Linux Watchdog driver development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Lakshay Piplani" <lakshay.piplani@nxp.com>
Cc: robh@kernel.org, conor+dt@kernel.org,
	"Alexandre Belloni" <alexandre.belloni@bootlin.com>,
	linux-rtc@vger.kernel.org, devicetree@vger.kernel.org,
	linux-watchdog@vger.kernel.org
Subject: Re: [PATCH v6 3/5] rtc: pcf85363: add timestamp support with configurable timestamp mode
Date: Mon, 14 Sep 2026 09:35:19 +0000	[thread overview]
Message-ID: <20260914093519.AE6111F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260914092126.3757418-3-lakshay.piplani@nxp.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] An I2C read error during event collection causes an early return, bypassing hardware flag clearance. Combined with returning IRQ_HANDLED, this leads to an infinite interrupt storm.
--

commit 71137d386eeb017385125a0418e12cdc1cafbbf2
Author: Lakshay Piplani <lakshay.piplani@nxp.com>

rtc: pcf85363: add timestamp support with configurable timestamp mode

Add support for the timestamp capture registers on PCF85263/PCF85363,
which latch the time on selected events (TS pin or battery switch-over).
The capture source is selected via the nxp,timestamp-mode device tree
property and latched values are exported through read-only sysfs
attributes, refreshed on read so poll-only boards still latch events.

> diff --git a/drivers/rtc/rtc-pcf85363.c b/drivers/rtc/rtc-pcf85363.c
> index c8c04312bc583..5cc854d617f3a 100644
> --- a/drivers/rtc/rtc-pcf85363.c
> +++ b/drivers/rtc/rtc-pcf85363.c

[ ... ]

> +static int pcf85363_collect_events(struct pcf85363 *pcf85363)
>  {
>  	unsigned int flags;
>  	int handled = 0;
> -	int ret;
> +	int i, ret;
>  
>  	ret = regmap_read(pcf85363->regmap, CTRL_FLAGS, &flags);
>  	if (ret)
>  		return ret;
>  
> +	for (i = 0; i < PCF85363_NUM_TS; i++) {
> +		if (!(flags & pcf85363_ts_flag[i]))
> +			continue;
> +
> +		if (pcf85363->ts_last_event[i]) {
> +			ret = pcf85363_clear_flags(pcf85363,
> +						   pcf85363_ts_flag[i]);

[ ... ]

> +		} else {
> +			ret = regmap_bulk_read(pcf85363->regmap,
> +					       pcf85363_ts_base[i],
> +					       pcf85363->ts[i].regs,
> +					       PCF85363_TS_LEN);
> +			if (ret)
> +				return ret;

[Severity: High]
If this bulk read fails, the function returns early, bypassing the call to
pcf85363_clear_flags() below and leaving the interrupt asserted in the
hardware. Is it possible for this early return to create a persistent
interrupt condition?

> +
> +			pcf85363->ts[i].valid = true;
> +
> +			ret = pcf85363_clear_flags(pcf85363,
> +						   pcf85363_ts_flag[i]);
> +			if (ret)
> +				return ret;
> +
> +			handled |= pcf85363_ts_flag[i];
> +		}
> +	}
> +

[ ... ]

> @@ -359,7 +488,7 @@ static irqreturn_t pcf85363_rtc_handle_irq(int irq, void *dev_id)
>  		handled = true;
>  	}
>  
> -	if (flags & FLAGS_BSF) {
> +	if (flags & (FLAGS_TSR1F | FLAGS_TSR2F | FLAGS_TSR3F | FLAGS_BSF)) {
>  		guard(mutex)(&pcf85363->lock);
>  
>  		err = pcf85363_collect_events(pcf85363);
> @@ -368,8 +497,8 @@ static irqreturn_t pcf85363_rtc_handle_irq(int irq, void *dev_id)
>  					    "failed to collect events: %d\n",
>  					    err);
>  		/*
> -		 * This is our interrupt source even if servicing it hit an
> -		 * I/O error, so acknowledge the interrupt either way.
> +		 * These are our interrupt sources even if servicing them hit
> +		 * an I/O error, so acknowledge the interrupt either way.
>  		 */
>  		handled = true;
>  	}

[Severity: High]
By unconditionally setting handled = true even after an I/O error, the
handler returns IRQ_HANDLED while the hardware interrupt line might still be
asserted (since pcf85363_collect_events() bails out early on a read error
without clearing the flags).

For a level-triggered interrupt, doesn't returning IRQ_HANDLED without clearing
the source circumvent the kernel's spurious IRQ detector (which relies on
IRQ_NONE to mask stuck interrupts)?

Could this result in an infinite interrupt storm that will peg a CPU core?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260914092126.3757418-1-lakshay.piplani@nxp.com?part=3

  reply	other threads:[~2026-09-14  9:35 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-14  9:21 [PATCH v6 1/5] dt-bindings: rtc: nxp,pcf85363: add timestamp mode config Lakshay Piplani
2026-09-14  9:21 ` [PATCH v6 2/5] rtc: pcf85363: support reporting battery switch-over via RTC_VL Lakshay Piplani
2026-09-14  9:32   ` sashiko-bot
2026-09-14  9:21 ` [PATCH v6 3/5] rtc: pcf85363: add timestamp support with configurable timestamp mode Lakshay Piplani
2026-09-14  9:35   ` sashiko-bot [this message]
2026-09-14  9:21 ` [PATCH v6 4/5] rtc: pcf85363: add oscillator offset calibration support Lakshay Piplani
2026-09-14  9:26   ` sashiko-bot
2026-09-14  9:21 ` [PATCH v6 5/5] rtc: pcf85363: add watchdog support with configurable step size Lakshay Piplani
2026-09-14  9:37   ` sashiko-bot
2026-09-14  9:25 ` [PATCH v6 1/5] dt-bindings: rtc: nxp,pcf85363: add timestamp mode config sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260914093519.AE6111F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=alexandre.belloni@bootlin.com \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=lakshay.piplani@nxp.com \
    --cc=linux-rtc@vger.kernel.org \
    --cc=linux-watchdog@vger.kernel.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox