Devicetree
 help / color / mirror / Atom feed
* [PATCH v2 0/2] pinctrl: apple: Add t8140-pinctrl support
@ 2026-09-26 14:51 Yureka Lilian
  2026-09-26 14:51 ` [PATCH v2 1/2] dt-bindings: pinctrl: apple,pinctrl: Add t8140 compatible Yureka Lilian
                   ` (3 more replies)
  0 siblings, 4 replies; 8+ messages in thread
From: Yureka Lilian @ 2026-09-26 14:51 UTC (permalink / raw)
  To: Sven Peter, Janne Grunau, Neal Gompa, Linus Walleij, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley, Mark Kettenis
  Cc: Yureka Lilian, asahi, linux-arm-kernel, linux-gpio, devicetree,
	linux-kernel

This patch series has fixes for probing the pinctrl_ap GPIO controller
on the MacBook Neo. The previous code would crash in the regmap_init on
this device, since reading the REG_GPIOx for certain pins causes an
SError.
To mitigate this, we adapt the gpio-reserved-ranges property to describe
pins which are unusable and whose REG_GPIOx should not be accessed.

Also add the new t8140 base compatible to the dt-bindings, signifying
the different behavior of the t8140 pinctrl_ap device, and make the
driver accept it since it now respects the gpio-reserved-ranges property.

Signed-off-by: Yureka Lilian <yureka@cyberchaos.dev>
---
Changes in v2:
- EDITME: describe what is new in this series revision.
- EDITME: use bulletpoints and terse descriptions.
- Link to v1: https://patch.msgid.link/20260925-apple-pinctrl-t8140-v1-0-1151bdaf2fff@cyberchaos.dev

To: Sven Peter <sven@kernel.org>
To: Janne Grunau <j@jannau.net>
To: Neal Gompa <neal@gompa.dev>
To: Linus Walleij <linusw@kernel.org>
To: Rob Herring <robh@kernel.org>
To: Krzysztof Kozlowski <krzk+dt@kernel.org>
To: Conor Dooley <conor+dt@kernel.org>
To: Mark Kettenis <kettenis@openbsd.org>
Cc: asahi@lists.linux.dev
Cc: linux-arm-kernel@lists.infradead.org
Cc: linux-gpio@vger.kernel.org
Cc: devicetree@vger.kernel.org
Cc: linux-kernel@vger.kernel.org

---
Yureka Lilian (2):
      dt-bindings: pinctrl: apple,pinctrl: Add t8140 compatible
      pinctrl: apple: Add t8140-pinctrl support

 .../devicetree/bindings/pinctrl/apple,pinctrl.yaml  | 12 ++++++++++++
 drivers/pinctrl/pinctrl-apple-gpio.c                | 21 ++++++++++++++++-----
 2 files changed, 28 insertions(+), 5 deletions(-)
---
base-commit: 63fcbd85bbb795805ce1014637de186c647fa59d
change-id: 20260925-apple-pinctrl-t8140-0e22af416f8c

Best regards,
--  
Yureka Lilian <yureka@cyberchaos.dev>


^ permalink raw reply	[flat|nested] 8+ messages in thread

* [PATCH v2 1/2] dt-bindings: pinctrl: apple,pinctrl: Add t8140 compatible
  2026-09-26 14:51 [PATCH v2 0/2] pinctrl: apple: Add t8140-pinctrl support Yureka Lilian
@ 2026-09-26 14:51 ` Yureka Lilian
  2026-09-30 10:05   ` Krzysztof Kozlowski
  2026-09-26 14:51 ` [PATCH v2 2/2] pinctrl: apple: Add t8140-pinctrl support Yureka Lilian
                   ` (2 subsequent siblings)
  3 siblings, 1 reply; 8+ messages in thread
From: Yureka Lilian @ 2026-09-26 14:51 UTC (permalink / raw)
  To: Sven Peter, Janne Grunau, Neal Gompa, Linus Walleij, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley, Mark Kettenis
  Cc: Yureka Lilian, asahi, linux-arm-kernel, linux-gpio, devicetree,
	linux-kernel

The pinctrl_ap GPIO controller on the MacBook Neo crashes upon reading
REG_GPIOx for certain pins. These pins, which are also listed in Apple's
device tree, are described by the gpio-reserved-ranges property.

Signed-off-by: Yureka Lilian <yureka@cyberchaos.dev>
---
 Documentation/devicetree/bindings/pinctrl/apple,pinctrl.yaml | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/Documentation/devicetree/bindings/pinctrl/apple,pinctrl.yaml b/Documentation/devicetree/bindings/pinctrl/apple,pinctrl.yaml
index bc6d41b63b5d..f2eac9b9a727 100644
--- a/Documentation/devicetree/bindings/pinctrl/apple,pinctrl.yaml
+++ b/Documentation/devicetree/bindings/pinctrl/apple,pinctrl.yaml
@@ -17,6 +17,7 @@ description: |
 properties:
   compatible:
     oneOf:
+      - const: apple,t8140-pinctrl
       - items:
           - enum:
               - apple,t6020-pinctrl
@@ -52,6 +53,8 @@ properties:
   gpio-ranges:
     maxItems: 1
 
+  gpio-reserved-ranges: true
+
   apple,npins:
     $ref: /schemas/types.yaml#/definitions/uint32
     description: The number of pins in this GPIO controller.
@@ -90,6 +93,15 @@ patternProperties:
 
 allOf:
   - $ref: pinctrl.yaml#
+  - if:
+      not:
+        properties:
+          compatible:
+            contains:
+              const: apple,t8140-pinctrl
+    then:
+      properties:
+        gpio-reserved-ranges: false
 
 required:
   - compatible

-- 
2.55.0


^ permalink raw reply related	[flat|nested] 8+ messages in thread

* [PATCH v2 2/2] pinctrl: apple: Add t8140-pinctrl support
  2026-09-26 14:51 [PATCH v2 0/2] pinctrl: apple: Add t8140-pinctrl support Yureka Lilian
  2026-09-26 14:51 ` [PATCH v2 1/2] dt-bindings: pinctrl: apple,pinctrl: Add t8140 compatible Yureka Lilian
@ 2026-09-26 14:51 ` Yureka Lilian
  2026-09-26 15:06   ` sashiko-bot
  2026-09-30 10:03 ` [PATCH v2 0/2] " Krzysztof Kozlowski
  2026-10-01 21:13 ` Linus Walleij
  3 siblings, 1 reply; 8+ messages in thread
From: Yureka Lilian @ 2026-09-26 14:51 UTC (permalink / raw)
  To: Sven Peter, Janne Grunau, Neal Gompa, Linus Walleij, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley, Mark Kettenis
  Cc: Yureka Lilian, asahi, linux-arm-kernel, linux-gpio, devicetree,
	linux-kernel

Ensure the regmap does not attempt to read REG_GPIOx of any of the pins
marked with gpio-reserved-ranges. For this purpose, move the regmap_init
just before the first regmap_read, at which point the valid_mask has
been populated from the gpio-reserved-ranges device tree property.
With this, make the driver accept the new t8140 base compatible as with
this modifications the driver can now be loaded on this SoC without
crashing.

Signed-off-by: Yureka Lilian <yureka@cyberchaos.dev>
---
 drivers/pinctrl/pinctrl-apple-gpio.c | 21 ++++++++++++++++-----
 1 file changed, 16 insertions(+), 5 deletions(-)

diff --git a/drivers/pinctrl/pinctrl-apple-gpio.c b/drivers/pinctrl/pinctrl-apple-gpio.c
index 6305b96aaa73..6b26a23d283c 100644
--- a/drivers/pinctrl/pinctrl-apple-gpio.c
+++ b/drivers/pinctrl/pinctrl-apple-gpio.c
@@ -66,6 +66,13 @@ struct apple_gpio_pinctrl {
 #define REG_GPIOx_DRIVE_STRENGTH1 GENMASK(23, 22)
 #define REG_IRQ(g, x)        (0x800 + 0x40 * (g) + 4 * ((x) >> 5))
 
+static bool apple_gpio_readable_register(struct device *dev, unsigned int reg)
+{
+	struct apple_gpio_pinctrl *pctl = dev_get_drvdata(dev);
+
+	return gpiochip_line_is_valid(&pctl->gpio_chip, reg / 4);
+}
+
 static const struct regmap_config regmap_config = {
 	.reg_bits = 32,
 	.val_bits = 32,
@@ -75,6 +82,7 @@ static const struct regmap_config regmap_config = {
 	.num_reg_defaults_raw = 512,
 	.use_relaxed_mmio = true,
 	.use_raw_spinlock = true,
+	.readable_reg = apple_gpio_readable_register,
 };
 
 /* No locking needed to mask/unmask IRQs as the interrupt mode is per pin-register. */
@@ -90,6 +98,13 @@ static u32 apple_gpio_get_reg(struct apple_gpio_pinctrl *pctl,
 	int ret;
 	u32 val;
 
+	if (!pctl->map)	{
+		pctl->map = devm_regmap_init_mmio(pctl->dev, pctl->base, &regmap_config);
+		if (IS_ERR(pctl->map))
+			return dev_err_probe(pctl->dev, PTR_ERR(pctl->map),
+					"Failed to create regmap\n");
+	}
+
 	ret = regmap_read(pctl->map, REG_GPIO(pin), &val);
 	if (ret)
 		return 0;
@@ -475,11 +490,6 @@ static int apple_gpio_pinctrl_probe(struct platform_device *pdev)
 	if (IS_ERR(pctl->base))
 		return PTR_ERR(pctl->base);
 
-	pctl->map = devm_regmap_init_mmio(&pdev->dev, pctl->base, &regmap_config);
-	if (IS_ERR(pctl->map))
-		return dev_err_probe(&pdev->dev, PTR_ERR(pctl->map),
-				     "Failed to create regmap\n");
-
 	for (i = 0; i < npins; i++) {
 		pins[i].number = i;
 		pins[i].name = devm_kasprintf(&pdev->dev, GFP_KERNEL, "PIN%u", i);
@@ -522,6 +532,7 @@ static int apple_gpio_pinctrl_probe(struct platform_device *pdev)
 }
 
 static const struct of_device_id apple_gpio_pinctrl_of_match[] = {
+	{ .compatible = "apple,t8140-pinctrl", },
 	{ .compatible = "apple,t8103-pinctrl", },
 	{ .compatible = "apple,pinctrl", },
 	{ }

-- 
2.55.0


^ permalink raw reply related	[flat|nested] 8+ messages in thread

* Re: [PATCH v2 2/2] pinctrl: apple: Add t8140-pinctrl support
  2026-09-26 14:51 ` [PATCH v2 2/2] pinctrl: apple: Add t8140-pinctrl support Yureka Lilian
@ 2026-09-26 15:06   ` sashiko-bot
  0 siblings, 0 replies; 8+ messages in thread
From: sashiko-bot @ 2026-09-26 15:06 UTC (permalink / raw)
  To: Yureka Lilian; +Cc: conor+dt, robh, devicetree

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] pinctrl: apple: NULL pointer deref in apple_gpio_set_reg() due to lazy init
- [High] pinctrl: apple: unhandled ERR_PTR from failed regmap init causes crash
--

commit e83219f35e40fdd986984c342182dca31136d937
Author: Yureka Lilian <yureka@cyberchaos.dev>

pinctrl: apple: Add t8140-pinctrl support
    
Ensure the regmap does not attempt to read REG_GPIOx of any of the pins
marked with gpio-reserved-ranges. For this purpose, move the regmap_init
just before the first regmap_read, at which point the valid_mask has
been populated from the gpio-reserved-ranges device tree property.

> diff --git a/drivers/pinctrl/pinctrl-apple-gpio.c b/drivers/pinctrl/pinctrl-apple-gpio.c
> index 6305b96aaa733..6b26a23d283c5 100644
> --- a/drivers/pinctrl/pinctrl-apple-gpio.c
> +++ b/drivers/pinctrl/pinctrl-apple-gpio.c
[ ... ]
> @@ -90,6 +98,13 @@ static u32 apple_gpio_get_reg(struct apple_gpio_pinctrl *pctl,
>  	int ret;
>  	u32 val;
>  
> +	if (!pctl->map)	{
> +		pctl->map = devm_regmap_init_mmio(pctl->dev, pctl->base, &regmap_config);
> +		if (IS_ERR(pctl->map))
> +			return dev_err_probe(pctl->dev, PTR_ERR(pctl->map),
> +					"Failed to create regmap\n");

[Severity: High]
If devm_regmap_init_mmio() fails here, pctl->map is assigned an ERR_PTR but
is never cleared.

Will subsequent calls to apple_gpio_get_reg() bypass this lazy
initialization check since pctl->map is no longer NULL, and dereference
the unhandled ERR_PTR in the following regmap_read() call?

[Severity: High]
Since pctl->map is now lazily initialized only in apple_gpio_get_reg(), what
happens if apple_gpio_set_reg() is called first?

If the device tree contains pinctrl hogs, or a consumer device requests a
pinmux before the first GPIO read triggers this lazy initialization,
apple_gpio_pinmux_set() can call apple_gpio_set_reg().

apple_gpio_set_reg() will then blindly pass the NULL pctl->map to
regmap_update_bits():

drivers/pinctrl/pinctrl-apple-gpio.c:apple_gpio_set_reg() {
	regmap_update_bits(pctl->map, REG_GPIO(pin), mask, value);
}

Could this result in a NULL pointer dereference causing a kernel panic?

> +	}
> +
>  	ret = regmap_read(pctl->map, REG_GPIO(pin), &val);
>  	if (ret)
>  		return 0;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260926-apple-pinctrl-t8140-v2-0-620bd11cd2a1@cyberchaos.dev?part=2

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH v2 0/2] pinctrl: apple: Add t8140-pinctrl support
  2026-09-26 14:51 [PATCH v2 0/2] pinctrl: apple: Add t8140-pinctrl support Yureka Lilian
  2026-09-26 14:51 ` [PATCH v2 1/2] dt-bindings: pinctrl: apple,pinctrl: Add t8140 compatible Yureka Lilian
  2026-09-26 14:51 ` [PATCH v2 2/2] pinctrl: apple: Add t8140-pinctrl support Yureka Lilian
@ 2026-09-30 10:03 ` Krzysztof Kozlowski
  2026-09-30 22:54   ` Yureka Lilian
  2026-10-01 21:13 ` Linus Walleij
  3 siblings, 1 reply; 8+ messages in thread
From: Krzysztof Kozlowski @ 2026-09-30 10:03 UTC (permalink / raw)
  To: Yureka Lilian
  Cc: Sven Peter, Janne Grunau, Neal Gompa, Linus Walleij, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley, Mark Kettenis, asahi,
	linux-arm-kernel, linux-gpio, devicetree, linux-kernel

On Sat, Sep 26, 2026 at 04:51:44PM +0200, Yureka Lilian wrote:
> This patch series has fixes for probing the pinctrl_ap GPIO controller
> on the MacBook Neo. The previous code would crash in the regmap_init on
> this device, since reading the REG_GPIOx for certain pins causes an
> SError.
> To mitigate this, we adapt the gpio-reserved-ranges property to describe
> pins which are unusable and whose REG_GPIOx should not be accessed.
> 
> Also add the new t8140 base compatible to the dt-bindings, signifying
> the different behavior of the t8140 pinctrl_ap device, and make the
> driver accept it since it now respects the gpio-reserved-ranges property.
> 
> Signed-off-by: Yureka Lilian <yureka@cyberchaos.dev>
> ---
> Changes in v2:
> - EDITME: describe what is new in this series revision.
> - EDITME: use bulletpoints and terse descriptions.

EDITME is here on purpose.

Best regards,
Krzysztof


^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH v2 1/2] dt-bindings: pinctrl: apple,pinctrl: Add t8140 compatible
  2026-09-26 14:51 ` [PATCH v2 1/2] dt-bindings: pinctrl: apple,pinctrl: Add t8140 compatible Yureka Lilian
@ 2026-09-30 10:05   ` Krzysztof Kozlowski
  0 siblings, 0 replies; 8+ messages in thread
From: Krzysztof Kozlowski @ 2026-09-30 10:05 UTC (permalink / raw)
  To: Yureka Lilian
  Cc: Sven Peter, Janne Grunau, Neal Gompa, Linus Walleij, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley, Mark Kettenis, asahi,
	linux-arm-kernel, linux-gpio, devicetree, linux-kernel

On Sat, Sep 26, 2026 at 04:51:45PM +0200, Yureka Lilian wrote:
> The pinctrl_ap GPIO controller on the MacBook Neo crashes upon reading
> REG_GPIOx for certain pins. These pins, which are also listed in Apple's
> device tree, are described by the gpio-reserved-ranges property.
> 
> Signed-off-by: Yureka Lilian <yureka@cyberchaos.dev>
> ---
>  Documentation/devicetree/bindings/pinctrl/apple,pinctrl.yaml | 12 ++++++++++++
>  1 file changed, 12 insertions(+)

Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

Best regards,
Krzysztof


^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH v2 0/2] pinctrl: apple: Add t8140-pinctrl support
  2026-09-30 10:03 ` [PATCH v2 0/2] " Krzysztof Kozlowski
@ 2026-09-30 22:54   ` Yureka Lilian
  0 siblings, 0 replies; 8+ messages in thread
From: Yureka Lilian @ 2026-09-30 22:54 UTC (permalink / raw)
  To: Krzysztof Kozlowski, Yureka Lilian
  Cc: Sven Peter, Janne Grunau, Neal Gompa, Linus Walleij, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley, Mark Kettenis, asahi,
	linux-arm-kernel, linux-gpio, devicetree, linux-kernel

On 9/30/26 12:03, Krzysztof Kozlowski wrote:
> On Sat, Sep 26, 2026 at 04:51:44PM +0200, Yureka Lilian wrote:
>> This patch series has fixes for probing the pinctrl_ap GPIO controller
>> on the MacBook Neo. The previous code would crash in the regmap_init on
>> this device, since reading the REG_GPIOx for certain pins causes an
>> SError.
>> To mitigate this, we adapt the gpio-reserved-ranges property to describe
>> pins which are unusable and whose REG_GPIOx should not be accessed.
>>
>> Also add the new t8140 base compatible to the dt-bindings, signifying
>> the different behavior of the t8140 pinctrl_ap device, and make the
>> driver accept it since it now respects the gpio-reserved-ranges property.
>>
>> Signed-off-by: Yureka Lilian <yureka@cyberchaos.dev>
>> ---
>> Changes in v2:
>> - EDITME: describe what is new in this series revision.
>> - EDITME: use bulletpoints and terse descriptions.
> EDITME is here on purpose.
>
> Best regards,
> Krzysztof

Sorry about that, I had to send it twice (this is the first version 
to actually land on the mailing list) and forgot that b4 does the whole 
auto-increment and add these cover letter entries. Will be more careful 
and use --preview-to before *every* send starting from next time.

Thank you for understanding,

- Yureka


^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH v2 0/2] pinctrl: apple: Add t8140-pinctrl support
  2026-09-26 14:51 [PATCH v2 0/2] pinctrl: apple: Add t8140-pinctrl support Yureka Lilian
                   ` (2 preceding siblings ...)
  2026-09-30 10:03 ` [PATCH v2 0/2] " Krzysztof Kozlowski
@ 2026-10-01 21:13 ` Linus Walleij
  3 siblings, 0 replies; 8+ messages in thread
From: Linus Walleij @ 2026-10-01 21:13 UTC (permalink / raw)
  To: Yureka Lilian
  Cc: Sven Peter, Janne Grunau, Neal Gompa, Rob Herring,
	Krzysztof Kozlowski, Conor Dooley, Mark Kettenis, asahi,
	linux-arm-kernel, linux-gpio, devicetree, linux-kernel

On Sat, Sep 26, 2026 at 4:52 PM Yureka Lilian <yureka@cyberchaos.dev> wrote:

> This patch series has fixes for probing the pinctrl_ap GPIO controller
> on the MacBook Neo. The previous code would crash in the regmap_init on
> this device, since reading the REG_GPIOx for certain pins causes an
> SError.
> To mitigate this, we adapt the gpio-reserved-ranges property to describe
> pins which are unusable and whose REG_GPIOx should not be accessed.
>
> Also add the new t8140 base compatible to the dt-bindings, signifying
> the different behavior of the t8140 pinctrl_ap device, and make the
> driver accept it since it now respects the gpio-reserved-ranges property.
>
> Signed-off-by: Yureka Lilian <yureka@cyberchaos.dev>

Patches applied!

Yours,
Linus Walleij

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-10-01 21:13 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 14:51 [PATCH v2 0/2] pinctrl: apple: Add t8140-pinctrl support Yureka Lilian
2026-09-26 14:51 ` [PATCH v2 1/2] dt-bindings: pinctrl: apple,pinctrl: Add t8140 compatible Yureka Lilian
2026-09-30 10:05   ` Krzysztof Kozlowski
2026-09-26 14:51 ` [PATCH v2 2/2] pinctrl: apple: Add t8140-pinctrl support Yureka Lilian
2026-09-26 15:06   ` sashiko-bot
2026-09-30 10:03 ` [PATCH v2 0/2] " Krzysztof Kozlowski
2026-09-30 22:54   ` Yureka Lilian
2026-10-01 21:13 ` Linus Walleij

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox