From: sashiko-bot@kernel.org
To: "Lakshay Piplani" <lakshay.piplani@nxp.com>
Cc: Frank.Li@kernel.org, lee@kernel.org, conor+dt@kernel.org,
"Alexandre Belloni" <alexandre.belloni@bootlin.com>,
linux-i3c@lists.infradead.org, mfd@lists.linux.dev,
devicetree@vger.kernel.org, robh@kernel.org
Subject: Re: [PATCH v20 8/8] i3c: hub: p3h2x4x: Add SMBus slave mode support
Date: Tue, 22 Sep 2026 10:55:50 +0000 [thread overview]
Message-ID: <20260922105550.B4DE61F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260922103551.2754613-9-lakshay.piplani@nxp.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] i3c: hub: race condition in W1C register drops SMBus packets on overflow
--
commit c3c584227ca9aea44ff10ea314eddee7cc1ae7a9
Author: Lakshay Piplani <lakshay.piplani@nxp.com>
i3c: hub: p3h2x4x: Add SMBus slave mode support
This commit adds SMBus slave mode support for the P3H2x4x hub SMBus target
ports, allowing it to receive downstream payloads and report them via IBI.
The payloads are then forwarded to the registered I2C slave client.
> diff --git a/drivers/i3c/hub/p3h2840_i3c_hub_smbus.c b/drivers/i3c/hub/p3h2840_i3c_hub_smbus.c
> index a3324cc365956..7fdfa79dfeb6c 100644
> --- a/drivers/i3c/hub/p3h2840_i3c_hub_smbus.c
> +++ b/drivers/i3c/hub/p3h2840_i3c_hub_smbus.c
[ ... ]
> @@ -15,6 +17,178 @@ enum p3h2x4x_smbus_desc_idx {
[ ... ]
> + case P3H2X4X_TARGET_BUF_OVRFL_VAL:
> + p3h2x4x_read_smbus_agent_rx_buf(i3cdev, RCV_BUF_0, i);
> + p3h2x4x_read_smbus_agent_rx_buf(i3cdev, RCV_BUF_1, i);
> + regmap_write(p3h2x4x_i3c_hub->regmap, P3H2X4X_TP0_SMBUS_AGNT_STS + i,
> + P3H2X4X_TARGET_BUF_OVRFL);
[Severity: Medium]
Does this write clear newly received packets on overflow?
If an external device sends a burst of packets, causing an overflow (bits 1, 2,
and 3 set in the status register), the IBI handler reads buffer 0 (which clears
bit 1 via a Write-1-to-Clear) and buffer 1 (which clears bit 2).
If the hardware receives a new packet into buffer 0 in the small window before
the overflow flag is cleared, bit 1 is set again by the hardware. The driver
then executes the regmap_write() to clear the overflow state.
Because P3H2X4X_TARGET_BUF_OVRFL is defined as GENMASK(3, 1), it writes '1' to
bits 1, 2, and 3. Since the register uses W1C semantics, this second write
inadvertently clears the newly set bit 1, permanently dropping the new packet
without reading it.
> + dev_err(&i3cdev->dev, "Overflow, reading buffer zero and one\n");
> + break;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922103551.2754613-1-lakshay.piplani@nxp.com?part=8
next prev parent reply other threads:[~2026-09-22 10:55 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 10:35 [PATCH v20 0/8] Add support for NXP P3H2x4x I3C hub driver Lakshay Piplani
2026-09-22 10:35 ` [PATCH v20 1/8] i3c: master: Add APIs for I3C hub support Lakshay Piplani
2026-09-22 10:48 ` sashiko-bot
2026-09-22 10:35 ` [PATCH v20 2/8] i3c: master: Add controller-only device operation helpers Lakshay Piplani
2026-09-22 10:45 ` sashiko-bot
2026-09-22 10:35 ` [PATCH v20 3/8] dt-bindings: i3c: Add NXP P3H2x4x i3c-hub support Lakshay Piplani
2026-09-22 10:44 ` sashiko-bot
2026-09-22 10:35 ` [PATCH v20 4/8] mfd: p3h2x4x: Add driver for NXP P3H2x4x i3c hub and on-die regulator Lakshay Piplani
2026-09-22 10:50 ` sashiko-bot
2026-09-22 10:35 ` [PATCH v20 5/8] regulator: p3h2x4x: Add driver for on-die regulators in NXP P3H2x4x i3c hub Lakshay Piplani
2026-09-22 10:47 ` sashiko-bot
2026-09-22 10:35 ` [PATCH v20 6/8] i3c: hub: Add support for the I3C interface in the I3C hub Lakshay Piplani
2026-09-22 10:53 ` sashiko-bot
2026-09-22 10:35 ` [PATCH v20 7/8] i3c: hub: p3h2x4x: Add support for NXP P3H2x4x I3C hub functionality Lakshay Piplani
2026-09-22 10:55 ` sashiko-bot
2026-09-22 10:35 ` [PATCH v20 8/8] i3c: hub: p3h2x4x: Add SMBus slave mode support Lakshay Piplani
2026-09-22 10:55 ` sashiko-bot [this message]
2026-09-30 14:23 ` (subset) [PATCH v20 0/8] Add support for NXP P3H2x4x I3C hub driver Alexandre Belloni
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260922105550.B4DE61F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=alexandre.belloni@bootlin.com \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=lakshay.piplani@nxp.com \
--cc=lee@kernel.org \
--cc=linux-i3c@lists.infradead.org \
--cc=mfd@lists.linux.dev \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox