From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 535F43E7151; Tue, 4 Aug 2026 13:38:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850707; cv=none; b=mVvXPY9rZ4JjqS/pf+iNyB9QARRAdZ3zyrHxRSRkJA0wpjq+tI3nRenv/3zW20gShjdr1pj9szB705K5znJvYQIuVfU80204A8GU8AQX4/b3fmDhLKvmTj5oSXzKBWUBE7BnNSX2ge0qJU8WQf5o0ycyQb8wU4BKV2t7zvYIPwE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850707; c=relaxed/simple; bh=/YJLMHgwJ9zZylDMc3vyUKxUIcU5EwDS9op8CsAb5/M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XpE41GKJqzwv1yxydSbgRL3gYZ2nFssCjan/5s7jzPpyZSKyQtp172RT1WosR0Ima948xrRTW08PbHAF6iiQB6SvclVz/skQ8Fwmzyjm0S/vKA4KGp276RV/kXC8zomGAZCr6d//Zb8MXe+zQyW7bKouLUySeiI1m+Xh6HusLbE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=avW6ZDFM; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="avW6ZDFM" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850704; x=1817386704; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=/YJLMHgwJ9zZylDMc3vyUKxUIcU5EwDS9op8CsAb5/M=; b=avW6ZDFMHRGWvowZuBNGuEOKErjot1y/gjDFHYwuiW4onAVDNGQjd3s3 vnqw3gLQINH1v8wbkrhXFmbM7tTeHHel+gJOaSyl/998QciJ5R6bTxiE0 3qqiXPOXppQ0evNfjjyXwv5wOHLbMMYgw5/ddndRcDm+VkK00HPITwd0P 76snr9EQoxth27riott3TjjizWDntKUvDQGDo7QKnm6YZkqdiLIvv08FA EcC8n0wWqqKSAVi4OuN/lv1prAlTsRKlGr0Aq2C71OtMRE6QEOICIdTC3 VwzAWVhoyELVPAJYzo1XbjjEFOhIsVSmxZDMXmxgg+iFtw+EgXU3AEcCq g==; X-CSE-ConnectionGUID: GDfn4uE0SkuvvdONXjiwSg== X-CSE-MsgGUID: E7d0W3LKQzerByonBBFisw== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410085" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410085" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:24 -0700 X-CSE-ConnectionGUID: 5W4UUwPxTEC+0hCehwOigg== X-CSE-MsgGUID: EToY/zfITaCxKX1ElS5jGw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501000" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:21 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 01/14] i3c: master: Fix recursive locking during device registration Date: Tue, 4 Aug 2026 16:37:57 +0300 Message-ID: <20260804133810.184905-2-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" i3c_master_register_new_i3c_devs() registers newly discovered devices while holding i3c_bus_normaluse_lock(), a down_read(). device_register() can immediately probe the device, and probe callbacks typically invoke I3C helpers that take i3c_bus_normaluse_lock() again, leading to a recursive acquisition of the same rwsem. rwsems do not support recursive read locking and can deadlock when a writer is waiting. See the "Recursive read locks" section of Documentation/locking/lockdep-design.rst. For example, with Intel LPSS I3C, LOCKDEP generates a WARNING like: # echo intel-lpss-i3c.0 > /sys/bus/platform/drivers/mipi-i3c-hci/unbind # echo intel-lpss-i3c.0 > /sys/bus/platform/drivers/mipi-i3c-hci/bind WARNING: possible recursive locking detected kworker/5:1/94 is trying to acquire lock: ffff88811c810d78 (&i3cbus->lock){++++}-{4:4}, at: i3c_device_match_id+0x4= 5/0x370 but task is already holding lock: ffff88811c810d78 (&i3cbus->lock){++++}-{4:4}, at: i3c_master_reg_work_fn+= 0x21/0x5f0 Fix this by separating device creation from device registration. Populate desc->dev under the maintenance lock, collect the devices that still need registration into a local list, then release the lock before calling device_register(). Finally retake the lock and clean up any devices that failed to register. Use the maintenance lock rather than the normal-use lock while adding device objects. A write-side maintenance lock prevents readers from observing a partially initialized desc->dev during initial device population, or desc->dev disappearing if registration fails. The local list requires a list node, so add a list node member to struct i3c_device. Fixes: 3a379bbcea0a ("i3c: Add core I3C infrastructure") Cc: stable@vger.kernel.org Signed-off-by: Adrian Hunter --- Changes in V3: Added Cc: stable@vger.kernel.org Changes in V2: New patch drivers/i3c/master.c | 45 ++++++++++++++++++++++++++++---------- include/linux/i3c/master.h | 2 ++ 2 files changed, 35 insertions(+), 12 deletions(-) diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c index f485b98805cf..d2fb1a110521 100644 --- a/drivers/i3c/master.c +++ b/drivers/i3c/master.c @@ -2069,12 +2069,21 @@ static int i3c_master_early_i3c_dev_add(struct i3c_= master_controller *master, static void i3c_master_register_new_i3c_devs(struct i3c_master_controller *master) { + struct i3c_device *i3cdev, *tmp; struct i3c_dev_desc *desc; + LIST_HEAD(i3c_unreg_devs); int ret; =20 if (!master->init_done) return; =20 + i3c_bus_maintenance_lock(&master->bus); + + if (master->shutting_down) { + i3c_bus_maintenance_unlock(&master->bus); + return; + } + i3c_bus_for_each_i3cdev(&master->bus, desc) { if (desc->dev || !desc->info.dyn_addr || desc =3D=3D master->this) continue; @@ -2104,25 +2113,37 @@ i3c_master_register_new_i3c_devs(struct i3c_master_= controller *master) if (desc->boardinfo) device_set_node(&desc->dev->dev, desc->boardinfo->fwnode); =20 - ret =3D device_register(&desc->dev->dev); - if (ret) { - dev_err(&master->dev, - "Failed to add I3C device (err =3D %d)\n", ret); - desc->dev->desc =3D NULL; - put_device(&desc->dev->dev); - desc->dev =3D NULL; - } + list_add_tail(&desc->dev->node, &i3c_unreg_devs); + } + + i3c_bus_maintenance_unlock(&master->bus); + + list_for_each_entry_safe(i3cdev, tmp, &i3c_unreg_devs, node) { + ret =3D device_register(&i3cdev->dev); + if (ret) + dev_err(&master->dev, "Failed to add I3C device (err =3D %d)\n", ret); + else + list_del_init(&i3cdev->node); + } + + i3c_bus_maintenance_lock(&master->bus); + + list_for_each_entry_safe(i3cdev, tmp, &i3c_unreg_devs, node) { + list_del(&i3cdev->node); + desc =3D i3cdev->desc; + i3cdev->desc =3D NULL; + put_device(&i3cdev->dev); + desc->dev =3D NULL; } + + i3c_bus_maintenance_unlock(&master->bus); } =20 static void i3c_master_reg_work_fn(struct work_struct *work) { struct i3c_master_controller *master =3D container_of(work, typeof(*maste= r), reg_work); =20 - i3c_bus_normaluse_lock(&master->bus); - if (!master->shutting_down) - i3c_master_register_new_i3c_devs(master); - i3c_bus_normaluse_unlock(&master->bus); + i3c_master_register_new_i3c_devs(master); } =20 /** diff --git a/include/linux/i3c/master.h b/include/linux/i3c/master.h index 2dc139a217bf..2b96c4ea75fb 100644 --- a/include/linux/i3c/master.h +++ b/include/linux/i3c/master.h @@ -238,6 +238,7 @@ struct i3c_dev_desc { * every time the I3C device is rediscovered with a different dynamic * address assigned * @bus: I3C bus this device is attached to + * @node: unregistered device list node * * I3C device object exposed to I3C device drivers. The takes care of link= ing * this object to the relevant &struct_i3c_dev_desc one. @@ -248,6 +249,7 @@ struct i3c_device { struct device dev; struct i3c_dev_desc *desc; struct i3c_bus *bus; + struct list_head node; }; =20 /* --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 60DF7463B85; Tue, 4 Aug 2026 13:38:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850709; cv=none; b=kLsiwguPDoBBSbVp4CcuyN9ipZ42qc6hTlXzYUaqweuM33QqTNvSLJa5PwrFvL3QX+7zOObWPAi9uMefwEyo3MXWZalhoyBZGHFIQpwnNSyfi4iFuaSQeBXy0oyidPfsC42TNkbsEevYLvgldbHItrv8c0gBk2uGt3GpsaQz+gk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850709; c=relaxed/simple; bh=RQeEDqRk73Kz1GwqhHPaFFYNyEP5mCXJwPZqp7MEZHA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MnZo5U2VKXVsTnkEaZYFP7q+9ibrb2oIKsXS5w26wJH4ZlHw1RkCAWRyNZ31MkNdFL0Z3qSLmP9kaoyz/kQe1TlOhmL60vPyyVbwTEzqMK+6w9LJxKHiCylLg7t3RJSzDf6y/c0oJ37Czhh5jKkXTDvv1NXi9QfiwEYkrRLJfw4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=S+9IxMc/; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="S+9IxMc/" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850706; x=1817386706; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=RQeEDqRk73Kz1GwqhHPaFFYNyEP5mCXJwPZqp7MEZHA=; b=S+9IxMc/A/yvKt06gq7SLo3ys65k7uPw5PvpbmjFehcARiZasT5OEBkG 1xbAIMVZJSO02+wtxR1CyBQGWPq6/vlcSI2Hb81T8FtvvqSaFS1/0fUgs deDvJbzRQvLLsoDIw1SeFhQqgcW/aN1qTMO6Rb2AsL2rKUFJ71Sscit/q GKL2t6QkbptaXqnnuGkxXQ7EDCVhFfrV6SjfRwxiTPpzbtW+IQyESoSrA sLIGL0FW+ni3m1AYWxIBeldYs/KRsDyTQ9YU97HqLwv9aoSXwREPJD/9k NzhaQU3Nb7zrOOLpzpperUHtGmIHeuteh83XfGjCU2Kg/ZEALMvN44yTZ g==; X-CSE-ConnectionGUID: cBY1GeqQSb2DPFk9lK+8ew== X-CSE-MsgGUID: tygP1DWbTsS4rcfvt9kWhQ== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410091" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410091" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:26 -0700 X-CSE-ConnectionGUID: cagky/0kTdWYLuQXSv/GIQ== X-CSE-MsgGUID: tBEA6V9hRsWhpmv1NdF7kw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501004" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:24 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 02/14] i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() Date: Tue, 4 Aug 2026 16:37:58 +0300 Message-ID: <20260804133810.184905-3-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" i3c_device_get_supported_xfer_mode() uses dev->desc to obtain the master controller. However, dev->desc must not be dereferenced unless bus->lock is held, and this function does not take that lock. The function only needs access to the master controller associated with the device's bus. Use dev->bus instead, which is always valid for the lifetime of the device and does not require dereferencing dev->desc. Fixes: 256a21743d91 ("i3c: Add HDR API support") Cc: stable@vger.kernel.org Signed-off-by: Adrian Hunter --- Changes in V3: New patch drivers/i3c/device.c | 2 +- drivers/i3c/internals.h | 5 +++++ drivers/i3c/master.c | 6 ------ 3 files changed, 6 insertions(+), 7 deletions(-) diff --git a/drivers/i3c/device.c b/drivers/i3c/device.c index 101eaa77de68..a3778282e84c 100644 --- a/drivers/i3c/device.c +++ b/drivers/i3c/device.c @@ -309,7 +309,7 @@ EXPORT_SYMBOL_GPL(i3c_device_match_id); */ u32 i3c_device_get_supported_xfer_mode(struct i3c_device *dev) { - return i3c_dev_get_master(dev->desc)->this->info.hdr_cap | BIT(I3C_SDR); + return i3c_bus_to_i3c_master(dev->bus)->this->info.hdr_cap | BIT(I3C_SDR); } EXPORT_SYMBOL_GPL(i3c_device_get_supported_xfer_mode); =20 diff --git a/drivers/i3c/internals.h b/drivers/i3c/internals.h index 0f1f3f766623..86a36b951e0d 100644 --- a/drivers/i3c/internals.h +++ b/drivers/i3c/internals.h @@ -72,4 +72,9 @@ static inline void i3c_readl_fifo(const void __iomem *add= r, void *buf, } } =20 +static inline struct i3c_master_controller *i3c_bus_to_i3c_master(struct i= 3c_bus *i3cbus) +{ + return container_of(i3cbus, struct i3c_master_controller, bus); +} + #endif /* I3C_INTERNAL_H */ diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c index d2fb1a110521..c7bb52b71d88 100644 --- a/drivers/i3c/master.c +++ b/drivers/i3c/master.c @@ -102,12 +102,6 @@ void i3c_bus_normaluse_unlock(struct i3c_bus *bus) up_read(&bus->lock); } =20 -static struct i3c_master_controller * -i3c_bus_to_i3c_master(struct i3c_bus *i3cbus) -{ - return container_of(i3cbus, struct i3c_master_controller, bus); -} - static struct i3c_master_controller *dev_to_i3cmaster(struct device *dev) { return container_of(dev, struct i3c_master_controller, dev); --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 03401466B0B; Tue, 4 Aug 2026 13:38:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850711; cv=none; b=X1v3BWf1Zq0iLLTZvKE3t8R4PHVjXvcIV+rNRl7zs2ND2mzSxxWr1hSkI23C3SDsELAZ2frGtSLv5W+vbxWLZwVCF2nSLKqXqLtL5mcxl6yj6cwEQGlRw6yZjpWblYd+1oqXMv+BqHjVPRrI1/TT7W+zsqk5WdrbUwyXxpjcWhg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850711; c=relaxed/simple; bh=voeBAnGBFWyl9y6fsdJxZVdFpnCWoucAS4P5V6Enbi4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Im0fkGOW8/WB1jhNN2O+JW/M0kBs+36o2jCRzHSxlLf7KJyFecgHEqMO1+u8aObcfLwCAe7n1BuNaxUX0ap4GDoE3cfYk/wmZxhpn2FNkwI/opnKRfpvlMPAKguuWVKuEBdnbnX84Wr3yh4Q64MZvgQkJ+jjKQJF8N1ztuGmt6Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=K0BG90F/; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="K0BG90F/" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850709; x=1817386709; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=voeBAnGBFWyl9y6fsdJxZVdFpnCWoucAS4P5V6Enbi4=; b=K0BG90F/ATOBzlJ83Zz2Zmu2tG9GohytGgJ+QNA2PhBWmmlnlzv8VxQQ QB3BfYKBXL5aYKYlIz6hxgZ1vvYLVfVVsySmn0d/F0euZQdD7tkM65inl lqYmAVV4pxnPsoM4leNb08IKREpoM3m2hzfBklWkpzpUJSxXsyB3skzzN CmjYGNDEs4xb4Z1v7tIyju1Ny4uMniFcwRUiHc+3K+9jcr9kV50LfbK5B Bych4c2Odq7dGRDEwHJYcSByC7qKCy6PVrsWd+gUvBNBI6z2HBy8C+Fwj zm/p3w9xquihlZcqKWbHKXmqUCK1aAZZS7yBAe4y9+RmSWkKMzqDjzeG6 w==; X-CSE-ConnectionGUID: GWudK5c9SfG8/F8EDFTBgg== X-CSE-MsgGUID: 3VoeW7YySYOShQBfgSDCbQ== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410097" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410097" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:29 -0700 X-CSE-ConnectionGUID: KlR37LwqQYGGpeUnydrrPA== X-CSE-MsgGUID: OiGhG4D/TsyUrJucXriXRg== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501008" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:26 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 03/14] i3c: master: Do not treat master device as a duplicate target Date: Tue, 4 Aug 2026 16:37:59 +0300 Message-ID: <20260804133810.184905-4-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" i3c_master_search_i3c_dev_duplicate() searches the bus for another I3C device with the same PID as the reference device. The search can match master->this, causing the controller itself to be returned as a duplicate. Since the controller is not a target device, it cannot be a duplicate of one. Exclude master->this from matching so that the function only returns real duplicate target devices. Fixes: 3a379bbcea0a ("i3c: Add core I3C infrastructure") Cc: stable@vger.kernel.org Signed-off-by: Adrian Hunter Acked-by: Mukesh Savaliya Reviewed-by: Frank Li --- Changes in V3: New patch drivers/i3c/master.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c index c7bb52b71d88..abb582645a2e 100644 --- a/drivers/i3c/master.c +++ b/drivers/i3c/master.c @@ -2545,7 +2545,8 @@ i3c_master_search_i3c_dev_duplicate(struct i3c_dev_de= sc *refdev) =20 i3c_bus_for_each_i3cdev(&master->bus, i3cdev) { if (i3cdev !=3D refdev && i3cdev->info.pid && - i3cdev->info.pid =3D=3D refdev->info.pid) + i3cdev->info.pid =3D=3D refdev->info.pid && + i3cdev !=3D master->this) return i3cdev; } =20 --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C41EB45DF72; Tue, 4 Aug 2026 13:38:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850713; cv=none; b=N4Ipyp5B6LhavRJLZgn+uiir71CuvxvYDnhHN3eB9aEW19psyPXYdyK2sxOuSo/okL5adCuZm/u7/pX0ICTqVjK9Q6A5ij0ex0q7Ag5BHwWkZMw+a7Jb083+wQ+nXb7MC/s0JOOSMwxFzuIvXa/krjzgQjS+CO4TFvPN/aBZLQg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850713; c=relaxed/simple; bh=LKC0QMMd/XJevryXpaROjCj9xdLCE4mgoSSaTfBGOkw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=EZx2XcGvFWzqzXLjTVXeSmIrGmJF+qncuvcuJsVcmvdeIhPJw8sj0bf+GICDHKTpKB6ZTQTP0oEqYJsnylq8DElSvQZEiNBs6Yk+qH9LbcPc62nqRnHiONCIJ4R0SUWNd1INQ8ogIIHlo6IzCwOCNgpR4H8bgr+wiWWz80TOzpc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=NVv3AVg3; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="NVv3AVg3" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850712; x=1817386712; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=LKC0QMMd/XJevryXpaROjCj9xdLCE4mgoSSaTfBGOkw=; b=NVv3AVg3e020crnsEVP2jDT8vB5YIOaltOYi+WYpApzckqZLuk90BNN5 uKn+NMvTuDaTG8qWRppQbwHCKdCUL2Q5SUQPvrVbmPwhQ1Da69QpkDpEb qXPpNmmORWYQwjmL2+qzsMdYC02LfvBud9p9wgFPXNrpwzJZQ9NAr0+O+ MGij1/Feo9crgpltPbgx3XutyQZRGdgOIfcJ66CbD7WW6TwGUTlIjakAL hojtu6BSFceVhIxwBse+vj8UkwHI94FhqnlEWJNjTjmINetkYMjkFjCv8 XiC6g0DdGcwliMdVm5aka12PyvKSXfnbicP+YLP7RIAIyDESBdVHRqxJc A==; X-CSE-ConnectionGUID: bXxopzvwTFG42jhZpfI2fw== X-CSE-MsgGUID: u+MdLMfkR2q46ewddF89nA== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410104" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410104" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:31 -0700 X-CSE-ConnectionGUID: YYbXWcnOQa6ckgQl8WVVmQ== X-CSE-MsgGUID: uFswiDBTSTqxPCk+c6eisw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501013" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:29 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 04/14] i3c: master: Fix use-after-free of master->this Date: Tue, 4 Aug 2026 16:38:00 +0300 Message-ID: <20260804133810.184905-5-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" sysfs attribute callbacks for the master controller device dereference master->this. However, master->this is currently freed in i3c_master_detach_free_devs(), before the master device itself is released. As a result, sysfs accesses can dereference a freed master->this pointer, leading to a use-after-free. Keep master->this alive until i3c_masterdev_release(), where all users of the master device have gone away and the associated sysfs state is being torn down. Do not free master->this as part of the normal device detach path. Fixes: 3a379bbcea0a ("i3c: Add core I3C infrastructure") Cc: stable@vger.kernel.org Signed-off-by: Adrian Hunter --- Changes in V3: New patch drivers/i3c/master.c | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c index abb582645a2e..4839c1c186eb 100644 --- a/drivers/i3c/master.c +++ b/drivers/i3c/master.c @@ -842,6 +842,11 @@ static struct attribute *i3c_masterdev_attrs[] =3D { }; ATTRIBUTE_GROUPS(i3c_masterdev); =20 +static void i3c_master_free_i3c_dev(struct i3c_dev_desc *dev) +{ + kfree(dev); +} + static void i3c_masterdev_release(struct device *dev) { struct i3c_master_controller *master =3D dev_to_i3cmaster(dev); @@ -854,6 +859,8 @@ static void i3c_masterdev_release(struct device *dev) i3c_bus_cleanup(bus); =20 fwnode_handle_put(dev->fwnode); + + i3c_master_free_i3c_dev(master->this); } =20 static const struct device_type i3c_masterdev_type =3D { @@ -1125,11 +1132,6 @@ static void i3c_device_release(struct device *dev) kfree(i3cdev); } =20 -static void i3c_master_free_i3c_dev(struct i3c_dev_desc *dev) -{ - kfree(dev); -} - static struct i3c_dev_desc * i3c_master_alloc_i3c_dev(struct i3c_master_controller *master, const struct i3c_device_info *info) @@ -2286,7 +2288,8 @@ static void i3c_master_detach_free_devs(struct i3c_ma= ster_controller *master) i3cdev->boardinfo->init_dyn_addr, I3C_ADDR_SLOT_FREE); =20 - i3c_master_free_i3c_dev(i3cdev); + if (i3cdev !=3D master->this) + i3c_master_free_i3c_dev(i3cdev); } =20 list_for_each_entry_safe(i2cdev, i2ctmp, &master->bus.devs.i2c, --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2E9BC469837; Tue, 4 Aug 2026 13:38:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850715; cv=none; b=nqvQo0MVGAbp6NP5ARxjSRHvzQwxL0jJjoRlqsKv1E2Hk+sa0IruIZeVJ+J96pPobdmdOrIYa0NiPDd3/3BnHtYnqTMaMfftyDcR/wwqKCYy2wwK5vXgnwtNsMdDkSDzHTLuU5oHfmVe0p62oyXmD2CXGQKWHIDac7JrKnm5Qoc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850715; c=relaxed/simple; bh=Z2TA/miuqxxjPRFW0ZELLHvJKfQaSPolisc0yaOn6HQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XMZM4VpYRaNkHQ0Ybs4DkAGQ9ukmz341vGCzAuZHSaxP7n1wQjofoSWPFTNB8yLJY3hTr9g+XKDC7sDJs4XGfIXxbKpyyXBjIf76td1RlYVBnl0/zDDCrL2xRf2oGjAH87gBGAzF8Oko8Ak6rNnK+PHYWPDt5zYYuQBDT7X4WR4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=DgOl2/us; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="DgOl2/us" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850714; x=1817386714; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=Z2TA/miuqxxjPRFW0ZELLHvJKfQaSPolisc0yaOn6HQ=; b=DgOl2/us84ODNibmOn6PqeEqA17hguiFvGHkjTNfqXLuvc0H661N+Ikd 34+qWtvZGcxoQ3tUETEaJsfrDbv+k64TRBSyIJR/S1AXrKv508RA2YMwt LX+rI0aDefNoj2c35m3jXhyZNWJWLuMsQwmHMEcMGJf1FNEjvUxrTLCNF 2j+0uoWp7pU3/4DXAEfyTihSFNQrdn4SsI+ksxHBebz88MO1CgCRgizEe yrxsPYV54Yp1qg+R9i9hQjQ62sTdvOsFkSQomT5sD373dDlbknmuFyWJm GXTvzAYVLmVt5sdZ90Lka1hiqv4aXQACgw8eKayVW4tzyVdGsh9SpWU3m A==; X-CSE-ConnectionGUID: NVsFN1z/S4mzOFTQvF0jfg== X-CSE-MsgGUID: SMQLua9tTaW9sO38RaHpvQ== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410114" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410114" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:34 -0700 X-CSE-ConnectionGUID: LDTB3y78Q+mtzTsATUkFTQ== X-CSE-MsgGUID: NJxJlSqeR/mCLrr2/sIvWw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501017" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:32 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 05/14] i3c: Make dev->desc locking assumptions explicit Date: Tue, 4 Aug 2026 16:38:01 +0300 Message-ID: <20260804133810.184905-6-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" i3c_device_get_info() takes the bus normal-use lock before accessing dev->desc. Under that lock, the descriptor pointer is guaranteed to be valid for the duration of the access. Remove the unnecessary NULL check on dev->desc so the code more clearly reflects the locking rules and expected descriptor lifetime. Signed-off-by: Adrian Hunter Acked-by: Mukesh Savaliya --- Changes in V3: New patch drivers/i3c/device.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/i3c/device.c b/drivers/i3c/device.c index a3778282e84c..5e6df6de0283 100644 --- a/drivers/i3c/device.c +++ b/drivers/i3c/device.c @@ -101,8 +101,7 @@ void i3c_device_get_info(const struct i3c_device *dev, return; =20 i3c_bus_normaluse_lock(dev->bus); - if (dev->desc) - *info =3D dev->desc->info; + *info =3D dev->desc->info; i3c_bus_normaluse_unlock(dev->bus); } EXPORT_SYMBOL_GPL(i3c_device_get_info); --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CFC9C466AE3; Tue, 4 Aug 2026 13:38:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850718; cv=none; b=TUdO2t5/oWrGLLg587ya4vJpH/MyVb+MtxUHzyuduOytD4Fj5ry/D5TcHRzhaQ6Acb78sSRETx9komDVgrEg+JVVWEUcWrXSxNHDQY+l0O0QwoBvSvN7Flcy05VMBoPRyYsYzpQSABnAE61NnLFatVo+03l4yoEtdubBJBoVTNA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850718; c=relaxed/simple; bh=Z/5ENodMgYfqvmrtqI5X0lDZjP+qbTBkC8CDKItDX9o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=kIgvbnT7Rmgd2AfRwznLKkKsDyYqV3tW0MWEOgE0h8Q+fTz/Njh8E1DToKyH27gQLXWkoZQr3TJVIY/Zaf/TQmwSSL9LD5mjfawQDI5d2dKHN3dzEttGwyzW24MZVZuztcCoRl8Jk8kainVuDWZQQICvT9cYfNL9E/mcFXh4opo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=GzYLg/rn; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="GzYLg/rn" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850717; x=1817386717; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=Z/5ENodMgYfqvmrtqI5X0lDZjP+qbTBkC8CDKItDX9o=; b=GzYLg/rnFPjQu+68SWehDeE+kipxfJ7jwAxHeTHwCBD/73ISKywi/TmI i9mUfZUrMfgzUrnK4Jw5WYmV7FoXBlyJj9fMiGHKGF3NIizp5u8+uqtqO IYlM1XLsr5SMIwQbcgN5zNLi2gkzqoYFhU7r7YwShNuivr68/OSxQAxEw hZjuM5H1Py6L34M9wElogADpaQ9wPgF7gBJeY+hAuTzGaMEGvHtugSXl5 aC3dgcLh+z9ssTm1pri5CsZdvkP/VQVF7pHO0r/2ZmNDRHNEGcJPxCeMr 2oCcDEf3DgiO5jSJlqn5O0NP6rMdGHLwbrOjvkYTCpLcjCfOrl7czI92G w==; X-CSE-ConnectionGUID: m3F9y7gISempnHgOesnmeA== X-CSE-MsgGUID: /2pBFceRRx292qzNq4uSLg== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410121" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410121" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:37 -0700 X-CSE-ConnectionGUID: T16+ul3uRemZyyA5RJdc5Q== X-CSE-MsgGUID: Lh9kcuOvRnm1kWEAks3TSw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501021" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:34 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 06/14] i3c: master: Fix potential UAF in i3c_device_uevent() Date: Tue, 4 Aug 2026 16:38:02 +0300 Message-ID: <20260804133810.184905-7-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" i3c_device_uevent() dereferences i3cdev->desc without holding the bus normal-use lock. Since the descriptor pointer can be replaced concurrently, including when a uevent is generated from sysfs, this can result in dereferencing a stale descriptor and lead to a use-after-free. Use i3c_device_get_info() instead, which protects access to the descriptor with the normal-use lock. Commit 6cf7b65f7029 ("i3c: Use i3cdev->desc->info instead of calling i3c_device_get_info() to avoid deadlock") replaced the accessor with a direct descriptor dereference because i3c_device_get_info() would recursively acquire bus->lock during device registration. This change depends on "i3c: master: Fix recursive locking during device registration", which moves device registration out from under bus->lock and removes the possibility of that deadlock. Without that change, restoring the i3c_device_get_info() call would reintroduce the deadlock. Fixes: 6cf7b65f7029 ("i3c: Use i3cdev->desc->info instead of calling i3c_de= vice_get_info() to avoid deadlock") Cc: stable@vger.kernel.org # requires "i3c: master: Fix recursive locking d= uring device registration" Signed-off-by: Adrian Hunter Acked-by: Mukesh Savaliya --- Changes in V3: New patch drivers/i3c/master.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c index 4839c1c186eb..947ab3c681d5 100644 --- a/drivers/i3c/master.c +++ b/drivers/i3c/master.c @@ -316,8 +316,7 @@ static int i3c_device_uevent(const struct device *dev, = struct kobj_uevent_env *e struct i3c_device_info devinfo; u16 manuf, part, ext; =20 - if (i3cdev->desc) - devinfo =3D i3cdev->desc->info; + i3c_device_get_info(i3cdev, &devinfo); manuf =3D I3C_PID_MANUF_ID(devinfo.pid); part =3D I3C_PID_PART_ID(devinfo.pid); ext =3D I3C_PID_EXTRA_INFO(devinfo.pid); --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5F7D346AA6D; Tue, 4 Aug 2026 13:38:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850720; cv=none; b=fq/g8T4/L3TvXq+2QmWZSg8H49tBm8QAOuiR4d+cPB8jfTy/tAMyqBUNoODI/O8LYHOrSZzNmw8MWdu/rMIS7qPjVGdckniS3IwNnlAPHWoA8pFAqCVc6pYw2i00jnWdMQo5sviWlvZVuoFSkrsZXtwuMnvJbro+hWokqawWSAQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850720; c=relaxed/simple; bh=5NmvrefdJdFqJwX9A5ehFBhEleFx9mtAtJU4G6VWcEI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Afy8CTLAsNTTOpKEL5DhagPJEtdl3PxFNEjoXrEWJ8dGkQ6hXyMTsNNCH68nbjIZlSK6oA8umhYi1npNZiq/Qmb+Ha+WCJv/bLc0OELU98gPJbvPBa4bwjuxGvnIYS9rrA853z0XZB9FE9TL9qoE1gpqD9RzMBLW7GUzc3+v/no= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=JrgiX1Xy; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="JrgiX1Xy" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850719; x=1817386719; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=5NmvrefdJdFqJwX9A5ehFBhEleFx9mtAtJU4G6VWcEI=; b=JrgiX1XyGep9nmD0v7xu8k8LYA6VM/IJODbodU1zGCpk4/vmtmlE8cyV iOMD1riZHFEPHWEYz37VwpP5XZUvwdx36wVPUfNN3I4TpJjHQAGV7dr6c GRRONyuAMOrCO6kGE1w0fskQ2raZI5fjwKNIRg+a8UGZmM3hBvIGDWqV8 756IBi4EteDlYTiOMAQQEfO2WL9I2T3pOE4PUyfZAhFRq0DbpFCBHazfe jAqxdxD7dvj9gBx81RO7mGJDqSc5gQT/vsL2h+YD62R/PBbumW+oAZgmZ CSaXy+o+i1RgvuBmathHD9RF4xXJ48RRVdRYYjYu1WDAC1QMLSC0Lw7so Q==; X-CSE-ConnectionGUID: 29ZzI3J4Qb2vDQDE/BHGJQ== X-CSE-MsgGUID: 04YiLBUgQauwQ8Dq55+wbg== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410128" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410128" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:39 -0700 X-CSE-ConnectionGUID: dt4O0ijsQAW1J5NR3MJFOw== X-CSE-MsgGUID: o3PUtclpQjiye19KAn9NzA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501024" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:37 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 07/14] i3c: master: Fix potential UAF in i3c_device_match() Date: Tue, 4 Aug 2026 16:38:03 +0300 Message-ID: <20260804133810.184905-8-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" i3c_device_match() dereferences i3cdev->desc without holding the bus normal-use lock. Since the descriptor pointer can be replaced concurrently, the dereference can race with descriptor replacement and result in a use-after-free. Protect access to i3cdev->desc with the normal-use lock. While the lock is held, the descriptor is guaranteed to remain valid, so the NULL check is also unnecessary and can be removed. This change depends on "i3c: master: Fix recursive locking during device registration". Prior to that change, taking the normal-use lock in i3c_device_match() could recurse on bus->lock during device registration. This fixes "i3c: master: match I3C device through DT and ACPI". Signed-off-by: Adrian Hunter --- Changes in V3: New patch drivers/i3c/master.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c index 947ab3c681d5..e7ea41007889 100644 --- a/drivers/i3c/master.c +++ b/drivers/i3c/master.c @@ -347,8 +347,10 @@ static int i3c_device_match(struct device *dev, const = struct device_driver *drv) i3cdev =3D dev_to_i3cdev(dev); i3cdrv =3D drv_to_i3cdrv(drv); =20 - if (i3cdev->desc && i3cdev->desc->boardinfo) + i3c_bus_normaluse_lock(i3cdev->bus); + if (i3cdev->desc->boardinfo) static_addr_method =3D i3cdev->desc->boardinfo->static_addr_method; + i3c_bus_normaluse_unlock(i3cdev->bus); =20 /* * SETAASA-based devices need not always have a matching ID since --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F0C64469837; Tue, 4 Aug 2026 13:38:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850724; cv=none; b=Z60B2TRQk/EJe+qp0ytWmr24x+rPdfnTcvDTKn5szyj2ISSFmgvK/nXRuZ0v4nDp/X/PGZoTdCLMk21apo6BESYXwCd8d0HTd0YnhCT6k3TPJhYRyFwzje6YeMWbGBEPU/hOPMen7wC3D/RT+ptF2xJJCxRdQyXMCWTh+cygEI0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850724; c=relaxed/simple; bh=HWQMI+wawODYOPEXCnKPsgukTVxlPA74yZ6Re2Vsr8Q=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fhauUosZnZ+n01WycMbxdRfDh2hti9F9RWk0XsJODG1G7GUt8gATqqxfYoe09zEcbDqcn3faGEANPfOiouhhcB2EObZuvG7zZO+1IXDTaE0G/phrScU7fWHhhqFiABU8Z3XJvUtJGGmGOJD/6kn5ZjkVIV1nvVO52tug74lE97E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=JRnYKRZZ; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="JRnYKRZZ" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850722; x=1817386722; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=HWQMI+wawODYOPEXCnKPsgukTVxlPA74yZ6Re2Vsr8Q=; b=JRnYKRZZwCCdDz8MKvlpz252LNrlG634OPYYgWBRA7yXVVmf72XqcC8K OIMvh/o0NXhP3C88aZxvSe1dk3N1woELs2h1s6/NJNSVYD8wXFdWuSOZ8 TX9BYlOBY7sI6r5xP6xyRFvAphvJHop25j3VZE04z1F7xcZtmHv3dgOkF RJJDeQF0RYbrdK4unZRGeluOlCrfjA+yImCiNqjiM9cbtsCdv/QKutzch n1QizbLHAkihijV7jzBN7Rt0i4qnBrOseZTCAUpPZDWY6kUsvjUCb9owh l2QT+4gD+0W7ZsfzaQyYVPXX3CROU9pPH8wofnkDnC4iMNIi8ajxkXxNG g==; X-CSE-ConnectionGUID: x8Rqd8KDRvSnwPFCxBGLzw== X-CSE-MsgGUID: KsaNzvT5QNSCBSWPmv8BHA== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410135" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410135" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:42 -0700 X-CSE-ConnectionGUID: b4EQ/XzgQrixUfSNLTCYvQ== X-CSE-MsgGUID: V4piSqSJQoe8IXa9kChn9w== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501030" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:39 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 08/14] i3c: master: Support IBI-based wakeup capability Date: Tue, 4 Aug 2026 16:38:04 +0300 Message-ID: <20260804133810.184905-9-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" An I3C controller acts as a bus controller for one or more I3C devices. If the controller can wake the system in response to an In-Band Interrupt (IBI), then any device on that bus that is capable of generating IBIs can potentially be used as a wakeup source. Add an ibi_wakeup flag to struct i3c_master_controller so controller drivers can advertise support for IBI-based wakeup. If set, mark IBI-capable I3C devices as wakeup capable when they are registered, allowing wakeup management through the standard device wakeup framework. Signed-off-by: Adrian Hunter Reviewed-by: Frank Li --- Changes in V3: None Changes in V2: Dropped the redundant #include . That header must not be included directly, and linux/device.h, which is already included, provides device_set_wakeup_capable(). drivers/i3c/master.c | 7 +++++++ include/linux/i3c/master.h | 2 ++ 2 files changed, 9 insertions(+) diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c index e7ea41007889..e6b320da475e 100644 --- a/drivers/i3c/master.c +++ b/drivers/i3c/master.c @@ -2110,6 +2110,13 @@ i3c_master_register_new_i3c_devs(struct i3c_master_c= ontroller *master) if (desc->boardinfo) device_set_node(&desc->dev->dev, desc->boardinfo->fwnode); =20 + /* + * In the case of IBI wakeup, any IBI-capable device can + * wakeup. + */ + if (master->ibi_wakeup && (desc->info.bcr & I3C_BCR_IBI_REQ_CAP)) + device_set_wakeup_capable(&desc->dev->dev, true); + list_add_tail(&desc->dev->node, &i3c_unreg_devs); } =20 diff --git a/include/linux/i3c/master.h b/include/linux/i3c/master.h index 2b96c4ea75fb..16394aca7230 100644 --- a/include/linux/i3c/master.h +++ b/include/linux/i3c/master.h @@ -523,6 +523,7 @@ struct i3c_master_controller_ops { * @hotjoin: true if the master support hotjoin * @rpm_allowed: true if Runtime PM allowed * @rpm_ibi_allowed: true if IBI and Hot-Join allowed while runtime suspen= ded + * @ibi_wakeup: IBI can wakeup the system * @shutting_down: set to true when master begins shutdown or unregister * @boardinfo.i3c: list of I3C boardinfo objects * @boardinfo.i2c: list of I2C boardinfo objects @@ -562,6 +563,7 @@ struct i3c_master_controller { unsigned int hotjoin: 1; unsigned int rpm_allowed: 1; unsigned int rpm_ibi_allowed: 1; + unsigned int ibi_wakeup: 1; bool shutting_down; struct { struct list_head i3c; --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D74C46C4AE; Tue, 4 Aug 2026 13:38:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850725; cv=none; b=rmQeEAtnEYs5pjj1I33v7oxumMVl4VltORdT5bop3En23CIZgqBdJzN2y+rpaMcqG9813sOJwm1XHeWB0bPFquQEvrHMsIHvOb5CEgLopzAxf/QM+5qjMI/zmyAqBGtHHPTyxySOGS0uJ9MC0Wq5dtBDjktXpSN6ChuxNZSo+Ho= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850725; c=relaxed/simple; bh=UaMLbZ0IzXimDx+Nc2/VUT4yVPyc/sRZ6Ky7fCkM2UA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PwXaqXlPt2iMNttI3maskN4u6DKkFmHES9nERLXS4kYU21jw+bpaXY3+sjwQ6sVYje3Ggw1iiaM6mN7fTvTcn8kqbfmgFAoTQe1J/7bApa59IcjeebZzF2k7tzd26z3dSp0iiH/npnCwZYVieNKkM6cijWIcwLLLWlq5dvrh4Dg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=elWlTu7D; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="elWlTu7D" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850725; x=1817386725; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=UaMLbZ0IzXimDx+Nc2/VUT4yVPyc/sRZ6Ky7fCkM2UA=; b=elWlTu7DqSKrIBruryIugTuxD0HVOz6klVQjz7sv0mdZqz2nmdylzOn0 MleS+ow2B4c5r2CKd/dzZJEG9mG2jWgxgCyGD4s/I68KD5T3mbZa+NgeW W8fuKZGPQOh6H0BvpIu58WuUAgR2wcZgbAnXpPjRp3tSkOEP0m0a9W1BG UfE2Q7GUwPpumI1hwPGyaQfrUhCrnzi/awGBsDnrXc4RUTyFbU6pdjgC+ 0TnSj73qm3w1OGCCzQ9LLddJcMByWxn7vNWLPFUO7g28kZi13gHDLoeY6 2kTWkfbzPkxALBj9sqkn1UPyBMOP5NGYXs+p8w9KhLxG8MsF2fcv28/Ke w==; X-CSE-ConnectionGUID: GutXkr/NS+ibP2sakxbv1A== X-CSE-MsgGUID: +M8oM0eMTXuOh/CccoQeRw== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410149" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410149" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:44 -0700 X-CSE-ConnectionGUID: wQ3+E0FYQy+92Wey6uHwCA== X-CSE-MsgGUID: 7ppwyp02T+S1JLi9peccvg== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501033" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:42 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 09/14] i3c: master: Report wakeup events for IBIs Date: Tue, 4 Aug 2026 16:38:05 +0300 Message-ID: <20260804133810.184905-10-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" An I3C device configured as a wakeup source can wake the system by generating an In-Band Interrupt (IBI). When an IBI is queued for processing, record a wakeup event for the device if wakeup is enabled. Use a 100 ms processing interval to give the I3C device driver time to process the IBI. Signed-off-by: Adrian Hunter --- Changes in V2 and V3: None drivers/i3c/master.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c index e6b320da475e..8c9e62e6f146 100644 --- a/drivers/i3c/master.c +++ b/drivers/i3c/master.c @@ -3385,6 +3385,9 @@ static void i3c_master_unregister_i3c_devs(struct i3c= _master_controller *master) } } =20 +/* Approximate time for IBI handler to run */ +#define I3C_WAKEUP_PROCESSING_TIME_MS 100 + /** * i3c_master_queue_ibi() - Queue an IBI * @dev: the device this IBI is coming from @@ -3398,6 +3401,9 @@ void i3c_master_queue_ibi(struct i3c_dev_desc *dev, s= truct i3c_ibi_slot *slot) if (!dev->ibi || !slot) return; =20 + if (device_may_wakeup(&dev->dev->dev)) + pm_wakeup_event(&dev->dev->dev, I3C_WAKEUP_PROCESSING_TIME_MS); + atomic_inc(&dev->ibi->pending_ibis); queue_work(dev->ibi->wq, &slot->work); } --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2066C46C831; Tue, 4 Aug 2026 13:38:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850729; cv=none; b=VqmpF72RgDV99yJQ/g90fLjjMHcNTqEULLigIJ7kXbRReGagta5V4JTXAOOlML4tv4YiObeN7KVbCF8S2nuu59W0UuU6vk45e5STeKqj01+1H7DnSbODV4wW0QPihqMJQ/kecRht21W3SQb0uPc6atB22bzCt0lF6q/Sz/lL5L4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850729; c=relaxed/simple; bh=epDNLfNxo0HhdOoHHk2SD/KTa8Th+00oBB7qdIaaf4Q=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=KMqJNRQVPfey9/6X/6vNvW/1psWl68KSeZ1Lp7Zvf2LbqKBoSCbe6rqJFwjOR8VPFylS5UwtRqaDmWSwU3VKdp1DqV1v6X+/yxLzEQpcXqPhSvV1wm+dCpbz4zmFrr1Ot3wBerAWQnBTYOGtCfA9PD+Fy5wTZdjELgfiWugc0hk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=VpihDY0T; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="VpihDY0T" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850727; x=1817386727; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=epDNLfNxo0HhdOoHHk2SD/KTa8Th+00oBB7qdIaaf4Q=; b=VpihDY0TbatEL5tJkTqsbvmKiuSRA84kmXQVej0SXymK7D1UMSX1z3tA 3Qsq27ShqHOWGqtOnzup/h/KB83J6nyjSTuJv05qrCNu2yZKvhLlg+IzX hjACh3lQcQYwcsHSiQMh/DEKSyhqkqem+TdevpgEYa3AOBXL00BFwGVPd +cl0+5Dqa/Lzd5WnPCF4zLsFHvWqcBYXaDJZJ8zxtQUkGftt6tU0QDPgM Yp947xmTVq73Kl/LS2RDJQE60MefNr3sdZA0L1ZpehtsA2wsbptNxyHSx r52ARGk2J0TrHnQonfY0uY6md/1/Zju/RlxsvGcLziO6oxUZ1ZSgl9jy8 Q==; X-CSE-ConnectionGUID: B3Xv6gVRRmGbYOq/w8hWZg== X-CSE-MsgGUID: V745IWAmTceQPMozg2COFw== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410158" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410158" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:47 -0700 X-CSE-ConnectionGUID: NnwHN2WpR96FBui+4ERNbg== X-CSE-MsgGUID: fkVMsxPQSNWLVdnGMMFWBw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501038" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:44 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 10/14] i3c: master: Add helper to query bus wakeup requirements Date: Tue, 4 Aug 2026 16:38:06 +0300 Message-ID: <20260804133810.184905-11-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add i3c_master_any_wakeup_enabled(), which iterates over the devices on an I3C bus and reports whether any of them are enabled for system wakeup and have IBI enabled. Controller drivers can use this helper to determine whether wakeup support must remain available while the system is suspended. Signed-off-by: Adrian Hunter --- Changes in V3: Skip the master device explicitly. Added kernel-doc noting that wakeup enablement is user space policy, so the helper is meant to be called from a system suspend callback. Changes in V2: i3c_master_any_wakeup_enabled() now also requires the device to have IBI enabled, not just system wakeup enabled, so that a device with no active IBI request does not keep PCI PME enabled. desc->ibi_lock is taken while checking. The commit message and kernel-doc are updated to match. drivers/i3c/master.c | 35 +++++++++++++++++++++++++++++++++++ include/linux/i3c/master.h | 1 + 2 files changed, 36 insertions(+) diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c index 8c9e62e6f146..baf4769f0512 100644 --- a/drivers/i3c/master.c +++ b/drivers/i3c/master.c @@ -2150,6 +2150,41 @@ static void i3c_master_reg_work_fn(struct work_struc= t *work) i3c_master_register_new_i3c_devs(master); } =20 +/** + * i3c_master_any_wakeup_enabled() - check if any device can wake the syst= em + * @master: I3C master controller + * + * Iterate over devices on the bus and return true if any device has + * system wakeup enabled and IBI enabled. + * + * Whether a device is enabled for system wakeup is user space policy, + * settable at any time through the device's power/wakeup sysfs attribute, + * so the answer is only stable once user space is frozen. Call this from + * a system suspend callback. + * + * Return: true if any device may wake the system via IBI, false otherwise. + */ +bool i3c_master_any_wakeup_enabled(struct i3c_master_controller *master) +{ + struct i3c_dev_desc *desc; + bool wakeup =3D false; + + i3c_bus_normaluse_lock(&master->bus); + i3c_bus_for_each_i3cdev(&master->bus, desc) { + if (!desc->dev || desc =3D=3D master->this || !device_may_wakeup(&desc->= dev->dev)) + continue; + guard(mutex)(&desc->ibi_lock); + if (desc->ibi && desc->ibi->enabled) { + wakeup =3D true; + break; + } + } + i3c_bus_normaluse_unlock(&master->bus); + + return wakeup; +} +EXPORT_SYMBOL_GPL(i3c_master_any_wakeup_enabled); + /** * i3c_master_dma_map_single() - Map buffer for single DMA transfer * @dev: device object of a device doing DMA diff --git a/include/linux/i3c/master.h b/include/linux/i3c/master.h index 16394aca7230..a579a2b3feeb 100644 --- a/include/linux/i3c/master.h +++ b/include/linux/i3c/master.h @@ -764,6 +764,7 @@ void i3c_generic_ibi_recycle_slot(struct i3c_generic_ib= i_pool *pool, struct i3c_ibi_slot *slot); =20 void i3c_master_queue_ibi(struct i3c_dev_desc *dev, struct i3c_ibi_slot *s= lot); +bool i3c_master_any_wakeup_enabled(struct i3c_master_controller *master); =20 struct i3c_ibi_slot *i3c_master_get_free_ibi_slot(struct i3c_dev_desc *dev= ); =20 --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ADCA446C841; Tue, 4 Aug 2026 13:38:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850731; cv=none; b=GbcD0QjPsACle237DrcwNmlGFmT59tJDUdEjGfRoxJjaS0eXyfjRLZboL8PTnhMYhOVu8yKXVwo/H8eEbsXRfNDwf5twvRYYULknv9SmbnmOEkJoztSMvKkNAoKXeB5ocvqoJxMFHjkgogZIxkd7Ap822Ty1D4OGPF51/npeDVA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850731; c=relaxed/simple; bh=ZkUaZuL70LekaMXKH0xasjz56ftvkRCLeoG4ImrPSCQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=HaeGPEz0osic9IgYMeqLNI9v5QDIPrRAHdidG6VNFGC/t/P9b4rQ9jccafhOtqQbuBFN/WM6grenhxodYDNR08sc8I72BkpkpRbAZo47Y++ZDBl21f+AiiBNF/XcwqcMtk6VED5UedlTx0Wo21edwz+N5iRh6LkMRq1n7ZAowFY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=dLjDznVi; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="dLjDznVi" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850730; x=1817386730; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=ZkUaZuL70LekaMXKH0xasjz56ftvkRCLeoG4ImrPSCQ=; b=dLjDznVihU9miDlhvR+xSgIQg0ZEsapYoUq55lECwD9ZN1+DskWszs3X y4l5zr33Cn8HFNlf+ybcjqadNkjSbXTqyxo+Y+FAw2yLXqtdIbasI7poh ovy2qeYZUvhOjVeLWHH6HRvkGOhKdbK98DOlVSydk9ZZ4rLUnhq2n1lw8 zUmePRawsguGyI2iMlww4noX16tdnnz4lvDOL5mnXvWuIy9wqZatTJdUn NCG+fPtqGkeLvhigrhO0SJuA/6j5otSw0jsM2H5XI5DWl9aGJWttgEQ1B hhLOtYBNAqnm5XvtYoQM1csJaBqik0DdmQocrgYiSshYczzGIF0ZUIs54 w==; X-CSE-ConnectionGUID: rlpNpTpeQ8exeePjtp4AcQ== X-CSE-MsgGUID: 7Y7u7I4NS1yfsXbkmdT8pw== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410167" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410167" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:50 -0700 X-CSE-ConnectionGUID: 2Xc+d9tmS8mqeONIWEnk1Q== X-CSE-MsgGUID: gVIB+3M+QgimrWrBQyQSIw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501059" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:47 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 11/14] i3c: master: Reject IBI requests from non-IBI-capable devices Date: Tue, 4 Aug 2026 16:38:07 +0300 Message-ID: <20260804133810.184905-12-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" i3c_device_request_ibi() does not verify that a device advertises IBI support before attempting to set up IBI handling. Add a check for I3C_BCR_IBI_REQ_CAP and fail with -EOPNOTSUPP when IBI support is not reported by the device. This keeps IBI setup consistent with other IBI-related functionality, such as exposing wakeup capability only for IBI-capable devices. Signed-off-by: Adrian Hunter Reviewed-by: Frank Li --- Changes in V3: Added Frank's Rev-by tag Changes in V2: None drivers/i3c/device.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/drivers/i3c/device.c b/drivers/i3c/device.c index 5e6df6de0283..f1ba363b22a1 100644 --- a/drivers/i3c/device.c +++ b/drivers/i3c/device.c @@ -204,12 +204,14 @@ int i3c_device_request_ibi(struct i3c_device *dev, return ret; =20 i3c_bus_normaluse_lock(dev->bus); - if (dev->desc) { + if (!dev->desc) { + ret =3D -ENOENT; + } else if (!(dev->desc->info.bcr & I3C_BCR_IBI_REQ_CAP)) { + ret =3D -EOPNOTSUPP; + } else { mutex_lock(&dev->desc->ibi_lock); ret =3D i3c_dev_request_ibi_locked(dev->desc, req); mutex_unlock(&dev->desc->ibi_lock); - } else { - ret =3D -ENOENT; } i3c_bus_normaluse_unlock(dev->bus); =20 --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4E58246D08B; Tue, 4 Aug 2026 13:38:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850734; cv=none; b=qtd4sMk5ZQhIv/SJ1np6m2bmr+qF78lJyeDA2/7XBE0i5P8Jn+zV57wqr3u/j7BhoRYwSrgJWmD1/OLlp/vnqVwr6YrlsJ+GuSGLQwh3nbTsXw0dVyvbIWC/IpARz2RR+qQaQeuuq3T0Tb76nbvotZhO6RhnGJJbIu25M/xLJpc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850734; c=relaxed/simple; bh=Yui0JEIkyYyZXPAqtsbqZy/EPeY64q0O+ohDv5wAbjI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=NLOQd9qrfjJT4Ey4EoCg7NffAS8kq7OECwXmZY/BysSk6YZ6E+fJGjSRyG9bjw02TQlfxWTvEJNORn2fgULKhT6rNJy5ydEZ7eDoqSwgVLy/E8PEIy0W4jOqyNcmWnTLKPaV7NKNO4rO+Hy6cSIsUFNm3a1bfOdN8HZAtgAn+nc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=ObbNqEjm; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="ObbNqEjm" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850732; x=1817386732; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=Yui0JEIkyYyZXPAqtsbqZy/EPeY64q0O+ohDv5wAbjI=; b=ObbNqEjmbC8eVJDToqaU/fOpaUZe9h8zD9cQLVSAfaD1T98+8uYnt/D/ q0ZH8xUPaXCAMem1pP3ivLatEqTYJX7W+QOlcAY+R293Xq71MblHDhHSq 57A+UYTi7gchKGAmwO1V5OrRQOmvgUHIs5VXSTm8bZj5W8K3+wT/rKB9d O9NAiMU3xUDRZ0bd0mZF6R2Inn4O66+NaNjRl3sPFQ6UW/3Ni3cSriBQ/ 77vo5RcoiAvihCrVKjZosJKgZG4YSb4Ae2Ktr6RggMJudQP6+Con6WMOc y8c5uWFxdeSnEA9GUjoSXzIEwaRfbXRpdtm9z03CLAE8vu43dsGYzFnfZ A==; X-CSE-ConnectionGUID: uqv9+H4KSaC9m4LE3rUzJw== X-CSE-MsgGUID: ff+D5jtaTmifhGEDdpFTkg== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410176" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410176" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:52 -0700 X-CSE-ConnectionGUID: iwg6wVGoShmonoIO8Y84uQ== X-CSE-MsgGUID: 7aLiYBIJRZmtCV3Vej0sDw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501065" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:50 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 12/14] i3c: mipi-i3c-hci-pci: Propagate I3C wakeup requirements to PCI Date: Tue, 4 Aug 2026 16:38:08 +0300 Message-ID: <20260804133810.184905-13-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Keep the PCI wakeup state aligned with the wakeup requirements of the devices served by the controller(s). The PCI function is the wakeup source for HCI instances exposed beneath it. However, wakeup is only needed when at least one attached I3C device is enabled as a wakeup source. During suspend, check whether any HCI instance has a wakeup-enabled I3C device and enable wakeup for the PCI function only in that case. Otherwise leave PCI wakeup disabled. Note, the suspend callback is used for both system and runtime suspend. Although this change may update the PCI wakeup state during runtime suspend, it does so only when the required wakeup state changes. Moreover, PCI wakeup-capable devices already have PME wakeup armed for runtime suspend, so changing the wakeup-enabled state does not affect runtime PM wakeup behavior. Note also, since the PCI wakeup state is derived from the wakeup configuration of the attached I3C devices, the PCI device power/wakeup sysfs attribute no longer provides independent wakeup control. Signed-off-by: Adrian Hunter --- Changes in V2 and V3: None .../master/mipi-i3c-hci/mipi-i3c-hci-pci.c | 23 +++++++++++++++++-- 1 file changed, 21 insertions(+), 2 deletions(-) diff --git a/drivers/i3c/master/mipi-i3c-hci/mipi-i3c-hci-pci.c b/drivers/i= 3c/master/mipi-i3c-hci/mipi-i3c-hci-pci.c index 5a9e2a43eff8..2b3bf6fa74f2 100644 --- a/drivers/i3c/master/mipi-i3c-hci/mipi-i3c-hci-pci.c +++ b/drivers/i3c/master/mipi-i3c-hci/mipi-i3c-hci-pci.c @@ -265,6 +265,8 @@ static bool mipi_i3c_hci_pci_is_operational(struct devi= ce *dev, bool update) struct mipi_i3c_hci_pci_pm_data { struct device *dev[INST_MAX]; int dev_cnt; + bool can_wakeup; + bool may_wakeup; }; =20 static bool mipi_i3c_hci_pci_is_mfd(struct device *dev) @@ -272,6 +274,13 @@ static bool mipi_i3c_hci_pci_is_mfd(struct device *dev) return dev_is_platform(dev) && mfd_get_cell(to_platform_device(dev)); } =20 +static bool mipi_i3c_hci_pci_any_wakeup_enabled(struct device *dev) +{ + struct i3c_hci *hci =3D dev_get_drvdata(dev); + + return i3c_master_any_wakeup_enabled(&hci->master); +} + static int mipi_i3c_hci_pci_suspend_instance(struct device *dev, void *dat= a) { struct mipi_i3c_hci_pci_pm_data *pm_data =3D data; @@ -287,6 +296,9 @@ static int mipi_i3c_hci_pci_suspend_instance(struct dev= ice *dev, void *data) =20 pm_data->dev[pm_data->dev_cnt++] =3D dev; =20 + if (pm_data->can_wakeup && mipi_i3c_hci_pci_any_wakeup_enabled(dev)) + pm_data->may_wakeup =3D true; + return 0; } =20 @@ -317,12 +329,19 @@ static int mipi_i3c_hci_pci_suspend(struct device *de= v) if (!hci->info->control_instance_pm) return 0; =20 + pm_data.can_wakeup =3D device_can_wakeup(dev); + ret =3D device_for_each_child_reverse(dev, &pm_data, mipi_i3c_hci_pci_sus= pend_instance); - if (ret) + if (ret) { for (int i =3D 0; i < pm_data.dev_cnt; i++) i3c_hci_rpm_resume(pm_data.dev[i]); + return ret; + } =20 - return ret; + if (device_may_wakeup(dev) !=3D pm_data.may_wakeup) + device_set_wakeup_enable(dev, pm_data.may_wakeup); + + return 0; } =20 static int mipi_i3c_hci_pci_resume(struct device *dev) --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E6A4046D0AD; Tue, 4 Aug 2026 13:38:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850736; cv=none; b=C9HSkx6TnG7ZvWd0rcpn2AEzfbeLwQPc/gRA4RQAZANfm18Nkzt5GSJnnk/hhRP/dChX6teQpO7MgzszTe/ppejkBxAKDUYengsEi5JYjLE7mHoeaBBVWcB5iBiRUcelalYaeyK4EWYgzj9lhphSs/KY/sCoGs1DCCMd/fMLpds= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850736; c=relaxed/simple; bh=qVCDtVw4YXVPC2Lgfv+Ullr3SJrYay9qNnR41X2bZPc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=FtUGCm9upBsQ8wE4R0y0hMrYqGmloodeAvuEFndOrJyF9QogusqHG6ydgV05IrzgZjqz/iXg77w1pBmEB4mo3J+0gyaUr1/mk+DWcw4zgoybA8ezrb6S2RkIJRbHtAkzmO8e8F8SHRUYxrZtNaPOwERpUGYNUiYkwzseU9tBSiA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=n1WH23uJ; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="n1WH23uJ" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850735; x=1817386735; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=qVCDtVw4YXVPC2Lgfv+Ullr3SJrYay9qNnR41X2bZPc=; b=n1WH23uJt/C9A8MzD2xTRBu2Nc+dNhH9gDbMT/Ust6suJEUXVN8rhsfM u/D1RbhNDOZMU/YpLAmHJvUipsXCarwVz3ppjkZKcBjX3leyOgFIZNxFO WVNDgKTtD1VgLrgLPR2bJfdfnR97H9Bfi1aMlsCfPlM3gnYe3aSKlB7wT VnnjxAy2mos3guIsxxXjPgwX3eGW4TdU5/I1F+zxAGYCpWq4axdu4iwpE Y10JqblR5jF2d5NxM1sCQ2xO7qjo4iom4/b38kHP1VG8TOCijA+YqpLL9 cfWSjoAKEL6ihXnmUAVrMaZ6BMr5+r4UDZdE7cY/C1EtSZ33KIlQvYDlp w==; X-CSE-ConnectionGUID: JPN3u7mfRbWMNpri4h49jw== X-CSE-MsgGUID: GxtXM+7DT6aZtTnJo0OriQ== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410184" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410184" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:55 -0700 X-CSE-ConnectionGUID: ZO6mh3C7R1GaEHjcXJHSPg== X-CSE-MsgGUID: xJXLWcKXTgidilOngklmhA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501068" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:52 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 13/14] i3c: mipi-i3c-hci: Factor out i3c_hci_sysdev() Date: Tue, 4 Aug 2026 16:38:09 +0300 Message-ID: <20260804133810.184905-14-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The MIPI I3C HCI driver needs to identify the underlying system device used for DMA mapping and PM operations. The logic for determining that device is currently embedded in the DMA implementation. Factor this code out into i3c_hci_sysdev() so it can be shared by other parts of the driver and keep the device-selection logic in one place. Signed-off-by: Adrian Hunter --- Changes in V2 and V3: None drivers/i3c/master/mipi-i3c-hci/core.c | 12 ++++++++++++ drivers/i3c/master/mipi-i3c-hci/dma.c | 15 +-------------- drivers/i3c/master/mipi-i3c-hci/hci.h | 2 ++ 3 files changed, 15 insertions(+), 14 deletions(-) diff --git a/drivers/i3c/master/mipi-i3c-hci/core.c b/drivers/i3c/master/mi= pi-i3c-hci/core.c index cfe9b5390b56..0212c9e984cf 100644 --- a/drivers/i3c/master/mipi-i3c-hci/core.c +++ b/drivers/i3c/master/mipi-i3c-hci/core.c @@ -15,6 +15,7 @@ #include #include #include +#include #include #include #include @@ -117,6 +118,17 @@ static inline struct i3c_hci *to_i3c_hci(struct i3c_ma= ster_controller *m) return container_of(m, struct i3c_hci, master); } =20 +/* + * Determine the device that does PM / DMA and has IOMMU setup done for it= in + * case of enabled IOMMU (for use with the DMA API). + * Such device is either "mipi-i3c-hci" platform device (OF/ACPI enumerati= on) + * parent or grandparent (PCI enumeration). + */ +struct device *i3c_hci_sysdev(struct device *dev) +{ + return dev->parent && dev_is_pci(dev->parent) ? dev->parent : dev; +} + static void i3c_hci_set_master_dyn_addr(struct i3c_hci *hci) { reg_write(MASTER_DEVICE_ADDR, diff --git a/drivers/i3c/master/mipi-i3c-hci/dma.c b/drivers/i3c/master/mip= i-i3c-hci/dma.c index 0672ed1132f8..7c2b20474130 100644 --- a/drivers/i3c/master/mipi-i3c-hci/dma.c +++ b/drivers/i3c/master/mipi-i3c-hci/dma.c @@ -15,7 +15,6 @@ #include #include #include -#include =20 #include "hci.h" #include "cmd.h" @@ -301,23 +300,11 @@ static int hci_dma_init(struct i3c_hci *hci) { struct hci_rings_data *rings; struct hci_rh_data *rh; - struct device *sysdev; u32 regval; unsigned int i, nr_rings, xfers_sz, resps_sz; unsigned int ibi_status_ring_sz, ibi_data_ring_sz; int ret; =20 - /* - * Set pointer to a physical device that does DMA and has IOMMU setup - * done for it in case of enabled IOMMU and use it with the DMA API. - * Here such device is either - * "mipi-i3c-hci" platform device (OF/ACPI enumeration) parent or - * grandparent (PCI enumeration). - */ - sysdev =3D hci->master.dev.parent; - if (sysdev->parent && dev_is_pci(sysdev->parent)) - sysdev =3D sysdev->parent; - regval =3D rhs_reg_read(CONTROL); nr_rings =3D FIELD_GET(MAX_HEADER_COUNT_CAP, regval); dev_dbg(&hci->master.dev, "%d DMA rings available\n", nr_rings); @@ -332,7 +319,7 @@ static int hci_dma_init(struct i3c_hci *hci) return -ENOMEM; hci->io_data =3D rings; rings->total =3D nr_rings; - rings->sysdev =3D sysdev; + rings->sysdev =3D i3c_hci_sysdev(hci->master.dev.parent); =20 for (i =3D 0; i < rings->total; i++) { u32 offset =3D rhs_reg_read(RHn_OFFSET(i)); diff --git a/drivers/i3c/master/mipi-i3c-hci/hci.h b/drivers/i3c/master/mip= i-i3c-hci/hci.h index b3d9803b1968..b8d2a3d680f8 100644 --- a/drivers/i3c/master/mipi-i3c-hci/hci.h +++ b/drivers/i3c/master/mipi-i3c-hci/hci.h @@ -184,6 +184,8 @@ void amd_set_resp_buf_thld(struct i3c_hci *hci); void i3c_hci_sync_irq_inactive(struct i3c_hci *hci); int i3c_hci_process_xfer(struct i3c_hci *hci, struct hci_xfer *xfer, int n= ); =20 +struct device *i3c_hci_sysdev(struct device *dev); + #define DEFAULT_AUTOSUSPEND_DELAY_MS 1000 =20 int i3c_hci_rpm_suspend(struct device *dev); --=20 2.53.0 From nobody Fri Oct 2 06:16:32 2026 Received: from mgamail.intel.com (mgamail.intel.com [198.175.65.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 81C8646D0B1; Tue, 4 Aug 2026 13:38:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=198.175.65.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850739; cv=none; b=V0oJUc6jtVa5f2+GDtZAqRuzS5A2iMNEWsMYKJw/np3ytoqIfyc9qup/JZffK8Kt/gJNWLvAt7jXFWxTHwkwOz+VwlZzYICcpqLSGo1ZV5668U/g45m060s2g9phqqtcwuwjZ3ayQsV5TUYNw9oPBB9dqwZIV6NjbCkVpbXhBjk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785850739; c=relaxed/simple; bh=fL5R1x9TZFT+HG95wJ+SGsMrSYKHX0Fo52jLM1Vj45E=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=HiuYAvhUcMMaZX6Ed+kPFF5mKD2NYHBuGwYmO8eFcRdFbzG/t6xIy0MVgBUMdZLeUEYstkvMgF8LYqcJZjho1Cjy08ORPCqMPmCmF+w3EoLzO5ccW6/ntGG3tn4JvSyFrhhNVaJeX+COV0KIE/2iZVvpK+DwRgGdOSXpgxugqO8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=bEYC1Ogn; arc=none smtp.client-ip=198.175.65.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="bEYC1Ogn" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1785850739; x=1817386739; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=fL5R1x9TZFT+HG95wJ+SGsMrSYKHX0Fo52jLM1Vj45E=; b=bEYC1OgnvbKmv1p6ZUFXB/975dfV6E2OI0pu+91PkI2M5JXtjckHB9gD SWsfOB2Xnikq+WquOSkvC7Q97QAPS8vxPArJ/uFDc4BmjeMxScFXYlwL9 kNHtYyOcGvxC/Jr/M1R1qbumKoUJhWGnfOI+BO+b/fV4kSGqhxtsX8JTC 1Ql54r6D27Qx6kf97IUO3mH3jk3rtZ6x+qU+j+RZXymx2AgsjBH/fhBYi B8aJeHCLoTt2Eyh/72sfAz8LcMVHUX2BNpoTBJ3VF2vxncHQ2pqT0KSUt zNwC9oLRZwl9HX1GsKclcBWXO4PNg3gea/3+w5onnDpP6xBBw8XMvdjiI Q==; X-CSE-ConnectionGUID: qMRvnyTAS9SXZyLYrkKGxg== X-CSE-MsgGUID: X09rv+wfQrGtn7kz5osaaQ== X-IronPort-AV: E=McAfee;i="6800,10657,11864"; a="86410195" X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="86410195" Received: from fmviesa004.fm.intel.com ([10.60.135.144]) by orvoesa109.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:57 -0700 X-CSE-ConnectionGUID: HvgyCBfORymBzck8FInXbQ== X-CSE-MsgGUID: s8v2B4aqRKuzsdG0ghgOWA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,204,1779174000"; d="scan'208";a="263501071" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.132]) by fmviesa004-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 04 Aug 2026 06:38:55 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com, rafael@kernel.org, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org, linux-pm@vger.kernel.org Subject: [PATCH V3 14/14] i3c: mipi-i3c-hci: Advertise IBI wakeup capability Date: Tue, 4 Aug 2026 16:38:10 +0300 Message-ID: <20260804133810.184905-15-adrian.hunter@intel.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260804133810.184905-1-adrian.hunter@intel.com> References: <20260804133810.184905-1-adrian.hunter@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Set master->ibi_wakeup during probe when the associated system device advertises wakeup capability, allowing the I3C core to mark IBI-capable I3C devices as wakeup capable. Tweak the comment for i3c_hci_sysdev() to mention the new usage. Signed-off-by: Adrian Hunter Reviewed-by: Frank Li --- Changes in V3: Added Frank's Rev-by tag Changes in V2: None drivers/i3c/master/mipi-i3c-hci/core.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/drivers/i3c/master/mipi-i3c-hci/core.c b/drivers/i3c/master/mi= pi-i3c-hci/core.c index 0212c9e984cf..5d92cf0645ef 100644 --- a/drivers/i3c/master/mipi-i3c-hci/core.c +++ b/drivers/i3c/master/mipi-i3c-hci/core.c @@ -120,9 +120,9 @@ static inline struct i3c_hci *to_i3c_hci(struct i3c_mas= ter_controller *m) =20 /* * Determine the device that does PM / DMA and has IOMMU setup done for it= in - * case of enabled IOMMU (for use with the DMA API). - * Such device is either "mipi-i3c-hci" platform device (OF/ACPI enumerati= on) - * parent or grandparent (PCI enumeration). + * case of enabled IOMMU (for use with the DMA API). It is also used to ch= eck + * for wakeup capability. Such device is either "mipi-i3c-hci" platform de= vice + * (OF/ACPI enumeration) parent or grandparent (PCI enumeration). */ struct device *i3c_hci_sysdev(struct device *dev) { @@ -1176,6 +1176,9 @@ static int i3c_hci_probe(struct platform_device *pdev) if (hci->quirks & HCI_QUIRK_RPM_IBI_ALLOWED) hci->master.rpm_ibi_allowed =3D true; =20 + if (device_can_wakeup(i3c_hci_sysdev(&pdev->dev))) + hci->master.ibi_wakeup =3D true; + return i3c_master_register(&hci->master, &pdev->dev, &i3c_hci_ops, false); } =20 --=20 2.53.0