From nobody Sat Jul 25 04:30:08 2026 Received: from mail-pf1-f176.google.com (mail-pf1-f176.google.com [209.85.210.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 765F82DBF75 for ; Sat, 18 Jul 2026 03:22:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784344974; cv=none; b=oCu86u2PjZY2uY4YD3h+dgo9+DM43sbK1ILrIvljlS6c9c7WGZNB7y0PTx5w/TefSD4QiPXbnczCaUNMwtkKng5ZQ3tgmPNEJi/3eoEnYRynEv3zS2wkkYdXpYR7fzUZeZ/cWbEQW0RglJgzIzKcAmOzF26eMwB9iamsd9fHi0o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784344974; c=relaxed/simple; bh=Y/57MkOM8eRSjxGaFFLidAiIlN1hiqs1oi1tNlpENeo=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=czYdWHb7puvKRCmcK8v9/vdgFw3yrB/r0nRp6DAeb27m9jCjxT4VZPCuCBLpq42OZZ52zUzA3SXbKKGhpQ1QEutT8uL3PJPjrKe/VcfnI4Vk8w8gcERBjqTBQU4uPZJqYrPq2P+xeN0ScgGcMZAllc6Fl7I8kaJztG07x69IhVI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.210.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pf1-f176.google.com with SMTP id d2e1a72fcca58-8453427d3f4so7814225b3a.3 for ; Fri, 17 Jul 2026 20:22:50 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784344970; x=1784949770; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=KqzS/pPchzVgr+e0CaFrcL+y7UklQglkh+sPLr2Qxq8=; b=o1hD9myZVjeBJzfjrZkh4UVFtD/ei2ZP3b2COI+HghyHFOklM0QuUNlrFQIDOg/nAO AvtGePMQ1gvJ9Zg8vATkHXWSmyU4Lf7KPTWTB3Kthy2h0oV3kt9+97s/l+MvESZH5L8E xmFv5T92fwUgXJKbafcwm35RN6xC8C8JPlTNSbx1IYwkf4DEpx0SuqqIANNd/yYGoWhl YX9nQR0pyPdi5QeHFa9gb7ZYlfXlxidjcl5WmvawkEIykaoar7f9B0bfoAfeH1B1PoZ9 77igrbJk/qf1BKBY9/zePlyoodcLgrdlOFK85Z/oBX0oMb+012sh0RbiYVxGByvEP20Y Q16A== X-Forwarded-Encrypted: i=1; AHgh+Ro6O7/bANJ4dQpU2OqGeNpQNQCFkwutk7ODEfj5OJwZV+F7yxWtqPx0u6auUq8Hjg5et3J/CkANbI3XoJk=@vger.kernel.org X-Gm-Message-State: AOJu0Yz9VB7hzxbGq8wcRIkGgzoMR7tcKGBYb31eKsMx1rZHHRT0moV8 7AcEapQzqNQ6yE2SywWNdi57/Mia0scK/mZ4EpdrOTaj5QHoDvdHdwc= X-Gm-Gg: AfdE7clx6favgQMMEekaBwQC1IX5HlARHkOhE0R7rR+qafeRZRoUA8gnH0v0HTgJ/Eg vKw2BYutJ6zWUEb19QHJEeQz/RQosAe0h6BQIp/3rTHZ+AoAaj+mH+7+Jw3zcozTRZ4pyIlt/Xt Zks9QnmLFSfh18yMkQDv/68HHLfXHTGYf8pqYlcRoOEK5d2/ONoA7ZuCXxnnDAzqw9Ac9Z6czrD oRYRMMGOZo8mVKAuuGAUsiRZSYwxu4ittF1zkyG5lSwMOsIEoCNhkV3htkEk0jGiV67j9SGQdNz SmpjQB8QGEsL6IDpk9WoyuQiO/6pCGrWCeH92ineGy3ZOpnyjMwGNzXuvdNgm6cOVIBWAZcPd21 sCNGjQdfztRx3uXG5gwJnKY9/HcGIj5rsqzBPOT2XE3K3BRsroHeZTuyfndgLYx88UNIK5S4cZH ytM31xju5S7acvsmsjY6CaGEouBcJLkpCaZUvyoWx5Eiy2PdbSQaqA0kC1DZzigWC6ffJGsuD98 cHJGKVXWtr1nlw= X-Received: by 2002:a05:6a00:a111:b0:84a:32a9:a5fe with SMTP id d2e1a72fcca58-84c2948a850mr5945827b3a.36.1784344969410; Fri, 17 Jul 2026 20:22:49 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-48-72.dynamic-ip.hinet.net. [61.228.48.72]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84c2af31790sm2088157b3a.37.2026.07.17.20.22.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 20:22:49 -0700 (PDT) From: Shih-Yuan Lee To: Mark Brown Cc: linux-spi@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v8 1/2] spi: pxa2xx: disable DMA and fix runtime PM for Apple MacBook8,1 Date: Sat, 18 Jul 2026 11:22:38 +0800 Message-Id: <20260718032239.19136-2-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260718032239.19136-1-fourdollars@debian.org> References: <20260718032239.19136-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" On MacBook8,1 (early 2015 12" MacBook), the LPSS SPI controller at 00:15.4 has two related problems: DMA handshake/interrupt routing fails, and runtime PM autosuspend clock-gates the LPSS block, triggering PCIe Completion Timeouts. Move the force-PIO DMI quirk to spi-pxa2xx-pci.c (the LPSS host controller driver) to avoid layering violations in the client driver. To prevent the PCIe Completion Timeout crash when operating in PIO mode: - If DMA is disabled (either statically via the DMI quirk / module parameter or dynamically due to channel exhaustion), call pm_runtime_get_noresume() in pxa2xx_spi_probe() to hold a runtime PM reference, and release it via pm_runtime_put_noidle() in the remove/error paths. This keeps the PM count above 0 and permanently locks the device out of autosuspend, preventing userspace tools (like PowerTOP) or udev rules from overriding it. - Implement helper functions pxa2xx_spi_clk_enable() and pxa2xx_spi_clk_dis= able() to track clock state via drv_data->clk_enabled, preventing clock disable count underflows and framework warnings on resume/autosuspend error paths. - Check device status in the shared interrupt handler ssp_int() using drv_data->clk_enabled and drv_data->suspended. If the device is suspended, suspending (RPM_SUSPENDING), or clock-disabled, ssp_int() immediately returns IRQ_NONE to avoid reading unclocked MMIO registers. Using drv_data->clk_enabled instead of pm_runtime_get_if_active() =3D=3D 0 avoids returning IRQ_NONE during runtime resume (RPM_RESUMING) when the clock is already enabled, eliminating level-triggered shared interrupt storms, while remaining fully functional when CONFIG_PM is disabled. - Reorder pxa2xx_spi_probe() to register the interrupt handler (request_irq= ()) after the device clock is enabled and the suspended flag is cleared. This prevents an early shared interrupt from asserting and triggering an inter= rupt storm before the clock is active to allow clearing it. - Overhaul the driver removal sequence in pxa2xx_spi_remove(): first disabl= e SSP hardware-level interrupt generation (pxa_ssp_disable()), then set drv_data->suspended to true and call synchronize_irq() to wait for in-flight interrupt handlers to complete, free the IRQ, and only then disable the clocks. This eliminates both post-clock-disable MMIO accesses= and race windows where level-triggered interrupts could cause a storm. - In pxa2xx_spi_runtime_suspend() and pxa2xx_spi_suspend(), call pxa_ssp_di= sable() to mask interrupt generation at the hardware level before setting drv_data->suspended to true, synchronizing IRQ, and disabling the clock. - Avoid duplicate can-DMA pci_info() logging by checking the pre-computed enable_dma status in probe and passing a verbose flag to can_dma(). Link: https://bugzilla.kernel.org/show_bug.cgi?id=3D108331 Signed-off-by: Shih-Yuan Lee --- drivers/spi/spi-pxa2xx-pci.c | 37 ++++++- drivers/spi/spi-pxa2xx.c | 180 +++++++++++++++++++++++++++-------- drivers/spi/spi-pxa2xx.h | 3 + 3 files changed, 178 insertions(+), 42 deletions(-) diff --git a/drivers/spi/spi-pxa2xx-pci.c b/drivers/spi/spi-pxa2xx-pci.c index cae77ac18520..79642fd811a1 100644 --- a/drivers/spi/spi-pxa2xx-pci.c +++ b/drivers/spi/spi-pxa2xx-pci.c @@ -18,9 +18,14 @@ =20 #include #include +#include =20 #include "spi-pxa2xx.h" =20 +static bool spi_pxa2xx_force_pio; +module_param_named(force_pio, spi_pxa2xx_force_pio, bool, 0444); +MODULE_PARM_DESC(force_pio, "Force PIO mode (disables DMA) for SPI transfe= rs. ([0] =3D disabled, 1 =3D enabled)"); + #define PCI_DEVICE_ID_INTEL_QUARK_X1000 0x0935 #define PCI_DEVICE_ID_INTEL_BYT 0x0f0e #define PCI_DEVICE_ID_INTEL_MRFLD 0x1194 @@ -93,6 +98,34 @@ static void lpss_dma_put_device(void *dma_dev) pci_dev_put(dma_dev); } =20 +static const struct dmi_system_id pxa2xx_spi_pci_dmi_table[] =3D { + { + .ident =3D "Apple MacBook8,1", + .matches =3D { + DMI_MATCH(DMI_SYS_VENDOR, "Apple Inc."), + DMI_MATCH(DMI_PRODUCT_NAME, "MacBook8,1"), + }, + }, + { } +}; + +static bool pxa2xx_spi_pci_can_dma(struct pci_dev *dev, bool verbose) +{ + if (spi_pxa2xx_force_pio) { + if (verbose) + pci_info(dev, "Forcing PIO mode (disabling DMA)\n"); + return false; + } + + if (dmi_check_system(pxa2xx_spi_pci_dmi_table)) { + if (verbose) + pci_info(dev, "MacBook8,1 detected: disabling DMA to force PIO mode\n"); + return false; + } + + return true; +} + static int lpss_spi_setup(struct pci_dev *dev, struct pxa2xx_spi_controlle= r *c) { struct ssp_device *ssp =3D &c->ssp; @@ -166,7 +199,7 @@ static int lpss_spi_setup(struct pci_dev *dev, struct p= xa2xx_spi_controller *c) =20 c->dma_filter =3D lpss_dma_filter; c->dma_burst_size =3D 1; - c->enable_dma =3D 1; + c->enable_dma =3D pxa2xx_spi_pci_can_dma(dev, true); return 0; } =20 @@ -238,7 +271,7 @@ static int mrfld_spi_setup(struct pci_dev *dev, struct = pxa2xx_spi_controller *c) =20 c->dma_filter =3D lpss_dma_filter; c->dma_burst_size =3D 8; - c->enable_dma =3D 1; + c->enable_dma =3D pxa2xx_spi_pci_can_dma(dev, true); return 0; } =20 diff --git a/drivers/spi/spi-pxa2xx.c b/drivers/spi/spi-pxa2xx.c index 6291d7c2e06f..f6cc39633191 100644 --- a/drivers/spi/spi-pxa2xx.c +++ b/drivers/spi/spi-pxa2xx.c @@ -72,7 +72,12 @@ struct chip_data { #define LPSS_CAPS_CS_EN_SHIFT 9 #define LPSS_CAPS_CS_EN_MASK (0xf << LPSS_CAPS_CS_EN_SHIFT) =20 -#define LPSS_PRIV_CLOCK_GATE 0x38 +/* Offsets from drv_data->lpss_base */ +#define LPSS_PRIV_RESETS 0x04 +#define LPSS_PRIV_RESETS_IDMA BIT(2) +#define LPSS_PRIV_RESETS_FUNC 0x3 + +#define LPSS_PRIV_CLOCK_GATE 0x38 #define LPSS_PRIV_CLOCK_GATE_CLK_CTL_MASK 0x3 #define LPSS_PRIV_CLOCK_GATE_CLK_CTL_FORCE_ON 0x3 #define LPSS_PRIV_CLOCK_GATE_CLK_CTL_FORCE_OFF 0x0 @@ -189,6 +194,7 @@ static bool is_lpss_ssp(const struct driver_data *drv_d= ata) } } =20 + static bool is_quark_x1000_ssp(const struct driver_data *drv_data) { return drv_data->ssp_type =3D=3D QUARK_X1000_SSP; @@ -713,22 +719,42 @@ static void handle_bad_msg(struct driver_data *drv_da= ta) dev_err(drv_data->ssp->dev, "bad message state in interrupt handler\n"); } =20 +static int pxa2xx_spi_clk_enable(struct driver_data *drv_data) +{ + int status; + + if (drv_data->clk_enabled) + return 0; + + status =3D clk_prepare_enable(drv_data->ssp->clk); + if (status =3D=3D 0) + drv_data->clk_enabled =3D true; + + return status; +} + +static void pxa2xx_spi_clk_disable(struct driver_data *drv_data) +{ + if (drv_data->clk_enabled) { + clk_disable_unprepare(drv_data->ssp->clk); + drv_data->clk_enabled =3D false; + } +} + static irqreturn_t ssp_int(int irq, void *dev_id) { struct driver_data *drv_data =3D dev_id; u32 sccr1_reg; u32 mask =3D drv_data->mask_sr; u32 status; + int active; + irqreturn_t ret =3D IRQ_NONE; =20 - /* - * The IRQ might be shared with other peripherals so we must first - * check that are we RPM suspended or not. If we are we assume that - * the IRQ was not for us (we shouldn't be RPM suspended when the - * interrupt is enabled). - */ - if (pm_runtime_suspended(drv_data->ssp->dev)) + if (drv_data->suspended || !drv_data->clk_enabled) return IRQ_NONE; =20 + active =3D pm_runtime_get_if_active(drv_data->ssp->dev); + /* * If the device is not yet in RPM suspended state and we get an * interrupt that is meant for another device, check if status bits @@ -737,7 +763,7 @@ static irqreturn_t ssp_int(int irq, void *dev_id) */ status =3D pxa2xx_spi_read(drv_data, SSSR); if (status =3D=3D ~0) - return IRQ_NONE; + goto out_put; =20 sccr1_reg =3D pxa2xx_spi_read(drv_data, SSCR1); =20 @@ -750,7 +776,7 @@ static irqreturn_t ssp_int(int irq, void *dev_id) mask &=3D ~SSSR_TINT; =20 if (!(status & mask)) - return IRQ_NONE; + goto out_put; =20 pxa2xx_spi_write(drv_data, SSCR1, sccr1_reg & ~drv_data->int_cr1); pxa2xx_spi_write(drv_data, SSCR1, sccr1_reg); @@ -758,10 +784,19 @@ static irqreturn_t ssp_int(int irq, void *dev_id) if (!drv_data->controller->cur_msg) { handle_bad_msg(drv_data); /* Never fail */ - return IRQ_HANDLED; + ret =3D IRQ_HANDLED; + goto out_put; + } + + ret =3D drv_data->transfer_handler(drv_data); + +out_put: + if (active > 0) { + pm_runtime_mark_last_busy(drv_data->ssp->dev); + pm_runtime_put_autosuspend(drv_data->ssp->dev); } =20 - return drv_data->transfer_handler(drv_data); + return ret; } =20 /* @@ -1288,6 +1323,7 @@ int pxa2xx_spi_probe(struct device *dev, struct ssp_d= evice *ssp, drv_data->controller =3D controller; drv_data->controller_info =3D platform_info; drv_data->ssp =3D ssp; + drv_data->suspended =3D true; /* Start suspended until clock is enabled */ =20 /* The spi->mode bits understood by this driver: */ controller->mode_bits =3D SPI_CPOL | SPI_CPHA | SPI_CS_HIGH | SPI_LOOP; @@ -1330,10 +1366,6 @@ int pxa2xx_spi_probe(struct device *dev, struct ssp_= device *ssp, | SSSR_ROR | SSSR_TUR; } =20 - status =3D request_irq(ssp->irq, ssp_int, IRQF_SHARED, dev_name(dev), - drv_data); - if (status < 0) - return dev_err_probe(dev, status, "cannot get IRQ %d\n", ssp->irq); =20 /* Setup DMA if requested */ if (platform_info->enable_dma) { @@ -1351,10 +1383,22 @@ int pxa2xx_spi_probe(struct device *dev, struct ssp= _device *ssp, } } =20 + if (!platform_info->enable_dma) + pm_runtime_get_noresume(dev); + /* Enable SOC clock */ - status =3D clk_prepare_enable(ssp->clk); + status =3D pxa2xx_spi_clk_enable(drv_data); if (status) - goto out_error_dma_irq_alloc; + goto out_error_dma_alloc; + + drv_data->suspended =3D false; + + status =3D request_irq(ssp->irq, ssp_int, IRQF_SHARED, dev_name(dev), + drv_data); + if (status < 0) { + status =3D dev_err_probe(dev, status, "cannot get IRQ %d\n", ssp->irq); + goto out_error_clock_enabled; + } =20 controller->max_speed_hz =3D clk_get_rate(ssp->clk); /* @@ -1434,7 +1478,7 @@ int pxa2xx_spi_probe(struct device *dev, struct ssp_d= evice *ssp, "ready", GPIOD_OUT_LOW); if (IS_ERR(drv_data->gpiod_ready)) { status =3D PTR_ERR(drv_data->gpiod_ready); - goto out_error_clock_enabled; + goto out_error_irq_alloc; } } =20 @@ -1443,17 +1487,21 @@ int pxa2xx_spi_probe(struct device *dev, struct ssp= _device *ssp, status =3D spi_register_controller(controller); if (status) { dev_err_probe(dev, status, "problem registering SPI controller\n"); - goto out_error_clock_enabled; + goto out_error_irq_alloc; } =20 return status; =20 +out_error_irq_alloc: + free_irq(ssp->irq, drv_data); + out_error_clock_enabled: - clk_disable_unprepare(ssp->clk); + pxa2xx_spi_clk_disable(drv_data); =20 -out_error_dma_irq_alloc: +out_error_dma_alloc: pxa2xx_spi_dma_release(drv_data); - free_irq(ssp->irq, drv_data); + if (!platform_info->enable_dma) + pm_runtime_put_noidle(dev); =20 return status; } @@ -1466,16 +1514,27 @@ void pxa2xx_spi_remove(struct device *dev) =20 spi_unregister_controller(drv_data->controller); =20 - /* Disable the SSP at the peripheral and SOC level */ + /* Disable SSP interrupt generation on hardware level while clock is acti= ve */ pxa_ssp_disable(ssp); - clk_disable_unprepare(ssp->clk); =20 - /* Release DMA */ - if (drv_data->controller_info->enable_dma) - pxa2xx_spi_dma_release(drv_data); + /* Mark as suspended to prevent further IRQ handling */ + drv_data->suspended =3D true; + + /* Wait for any pending interrupt handlers to complete */ + synchronize_irq(ssp->irq); =20 /* Release IRQ */ free_irq(ssp->irq, drv_data); + + /* Safe to disable the SSP clock now */ + pxa2xx_spi_clk_disable(drv_data); + + /* Release DMA */ + if (drv_data->controller_info->enable_dma) { + pxa2xx_spi_dma_release(drv_data); + } else { + pm_runtime_put_noidle(dev); + } } EXPORT_SYMBOL_NS_GPL(pxa2xx_spi_remove, "SPI_PXA2xx"); =20 @@ -1485,16 +1544,30 @@ static int pxa2xx_spi_suspend(struct device *dev) struct ssp_device *ssp =3D drv_data->ssp; int status; =20 - status =3D spi_controller_suspend(drv_data->controller); - if (status) + status =3D pm_runtime_resume_and_get(dev); + if (status < 0) return status; =20 + status =3D spi_controller_suspend(drv_data->controller); + if (status) { + spi_controller_resume(drv_data->controller); + goto out_put; + } + + /* Disable SSP interrupt generation on hardware level while clock is acti= ve */ pxa_ssp_disable(ssp); =20 - if (!pm_runtime_suspended(dev)) - clk_disable_unprepare(ssp->clk); + /* Mark as suspended and synchronize IRQ before disabling clock */ + drv_data->suspended =3D true; + synchronize_irq(ssp->irq); =20 + + pxa2xx_spi_clk_disable(drv_data); return 0; + +out_put: + pm_runtime_put_noidle(dev); + return status; } =20 static int pxa2xx_spi_resume(struct device *dev) @@ -1504,29 +1577,56 @@ static int pxa2xx_spi_resume(struct device *dev) int status; =20 /* Enable the SSP clock */ - if (!pm_runtime_suspended(dev)) { - status =3D clk_prepare_enable(ssp->clk); - if (status) - return status; - } + status =3D pxa2xx_spi_clk_enable(drv_data); + if (status) + goto out_put; + + + /* + * Now that resets are de-asserted and registers are restored, + * it is safe to handle interrupts. + */ + drv_data->suspended =3D false; =20 /* Start the queue running */ - return spi_controller_resume(drv_data->controller); + status =3D spi_controller_resume(drv_data->controller); + if (status) { + drv_data->suspended =3D true; + synchronize_irq(ssp->irq); + pxa2xx_spi_clk_disable(drv_data); + goto out_put; + } + +out_put: + /* Let runtime PM autosuspend again if needed */ + pm_runtime_mark_last_busy(dev); + pm_runtime_put_autosuspend(dev); + + return status; } =20 static int pxa2xx_spi_runtime_suspend(struct device *dev) { struct driver_data *drv_data =3D dev_get_drvdata(dev); =20 - clk_disable_unprepare(drv_data->ssp->clk); + pxa_ssp_disable(drv_data->ssp); + drv_data->suspended =3D true; + synchronize_irq(drv_data->ssp->irq); + pxa2xx_spi_clk_disable(drv_data); return 0; } =20 static int pxa2xx_spi_runtime_resume(struct device *dev) { struct driver_data *drv_data =3D dev_get_drvdata(dev); + int status; =20 - return clk_prepare_enable(drv_data->ssp->clk); + status =3D pxa2xx_spi_clk_enable(drv_data); + if (status) + return status; + + drv_data->suspended =3D false; + return 0; } =20 EXPORT_NS_GPL_DEV_PM_OPS(pxa2xx_spi_pm_ops, SPI_PXA2xx) =3D { diff --git a/drivers/spi/spi-pxa2xx.h b/drivers/spi/spi-pxa2xx.h index 447be0369384..44f37bf9c519 100644 --- a/drivers/spi/spi-pxa2xx.h +++ b/drivers/spi/spi-pxa2xx.h @@ -72,6 +72,9 @@ struct driver_data { =20 void __iomem *lpss_base; =20 + bool suspended; + bool clk_enabled; + /* Optional slave FIFO ready signal */ struct gpio_desc *gpiod_ready; }; --=20 2.39.5 From nobody Sat Jul 25 04:30:08 2026 Received: from mail-pf1-f170.google.com (mail-pf1-f170.google.com [209.85.210.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C94B22E7378 for ; Sat, 18 Jul 2026 03:22:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784344973; cv=none; b=CVy1e9frkPzHw9l7WCsBd2Lqqf0wEg9iA1WxLDR4fNnDUgxK6h/dHMTg6ZvVRiDTHIshPrXZRB01tITO5KCA3pK27kys498F4jsav6zMEqAcXovzmeQ6pZzPX7+O5lc8DVyoNUugD/w/TgqHJ46xaAvg9Bl300JdrYy0W++v1eQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784344973; c=relaxed/simple; bh=1MuJTtWbAuPleMDlezS6XKBQ4UcAo0HPFgrqr8Ze7iQ=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=FURwICI8Mn33+EjOGa0JO4litwfd+098c0DG/86L8fS2Ef6saIpXhMSoHLPkqIeVbvi5aQKjXApYn7GOCO1ykVKktkV10mSdhLALNR3BkA+XbAYKV0BQRv0+p3wX2qoTwXf0kNyKxUYuIdpi8K2W30ZGb0bv0258/damtyCqljc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.210.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pf1-f170.google.com with SMTP id d2e1a72fcca58-845b6d9bf39so2336813b3a.1 for ; Fri, 17 Jul 2026 20:22:51 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784344971; x=1784949771; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=QXf8o0rZeClVWesXILVN9mkThfzs4A71dIFBvPFH0NU=; b=C1s9w2q//xFyTNCyl7oieLJMIOfG/M+w6lpETcYsHcL5tsGE1akt2mXA2u4EcxzqPW 6uMgWYTaCG2XNe9gLcFA0yqAI8CCzyXdOfGWILtIOKWq94D1eoK/hBXxbYFkaZaLi/cn iLhzVEL56K6m0QeFVK8xjj2rGsDCzC6iBIIbljE1qgkjqKZYm+pq28e7ax7asAD22b+x 2bDC6vUhdjmEpwo/8qeaHg5idhWN7+kOsXnFSQrGjkEnISOOOq9v8FcPScvi/guN/N2i Or6G7M8LB0KvGBqgetslvNB78UrlnXbSle9T19hwKkmvU8tpvPq/2xfffZqIrLYskiJk kwmA== X-Forwarded-Encrypted: i=1; AHgh+RpVN/h3QoOvoW+osawXAICo9Z2INS3jMPsLhAyOGMRpAQyd3nZt2Wtanv5B52oIv9LZtWssMAL3kkvIWJI=@vger.kernel.org X-Gm-Message-State: AOJu0Yyjgh/2zaXhQyKMmD3rOg5qH0dTbNbb/vO8QrWt9r4mG4Pix377 hxd7R8RzQg+hHNvPIBSYy7OxtIYwSpcKjeLHwTmZTIhrGVD6y6+Ltm8wwjuEOdVMwQ== X-Gm-Gg: AfdE7cmK39CUssawT3lvO+e9z9yXEir7pQcxHGREwjcFO+Ph5mQObhxYgXC1VZr+fUE I0T+63TcCbKYgtSCGwn9QmclSLYkGlW7b3H+n+MkF5zwJkb0nuIGHqj9sKtBpQqM7AzDmJeKAvU rp25o9LMbSRy9iRNCxsxMmsZUwNU7mDUouaXIvg9pLVKjKORYgkR2lbkCrMTWFigaqPVG/KwEft +T9/rl3T2MJ5FEkIJrAwui2Q0w/O2frcWvFSjSlWck0to/cOl18iIJa/FBqxZ/5zetm6ow9sb// bK2bHOuHfe/ENZe8Q67PbioPiwyOkloN2ExRiZOJi6la1wBMqLPqGfnyFnSyzCIyVCo1BpfDWDz yISbANBIF+7zusrInh02NOCxeZAdEhoA/xgVc7d2IEKxPZIOMYEAlYhig4oTNMEbKq6AVAbiLGR g5dX3NQ6dJQnKuQbnr5TbrUOZjnXrMlFfsATpXCWgjduiDYa6ndtFE/Eu+EUrjMdaCKMzb6EbD7 adwPxcZxcKjDTw= X-Received: by 2002:a05:6a00:2e0e:b0:847:9919:e772 with SMTP id d2e1a72fcca58-84c28aa67eemr5351884b3a.21.1784344971116; Fri, 17 Jul 2026 20:22:51 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-48-72.dynamic-ip.hinet.net. [61.228.48.72]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84c2af31790sm2088157b3a.37.2026.07.17.20.22.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 20:22:50 -0700 (PDT) From: Shih-Yuan Lee To: Mark Brown Cc: linux-spi@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v8 2/2] spi: pxa2xx: restore LPSS private register state on S3 resume Date: Sat, 18 Jul 2026 11:22:39 +0800 Message-Id: <20260718032239.19136-3-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260718032239.19136-1-fourdollars@debian.org> References: <20260718032239.19136-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Intel LPSS SPI controllers lose all private register state across S3 suspend because the LPSS power domain is fully removed. On resume the driver only re-enables the SSP clock, leaving the LPSS private registers in their power-on-reset state, which causes two problems: 1. LPSS_PRIV_RESETS (offset 0x04 within the LPSS private space) stays zero, keeping the functional block in reset. Any MMIO access while the block is held in reset causes a PCIe Completion Timeout and a watchdog-triggered system reset. LPSS_PRIV_RESETS_FUNC and LPSS_PRIV_RESETS_IDMA must be de-asserted before any other register access on resume. 2. The LPSS software chip-select control register must not be blindly restored from its suspend-time snapshot: if CS was asserted at the moment of suspend, restoring that state corrupts the first post-resume SPI transaction. Instead, call lpss_ssp_setup() which unconditionally writes SW_MODE | CS_HIGH (idle/deasserted), matching the state established at probe time. To resolve these issues safely: - Wrap S3 suspend/resume with pm_runtime_resume_and_get() and pm_runtime_put_autosuspend() respectively. This ensures that if the device was runtime-suspended, it is temporarily resumed to active state prior to suspend. This guarantees that the clock and power domain are active during MMIO register access, and that the private registers are consistently saved and restored across S3 sleep cycles. This also ensures that the unconditional MMIO register access in pxa2xx_spi_suspend() (specifically pxa_ssp_disable()) is safe from trigge= ring PCIe Completion Timeouts. - On S3 suspend success path, return 0 directly without dropping the PM reference. This preserves the acquired PM reference across suspend. On S3 resume, release it via pm_runtime_put_autosuspend(), and ensure all error paths in resume (clock enable failure or spi_controller_resume failure) jump to out_put to correctly release the reference, preventing reference count underflow and leaks. - Save and restore LPSS private registers only on LPT, BYT, and BSW platfor= ms (via helper pxa2xx_spi_need_lpss_restore()). These platforms operate dire= ctly as PCI/platform devices without parent MFD drivers (intel-lpss). For newer platforms (SPT, BXT, CNL), private registers are already saved/restored by the parent MFD driver intel-lpss.c; accessing hardcoded offsets 0x00..0x1= 4 on newer platforms where offsets 0x08/0x0c are absent/reserved causes PCIe Completion Timeouts and system freezes. - Save the first 6 LPSS private registers (offsets 0x00 to 0x14) via drv_data->lpss_base during suspend for LPT/BYT/BSW platforms. Offsets bey= ond 0x14 (except CS control at 0x18, which is re-initialised by lpss_ssp_setu= p()) are reserved/unimplemented on LPT platforms, and writing to them triggers= a PCIe Completion Timeout causing a system halt. - Clear drv_data->suspended only after de-asserting the resets and restoring the private registers on resume. This prevents shared interrupt handlers from performing unclocked/held-in-reset MMIO accesses if an interrupt fires during the resume process. - Revert drv_data->suspended to true and call synchronize_irq() on spi_controller_resume() failure to ensure subsequent interrupts do not attempt register reads after the clock is disabled. - Add spi_controller_resume() recovery to the error path of spi_controller_suspend() in pxa2xx_spi_suspend() to prevent the controller from remaining permanently disabled in the event system suspend is aborte= d. - Store the saved context in drv_data->lpss_priv_ctx[6] (inside struct driver_data) which is private to the core driver. This avoids changing the layout of struct pxa2xx_spi_controller, preventing ABI symbol version mismatches with uncompiled platform drivers (e.g., spi-pxa2xx-platform.ko). On resume, de-assert resets first, restore all other saved registers, then call lpss_ssp_setup() to re-initialise CS. Link: https://bugzilla.kernel.org/show_bug.cgi?id=3D108331 Signed-off-by: Shih-Yuan Lee --- drivers/spi/spi-pxa2xx.c | 60 ++++++++++++++++++++++++++++++++++++++++ drivers/spi/spi-pxa2xx.h | 1 + 2 files changed, 61 insertions(+) diff --git a/drivers/spi/spi-pxa2xx.c b/drivers/spi/spi-pxa2xx.c index f6cc39633191..c200930a2fc5 100644 --- a/drivers/spi/spi-pxa2xx.c +++ b/drivers/spi/spi-pxa2xx.c @@ -194,6 +194,17 @@ static bool is_lpss_ssp(const struct driver_data *drv_= data) } } =20 +static bool pxa2xx_spi_need_lpss_restore(const struct driver_data *drv_dat= a) +{ + switch (drv_data->ssp_type) { + case LPSS_LPT_SSP: + case LPSS_BYT_SSP: + case LPSS_BSW_SSP: + return true; + default: + return false; + } +} =20 static bool is_quark_x1000_ssp(const struct driver_data *drv_data) { @@ -1561,6 +1572,22 @@ static int pxa2xx_spi_suspend(struct device *dev) drv_data->suspended =3D true; synchronize_irq(ssp->irq); =20 + if (pxa2xx_spi_need_lpss_restore(drv_data)) { + unsigned int i; + + /* + * Save the first 6 LPSS private registers (offsets 0x00 to 0x14) + * while the clock is still enabled. They are lost when the LPSS + * power domain is removed across S3 and must be restored on resume. + * Use drv_data->lpss_base so the correct per-platform offset + * is applied regardless of LPSS IP revision. + * Registers beyond 0x14 (except CS control at 0x18) are reserved + * or unimplemented on LPT, and accessing them triggers a PCIe + * Completion Timeout causing a system halt. + */ + for (i =3D 0; i < 6; i++) + drv_data->lpss_priv_ctx[i] =3D readl(drv_data->lpss_base + i * 4); + } =20 pxa2xx_spi_clk_disable(drv_data); return 0; @@ -1581,6 +1608,39 @@ static int pxa2xx_spi_resume(struct device *dev) if (status) goto out_put; =20 + if (pxa2xx_spi_need_lpss_restore(drv_data)) { + unsigned int i; + + /* + * The LPSS power domain is removed across S3, taking + * all private registers with it. De-assert the + * functional block and IDMA resets first; any MMIO + * access while the block is held in reset causes a + * PCIe Completion Timeout and a watchdog-triggered + * system reset. + */ + writel(LPSS_PRIV_RESETS_FUNC | LPSS_PRIV_RESETS_IDMA, + drv_data->lpss_base + LPSS_PRIV_RESETS); + + /* Restore the other 5 saved private registers */ + for (i =3D 0; i < 6; i++) { + if (i =3D=3D LPSS_PRIV_RESETS / 4) + continue; + writel(drv_data->lpss_priv_ctx[i], + drv_data->lpss_base + i * 4); + } + } + + if (is_lpss_ssp(drv_data)) { + /* + * Re-initialise the SW chip-select control register so + * CS starts deasserted (SW_MODE | CS_HIGH), regardless + * of the state it was in at suspend time. A stale + * asserted CS on the first post-resume transaction + * corrupts the write-status response from the device. + */ + lpss_ssp_setup(drv_data); + } =20 /* * Now that resets are de-asserted and registers are restored, diff --git a/drivers/spi/spi-pxa2xx.h b/drivers/spi/spi-pxa2xx.h index 44f37bf9c519..48169494f74e 100644 --- a/drivers/spi/spi-pxa2xx.h +++ b/drivers/spi/spi-pxa2xx.h @@ -71,6 +71,7 @@ struct driver_data { irqreturn_t (*transfer_handler)(struct driver_data *drv_data); =20 void __iomem *lpss_base; + u32 lpss_priv_ctx[6]; =20 bool suspended; bool clk_enabled; --=20 2.39.5