Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Santhosh Kumar K" <s-k6@ti.com>
Cc: conor+dt@kernel.org, robh@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH v10 04/19] spi: spi-mem: teach spi_mem_adjust_op_freq() about post-config ops
Date: Tue, 29 Sep 2026 06:51:44 +0000	[thread overview]
Message-ID: <20260929065144.95D711F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929063529.1235417-5-s-k6@ti.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] spi-mem: falsely rejects normal ops when max_speed_hz matches post_config speed
- [Medium] spi-mem: premature high-speed execution due to numerical frequency match
- [Medium] spi-mem: missing hardware limit clamp for post-config operations
--

commit 597934102ffdf54ebc8e13a8b68844c8afbc350b
Author: Santhosh Kumar K <s-k6@ti.com>

spi: spi-mem: teach spi_mem_adjust_op_freq() about post-config ops

This patch extends spi_mem_adjust_op_freq() to handle post-config
operations by adding a bypass when op->max_freq matches
post_config_max_speed_hz. It also updates spi_mem_default_supports_op()
to require per-op frequency switching capability for such ops.

> diff --git a/drivers/spi/spi-mem.c b/drivers/spi/spi-mem.c
> index b94680b60af95..7916387a4f1d0 100644
> --- a/drivers/spi/spi-mem.c
> +++ b/drivers/spi/spi-mem.c
> @@ -206,7 +206,8 @@ bool spi_mem_default_supports_op(struct spi_mem *mem,
>  		return false;
>  
>  	if (op->max_freq &&
> -	    op->max_freq < mem->spi->max_speed_hz) {
> +	    (op->max_freq < mem->spi->max_speed_hz ||
> +	     op->max_freq == mem->spi->post_config_max_speed_hz)) {
>  		if (!spi_mem_controller_is_capable(ctlr, per_op_freq))
>  			return false;
>  	}

[Severity: High]
Could this falsely reject standard operations if a board's Device Tree
configures spi-max-frequency and spi-max-post-config-frequency-hz to the
same value?

If post_config_max_speed_hz equals max_speed_hz, spi_mem_adjust_op_freq()
will set an untuned operation's max_freq to max_speed_hz. When
spi_mem_default_supports_op() checks this, it sees op->max_freq ==
mem->spi->post_config_max_speed_hz and strictly requires the per_op_freq
capability.

Controllers lacking per_op_freq would fail this check and reject standard
operations, even though the pre-config and post-config frequencies are identical
and no per-op frequency switching is actually needed.

[ ... ]

> @@ -627,9 +628,18 @@ EXPORT_SYMBOL_GPL(spi_mem_adjust_op_size);
>   * Some chips have per-op frequency limitations and must adapt the maximum
>   * speed. This function allows SPI mem drivers to set @op->max_freq to the
>   * maximum supported value.
> + *
> + * When @mem->spi->post_config_max_speed_hz is set, ops with @op->max_freq
> + * equal to that value are treated as post-configuration ops (e.g. PHY-tuned)
> + * and are allowed to run at the full post-config rate. All other ops are
> + * capped to @mem->spi->max_speed_hz, the always-reachable base rate.
>   */
>  void spi_mem_adjust_op_freq(struct spi_mem *mem, struct spi_mem_op *op)
>  {
> +	if (mem->spi->post_config_max_speed_hz &&
> +	    op->max_freq == mem->spi->post_config_max_speed_hz)
> +		return;
> +

[Severity: Medium]
Does this logic prematurely elevate standard untuned operations to run at high
post-config speeds just because their frequency happens to match numerically?

Since spi->post_config_max_speed_hz is unconditionally populated from the
Device Tree during probe:

drivers/spi/spi.c:of_spi_parse_dt() {
    ...
	if (!of_property_read_u32(nc, "spi-max-post-config-frequency-hz", &value))
		spi->post_config_max_speed_hz = value;
    ...
}

If a standard untuned operation specifies a max_freq limit that
serendipitously matches the DT-populated value, it will be treated as a
post-config op and bypass the base-rate safety cap. Could this result in bus
failures or data corruption for unrelated ops?

[Severity: Medium]
Does this early return also miss a hardware limit clamp for post-config
operations?

Unlike standard max_speed_hz, post_config_max_speed_hz isn't clamped to
the controller's maximum supported hardware speed (ctlr->max_speed_hz) during
device setup. If a misconfigured device tree specifies a
spi-max-post-config-frequency-hz that exceeds ctlr->max_speed_hz, this early
return bypasses the fallback clamping logic entirely. Could this cause the
hardware to receive a frequency request exceeding its absolute physical limits?

>  	if (!op->max_freq || op->max_freq > mem->spi->max_speed_hz)
>  		op->max_freq = mem->spi->max_speed_hz;
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929063529.1235417-1-s-k6@ti.com?part=4

  reply	other threads:[~2026-09-29  6:51 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  6:35 [PATCH v10 00/19] spi: cadence-quadspi: add PHY tuning support Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 01/19] spi: dt-bindings: add spi-max-post-config-frequency-hz property Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 02/19] spi: dt-bindings: add spi-phy-pattern-partition property Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 03/19] spi: parse spi-max-post-config-frequency-hz into post_config_max_speed_hz Santhosh Kumar K
2026-09-29  6:48   ` sashiko-bot
2026-09-29  6:35 ` [PATCH v10 04/19] spi: spi-mem: teach spi_mem_adjust_op_freq() about post-config ops Santhosh Kumar K
2026-09-29  6:51   ` sashiko-bot [this message]
2026-09-29  6:35 ` [PATCH v10 05/19] spi: spi-mem: add execute_tuning callback and spi_mem_execute_tuning() Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 06/19] spi: cadence-quadspi: move cqspi_readdata_capture earlier Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 07/19] spi: cadence-quadspi: add DQS support to read data capture Santhosh Kumar K
2026-09-29  6:51   ` sashiko-bot
2026-09-29  6:35 ` [PATCH v10 08/19] spi: cadence-quadspi: add PHY tuning support Santhosh Kumar K
2026-09-29  6:57   ` sashiko-bot
2026-09-29  6:35 ` [PATCH v10 09/19] spi: cadence-quadspi: skip DDR PHY tuning for 2-byte-address ops (i2383) Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 10/19] spi: cadence-quadspi: refactor direct read path for PHY support Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 11/19] spi: cadence-quadspi: enable PHY for direct reads Santhosh Kumar K
2026-09-29  6:59   ` sashiko-bot
2026-09-29  6:35 ` [PATCH v10 12/19] spi: cadence-quadspi: enable PHY for indirect writes Santhosh Kumar K
2026-09-29  7:00   ` sashiko-bot
2026-09-29  6:35 ` [PATCH v10 13/19] spi: cadence-quadspi: reprogram CS timing on every chip-select switch Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 14/19] spi: cadence-quadspi: reprogram PHY DLL on runtime resume Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 15/19] mtd: spinand: extract variant ranking logic into spinand_op_find_best_variant() Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 16/19] mtd: spinand: negotiate optimal controller operating point before dirmap creation Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 17/19] mtd: spi-nor: extract read op template construction into helper Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 18/19] mtd: spi-nor: run controller optimization before dirmap creation Santhosh Kumar K
2026-09-29  6:35 ` [PATCH v10 19/19] mtd: spi-nor: reset max_read_op frequency for security register reads Santhosh Kumar K

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929065144.95D711F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=s-k6@ti.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox