* [PATCH v5 0/6] spmi: apple: Additional commands and interrupt support.
@ 2026-08-08 11:31 Sasha Finkelstein
2026-08-08 11:31 ` [PATCH v5 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122 Sasha Finkelstein
` (5 more replies)
0 siblings, 6 replies; 13+ messages in thread
From: Sasha Finkelstein @ 2026-08-08 11:31 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Alba Mendez
The SPMI bus has grown additional responsibilities in the M3
generation, making the current driver insufficient. Add M3 comatibles,
support for slave-sent interrupts, FIFO interrupts, power management
commands, parity validation, and fix locking.
To simplify the merge strategy, the device tree entries will be sent
in a future patch series.
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
Changes in v5:
- Style fixes per review
- Fix fifo flush
- Link to v4: https://patch.msgid.link/20260805-t603x-spmi-v4-0-c15a12d9a7d1@chaosmail.tech
Changes in v4:
- Re-do error recovery.
- Fix an address calculation mistake
- Link to v3: https://patch.msgid.link/20260803-t603x-spmi-v3-0-c17b506d91a1@chaosmail.tech
Changes in v3:
- Rework interrupt support
- Address review comments
- Link to v2: https://patch.msgid.link/20260728-t603x-spmi-v2-0-f43e5f10e583@chaosmail.tech
Changes in v2:
- Change locking to non-interruptible
- Reorder irq ack
- Clarify dt binding
- Some data type cleanups
- Link to v1: https://patch.msgid.link/20260725-t603x-spmi-v1-0-e1a29fcd2d38@chaosmail.tech
---
Alba Mendez (5):
spmi: apple: Validate FIFO state
spmi: apple: check transaction status
spmi: apple: Implement remaining commands
spmi: apple: lock around FIFOs
spmi: apple: Add interrupt functionality
Sasha Finkelstein (1):
dt-bindings: spmi: apple,spmi: Add t603x and t8122
Documentation/devicetree/bindings/spmi/apple,spmi.yaml | 15 +++++
drivers/spmi/Kconfig | 3 +-
drivers/spmi/spmi-apple-controller.c | 389 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++----------
3 files changed, 375 insertions(+), 32 deletions(-)
---
base-commit: 0ce37745d4bfbc493f718169c3974898ffec8ee7
change-id: 20260725-t603x-spmi-74630bf1b0a0
Best regards,
--
Sasha Finkelstein <k@chaosmail.tech>
^ permalink raw reply [flat|nested] 13+ messages in thread
* [PATCH v5 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122
2026-08-08 11:31 [PATCH v5 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
@ 2026-08-08 11:31 ` Sasha Finkelstein
2026-08-08 11:36 ` sashiko-bot
2026-08-08 11:31 ` [PATCH v5 2/6] spmi: apple: Validate FIFO state Sasha Finkelstein
` (4 subsequent siblings)
5 siblings, 1 reply; 13+ messages in thread
From: Sasha Finkelstein @ 2026-08-08 11:31 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein
Add t603x and t8122 compatibles, interrupt support, and support for
SPMI controllers that are not always-on.
Keeping the "interrupt-controller" property as optional, as taking the
j514c as an example, we only need this functionality on 3 out of 10
SPMI controllers present on this SoC.
Reviewed-by: Janne Grunau <j@jannau.net>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
Documentation/devicetree/bindings/spmi/apple,spmi.yaml | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/Documentation/devicetree/bindings/spmi/apple,spmi.yaml b/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
index 3e5b14bc8c31..fceed47b2cd1 100644
--- a/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
+++ b/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
@@ -20,8 +20,11 @@ properties:
- items:
- enum:
- apple,t6020-spmi
+ - apple,t6030-spmi
+ - apple,t6031-spmi
- apple,t8012-spmi
- apple,t8015-spmi
+ - apple,t8122-spmi
- const: apple,t8103-spmi
- items:
- enum:
@@ -34,6 +37,18 @@ properties:
reg:
maxItems: 1
+ interrupts:
+ maxItems: 1
+ description: Optional, operates in polled mode if not present
+
+ interrupt-controller: true
+
+ "#interrupt-cells":
+ const: 2
+
+ power-domains:
+ maxItems: 1
+
required:
- compatible
- reg
--
2.55.0
^ permalink raw reply related [flat|nested] 13+ messages in thread
* [PATCH v5 2/6] spmi: apple: Validate FIFO state
2026-08-08 11:31 [PATCH v5 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
2026-08-08 11:31 ` [PATCH v5 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122 Sasha Finkelstein
@ 2026-08-08 11:31 ` Sasha Finkelstein
2026-08-08 11:52 ` sashiko-bot
2026-08-08 11:31 ` [PATCH v5 3/6] spmi: apple: check transaction status Sasha Finkelstein
` (3 subsequent siblings)
5 siblings, 1 reply; 13+ messages in thread
From: Sasha Finkelstein @ 2026-08-08 11:31 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Alba Mendez
From: Alba Mendez <me@alba.sh>
Check for data before reading the body of a reply, and check for
end of data afterwards.
Signed-off-by: Alba Mendez <me@alba.sh>
Reviewed-by: Janne Grunau <j@jannau.net>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
drivers/spmi/spmi-apple-controller.c | 30 ++++++++++++++++++++++++++++++
1 file changed, 30 insertions(+)
diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
index 376cf682c43e..15721cb41d5c 100644
--- a/drivers/spmi/spmi-apple-controller.c
+++ b/drivers/spmi/spmi-apple-controller.c
@@ -21,7 +21,9 @@
#define SPMI_STATUS_REG 0
#define SPMI_CMD_REG 0x4
#define SPMI_RSP_REG 0x8
+#define SPMI_ACT_REG 0xa4
+#define SPMI_ACT_FIFO_FLUSH BIT(0)
#define SPMI_RX_FIFO_EMPTY BIT(24)
#define REG_POLL_INTERVAL_US 10000
@@ -29,6 +31,7 @@
struct apple_spmi {
void __iomem *regs;
+ bool prev_fail;
};
#define poll_reg(spmi, reg, val, cond) \
@@ -49,6 +52,7 @@ static int apple_spmi_wait_rx_not_empty(struct spmi_controller *ctrl)
ret = poll_reg(spmi, SPMI_STATUS_REG, status, !(status & SPMI_RX_FIFO_EMPTY));
if (ret) {
+ spmi->prev_fail = true;
dev_err(&ctrl->dev,
"failed to wait for RX FIFO not empty\n");
return ret;
@@ -67,6 +71,11 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
u8 i;
int ret;
+ if (spmi->prev_fail) {
+ writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
+ spmi->prev_fail = false;
+ }
+
writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
ret = apple_spmi_wait_rx_not_empty(ctrl);
@@ -78,6 +87,12 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
/* Read SPMI data reply */
while (len_read < len) {
+ if (readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY) {
+ spmi->prev_fail = true;
+ dev_err_ratelimited(&ctrl->dev,
+ "FIFO lacks reply data, controller stuck?\n");
+ return -EIO;
+ }
rsp = readl(spmi->regs + SPMI_RSP_REG);
i = 0;
while ((len_read < len) && (i < 4)) {
@@ -86,6 +101,11 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
}
}
+ if (!(readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)) {
+ dev_warn(&ctrl->dev, "FIFO has extra data\n");
+ spmi->prev_fail = true;
+ }
+
return 0;
}
@@ -97,6 +117,11 @@ static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
size_t i = 0, j;
int ret;
+ if (spmi->prev_fail) {
+ writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
+ spmi->prev_fail = false;
+ }
+
writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
while (i < len) {
@@ -115,6 +140,11 @@ static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
/* Discard */
readl(spmi->regs + SPMI_RSP_REG);
+ if (!(readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)) {
+ dev_warn(&ctrl->dev, "FIFO has extra data\n");
+ spmi->prev_fail = true;
+ }
+
return 0;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 13+ messages in thread
* [PATCH v5 3/6] spmi: apple: check transaction status
2026-08-08 11:31 [PATCH v5 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
2026-08-08 11:31 ` [PATCH v5 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122 Sasha Finkelstein
2026-08-08 11:31 ` [PATCH v5 2/6] spmi: apple: Validate FIFO state Sasha Finkelstein
@ 2026-08-08 11:31 ` Sasha Finkelstein
2026-08-08 11:48 ` sashiko-bot
2026-08-08 11:31 ` [PATCH v5 4/6] spmi: apple: Implement remaining commands Sasha Finkelstein
` (2 subsequent siblings)
5 siblings, 1 reply; 13+ messages in thread
From: Sasha Finkelstein @ 2026-08-08 11:31 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Alba Mendez
From: Alba Mendez <me@alba.sh>
Check for parity errors and missing command ACKs.
Signed-off-by: Alba Mendez <me@alba.sh>
Reviewed-by: Janne Grunau <j@jannau.net>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
drivers/spmi/spmi-apple-controller.c | 25 ++++++++++++++++++++-----
1 file changed, 20 insertions(+), 5 deletions(-)
diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
index 15721cb41d5c..b1c127cf5f44 100644
--- a/drivers/spmi/spmi-apple-controller.c
+++ b/drivers/spmi/spmi-apple-controller.c
@@ -11,6 +11,8 @@
* spmi-pmic-arb.c Copyright (c) 2021, The Linux Foundation.
*/
+#include <linux/bitfield.h>
+#include <linux/bits.h>
#include <linux/io.h>
#include <linux/iopoll.h>
#include <linux/module.h>
@@ -23,6 +25,12 @@
#define SPMI_RSP_REG 0x8
#define SPMI_ACT_REG 0xa4
+/* SPMI_RSP_REG reply word */
+#define SPMI_REPLY_FRAME_PARITY_STATUS GENMASK(31, 16)
+#define SPMI_REPLY_ACK BIT(15)
+#define SPMI_REPLY_SLAVE_ID GENMASK(14, 8)
+#define SPMI_REPLY_CMD GENMASK(7, 0)
+
#define SPMI_ACT_FIFO_FLUSH BIT(0)
#define SPMI_RX_FIFO_EMPTY BIT(24)
@@ -66,7 +74,7 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
{
struct apple_spmi *spmi = spmi_controller_get_drvdata(ctrl);
u32 spmi_cmd = apple_spmi_pack_cmd(opc, sid, saddr, len);
- u32 rsp;
+ u32 reply, rsp;
size_t len_read = 0;
u8 i;
int ret;
@@ -82,8 +90,7 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
if (ret)
return ret;
- /* Discard SPMI reply status */
- readl(spmi->regs + SPMI_RSP_REG);
+ reply = readl(spmi->regs + SPMI_RSP_REG);
/* Read SPMI data reply */
while (len_read < len) {
@@ -106,6 +113,10 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
spmi->prev_fail = true;
}
+ if (~FIELD_GET(SPMI_REPLY_FRAME_PARITY_STATUS, reply) & ((1 << len) - 1)) {
+ dev_err(&ctrl->dev, "some frames failed parity check\n");
+ return -EIO;
+ }
return 0;
}
@@ -114,6 +125,7 @@ static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
{
struct apple_spmi *spmi = spmi_controller_get_drvdata(ctrl);
u32 spmi_cmd = apple_spmi_pack_cmd(opc, sid, saddr, len);
+ u32 reply;
size_t i = 0, j;
int ret;
@@ -137,14 +149,17 @@ static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
if (ret)
return ret;
- /* Discard */
- readl(spmi->regs + SPMI_RSP_REG);
+ reply = readl(spmi->regs + SPMI_RSP_REG);
if (!(readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)) {
dev_warn(&ctrl->dev, "FIFO has extra data\n");
spmi->prev_fail = true;
}
+ if (!FIELD_GET(SPMI_REPLY_ACK, reply)) {
+ dev_err(&ctrl->dev, "command not acknowledged\n");
+ return -EIO;
+ }
return 0;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 13+ messages in thread
* [PATCH v5 4/6] spmi: apple: Implement remaining commands
2026-08-08 11:31 [PATCH v5 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
` (2 preceding siblings ...)
2026-08-08 11:31 ` [PATCH v5 3/6] spmi: apple: check transaction status Sasha Finkelstein
@ 2026-08-08 11:31 ` Sasha Finkelstein
2026-08-08 11:41 ` sashiko-bot
2026-08-08 11:31 ` [PATCH v5 5/6] spmi: apple: lock around FIFOs Sasha Finkelstein
2026-08-08 11:31 ` [PATCH v5 6/6] spmi: apple: Add interrupt functionality Sasha Finkelstein
5 siblings, 1 reply; 13+ messages in thread
From: Sasha Finkelstein @ 2026-08-08 11:31 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Alba Mendez
From: Alba Mendez <me@alba.sh>
Add support for zero write and power management commands.
Signed-off-by: Alba Mendez <me@alba.sh>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
drivers/spmi/spmi-apple-controller.c | 116 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-----------------------------------------------
1 file changed, 69 insertions(+), 47 deletions(-)
diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
index b1c127cf5f44..9843dc871d6c 100644
--- a/drivers/spmi/spmi-apple-controller.c
+++ b/drivers/spmi/spmi-apple-controller.c
@@ -46,9 +46,9 @@ struct apple_spmi {
readl_poll_timeout((spmi)->regs + (reg), (val), (cond), \
REG_POLL_INTERVAL_US, REG_POLL_TIMEOUT_US)
-static inline u32 apple_spmi_pack_cmd(u8 opc, u8 sid, u16 saddr, size_t len)
+static inline u32 apple_spmi_pack_cmd(u8 opc, u8 sid, u16 param)
{
- return opc | sid << 8 | saddr << 16 | (len - 1) | (1 << 15);
+ return opc | sid << 8 | (u32)param << 16 | (1 << 15);
}
/* Wait for Rx FIFO to have something */
@@ -69,14 +69,13 @@ static int apple_spmi_wait_rx_not_empty(struct spmi_controller *ctrl)
return 0;
}
-static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
- u16 saddr, u8 *buf, size_t len)
+static int spmi_raw_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid, u16 param,
+ const u8 *buf_wr, size_t len_wr, u8 *buf_rd, size_t len_rd)
{
struct apple_spmi *spmi = spmi_controller_get_drvdata(ctrl);
- u32 spmi_cmd = apple_spmi_pack_cmd(opc, sid, saddr, len);
+ u32 spmi_cmd = apple_spmi_pack_cmd(opc, sid, param);
u32 reply, rsp;
- size_t len_read = 0;
- u8 i;
+ size_t i = 0, j;
int ret;
if (spmi->prev_fail) {
@@ -86,6 +85,14 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
+ while (i < len_wr) {
+ j = min_t(size_t, sizeof(spmi_cmd), len_wr - i);
+ spmi_cmd = 0;
+ memcpy(&spmi_cmd, buf_wr + i, j);
+ writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
+ i += j;
+ }
+
ret = apple_spmi_wait_rx_not_empty(ctrl);
if (ret)
return ret;
@@ -93,7 +100,8 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
reply = readl(spmi->regs + SPMI_RSP_REG);
/* Read SPMI data reply */
- while (len_read < len) {
+ i = 0;
+ while (i < len_rd) {
if (readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY) {
spmi->prev_fail = true;
dev_err_ratelimited(&ctrl->dev,
@@ -101,11 +109,9 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
return -EIO;
}
rsp = readl(spmi->regs + SPMI_RSP_REG);
- i = 0;
- while ((len_read < len) && (i < 4)) {
- buf[len_read++] = ((0xff << (8 * i)) & rsp) >> (8 * i);
- i += 1;
- }
+ j = min_t(size_t, sizeof(spmi_cmd), len_rd - i);
+ memcpy(buf_rd + i, &rsp, j);
+ i += j;
}
if (!(readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)) {
@@ -113,54 +119,69 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
spmi->prev_fail = true;
}
- if (~FIELD_GET(SPMI_REPLY_FRAME_PARITY_STATUS, reply) & ((1 << len) - 1)) {
+ if (!len_rd && !FIELD_GET(SPMI_REPLY_ACK, reply)) {
+ dev_err(&ctrl->dev, "command not acknowledged\n");
+ return -EIO;
+ }
+ if (~FIELD_GET(SPMI_REPLY_FRAME_PARITY_STATUS, reply) & ((1 << len_rd) - 1)) {
dev_err(&ctrl->dev, "some frames failed parity check\n");
return -EIO;
}
return 0;
}
-static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
- u16 saddr, const u8 *buf, size_t len)
+/* Send a raw command with 1..16 input data frames */
+static int spmi_raw_cmd_input(struct spmi_controller *ctrl, u8 opc, u8 sid,
+ u16 param, u8 *buf, size_t len)
{
- struct apple_spmi *spmi = spmi_controller_get_drvdata(ctrl);
- u32 spmi_cmd = apple_spmi_pack_cmd(opc, sid, saddr, len);
- u32 reply;
- size_t i = 0, j;
- int ret;
-
- if (spmi->prev_fail) {
- writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
- spmi->prev_fail = false;
- }
-
- writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
+ return spmi_raw_cmd(ctrl, opc, sid, param, NULL, 0, buf, len);
+}
- while (i < len) {
- j = 0;
- spmi_cmd = 0;
- while ((j < 4) & (i < len))
- spmi_cmd |= buf[i++] << (j++ * 8);
+/* Send a raw command with (optional) body and an input ACK */
+static int spmi_raw_cmd_ack(struct spmi_controller *ctrl, u8 opc, u8 sid,
+ u16 param, const u8 *buf, size_t len)
+{
+ return spmi_raw_cmd(ctrl, opc, sid, param, buf, len, NULL, 0);
+}
- writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
+static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
+ u16 saddr, u8 *buf, size_t len)
+{
+ switch (opc) {
+ case SPMI_CMD_EXT_READ:
+ case SPMI_CMD_EXT_READL:
+ return spmi_raw_cmd_input(ctrl, opc | (len - 1), sid, saddr, buf, len);
+ case SPMI_CMD_READ:
+ return spmi_raw_cmd_input(ctrl, opc | saddr, sid, saddr, buf, len);
}
+ return -EINVAL;
+}
- ret = apple_spmi_wait_rx_not_empty(ctrl);
- if (ret)
- return ret;
-
- reply = readl(spmi->regs + SPMI_RSP_REG);
-
- if (!(readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)) {
- dev_warn(&ctrl->dev, "FIFO has extra data\n");
- spmi->prev_fail = true;
+static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
+ u16 saddr, const u8 *buf, size_t len)
+{
+ switch (opc) {
+ case SPMI_CMD_WRITE:
+ return spmi_raw_cmd_ack(ctrl, opc | saddr, sid, buf[0] << 8 | saddr, NULL, 0);
+ case SPMI_CMD_ZERO_WRITE:
+ return spmi_raw_cmd_ack(ctrl, opc | buf[0], sid, buf[0] << 8 | saddr, NULL, 0);
+ case SPMI_CMD_EXT_WRITE:
+ case SPMI_CMD_EXT_WRITEL:
+ return spmi_raw_cmd_ack(ctrl, opc | (len - 1), sid, saddr, buf, len);
}
+ return -EINVAL;
+}
- if (!FIELD_GET(SPMI_REPLY_ACK, reply)) {
- dev_err(&ctrl->dev, "command not acknowledged\n");
- return -EIO;
+static int spmi_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid)
+{
+ switch (opc) {
+ case SPMI_CMD_RESET:
+ case SPMI_CMD_SLEEP:
+ case SPMI_CMD_SHUTDOWN:
+ case SPMI_CMD_WAKEUP:
+ return spmi_raw_cmd_ack(ctrl, opc, sid, 0, NULL, 0);
}
- return 0;
+ return -EINVAL;
}
static int apple_spmi_probe(struct platform_device *pdev)
@@ -183,6 +204,7 @@ static int apple_spmi_probe(struct platform_device *pdev)
ctrl->read_cmd = spmi_read_cmd;
ctrl->write_cmd = spmi_write_cmd;
+ ctrl->cmd = spmi_cmd;
ret = devm_spmi_controller_add(&pdev->dev, ctrl);
if (ret)
--
2.55.0
^ permalink raw reply related [flat|nested] 13+ messages in thread
* [PATCH v5 5/6] spmi: apple: lock around FIFOs
2026-08-08 11:31 [PATCH v5 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
` (3 preceding siblings ...)
2026-08-08 11:31 ` [PATCH v5 4/6] spmi: apple: Implement remaining commands Sasha Finkelstein
@ 2026-08-08 11:31 ` Sasha Finkelstein
2026-08-08 11:41 ` sashiko-bot
2026-08-08 11:31 ` [PATCH v5 6/6] spmi: apple: Add interrupt functionality Sasha Finkelstein
5 siblings, 1 reply; 13+ messages in thread
From: Sasha Finkelstein @ 2026-08-08 11:31 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Alba Mendez
From: Alba Mendez <me@alba.sh>
The driver was missing locking around register interactions.
Signed-off-by: Alba Mendez <me@alba.sh>
Reviewed-by: Janne Grunau <j@jannau.net>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
drivers/spmi/spmi-apple-controller.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
index 9843dc871d6c..fabccd25aa0d 100644
--- a/drivers/spmi/spmi-apple-controller.c
+++ b/drivers/spmi/spmi-apple-controller.c
@@ -16,6 +16,7 @@
#include <linux/io.h>
#include <linux/iopoll.h>
#include <linux/module.h>
+#include <linux/mutex.h>
#include <linux/platform_device.h>
#include <linux/spmi.h>
@@ -39,6 +40,7 @@
struct apple_spmi {
void __iomem *regs;
+ struct mutex fifo_lock;
bool prev_fail;
};
@@ -78,6 +80,8 @@ static int spmi_raw_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid, u16 param,
size_t i = 0, j;
int ret;
+ guard(mutex)(&spmi->fifo_lock);
+
if (spmi->prev_fail) {
writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
spmi->prev_fail = false;
@@ -195,6 +199,7 @@ static int apple_spmi_probe(struct platform_device *pdev)
return -ENOMEM;
spmi = spmi_controller_get_drvdata(ctrl);
+ mutex_init(&spmi->fifo_lock);
spmi->regs = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(spmi->regs))
--
2.55.0
^ permalink raw reply related [flat|nested] 13+ messages in thread
* [PATCH v5 6/6] spmi: apple: Add interrupt functionality
2026-08-08 11:31 [PATCH v5 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
` (4 preceding siblings ...)
2026-08-08 11:31 ` [PATCH v5 5/6] spmi: apple: lock around FIFOs Sasha Finkelstein
@ 2026-08-08 11:31 ` Sasha Finkelstein
2026-08-08 11:44 ` sashiko-bot
5 siblings, 1 reply; 13+ messages in thread
From: Sasha Finkelstein @ 2026-08-08 11:31 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Alba Mendez
From: Alba Mendez <me@alba.sh>
Add support for interrupts sent by slave devices and use IRQ for
RX FIFO if possible, as that IRQ fires as soon as the reply is
available, which is usually takes a few us instead of the 10ms sleep
interval for polling.
Signed-off-by: Alba Mendez <me@alba.sh>
Reviewed-by: Janne Grunau <j@jannau.net>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
drivers/spmi/Kconfig | 3 +-
drivers/spmi/spmi-apple-controller.c | 257 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-
2 files changed, 258 insertions(+), 2 deletions(-)
diff --git a/drivers/spmi/Kconfig b/drivers/spmi/Kconfig
index a80cf4047b86..7243863a09b4 100644
--- a/drivers/spmi/Kconfig
+++ b/drivers/spmi/Kconfig
@@ -13,7 +13,8 @@ if SPMI
config SPMI_APPLE
tristate "Apple SoC SPMI Controller platform driver"
- depends on ARCH_APPLE || COMPILE_TEST
+ select IRQ_DOMAIN_HIERARCHY
+ depends on ARCH_APPLE || (COMPILE_TEST && 64BIT)
help
If you say yes to this option, support will be included for the
SPMI controller present on many Apple SoCs, including the
diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
index fabccd25aa0d..1e6cc30da196 100644
--- a/drivers/spmi/spmi-apple-controller.c
+++ b/drivers/spmi/spmi-apple-controller.c
@@ -13,11 +13,17 @@
#include <linux/bitfield.h>
#include <linux/bits.h>
+#include <linux/completion.h>
+#include <linux/interrupt.h>
#include <linux/io.h>
#include <linux/iopoll.h>
+#include <linux/irq.h>
+#include <linux/irqchip/chained_irq.h>
+#include <linux/irqdomain.h>
#include <linux/module.h>
#include <linux/mutex.h>
#include <linux/platform_device.h>
+#include <linux/spinlock.h>
#include <linux/spmi.h>
/* SPMI Controller Registers */
@@ -26,6 +32,13 @@
#define SPMI_RSP_REG 0x8
#define SPMI_ACT_REG 0xa4
+#define SPMI_IRQ_MASK_BASE 0x20
+#define SPMI_IRQ_ACK_BASE 0x60
+#define SPMI_NUM_PERIPHERAL_IRQS 256
+#define SPMI_NUM_IRQS (SPMI_NUM_PERIPHERAL_IRQS + 32)
+
+#define SPMI_IRQ_NOTIFY 256
+
/* SPMI_RSP_REG reply word */
#define SPMI_REPLY_FRAME_PARITY_STATUS GENMASK(31, 16)
#define SPMI_REPLY_ACK BIT(15)
@@ -41,6 +54,12 @@
struct apple_spmi {
void __iomem *regs;
struct mutex fifo_lock;
+ struct completion fifo_rx;
+ struct irq_domain *irqd;
+ raw_spinlock_t irq_mask_lock;
+ DECLARE_BITMAP(irq_mask_cache, SPMI_NUM_PERIPHERAL_IRQS);
+ int irq;
+ bool notify_irq;
bool prev_fail;
};
@@ -48,6 +67,56 @@ struct apple_spmi {
readl_poll_timeout((spmi)->regs + (reg), (val), (cond), \
REG_POLL_INTERVAL_US, REG_POLL_TIMEOUT_US)
+static void apple_spmi_irq_ack_raw(struct apple_spmi *spmi, u32 irq)
+{
+ u32 __iomem *reg = spmi->regs + SPMI_IRQ_ACK_BASE + (irq / 32) * 4;
+
+ writel(BIT(irq % 32), reg);
+}
+
+static void apple_spmi_irq_mask_raw(struct apple_spmi *spmi, u32 irq)
+{
+ u32 __iomem *reg = spmi->regs + SPMI_IRQ_MASK_BASE + (irq / 32) * 4;
+
+ writel(readl(reg) & ~BIT(irq % 32), reg);
+}
+
+static void apple_spmi_irq_unmask_raw(struct apple_spmi *spmi, u32 irq)
+{
+ u32 __iomem *reg = spmi->regs + SPMI_IRQ_MASK_BASE + (irq / 32) * 4;
+
+ writel(readl(reg) | BIT(irq % 32), reg);
+}
+
+static void apple_spmi_irq_ack(struct irq_data *d)
+{
+ struct apple_spmi *spmi = irq_data_get_irq_chip_data(d);
+
+ apple_spmi_irq_ack_raw(spmi, d->hwirq);
+}
+
+static void apple_spmi_irq_mask(struct irq_data *d)
+{
+ struct apple_spmi *spmi = irq_data_get_irq_chip_data(d);
+ unsigned long flags;
+
+ raw_spin_lock_irqsave(&spmi->irq_mask_lock, flags);
+ apple_spmi_irq_mask_raw(spmi, d->hwirq);
+ clear_bit(d->hwirq, spmi->irq_mask_cache);
+ raw_spin_unlock_irqrestore(&spmi->irq_mask_lock, flags);
+}
+
+static void apple_spmi_irq_unmask(struct irq_data *d)
+{
+ struct apple_spmi *spmi = irq_data_get_irq_chip_data(d);
+ unsigned long flags;
+
+ raw_spin_lock_irqsave(&spmi->irq_mask_lock, flags);
+ set_bit(d->hwirq, spmi->irq_mask_cache);
+ apple_spmi_irq_unmask_raw(spmi, d->hwirq);
+ raw_spin_unlock_irqrestore(&spmi->irq_mask_lock, flags);
+}
+
static inline u32 apple_spmi_pack_cmd(u8 opc, u8 sid, u16 param)
{
return opc | sid << 8 | (u32)param << 16 | (1 << 15);
@@ -60,7 +129,19 @@ static int apple_spmi_wait_rx_not_empty(struct spmi_controller *ctrl)
int ret;
u32 status;
- ret = poll_reg(spmi, SPMI_STATUS_REG, status, !(status & SPMI_RX_FIFO_EMPTY));
+ if (spmi->notify_irq) {
+ ret = wait_for_completion_timeout(&spmi->fifo_rx,
+ usecs_to_jiffies(REG_POLL_TIMEOUT_US));
+ if (!ret)
+ ret = -ETIMEDOUT;
+ else if (readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)
+ ret = -EIO;
+ else
+ ret = 0;
+ } else {
+ ret = poll_reg(spmi, SPMI_STATUS_REG, status, !(status & SPMI_RX_FIFO_EMPTY));
+ }
+
if (ret) {
spmi->prev_fail = true;
dev_err(&ctrl->dev,
@@ -84,8 +165,10 @@ static int spmi_raw_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid, u16 param,
if (spmi->prev_fail) {
writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
+ apple_spmi_irq_ack_raw(spmi, SPMI_IRQ_NOTIFY);
spmi->prev_fail = false;
}
+ reinit_completion(&spmi->fifo_rx);
writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
@@ -188,6 +271,167 @@ static int spmi_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid)
return -EINVAL;
}
+static int apple_spmi_irq_set_type(struct irq_data *d, unsigned int type)
+{
+ /* all interrupts have MSI semantics */
+ return type == IRQ_TYPE_EDGE_RISING ? 0 : -EINVAL;
+}
+
+static struct irq_chip apple_spmi_irq_chip = {
+ .name = "apple_spmi",
+ .irq_mask = apple_spmi_irq_mask,
+ .irq_unmask = apple_spmi_irq_unmask,
+ .irq_ack = apple_spmi_irq_ack,
+ .irq_set_type = apple_spmi_irq_set_type,
+ .flags = IRQCHIP_ONESHOT_SAFE,
+};
+
+static int apple_spmi_irq_domain_map(struct irq_domain *irqd,
+ unsigned int irq, irq_hw_number_t hw)
+{
+ irq_domain_set_info(irqd, irq, hw, &apple_spmi_irq_chip, irqd->host_data,
+ handle_edge_irq, NULL, NULL);
+ return 0;
+}
+
+static int apple_spmi_irq_domain_translate(struct irq_domain *irqd,
+ struct irq_fwspec *fwspec,
+ unsigned long *hwirq,
+ unsigned int *type)
+{
+ u32 *args = fwspec->param;
+
+ if (fwspec->param_count != 2)
+ return -EINVAL;
+
+ if (args[0] >= SPMI_NUM_PERIPHERAL_IRQS)
+ return -EINVAL;
+ *hwirq = args[0];
+ *type = args[1] & IRQ_TYPE_SENSE_MASK;
+ return 0;
+}
+
+static int apple_spmi_irq_domain_alloc(struct irq_domain *irqd, unsigned int virq,
+ unsigned int nr_irqs, void *arg)
+{
+ unsigned int type = IRQ_TYPE_NONE;
+ struct irq_fwspec *fwspec = arg;
+ irq_hw_number_t hwirq;
+ int i, ret;
+
+ ret = apple_spmi_irq_domain_translate(irqd, fwspec, &hwirq, &type);
+ if (ret)
+ return ret;
+
+ if (hwirq + nr_irqs > SPMI_NUM_PERIPHERAL_IRQS)
+ return -EINVAL;
+
+ for (i = 0; i < nr_irqs; i++) {
+ ret = apple_spmi_irq_domain_map(irqd, virq + i, hwirq + i);
+ if (ret)
+ return ret;
+ }
+
+ return 0;
+}
+
+static void apple_spmi_irq_domain_free(struct irq_domain *irqd, unsigned int virq,
+ unsigned int nr_irqs)
+{
+ int i;
+
+ for (i = 0; i < nr_irqs; i++) {
+ struct irq_data *d = irq_domain_get_irq_data(irqd, virq + i);
+
+ irq_set_handler(virq + i, NULL);
+ irq_domain_reset_irq_data(d);
+ }
+}
+
+static const struct irq_domain_ops apple_spmi_irq_domain_ops = {
+ .translate = apple_spmi_irq_domain_translate,
+ .alloc = apple_spmi_irq_domain_alloc,
+ .free = apple_spmi_irq_domain_free,
+};
+
+static void apple_spmi_irq_handler(struct irq_desc *desc)
+{
+ struct apple_spmi *spmi = irq_desc_get_handler_data(desc);
+ struct irq_chip *chip = irq_desc_get_chip(desc);
+ bool handled = false;
+ unsigned long val, offset, bit;
+
+ chained_irq_enter(chip, desc);
+ val = readl(spmi->regs + SPMI_IRQ_ACK_BASE + (SPMI_IRQ_NOTIFY / 32) * 4);
+ if (val & BIT(SPMI_IRQ_NOTIFY % 32)) {
+ apple_spmi_irq_ack_raw(spmi, SPMI_IRQ_NOTIFY);
+ complete(&spmi->fifo_rx);
+ handled = true;
+ }
+
+ for (offset = 0; offset < SPMI_NUM_PERIPHERAL_IRQS / 8; offset += sizeof(val)) {
+ val = readq(spmi->regs + SPMI_IRQ_ACK_BASE + offset);
+ /**
+ * because of other masters in the bus, we're going to get a multitude of
+ * interrupts we're not interested in. irq_resolve_mapping isn't very
+ * optimized for the nonexistent path, so instead we mask with (a locally
+ * cached version of) the IRQ mask
+ */
+ val &= spmi->irq_mask_cache[offset / sizeof(val)];
+ for_each_set_bit(bit, &val, 64) {
+ generic_handle_domain_irq(spmi->irqd, offset * 8 + bit);
+ handled = true;
+ }
+ }
+ if (!handled)
+ handle_bad_irq(desc);
+ chained_irq_exit(chip, desc);
+}
+
+static void apple_spmi_teardown_irq(void *data)
+{
+ struct apple_spmi *spmi = data;
+
+ for (size_t offset = 0; offset < SPMI_NUM_IRQS / 8; offset += 4)
+ writel(U32_MAX, spmi->regs + SPMI_IRQ_MASK_BASE + offset);
+
+ synchronize_irq(spmi->irq);
+ irq_set_chained_handler_and_data(spmi->irq, NULL, NULL);
+}
+
+static int apple_spmi_init_irq(struct platform_device *pdev,
+ struct apple_spmi *spmi, int irq)
+{
+ int ret;
+ struct irq_domain_info info = {
+ .fwnode = pdev->dev.fwnode,
+ .hwirq_max = ~0U,
+ .ops = &apple_spmi_irq_domain_ops,
+ .host_data = spmi,
+ };
+
+ raw_spin_lock_init(&spmi->irq_mask_lock);
+
+ for (size_t offset = 0; offset < SPMI_NUM_IRQS / 8; offset += 4) {
+ writel(0, spmi->regs + SPMI_IRQ_MASK_BASE + offset);
+ writel(U32_MAX, spmi->regs + SPMI_IRQ_ACK_BASE + offset);
+ }
+
+ spmi->irqd = devm_irq_domain_instantiate(&pdev->dev, &info);
+ if (IS_ERR(spmi->irqd))
+ return PTR_ERR(spmi->irqd);
+
+ ret = devm_add_action(&pdev->dev, apple_spmi_teardown_irq, spmi);
+ if (ret)
+ return ret;
+
+ irq_set_chained_handler_and_data(spmi->irq, apple_spmi_irq_handler, spmi);
+ apple_spmi_irq_unmask_raw(spmi, SPMI_IRQ_NOTIFY);
+ spmi->notify_irq = true;
+
+ return 0;
+}
+
static int apple_spmi_probe(struct platform_device *pdev)
{
struct apple_spmi *spmi;
@@ -200,6 +444,8 @@ static int apple_spmi_probe(struct platform_device *pdev)
spmi = spmi_controller_get_drvdata(ctrl);
mutex_init(&spmi->fifo_lock);
+ init_completion(&spmi->fifo_rx);
+ platform_set_drvdata(pdev, spmi);
spmi->regs = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(spmi->regs))
@@ -211,6 +457,15 @@ static int apple_spmi_probe(struct platform_device *pdev)
ctrl->write_cmd = spmi_write_cmd;
ctrl->cmd = spmi_cmd;
+ spmi->irq = platform_get_irq_optional(pdev, 0);
+ if (spmi->irq < 0 && spmi->irq != -ENXIO)
+ return spmi->irq;
+ if (spmi->irq >= 0) {
+ ret = apple_spmi_init_irq(pdev, spmi, spmi->irq);
+ if (ret)
+ return ret;
+ }
+
ret = devm_spmi_controller_add(&pdev->dev, ctrl);
if (ret)
return dev_err_probe(&pdev->dev, ret,
--
2.55.0
^ permalink raw reply related [flat|nested] 13+ messages in thread
* Re: [PATCH v5 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122
2026-08-08 11:31 ` [PATCH v5 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122 Sasha Finkelstein
@ 2026-08-08 11:36 ` sashiko-bot
0 siblings, 0 replies; 13+ messages in thread
From: sashiko-bot @ 2026-08-08 11:36 UTC (permalink / raw)
To: Sasha Finkelstein; +Cc: robh, conor+dt, devicetree
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] The dt-bindings subsystem guidelines state that when a binding adds a new provider capability like `interrupt-controller`, the corresponding required properties (`interrupt-controller` and `#interrupt-cells`) must be enforced, and the examples section must include all required properties. The patch adds `interrupt-controller` and `#interrupt-cells` but keeps them optional without a `dependencies` block to enforce `#interrupt-cells` when `interrupt-controller` is used. It also fails to include these properties in the provided examples.
--
--- Patch [1]: [PATCH v5 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122 ---
commit 65d257979c0e4c52b73ff9a4d1d799b2a91dd019
Author: Sasha Finkelstein <k@chaosmail.tech>
dt-bindings: spmi: apple,spmi: Add t603x and t8122
Add t603x and t8122 compatibles, interrupt support, and support for
SPMI controllers that are not always-on.
> diff --git a/Documentation/devicetree/bindings/spmi/apple,spmi.yaml b/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
> index 3e5b14bc8c317..fceed47b2cd17 100644
> --- a/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
> +++ b/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
[ ... ]
> @@ -34,6 +37,18 @@ properties:
> reg:
> maxItems: 1
>
> + interrupts:
> + maxItems: 1
> + description: Optional, operates in polled mode if not present
> +
> + interrupt-controller: true
> +
> + "#interrupt-cells":
> + const: 2
> +
> + power-domains:
> + maxItems: 1
> +
> required:
> - compatible
> - reg
[Severity: Medium]
Does this schema lack a dependencies block to enforce that #interrupt-cells
is required whenever interrupt-controller is present?
Without this enforcement, could a device tree node utilizing the
interrupt-controller capability but missing #interrupt-cells silently pass
schema validation?
Additionally, should the examples section be updated to demonstrate these
new provider properties, ensuring dt_binding_check validates a fully
compliant configuration?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260808-t603x-spmi-v5-0-553c5ac2f137@chaosmail.tech?part=1
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v5 5/6] spmi: apple: lock around FIFOs
2026-08-08 11:31 ` [PATCH v5 5/6] spmi: apple: lock around FIFOs Sasha Finkelstein
@ 2026-08-08 11:41 ` sashiko-bot
0 siblings, 0 replies; 13+ messages in thread
From: sashiko-bot @ 2026-08-08 11:41 UTC (permalink / raw)
To: Sasha Finkelstein; +Cc: conor+dt, robh, devicetree
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] The driver uses register I/O accessors (`writel()` and `readl()`) with `memcpy()` to stream payload bytes to/from the SPMI FIFOs instead of using stream accessors (`writesl()` and `readsl()`), which causes endianness portability bugs on big-endian architectures.
--
--- Patch [5]: [PATCH v5 5/6] spmi: apple: lock around FIFOs ---
commit 79f5d9aebdc66fbf9df1c1b4f401429d674f9b42
Author: Alba Mendez <me@alba.sh>
spmi: apple: lock around FIFOs
This commit adds a mutex to protect FIFO register interactions in the Apple
SPMI controller driver, preventing concurrent access issues.
> diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
> index 9843dc871d6c7..fabccd25aa0da 100644
> --- a/drivers/spmi/spmi-apple-controller.c
> +++ b/drivers/spmi/spmi-apple-controller.c
[ ... ]
> @@ -78,6 +80,8 @@ static int spmi_raw_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid, u16 param,
> size_t i = 0, j;
> int ret;
>
> + guard(mutex)(&spmi->fifo_lock);
> +
[Severity: High]
This is a pre-existing issue, but does using writel() and readl() to transfer
byte buffers to the FIFO cause endianness portability bugs on big-endian
architectures?
Further down in spmi_raw_cmd(), the driver streams payload bytes to the
hardware FIFO using writel() with memcpy():
while (i < len_wr) {
j = min_t(size_t, sizeof(spmi_cmd), len_wr - i);
spmi_cmd = 0;
memcpy(&spmi_cmd, buf_wr + i, j);
writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
i += j;
}
And similarly for reads:
rsp = readl(spmi->regs + SPMI_RSP_REG);
j = min_t(size_t, sizeof(spmi_cmd), len_rd - i);
memcpy(buf_rd + i, &rsp, j);
Using writel() and readl() instead of stream accessors like writesl() and
readsl() performs an implicit CPU-to-LE conversion.
Could this cause the data to be unexpectedly byte-swapped on big-endian
systems, corrupting the payload sent to the device on the bus?
> if (spmi->prev_fail) {
> writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
> spmi->prev_fail = false;
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260808-t603x-spmi-v5-0-553c5ac2f137@chaosmail.tech?part=5
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v5 4/6] spmi: apple: Implement remaining commands
2026-08-08 11:31 ` [PATCH v5 4/6] spmi: apple: Implement remaining commands Sasha Finkelstein
@ 2026-08-08 11:41 ` sashiko-bot
0 siblings, 0 replies; 13+ messages in thread
From: sashiko-bot @ 2026-08-08 11:41 UTC (permalink / raw)
To: Sasha Finkelstein; +Cc: conor+dt, devicetree, robh
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Using `memcpy()` to pack/unpack byte streams into a 32-bit integer variable combined with `writel()`/`readl()` causes byte-swapping data corruption on big-endian architectures.
--
--- Patch [4]: [PATCH v5 4/6] spmi: apple: Implement remaining commands ---
commit 133f8b2358af9160fedbf5fcf84ef152c33022e4
Author: Alba Mendez <me@alba.sh>
spmi: apple: Implement remaining commands
This patch adds support for zero write and power management commands to the
Apple SPMI controller driver. It achieves this by introducing a unified
spmi_raw_cmd function for executing SPMI transactions.
> diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
> --- a/drivers/spmi/spmi-apple-controller.c
> +++ b/drivers/spmi/spmi-apple-controller.c
[ ... ]
> -static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
> - u16 saddr, u8 *buf, size_t len)
> +static int spmi_raw_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid, u16 param,
> + const u8 *buf_wr, size_t len_wr, u8 *buf_rd, size_t len_rd)
> {
[ ... ]
> + while (i < len_wr) {
> + j = min_t(size_t, sizeof(spmi_cmd), len_wr - i);
> + spmi_cmd = 0;
> + memcpy(&spmi_cmd, buf_wr + i, j);
> + writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
> + i += j;
> + }
[Severity: High]
Will this sequence cause byte-swapping data corruption on big-endian
architectures?
When len_wr is greater than zero, memcpy copies the byte stream into the
u32 spmi_cmd. On big-endian systems, memcpy places the first byte in the
most-significant byte position.
writel then performs CPU-to-LE conversion (byte-swapping), which causes
the hardware to receive the bytes in reverse order.
[ ... ]
> rsp = readl(spmi->regs + SPMI_RSP_REG);
> - i = 0;
> - while ((len_read < len) && (i < 4)) {
> - buf[len_read++] = ((0xff << (8 * i)) & rsp) >> (8 * i);
> - i += 1;
> - }
> + j = min_t(size_t, sizeof(spmi_cmd), len_rd - i);
> + memcpy(buf_rd + i, &rsp, j);
> + i += j;
> }
[Severity: High]
Does the read path in spmi_raw_cmd suffer from the exact inverse problem?
readl will byte-swap the incoming data on big-endian hosts, and memcpy
will then save it into buf_rd in reverse order.
While Apple SoCs are primarily little-endian, Linux drivers are expected to
be endian-portable. Would it be better to use stream accessors like writesl
and readsl, or manually pack the bytes using shifts (as the original read
code did) to ensure consistent behavior across architectures?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260808-t603x-spmi-v5-0-553c5ac2f137@chaosmail.tech?part=4
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v5 6/6] spmi: apple: Add interrupt functionality
2026-08-08 11:31 ` [PATCH v5 6/6] spmi: apple: Add interrupt functionality Sasha Finkelstein
@ 2026-08-08 11:44 ` sashiko-bot
0 siblings, 0 replies; 13+ messages in thread
From: sashiko-bot @ 2026-08-08 11:44 UTC (permalink / raw)
To: Sasha Finkelstein; +Cc: robh, devicetree, conor+dt
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] The IRQ teardown function incorrectly unmasks all hardware interrupts instead of masking them, leading to a potential interrupt storm on module removal.
- [High] A race condition during timeout recovery can cause the next command to spuriously fail with `-EIO` due to a late interrupt completion.
- [Medium] The IRQ handler uses `readq()` to read two 32-bit registers at once, which may cause a synchronous external abort (SError) if the peripheral bus strictly limits accesses to 32-bit.
--
--- Patch [6]: [PATCH v5 6/6] spmi: apple: Add interrupt functionality ---
commit cbf4e6ab067495af30bb6cec8a0023d78009efc4
Author: Alba Mendez <me@alba.sh>
spmi: apple: Add interrupt functionality
This commit adds support for interrupts sent by slave devices on the Apple
SPMI controller. It utilizes an IRQ for the RX FIFO when available, which
reduces the response latency compared to a 10ms polling sleep interval.
> diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
> index fabccd25aa0da..1e6cc30da1965 100644
> --- a/drivers/spmi/spmi-apple-controller.c
> +++ b/drivers/spmi/spmi-apple-controller.c
[ ... ]
> @@ -84,8 +165,10 @@ static int spmi_raw_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid, u16 param,
>
> if (spmi->prev_fail) {
> writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
> + apple_spmi_irq_ack_raw(spmi, SPMI_IRQ_NOTIFY);
> spmi->prev_fail = false;
> }
> + reinit_completion(&spmi->fifo_rx);
[Severity: High]
Could this reinit_completion() race with a late completion from the IRQ
handler?
If a previous command times out, spmi_raw_cmd() attempts to recover by
flushing the FIFO and calling reinit_completion(). Concurrently, a delayed
hardware interrupt might trigger apple_spmi_irq_handler().
If the handler reads the ACK register before the recovery clears it, but
calls complete() right after this reinit_completion() runs, the new
command's wait_for_completion_timeout() will return immediately. Because
the FIFO is actually empty, this falsely aborts the next valid command with
-EIO.
[ ... ]
> +static void apple_spmi_irq_handler(struct irq_desc *desc)
> +{
> + struct apple_spmi *spmi = irq_desc_get_handler_data(desc);
> + struct irq_chip *chip = irq_desc_get_chip(desc);
> + bool handled = false;
> + unsigned long val, offset, bit;
> +
> + chained_irq_enter(chip, desc);
> + val = readl(spmi->regs + SPMI_IRQ_ACK_BASE + (SPMI_IRQ_NOTIFY / 32) * 4);
> + if (val & BIT(SPMI_IRQ_NOTIFY % 32)) {
> + apple_spmi_irq_ack_raw(spmi, SPMI_IRQ_NOTIFY);
> + complete(&spmi->fifo_rx);
> + handled = true;
> + }
> +
> + for (offset = 0; offset < SPMI_NUM_PERIPHERAL_IRQS / 8; offset += sizeof(val)) {
> + val = readq(spmi->regs + SPMI_IRQ_ACK_BASE + offset);
[Severity: Medium]
Is it safe to use readq() here to read two adjacent 32-bit registers?
Apple Silicon APB peripherals commonly enforce strict 32-bit access widths.
If the peripheral bus rejects 64-bit accesses, this single readq() could
cause a synchronous external abort (SError) resulting in a kernel panic.
Would it be safer to use two 32-bit readl() calls instead?
> + /**
> + * because of other masters in the bus, we're going to get a multitude of
> + * interrupts we're not interested in. irq_resolve_mapping isn't very
> + * optimized for the nonexistent path, so instead we mask with (a locally
> + * cached version of) the IRQ mask
> + */
> + val &= spmi->irq_mask_cache[offset / sizeof(val)];
> + for_each_set_bit(bit, &val, 64) {
> + generic_handle_domain_irq(spmi->irqd, offset * 8 + bit);
> + handled = true;
> + }
> + }
> + if (!handled)
> + handle_bad_irq(desc);
> + chained_irq_exit(chip, desc);
> +}
> +
> +static void apple_spmi_teardown_irq(void *data)
> +{
> + struct apple_spmi *spmi = data;
> +
> + for (size_t offset = 0; offset < SPMI_NUM_IRQS / 8; offset += 4)
> + writel(U32_MAX, spmi->regs + SPMI_IRQ_MASK_BASE + offset);
[Severity: High]
Does writing U32_MAX here accidentally unmask all interrupts on module
removal?
In apple_spmi_init_irq(), 0 is written to safely mask everything, which
implies the hardware uses 1 to unmask. Writing U32_MAX here fully unmasks
all 288 peripheral interrupts on the controller just before the chained
handler is removed.
Could this lead to an unhandled interrupt storm that locks up a CPU or
forces the generic IRQ subsystem to permanently disable the shared parent
IRQ line?
> +
> + synchronize_irq(spmi->irq);
> + irq_set_chained_handler_and_data(spmi->irq, NULL, NULL);
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260808-t603x-spmi-v5-0-553c5ac2f137@chaosmail.tech?part=6
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v5 3/6] spmi: apple: check transaction status
2026-08-08 11:31 ` [PATCH v5 3/6] spmi: apple: check transaction status Sasha Finkelstein
@ 2026-08-08 11:48 ` sashiko-bot
0 siblings, 0 replies; 13+ messages in thread
From: sashiko-bot @ 2026-08-08 11:48 UTC (permalink / raw)
To: Sasha Finkelstein; +Cc: robh, conor+dt, devicetree
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] Missing synchronization in SPMI read and write commands leads to data races and hardware state corruption.
- [High] Signed integer overflow undefined behavior (UB) during bitwise shifts in command packing and data transfer.
--
--- Patch [3]: [PATCH v5 3/6] spmi: apple: check transaction status ---
commit 138d557e0b3d3f2a65351b5debb754e7d0b8485e
Author: Alba Mendez <me@alba.sh>
spmi: apple: check transaction status
Check for parity errors and missing command ACKs.
> diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
> index 15721cb41d5c8..b1c127cf5f441 100644
> --- a/drivers/spmi/spmi-apple-controller.c
> +++ b/drivers/spmi/spmi-apple-controller.c
[ ... ]
> @@ -66,7 +74,7 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
> {
> struct apple_spmi *spmi = spmi_controller_get_drvdata(ctrl);
> u32 spmi_cmd = apple_spmi_pack_cmd(opc, sid, saddr, len);
[Severity: High]
This is a pre-existing issue, but this multi-step transaction begins here
without holding a lock to serialize with other SPMI commands.
If two kernel threads (e.g. a regulator driver and a thermal sensor driver)
initiate an SPMI transaction on the same controller simultaneously, can this
lead to interleaved register writes to the shared SPMI_CMD_REG and reads from
SPMI_RSP_REG?
This missing synchronization seems like it could corrupt SPMI transactions,
leading to incorrect PMIC accesses. This patch also exacerbates the issue by
adding unsynchronized non-atomic accesses to spmi->prev_fail.
[Severity: High]
This isn't a bug introduced by this patch, but does the bitwise shift inside
apple_spmi_pack_cmd() invoke undefined behavior due to signed integer overflow?
In apple_spmi_pack_cmd():
return opc | sid << 8 | saddr << 16 | (len - 1) | (1 << 15);
Since saddr is implicitly promoted to a signed int, will shifting it by 16
when saddr >= 0x8000 overflow INT_MAX?
There appear to be similar signed integer overflows during data transfers.
In spmi_read_cmd():
buf[len_read++] = ((0xff << (8 * i)) & rsp) >> (8 * i);
Does shifting the signed literal 0xff left by 24 (when i == 3) overflow
INT_MAX?
In spmi_write_cmd():
spmi_cmd |= buf[i++] << (j++ * 8);
Since buf[i] is promoted to a signed int, will shifting left by 24 (when
j == 3 and the byte is >= 128) overflow INT_MAX?
Compilers can exploit this undefined behavior to aggressively optimize or drop
code, which may result in corrupted SPMI commands or missing bytes in
transactions.
> - u32 rsp;
> + u32 reply, rsp;
> size_t len_read = 0;
> u8 i;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260808-t603x-spmi-v5-0-553c5ac2f137@chaosmail.tech?part=3
^ permalink raw reply [flat|nested] 13+ messages in thread
* Re: [PATCH v5 2/6] spmi: apple: Validate FIFO state
2026-08-08 11:31 ` [PATCH v5 2/6] spmi: apple: Validate FIFO state Sasha Finkelstein
@ 2026-08-08 11:52 ` sashiko-bot
0 siblings, 0 replies; 13+ messages in thread
From: sashiko-bot @ 2026-08-08 11:52 UTC (permalink / raw)
To: Sasha Finkelstein; +Cc: devicetree, robh, conor+dt
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] The SPMI controller lacks a lock to serialize concurrent read/write commands, leading to hardware FIFO corruption and race conditions on the `prev_fail` flag.
--
--- Patch [2]: [PATCH v5 2/6] spmi: apple: Validate FIFO state ---
commit c5b2972a9b6f963ec09316a6569b8c232707ae21
Author: Alba Mendez <me@alba.sh>
spmi: apple: Validate FIFO state
This commit adds validation of the FIFO state before reading the body of
a reply and checks for the end of data afterwards.
> diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
> index 376cf682c43e0..15721cb41d5c8 100644
> --- a/drivers/spmi/spmi-apple-controller.c
> +++ b/drivers/spmi/spmi-apple-controller.c
[ ... ]
> @@ -67,6 +71,11 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
> u8 i;
> int ret;
>
> + if (spmi->prev_fail) {
> + writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
> + spmi->prev_fail = false;
> + }
> +
> writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
[Severity: High]
This is a pre-existing issue, but does the lack of locking here allow
concurrent accesses to corrupt the hardware FIFO?
Because the hardware sequence involves multiple unprotected MMIO operations,
interleaving these steps from concurrent threads can mix the command and
response streams. This can happen if two different SPMI devices on the same
controller are accessed concurrently, as the SPMI framework core does not
serialize accesses across the controller.
Additionally, could the introduction of the prev_fail flag create a data
race? If one thread evaluates prev_fail and flushes the FIFO just after a
concurrent thread has written its command, it might actively abort the
concurrent transaction.
[ ... ]
> @@ -97,6 +117,11 @@ static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
> size_t i = 0, j;
> int ret;
>
> + if (spmi->prev_fail) {
> + writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
> + spmi->prev_fail = false;
> + }
> +
> writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
[Severity: High]
This isn't a bug introduced by this patch, but similarly to spmi_read_cmd(),
does this unprotected multi-step sequence allow for concurrent accesses to
corrupt the hardware FIFO?
Could the same race condition with the prev_fail flag occur here if another
thread is currently reading or writing to the controller?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260808-t603x-spmi-v5-0-553c5ac2f137@chaosmail.tech?part=2
^ permalink raw reply [flat|nested] 13+ messages in thread
end of thread, other threads:[~2026-08-08 11:52 UTC | newest]
Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-08 11:31 [PATCH v5 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
2026-08-08 11:31 ` [PATCH v5 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122 Sasha Finkelstein
2026-08-08 11:36 ` sashiko-bot
2026-08-08 11:31 ` [PATCH v5 2/6] spmi: apple: Validate FIFO state Sasha Finkelstein
2026-08-08 11:52 ` sashiko-bot
2026-08-08 11:31 ` [PATCH v5 3/6] spmi: apple: check transaction status Sasha Finkelstein
2026-08-08 11:48 ` sashiko-bot
2026-08-08 11:31 ` [PATCH v5 4/6] spmi: apple: Implement remaining commands Sasha Finkelstein
2026-08-08 11:41 ` sashiko-bot
2026-08-08 11:31 ` [PATCH v5 5/6] spmi: apple: lock around FIFOs Sasha Finkelstein
2026-08-08 11:41 ` sashiko-bot
2026-08-08 11:31 ` [PATCH v5 6/6] spmi: apple: Add interrupt functionality Sasha Finkelstein
2026-08-08 11:44 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).