* [PATCH v5 1/4] dt-bindings: nvmem: mediatek: efuse: add mt6572
2026-09-30 10:14 [PATCH v5 0/4] nvmem: mtk-efuse: mt6572 support Roman Vivchar via B4 Relay
@ 2026-09-30 10:14 ` Roman Vivchar via B4 Relay
2026-09-30 10:14 ` [PATCH v5 2/4] nvmem: mtk-efuse: add support for 32-bit aligned reads Roman Vivchar via B4 Relay
` (2 subsequent siblings)
3 siblings, 0 replies; 6+ messages in thread
From: Roman Vivchar via B4 Relay @ 2026-09-30 10:14 UTC (permalink / raw)
To: Srinivas Kandagatla, Rob Herring, Krzysztof Kozlowski,
Conor Dooley, Matthias Brugger, AngeloGioacchino Del Regno,
Andrew-CT Chen, Lala Lin
Cc: devicetree, linux-kernel, linux-arm-kernel, linux-mediatek,
Roman Vivchar
From: Roman Vivchar <rva333@protonmail.com>
Add a compatible string for the mt6572 SoC efuse controller.
Reviewed-by: Rob Herring (Arm) <robh@kernel.org>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: Roman Vivchar <rva333@protonmail.com>
---
Documentation/devicetree/bindings/nvmem/mediatek,efuse.yaml | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/Documentation/devicetree/bindings/nvmem/mediatek,efuse.yaml b/Documentation/devicetree/bindings/nvmem/mediatek,efuse.yaml
index f9323b3ecfc8..e10947164941 100644
--- a/Documentation/devicetree/bindings/nvmem/mediatek,efuse.yaml
+++ b/Documentation/devicetree/bindings/nvmem/mediatek,efuse.yaml
@@ -24,13 +24,16 @@ properties:
compatible:
oneOf:
+ - enum:
+ - mediatek,mt6572-efuse
+ - mediatek,mt8186-efuse
+
- items:
- enum:
- mediatek,mt8188-efuse
- mediatek,mt8189-efuse
- mediatek,mt8196-efuse
- const: mediatek,mt8186-efuse
- - const: mediatek,mt8186-efuse
- items:
- enum:
--
2.55.0
^ permalink raw reply related [flat|nested] 6+ messages in thread* [PATCH v5 2/4] nvmem: mtk-efuse: add support for 32-bit aligned reads
2026-09-30 10:14 [PATCH v5 0/4] nvmem: mtk-efuse: mt6572 support Roman Vivchar via B4 Relay
2026-09-30 10:14 ` [PATCH v5 1/4] dt-bindings: nvmem: mediatek: efuse: add mt6572 Roman Vivchar via B4 Relay
@ 2026-09-30 10:14 ` Roman Vivchar via B4 Relay
2026-09-30 10:14 ` [PATCH v5 3/4] nvmem: mtk-efuse: add CPU speedbin post-processing Roman Vivchar via B4 Relay
2026-09-30 10:14 ` [PATCH v5 4/4] nvmem: mtk-efuse: add mt6572 support Roman Vivchar via B4 Relay
3 siblings, 0 replies; 6+ messages in thread
From: Roman Vivchar via B4 Relay @ 2026-09-30 10:14 UTC (permalink / raw)
To: Srinivas Kandagatla, Rob Herring, Krzysztof Kozlowski,
Conor Dooley, Matthias Brugger, AngeloGioacchino Del Regno,
Andrew-CT Chen, Lala Lin
Cc: devicetree, linux-kernel, linux-arm-kernel, linux-mediatek,
Roman Vivchar
From: Roman Vivchar <rva333@protonmail.com>
Some MediaTek SoCs, such as mt6572, don't support 8-bit reads, leading
to zeroes or garbage data. 32-bit aligned reads must be used instead.
Introduce a 'mtk_reg_read_aligned' helper to enforce 32-bit aligned
register access. All reads will be performed by reading 4-byte words
and masking them.
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: Roman Vivchar <rva333@protonmail.com>
---
drivers/nvmem/mtk-efuse.c | 35 ++++++++++++++++++++++++++++++++++-
1 file changed, 34 insertions(+), 1 deletion(-)
diff --git a/drivers/nvmem/mtk-efuse.c b/drivers/nvmem/mtk-efuse.c
index 00a84ea963a8..980c29d01337 100644
--- a/drivers/nvmem/mtk-efuse.c
+++ b/drivers/nvmem/mtk-efuse.c
@@ -4,6 +4,7 @@
* Author: Andrew-CT Chen <andrew-ct.chen@mediatek.com>
*/
+#include <linux/align.h>
#include <linux/device.h>
#include <linux/module.h>
#include <linux/io.h>
@@ -13,12 +14,37 @@
struct mtk_efuse_pdata {
bool uses_post_processing;
+ bool needs_aligned_read;
};
struct mtk_efuse_priv {
void __iomem *base;
};
+static int mtk_reg_read_aligned(void *context,
+ unsigned int reg, void *_val, size_t bytes)
+{
+ struct mtk_efuse_priv *priv = context;
+ u8 *val = _val;
+ u32 i, pos, shift, val32;
+
+ for (i = 0; i < bytes; i++, val++) {
+ pos = reg + i;
+
+ /*
+ * Read on 32-bit word boundary or if it's the first
+ * iteration
+ */
+ if (i == 0 || IS_ALIGNED(pos, 4))
+ val32 = readl(priv->base + (pos & ~3));
+
+ shift = (pos & 3) * 8;
+ *val = (val32 >> shift) & 0xff;
+ }
+
+ return 0;
+}
+
static int mtk_reg_read(void *context,
unsigned int reg, void *_val, size_t bytes)
{
@@ -81,7 +107,12 @@ static int mtk_efuse_probe(struct platform_device *pdev)
econfig.add_legacy_fixed_of_cells = true;
econfig.stride = 1;
econfig.word_size = 1;
- econfig.reg_read = mtk_reg_read;
+
+ if (pdata->needs_aligned_read)
+ econfig.reg_read = mtk_reg_read_aligned;
+ else
+ econfig.reg_read = mtk_reg_read;
+
econfig.size = resource_size(res);
econfig.priv = priv;
econfig.dev = dev;
@@ -102,10 +133,12 @@ static int mtk_efuse_probe(struct platform_device *pdev)
static const struct mtk_efuse_pdata mtk_mt8186_efuse_pdata = {
.uses_post_processing = true,
+ .needs_aligned_read = false,
};
static const struct mtk_efuse_pdata mtk_efuse_pdata = {
.uses_post_processing = false,
+ .needs_aligned_read = false,
};
static const struct of_device_id mtk_efuse_of_match[] = {
--
2.55.0
^ permalink raw reply related [flat|nested] 6+ messages in thread* [PATCH v5 3/4] nvmem: mtk-efuse: add CPU speedbin post-processing
2026-09-30 10:14 [PATCH v5 0/4] nvmem: mtk-efuse: mt6572 support Roman Vivchar via B4 Relay
2026-09-30 10:14 ` [PATCH v5 1/4] dt-bindings: nvmem: mediatek: efuse: add mt6572 Roman Vivchar via B4 Relay
2026-09-30 10:14 ` [PATCH v5 2/4] nvmem: mtk-efuse: add support for 32-bit aligned reads Roman Vivchar via B4 Relay
@ 2026-09-30 10:14 ` Roman Vivchar via B4 Relay
2026-09-30 10:27 ` sashiko-bot
2026-09-30 10:14 ` [PATCH v5 4/4] nvmem: mtk-efuse: add mt6572 support Roman Vivchar via B4 Relay
3 siblings, 1 reply; 6+ messages in thread
From: Roman Vivchar via B4 Relay @ 2026-09-30 10:14 UTC (permalink / raw)
To: Srinivas Kandagatla, Rob Herring, Krzysztof Kozlowski,
Conor Dooley, Matthias Brugger, AngeloGioacchino Del Regno,
Andrew-CT Chen, Lala Lin
Cc: devicetree, linux-kernel, linux-arm-kernel, linux-mediatek,
Roman Vivchar
From: Roman Vivchar <rva333@protonmail.com>
MediaTek SoCs are often released under the same marketing name, but with
different suffix for the speedbin. For example, mt6572m has 1 GHz limit,
mt6572a - 1.2 GHz, mt6572w - 1.4 GHz.
Since the speedbin is stored as a number in the efuse, add support for
converting it to the bitmask for opp-supported-hw usage in the DT.
Signed-off-by: Roman Vivchar <rva333@protonmail.com>
---
drivers/nvmem/mtk-efuse.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
diff --git a/drivers/nvmem/mtk-efuse.c b/drivers/nvmem/mtk-efuse.c
index 980c29d01337..d2e5c69c580e 100644
--- a/drivers/nvmem/mtk-efuse.c
+++ b/drivers/nvmem/mtk-efuse.c
@@ -70,6 +70,18 @@ static int mtk_efuse_gpu_speedbin_pp(void *context, const char *id, int index,
return 0;
}
+static int mtk_efuse_cpu_speedbin_pp(void *context, const char *id, int index,
+ unsigned int offset, void *data, size_t bytes)
+{
+ u8 *val = data;
+
+ if (val[0] >= 8)
+ return -EINVAL;
+
+ val[0] = BIT(val[0]);
+ return 0;
+}
+
static void mtk_efuse_fixup_dt_cell_info(struct nvmem_device *nvmem,
struct nvmem_cell_info *cell)
{
@@ -83,6 +95,13 @@ static void mtk_efuse_fixup_dt_cell_info(struct nvmem_device *nvmem,
if (cell->nbits <= 3 &&
strncmp(cell->name, "gpu-speedbin", min(sz, strlen("gpu-speedbin"))) == 0)
cell->read_post_process = mtk_efuse_gpu_speedbin_pp;
+
+ /*
+ * On mobile SoCs, the CPU speedbin is a number. Convert it to
+ * a bitmask for supported-hw usage.
+ */
+ if (strncmp(cell->name, "cpu-speedbin", min(sz, strlen("cpu-speedbin"))) == 0)
+ cell->read_post_process = mtk_efuse_cpu_speedbin_pp;
}
static int mtk_efuse_probe(struct platform_device *pdev)
--
2.55.0
^ permalink raw reply related [flat|nested] 6+ messages in thread* Re: [PATCH v5 3/4] nvmem: mtk-efuse: add CPU speedbin post-processing
2026-09-30 10:14 ` [PATCH v5 3/4] nvmem: mtk-efuse: add CPU speedbin post-processing Roman Vivchar via B4 Relay
@ 2026-09-30 10:27 ` sashiko-bot
0 siblings, 0 replies; 6+ messages in thread
From: sashiko-bot @ 2026-09-30 10:27 UTC (permalink / raw)
To: Roman Vivchar; +Cc: robh, devicetree, conor+dt
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] nvmem: flawed string matching applies cpu-speedbin hook to unintended prefixes
- [High] nvmem: out-of-bounds access on zero-length cell in mtk_efuse_cpu_speedbin_pp()
--
commit 6fd2c8ebf274a3effe09809dbfe826b5c25b063f
Author: Roman Vivchar <rva333@protonmail.com>
nvmem: mtk-efuse: add CPU speedbin post-processing
This commit adds support for converting CPU speedbin values stored in efuse
into a bitmask for opp-supported-hw usage in device trees on mobile SoCs.
> diff --git a/drivers/nvmem/mtk-efuse.c b/drivers/nvmem/mtk-efuse.c
> index 980c29d013375..d2e5c69c580e3 100644
> --- a/drivers/nvmem/mtk-efuse.c
> +++ b/drivers/nvmem/mtk-efuse.c
> @@ -70,6 +70,18 @@ static int mtk_efuse_gpu_speedbin_pp(void *context, const char *id, int index,
> return 0;
> }
>
> +static int mtk_efuse_cpu_speedbin_pp(void *context, const char *id, int index,
> + unsigned int offset, void *data, size_t bytes)
> +{
> + u8 *val = data;
> +
> + if (val[0] >= 8)
[Severity: High]
If a device tree defines a matching nvmem cell with a length of 0 bytes
(e.g., reg = <0x0 0x0>), the nvmem core allocates an empty buffer using
kzalloc(0, GFP_KERNEL), which returns the ZERO_SIZE_PTR macro.
Could this unconditionally dereference that ZERO_SIZE_PTR and cause a
kernel panic when reading the cell?
> + return -EINVAL;
> +
> + val[0] = BIT(val[0]);
> + return 0;
> +}
> +
> static void mtk_efuse_fixup_dt_cell_info(struct nvmem_device *nvmem,
> struct nvmem_cell_info *cell)
> {
[ ... ]
> @@ -83,6 +95,13 @@ static void mtk_efuse_fixup_dt_cell_info(struct nvmem_device *nvmem,
> if (cell->nbits <= 3 &&
> strncmp(cell->name, "gpu-speedbin", min(sz, strlen("gpu-speedbin"))) == 0)
> cell->read_post_process = mtk_efuse_gpu_speedbin_pp;
> +
> + /*
> + * On mobile SoCs, the CPU speedbin is a number. Convert it to
> + * a bitmask for supported-hw usage.
> + */
> + if (strncmp(cell->name, "cpu-speedbin", min(sz, strlen("cpu-speedbin"))) == 0)
[Severity: High]
Does this string comparison correctly restrict the match to just the
"cpu-speedbin" cell?
Since the comparison length uses min(sz, strlen("cpu-speedbin")), if a
device tree contains a cell with a name that is a shorter prefix of
"cpu-speedbin" (like "cpu" or "c"), the min() function will select the
shorter string's length.
Could this result in strncmp returning 0 for unrelated cell prefixes,
incorrectly applying the post-processing hook and silently corrupting
their data?
> + cell->read_post_process = mtk_efuse_cpu_speedbin_pp;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260930-6572-nvmem-v5-0-384d2a3a1770@protonmail.com?part=3
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH v5 4/4] nvmem: mtk-efuse: add mt6572 support
2026-09-30 10:14 [PATCH v5 0/4] nvmem: mtk-efuse: mt6572 support Roman Vivchar via B4 Relay
` (2 preceding siblings ...)
2026-09-30 10:14 ` [PATCH v5 3/4] nvmem: mtk-efuse: add CPU speedbin post-processing Roman Vivchar via B4 Relay
@ 2026-09-30 10:14 ` Roman Vivchar via B4 Relay
3 siblings, 0 replies; 6+ messages in thread
From: Roman Vivchar via B4 Relay @ 2026-09-30 10:14 UTC (permalink / raw)
To: Srinivas Kandagatla, Rob Herring, Krzysztof Kozlowski,
Conor Dooley, Matthias Brugger, AngeloGioacchino Del Regno,
Andrew-CT Chen, Lala Lin
Cc: devicetree, linux-kernel, linux-arm-kernel, linux-mediatek,
Roman Vivchar
From: Roman Vivchar <rva333@protonmail.com>
Add a platform data struct for the efuse controller.
Signed-off-by: Roman Vivchar <rva333@protonmail.com>
---
drivers/nvmem/mtk-efuse.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/nvmem/mtk-efuse.c b/drivers/nvmem/mtk-efuse.c
index d2e5c69c580e..24d302a15528 100644
--- a/drivers/nvmem/mtk-efuse.c
+++ b/drivers/nvmem/mtk-efuse.c
@@ -150,6 +150,11 @@ static int mtk_efuse_probe(struct platform_device *pdev)
return 0;
}
+static const struct mtk_efuse_pdata mtk_mt6572_efuse_pdata = {
+ .uses_post_processing = true,
+ .needs_aligned_read = true,
+};
+
static const struct mtk_efuse_pdata mtk_mt8186_efuse_pdata = {
.uses_post_processing = true,
.needs_aligned_read = false,
@@ -161,6 +166,7 @@ static const struct mtk_efuse_pdata mtk_efuse_pdata = {
};
static const struct of_device_id mtk_efuse_of_match[] = {
+ { .compatible = "mediatek,mt6572-efuse", .data = &mtk_mt6572_efuse_pdata },
{ .compatible = "mediatek,mt8173-efuse", .data = &mtk_efuse_pdata },
{ .compatible = "mediatek,mt8186-efuse", .data = &mtk_mt8186_efuse_pdata },
{ .compatible = "mediatek,efuse", .data = &mtk_efuse_pdata },
--
2.55.0
^ permalink raw reply related [flat|nested] 6+ messages in thread