Linux Input/HID development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Michael Reeves" <michael.reeves077@gmail.com>
Cc: linux-input@vger.kernel.org, robh@kernel.org,
	dmitry.torokhov@gmail.com, conor+dt@kernel.org,
	devicetree@vger.kernel.org
Subject: Re: [PATCH v2 05/10] mailbox: apple: Add DockChannel FIFO controller
Date: Fri, 18 Sep 2026 11:19:31 +0000	[thread overview]
Message-ID: <20260918111932.3DDC21F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260918-apple-mtp-keyboard-final-v2-5-a5c685e50b60@gmail.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] mailbox: apple: interrupt storm if TX FIFO not empty during IRQ_TX
- [High] mailbox: apple: data corruption due to asymmetric byte lane mapping on TX
- [High] mailbox: apple: TOCTOU race clearing IRQ_FLAG loses TX/RX events
--

commit 93fab252e833f92aad9624f1eae3f18e4b2d3e72
Author: Michael Reeves <michael.reeves077@gmail.com>

mailbox: apple: Add DockChannel FIFO controller

DockChannel is a hardware FIFO used by Apple coprocessors for
low-latency byte-stream communication with the AP. Add a mailbox
controller that preallocates RX storage, tracks IRQ enable state
in software, and reports TX completion from the TX-empty interrupt.

> diff --git a/drivers/mailbox/apple-dockchannel.c b/drivers/mailbox/apple-dockchannel.c
> index 0000000000000..d0a66e1b786cd
> --- /dev/null
> +++ b/drivers/mailbox/apple-dockchannel.c
[ ... ]
> +static void apple_dockchannel_irq_enable(struct apple_dockchannel *dc, u32 bits)
> +{
> +	/*
> +	 * IRQ_FLAG is write-to-clear. Clear stale latched flags before
> +	 * unmasking so the next interrupt reflects current FIFO state.
> +	 */
> +	writel_relaxed(bits, dc->irq_base + IRQ_FLAG);

[Severity: High]
Does clearing IRQ_FLAG unconditionally before unmasking create a TOCTOU race
that loses events?

For example, in apple_dockchannel_send_data():
1. apple_dockchannel_write_pending() runs and the coprocessor starts draining
   the FIFO.
2. The coprocessor drains the TX FIFO and the hardware latches IRQ_TX.
3. apple_dockchannel_irq_enable(dc, IRQ_TX) unconditionally clears the latched
   IRQ_TX completion flag.

Can this result in permanent loss of TX completion interrupts, or similarly
swallow RX data interrupts during apple_dockchannel_startup(), leading to a
channel deadlock?

> +	apple_dockchannel_irq_update(dc, bits, true);
> +}
[ ... ]
> +static void apple_dockchannel_write_pending(struct apple_dockchannel *dc)
> +{
> +	size_t left = dc->tx_len - dc->tx_pos;
> +	const u8 *p = dc->tx_buf + dc->tx_pos;
> +
> +	while (left) {
> +		size_t avail;
> +		size_t block;
> +
> +		avail = readl_relaxed(dc->data_base + DATA_TX_FREE);
> +		if (!avail)
> +			break;
> +
> +		block = min(left, avail);
> +
> +		while (block >= sizeof(u32)) {
> +			writel_relaxed(get_unaligned_le32(p),
> +				       dc->data_base + DATA_TX32);
> +			p += sizeof(u32);
> +			left -= sizeof(u32);
> +			block -= sizeof(u32);
> +		}
> +
> +		while (block) {
> +			writel_relaxed(*p++, dc->data_base + DATA_TX8);

[Severity: High]
Does this place the remainder byte in the wrong byte lane?

The RX path in apple_dockchannel_read() documents that the hardware uses
bits [15:8] for 8-bit FIFO accesses, shifting the read value by 8:

    *p++ = readl_relaxed(dc->data_base + DATA_RX8) >> 8;

Should the TX path also shift the byte << 8 to align with the hardware's
expected byte lane, avoiding data corruption for unaligned payloads?

> +			left--;
> +			block--;
> +		}
> +	}
> +
> +	dc->tx_pos = dc->tx_len - left;
> +}
[ ... ]
> +static irqreturn_t apple_dockchannel_irq_thread(int irq, void *data)
> +{
> +	struct apple_dockchannel *dc = data;
> +	unsigned long irqflags;
> +	u32 flags;
> +	u32 pending;
> +	bool tx_done = false;
> +
> +	flags = readl_relaxed(dc->irq_base + IRQ_FLAG);
> +
> +	spin_lock_irqsave(&dc->lock, irqflags);
> +
> +	pending = flags & dc->irq_mask & (IRQ_TX | IRQ_RX);
> +	if (!pending)
> +		goto out_unlock_none;
> +
> +	if (pending & IRQ_TX) {
> +		if (apple_dockchannel_tx_empty(dc)) {
> +			apple_dockchannel_irq_disable(dc, IRQ_TX);
> +			tx_done = dc->tx_active;
> +			dc->tx_active = false;
> +		} else {
> +			pending &= ~IRQ_TX;
> +		}
> +	}
> +
> +	writel_relaxed(pending, dc->irq_base + IRQ_FLAG);

[Severity: High]
If IRQ_TX is removed from the pending mask when the FIFO is not empty, does
it prevent the hardware latch from being cleared?

Since IRQ_FLAG is a write-to-clear register, writing back the modified mask
with IRQ_TX cleared will fail to clear the IRQ_TX hardware latch. Will this
cause an infinite interrupt storm upon returning from the handler?

> +
> +	spin_unlock_irqrestore(&dc->lock, irqflags);
> +
> +	if (tx_done)
> +		mbox_chan_txdone(&dc->chan, 0);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260918-apple-mtp-keyboard-final-v2-0-a5c685e50b60@gmail.com?part=5

  reply	other threads:[~2026-09-18 11:19 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18 11:06 [PATCH v2 00/10] Add support for Apple Silicon DockChannel internal keyboards Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 01/10] dt-bindings: mailbox: apple: Add M3 ASC mailbox compatibles Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 02/10] dt-bindings: mailbox: apple: Add DockChannel mailbox Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 03/10] dt-bindings: iommu: apple,dart: Add M3 compatibles Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 04/10] dt-bindings: input: apple: Add DockChannel HID transport Michael Reeves via B4 Relay
2026-09-18 11:15   ` sashiko-bot
2026-09-18 11:06 ` [PATCH v2 05/10] mailbox: apple: Add DockChannel FIFO controller Michael Reeves via B4 Relay
2026-09-18 11:19   ` sashiko-bot [this message]
2026-09-18 13:07   ` Yureka Lilian
2026-09-18 11:06 ` [PATCH v2 06/10] soc: apple: rtkit: Add tracekit endpoint Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 07/10] HID: apple: Add support for DockChannel HID keyboards Michael Reeves via B4 Relay
2026-09-18 11:18   ` sashiko-bot
2026-09-18 11:06 ` [PATCH v2 08/10] HID: apple: Add DockChannel HID transport driver Michael Reeves via B4 Relay
2026-09-18 11:19   ` sashiko-bot
2026-09-18 11:06 ` [PATCH v2 09/10] arm64: dts: apple: Add MTP DockChannel HID nodes Michael Reeves via B4 Relay
2026-09-18 11:06 ` [PATCH v2 10/10] arm64: dts: apple: Enable DockChannel HID on M2 and M3 laptops Michael Reeves via B4 Relay

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260918111932.3DDC21F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=dmitry.torokhov@gmail.com \
    --cc=linux-input@vger.kernel.org \
    --cc=michael.reeves077@gmail.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox