* [PATCH v10 0/6] spmi: apple: Additional commands and interrupt support.
@ 2026-10-01 20:26 Sasha Finkelstein
2026-10-01 20:26 ` [PATCH v10 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122 Sasha Finkelstein
` (5 more replies)
0 siblings, 6 replies; 11+ messages in thread
From: Sasha Finkelstein @ 2026-10-01 20:26 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Conor Dooley, Alba Mendez
The SPMI bus has grown additional responsibilities in the M3
generation, making the current driver insufficient. Add M3 comatibles,
support for slave-sent interrupts, FIFO interrupts, power management
commands, parity validation, and fix locking.
To simplify the merge strategy, the device tree entries will be sent
in a future patch series.
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
Changes in v10:
- Just collecting tags, effectively a resend
- Link to v9: https://patch.msgid.link/20260901-t603x-spmi-v9-0-09e702e3b153@chaosmail.tech
Changes in v9:
- more dt-binding fixes
- Link to v8: https://patch.msgid.link/20260828-t603x-spmi-v8-0-708d4d12e0fd@chaosmail.tech
Changes in v8:
- dt-binding style fixes per review
- Link to v7: https://patch.msgid.link/20260818-t603x-spmi-v7-0-dafebe6e7739@chaosmail.tech
Changes in v7:
- Require interrupt support on M3+
- Link to v6: https://patch.msgid.link/20260816-t603x-spmi-v6-0-c5ab87aa447b@chaosmail.tech
Changes in v6:
- Fix interrupt controller teardown
- Link to v5: https://patch.msgid.link/20260808-t603x-spmi-v5-0-553c5ac2f137@chaosmail.tech
Changes in v5:
- Style fixes per review
- Fix fifo flush
- Link to v4: https://patch.msgid.link/20260805-t603x-spmi-v4-0-c15a12d9a7d1@chaosmail.tech
Changes in v4:
- Re-do error recovery.
- Fix an address calculation mistake
- Link to v3: https://patch.msgid.link/20260803-t603x-spmi-v3-0-c17b506d91a1@chaosmail.tech
Changes in v3:
- Rework interrupt support
- Address review comments
- Link to v2: https://patch.msgid.link/20260728-t603x-spmi-v2-0-f43e5f10e583@chaosmail.tech
Changes in v2:
- Change locking to non-interruptible
- Reorder irq ack
- Clarify dt binding
- Some data type cleanups
- Link to v1: https://patch.msgid.link/20260725-t603x-spmi-v1-0-e1a29fcd2d38@chaosmail.tech
---
Alba Mendez (5):
spmi: apple: Validate FIFO state
spmi: apple: check transaction status
spmi: apple: Implement remaining commands
spmi: apple: lock around FIFOs
spmi: apple: Add interrupt functionality
Sasha Finkelstein (1):
dt-bindings: spmi: apple,spmi: Add t603x and t8122
Documentation/devicetree/bindings/spmi/apple,spmi.yaml | 29 ++++++++++
drivers/spmi/Kconfig | 3 +-
drivers/spmi/spmi-apple-controller.c | 389 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++----------
3 files changed, 389 insertions(+), 32 deletions(-)
---
base-commit: 0f23d56f17fdfc7db69d51f64c8b91bbab947aa9
change-id: 20260725-t603x-spmi-74630bf1b0a0
Best regards,
--
Sasha Finkelstein <k@chaosmail.tech>
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH v10 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122
2026-10-01 20:26 [PATCH v10 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
@ 2026-10-01 20:26 ` Sasha Finkelstein
2026-10-02 9:13 ` sashiko-bot
2026-10-01 20:26 ` [PATCH v10 2/6] spmi: apple: Validate FIFO state Sasha Finkelstein
` (4 subsequent siblings)
5 siblings, 1 reply; 11+ messages in thread
From: Sasha Finkelstein @ 2026-10-01 20:26 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Conor Dooley
Add t603x and t8122 compatibles, interrupt support, and support for
SPMI controllers that are not always-on.
Reviewed-by: Janne Grunau <j@jannau.net>
Acked-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
Documentation/devicetree/bindings/spmi/apple,spmi.yaml | 29 +++++++++++++++++++++++++++++
1 file changed, 29 insertions(+)
diff --git a/Documentation/devicetree/bindings/spmi/apple,spmi.yaml b/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
index 3e5b14bc8c31..4e73083ecec3 100644
--- a/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
+++ b/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
@@ -20,8 +20,11 @@ properties:
- items:
- enum:
- apple,t6020-spmi
+ - apple,t6030-spmi
+ - apple,t6031-spmi
- apple,t8012-spmi
- apple,t8015-spmi
+ - apple,t8122-spmi
- const: apple,t8103-spmi
- items:
- enum:
@@ -34,10 +37,36 @@ properties:
reg:
maxItems: 1
+ interrupts:
+ maxItems: 1
+ description: Optional, operates in polled mode if not present
+
+ interrupt-controller: true
+
+ "#interrupt-cells":
+ const: 2
+
+ power-domains:
+ maxItems: 1
+
required:
- compatible
- reg
+if:
+ properties:
+ compatible:
+ contains:
+ enum:
+ - apple,t8122-spmi
+ - apple,t6030-spmi
+ - apple,t6031-spmi
+then:
+ required:
+ - interrupt-controller
+ - "#interrupt-cells"
+ - interrupts
+
unevaluatedProperties: false
examples:
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v10 2/6] spmi: apple: Validate FIFO state
2026-10-01 20:26 [PATCH v10 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
2026-10-01 20:26 ` [PATCH v10 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122 Sasha Finkelstein
@ 2026-10-01 20:26 ` Sasha Finkelstein
2026-10-01 20:26 ` [PATCH v10 3/6] spmi: apple: check transaction status Sasha Finkelstein
` (3 subsequent siblings)
5 siblings, 0 replies; 11+ messages in thread
From: Sasha Finkelstein @ 2026-10-01 20:26 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Alba Mendez
From: Alba Mendez <me@alba.sh>
Check for data before reading the body of a reply, and check for
end of data afterwards.
Signed-off-by: Alba Mendez <me@alba.sh>
Reviewed-by: Janne Grunau <j@jannau.net>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
drivers/spmi/spmi-apple-controller.c | 30 ++++++++++++++++++++++++++++++
1 file changed, 30 insertions(+)
diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
index 376cf682c43e..15721cb41d5c 100644
--- a/drivers/spmi/spmi-apple-controller.c
+++ b/drivers/spmi/spmi-apple-controller.c
@@ -21,7 +21,9 @@
#define SPMI_STATUS_REG 0
#define SPMI_CMD_REG 0x4
#define SPMI_RSP_REG 0x8
+#define SPMI_ACT_REG 0xa4
+#define SPMI_ACT_FIFO_FLUSH BIT(0)
#define SPMI_RX_FIFO_EMPTY BIT(24)
#define REG_POLL_INTERVAL_US 10000
@@ -29,6 +31,7 @@
struct apple_spmi {
void __iomem *regs;
+ bool prev_fail;
};
#define poll_reg(spmi, reg, val, cond) \
@@ -49,6 +52,7 @@ static int apple_spmi_wait_rx_not_empty(struct spmi_controller *ctrl)
ret = poll_reg(spmi, SPMI_STATUS_REG, status, !(status & SPMI_RX_FIFO_EMPTY));
if (ret) {
+ spmi->prev_fail = true;
dev_err(&ctrl->dev,
"failed to wait for RX FIFO not empty\n");
return ret;
@@ -67,6 +71,11 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
u8 i;
int ret;
+ if (spmi->prev_fail) {
+ writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
+ spmi->prev_fail = false;
+ }
+
writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
ret = apple_spmi_wait_rx_not_empty(ctrl);
@@ -78,6 +87,12 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
/* Read SPMI data reply */
while (len_read < len) {
+ if (readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY) {
+ spmi->prev_fail = true;
+ dev_err_ratelimited(&ctrl->dev,
+ "FIFO lacks reply data, controller stuck?\n");
+ return -EIO;
+ }
rsp = readl(spmi->regs + SPMI_RSP_REG);
i = 0;
while ((len_read < len) && (i < 4)) {
@@ -86,6 +101,11 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
}
}
+ if (!(readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)) {
+ dev_warn(&ctrl->dev, "FIFO has extra data\n");
+ spmi->prev_fail = true;
+ }
+
return 0;
}
@@ -97,6 +117,11 @@ static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
size_t i = 0, j;
int ret;
+ if (spmi->prev_fail) {
+ writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
+ spmi->prev_fail = false;
+ }
+
writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
while (i < len) {
@@ -115,6 +140,11 @@ static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
/* Discard */
readl(spmi->regs + SPMI_RSP_REG);
+ if (!(readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)) {
+ dev_warn(&ctrl->dev, "FIFO has extra data\n");
+ spmi->prev_fail = true;
+ }
+
return 0;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v10 3/6] spmi: apple: check transaction status
2026-10-01 20:26 [PATCH v10 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
2026-10-01 20:26 ` [PATCH v10 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122 Sasha Finkelstein
2026-10-01 20:26 ` [PATCH v10 2/6] spmi: apple: Validate FIFO state Sasha Finkelstein
@ 2026-10-01 20:26 ` Sasha Finkelstein
2026-10-01 20:26 ` [PATCH v10 4/6] spmi: apple: Implement remaining commands Sasha Finkelstein
` (2 subsequent siblings)
5 siblings, 0 replies; 11+ messages in thread
From: Sasha Finkelstein @ 2026-10-01 20:26 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Alba Mendez
From: Alba Mendez <me@alba.sh>
Check for parity errors and missing command ACKs.
Signed-off-by: Alba Mendez <me@alba.sh>
Reviewed-by: Janne Grunau <j@jannau.net>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
drivers/spmi/spmi-apple-controller.c | 25 ++++++++++++++++++++-----
1 file changed, 20 insertions(+), 5 deletions(-)
diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
index 15721cb41d5c..b1c127cf5f44 100644
--- a/drivers/spmi/spmi-apple-controller.c
+++ b/drivers/spmi/spmi-apple-controller.c
@@ -11,6 +11,8 @@
* spmi-pmic-arb.c Copyright (c) 2021, The Linux Foundation.
*/
+#include <linux/bitfield.h>
+#include <linux/bits.h>
#include <linux/io.h>
#include <linux/iopoll.h>
#include <linux/module.h>
@@ -23,6 +25,12 @@
#define SPMI_RSP_REG 0x8
#define SPMI_ACT_REG 0xa4
+/* SPMI_RSP_REG reply word */
+#define SPMI_REPLY_FRAME_PARITY_STATUS GENMASK(31, 16)
+#define SPMI_REPLY_ACK BIT(15)
+#define SPMI_REPLY_SLAVE_ID GENMASK(14, 8)
+#define SPMI_REPLY_CMD GENMASK(7, 0)
+
#define SPMI_ACT_FIFO_FLUSH BIT(0)
#define SPMI_RX_FIFO_EMPTY BIT(24)
@@ -66,7 +74,7 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
{
struct apple_spmi *spmi = spmi_controller_get_drvdata(ctrl);
u32 spmi_cmd = apple_spmi_pack_cmd(opc, sid, saddr, len);
- u32 rsp;
+ u32 reply, rsp;
size_t len_read = 0;
u8 i;
int ret;
@@ -82,8 +90,7 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
if (ret)
return ret;
- /* Discard SPMI reply status */
- readl(spmi->regs + SPMI_RSP_REG);
+ reply = readl(spmi->regs + SPMI_RSP_REG);
/* Read SPMI data reply */
while (len_read < len) {
@@ -106,6 +113,10 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
spmi->prev_fail = true;
}
+ if (~FIELD_GET(SPMI_REPLY_FRAME_PARITY_STATUS, reply) & ((1 << len) - 1)) {
+ dev_err(&ctrl->dev, "some frames failed parity check\n");
+ return -EIO;
+ }
return 0;
}
@@ -114,6 +125,7 @@ static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
{
struct apple_spmi *spmi = spmi_controller_get_drvdata(ctrl);
u32 spmi_cmd = apple_spmi_pack_cmd(opc, sid, saddr, len);
+ u32 reply;
size_t i = 0, j;
int ret;
@@ -137,14 +149,17 @@ static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
if (ret)
return ret;
- /* Discard */
- readl(spmi->regs + SPMI_RSP_REG);
+ reply = readl(spmi->regs + SPMI_RSP_REG);
if (!(readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)) {
dev_warn(&ctrl->dev, "FIFO has extra data\n");
spmi->prev_fail = true;
}
+ if (!FIELD_GET(SPMI_REPLY_ACK, reply)) {
+ dev_err(&ctrl->dev, "command not acknowledged\n");
+ return -EIO;
+ }
return 0;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v10 4/6] spmi: apple: Implement remaining commands
2026-10-01 20:26 [PATCH v10 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
` (2 preceding siblings ...)
2026-10-01 20:26 ` [PATCH v10 3/6] spmi: apple: check transaction status Sasha Finkelstein
@ 2026-10-01 20:26 ` Sasha Finkelstein
2026-10-02 9:13 ` sashiko-bot
2026-10-01 20:27 ` [PATCH v10 5/6] spmi: apple: lock around FIFOs Sasha Finkelstein
2026-10-01 20:27 ` [PATCH v10 6/6] spmi: apple: Add interrupt functionality Sasha Finkelstein
5 siblings, 1 reply; 11+ messages in thread
From: Sasha Finkelstein @ 2026-10-01 20:26 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Alba Mendez
From: Alba Mendez <me@alba.sh>
Add support for zero write and power management commands.
Signed-off-by: Alba Mendez <me@alba.sh>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
drivers/spmi/spmi-apple-controller.c | 116 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-----------------------------------------------
1 file changed, 69 insertions(+), 47 deletions(-)
diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
index b1c127cf5f44..9843dc871d6c 100644
--- a/drivers/spmi/spmi-apple-controller.c
+++ b/drivers/spmi/spmi-apple-controller.c
@@ -46,9 +46,9 @@ struct apple_spmi {
readl_poll_timeout((spmi)->regs + (reg), (val), (cond), \
REG_POLL_INTERVAL_US, REG_POLL_TIMEOUT_US)
-static inline u32 apple_spmi_pack_cmd(u8 opc, u8 sid, u16 saddr, size_t len)
+static inline u32 apple_spmi_pack_cmd(u8 opc, u8 sid, u16 param)
{
- return opc | sid << 8 | saddr << 16 | (len - 1) | (1 << 15);
+ return opc | sid << 8 | (u32)param << 16 | (1 << 15);
}
/* Wait for Rx FIFO to have something */
@@ -69,14 +69,13 @@ static int apple_spmi_wait_rx_not_empty(struct spmi_controller *ctrl)
return 0;
}
-static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
- u16 saddr, u8 *buf, size_t len)
+static int spmi_raw_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid, u16 param,
+ const u8 *buf_wr, size_t len_wr, u8 *buf_rd, size_t len_rd)
{
struct apple_spmi *spmi = spmi_controller_get_drvdata(ctrl);
- u32 spmi_cmd = apple_spmi_pack_cmd(opc, sid, saddr, len);
+ u32 spmi_cmd = apple_spmi_pack_cmd(opc, sid, param);
u32 reply, rsp;
- size_t len_read = 0;
- u8 i;
+ size_t i = 0, j;
int ret;
if (spmi->prev_fail) {
@@ -86,6 +85,14 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
+ while (i < len_wr) {
+ j = min_t(size_t, sizeof(spmi_cmd), len_wr - i);
+ spmi_cmd = 0;
+ memcpy(&spmi_cmd, buf_wr + i, j);
+ writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
+ i += j;
+ }
+
ret = apple_spmi_wait_rx_not_empty(ctrl);
if (ret)
return ret;
@@ -93,7 +100,8 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
reply = readl(spmi->regs + SPMI_RSP_REG);
/* Read SPMI data reply */
- while (len_read < len) {
+ i = 0;
+ while (i < len_rd) {
if (readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY) {
spmi->prev_fail = true;
dev_err_ratelimited(&ctrl->dev,
@@ -101,11 +109,9 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
return -EIO;
}
rsp = readl(spmi->regs + SPMI_RSP_REG);
- i = 0;
- while ((len_read < len) && (i < 4)) {
- buf[len_read++] = ((0xff << (8 * i)) & rsp) >> (8 * i);
- i += 1;
- }
+ j = min_t(size_t, sizeof(spmi_cmd), len_rd - i);
+ memcpy(buf_rd + i, &rsp, j);
+ i += j;
}
if (!(readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)) {
@@ -113,54 +119,69 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
spmi->prev_fail = true;
}
- if (~FIELD_GET(SPMI_REPLY_FRAME_PARITY_STATUS, reply) & ((1 << len) - 1)) {
+ if (!len_rd && !FIELD_GET(SPMI_REPLY_ACK, reply)) {
+ dev_err(&ctrl->dev, "command not acknowledged\n");
+ return -EIO;
+ }
+ if (~FIELD_GET(SPMI_REPLY_FRAME_PARITY_STATUS, reply) & ((1 << len_rd) - 1)) {
dev_err(&ctrl->dev, "some frames failed parity check\n");
return -EIO;
}
return 0;
}
-static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
- u16 saddr, const u8 *buf, size_t len)
+/* Send a raw command with 1..16 input data frames */
+static int spmi_raw_cmd_input(struct spmi_controller *ctrl, u8 opc, u8 sid,
+ u16 param, u8 *buf, size_t len)
{
- struct apple_spmi *spmi = spmi_controller_get_drvdata(ctrl);
- u32 spmi_cmd = apple_spmi_pack_cmd(opc, sid, saddr, len);
- u32 reply;
- size_t i = 0, j;
- int ret;
-
- if (spmi->prev_fail) {
- writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
- spmi->prev_fail = false;
- }
-
- writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
+ return spmi_raw_cmd(ctrl, opc, sid, param, NULL, 0, buf, len);
+}
- while (i < len) {
- j = 0;
- spmi_cmd = 0;
- while ((j < 4) & (i < len))
- spmi_cmd |= buf[i++] << (j++ * 8);
+/* Send a raw command with (optional) body and an input ACK */
+static int spmi_raw_cmd_ack(struct spmi_controller *ctrl, u8 opc, u8 sid,
+ u16 param, const u8 *buf, size_t len)
+{
+ return spmi_raw_cmd(ctrl, opc, sid, param, buf, len, NULL, 0);
+}
- writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
+static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
+ u16 saddr, u8 *buf, size_t len)
+{
+ switch (opc) {
+ case SPMI_CMD_EXT_READ:
+ case SPMI_CMD_EXT_READL:
+ return spmi_raw_cmd_input(ctrl, opc | (len - 1), sid, saddr, buf, len);
+ case SPMI_CMD_READ:
+ return spmi_raw_cmd_input(ctrl, opc | saddr, sid, saddr, buf, len);
}
+ return -EINVAL;
+}
- ret = apple_spmi_wait_rx_not_empty(ctrl);
- if (ret)
- return ret;
-
- reply = readl(spmi->regs + SPMI_RSP_REG);
-
- if (!(readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)) {
- dev_warn(&ctrl->dev, "FIFO has extra data\n");
- spmi->prev_fail = true;
+static int spmi_write_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
+ u16 saddr, const u8 *buf, size_t len)
+{
+ switch (opc) {
+ case SPMI_CMD_WRITE:
+ return spmi_raw_cmd_ack(ctrl, opc | saddr, sid, buf[0] << 8 | saddr, NULL, 0);
+ case SPMI_CMD_ZERO_WRITE:
+ return spmi_raw_cmd_ack(ctrl, opc | buf[0], sid, buf[0] << 8 | saddr, NULL, 0);
+ case SPMI_CMD_EXT_WRITE:
+ case SPMI_CMD_EXT_WRITEL:
+ return spmi_raw_cmd_ack(ctrl, opc | (len - 1), sid, saddr, buf, len);
}
+ return -EINVAL;
+}
- if (!FIELD_GET(SPMI_REPLY_ACK, reply)) {
- dev_err(&ctrl->dev, "command not acknowledged\n");
- return -EIO;
+static int spmi_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid)
+{
+ switch (opc) {
+ case SPMI_CMD_RESET:
+ case SPMI_CMD_SLEEP:
+ case SPMI_CMD_SHUTDOWN:
+ case SPMI_CMD_WAKEUP:
+ return spmi_raw_cmd_ack(ctrl, opc, sid, 0, NULL, 0);
}
- return 0;
+ return -EINVAL;
}
static int apple_spmi_probe(struct platform_device *pdev)
@@ -183,6 +204,7 @@ static int apple_spmi_probe(struct platform_device *pdev)
ctrl->read_cmd = spmi_read_cmd;
ctrl->write_cmd = spmi_write_cmd;
+ ctrl->cmd = spmi_cmd;
ret = devm_spmi_controller_add(&pdev->dev, ctrl);
if (ret)
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v10 5/6] spmi: apple: lock around FIFOs
2026-10-01 20:26 [PATCH v10 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
` (3 preceding siblings ...)
2026-10-01 20:26 ` [PATCH v10 4/6] spmi: apple: Implement remaining commands Sasha Finkelstein
@ 2026-10-01 20:27 ` Sasha Finkelstein
2026-10-02 9:13 ` sashiko-bot
2026-10-01 20:27 ` [PATCH v10 6/6] spmi: apple: Add interrupt functionality Sasha Finkelstein
5 siblings, 1 reply; 11+ messages in thread
From: Sasha Finkelstein @ 2026-10-01 20:27 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Alba Mendez
From: Alba Mendez <me@alba.sh>
The driver was missing locking around register interactions.
Signed-off-by: Alba Mendez <me@alba.sh>
Reviewed-by: Janne Grunau <j@jannau.net>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
drivers/spmi/spmi-apple-controller.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
index 9843dc871d6c..fabccd25aa0d 100644
--- a/drivers/spmi/spmi-apple-controller.c
+++ b/drivers/spmi/spmi-apple-controller.c
@@ -16,6 +16,7 @@
#include <linux/io.h>
#include <linux/iopoll.h>
#include <linux/module.h>
+#include <linux/mutex.h>
#include <linux/platform_device.h>
#include <linux/spmi.h>
@@ -39,6 +40,7 @@
struct apple_spmi {
void __iomem *regs;
+ struct mutex fifo_lock;
bool prev_fail;
};
@@ -78,6 +80,8 @@ static int spmi_raw_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid, u16 param,
size_t i = 0, j;
int ret;
+ guard(mutex)(&spmi->fifo_lock);
+
if (spmi->prev_fail) {
writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
spmi->prev_fail = false;
@@ -195,6 +199,7 @@ static int apple_spmi_probe(struct platform_device *pdev)
return -ENOMEM;
spmi = spmi_controller_get_drvdata(ctrl);
+ mutex_init(&spmi->fifo_lock);
spmi->regs = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(spmi->regs))
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH v10 6/6] spmi: apple: Add interrupt functionality
2026-10-01 20:26 [PATCH v10 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
` (4 preceding siblings ...)
2026-10-01 20:27 ` [PATCH v10 5/6] spmi: apple: lock around FIFOs Sasha Finkelstein
@ 2026-10-01 20:27 ` Sasha Finkelstein
2026-10-02 9:13 ` sashiko-bot
5 siblings, 1 reply; 11+ messages in thread
From: Sasha Finkelstein @ 2026-10-01 20:27 UTC (permalink / raw)
To: Sven Peter, Janne Grunau, Neal Gompa, Stephen Boyd, Rob Herring,
Krzysztof Kozlowski, Conor Dooley
Cc: asahi, linux-arm-kernel, linux-kernel, devicetree,
Sasha Finkelstein, Alba Mendez
From: Alba Mendez <me@alba.sh>
Add support for interrupts sent by slave devices and use IRQ for
RX FIFO if possible, as that IRQ fires as soon as the reply is
available, which is usually takes a few us instead of the 10ms sleep
interval for polling.
Signed-off-by: Alba Mendez <me@alba.sh>
Reviewed-by: Janne Grunau <j@jannau.net>
Signed-off-by: Sasha Finkelstein <k@chaosmail.tech>
---
drivers/spmi/Kconfig | 3 +-
drivers/spmi/spmi-apple-controller.c | 257 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-
2 files changed, 258 insertions(+), 2 deletions(-)
diff --git a/drivers/spmi/Kconfig b/drivers/spmi/Kconfig
index a80cf4047b86..7243863a09b4 100644
--- a/drivers/spmi/Kconfig
+++ b/drivers/spmi/Kconfig
@@ -13,7 +13,8 @@ if SPMI
config SPMI_APPLE
tristate "Apple SoC SPMI Controller platform driver"
- depends on ARCH_APPLE || COMPILE_TEST
+ select IRQ_DOMAIN_HIERARCHY
+ depends on ARCH_APPLE || (COMPILE_TEST && 64BIT)
help
If you say yes to this option, support will be included for the
SPMI controller present on many Apple SoCs, including the
diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
index fabccd25aa0d..2390174452ab 100644
--- a/drivers/spmi/spmi-apple-controller.c
+++ b/drivers/spmi/spmi-apple-controller.c
@@ -13,11 +13,17 @@
#include <linux/bitfield.h>
#include <linux/bits.h>
+#include <linux/completion.h>
+#include <linux/interrupt.h>
#include <linux/io.h>
#include <linux/iopoll.h>
+#include <linux/irq.h>
+#include <linux/irqchip/chained_irq.h>
+#include <linux/irqdomain.h>
#include <linux/module.h>
#include <linux/mutex.h>
#include <linux/platform_device.h>
+#include <linux/spinlock.h>
#include <linux/spmi.h>
/* SPMI Controller Registers */
@@ -26,6 +32,13 @@
#define SPMI_RSP_REG 0x8
#define SPMI_ACT_REG 0xa4
+#define SPMI_IRQ_MASK_BASE 0x20
+#define SPMI_IRQ_ACK_BASE 0x60
+#define SPMI_NUM_PERIPHERAL_IRQS 256
+#define SPMI_NUM_IRQS (SPMI_NUM_PERIPHERAL_IRQS + 32)
+
+#define SPMI_IRQ_NOTIFY 256
+
/* SPMI_RSP_REG reply word */
#define SPMI_REPLY_FRAME_PARITY_STATUS GENMASK(31, 16)
#define SPMI_REPLY_ACK BIT(15)
@@ -41,6 +54,12 @@
struct apple_spmi {
void __iomem *regs;
struct mutex fifo_lock;
+ struct completion fifo_rx;
+ struct irq_domain *irqd;
+ raw_spinlock_t irq_mask_lock;
+ DECLARE_BITMAP(irq_mask_cache, SPMI_NUM_PERIPHERAL_IRQS);
+ int irq;
+ bool notify_irq;
bool prev_fail;
};
@@ -48,6 +67,56 @@ struct apple_spmi {
readl_poll_timeout((spmi)->regs + (reg), (val), (cond), \
REG_POLL_INTERVAL_US, REG_POLL_TIMEOUT_US)
+static void apple_spmi_irq_ack_raw(struct apple_spmi *spmi, u32 irq)
+{
+ u32 __iomem *reg = spmi->regs + SPMI_IRQ_ACK_BASE + (irq / 32) * 4;
+
+ writel(BIT(irq % 32), reg);
+}
+
+static void apple_spmi_irq_mask_raw(struct apple_spmi *spmi, u32 irq)
+{
+ u32 __iomem *reg = spmi->regs + SPMI_IRQ_MASK_BASE + (irq / 32) * 4;
+
+ writel(readl(reg) & ~BIT(irq % 32), reg);
+}
+
+static void apple_spmi_irq_unmask_raw(struct apple_spmi *spmi, u32 irq)
+{
+ u32 __iomem *reg = spmi->regs + SPMI_IRQ_MASK_BASE + (irq / 32) * 4;
+
+ writel(readl(reg) | BIT(irq % 32), reg);
+}
+
+static void apple_spmi_irq_ack(struct irq_data *d)
+{
+ struct apple_spmi *spmi = irq_data_get_irq_chip_data(d);
+
+ apple_spmi_irq_ack_raw(spmi, d->hwirq);
+}
+
+static void apple_spmi_irq_mask(struct irq_data *d)
+{
+ struct apple_spmi *spmi = irq_data_get_irq_chip_data(d);
+ unsigned long flags;
+
+ raw_spin_lock_irqsave(&spmi->irq_mask_lock, flags);
+ apple_spmi_irq_mask_raw(spmi, d->hwirq);
+ clear_bit(d->hwirq, spmi->irq_mask_cache);
+ raw_spin_unlock_irqrestore(&spmi->irq_mask_lock, flags);
+}
+
+static void apple_spmi_irq_unmask(struct irq_data *d)
+{
+ struct apple_spmi *spmi = irq_data_get_irq_chip_data(d);
+ unsigned long flags;
+
+ raw_spin_lock_irqsave(&spmi->irq_mask_lock, flags);
+ set_bit(d->hwirq, spmi->irq_mask_cache);
+ apple_spmi_irq_unmask_raw(spmi, d->hwirq);
+ raw_spin_unlock_irqrestore(&spmi->irq_mask_lock, flags);
+}
+
static inline u32 apple_spmi_pack_cmd(u8 opc, u8 sid, u16 param)
{
return opc | sid << 8 | (u32)param << 16 | (1 << 15);
@@ -60,7 +129,19 @@ static int apple_spmi_wait_rx_not_empty(struct spmi_controller *ctrl)
int ret;
u32 status;
- ret = poll_reg(spmi, SPMI_STATUS_REG, status, !(status & SPMI_RX_FIFO_EMPTY));
+ if (spmi->notify_irq) {
+ ret = wait_for_completion_timeout(&spmi->fifo_rx,
+ usecs_to_jiffies(REG_POLL_TIMEOUT_US));
+ if (!ret)
+ ret = -ETIMEDOUT;
+ else if (readl(spmi->regs + SPMI_STATUS_REG) & SPMI_RX_FIFO_EMPTY)
+ ret = -EIO;
+ else
+ ret = 0;
+ } else {
+ ret = poll_reg(spmi, SPMI_STATUS_REG, status, !(status & SPMI_RX_FIFO_EMPTY));
+ }
+
if (ret) {
spmi->prev_fail = true;
dev_err(&ctrl->dev,
@@ -84,8 +165,10 @@ static int spmi_raw_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid, u16 param,
if (spmi->prev_fail) {
writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
+ apple_spmi_irq_ack_raw(spmi, SPMI_IRQ_NOTIFY);
spmi->prev_fail = false;
}
+ reinit_completion(&spmi->fifo_rx);
writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
@@ -188,6 +271,167 @@ static int spmi_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid)
return -EINVAL;
}
+static int apple_spmi_irq_set_type(struct irq_data *d, unsigned int type)
+{
+ /* all interrupts have MSI semantics */
+ return type == IRQ_TYPE_EDGE_RISING ? 0 : -EINVAL;
+}
+
+static struct irq_chip apple_spmi_irq_chip = {
+ .name = "apple_spmi",
+ .irq_mask = apple_spmi_irq_mask,
+ .irq_unmask = apple_spmi_irq_unmask,
+ .irq_ack = apple_spmi_irq_ack,
+ .irq_set_type = apple_spmi_irq_set_type,
+ .flags = IRQCHIP_ONESHOT_SAFE,
+};
+
+static int apple_spmi_irq_domain_map(struct irq_domain *irqd,
+ unsigned int irq, irq_hw_number_t hw)
+{
+ irq_domain_set_info(irqd, irq, hw, &apple_spmi_irq_chip, irqd->host_data,
+ handle_edge_irq, NULL, NULL);
+ return 0;
+}
+
+static int apple_spmi_irq_domain_translate(struct irq_domain *irqd,
+ struct irq_fwspec *fwspec,
+ unsigned long *hwirq,
+ unsigned int *type)
+{
+ u32 *args = fwspec->param;
+
+ if (fwspec->param_count != 2)
+ return -EINVAL;
+
+ if (args[0] >= SPMI_NUM_PERIPHERAL_IRQS)
+ return -EINVAL;
+ *hwirq = args[0];
+ *type = args[1] & IRQ_TYPE_SENSE_MASK;
+ return 0;
+}
+
+static int apple_spmi_irq_domain_alloc(struct irq_domain *irqd, unsigned int virq,
+ unsigned int nr_irqs, void *arg)
+{
+ unsigned int type = IRQ_TYPE_NONE;
+ struct irq_fwspec *fwspec = arg;
+ irq_hw_number_t hwirq;
+ int i, ret;
+
+ ret = apple_spmi_irq_domain_translate(irqd, fwspec, &hwirq, &type);
+ if (ret)
+ return ret;
+
+ if (hwirq + nr_irqs > SPMI_NUM_PERIPHERAL_IRQS)
+ return -EINVAL;
+
+ for (i = 0; i < nr_irqs; i++) {
+ ret = apple_spmi_irq_domain_map(irqd, virq + i, hwirq + i);
+ if (ret)
+ return ret;
+ }
+
+ return 0;
+}
+
+static void apple_spmi_irq_domain_free(struct irq_domain *irqd, unsigned int virq,
+ unsigned int nr_irqs)
+{
+ int i;
+
+ for (i = 0; i < nr_irqs; i++) {
+ struct irq_data *d = irq_domain_get_irq_data(irqd, virq + i);
+
+ irq_set_handler(virq + i, NULL);
+ irq_domain_reset_irq_data(d);
+ }
+}
+
+static const struct irq_domain_ops apple_spmi_irq_domain_ops = {
+ .translate = apple_spmi_irq_domain_translate,
+ .alloc = apple_spmi_irq_domain_alloc,
+ .free = apple_spmi_irq_domain_free,
+};
+
+static void apple_spmi_irq_handler(struct irq_desc *desc)
+{
+ struct apple_spmi *spmi = irq_desc_get_handler_data(desc);
+ struct irq_chip *chip = irq_desc_get_chip(desc);
+ bool handled = false;
+ unsigned long val, offset, bit;
+
+ chained_irq_enter(chip, desc);
+ val = readl(spmi->regs + SPMI_IRQ_ACK_BASE + (SPMI_IRQ_NOTIFY / 32) * 4);
+ if (val & BIT(SPMI_IRQ_NOTIFY % 32)) {
+ apple_spmi_irq_ack_raw(spmi, SPMI_IRQ_NOTIFY);
+ complete(&spmi->fifo_rx);
+ handled = true;
+ }
+
+ for (offset = 0; offset < SPMI_NUM_PERIPHERAL_IRQS / 8; offset += sizeof(val)) {
+ val = readq(spmi->regs + SPMI_IRQ_ACK_BASE + offset);
+ /**
+ * because of other masters in the bus, we're going to get a multitude of
+ * interrupts we're not interested in. irq_resolve_mapping isn't very
+ * optimized for the nonexistent path, so instead we mask with (a locally
+ * cached version of) the IRQ mask
+ */
+ val &= spmi->irq_mask_cache[offset / sizeof(val)];
+ for_each_set_bit(bit, &val, 64) {
+ generic_handle_domain_irq(spmi->irqd, offset * 8 + bit);
+ handled = true;
+ }
+ }
+ if (!handled)
+ handle_bad_irq(desc);
+ chained_irq_exit(chip, desc);
+}
+
+static void apple_spmi_teardown_irq(void *data)
+{
+ struct apple_spmi *spmi = data;
+
+ for (size_t offset = 0; offset < SPMI_NUM_IRQS / 8; offset += 4)
+ writel(0, spmi->regs + SPMI_IRQ_MASK_BASE + offset);
+
+ synchronize_irq(spmi->irq);
+ irq_set_chained_handler_and_data(spmi->irq, NULL, NULL);
+}
+
+static int apple_spmi_init_irq(struct platform_device *pdev,
+ struct apple_spmi *spmi, int irq)
+{
+ int ret;
+ struct irq_domain_info info = {
+ .fwnode = pdev->dev.fwnode,
+ .hwirq_max = ~0U,
+ .ops = &apple_spmi_irq_domain_ops,
+ .host_data = spmi,
+ };
+
+ raw_spin_lock_init(&spmi->irq_mask_lock);
+
+ for (size_t offset = 0; offset < SPMI_NUM_IRQS / 8; offset += 4) {
+ writel(0, spmi->regs + SPMI_IRQ_MASK_BASE + offset);
+ writel(U32_MAX, spmi->regs + SPMI_IRQ_ACK_BASE + offset);
+ }
+
+ spmi->irqd = devm_irq_domain_instantiate(&pdev->dev, &info);
+ if (IS_ERR(spmi->irqd))
+ return PTR_ERR(spmi->irqd);
+
+ ret = devm_add_action(&pdev->dev, apple_spmi_teardown_irq, spmi);
+ if (ret)
+ return ret;
+
+ irq_set_chained_handler_and_data(spmi->irq, apple_spmi_irq_handler, spmi);
+ apple_spmi_irq_unmask_raw(spmi, SPMI_IRQ_NOTIFY);
+ spmi->notify_irq = true;
+
+ return 0;
+}
+
static int apple_spmi_probe(struct platform_device *pdev)
{
struct apple_spmi *spmi;
@@ -200,6 +444,8 @@ static int apple_spmi_probe(struct platform_device *pdev)
spmi = spmi_controller_get_drvdata(ctrl);
mutex_init(&spmi->fifo_lock);
+ init_completion(&spmi->fifo_rx);
+ platform_set_drvdata(pdev, spmi);
spmi->regs = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(spmi->regs))
@@ -211,6 +457,15 @@ static int apple_spmi_probe(struct platform_device *pdev)
ctrl->write_cmd = spmi_write_cmd;
ctrl->cmd = spmi_cmd;
+ spmi->irq = platform_get_irq_optional(pdev, 0);
+ if (spmi->irq < 0 && spmi->irq != -ENXIO)
+ return spmi->irq;
+ if (spmi->irq >= 0) {
+ ret = apple_spmi_init_irq(pdev, spmi, spmi->irq);
+ if (ret)
+ return ret;
+ }
+
ret = devm_spmi_controller_add(&pdev->dev, ctrl);
if (ret)
return dev_err_probe(&pdev->dev, ret,
--
2.55.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* Re: [PATCH v10 6/6] spmi: apple: Add interrupt functionality
2026-10-01 20:27 ` [PATCH v10 6/6] spmi: apple: Add interrupt functionality Sasha Finkelstein
@ 2026-10-02 9:13 ` sashiko-bot
0 siblings, 0 replies; 11+ messages in thread
From: sashiko-bot @ 2026-10-02 9:13 UTC (permalink / raw)
To: Sasha Finkelstein; +Cc: devicetree, robh, conor+dt
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] spmi: race condition in spmi_raw_cmd() error recovery causes premature completion
- [High] spmi: TOCTOU race on irq_mask_cache triggers spurious handle_bad_irq()
- [Medium] spmi: endianness corruption on Big-Endian architectures due to writel() for FIFO
--
commit 30246ba2a054ae67e63f97a3891036e8eeaf0cd4
Author: Alba Mendez <me@alba.sh>
spmi: apple: Add interrupt functionality
This commit adds support for interrupts sent by slave devices and uses the
IRQ for the RX FIFO if possible. This allows the driver to respond as soon
as the reply is available rather than polling with a 10ms sleep interval.
> diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
> index fabccd25aa0da..2390174452ab4 100644
> --- a/drivers/spmi/spmi-apple-controller.c
> +++ b/drivers/spmi/spmi-apple-controller.c
> @@ -26,6 +32,13 @@
[ ... ]
> +static void apple_spmi_irq_mask(struct irq_data *d)
> +{
> + struct apple_spmi *spmi = irq_data_get_irq_chip_data(d);
> + unsigned long flags;
> +
> + raw_spin_lock_irqsave(&spmi->irq_mask_lock, flags);
> + apple_spmi_irq_mask_raw(spmi, d->hwirq);
> + clear_bit(d->hwirq, spmi->irq_mask_cache);
> + raw_spin_unlock_irqrestore(&spmi->irq_mask_lock, flags);
> +}
[ ... ]
> static int spmi_raw_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid, u16 param,
> const u8 *buf_wr, size_t len_wr, u8 *buf_rd, size_t len_rd)
> {
[ ... ]
> if (spmi->prev_fail) {
> writel(SPMI_ACT_FIFO_FLUSH, spmi->regs + SPMI_ACT_REG);
> + apple_spmi_irq_ack_raw(spmi, SPMI_IRQ_NOTIFY);
> spmi->prev_fail = false;
> }
> + reinit_completion(&spmi->fifo_rx);
[Severity: High]
Does this reinit_completion() risk a race condition in spmi_raw_cmd()?
If a previous command timed out and the chained IRQ handler is concurrently
executing on another CPU, it could read the hardware status before it is
acked, but call complete() after this reinit_completion() runs. This would
spuriously mark the next command's wait as done, causing it to fail with
-EIO prematurely.
>
> writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
>
> while (i < len_wr) {
> j = min_t(size_t, sizeof(spmi_cmd), len_wr - i);
> spmi_cmd = 0;
> memcpy(&spmi_cmd, buf_wr + i, j);
> writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
[Severity: Medium]
Since this driver can be built on 64-bit Big-Endian architectures via
COMPILE_TEST && 64BIT, could using writel() here cause endianness
corruption? The writel() accessor performs byte-swapping which reverses the
memory layout of the stream in 4-byte chunks. Should this use writesl()
exclusively for FIFO stream accesses instead?
> i += j;
> }
[ ... ]
> /* Read SPMI data reply */
> i = 0;
> while (i < len_rd) {
[ ... ]
> rsp = readl(spmi->regs + SPMI_RSP_REG);
> j = min_t(size_t, sizeof(spmi_cmd), len_rd - i);
> memcpy(buf_rd + i, &rsp, j);
[Severity: Medium]
Similar to the write path above, does using readl() for the FIFO stream read
cause unintended byte-swapping on Big-Endian systems?
> i += j;
> }
[ ... ]
> +static void apple_spmi_irq_handler(struct irq_desc *desc)
> +{
[ ... ]
> + for (offset = 0; offset < SPMI_NUM_PERIPHERAL_IRQS / 8; offset += sizeof(val)) {
> + val = readq(spmi->regs + SPMI_IRQ_ACK_BASE + offset);
> + /**
> + * because of other masters in the bus, we're going to get a multitude of
> + * interrupts we're not interested in. irq_resolve_mapping isn't very
> + * optimized for the nonexistent path, so instead we mask with (a locally
> + * cached version of) the IRQ mask
> + */
> + val &= spmi->irq_mask_cache[offset / sizeof(val)];
> + for_each_set_bit(bit, &val, 64) {
> + generic_handle_domain_irq(spmi->irqd, offset * 8 + bit);
> + handled = true;
> + }
> + }
> + if (!handled)
> + handle_bad_irq(desc);
> + chained_irq_exit(chip, desc);
> +}
[Severity: High]
Could this lockless read of irq_mask_cache cause a Time-of-Check to
Time-of-Use race?
If a peripheral interrupt is pending in the hardware status val, but another
thread concurrently calls disable_irq(), it invokes apple_spmi_irq_mask()
which clears the bit in irq_mask_cache.
If irq_mask_cache is read right after the bit is cleared, the pending bit
will be masked out. The handler would then leave the legitimately fired
interrupt unacked, set handled = false, and incorrectly fall through to
handle_bad_irq() on the parent interrupt controller.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261001-t603x-spmi-v10-0-ff815c66c73f@chaosmail.tech?part=6
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH v10 5/6] spmi: apple: lock around FIFOs
2026-10-01 20:27 ` [PATCH v10 5/6] spmi: apple: lock around FIFOs Sasha Finkelstein
@ 2026-10-02 9:13 ` sashiko-bot
0 siblings, 0 replies; 11+ messages in thread
From: sashiko-bot @ 2026-10-02 9:13 UTC (permalink / raw)
To: Sasha Finkelstein; +Cc: conor+dt, devicetree, robh
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Medium] spmi: massive undocumented behavioral changes
- [Low] spmi: memcpy reverses payload byte order on BE hosts
--
commit f3fb1f6f3bd3cd5bdd607e9046ac360f8925a56a
Author: Alba Mendez <me@alba.sh>
spmi: apple: lock around FIFOs
This commit adds a mutex to the apple_spmi structure to serialize register
interactions. The new fifo_lock is initialized during probe and guards the
FIFO operations within spmi_raw_cmd().
> spmi: apple: lock around FIFOs
>
> The driver was missing locking around register interactions.
[Severity: Medium]
Does this patch bundle undocumented behavioral regressions?
The commit message claims to only add locking around register interactions,
but it appears to silently bundle major refactorings and logic changes.
For example, does it introduce new hardware ACK checking logic in
spmi_raw_cmd()?
drivers/spmi/spmi-apple-controller.c:spmi_raw_cmd() {
...
if (!len_rd && !FIELD_GET(SPMI_REPLY_ACK, reply)) {
...
}
}
Does it also alter how standard write commands are packed?
drivers/spmi/spmi-apple-controller.c:spmi_write_cmd() {
...
return spmi_raw_cmd_ack(ctrl, opc | saddr, sid,
buf[0] << 8 | saddr, NULL, 0);
}
And does it implement a new callback for sleep/wakeup/shutdown commands?
drivers/spmi/spmi-apple-controller.c:
static int spmi_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid)
{
...
}
Could the commit message be updated to describe these changes, or should they
be split into separate commits?
> diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
> index 9843dc871d6c7..fabccd25aa0da 100644
> --- a/drivers/spmi/spmi-apple-controller.c
> +++ b/drivers/spmi/spmi-apple-controller.c
[ ... ]
> @@ -78,6 +80,8 @@ static int spmi_raw_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid, u16 param,
> size_t i = 0, j;
> int ret;
>
> + guard(mutex)(&spmi->fifo_lock);
> +
[Severity: Low]
Does this code introduce a regression by reversing the payload byte order on
big-endian hosts?
In spmi_raw_cmd(), memcpy() is used to copy byte arrays into a host-endian
u32 variable, which is then written to the bus using writel():
drivers/spmi/spmi-apple-controller.c:spmi_raw_cmd() {
...
while (i < len_wr) {
j = min_t(size_t, sizeof(spmi_cmd), len_wr - i);
spmi_cmd = 0;
memcpy(&spmi_cmd, buf_wr + i, j);
writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
i += j;
}
...
}
On big-endian hosts, writel() will byte-swap this, resulting in the bytes
being written in reverse order compared to the original bitwise logic.
A similar reversal happens when reading the received payload:
drivers/spmi/spmi-apple-controller.c:spmi_raw_cmd() {
...
while (i < len_rd) {
...
rsp = readl(spmi->regs + SPMI_RSP_REG);
j = min_t(size_t, sizeof(spmi_cmd), len_rd - i);
memcpy(buf_rd + i, &rsp, j);
i += j;
}
...
}
While Apple SoCs are little-endian and this may have no visible effect in
practice, could this unconditional byte swapping manifest as a regression on
big-endian architectures under COMPILE_TEST?
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261001-t603x-spmi-v10-0-ff815c66c73f@chaosmail.tech?part=5
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH v10 4/6] spmi: apple: Implement remaining commands
2026-10-01 20:26 ` [PATCH v10 4/6] spmi: apple: Implement remaining commands Sasha Finkelstein
@ 2026-10-02 9:13 ` sashiko-bot
0 siblings, 0 replies; 11+ messages in thread
From: sashiko-bot @ 2026-10-02 9:13 UTC (permalink / raw)
To: Sasha Finkelstein; +Cc: conor+dt, devicetree, robh
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] spmi: apple: endianness regression via memcpy of IO registers
--
commit 5d4bbe94448e65d1ac0f0f10ab2dd3e91020bef4
Author: Alba Mendez <me@alba.sh>
spmi: apple: Implement remaining commands
This commit adds support for zero write and power management commands to
the Apple SPMI controller driver.
> diff --git a/drivers/spmi/spmi-apple-controller.c b/drivers/spmi/spmi-apple-controller.c
> index b1c127cf5f441..9843dc871d6c7 100644
> --- a/drivers/spmi/spmi-apple-controller.c
> +++ b/drivers/spmi/spmi-apple-controller.c
[ ... ]
> @@ -86,6 +85,14 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
>
> writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
>
> + while (i < len_wr) {
> + j = min_t(size_t, sizeof(spmi_cmd), len_wr - i);
> + spmi_cmd = 0;
> + memcpy(&spmi_cmd, buf_wr + i, j);
> + writel(spmi_cmd, spmi->regs + SPMI_CMD_REG);
[Severity: Medium]
Does this cause an endianness regression on Big Endian architectures?
Using memcpy() to copy a u8 array into a u32 variable before passing it
to writel() can reverse the byte order. On Big Endian hosts, the first
byte of the array is placed in the most significant byte of the u32 in
memory, which writel() will then implicitly swap to Little Endian for
the bus, effectively reversing the byte stream.
While Apple SoCs currently operate in Little Endian, does this break
driver endianness-cleanliness and architectural portability?
> + i += j;
> + }
> +
> ret = apple_spmi_wait_rx_not_empty(ctrl);
[ ... ]
> @@ -101,11 +109,9 @@ static int spmi_read_cmd(struct spmi_controller *ctrl, u8 opc, u8 sid,
> return -EIO;
> }
> rsp = readl(spmi->regs + SPMI_RSP_REG);
> - i = 0;
> - while ((len_read < len) && (i < 4)) {
> - buf[len_read++] = ((0xff << (8 * i)) & rsp) >> (8 * i);
> - i += 1;
> - }
> + j = min_t(size_t, sizeof(spmi_cmd), len_rd - i);
> + memcpy(buf_rd + i, &rsp, j);
[Severity: Medium]
Similarly, does destructuring the readl() return value via memcpy() misplace
the bytes on Big Endian hosts?
The original code used bitwise operations to safely pack and unpack the
u32 words byte-by-byte, which inherently abstracts away host endianness.
> + i += j;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261001-t603x-spmi-v10-0-ff815c66c73f@chaosmail.tech?part=4
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH v10 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122
2026-10-01 20:26 ` [PATCH v10 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122 Sasha Finkelstein
@ 2026-10-02 9:13 ` sashiko-bot
0 siblings, 0 replies; 11+ messages in thread
From: sashiko-bot @ 2026-10-02 9:13 UTC (permalink / raw)
To: Sasha Finkelstein; +Cc: robh, conor+dt, devicetree
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] dt-bindings: spmi: apple: missing power-domains in required list for non-always-on SoCs
--
commit 888cdba0f17c299db4b50bbf52f14fcb099ef7c9
Author: Sasha Finkelstein <k@chaosmail.tech>
dt-bindings: spmi: apple,spmi: Add t603x and t8122
This commit adds new t603x and t8122 compatibles to the apple,spmi bindings.
It also introduces optional interrupt properties and adds support for SPMI
controllers that are not always-on.
> diff --git a/Documentation/devicetree/bindings/spmi/apple,spmi.yaml b/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
> index 3e5b14bc8c317..4e73083ecec33 100644
> --- a/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
> +++ b/Documentation/devicetree/bindings/spmi/apple,spmi.yaml
[ ... ]
> @@ -34,10 +37,36 @@ properties:
> reg:
> maxItems: 1
>
> + interrupts:
> + maxItems: 1
> + description: Optional, operates in polled mode if not present
> +
> + interrupt-controller: true
> +
> + "#interrupt-cells":
> + const: 2
> +
> + power-domains:
> + maxItems: 1
> +
> required:
> - compatible
> - reg
>
> +if:
> + properties:
> + compatible:
> + contains:
> + enum:
> + - apple,t8122-spmi
> + - apple,t6030-spmi
> + - apple,t6031-spmi
> +then:
> + required:
> + - interrupt-controller
> + - "#interrupt-cells"
> + - interrupts
[Severity: Medium]
Should power-domains be included in this required list?
If a device tree for a non-always-on Apple SoC, such as t8122-spmi or
t6030-spmi, is authored without the power-domains property, the schema
validation will incorrectly accept it as valid due to the missing constraint
in this block.
At runtime, the kernel will fail to attach the power domain, resulting in a
fatal synchronous external abort and system panic when the driver accesses
unpowered registers.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261001-t603x-spmi-v10-0-ff815c66c73f@chaosmail.tech?part=1
^ permalink raw reply [flat|nested] 11+ messages in thread
end of thread, other threads:[~2026-10-02 9:13 UTC | newest]
Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-01 20:26 [PATCH v10 0/6] spmi: apple: Additional commands and interrupt support Sasha Finkelstein
2026-10-01 20:26 ` [PATCH v10 1/6] dt-bindings: spmi: apple,spmi: Add t603x and t8122 Sasha Finkelstein
2026-10-02 9:13 ` sashiko-bot
2026-10-01 20:26 ` [PATCH v10 2/6] spmi: apple: Validate FIFO state Sasha Finkelstein
2026-10-01 20:26 ` [PATCH v10 3/6] spmi: apple: check transaction status Sasha Finkelstein
2026-10-01 20:26 ` [PATCH v10 4/6] spmi: apple: Implement remaining commands Sasha Finkelstein
2026-10-02 9:13 ` sashiko-bot
2026-10-01 20:27 ` [PATCH v10 5/6] spmi: apple: lock around FIFOs Sasha Finkelstein
2026-10-02 9:13 ` sashiko-bot
2026-10-01 20:27 ` [PATCH v10 6/6] spmi: apple: Add interrupt functionality Sasha Finkelstein
2026-10-02 9:13 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox