Linux Input/HID development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Dmitry Torokhov" <dmitry.torokhov@gmail.com>
Cc: dmitry.torokhov@gmail.com, linux-input@vger.kernel.org
Subject: Re: [PATCH 1/7] Input: gscps2 - clean up driver code style and structure
Date: Sun, 30 Aug 2026 21:04:46 +0000	[thread overview]
Message-ID: <20260830210447.0C8D31F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260830-gscps2-v1-1-c733d4cae7f9@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] The busy-wait loop in `gscps2_writeb_output` polling the hardware status register lacks a timeout, creating a hard lockup (deadlock) risk when invoked with local interrupts disabled.
--

commit edfe57337208b53162446f9db3e046a15ffe59af
Author: Dmitry Torokhov <dmitry.torokhov@gmail.com>

Input: gscps2 - clean up driver code style and structure

This commit cleans up code style and function ordering in the gscps2 driver.
It updates macro definitions, replaces printk with dev_dbg, and introduces
cpu_relax() into the spin-wait loops.

> diff --git a/drivers/input/serio/gscps2.c b/drivers/input/serio/gscps2.c
> index 43453ec533b22..b82c56ba8ff70 100644
> --- a/drivers/input/serio/gscps2.c
> +++ b/drivers/input/serio/gscps2.c

[ ... ]

> +/*
> + * gscps2_writeb_output() - write a byte to the port
> + *
> + * returns 1 on success, 0 on error
> + */
> +static inline int gscps2_writeb_output(struct gscps2port *ps2port, u8 data)
> +{
> +	char __iomem *addr = ps2port->addr;
> +
> +	if (!wait_TBE(addr)) {
> +		dev_dbg(&ps2port->padev->dev, "timeout - could not write byte %#x\n", data);
> +		return 0;
> +	}
> +
> +	while (gscps2_readb_status(addr) & GSC_STAT_RBNE)
> +		cpu_relax();

[Severity: High]
This is a pre-existing issue, but does this busy-wait loop risk a hard CPU
lockup when invoked with local interrupts disabled?

A PS/2 driver like atkbd can call serio_write() from an interrupt context
with local IRQs disabled (for example, in atkbd_interrupt sending
ATKBD_CMD_RESEND in response to a parity error).

If a new byte arrives in the receive buffer concurrently, the GSC_STAT_RBNE
bit is set. Since local IRQs are disabled, the hardware interrupt handler
cannot run to read the pending byte. This means GSC_STAT_RBNE will never
clear and the CPU could hang indefinitely waiting for the buffer to empty.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260830-gscps2-v1-0-c733d4cae7f9@gmail.com?part=1

  reply	other threads:[~2026-08-30 21:04 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-30 20:52 [PATCH 0/7] Input: gscps2: cleanups and locking fixes Dmitry Torokhov
2026-08-30 20:52 ` [PATCH 1/7] Input: gscps2 - clean up driver code style and structure Dmitry Torokhov
2026-08-30 21:04   ` sashiko-bot [this message]
2026-08-30 20:52 ` [PATCH 2/7] Input: gscps2 - use RCU for ps2port_list and manage it in open/close Dmitry Torokhov
2026-08-30 20:52 ` [PATCH 3/7] Input: gscps2 - protect buffer access in read and report helpers Dmitry Torokhov
2026-08-30 21:05   ` sashiko-bot
2026-08-30 20:52 ` [PATCH 4/7] Input: gscps2 - serialize hardware and buffer access in gscps2_flush() Dmitry Torokhov
2026-08-30 21:02   ` sashiko-bot
2026-08-30 20:52 ` [PATCH 5/7] Input: gscps2 - return IRQ_NONE when interrupt is not handled Dmitry Torokhov
2026-08-30 21:05   ` sashiko-bot
2026-08-30 20:52 ` [PATCH 6/7] Input: gscps2 - serialize concurrent interrupt handlers Dmitry Torokhov
2026-08-30 21:07   ` sashiko-bot
2026-08-30 20:52 ` [PATCH 7/7] Input: gscps2 - drop busy-wait and manual interrupt pump on transmit Dmitry Torokhov
2026-08-30 21:05   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260830210447.0C8D31F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dmitry.torokhov@gmail.com \
    --cc=linux-input@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox