From: sashiko-bot@kernel.org
To: "Michael Reeves" <michael.reeves077@gmail.com>
Cc: linux-input@vger.kernel.org, robh@kernel.org,
dmitry.torokhov@gmail.com, conor+dt@kernel.org,
devicetree@vger.kernel.org
Subject: Re: [PATCH v2 05/10] mailbox: apple: Add DockChannel FIFO controller
Date: Fri, 18 Sep 2026 11:19:31 +0000 [thread overview]
Message-ID: <20260918111932.3DDC21F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260918-apple-mtp-keyboard-final-v2-5-a5c685e50b60@gmail.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] mailbox: apple: interrupt storm if TX FIFO not empty during IRQ_TX
- [High] mailbox: apple: data corruption due to asymmetric byte lane mapping on TX
- [High] mailbox: apple: TOCTOU race clearing IRQ_FLAG loses TX/RX events
--
commit 93fab252e833f92aad9624f1eae3f18e4b2d3e72
Author: Michael Reeves <michael.reeves077@gmail.com>
mailbox: apple: Add DockChannel FIFO controller
DockChannel is a hardware FIFO used by Apple coprocessors for
low-latency byte-stream communication with the AP. Add a mailbox
controller that preallocates RX storage, tracks IRQ enable state
in software, and reports TX completion from the TX-empty interrupt.
> diff --git a/drivers/mailbox/apple-dockchannel.c b/drivers/mailbox/apple-dockchannel.c
> index 0000000000000..d0a66e1b786cd
> --- /dev/null
> +++ b/drivers/mailbox/apple-dockchannel.c
[ ... ]
> +static void apple_dockchannel_irq_enable(struct apple_dockchannel *dc, u32 bits)
> +{
> + /*
> + * IRQ_FLAG is write-to-clear. Clear stale latched flags before
> + * unmasking so the next interrupt reflects current FIFO state.
> + */
> + writel_relaxed(bits, dc->irq_base + IRQ_FLAG);
[Severity: High]
Does clearing IRQ_FLAG unconditionally before unmasking create a TOCTOU race
that loses events?
For example, in apple_dockchannel_send_data():
1. apple_dockchannel_write_pending() runs and the coprocessor starts draining
the FIFO.
2. The coprocessor drains the TX FIFO and the hardware latches IRQ_TX.
3. apple_dockchannel_irq_enable(dc, IRQ_TX) unconditionally clears the latched
IRQ_TX completion flag.
Can this result in permanent loss of TX completion interrupts, or similarly
swallow RX data interrupts during apple_dockchannel_startup(), leading to a
channel deadlock?
> + apple_dockchannel_irq_update(dc, bits, true);
> +}
[ ... ]
> +static void apple_dockchannel_write_pending(struct apple_dockchannel *dc)
> +{
> + size_t left = dc->tx_len - dc->tx_pos;
> + const u8 *p = dc->tx_buf + dc->tx_pos;
> +
> + while (left) {
> + size_t avail;
> + size_t block;
> +
> + avail = readl_relaxed(dc->data_base + DATA_TX_FREE);
> + if (!avail)
> + break;
> +
> + block = min(left, avail);
> +
> + while (block >= sizeof(u32)) {
> + writel_relaxed(get_unaligned_le32(p),
> + dc->data_base + DATA_TX32);
> + p += sizeof(u32);
> + left -= sizeof(u32);
> + block -= sizeof(u32);
> + }
> +
> + while (block) {
> + writel_relaxed(*p++, dc->data_base + DATA_TX8);
[Severity: High]
Does this place the remainder byte in the wrong byte lane?
The RX path in apple_dockchannel_read() documents that the hardware uses
bits [15:8] for 8-bit FIFO accesses, shifting the read value by 8:
*p++ = readl_relaxed(dc->data_base + DATA_RX8) >> 8;
Should the TX path also shift the byte << 8 to align with the hardware's
expected byte lane, avoiding data corruption for unaligned payloads?
> + left--;
> + block--;
> + }
> + }
> +
> + dc->tx_pos = dc->tx_len - left;
> +}
[ ... ]
> +static irqreturn_t apple_dockchannel_irq_thread(int irq, void *data)
> +{
> + struct apple_dockchannel *dc = data;
> + unsigned long irqflags;
> + u32 flags;
> + u32 pending;
> + bool tx_done = false;
> +
> + flags = readl_relaxed(dc->irq_base + IRQ_FLAG);
> +
> + spin_lock_irqsave(&dc->lock, irqflags);
> +
> + pending = flags & dc->irq_mask & (IRQ_TX | IRQ_RX);
> + if (!pending)
> + goto out_unlock_none;
> +
> + if (pending & IRQ_TX) {
> + if (apple_dockchannel_tx_empty(dc)) {
> + apple_dockchannel_irq_disable(dc, IRQ_TX);
> + tx_done = dc->tx_active;
> + dc->tx_active = false;
> + } else {
> + pending &= ~IRQ_TX;
> + }
> + }
> +
> + writel_relaxed(pending, dc->irq_base + IRQ_FLAG);
[Severity: High]
If IRQ_TX is removed from the pending mask when the FIFO is not empty, does
it prevent the hardware latch from being cleared?
Since IRQ_FLAG is a write-to-clear register, writing back the modified mask
with IRQ_TX cleared will fail to clear the IRQ_TX hardware latch. Will this
cause an infinite interrupt storm upon returning from the handler?
> +
> + spin_unlock_irqrestore(&dc->lock, irqflags);
> +
> + if (tx_done)
> + mbox_chan_txdone(&dc->chan, 0);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260918-apple-mtp-keyboard-final-v2-0-a5c685e50b60@gmail.com?part=5
next prev parent reply other threads:[~2026-09-18 11:19 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 11:06 [PATCH v2 00/10] Add support for Apple Silicon DockChannel internal keyboards Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 01/10] dt-bindings: mailbox: apple: Add M3 ASC mailbox compatibles Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 02/10] dt-bindings: mailbox: apple: Add DockChannel mailbox Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 03/10] dt-bindings: iommu: apple,dart: Add M3 compatibles Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 04/10] dt-bindings: input: apple: Add DockChannel HID transport Michael Reeves via B4 Relay
2026-09-18 11:15 ` sashiko-bot
2026-09-18 11:06 ` [PATCH v2 05/10] mailbox: apple: Add DockChannel FIFO controller Michael Reeves via B4 Relay
2026-09-18 11:19 ` sashiko-bot [this message]
2026-09-18 13:07 ` Yureka Lilian
2026-09-18 11:06 ` [PATCH v2 06/10] soc: apple: rtkit: Add tracekit endpoint Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 07/10] HID: apple: Add support for DockChannel HID keyboards Michael Reeves via B4 Relay
2026-09-18 11:18 ` sashiko-bot
2026-09-18 11:06 ` [PATCH v2 08/10] HID: apple: Add DockChannel HID transport driver Michael Reeves via B4 Relay
2026-09-18 11:19 ` sashiko-bot
2026-09-18 11:06 ` [PATCH v2 09/10] arm64: dts: apple: Add MTP DockChannel HID nodes Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 10/10] arm64: dts: apple: Enable DockChannel HID on M2 and M3 laptops Michael Reeves via B4 Relay
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918111932.3DDC21F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dmitry.torokhov@gmail.com \
--cc=linux-input@vger.kernel.org \
--cc=michael.reeves077@gmail.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox