* [PATCH 0/2] Add Altera timeout bridge driver
@ 2026-10-03 20:19 Vyacheslav Yurkov via B4 Relay
2026-10-03 20:19 ` [PATCH 1/2] dt-bindings: bus: Add binding for Altera AXI Timeout Bridge Vyacheslav Yurkov via B4 Relay
2026-10-03 20:19 ` [PATCH 2/2] bus: add Altera timeout bridge driver Vyacheslav Yurkov via B4 Relay
0 siblings, 2 replies; 10+ messages in thread
From: Vyacheslav Yurkov via B4 Relay @ 2026-10-03 20:19 UTC (permalink / raw)
To: Rob Herring, Krzysztof Kozlowski, Conor Dooley
Cc: devicetree, linux-kernel, Vyacheslav Yurkov, Vyacheslav Yurkov
This series adds support for the Altera timeout bridge IP.
The timeout bridge connects an Avalon bus to the HPS and provides a
downstream address space for devices implemented in the FPGA. The
bridge also exposes status information and generates an interrupt when
a timeout occurs.
The driver registers the timeout bridge as a bus and allows child
devices behind the bridge to be described as the child nodes in the
device tree.
The latest bridge documentation (as of October 2026):
https://docs.altera.com/r/docs/683609/26.1/quartus-prime-pro-edition-user-guide/axi-timeout-bridge-ip
Signed-off-by: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com>
---
Vyacheslav Yurkov (2):
dt-bindings: bus: Add binding for Altera AXI Timeout Bridge
bus: add Altera timeout bridge driver
.../bindings/bus/altera-timeout-bridge.yaml | 82 ++++++++
drivers/bus/Kconfig | 10 +
drivers/bus/Makefile | 1 +
drivers/bus/altera-timeout-bridge.c | 219 +++++++++++++++++++++
4 files changed, 312 insertions(+)
---
base-commit: a74306e2e676f9775457366fc047a660fbf02f26
change-id: 20261003-feature-timeout-ip-7a93630de299
Best regards,
--
Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com>
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH 1/2] dt-bindings: bus: Add binding for Altera AXI Timeout Bridge 2026-10-03 20:19 [PATCH 0/2] Add Altera timeout bridge driver Vyacheslav Yurkov via B4 Relay @ 2026-10-03 20:19 ` Vyacheslav Yurkov via B4 Relay 2026-10-03 20:26 ` sashiko-bot ` (2 more replies) 2026-10-03 20:19 ` [PATCH 2/2] bus: add Altera timeout bridge driver Vyacheslav Yurkov via B4 Relay 1 sibling, 3 replies; 10+ messages in thread From: Vyacheslav Yurkov via B4 Relay @ 2026-10-03 20:19 UTC (permalink / raw) To: Rob Herring, Krzysztof Kozlowski, Conor Dooley Cc: devicetree, linux-kernel, Vyacheslav Yurkov, Vyacheslav Yurkov From: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> Add a device tree binding for the Altera timeout bridge, which connects an Avalon bus to the HPS and provides an address space for child devices with a fall back to a simple bus. Signed-off-by: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> --- .../bindings/bus/altera-timeout-bridge.yaml | 82 ++++++++++++++++++++++ 1 file changed, 82 insertions(+) diff --git a/Documentation/devicetree/bindings/bus/altera-timeout-bridge.yaml b/Documentation/devicetree/bindings/bus/altera-timeout-bridge.yaml new file mode 100644 index 000000000000..b57a0966ba6e --- /dev/null +++ b/Documentation/devicetree/bindings/bus/altera-timeout-bridge.yaml @@ -0,0 +1,82 @@ +# SPDX-License-Identifier: GPL-2.0-only OR BSD-2-Clause +%YAML 1.2 +--- +$id: http://devicetree.org/schemas/bus/altera-timeout-bridge.yaml# +$schema: http://devicetree.org/meta-schemas/core.yaml# + +title: Altera Timeout Bridge + +maintainers: + - Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> + +description: | + Altera timeout bridge bus. + +properties: + compatible: + items: + - const: altera-timeout-bridge + - const: simple-bus + reg: + maxItems: 1 + + interrupts: + maxItems: 1 + + ranges: true + + "#address-cells": + const: 1 + + "#size-cells": + const: 1 + +required: + - compatible + - reg + - interrupts + - interrupt-parent + - ranges + - "#address-cells" + - "#size-cells" + +patternProperties: + "^[a-zA-Z][a-zA-Z0-9,+._-]*@[0-9a-f]+$": + type: object + description: | + Device connected to the timeout bridge. + + required: + - compatible + - reg + + additionalProperties: true + +additionalProperties: false + +examples: + - | + #include <dt-bindings/interrupt-controller/irq.h> + + intc: interrupt-controller { + interrupt-controller; + #interrupt-cells = <3>; + }; + + timeout_bridge_hps@10000 { + compatible = "altera-timeout-bridge", "simple-bus"; + #address-cells = <1>; + #size-cells = <1>; + + reg = <0x10000 0xF>; + + interrupts = <0 12 IRQ_TYPE_LEVEL_HIGH>; + interrupt-parent = <&intc>; + + ranges = <0x0 0x10010 0x1000>; + + timeout-device@100 { + compatible = "timeout-device"; + reg = <0x100 0x10>; + }; + }; -- 2.34.1 ^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [PATCH 1/2] dt-bindings: bus: Add binding for Altera AXI Timeout Bridge 2026-10-03 20:19 ` [PATCH 1/2] dt-bindings: bus: Add binding for Altera AXI Timeout Bridge Vyacheslav Yurkov via B4 Relay @ 2026-10-03 20:26 ` sashiko-bot 2026-10-03 21:18 ` Krzysztof Kozlowski 2026-10-05 13:30 ` Rob Herring (Arm) 2 siblings, 0 replies; 10+ messages in thread From: sashiko-bot @ 2026-10-03 20:26 UTC (permalink / raw) To: Vyacheslav Yurkov; +Cc: robh, conor+dt, devicetree Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider: - [Medium] dt-bindings: invalid compatible string format altera-timeout-bridge - [Medium] dt-bindings: erroneous required interrupt-parent breaks inheritance - [Low] dt-bindings: example node name uses underscores instead of hyphens - [Low] dt-bindings: unaligned 15-byte reg size in example -- commit 2cd126fb35ab7ef8e7fe6463a8fed9d0a99d2108 Author: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> dt-bindings: bus: Add binding for Altera AXI Timeout Bridge This commit adds a device tree binding for the Altera timeout bridge, which connects an Avalon bus to the HPS and provides an address space for child devices. > diff --git a/Documentation/devicetree/bindings/bus/altera-timeout-bridge.yaml b/Documentation/devicetree/bindings/bus/altera-timeout-bridge.yaml > new file mode 100644 > --- /dev/null > +++ b/Documentation/devicetree/bindings/bus/altera-timeout-bridge.yaml > @@ -0,0 +1,82 @@ > +# SPDX-License-Identifier: GPL-2.0-only OR BSD-2-Clause > +%YAML 1.2 > +--- > +$id: http://devicetree.org/schemas/bus/altera-timeout-bridge.yaml# [Severity: Medium] Does this $id field inherit an incorrectly formatted prefix and missing comma from the filename? The compatible string issues mentioned below seem to have propagated to both the filename and this path reference. [ ... ] > +properties: > + compatible: > + items: > + - const: altera-timeout-bridge [Severity: Medium] Does this compatible string violate the standard device tree specification that mandates the '<vendor>,<device>' format? The standard vendor prefix for Altera is 'altr', not 'altera', and the missing comma separator breaks standard pattern matching. [ ... ] > +required: > + - compatible > + - reg > + - interrupts > + - interrupt-parent [Severity: Medium] Should 'interrupt-parent' be explicitly required here? By explicitly listing it as a required property, the schema mandates that every instantiated node must define it. Does this violate standard Device Tree structural inheritance, where interrupt routing is inherited from parent nodes? [ ... ] > +examples: > + - | > + #include <dt-bindings/interrupt-controller/irq.h> > + > + intc: interrupt-controller { > + interrupt-controller; > + #interrupt-cells = <3>; > + }; > + > + timeout_bridge_hps@10000 { [Severity: Low] This isn't a functional bug, but the example node name uses underscores instead of hyphens. Could this trigger dtc W=1 warnings by violating standard Device Tree naming conventions? > + compatible = "altera-timeout-bridge", "simple-bus"; > + #address-cells = <1>; > + #size-cells = <1>; > + > + reg = <0x10000 0xF>; [Severity: Low] Is this 15-byte window size intentional? MMIO regions are universally aligned to word (4-byte) boundaries, meaning a 15-byte window truncates the final 32-bit register space (ending at 15 instead of 16). Could this be a typo for 0x10? -- Sashiko AI review · https://sashiko.dev/#/patchset/20261003-feature-timeout-ip-v1-0-8837c311d571@bruker.com?part=1 ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH 1/2] dt-bindings: bus: Add binding for Altera AXI Timeout Bridge 2026-10-03 20:19 ` [PATCH 1/2] dt-bindings: bus: Add binding for Altera AXI Timeout Bridge Vyacheslav Yurkov via B4 Relay 2026-10-03 20:26 ` sashiko-bot @ 2026-10-03 21:18 ` Krzysztof Kozlowski 2026-10-05 13:30 ` Rob Herring (Arm) 2 siblings, 0 replies; 10+ messages in thread From: Krzysztof Kozlowski @ 2026-10-03 21:18 UTC (permalink / raw) To: V.Yurkov.EXT, Rob Herring, Krzysztof Kozlowski, Conor Dooley Cc: devicetree, linux-kernel, Vyacheslav Yurkov On 03/10/2026 22:19, Vyacheslav Yurkov via B4 Relay wrote: > From: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> > > Add a device tree binding for the Altera timeout bridge, which connects > an Avalon bus to the HPS and provides an address space for child > devices with a fall back to a simple bus. > > Signed-off-by: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> > --- > .../bindings/bus/altera-timeout-bridge.yaml | 82 ++++++++++++++++++++++ Filename must match compatible and compatible has completely broken format. Please look at DT spec or any other examples how compatibles are created. > 1 file changed, 82 insertions(+) > > diff --git a/Documentation/devicetree/bindings/bus/altera-timeout-bridge.yaml b/Documentation/devicetree/bindings/bus/altera-timeout-bridge.yaml > new file mode 100644 > index 000000000000..b57a0966ba6e > --- /dev/null > +++ b/Documentation/devicetree/bindings/bus/altera-timeout-bridge.yaml > @@ -0,0 +1,82 @@ > +# SPDX-License-Identifier: GPL-2.0-only OR BSD-2-Clause > +%YAML 1.2 > +--- > +$id: http://devicetree.org/schemas/bus/altera-timeout-bridge.yaml# > +$schema: http://devicetree.org/meta-schemas/core.yaml# > + > +title: Altera Timeout Bridge > + > +maintainers: > + - Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> > + > +description: | > + Altera timeout bridge bus. Useless description. You keep repeating the same. > + > +properties: > + compatible: > + items: > + - const: altera-timeout-bridge > + - const: simple-bus Why the fallback? Your commit msg is also useless here, you just wrote what you did, not why. I see no reason why generic "bus" like that should stay generic, although you have entire commit msg to explain why this is different or what is the versioning of this IP block. Missing blank line. > + reg: > + maxItems: 1 > + > + interrupts: > + maxItems: 1 > + > + ranges: true > + > + "#address-cells": > + const: 1 > + > + "#size-cells": > + const: 1 > + > +required: > + - compatible > + - reg > + - interrupts > + - interrupt-parent > + - ranges > + - "#address-cells" > + - "#size-cells" > + > +patternProperties: This follows properties. > + "^[a-zA-Z][a-zA-Z0-9,+._-]*@[0-9a-f]+$": > + type: object > + description: | > + Device connected to the timeout bridge. > + > + required: > + - compatible > + - reg > + > + additionalProperties: true > + > +additionalProperties: false > + > +examples: > + - | > + #include <dt-bindings/interrupt-controller/irq.h> > + > + intc: interrupt-controller { > + interrupt-controller; > + #interrupt-cells = <3>; > + }; Drop, irrelevant > + > + timeout_bridge_hps@10000 { Really, this is the style you send? So the toolset - dt-check-style - or the Coding style mean nothing and you keep sending what you have in downstream. Best regards, Krzysztof ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH 1/2] dt-bindings: bus: Add binding for Altera AXI Timeout Bridge 2026-10-03 20:19 ` [PATCH 1/2] dt-bindings: bus: Add binding for Altera AXI Timeout Bridge Vyacheslav Yurkov via B4 Relay 2026-10-03 20:26 ` sashiko-bot 2026-10-03 21:18 ` Krzysztof Kozlowski @ 2026-10-05 13:30 ` Rob Herring (Arm) 2 siblings, 0 replies; 10+ messages in thread From: Rob Herring (Arm) @ 2026-10-05 13:30 UTC (permalink / raw) To: Vyacheslav Yurkov Cc: Vyacheslav Yurkov, linux-kernel, devicetree, Conor Dooley, Krzysztof Kozlowski On Sat, 03 Oct 2026 20:19:19 +0000, Vyacheslav Yurkov wrote: > Add a device tree binding for the Altera timeout bridge, which connects > an Avalon bus to the HPS and provides an address space for child > devices with a fall back to a simple bus. > > Signed-off-by: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> > --- > .../bindings/bus/altera-timeout-bridge.yaml | 82 ++++++++++++++++++++++ > 1 file changed, 82 insertions(+) > My bot found errors running 'make dt_binding_check' on your patch: yamllint warnings/errors: dtschema/dtc warnings/errors: Documentation/devicetree/bindings/bus/altera-timeout-bridge.example.dtb: /example-0/timeout_bridge_hps@10000/timeout-device@100: failed to match any schema with compatible: ['timeout-device'] doc reference errors (make refcheckdocs): See https://patchwork.kernel.org/project/devicetree/patch/20261003-feature-timeout-ip-v1-1-8837c311d571@bruker.com The base for the series is generally the latest rc1. A different dependency should be noted in *this* patch. If you already ran 'make dt_binding_check' and didn't see the above error(s), then make sure 'yamllint' is installed and dt-schema is up to date: pip3 install dtschema --upgrade Please check and re-submit after running the above command yourself. Note that DT_SCHEMA_FILES can be set to your schema file to speed up checking your schema. However, it must be unset to test all examples with your schema. ^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH 2/2] bus: add Altera timeout bridge driver 2026-10-03 20:19 [PATCH 0/2] Add Altera timeout bridge driver Vyacheslav Yurkov via B4 Relay 2026-10-03 20:19 ` [PATCH 1/2] dt-bindings: bus: Add binding for Altera AXI Timeout Bridge Vyacheslav Yurkov via B4 Relay @ 2026-10-03 20:19 ` Vyacheslav Yurkov via B4 Relay 2026-10-03 20:29 ` sashiko-bot ` (3 more replies) 1 sibling, 4 replies; 10+ messages in thread From: Vyacheslav Yurkov via B4 Relay @ 2026-10-03 20:19 UTC (permalink / raw) To: Rob Herring, Krzysztof Kozlowski, Conor Dooley Cc: devicetree, linux-kernel, Vyacheslav Yurkov, Vyacheslav Yurkov From: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> Add support for the Altera timeout bridge IP. The bridge connects an Avalon bus to the HPS and monitors accesses for timeouts. When a timeout occurs the interrupt communicates the event via sysfs, which user space can monitor to handle it accordingly. The address with the timeout is reported as well. Signed-off-by: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> --- drivers/bus/Kconfig | 10 ++ drivers/bus/Makefile | 1 + drivers/bus/altera-timeout-bridge.c | 219 ++++++++++++++++++++++++++++++++++++ 3 files changed, 230 insertions(+) diff --git a/drivers/bus/Kconfig b/drivers/bus/Kconfig index e4b1db809187..8a4ad96742e5 100644 --- a/drivers/bus/Kconfig +++ b/drivers/bus/Kconfig @@ -247,6 +247,16 @@ config DA8XX_MSTPRI configuration. Allows to adjust the priorities of all master peripherals. +config ALTERA_TIMEOUT_BRIDGE + tristate "Altera AXI Timeout Bridge bus" + depends on OF + default n + help + Driver for Altera AXI Timeout Bridge, which can be used a bus. + The subordinate devices can be connected to the bridge, which + detects frozen read/write requests and notifies user space by + means of a sysfs interrupt flag. + source "drivers/bus/fsl-mc/Kconfig" source "drivers/bus/mhi/Kconfig" diff --git a/drivers/bus/Makefile b/drivers/bus/Makefile index a01f97fef3e8..ad4e6d7b1e49 100644 --- a/drivers/bus/Makefile +++ b/drivers/bus/Makefile @@ -39,6 +39,7 @@ obj-$(CONFIG_UNIPHIER_SYSTEM_BUS) += uniphier-system-bus.o obj-$(CONFIG_VEXPRESS_CONFIG) += vexpress-config.o obj-$(CONFIG_DA8XX_MSTPRI) += da8xx-mstpri.o +obj-$(CONFIG_ALTERA_TIMEOUT_BRIDGE) += altera-timeout-bridge.o # MHI obj-y += mhi/ diff --git a/drivers/bus/altera-timeout-bridge.c b/drivers/bus/altera-timeout-bridge.c new file mode 100644 index 000000000000..bb44ff4a7591 --- /dev/null +++ b/drivers/bus/altera-timeout-bridge.c @@ -0,0 +1,219 @@ +// SPDX-License-Identifier: GPL-2.0 +/* + * Altera Timeout Bridge Bus Driver + * + * Copyright (C) 2026 Bruker Corporation + */ + +#include <linux/interrupt.h> +#include <linux/module.h> +#include <linux/of.h> +#include <linux/of_device.h> +#include <linux/of_platform.h> +#include <linux/platform_device.h> + +#define ALTERA_TIMEOUT_BRIDGE_REG_TIMED_OUT_ADDRESS 0x08 +#define ALTERA_TIMEOUT_BRIDGE_REG_IRQ_STATUS_RESET 0x00 + +struct altera_timeout_bridge_data { + struct device *dev; + struct resource *bridge_register_resource; + void __iomem *bridge_registers; + atomic_t irq_count; + struct kernfs_node *irq_node; +}; + +static ssize_t timeout_irq_show(struct device *dev, struct device_attribute *attr, + char *buf) +{ + return 0; +} + +static ssize_t irq_count_show(struct device *dev, + struct device_attribute *attr, + char *buf) +{ + struct altera_timeout_bridge_data *driver_data = dev_get_drvdata(dev); + + return sysfs_emit(buf, "%d\n", atomic_read(&driver_data->irq_count)); +} + +static DEVICE_ATTR_RO(timeout_irq); +static DEVICE_ATTR_RO(irq_count); + +static struct attribute *altera_timeout_bridge_sysfs_attrs[] = { + &dev_attr_timeout_irq.attr, + &dev_attr_irq_count.attr, + NULL /* sentinel */ +}; + +static const struct attribute_group altera_timeout_bridge_sysfs_group = { + .attrs = altera_timeout_bridge_sysfs_attrs, +}; + +static u32 +bridge_reg_read(struct altera_timeout_bridge_data *driver_data, + u32 offset) +{ + u32 result; + + result = readl(driver_data->bridge_registers + offset); + + return result; +} + +static void bridge_reg_write( + struct altera_timeout_bridge_data *driver_data, + int offset, u32 value) +{ + writel(value, driver_data->bridge_registers + offset); +} + +static irqreturn_t altera_timeout_bridge_isr(int irq, void *data) +{ + struct altera_timeout_bridge_data *driver_data = data; + u32 timed_out_address; + resource_size_t effective_base_address; + resource_size_t effective_timed_out_address; + + atomic_inc(&driver_data->irq_count); + + // Read and print the timed-out address (encoded in the lower nibble + // 0x8..0xF according to AXI Timeout Bridge IP (CSR Interrupt Status Information) + timed_out_address = bridge_reg_read( + driver_data, + ALTERA_TIMEOUT_BRIDGE_REG_TIMED_OUT_ADDRESS); + effective_base_address = driver_data->bridge_register_resource->start; + effective_timed_out_address = effective_base_address + timed_out_address; + pr_err("%s: timeout at address 0x%llx\n", + __func__, (unsigned long long)effective_timed_out_address); + + // Reset IRQ status in the bridge + bridge_reg_write( + driver_data, + ALTERA_TIMEOUT_BRIDGE_REG_IRQ_STATUS_RESET, + 0x1); + // notify the user space + sysfs_notify_dirent(driver_data->irq_node); + + return IRQ_HANDLED; +} +static int altera_timeout_bridge_probe(struct platform_device *pdev) +{ + struct device *dev = &pdev->dev; + const struct of_device_id *match; + const struct of_dev_auxdata *lookup = dev_get_platdata(dev); + struct device_node *np = dev->of_node; + struct altera_timeout_bridge_data *driver_data; + int ret = 0; + int irq = -1; + + /* + * Allow user to use driver_override to bind this driver to a + * transparent bus device which has a different compatible string + * that's not listed in simple_pm_bus_of_match. We don't want to do any + * of the simple-pm-bus tasks for these devices, so return early. + */ + if (device_has_driver_override(&pdev->dev)) + return 0; + + match = of_match_device(dev->driver->of_match_table, dev); + + /* Use a fall back logic like in simple-pm-bus */ + if (match && match->data) { + if (of_property_match_string(np, "compatible", match->compatible) == 0) + return 0; + else + return -ENODEV; + } + + driver_data = + devm_kzalloc(&pdev->dev, sizeof(*driver_data), GFP_KERNEL); + if (!driver_data) { + dev_err(&pdev->dev, + "%s: kzalloc failed: no memory for the driver's data, returning ENOMEM\n", + __func__); + return -ENOMEM; + } + + driver_data->dev = dev; + platform_set_drvdata(pdev, driver_data); + + driver_data->bridge_register_resource = + platform_get_resource(pdev, IORESOURCE_MEM, 0); + if (!driver_data->bridge_register_resource) { + dev_err(dev, + "%s: missing required reg binding\n", + __func__); + return -ENOENT; + } + driver_data->bridge_registers = + devm_ioremap_resource(dev, + driver_data->bridge_register_resource); + if (IS_ERR(driver_data->bridge_registers)) { + dev_err(dev, + "%s: ioremap_resource failed for bridge-status MMIO, returning PTR_ERR(%ld)\n", + __func__, PTR_ERR(driver_data->bridge_registers)); + return PTR_ERR(driver_data->bridge_registers); + } + + irq = platform_get_irq(pdev, 0); + if (irq < 0) { + dev_err(dev, + "%s: platform_get_irq failed: %d\n", __func__, irq); + return irq; + } + + ret = devm_request_irq(dev, irq, + altera_timeout_bridge_isr, + 0, + dev_name(dev), + driver_data); + if (ret) { + dev_err(dev, + "%s: devm_request_irq failed for IRQ %d: %d\n", + __func__, irq, ret); + return ret; + } + + ret = devm_device_add_group(dev, &altera_timeout_bridge_sysfs_group); + if (ret) + return ret; + + driver_data->irq_node = sysfs_get_dirent(dev->kobj.sd, "timeout_irq"); + if (!driver_data->irq_node) + return -ENOENT; + + ret = devm_add_action_or_reset(dev, (void (*)(void *))sysfs_put, driver_data->irq_node); + if (ret) + return ret; + + if (np) + of_platform_populate(np, NULL, lookup, &pdev->dev); + + return 0; +} + +#define ONLY_BUS ((void *) 1) /* Match if the device is only a bus. */ + +static const struct of_device_id altera_timeout_bridge_of_match[] = { + { .compatible = "altera-timeout-bridge", }, + { .compatible = "simple-bus", .data = ONLY_BUS }, + { /* sentinel */ } +}; +MODULE_DEVICE_TABLE(of, altera_timeout_bridge_of_match); + +static struct platform_driver altera_timeout_bridge_driver = { + .probe = altera_timeout_bridge_probe, + .driver = { + .name = "altera-timeout-bridge", + .of_match_table = altera_timeout_bridge_of_match, + }, +}; + +module_platform_driver(altera_timeout_bridge_driver); + +MODULE_LICENSE("GPL"); +MODULE_DESCRIPTION("Avalon Timeout Bridge Bus"); +MODULE_AUTHOR("Vyacheslav Yurkov (V.Yurkov.EXT@bruker.com)"); + -- 2.34.1 ^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [PATCH 2/2] bus: add Altera timeout bridge driver 2026-10-03 20:19 ` [PATCH 2/2] bus: add Altera timeout bridge driver Vyacheslav Yurkov via B4 Relay @ 2026-10-03 20:29 ` sashiko-bot 2026-10-03 21:24 ` Krzysztof Kozlowski ` (2 subsequent siblings) 3 siblings, 0 replies; 10+ messages in thread From: sashiko-bot @ 2026-10-03 20:29 UTC (permalink / raw) To: Vyacheslav Yurkov; +Cc: robh, devicetree, conor+dt Thank you for your contribution! Sashiko AI review found 7 potential issue(s) to consider: - [High] bus: UAF of irq_node during teardown or early interrupt - [High] bus: CFI violation in devres teardown due to mismatched function pointer cast - [High] bus: driver incorrectly claims simple-bus devices, breaking power management - [Medium] bus: bypassed hardware initialization when bound via driver_override - [Medium] bus: leaked child devices due to missing depopulation on driver remove - [Medium] bus: incorrectly adds physical base address to timeout address - [Medium] bus: un-rate-limited error logging in ISR causes kernel log flooding -- commit c74336cb2c00c16659c7f03c8c51687597e67ab5 Author: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> Subject: bus: add Altera timeout bridge driver Add support for the Altera timeout bridge IP. The bridge connects an Avalon bus to the HPS and monitors accesses for timeouts. When a timeout occurs the interrupt communicates the event via sysfs. > diff --git a/drivers/bus/altera-timeout-bridge.c b/drivers/bus/altera-timeout-bridge.c > new file mode 100644 > index 0000000000000..bb44ff4a75910 > --- /dev/null > +++ b/drivers/bus/altera-timeout-bridge.c > @@ -0,0 +1,219 @@ [ ... ] > +static irqreturn_t altera_timeout_bridge_isr(int irq, void *data) > +{ > + struct altera_timeout_bridge_data *driver_data = data; > + u32 timed_out_address; > + resource_size_t effective_base_address; > + resource_size_t effective_timed_out_address; > + > + atomic_inc(&driver_data->irq_count); > + > + // Read and print the timed-out address (encoded in the lower nibble > + // 0x8..0xF according to AXI Timeout Bridge IP (CSR Interrupt Status Information) > + timed_out_address = bridge_reg_read( > + driver_data, > + ALTERA_TIMEOUT_BRIDGE_REG_TIMED_OUT_ADDRESS); > + effective_base_address = driver_data->bridge_register_resource->start; > + effective_timed_out_address = effective_base_address + timed_out_address; [Severity: Medium] Does this calculation corrupt the actual timed-out AXI address by erroneously adding the driver's own register base? > + pr_err("%s: timeout at address 0x%llx\n", > + __func__, (unsigned long long)effective_timed_out_address); [Severity: Medium] Will this synchronous pr_err() statement flood the kernel log if the hardware triggers continuous faults? > + > + // Reset IRQ status in the bridge > + bridge_reg_write( > + driver_data, > + ALTERA_TIMEOUT_BRIDGE_REG_IRQ_STATUS_RESET, > + 0x1); > + // notify the user space > + sysfs_notify_dirent(driver_data->irq_node); [Severity: High] Can this sysfs_notify_dirent() dereference an uninitialized or freed irq_node? During probe, devm_request_irq() is called before driver_data->irq_node is initialized, leaving a window where early interrupts see a NULL pointer. Additionally, because the devres action to free irq_node is registered after the interrupt request, devres executes in LIFO order and frees irq_node before the interrupt is disabled during teardown. > + > + return IRQ_HANDLED; > +} > +static int altera_timeout_bridge_probe(struct platform_device *pdev) > +{ > + struct device *dev = &pdev->dev; > + const struct of_device_id *match; > + const struct of_dev_auxdata *lookup = dev_get_platdata(dev); > + struct device_node *np = dev->of_node; > + struct altera_timeout_bridge_data *driver_data; > + int ret = 0; > + int irq = -1; > + > + /* > + * Allow user to use driver_override to bind this driver to a > + * transparent bus device which has a different compatible string > + * that's not listed in simple_pm_bus_of_match. We don't want to do any > + * of the simple-pm-bus tasks for these devices, so return early. > + */ > + if (device_has_driver_override(&pdev->dev)) > + return 0; [Severity: Medium] Does this check incorrectly bypass the entire hardware initialization logic if a driver override is used? If a user explicitly binds the driver to a device via the driver_override sysfs attribute, the probe function immediately returns 0, skipping all memory allocations, register mappings, and interrupt requests. > + > + match = of_match_device(dev->driver->of_match_table, dev); > + > + /* Use a fall back logic like in simple-pm-bus */ > + if (match && match->data) { > + if (of_property_match_string(np, "compatible", match->compatible) == 0) > + return 0; [Severity: High] Does this cause the driver to incorrectly claim generic system buses and break power management? The driver's OF match table includes the generic "simple-bus" compatible string. Returning 0 here prevents the correct simple-pm-bus driver from binding to these buses, which is responsible for enabling their power domains and clocks, breaking all child devices on the bus. > + else > + return -ENODEV; > + } [ ... ] > + ret = devm_request_irq(dev, irq, > + altera_timeout_bridge_isr, > + 0, > + dev_name(dev), > + driver_data); > + if (ret) { > + dev_err(dev, > + "%s: devm_request_irq failed for IRQ %d: %d\n", > + __func__, irq, ret); > + return ret; > + } > + > + ret = devm_device_add_group(dev, &altera_timeout_bridge_sysfs_group); > + if (ret) > + return ret; > + > + driver_data->irq_node = sysfs_get_dirent(dev->kobj.sd, "timeout_irq"); > + if (!driver_data->irq_node) > + return -ENOENT; > + > + ret = devm_add_action_or_reset(dev, (void (*)(void *))sysfs_put, driver_data->irq_node); [Severity: High] Does this mismatched function pointer cast cause a Control-Flow Integrity (CFI) violation during devres teardown? The driver registers sysfs_put() with devm_add_action_or_reset() by casting it to (void (*)(void *)). The actual signature of sysfs_put() expects a struct kernfs_node *, not void *. When devres executes this action on module unload or probe failure, KCFI detects the signature mismatch and panics. > + if (ret) > + return ret; > + > + if (np) > + of_platform_populate(np, NULL, lookup, &pdev->dev); > + > + return 0; > +} [Severity: Medium] Are these child devices leaked when the driver is unbound? During probe, of_platform_populate() creates child platform devices. However, the platform driver lacks a .remove callback and does not use devm_of_platform_populate(). The child devices are never destroyed when the driver is unbound. -- Sashiko AI review · https://sashiko.dev/#/patchset/20261003-feature-timeout-ip-v1-0-8837c311d571@bruker.com?part=2 ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH 2/2] bus: add Altera timeout bridge driver 2026-10-03 20:19 ` [PATCH 2/2] bus: add Altera timeout bridge driver Vyacheslav Yurkov via B4 Relay 2026-10-03 20:29 ` sashiko-bot @ 2026-10-03 21:24 ` Krzysztof Kozlowski 2026-10-04 20:01 ` kernel test robot 2026-10-06 9:55 ` kernel test robot 3 siblings, 0 replies; 10+ messages in thread From: Krzysztof Kozlowski @ 2026-10-03 21:24 UTC (permalink / raw) To: V.Yurkov.EXT, Rob Herring, Krzysztof Kozlowski, Conor Dooley Cc: devicetree, linux-kernel, Vyacheslav Yurkov On 03/10/2026 22:19, Vyacheslav Yurkov via B4 Relay wrote: > From: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> > > Add support for the Altera timeout bridge IP. > > The bridge connects an Avalon bus to the HPS and monitors accesses for > timeouts. When a timeout occurs the interrupt communicates the event via > sysfs, which user space can monitor to handle it accordingly. The > address with the timeout is reported as well. > Neither this nor binding explains what is this hardware and where I can find it. > Signed-off-by: Vyacheslav Yurkov <V.Yurkov.EXT@bruker.com> > --- > drivers/bus/Kconfig | 10 ++ > drivers/bus/Makefile | 1 + > drivers/bus/altera-timeout-bridge.c | 219 ++++++++++++++++++++++++++++++++++++ > 3 files changed, 230 insertions(+) > > diff --git a/drivers/bus/Kconfig b/drivers/bus/Kconfig > index e4b1db809187..8a4ad96742e5 100644 > --- a/drivers/bus/Kconfig > +++ b/drivers/bus/Kconfig > @@ -247,6 +247,16 @@ config DA8XX_MSTPRI > configuration. Allows to adjust the priorities of all master > peripherals. > > +config ALTERA_TIMEOUT_BRIDGE > + tristate "Altera AXI Timeout Bridge bus" > + depends on OF > + default n > + help > + Driver for Altera AXI Timeout Bridge, which can be used a bus. > + The subordinate devices can be connected to the bridge, which > + detects frozen read/write requests and notifies user space by > + means of a sysfs interrupt flag. > + > +static ssize_t irq_count_show(struct device *dev, > + struct device_attribute *attr, > + char *buf) > +{ > + struct altera_timeout_bridge_data *driver_data = dev_get_drvdata(dev); > + > + return sysfs_emit(buf, "%d\n", atomic_read(&driver_data->irq_count)); > +} > + > +static DEVICE_ATTR_RO(timeout_irq); > +static DEVICE_ATTR_RO(irq_count); Missing ABI documentation. > + > + > +#define ONLY_BUS ((void *) 1) /* Match if the device is only a bus. */ > + > +static const struct of_device_id altera_timeout_bridge_of_match[] = { > + { .compatible = "altera-timeout-bridge", }, > + { .compatible = "simple-bus", .data = ONLY_BUS }, I don't understand why you want to bind to generic compatible. > + { /* sentinel */ } > +}; > +MODULE_DEVICE_TABLE(of, altera_timeout_bridge_of_match); > + > +static struct platform_driver altera_timeout_bridge_driver = { > + .probe = altera_timeout_bridge_probe, > + .driver = { > + .name = "altera-timeout-bridge", > + .of_match_table = altera_timeout_bridge_of_match, > + }, > +}; > + > +module_platform_driver(altera_timeout_bridge_driver); > + > +MODULE_LICENSE("GPL"); > +MODULE_DESCRIPTION("Avalon Timeout Bridge Bus"); > +MODULE_AUTHOR("Vyacheslav Yurkov (V.Yurkov.EXT@bruker.com)"); > + > Best regards, Krzysztof ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH 2/2] bus: add Altera timeout bridge driver 2026-10-03 20:19 ` [PATCH 2/2] bus: add Altera timeout bridge driver Vyacheslav Yurkov via B4 Relay 2026-10-03 20:29 ` sashiko-bot 2026-10-03 21:24 ` Krzysztof Kozlowski @ 2026-10-04 20:01 ` kernel test robot 2026-10-06 9:55 ` kernel test robot 3 siblings, 0 replies; 10+ messages in thread From: kernel test robot @ 2026-10-04 20:01 UTC (permalink / raw) To: Vyacheslav Yurkov via B4 Relay, Rob Herring, Krzysztof Kozlowski, Conor Dooley Cc: llvm, oe-kbuild-all, devicetree, linux-kernel, Vyacheslav Yurkov Hi Vyacheslav, kernel test robot noticed the following build errors: [auto build test ERROR on a74306e2e676f9775457366fc047a660fbf02f26] url: https://github.com/intel-lab-lkp/linux/commits/Vyacheslav-Yurkov-via-B4-Relay/dt-bindings-bus-Add-binding-for-Altera-AXI-Timeout-Bridge/20261003-201919 base: a74306e2e676f9775457366fc047a660fbf02f26 patch link: https://lore.kernel.org/r/20261003-feature-timeout-ip-v1-2-8837c311d571%40bruker.com patch subject: [PATCH 2/2] bus: add Altera timeout bridge driver config: s390-allmodconfig (https://download.01.org/0day-ci/archive/20261005/202610050325.ZOPvf8XR-lkp@intel.com/config) compiler: clang version 24.0.0git (https://github.com/llvm/llvm-project 5f609f950d2e80addf5566623013db68394334db) reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20261005/202610050325.ZOPvf8XR-lkp@intel.com/reproduce) If you fix the issue in a separate patch/commit (i.e. not just a new version of the same patch/commit), kindly add following tags | Reported-by: kernel test robot <lkp@intel.com> | Closes: https://lore.kernel.org/oe-kbuild-all/202610050325.ZOPvf8XR-lkp@intel.com/ All error/warnings (new ones prefixed by >>): >> drivers/bus/altera-timeout-bridge.c:60:11: error: call to undeclared function 'readl'; ISO C99 and later do not support implicit function declarations [-Wimplicit-function-declaration] 60 | result = readl(driver_data->bridge_registers + offset); | ^ >> drivers/bus/altera-timeout-bridge.c:69:2: error: call to undeclared function 'writel'; ISO C99 and later do not support implicit function declarations [-Wimplicit-function-declaration] 69 | writel(value, driver_data->bridge_registers + offset); | ^ >> drivers/bus/altera-timeout-bridge.c:187:38: warning: cast from 'void (*)(struct kernfs_node *)' to 'void (*)(void *)' converts to incompatible function type [-Wcast-function-type-strict] 187 | ret = devm_add_action_or_reset(dev, (void (*)(void *))sysfs_put, driver_data->irq_node); | ^~~~~~~~~~~~~~~~~~~~~~~~~~~ include/linux/device/devres.h:181:34: note: expanded from macro 'devm_add_action_or_reset' 181 | __devm_add_action_or_reset(dev, action, data, #action) | ^~~~~~ 1 warning and 2 errors generated. vim +/readl +60 drivers/bus/altera-timeout-bridge.c 53 54 static u32 55 bridge_reg_read(struct altera_timeout_bridge_data *driver_data, 56 u32 offset) 57 { 58 u32 result; 59 > 60 result = readl(driver_data->bridge_registers + offset); 61 62 return result; 63 } 64 65 static void bridge_reg_write( 66 struct altera_timeout_bridge_data *driver_data, 67 int offset, u32 value) 68 { > 69 writel(value, driver_data->bridge_registers + offset); 70 } 71 72 static irqreturn_t altera_timeout_bridge_isr(int irq, void *data) 73 { 74 struct altera_timeout_bridge_data *driver_data = data; 75 u32 timed_out_address; 76 resource_size_t effective_base_address; 77 resource_size_t effective_timed_out_address; 78 79 atomic_inc(&driver_data->irq_count); 80 81 // Read and print the timed-out address (encoded in the lower nibble 82 // 0x8..0xF according to AXI Timeout Bridge IP (CSR Interrupt Status Information) 83 timed_out_address = bridge_reg_read( 84 driver_data, 85 ALTERA_TIMEOUT_BRIDGE_REG_TIMED_OUT_ADDRESS); 86 effective_base_address = driver_data->bridge_register_resource->start; 87 effective_timed_out_address = effective_base_address + timed_out_address; 88 pr_err("%s: timeout at address 0x%llx\n", 89 __func__, (unsigned long long)effective_timed_out_address); 90 91 // Reset IRQ status in the bridge 92 bridge_reg_write( 93 driver_data, 94 ALTERA_TIMEOUT_BRIDGE_REG_IRQ_STATUS_RESET, 95 0x1); 96 // notify the user space 97 sysfs_notify_dirent(driver_data->irq_node); 98 99 return IRQ_HANDLED; 100 } 101 static int altera_timeout_bridge_probe(struct platform_device *pdev) 102 { 103 struct device *dev = &pdev->dev; 104 const struct of_device_id *match; 105 const struct of_dev_auxdata *lookup = dev_get_platdata(dev); 106 struct device_node *np = dev->of_node; 107 struct altera_timeout_bridge_data *driver_data; 108 int ret = 0; 109 int irq = -1; 110 111 /* 112 * Allow user to use driver_override to bind this driver to a 113 * transparent bus device which has a different compatible string 114 * that's not listed in simple_pm_bus_of_match. We don't want to do any 115 * of the simple-pm-bus tasks for these devices, so return early. 116 */ 117 if (device_has_driver_override(&pdev->dev)) 118 return 0; 119 120 match = of_match_device(dev->driver->of_match_table, dev); 121 122 /* Use a fall back logic like in simple-pm-bus */ 123 if (match && match->data) { 124 if (of_property_match_string(np, "compatible", match->compatible) == 0) 125 return 0; 126 else 127 return -ENODEV; 128 } 129 130 driver_data = 131 devm_kzalloc(&pdev->dev, sizeof(*driver_data), GFP_KERNEL); 132 if (!driver_data) { 133 dev_err(&pdev->dev, 134 "%s: kzalloc failed: no memory for the driver's data, returning ENOMEM\n", 135 __func__); 136 return -ENOMEM; 137 } 138 139 driver_data->dev = dev; 140 platform_set_drvdata(pdev, driver_data); 141 142 driver_data->bridge_register_resource = 143 platform_get_resource(pdev, IORESOURCE_MEM, 0); 144 if (!driver_data->bridge_register_resource) { 145 dev_err(dev, 146 "%s: missing required reg binding\n", 147 __func__); 148 return -ENOENT; 149 } 150 driver_data->bridge_registers = 151 devm_ioremap_resource(dev, 152 driver_data->bridge_register_resource); 153 if (IS_ERR(driver_data->bridge_registers)) { 154 dev_err(dev, 155 "%s: ioremap_resource failed for bridge-status MMIO, returning PTR_ERR(%ld)\n", 156 __func__, PTR_ERR(driver_data->bridge_registers)); 157 return PTR_ERR(driver_data->bridge_registers); 158 } 159 160 irq = platform_get_irq(pdev, 0); 161 if (irq < 0) { 162 dev_err(dev, 163 "%s: platform_get_irq failed: %d\n", __func__, irq); 164 return irq; 165 } 166 167 ret = devm_request_irq(dev, irq, 168 altera_timeout_bridge_isr, 169 0, 170 dev_name(dev), 171 driver_data); 172 if (ret) { 173 dev_err(dev, 174 "%s: devm_request_irq failed for IRQ %d: %d\n", 175 __func__, irq, ret); 176 return ret; 177 } 178 179 ret = devm_device_add_group(dev, &altera_timeout_bridge_sysfs_group); 180 if (ret) 181 return ret; 182 183 driver_data->irq_node = sysfs_get_dirent(dev->kobj.sd, "timeout_irq"); 184 if (!driver_data->irq_node) 185 return -ENOENT; 186 > 187 ret = devm_add_action_or_reset(dev, (void (*)(void *))sysfs_put, driver_data->irq_node); 188 if (ret) 189 return ret; 190 191 if (np) 192 of_platform_populate(np, NULL, lookup, &pdev->dev); 193 194 return 0; 195 } 196 -- 0-DAY CI Kernel Test Service https://github.com/intel/lkp-tests/wiki ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [PATCH 2/2] bus: add Altera timeout bridge driver 2026-10-03 20:19 ` [PATCH 2/2] bus: add Altera timeout bridge driver Vyacheslav Yurkov via B4 Relay ` (2 preceding siblings ...) 2026-10-04 20:01 ` kernel test robot @ 2026-10-06 9:55 ` kernel test robot 3 siblings, 0 replies; 10+ messages in thread From: kernel test robot @ 2026-10-06 9:55 UTC (permalink / raw) To: Vyacheslav Yurkov via B4 Relay, Rob Herring, Krzysztof Kozlowski, Conor Dooley Cc: oe-kbuild-all, devicetree, linux-kernel, Vyacheslav Yurkov Hi Vyacheslav, kernel test robot noticed the following build errors: [auto build test ERROR on a74306e2e676f9775457366fc047a660fbf02f26] url: https://github.com/intel-lab-lkp/linux/commits/Vyacheslav-Yurkov-via-B4-Relay/dt-bindings-bus-Add-binding-for-Altera-AXI-Timeout-Bridge/20261003-201919 base: a74306e2e676f9775457366fc047a660fbf02f26 patch link: https://lore.kernel.org/r/20261003-feature-timeout-ip-v1-2-8837c311d571%40bruker.com patch subject: [PATCH 2/2] bus: add Altera timeout bridge driver config: s390-allyesconfig (https://download.01.org/0day-ci/archive/20261006/202610061734.ZXwVnIt2-lkp@intel.com/config) compiler: s390-linux-gcc (GCC) 16.1.0 reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20261006/202610061734.ZXwVnIt2-lkp@intel.com/reproduce) If you fix the issue in a separate patch/commit (i.e. not just a new version of the same patch/commit), kindly add following tags | Reported-by: kernel test robot <lkp@intel.com> | Closes: https://lore.kernel.org/oe-kbuild-all/202610061734.ZXwVnIt2-lkp@intel.com/ All errors (new ones prefixed by >>): drivers/bus/altera-timeout-bridge.c: In function 'bridge_reg_read': >> drivers/bus/altera-timeout-bridge.c:60:18: error: implicit declaration of function 'readl' [-Wimplicit-function-declaration] 60 | result = readl(driver_data->bridge_registers + offset); | ^~~~~ drivers/bus/altera-timeout-bridge.c: In function 'bridge_reg_write': >> drivers/bus/altera-timeout-bridge.c:69:9: error: implicit declaration of function 'writel' [-Wimplicit-function-declaration] 69 | writel(value, driver_data->bridge_registers + offset); | ^~~~~~ vim +/readl +60 drivers/bus/altera-timeout-bridge.c 53 54 static u32 55 bridge_reg_read(struct altera_timeout_bridge_data *driver_data, 56 u32 offset) 57 { 58 u32 result; 59 > 60 result = readl(driver_data->bridge_registers + offset); 61 62 return result; 63 } 64 65 static void bridge_reg_write( 66 struct altera_timeout_bridge_data *driver_data, 67 int offset, u32 value) 68 { > 69 writel(value, driver_data->bridge_registers + offset); 70 } 71 -- 0-DAY CI Kernel Test Service https://github.com/intel/lkp-tests/wiki ^ permalink raw reply [flat|nested] 10+ messages in thread
end of thread, other threads:[~2026-10-06 9:56 UTC | newest] Thread overview: 10+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-10-03 20:19 [PATCH 0/2] Add Altera timeout bridge driver Vyacheslav Yurkov via B4 Relay 2026-10-03 20:19 ` [PATCH 1/2] dt-bindings: bus: Add binding for Altera AXI Timeout Bridge Vyacheslav Yurkov via B4 Relay 2026-10-03 20:26 ` sashiko-bot 2026-10-03 21:18 ` Krzysztof Kozlowski 2026-10-05 13:30 ` Rob Herring (Arm) 2026-10-03 20:19 ` [PATCH 2/2] bus: add Altera timeout bridge driver Vyacheslav Yurkov via B4 Relay 2026-10-03 20:29 ` sashiko-bot 2026-10-03 21:24 ` Krzysztof Kozlowski 2026-10-04 20:01 ` kernel test robot 2026-10-06 9:55 ` kernel test robot
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox