From: sashiko-bot@kernel.org
To: "Santhosh Kumar K" <s-k6@ti.com>
Cc: devicetree@vger.kernel.org, robh@kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v10 11/19] spi: cadence-quadspi: enable PHY for direct reads
Date: Tue, 29 Sep 2026 06:59:35 +0000 [thread overview]
Message-ID: <20260929065935.D93B41F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929063529.1235417-12-s-k6@ti.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] spi: cadence-quadspi: hardware state leak on PHY read disable timeout
--
commit 439a6492544eb30602326054af398141c453e461
Author: Santhosh Kumar K <s-k6@ti.com>
spi: cadence-quadspi: enable PHY for direct reads
Add cqspi_tune_phy_read() to toggle PHY mode around a direct-mode DMA
read. On enable, it reprograms the DLL from the per-CS calibration result,
configures read-capture for the tuned delay, and asserts PHY_EN and
PHY_PIPELINE in CONFIG. A fallback mechanism drops the clock to the base
rate for operations that cannot use the tuned PHY.
> diff --git a/drivers/spi/spi-cadence-quadspi.c b/drivers/spi/spi-cadence-quadspi.c
> index 494008b953cd6..ad99e72578337 100644
> --- a/drivers/spi/spi-cadence-quadspi.c
> +++ b/drivers/spi/spi-cadence-quadspi.c
[ ... ]
> @@ -1075,6 +1076,105 @@ static int cqspi_resync_dll(struct cqspi_st *cqspi)
[ ... ]
> +static int cqspi_tune_phy_read(struct cqspi_flash_pdata *f_pdata, bool enable)
> +{
> + struct cqspi_st *cqspi = f_pdata->cqspi;
> + void __iomem *reg_base = cqspi->iobase;
> + u32 reg;
> + u8 dummy;
> + int ret;
> +
> + /* Wait for idle before touching CONFIG/RD_INSTR either direction. */
> + ret = cqspi_wait_idle(cqspi);
> + if (ret)
> + return ret;
[Severity: High]
Does returning early here on a timeout during disable leak the PHY state?
In cqspi_direct_read_execute(), a direct read is initiated and then the PHY
is disabled via cqspi_tune_phy_read(f_pdata, false). If the direct read
operation stalls and cqspi_wait_idle() times out here, the early return
bypasses the cleanup in cqspi_phy_restore_read_config().
This would leave the CQSPI_REG_CONFIG_PHY_EN and CQSPI_REG_CONFIG_PHY_PIPELINE
bits permanently set in the controller's configuration register. Could this
cause subsequent untuned or indirect operations (which do not clear these
bits) to execute with the PHY unexpectedly active, leading to timing
mismatches or data corruption?
> +
> + if (!enable) {
> + cqspi_phy_restore_read_config(f_pdata);
> + return 0;
> + }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929063529.1235417-1-s-k6@ti.com?part=11
next prev parent reply other threads:[~2026-09-29 6:59 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 6:35 [PATCH v10 00/19] spi: cadence-quadspi: add PHY tuning support Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 01/19] spi: dt-bindings: add spi-max-post-config-frequency-hz property Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 02/19] spi: dt-bindings: add spi-phy-pattern-partition property Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 03/19] spi: parse spi-max-post-config-frequency-hz into post_config_max_speed_hz Santhosh Kumar K
2026-09-29 6:48 ` sashiko-bot
2026-09-29 6:35 ` [PATCH v10 04/19] spi: spi-mem: teach spi_mem_adjust_op_freq() about post-config ops Santhosh Kumar K
2026-09-29 6:51 ` sashiko-bot
2026-09-29 6:35 ` [PATCH v10 05/19] spi: spi-mem: add execute_tuning callback and spi_mem_execute_tuning() Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 06/19] spi: cadence-quadspi: move cqspi_readdata_capture earlier Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 07/19] spi: cadence-quadspi: add DQS support to read data capture Santhosh Kumar K
2026-09-29 6:51 ` sashiko-bot
2026-09-29 6:35 ` [PATCH v10 08/19] spi: cadence-quadspi: add PHY tuning support Santhosh Kumar K
2026-09-29 6:57 ` sashiko-bot
2026-09-29 6:35 ` [PATCH v10 09/19] spi: cadence-quadspi: skip DDR PHY tuning for 2-byte-address ops (i2383) Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 10/19] spi: cadence-quadspi: refactor direct read path for PHY support Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 11/19] spi: cadence-quadspi: enable PHY for direct reads Santhosh Kumar K
2026-09-29 6:59 ` sashiko-bot [this message]
2026-09-29 6:35 ` [PATCH v10 12/19] spi: cadence-quadspi: enable PHY for indirect writes Santhosh Kumar K
2026-09-29 7:00 ` sashiko-bot
2026-09-29 6:35 ` [PATCH v10 13/19] spi: cadence-quadspi: reprogram CS timing on every chip-select switch Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 14/19] spi: cadence-quadspi: reprogram PHY DLL on runtime resume Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 15/19] mtd: spinand: extract variant ranking logic into spinand_op_find_best_variant() Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 16/19] mtd: spinand: negotiate optimal controller operating point before dirmap creation Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 17/19] mtd: spi-nor: extract read op template construction into helper Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 18/19] mtd: spi-nor: run controller optimization before dirmap creation Santhosh Kumar K
2026-09-29 6:35 ` [PATCH v10 19/19] mtd: spi-nor: reset max_read_op frequency for security register reads Santhosh Kumar K
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929065935.D93B41F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=robh@kernel.org \
--cc=s-k6@ti.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox