From: sashiko-bot@kernel.org
To: "Manaf Meethalavalappu Pallikunhi" <manaf.pallikunhi@oss.qualcomm.com>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org,
linux-hwmon@vger.kernel.org, mfd@lists.linux.dev, lee@kernel.org
Subject: Re: [PATCH v4 02/12] hwmon: Add Qualcomm PMIC BCL driver
Date: Mon, 05 Oct 2026 12:40:17 +0000 [thread overview]
Message-ID: <20261005124017.A81141F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261005-qcom-bcl-hwmon-v4-2-50b9a8c730b7@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] hwmon: qcom-bcl: IRQ storm on teardown due to devres LIFO ordering
- [Medium] hwmon: qcom-bcl: leaked wake source due to devres LIFO race with delayed work
- [Medium] hwmon: qcom-bcl: max_mu limits for SMB2360/SMB2370 exceed L1/L2 threshold register capacity
--
commit 89d1ce4f2b9b2e93fca41d6caf2cfb094e5b9f02
Author: Manaf Meethalavalappu Pallikunhi <manaf.pallikunhi@oss.qualcomm.com>
hwmon: Add Qualcomm PMIC BCL driver
This commit adds a hardware monitoring driver for the Qualcomm SPMI PMIC
Battery Current Limiting (BCL) peripheral. It provides real-time voltage and
current readings, configurable threshold-based alarms, and automatic
threshold management with polling-based recovery.
> diff --git a/drivers/hwmon/qcom-bcl-hwmon.c b/drivers/hwmon/qcom-bcl-hwmon.c
> --- /dev/null
> +++ b/drivers/hwmon/qcom-bcl-hwmon.c
[ ... ]
> +static const struct bcl_desc smb2360_data = {
> + .reg_fields = bcl_smb2360_reg_fields,
> + .num_reg_fields = F_CURR_INPUT + 1,
> + .data_field_bits_size = 8,
> + .thresh_field_bits_size = 8,
> + .battery_config_field = REG_FIELD(0x2a50, 0, 1),
> + .in_mon_enabled = true,
> + .in_input_enabled = true,
> + .curr_mon_enabled = true,
> + .channel_cfg[BCL_BATT_2S][CHANNEL_IN] = {
> + .base_mu = 4500,
> + .max_mu = 8400,
> + .step_mu = 50,
[Severity: Medium]
Does this maximum threshold value exceed the capacity of the L1 and L2
registers?
The L1 and L2 registers use a 6-bit index field, which limits the maximum
value to 63. For BCL_BATT_2S, this gives a maximum voltage of 7650 mV
(4500 base + 63 * 50 step).
Since max_mu is 8400, if userspace tries to set a valid value like 8000 mV,
the computed index will exceed the field mask and be rejected by
bcl_validate_threshold_fits(), resulting in an unexpected -EINVAL error.
[ ... ]
> +static int bcl_alarm_irq_init(struct platform_device *pdev,
> + struct bcl_device *bcl)
> +{
[ ... ]
> + ret = devm_request_threaded_irq(&pdev->dev, irq_num, NULL,
> + bcl_handle_alarm, IRQF_ONESHOT,
> + bcl_int_names[i], alarm);
> + if (ret)
> + return ret;
> +
> + /*
> + * Register the work cleanup action right after the IRQ is
> + * requested, before any other fallible step in this loop, so
> + * a delayed work scheduled by the IRQ handler is guaranteed to
> + * be canceled on teardown even if the wake cleanup registration
> + * below fails. Keeping it after the IRQ request also preserves
> + * safe devm LIFO teardown order.
> + */
> + ret = devm_add_action_or_reset(&pdev->dev, bcl_alarm_work_cleanup_action,
> + alarm);
[Severity: High]
Is it possible for an endless IRQ storm to occur during teardown?
Because devres uses LIFO ordering, the work cleanup action runs before the
IRQ is freed, which sets shutting_down to true. If the hardware asserts the
interrupt in this window, bcl_handle_alarm() will return IRQ_HANDLED without
calling disable_irq_nosync().
Could this leave the level-triggered interrupt unmasked and cause it to
continuously fire in a loop?
> + if (ret)
> + return ret;
> +
> + if (!enable_irq_wake(irq_num))
> + alarm->irq_wake_enabled = true;
> +
> + ret = devm_add_action_or_reset(&pdev->dev, bcl_alarm_wake_cleanup_action,
> + alarm);
[Severity: Medium]
Could this lead to a leaked wake source during driver unbind?
The bcl_alarm_wake_cleanup_action is registered after the work cleanup action,
meaning devres will execute it first and disable the wake source. However, the
delayed polling work hasn't been canceled yet.
If bcl_alarm_enable_poll() executes concurrently in this window, it will see
shutting_down is still false and could call enable_irq_wake() again, leaving
the wake source permanently enabled after the work is finally canceled.
> + if (ret)
> + return ret;
> + }
> +
> + return 0;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261005-qcom-bcl-hwmon-v4-0-50b9a8c730b7@oss.qualcomm.com?part=2
next prev parent reply other threads:[~2026-10-05 12:40 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 12:24 [PATCH v4 00/12] hwmon: Add Qualcomm SPMI BCL driver Manaf Meethalavalappu Pallikunhi
2026-10-05 12:24 ` [PATCH v4 01/12] dt-bindings: hwmon: Describe Qualcomm BCL hardware Manaf Meethalavalappu Pallikunhi
2026-10-05 12:32 ` sashiko-bot
2026-10-07 20:42 ` Rob Herring (Arm)
2026-10-05 12:24 ` [PATCH v4 02/12] hwmon: Add Qualcomm PMIC BCL driver Manaf Meethalavalappu Pallikunhi
2026-10-05 12:40 ` sashiko-bot [this message]
2026-10-05 12:24 ` [PATCH v4 03/12] arm64: dts: qcom: hamoa-pmic: Enable BCL sensor node Manaf Meethalavalappu Pallikunhi
2026-10-05 12:31 ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 04/12] arm64: dts: qcom: pm7250b: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:33 ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 05/12] arm64: dts: qcom: pm7550-eliza: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:38 ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 06/12] arm64: dts: qcom: pm7550ba-eliza: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:40 ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 07/12] arm64: dts: qcom: pm8350c: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:40 ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 08/12] arm64: dts: qcom: pm8550: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:44 ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 09/12] arm64: dts: qcom: pmh0101: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:42 ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 10/12] arm64: dts: qcom: pmih0108-kaanapali: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:44 ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 11/12] arm64: dts: qcom: pmih0108: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:44 ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 12/12] arm64: dts: qcom: smb2370: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:47 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005124017.A81141F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=lee@kernel.org \
--cc=linux-hwmon@vger.kernel.org \
--cc=manaf.pallikunhi@oss.qualcomm.com \
--cc=mfd@lists.linux.dev \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox