Linux Hardware Monitor development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Manaf Meethalavalappu Pallikunhi" <manaf.pallikunhi@oss.qualcomm.com>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org,
	linux-hwmon@vger.kernel.org, mfd@lists.linux.dev, lee@kernel.org
Subject: Re: [PATCH v4 02/12] hwmon: Add Qualcomm PMIC BCL driver
Date: Mon, 05 Oct 2026 12:40:17 +0000	[thread overview]
Message-ID: <20261005124017.A81141F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261005-qcom-bcl-hwmon-v4-2-50b9a8c730b7@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] hwmon: qcom-bcl: IRQ storm on teardown due to devres LIFO ordering
- [Medium] hwmon: qcom-bcl: leaked wake source due to devres LIFO race with delayed work
- [Medium] hwmon: qcom-bcl: max_mu limits for SMB2360/SMB2370 exceed L1/L2 threshold register capacity
--

commit 89d1ce4f2b9b2e93fca41d6caf2cfb094e5b9f02
Author: Manaf Meethalavalappu Pallikunhi <manaf.pallikunhi@oss.qualcomm.com>

hwmon: Add Qualcomm PMIC BCL driver

This commit adds a hardware monitoring driver for the Qualcomm SPMI PMIC
Battery Current Limiting (BCL) peripheral. It provides real-time voltage and
current readings, configurable threshold-based alarms, and automatic
threshold management with polling-based recovery.

> diff --git a/drivers/hwmon/qcom-bcl-hwmon.c b/drivers/hwmon/qcom-bcl-hwmon.c
> --- /dev/null
> +++ b/drivers/hwmon/qcom-bcl-hwmon.c
[ ... ]
> +static const struct bcl_desc smb2360_data = {
> +	.reg_fields = bcl_smb2360_reg_fields,
> +	.num_reg_fields = F_CURR_INPUT + 1,
> +	.data_field_bits_size = 8,
> +	.thresh_field_bits_size = 8,
> +	.battery_config_field = REG_FIELD(0x2a50, 0, 1),
> +	.in_mon_enabled = true,
> +	.in_input_enabled = true,
> +	.curr_mon_enabled = true,
> +	.channel_cfg[BCL_BATT_2S][CHANNEL_IN] = {
> +		.base_mu = 4500,
> +		.max_mu = 8400,
> +		.step_mu = 50,

[Severity: Medium]
Does this maximum threshold value exceed the capacity of the L1 and L2
registers?

The L1 and L2 registers use a 6-bit index field, which limits the maximum
value to 63. For BCL_BATT_2S, this gives a maximum voltage of 7650 mV
(4500 base + 63 * 50 step).

Since max_mu is 8400, if userspace tries to set a valid value like 8000 mV,
the computed index will exceed the field mask and be rejected by
bcl_validate_threshold_fits(), resulting in an unexpected -EINVAL error.

[ ... ]
> +static int bcl_alarm_irq_init(struct platform_device *pdev,
> +			      struct bcl_device *bcl)
> +{
[ ... ]
> +		ret = devm_request_threaded_irq(&pdev->dev, irq_num, NULL,
> +						bcl_handle_alarm, IRQF_ONESHOT,
> +						bcl_int_names[i], alarm);
> +		if (ret)
> +			return ret;
> +
> +		/*
> +		 * Register the work cleanup action right after the IRQ is
> +		 * requested, before any other fallible step in this loop, so
> +		 * a delayed work scheduled by the IRQ handler is guaranteed to
> +		 * be canceled on teardown even if the wake cleanup registration
> +		 * below fails. Keeping it after the IRQ request also preserves
> +		 * safe devm LIFO teardown order.
> +		 */
> +		ret = devm_add_action_or_reset(&pdev->dev, bcl_alarm_work_cleanup_action,
> +					       alarm);

[Severity: High]
Is it possible for an endless IRQ storm to occur during teardown?

Because devres uses LIFO ordering, the work cleanup action runs before the
IRQ is freed, which sets shutting_down to true. If the hardware asserts the
interrupt in this window, bcl_handle_alarm() will return IRQ_HANDLED without
calling disable_irq_nosync().

Could this leave the level-triggered interrupt unmasked and cause it to
continuously fire in a loop?

> +		if (ret)
> +			return ret;
> +
> +		if (!enable_irq_wake(irq_num))
> +			alarm->irq_wake_enabled = true;
> +
> +		ret = devm_add_action_or_reset(&pdev->dev, bcl_alarm_wake_cleanup_action,
> +					       alarm);

[Severity: Medium]
Could this lead to a leaked wake source during driver unbind?

The bcl_alarm_wake_cleanup_action is registered after the work cleanup action,
meaning devres will execute it first and disable the wake source. However, the
delayed polling work hasn't been canceled yet.

If bcl_alarm_enable_poll() executes concurrently in this window, it will see
shutting_down is still false and could call enable_irq_wake() again, leaving
the wake source permanently enabled after the work is finally canceled.

> +		if (ret)
> +			return ret;
> +	}
> +
> +	return 0;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261005-qcom-bcl-hwmon-v4-0-50b9a8c730b7@oss.qualcomm.com?part=2

  reply	other threads:[~2026-10-05 12:40 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 12:24 [PATCH v4 00/12] hwmon: Add Qualcomm SPMI BCL driver Manaf Meethalavalappu Pallikunhi
2026-10-05 12:24 ` [PATCH v4 01/12] dt-bindings: hwmon: Describe Qualcomm BCL hardware Manaf Meethalavalappu Pallikunhi
2026-10-05 12:32   ` sashiko-bot
2026-10-07 20:42   ` Rob Herring (Arm)
2026-10-05 12:24 ` [PATCH v4 02/12] hwmon: Add Qualcomm PMIC BCL driver Manaf Meethalavalappu Pallikunhi
2026-10-05 12:40   ` sashiko-bot [this message]
2026-10-05 12:24 ` [PATCH v4 03/12] arm64: dts: qcom: hamoa-pmic: Enable BCL sensor node Manaf Meethalavalappu Pallikunhi
2026-10-05 12:31   ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 04/12] arm64: dts: qcom: pm7250b: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:33   ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 05/12] arm64: dts: qcom: pm7550-eliza: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:38   ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 06/12] arm64: dts: qcom: pm7550ba-eliza: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:40   ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 07/12] arm64: dts: qcom: pm8350c: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:40   ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 08/12] arm64: dts: qcom: pm8550: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:44   ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 09/12] arm64: dts: qcom: pmh0101: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:42   ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 10/12] arm64: dts: qcom: pmih0108-kaanapali: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:44   ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 11/12] arm64: dts: qcom: pmih0108: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:44   ` sashiko-bot
2026-10-05 12:24 ` [PATCH v4 12/12] arm64: dts: qcom: smb2370: " Manaf Meethalavalappu Pallikunhi
2026-10-05 12:47   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261005124017.A81141F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=lee@kernel.org \
    --cc=linux-hwmon@vger.kernel.org \
    --cc=manaf.pallikunhi@oss.qualcomm.com \
    --cc=mfd@lists.linux.dev \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox