | 32 ++++++++++++++++++++++++++++++--
 2 files changed, 38 insertions(+), 4 deletions(-)
---
base-commit: 0ce37745d4bfbc493f718169c3974898ffec8ee7
change-id: 20260725-t603x-admac-a1b07a2ccb54

Best regards,
--  
Sasha Finkelstein <k@chaosmail.tech>


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH v2 1/2] dt-bindings: dma: apple,admac: Add M3 generation ADMACs
  2026-07-29 11:46 [PATCH v2 0/2] dmaengine: apple-admac: Add support for M3 generation Sasha Finkelstein
@ 2026-07-29 11:46 ` Sasha Finkelstein
  2026-07-29 11:46 ` [PATCH v2 2/2] dmaengine: apple-admac: " Sasha Finkelstein
  1 sibling, 0 replies; 4+ messages in thread
From: Sasha Finkelstein @ 2026-07-29 11:46 UTC (permalink / raw)
  To: Sven Peter, Janne Grunau, Vinod Koul, Frank Li, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley, Martin Povišer
  Cc: asahi, linux-arm-kernel, dmaengine, devicetree, linux-kernel,
	Sasha Finkelstein, Joshua Peisach

The admacs seen in M3-generation SoCs (t603x, t8122) need additional
configuration writes and so are getting a new compatible chain.

Acked-by: Rob Herring (Arm) <robh@kernel.org>
Reviewed-by: Joshua Peisach <jpeisach@ubuntu.com>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
 Documentation/devicetree/bindings/dma/apple,admac.yaml | 10 ++++++++--
 1 file changed, 8 insertions(+), 2 deletions(-)

diff --git a/Documentation/devicetree/bindings/dma/apple,admac.yaml b/Documentation/devicetree/bindings/dma/apple,admac.yaml
index 6a200cbd7d02..5b4fd8348f99 100644
--- a/Documentation/devicetree/bindings/dma/apple,admac.yaml
+++ b/Documentation/devicetree/bindings/dma/apple,admac.yaml
@@ -10,7 +10,7 @@ description: |
   Apple's Audio DMA Controller (ADMAC) is used to fetch and store audio samples
   on SoCs from the "Apple Silicon" family.
 
-  The controller has been seen with up to 24 channels. Even-numbered channels
+  The controller has been seen with up to 32 channels. Even-numbered channels
   are TX-only, odd-numbered are RX-only. Individual channels are coupled to
   fixed device endpoints.
 
@@ -33,6 +33,12 @@ properties:
               - apple,t8103-admac
               - apple,t8112-admac
           - const: apple,admac
+      - items:
+          - enum:
+              - apple,t6030-admac
+              - apple,t6031-admac
+          - const: apple,t8122-admac
+      - const: apple,t8122-admac
 
   reg:
     maxItems: 1
@@ -43,7 +49,7 @@ properties:
       Clients specify a single cell with channel number.
 
   dma-channels:
-    maximum: 24
+    maximum: 32
 
   interrupts:
     minItems: 4

-- 
2.55.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [PATCH v2 2/2] dmaengine: apple-admac: Add M3 generation ADMACs
  2026-07-29 11:46 [PATCH v2 0/2] dmaengine: apple-admac: Add support for M3 generation Sasha Finkelstein
  2026-07-29 11:46 ` [PATCH v2 1/2] dt-bindings: dma: apple,admac: Add M3 generation ADMACs Sasha Finkelstein
@ 2026-07-29 11:46 ` Sasha Finkelstein
  2026-07-29 11:56   ` sashiko-bot
  1 sibling, 1 reply; 4+ messages in thread
From: Sasha Finkelstein @ 2026-07-29 11:46 UTC (permalink / raw)
  To: Sven Peter, Janne Grunau, Vinod Koul, Frank Li, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley, Martin Povišer
  Cc: asahi, linux-arm-kernel, dmaengine, devicetree, linux-kernel,
	Sasha Finkelstein

The admacs present on t8122 and t603x SoCs need additional writes in
order to operate correctly. The exact purpose of this register
is unknown

Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
 drivers/dma/apple-admac.c | 32 ++++++++++++++++++++++++++++++--
 1 file changed, 30 insertions(+), 2 deletions(-)

diff --git a/drivers/dma/apple-admac.c b/drivers/dma/apple-admac.c
index 14a5ee14a481..72ff677c8ce5 100644
--- a/drivers/dma/apple-admac.c
+++ b/drivers/dma/apple-admac.c
@@ -39,10 +39,14 @@
 
 #define FLAG_DESC_NOTIFY	BIT(16)
 
+#define T8122_UNK_28_VAL	0x200000
+
 #define REG_TX_START		0x0000
 #define REG_TX_STOP		0x0004
 #define REG_RX_START		0x0008
 #define REG_RX_STOP		0x000c
+#define REG_UNK_28		0x0028
+#define REG_UNK_2C		0x002c
 #define REG_IMPRINT		0x0090
 #define REG_TX_SRAM_SIZE	0x0094
 #define REG_RX_SRAM_SIZE	0x0098
@@ -127,6 +131,7 @@ struct admac_data {
 	struct mutex cache_alloc_lock;
 	struct admac_sram txcache, rxcache;
 
+	bool set_unk28;
 	int irq;
 	int irq_index;
 	int nchannels;
@@ -147,6 +152,10 @@ struct admac_tx {
 	struct list_head node;
 };
 
+struct admac_hw {
+	bool set_unk28;
+};
+
 static int admac_alloc_sram_carveout(struct admac_data *ad,
 				     enum dma_transfer_direction dir,
 				     u32 *out)
@@ -747,6 +756,11 @@ static int admac_device_config(struct dma_chan *chan,
 	u32 bus_width = readl_relaxed(ad->base + REG_BUS_WIDTH(adchan->no)) &
 		~(BUS_WIDTH_WORD_SIZE | BUS_WIDTH_FRAME_SIZE);
 
+	if (ad->set_unk28) {
+		writel_relaxed(T8122_UNK_28_VAL, ad->base + REG_UNK_28);
+		writel_relaxed(T8122_UNK_28_VAL, ad->base + REG_UNK_2C);
+	}
+
 	switch (is_tx ? config->dst_addr_width : config->src_addr_width) {
 	case DMA_SLAVE_BUSWIDTH_1_BYTE:
 		wordsize = 1;
@@ -805,6 +819,7 @@ static int admac_probe(struct platform_device *pdev)
 	struct device_node *np = pdev->dev.of_node;
 	struct admac_data *ad;
 	struct dma_device *dma;
+	const struct admac_hw *hw;
 	int nchannels;
 	int err, irq, i;
 
@@ -813,6 +828,9 @@ static int admac_probe(struct platform_device *pdev)
 		dev_err(&pdev->dev, "missing or invalid dma-channels property\n");
 		return -EINVAL;
 	}
+	hw = of_device_get_match_data(&pdev->dev);
+	if (!hw)
+		return -EINVAL;
 
 	ad = devm_kzalloc(&pdev->dev, struct_size(ad, channels, nchannels), GFP_KERNEL);
 	if (!ad)
@@ -821,6 +839,7 @@ static int admac_probe(struct platform_device *pdev)
 	platform_set_drvdata(pdev, ad);
 	ad->dev = &pdev->dev;
 	ad->nchannels = nchannels;
+	ad->set_unk28 = hw->set_unk28;
 	mutex_init(&ad->cache_alloc_lock);
 
 	/*
@@ -935,9 +954,18 @@ static void admac_remove(struct platform_device *pdev)
 	reset_control_rearm(ad->rstc);
 }
 
+static const struct admac_hw admac_t8103_hw = {
+	.set_unk28 = false,
+};
+
+static const struct admac_hw admac_t8122_hw = {
+	.set_unk28 = true,
+};
+
 static const struct of_device_id admac_of_match[] = {
-	{ .compatible = "apple,t8103-admac", },
-	{ .compatible = "apple,admac", },
+	{ .compatible = "apple,t8122-admac", .data = &admac_t8122_hw },
+	{ .compatible = "apple,t8103-admac", .data = &admac_t8103_hw },
+	{ .compatible = "apple,admac", .data = &admac_t8103_hw },
 	{ }
 };
 MODULE_DEVICE_TABLE(of, admac_of_match);

-- 
2.55.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH v2 2/2] dmaengine: apple-admac: Add M3 generation ADMACs
  2026-07-29 11:46 ` [PATCH v2 2/2] dmaengine: apple-admac: " Sasha Finkelstein
@ 2026-07-29 11:56   ` sashiko-bot
  0 siblings, 0 replies; 4+ messages in thread
From: sashiko-bot @ 2026-07-29 11:56 UTC (permalink / raw)
  To: Sasha Finkelstein; +Cc: devicetree, robh, Frank.Li, dmaengine, vkoul, conor+dt

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

Pre-existing issues:
- [High] The driver schedules a tasklet for DMA channel completion but fails to kill it upon driver unbind, leading to a Use-After-Free.
- [High] Missing memory barrier between CPU writes to the DMA buffer and triggering the hardware via MMIO.
--

--- Patch [2]: [PATCH v2 2/2] dmaengine: apple-admac: Add M3 generation ADMACs ---
commit 3e4665bdfbbc14988e79c929d83bff445def0885
Author: Sasha Finkelstein <k@chaosmail.tech>

dmaengine: apple-admac: Add M3 generation ADMACs
    
The admacs present on t8122 and t603x SoCs need additional writes in
order to operate correctly. The exact purpose of this register
is unknown

> diff --git a/drivers/dma/apple-admac.c b/drivers/dma/apple-admac.c
> index 14a5ee14a4815..72ff677c8ce54 100644
> --- a/drivers/dma/apple-admac.c
> +++ b/drivers/dma/apple-admac.c
[ ... ]
> @@ -935,9 +954,18 @@ static void admac_remove(struct platform_device *pdev)
>  	reset_control_rearm(ad->rstc);
>  }

[Severity: High]
This isn't a bug introduced by this patch, but I noticed the driver schedules
a tasklet for DMA channel completion but fails to kill it upon driver unbind.

Does this leave the code open to a use-after-free? If an interrupt fires just
before free_irq() and schedules the tasklet, the tasklet may run after
admac_remove() returns and the devm_kzalloc managed memory (struct admac_data)
is freed.

Could we add a call to tasklet_kill() during the teardown sequence?

[Severity: High]
This is another pre-existing issue not touched by this patch, but I noticed
missing memory barriers when the hardware is started via MMIO.

Looking at admac_start_chan() and admac_cyclic_write_one_desc():

drivers/dma/apple-admac.c:admac_start_chan() {
    ...
	switch (admac_chan_direction(adchan->no)) {
	case DMA_MEM_TO_DEV:
		writel_relaxed(startbit, ad->base + REG_TX_START);
		break;
    ...
}

drivers/dma/apple-admac.c:admac_cyclic_write_one_desc() {
    ...
	writel_relaxed(lower_32_bits(addr), ad->base + REG_DESC_WRITE(channo));
	writel_relaxed(upper_32_bits(addr), ad->base + REG_DESC_WRITE(channo));
    ...
}

Could CPU writes to the DMA buffer be delayed and become visible to the DMA
controller only after it starts fetching data? 

Since writel_relaxed() does not include a memory barrier on ARM64 architectures
and spin_lock only provides ACQUIRE semantics, prior memory stores to the DMA
buffer might be reordered after the MMIO write. Does this require a memory
barrier to prevent transmitting stale data?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260729-t603x-admac-v2-0-e4b2bb6ca45e@chaosmail.tech?part=2

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-07-29 11:56 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-29 11:46 [PATCH v2 0/2] dmaengine: apple-admac: Add support for M3 generation Sasha Finkelstein
2026-07-29 11:46 ` [PATCH v2 1/2] dt-bindings: dma: apple,admac: Add M3 generation ADMACs Sasha Finkelstein
2026-07-29 11:46 ` [PATCH v2 2/2] dmaengine: apple-admac: " Sasha Finkelstein
2026-07-29 11:56   ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox