From nobody Tue Sep 29 06:46:55 2026 Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 58AF033D6CA for ; Tue, 11 Aug 2026 13:57:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786456648; cv=none; b=RckMZDxo5L3krIUDjx4S+jq4QHWYxIU4N2EGIsdysvyjkEuupdKKmqEXk9JhDvpcm4dgfQ67OUoKkmO7H+5QWvQI1LvteJb1GNXOaZDWtteCQX2Fk8bIUPp2NP9tSx3JfIjUSSP9/nsJm/DBvn9fB1BH5pJOSZ6Duif9kY39B3Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786456648; c=relaxed/simple; bh=r717KXPZHq0AeGzjZcDnH3nuDhjxd5wlCgI0fcKPl7k=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CQcDHd72spidcx9WNWS0Bwu/SSzBM33MEAdReyS6Dg7j5M//FzIQ+BRR4u/Vn8C8V8kNcE3jJBj2PGlYSfEbaHjZEzmneR3BfhK3/e5oiPk7aToJ29IuSKuWH9s3/J6faVdQLdeZFnkLmGJFCJOGjBUvTvtS9FlDUdedqWMGB60= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=rYhGaGDR; arc=none smtp.client-ip=209.85.128.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="rYhGaGDR" Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-490cf322ed0so25142105e9.1 for ; Tue, 11 Aug 2026 06:57:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786456644; x=1787061444; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/LP+rqxzXW4o8Xbx0YIINob+HrBwNhW+3kF26O6H66E=; b=rYhGaGDRUiNFMiwoFipIugE5QdFDKR0RONGmjyNg1bzD2QtdIB9Qro7JvIX9eQwWdI 06GTt93Hz4tY2D4gaql9uwyB5Py/caKugwTstEnrznTs/cF4JMBO/DUEwhe+4YE7Q1p0 2rSrFyUyv07yGAaScIaST0tK+xPKvEc5Tp7wVFK203Ro3YQdv3LOuTi9TBoaTGX8UWlO znrLNc+XfIt5UbF9g5kRWqFebfLkOpDEDa6vf4HmJ9IfIHOD9ZARC2/GMt2RBb5mBtts fyoU8EG3NTjlw9voFIVNszw37OiusY4uxNJVWbqHVyWtFhMCn7xaoMMXryfrsob32oj+ Jqhg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786456644; x=1787061444; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/LP+rqxzXW4o8Xbx0YIINob+HrBwNhW+3kF26O6H66E=; b=Gird93F77Xv47guEJ4jPKXh43T0BdveURAeFoUgMMjbCwKX41MX2iRm9oXbr8oQHPh 90MXik27Dc/qSnVknOR/Gbd+P3gh9G8u1dJA29tFukvk7uF0ATVYtgY5kVWqWNB0GULM TCaa/6Ku+15nVMqsqPQMHAYjPVSdejiBCimJUM4esByDERsTcjDQlesEQXYCMCZIXqWv m6A6QNONYf+0A+59sPRe1QCMhZvk4KVjoOw9PQlU5LEKuV1jz15GD2/hlaTfw3sVl309 YHGzeugpbA5TqD0bUk45M83LaslkJ5tNiG1jlqsjZLEB3TeDeJ4ILOwjuoAOMQpX9uq6 MvvQ== X-Forwarded-Encrypted: i=1; AHgh+RoA6UeDGOjCx81HLC0mAqfuTdsn/32feK7k5SdFipYxTcfPpTtlSn0XFDdPoC30duCrQd4Fw+QdIhCFzyg=@vger.kernel.org X-Gm-Message-State: AOJu0Yy7MA1/pAUcxox/1YhlE3W/4424SUEgxgMiHkOxcy99LaAIb41M L+QbJuHZUp5zlyBJ4coxLOMdJx2jZejxB+RTzg1nn7GXjgwlD3DDaY/x X-Gm-Gg: AR+sD12z6MSi5wx9V+Ekpo/QvK9pesiL5KbeHaY+tym1y+OsA/3zrEkgZfMuqinc6Ta jhs/mKUEt6qGlXiMT7Fj739NTzCgYbbp9BDSphs1nbObafUoFT6KkXL69ilFmYSq1X3F0jsVSdS F1MkVxz557sh9XwrRhxXWWigExqM5pz6S6FV6nxXmf7ojZM5NRbIGeiv/cKEvyIFfGArT8DN/eq EjPeGJuR3Byzo5qtU1XE+mSkvO9ipvPO3pJjDiLUhnryEoPG3h0HA32ANM+QB9HMdDX2u6pgKX+ 0H94yn8bs7wpnyfOi/CHosvKvRi/Tm4Tmwv0ndW/fLmoCTzlAa/PHjxSVrupiDXB80UvlgmpZU/ sNp26BSiylaJzzkDMSXlpcQtaaH88AOYFYjunlUezFVKIRzEXexZp7a9VxTeG0xU/PR+xCmmuBQ xnlajZFepZZvTewab6eLh9ZabvwqU3UObXfxJKumSzwX4bJY7cN4SZPpVP9A/60eXnTf+FGdZyB 1LZ0hs4n6wz6BuiKqPgo8S22tdd4M7pH9ty X-Received: by 2002:a05:600c:1d24:b0:495:503f:cf9a with SMTP id 5b1f17b1804b1-49978460326mr53149385e9.9.1786456644236; Tue, 11 Aug 2026 06:57:24 -0700 (PDT) Received: from fedora.advaoptical.com ([82.166.23.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499788a6cdfsm34095085e9.6.2026.08.11.06.57.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 06:57:23 -0700 (PDT) From: Sagi Maimon To: netdev@vger.kernel.org Cc: vadim.fedorenko@linux.dev, richardcochran@gmail.com, kuba@kernel.org, andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Sagi Maimon Subject: [PATCH net-next v11 1/2] ptp: ocp: add TAP CPLD access for ADVA TimeCard X1 Date: Tue, 11 Aug 2026 16:57:19 +0300 Message-ID: <20260811135720.109580-2-maimon.sagi@gmail.com> X-Mailer: git-send-email 2.47.0 In-Reply-To: <20260811135720.109580-1-maimon.sagi@gmail.com> References: <20260811135720.109580-1-maimon.sagi@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The ADVA TimeCard X1 (PCI device 0x0410) carries a Lattice MachXO3 CPLD on the TMC I2C bus. The card has two I2C controllers: Linux registers only the one at 0x00150000, normally routed to the config EEPROMs, while the one at 0x00120000 belongs to the on-card MicroBlaze and is routed to either the TMC or the M.2 bus as its firmware selects. A request/grant handshake re-routes the host controller from the EEPROM segment onto the TMC bus, leaving the MicroBlaze with M.2 only. The PCA9548 at 0x74 and the CPLD at 0x40 behind its channel 0 are reachable from the host only while that grant is held. Add the arbitration and the read-only interfaces built on it. Because the handshake changes what the host adapter is wired to, an operation takes the i2c core adapter lock for the whole grant window and uses __i2c_transfer() internally; without that, a concurrent transfer from ptp_ocp_read_eeprom(), from the nvmem attributes or from the at24 sysfs files would be issued onto the TMC bus instead of to the EEPROM. The Lattice device ID is a fixed property of the part, so report it as the fixed devlink version "cpld.id" rather than as a sysfs attribute, and cache it so the arbitration is paid once per card. Add one X1-only attribute: /sys/class/timecard/ocpN/cpld_status report the CPLD status register, including the DONE, BUSY and FAILED indicators A read arbitrates for the shared bus and reprograms the on-card mux, so it is root-only and takes cpld_lock interruptibly. Signed-off-by: Sagi Maimon --- Documentation/ABI/testing/sysfs-timecard | 19 ++ drivers/ptp/ptp_ocp.c | 344 ++++++++++++++++++++++- 2 files changed, 359 insertions(+), 4 deletions(-) diff --git a/Documentation/ABI/testing/sysfs-timecard b/Documentation/ABI/t= esting/sysfs-timecard index 3ae41b7634ac..26a93cee0b89 100644 --- a/Documentation/ABI/testing/sysfs-timecard +++ b/Documentation/ABI/testing/sysfs-timecard @@ -11,6 +11,25 @@ Contact: Jonathan Lemon Description: This directory contains the attributes of the Nth timecard registered. =20 +What: /sys/class/timecard/ocpN/cpld_status +Date: July 2026 +Contact: Sagi Maimon +Description: (RO, root only) The status register of the TAP CPLD, in + human-readable form: + + done=3D<0|1> busy=3D<0|1> failed=3D<0|1> + + Only present on ADVA x1 TAP boards (PCI ID 0xad5a:0x0410). + + done=3D1 indicates the configuration flash was successfully + programmed and is active. busy=3D1 means an internal operation + is in progress. failed=3D1 means the last ISC operation failed. + + A read arbitrates for the shared I2C bus and reprograms the + on-card mux, so it is restricted to root. The Lattice device + ID of the CPLD is reported as the fixed "cpld.id" version by + devlink dev info. + What: /sys/class/timecard/ocpN/available_clock_sources Date: September 2021 Contact: Jonathan Lemon diff --git a/drivers/ptp/ptp_ocp.c b/drivers/ptp/ptp_ocp.c index 3d26ec1f7b9e..41a7fde1ae6a 100644 --- a/drivers/ptp/ptp_ocp.c +++ b/drivers/ptp/ptp_ocp.c @@ -24,6 +24,8 @@ #include #include #include +#include +#include =20 #define PCI_DEVICE_ID_META_TIMECARD 0x0400 =20 @@ -85,6 +87,7 @@ struct ptp_ocp_adva_info { u8 signals_nr; u8 freq_in_nr; const struct ocp_attr_group *attr_groups; + bool has_cpld; /* x1: supports CPLD firmware upload */ }; =20 #define OCP_CTRL_ENABLE BIT(0) @@ -163,7 +166,8 @@ struct gpio_reg { u32 gpio1; u32 __pad0; u32 gpio2; - u32 __pad1; + /* adva_x1: I2C bus ownership register; reserved on other variants */ + u32 i2c_bus_ctrl; }; =20 struct irig_master_reg { @@ -416,6 +420,12 @@ struct ptp_ocp { dpll_tracker tracker; int signals_nr; int freq_in_nr; + /* adva_x1 CPLD I2C (internal use only) */ + struct mutex cpld_lock; /* serialises CPLD operations */ + int cpld_i2c_adap_nr; /* I2C adapter nr; -1 if absent */ + struct i2c_adapter *cpld_adap; /* claimed adapter; valid under = cpld_lock */ + u32 cpld_id; /* cached Lattice device ID; 0 if unread */ + bool has_cpld; /* x1 TAP CPLD present */ }; =20 #define OCP_REQ_TIMESTAMP BIT(0) @@ -451,6 +461,7 @@ static int ptp_ocp_adva_board_init(struct ptp_ocp *bp, = struct ocp_resource *r); =20 static const struct ocp_sma_op ocp_adva_sma_op; static const struct ocp_sma_op ocp_adva_x1_sma_op; +static int adva_x1_cpld_device_id(struct ptp_ocp *bp, u32 *id); =20 static const struct ocp_attr_group fb_timecard_groups[]; =20 @@ -1273,6 +1284,7 @@ static struct ocp_resource ocp_adva_x1_resource[] =3D= { .signals_nr =3D 4, .freq_in_nr =3D 4, .attr_groups =3D adva_timecard_x1_groups, + .has_cpld =3D true, }, }, { } @@ -2185,6 +2197,19 @@ ptp_ocp_devlink_info_get(struct devlink *devlink, st= ruct devlink_info_req *req, if (err) return err; =20 + if (bp->has_cpld) { + u32 id; + + err =3D adva_x1_cpld_device_id(bp, &id); + if (err) + return err; + + sprintf(buf, "0x%08x", id); + err =3D devlink_info_version_fixed_put(req, "cpld.id", buf); + if (err) + return err; + } + return 0; } =20 @@ -3199,6 +3224,7 @@ ptp_ocp_adva_board_init(struct ptp_ocp *bp, struct oc= p_resource *r) return err; ptp_ocp_sma_init(bp); =20 + bp->has_cpld =3D info->has_cpld; return ptp_ocp_init_clock(bp, &info->servo); } =20 @@ -4226,6 +4252,298 @@ static const struct ocp_attr_group art_timecard_gro= ups[] =3D { { }, }; =20 +/* + * Internal helpers for the adva_x1 TAP CPLD (Lattice LCMXO3LF-2100). + * + * The card has two I2C controllers; Linux registers only 0x00150000. + * The i2c_bus_ctrl handshake re-routes what each one is wired to: + * + * grant 0: 0x150000 -> EEPROMs 0x120000 -> TMC or M.2, MB's choice + * grant 1: 0x150000 -> TMC bus 0x120000 -> M.2 + * + * The PCA9548 at 0x74 and the CPLD at 0x40 behind its channel 0 sit on + * the TMC bus, so they are reachable only while the grant is held. For + * that same window the EEPROMs are not behind the adapter at all, so a + * CPLD operation holds cpld_lock and the i2c adapter lock across it to + * keep the EEPROM and nvmem paths off the controller. + * + * No raw I2C access is exposed to userspace, only the attributes below. + */ + +#define ADVA_MUX_ADDR 0x74 +#define ADVA_CPLD_ADDR 0x40 +#define ADVA_MUX_CHANNEL 0 + +#define MBLAZE_REQUEST 0x0000aaaaU +#define MBLAZE_GRANTED 0x5555aaaaU +#define MBLAZE_RELEASE 0x55550000U +#define MBLAZE_RETRIES 200 +#define MBLAZE_RETRY_US 10000 + +/* Lattice LCMXO3LF ISC command codes */ +#define CPLD_CMD_READ_ID 0xE0000000UL +#define CPLD_CMD_READ_STATUS 0x3C000000UL + +/* Status register bit positions (Lattice LCMXO3LF datasheet) */ +#define CPLD_STATUS_DONE BIT(8) +#define CPLD_STATUS_BUSY BIT(12) +#define CPLD_STATUS_FAILED BIT(13) + +/* + * adva_x1_i2c_xfer() - issue a single I2C transaction on the TMC bus. + * + * All buffers are heap-allocated internally to guarantee DMA safety for + * the Xilinx I2C controller. Caller must hold the claim taken by + * adva_x1_bus_claim(), hence __i2c_transfer() rather than i2c_transfer(). + */ +static int adva_x1_i2c_xfer(struct ptp_ocp *bp, + u8 addr, const void *wdata, u8 wlen, + void *rdata, u8 rlen) +{ + u8 *wbuf =3D NULL, *rbuf =3D NULL; + struct i2c_adapter *adap; + struct i2c_msg msgs[2]; + int nmsgs =3D 0, ret; + + lockdep_assert_held(&bp->cpld_lock); + + adap =3D bp->cpld_adap; + if (!adap) + return -ENODEV; + + if (wlen) { + wbuf =3D kmemdup(wdata, wlen, GFP_KERNEL); + if (!wbuf) { + ret =3D -ENOMEM; + goto free; + } + msgs[nmsgs++] =3D (struct i2c_msg){ + .addr =3D addr, + .flags =3D I2C_M_DMA_SAFE, + .len =3D wlen, + .buf =3D wbuf, + }; + } + if (rlen) { + rbuf =3D kzalloc(rlen, GFP_KERNEL); + if (!rbuf) { + ret =3D -ENOMEM; + goto free; + } + msgs[nmsgs++] =3D (struct i2c_msg){ + .addr =3D addr, + .flags =3D I2C_M_RD | I2C_M_DMA_SAFE, + .len =3D rlen, + .buf =3D rbuf, + }; + } + + ret =3D __i2c_transfer(adap, msgs, nmsgs); + if (ret =3D=3D nmsgs) { + if (rdata && rlen) + memcpy(rdata, rbuf, rlen); + ret =3D 0; + } else { + ret =3D (ret < 0) ? ret : -EIO; + } +free: + kfree(wbuf); + kfree(rbuf); + return ret; +} + +static void adva_x1_mblaze_release(struct ptp_ocp *bp) +{ + if (bp->pps_select) + iowrite32(MBLAZE_RELEASE, &bp->pps_select->i2c_bus_ctrl); +} + +/* Acquire the shared I2C bus from the MicroBlaze firmware. Returns with = no + * request outstanding on failure, so the firmware is never left granting a + * segment to a host that has given up waiting for it. + */ +static int adva_x1_mblaze_acquire(struct ptp_ocp *bp) +{ + u32 val; + int i; + + if (!bp->pps_select) + return -ENODEV; + + /* Drop a request left by a caller that died mid-sequence; cpld_lock + * keeps live ones out. The read back only flushes the posted write. + */ + iowrite32(0, &bp->pps_select->i2c_bus_ctrl); + ioread32(&bp->pps_select->i2c_bus_ctrl); + + iowrite32(MBLAZE_REQUEST, &bp->pps_select->i2c_bus_ctrl); + for (i =3D 0; i < MBLAZE_RETRIES; i++) { + usleep_range(MBLAZE_RETRY_US, MBLAZE_RETRY_US + 1000); + val =3D ioread32(&bp->pps_select->i2c_bus_ctrl); + if (val =3D=3D MBLAZE_GRANTED) + return 0; + } + + adva_x1_mblaze_release(bp); + return -ETIMEDOUT; +} + +/* Route the host controller back to the EEPROMs and release the adapter. + * Safe after a failed claim: it also clears a request that was never gran= ted. + */ +static void adva_x1_bus_release(struct ptp_ocp *bp) +{ + struct i2c_adapter *adap =3D bp->cpld_adap; + + if (!adap) + return; + + adva_x1_mblaze_release(bp); + bp->cpld_adap =3D NULL; + i2c_unlock_bus(adap, I2C_LOCK_ROOT_ADAPTER); + i2c_put_adapter(adap); +} + +/* + * Claim the TMC bus for a CPLD operation. Holding the adapter lock over + * the handshake keeps ptp_ocp_read_eeprom(), the nvmem attributes and the + * at24 sysfs files off the controller while it is routed away from the + * EEPROMs. + */ +static int adva_x1_bus_claim(struct ptp_ocp *bp) +{ + struct i2c_adapter *adap; + int ret; + + lockdep_assert_held(&bp->cpld_lock); + + adap =3D i2c_get_adapter(READ_ONCE(bp->cpld_i2c_adap_nr)); + if (!adap) + return -ENODEV; + + i2c_lock_bus(adap, I2C_LOCK_ROOT_ADAPTER); + bp->cpld_adap =3D adap; + + ret =3D adva_x1_mblaze_acquire(bp); + if (ret) + adva_x1_bus_release(bp); + + return ret; +} + +/* Select a mux channel, or deselect all with ch < 0 - the power-on state. + * The mux is on the TMC bus, so what it is left set to never affects the + * EEPROM paths. + */ +static int adva_x1_mux_select(struct ptp_ocp *bp, int ch) +{ + u8 val =3D (ch >=3D 0) ? BIT(ch) : 0; + + return adva_x1_i2c_xfer(bp, ADVA_MUX_ADDR, &val, 1, NULL, 0); +} + +/* + * Send a 4-byte command then read data back without an intermediate STOP + * (Lattice combined write->repeated-START->read). Two messages in one + * transfer is exactly that, so no protocol-mangling flag is needed. + */ +static int adva_x1_cpld_cmd_read(struct ptp_ocp *bp, + u32 cmd_be, u8 *out, u8 out_len) +{ + __be32 cmd =3D cpu_to_be32(cmd_be); + + return adva_x1_i2c_xfer(bp, ADVA_CPLD_ADDR, &cmd, 4, out, out_len); +} + +static int adva_x1_cpld_read_status(struct ptp_ocp *bp, u32 *status) +{ + u8 buf[4]; + int ret; + + ret =3D adva_x1_cpld_cmd_read(bp, CPLD_CMD_READ_STATUS, buf, 4); + if (ret) + return ret; + *status =3D get_unaligned_be32(buf); + return 0; +} + +/* + * Read the Lattice device ID of the TAP CPLD. It is a fixed property of + * the part, so cache it and pay the bus arbitration only once. The + * LCMXO3LF-2100 reports 0x612BC043. + */ +static int adva_x1_cpld_device_id(struct ptp_ocp *bp, u32 *id) +{ + u8 data[4]; + int ret; + + if (bp->cpld_id) { + *id =3D bp->cpld_id; + return 0; + } + + /* A CPLD operation can hold cpld_lock a long time; stay killable. */ + ret =3D mutex_lock_interruptible(&bp->cpld_lock); + if (ret) + return ret; + + ret =3D adva_x1_bus_claim(bp); + if (ret) + goto out; + ret =3D adva_x1_mux_select(bp, ADVA_MUX_CHANNEL); + if (ret) + goto release; + ret =3D adva_x1_cpld_cmd_read(bp, CPLD_CMD_READ_ID, data, 4); + if (!ret) + bp->cpld_id =3D get_unaligned_be32(data); + adva_x1_mux_select(bp, -1); +release: + adva_x1_bus_release(bp); +out: + mutex_unlock(&bp->cpld_lock); + if (!ret) + *id =3D bp->cpld_id; + + return ret; +} + +/* + * cpld_status - show the status register of the TAP CPLD. + * + * Returns a human-readable string: "done=3D<0|1> busy=3D<0|1> failed=3D<0= |1>\n" + */ +static ssize_t +cpld_status_show(struct device *dev, struct device_attribute *attr, + char *buf) +{ + struct ptp_ocp *bp =3D dev_get_drvdata(dev); + u32 st =3D 0; + int ret; + + /* A CPLD operation can hold cpld_lock a long time; stay killable. */ + ret =3D mutex_lock_interruptible(&bp->cpld_lock); + if (ret) + return ret; + + ret =3D adva_x1_bus_claim(bp); + if (ret) + goto out; + ret =3D adva_x1_mux_select(bp, ADVA_MUX_CHANNEL); + if (ret) + goto release; + ret =3D adva_x1_cpld_read_status(bp, &st); + adva_x1_mux_select(bp, -1); +release: + adva_x1_bus_release(bp); +out: + mutex_unlock(&bp->cpld_lock); + return ret ? ret : sysfs_emit(buf, "done=3D%u busy=3D%u failed=3D%u\n", + !!(st & CPLD_STATUS_DONE), + !!(st & CPLD_STATUS_BUSY), + !!(st & CPLD_STATUS_FAILED)); +} +static DEVICE_ATTR_ADMIN_RO(cpld_status); + static struct attribute *adva_timecard_attrs[] =3D { &dev_attr_serialnum.attr, &dev_attr_gnss_sync.attr, @@ -4274,6 +4592,7 @@ static struct attribute *adva_timecard_x1_attrs[] =3D= { &dev_attr_ts_window_adjust.attr, &dev_attr_utc_tai_offset.attr, &dev_attr_tod_correction.attr, + &dev_attr_cpld_status.attr, NULL, }; =20 @@ -4904,6 +5223,7 @@ ptp_ocp_detach(struct ptp_ocp *bp) clk_hw_unregister_fixed_rate(bp->i2c_clk); if (bp->n_irqs) pci_free_irq_vectors(bp->pdev); + mutex_destroy(&bp->cpld_lock); device_unregister(&bp->dev); } =20 @@ -5080,6 +5400,17 @@ ptp_ocp_probe(struct pci_dev *pdev, const struct pci= _device_id *id) if (err) goto out_disable; =20 + /* Must be before the first error path that calls ptp_ocp_detach(), + * so mutex_destroy() always runs on an initialised mutex. + * Must also be before ptp_ocp_register_resources(): the I2C bus + * notifier (ptp_ocp_i2c_notifier_call) fires when the adapter + * registers and stores the adapter number in cpld_i2c_adap_nr; the + * -1 sentinel below must already be written so that a notifier + * firing during registration is never overwritten by this init. + */ + mutex_init(&bp->cpld_lock); + bp->cpld_i2c_adap_nr =3D -1; + INIT_DELAYED_WORK(&bp->sync_work, ptp_ocp_sync_work); =20 /* compat mode. @@ -5219,11 +5550,16 @@ ptp_ocp_i2c_notifier_call(struct notifier_block *nb, =20 found: bp =3D dev_get_drvdata(dev); - if (add) + if (add) { ptp_ocp_symlink(bp, child, "i2c"); - else + /* Cache adapter nr; used by the CPLD status/id/upload paths + * for reference-counted unbind-safe adapter access. + */ + WRITE_ONCE(bp->cpld_i2c_adap_nr, i2c_verify_adapter(child)->nr); + } else { + WRITE_ONCE(bp->cpld_i2c_adap_nr, -1); /* invalidate before free */ sysfs_remove_link(&bp->dev.kobj, "i2c"); - + } return 0; } =20 --=20 2.47.0 From nobody Tue Sep 29 06:46:55 2026 Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7FF7D446845 for ; Tue, 11 Aug 2026 13:57:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786456651; cv=none; b=jKlYsHdwFLGxXoehSIHsnSGU8JW5yxmCg9gNGDh/59iGDGuaAvYrA0bgF4UNTP5u8VsAkiYoOUyI96tULn7GjqyIRfqHRP8QjHnE/2kOqBRBLvfYnbz5iOwYWuJ2sCA1kxBkEswT+5jW3lu6GG361UlYwDeFBcspZQ9wwLq6qNI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786456651; c=relaxed/simple; bh=vXAp/mVOlrPb7Fd1npy+/sCObkSdPXGRgr+b71UchmY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=SWnpFZ62HkzzR5x5IcukFhtNylkTreM/mU1CttS6M9EDKVJgEwWnbosvWwToPmrE+QCaYoTVhXzqVhSMdaw3pPndYUB/GDRiGXkZWGewgjhVmDIPMwNaZj18+yrPqbQHffXgh9A0hRnmmcHNsNvV8wmatEKET739dGnRkGnSBKg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=JgURVIHp; arc=none smtp.client-ip=209.85.128.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="JgURVIHp" Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-49558ce01afso7399495e9.1 for ; Tue, 11 Aug 2026 06:57:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786456646; x=1787061446; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=J/ebuaLZT2Md8xdvwJSHj1EqpYIvEP+OxtDAJHEpI5E=; b=JgURVIHpEam5Dct6qTA128BIJpNIkLVc9BBJmbtvQe0VstKI7pfgM+feOtYdpDgh3T RaCmsnbG9An3Y4LIyGzlCioV/FPJ/A7VbzhXPnAowS9JfrUP0v4XDR2IN37uAU0+Pina /Eyimw4eDRlvaIMZk5s6lo9Gwu6SXfJHiIBNpmRScy6Ri6iq0f9Q/Y2pOItefZPVgTqM Qhh1zz0kVoLgSv2FkNCmdhPf75qk+XHa3kt9qVlZQcpJ4765n1Y78IJVKZhcygAwxwbM GNVoo967RTJ6ES5tbRqM0l2Br/FttxGQ5HZzSe7e6sIzfObJPlWv4eQxlUIAikp0TieF H2ew== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786456646; x=1787061446; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=J/ebuaLZT2Md8xdvwJSHj1EqpYIvEP+OxtDAJHEpI5E=; b=Y8fy1H2ZfLI/8oirHVkSngawKVlVyuvEOFk4U7igKDGzUNIRtd2K4oDIJxFfYNk8c4 sigAFVzYqI2bhWbvqyKXoL/siw2Y0cAZP/HvW+k/XFCR9GlQKxslMTn5qJJnwTyqBnyp 6LzSq6iCQq1QV+eOwvZYKP7Tbs7VwM65RedK0mya3cP3vBBu5D6OdDSKPMsYgh7fsAW3 /yYnvcLsEAAmiAmdw0id7bUonaCs0WvVqDl88lzo7D0zaimxGCwDg24wq1a79M+FNAB5 LEvoEPrVCM49XOWGi8+9cYlZDGz9wzPZ0EdcQkQbx50+/pVKdI/IPsgapL12mkkz5sH0 1xTg== X-Forwarded-Encrypted: i=1; AHgh+RpfHfBj3TbxlT0Gi8c0g85Kwh0J9sUHMglSl3/wA4LTlKoMmBZSKEkvbyOeBKPgy7itAgvN6L0LY2gvF8o=@vger.kernel.org X-Gm-Message-State: AOJu0Yw4U7lLRBa7YRPp2dYgXEoTgatrjgbUaIRGqScpVhqynMD72ZLS B65buZ251m/Z/j32r2MNqrwKlpP4+1HA8A9OYAmGFI7wsqGkV526bcNA X-Gm-Gg: AR+sD12mEw9dmH4KEkILbIlsNvwsuAD+JvhhQsCyCnd2WJyzyy5jygx6CCPRP98JKjw dUSK6WlDaKMpd0Y0zn3Kvmk2brxoRKi8c8HiO6ycEENppHgUnk39+pz52Za+DAd1fxaA6Mc6KM8 Mg3GmNa15bcOH2+Y7RQ/LH34GtFbSRsulKn7AkVKKVDmg32H14W4WLldmyMIFVwXpzSeZtmDEO2 6J1u6qEMln5xxQpyRXOj+gkK9Bj3LNxXOmNebe5dVUr7w9u/LdJdSSFeQVWSvOm6+QvciWhcPVx wUmJXSJAwm+5FEp6yDOyVWWO531uRH/wZmxBGgbJMnGFm2pNAr5S7qe+rnrRkM+fmW6jJ8XwrMT exKDIMKynEztRv2hjmUMLHgVYNJkS6/20M9wQeO1l61FWNRpfow4syaQ/WjoXwGaOObstwxCA4k 5SdX2kCrE1YEcd5v3zgie0V6xhBRb3FOVqKhyUBds2wLAGgtbL6ZZv7a1OvLuRjDypjvigNGcoC xwdcuYf2sRN2au5ldNPW9/Bbw== X-Received: by 2002:a05:600c:3b9b:b0:495:7a5a:d96c with SMTP id 5b1f17b1804b1-4997a62dcb0mr3540765e9.18.1786456645673; Tue, 11 Aug 2026 06:57:25 -0700 (PDT) Received: from fedora.advaoptical.com ([82.166.23.19]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499788a6cdfsm34095085e9.6.2026.08.11.06.57.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 06:57:25 -0700 (PDT) From: Sagi Maimon To: netdev@vger.kernel.org Cc: vadim.fedorenko@linux.dev, richardcochran@gmail.com, kuba@kernel.org, andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, linux-kernel@vger.kernel.org, Sagi Maimon Subject: [PATCH net-next v11 2/2] ptp: ocp: add TAP CPLD firmware upload for ADVA TimeCard X1 Date: Tue, 11 Aug 2026 16:57:20 +0300 Message-ID: <20260811135720.109580-3-maimon.sagi@gmail.com> X-Mailer: git-send-email 2.47.0 In-Reply-To: <20260811135720.109580-1-maimon.sagi@gmail.com> References: <20260811135720.109580-1-maimon.sagi@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The Lattice MachXO3 CPLD on the ADVA TimeCard X1 is programmed over I2C using in-system programming (ISP). Build on the TMC bus arbitration added previously and expose the update path through the kernel firmware-upload subsystem. The framework acquires the bus, erases the configuration flash, programs the image page-by-page and activates it with the MachXO3 REFRESH command. The upload node is registered per card as adva-cpld.N, using the same index as the owning ocpN device, so a host with more than one X1 board gets one node each: /sys/class/firmware/adva-cpld.N/ The whole prepare/write/poll_complete/cleanup sequence runs under cpld_lock and the i2c adapter lock, so an EEPROM read blocks for as long as programming takes; the alternative is reading the TMC bus instead. The upload is unregistered first on detach, which cancels and flushes an in-flight programming cycle while the I2C controller is still up. Select FW_LOADER and FW_UPLOAD, as the documented update path does not exist without them. Signed-off-by: Sagi Maimon --- Documentation/ABI/testing/sysfs-timecard | 5 + drivers/ptp/Kconfig | 2 + drivers/ptp/ptp_ocp.c | 313 ++++++++++++++++++++++- 3 files changed, 319 insertions(+), 1 deletion(-) diff --git a/Documentation/ABI/testing/sysfs-timecard b/Documentation/ABI/t= esting/sysfs-timecard index 26a93cee0b89..41eeadd46330 100644 --- a/Documentation/ABI/testing/sysfs-timecard +++ b/Documentation/ABI/testing/sysfs-timecard @@ -30,6 +30,11 @@ Description: (RO, root only) The status register of the = TAP CPLD, in ID of the CPLD is reported as the fixed "cpld.id" version by devlink dev info. =20 + To program new CPLD firmware use the standard kernel + firmware-upload interface, registered per card at: + /sys/class/firmware/adva-cpld.N/ + where N is the index of this ocpN device. + What: /sys/class/timecard/ocpN/available_clock_sources Date: September 2021 Contact: Jonathan Lemon diff --git a/drivers/ptp/Kconfig b/drivers/ptp/Kconfig index b93640ca08b7..0c2c7dd32e7f 100644 --- a/drivers/ptp/Kconfig +++ b/drivers/ptp/Kconfig @@ -218,6 +218,8 @@ config PTP_1588_CLOCK_OCP select NET_DEVLINK select CRC16 select DPLL + select FW_LOADER + select FW_UPLOAD help This driver adds support for an OpenCompute time card. =20 diff --git a/drivers/ptp/ptp_ocp.c b/drivers/ptp/ptp_ocp.c index 41a7fde1ae6a..4a0bd9b89452 100644 --- a/drivers/ptp/ptp_ocp.c +++ b/drivers/ptp/ptp_ocp.c @@ -20,12 +20,14 @@ #include #include #include +#include #include #include #include #include #include #include +#include =20 #define PCI_DEVICE_ID_META_TIMECARD 0x0400 =20 @@ -426,6 +428,9 @@ struct ptp_ocp { struct i2c_adapter *cpld_adap; /* claimed adapter; valid under = cpld_lock */ u32 cpld_id; /* cached Lattice device ID; 0 if unread */ bool has_cpld; /* x1 TAP CPLD present */ + struct fw_upload *cpld_fw_upload; /* firmware upload handle; NULL if= absent */ + bool cpld_cancel; /* cancellation requested */ + bool cpld_in_config_mode; /* EN_CFG_TP issued but not yet REFRESH'd */ }; =20 #define OCP_REQ_TIMESTAMP BIT(0) @@ -459,6 +464,8 @@ static int ptp_ocp_art_board_init(struct ptp_ocp *bp, s= truct ocp_resource *r); =20 static int ptp_ocp_adva_board_init(struct ptp_ocp *bp, struct ocp_resource= *r); =20 +static const struct fw_upload_ops adva_cpld_upload_ops; + static const struct ocp_sma_op ocp_adva_sma_op; static const struct ocp_sma_op ocp_adva_x1_sma_op; static int adva_x1_cpld_device_id(struct ptp_ocp *bp, u32 *id); @@ -3225,6 +3232,29 @@ ptp_ocp_adva_board_init(struct ptp_ocp *bp, struct o= cp_resource *r) ptp_ocp_sma_init(bp); =20 bp->has_cpld =3D info->has_cpld; + if (bp->has_cpld) { + struct fw_upload *fwl; + const char *name; + + /* One instance per card, numbered like the ocpN device. + * firmware_upload_register() keeps the pointer rather than + * copying the string, so it has to outlive the registration. + */ + name =3D devm_kasprintf(&bp->pdev->dev, GFP_KERNEL, + "adva-cpld.%d", bp->id); + if (!name) + return -ENOMEM; + + fwl =3D firmware_upload_register(THIS_MODULE, &bp->pdev->dev, + name, &adva_cpld_upload_ops, bp); + if (IS_ERR(fwl)) + dev_warn(&bp->pdev->dev, + "CPLD firmware upload unavailable: %pe\n", + fwl); + else + bp->cpld_fw_upload =3D fwl; + } + return ptp_ocp_init_clock(bp, &info->servo); } =20 @@ -4283,6 +4313,15 @@ static const struct ocp_attr_group art_timecard_grou= ps[] =3D { /* Lattice LCMXO3LF ISC command codes */ #define CPLD_CMD_READ_ID 0xE0000000UL #define CPLD_CMD_READ_STATUS 0x3C000000UL +#define CPLD_CMD_EN_CFG_TP 0x74 /* enable config, transparent mode */ +#define CPLD_CMD_DIS_CFG 0x26 +#define CPLD_CMD_ERASE 0x0E +#define CPLD_CMD_RESET_ADDR 0x46 +#define CPLD_CMD_WRITE_PAGE 0x70 +#define CPLD_CMD_SET_DONE 0x5E +#define CPLD_CMD_REFRESH 0x79 +#define CPLD_PAGE_SIZE 16 +#define CPLD_POLL_US 10000 /* status poll interval while busy */ =20 /* Status register bit positions (Lattice LCMXO3LF datasheet) */ #define CPLD_STATUS_DONE BIT(8) @@ -4408,7 +4447,8 @@ static void adva_x1_bus_release(struct ptp_ocp *bp) * Claim the TMC bus for a CPLD operation. Holding the adapter lock over * the handshake keeps ptp_ocp_read_eeprom(), the nvmem attributes and the * at24 sysfs files off the controller while it is routed away from the - * EEPROMs. + * EEPROMs. A firmware upload holds it across the whole prepare/write/poll + * sequence, so an EEPROM read blocks for as long as programming takes. */ static int adva_x1_bus_claim(struct ptp_ocp *bp) { @@ -4442,6 +4482,20 @@ static int adva_x1_mux_select(struct ptp_ocp *bp, in= t ch) return adva_x1_i2c_xfer(bp, ADVA_MUX_ADDR, &val, 1, NULL, 0); } =20 +/* Send 1-byte ISC command + optional arguments. */ +static int adva_x1_cpld_write(struct ptp_ocp *bp, + u8 cmd, const u8 *args, u8 nargs) +{ + u8 buf[1 + 64]; + + if (nargs > 64) + return -EINVAL; + buf[0] =3D cmd; + if (nargs) + memcpy(&buf[1], args, nargs); + return adva_x1_i2c_xfer(bp, ADVA_CPLD_ADDR, buf, 1 + nargs, NULL, 0); +} + /* * Send a 4-byte command then read data back without an intermediate STOP * (Lattice combined write->repeated-START->read). Two messages in one @@ -4467,6 +4521,38 @@ static int adva_x1_cpld_read_status(struct ptp_ocp *= bp, u32 *status) return 0; } =20 +/* Poll the status register until the CPLD goes idle, or @max_ms elapses. + * The deadline is on wall time, so the I2C transactions count against it, + * and the status is read once more after it expires before giving up. + */ +static int adva_x1_cpld_wait_ready(struct ptp_ocp *bp, unsigned int max_ms) +{ + u32 status =3D 0; + int err, ret; + + ret =3D read_poll_timeout(adva_x1_cpld_read_status, err, + err || READ_ONCE(bp->cpld_cancel) || + (status & CPLD_STATUS_FAILED) || + !(status & CPLD_STATUS_BUSY), + CPLD_POLL_US, max_ms * USEC_PER_MSEC, false, + bp, &status); + if (ret) + return ret; + if (READ_ONCE(bp->cpld_cancel)) + return -ECANCELED; + if (err || (status & CPLD_STATUS_FAILED)) + return -EIO; + + return 0; +} + +/* A step aborted by cancel() must be reported as such, not as a HW error.= */ +static enum fw_upload_err adva_cpld_err(struct ptp_ocp *bp) +{ + return READ_ONCE(bp->cpld_cancel) ? FW_UPLOAD_ERR_CANCELED + : FW_UPLOAD_ERR_HW_ERROR; +} + /* * Read the Lattice device ID of the TAP CPLD. It is a fixed property of * the part, so cache it and pay the bus arbitration only once. The @@ -4544,6 +4630,222 @@ cpld_status_show(struct device *dev, struct device_= attribute *attr, } static DEVICE_ATTR_ADMIN_RO(cpld_status); =20 +/* + * adva_x1 CPLD firmware-upload callbacks. + * + * The kernel firmware-upload subsystem (CONFIG_FW_UPLOAD) exposes: + * /sys/class/firmware/adva-cpld.N/{data,loading,status,error,...} + * where N is the index of the owning ocpN device. + * Userspace writes the raw binary page data directly =E2=80=94 no /lib/fi= rmware/ + * staging file is needed. + * + * Callback sequence driven by the framework: + * prepare() - validate size, acquire bus, enable config, erase fla= sh + * write() - program one 16-byte page per call + * poll_complete()- set DONE, REFRESH, wait for CPLD to reboot + * cancel() - set flag; checked at the start of each callback + * cleanup() - release bus resources (called on success or failure) + */ +static enum fw_upload_err +adva_cpld_prepare(struct fw_upload *fwl, const u8 *data, u32 size) +{ + static const u8 era_args[3] =3D { 0x04, 0x00, 0x00 }; /* cfg sector only = */ + static const u8 en_args[2] =3D { 0x08, 0x00 }; + static const u8 dis_args[2] =3D { 0x00, 0x00 }; + static const u8 zero3[3] =3D { 0 }; + enum fw_upload_err ret =3D FW_UPLOAD_ERR_NONE; + struct ptp_ocp *bp =3D fwl->dd_handle; + + /* Do not clear cpld_cancel here: fw_upload_start() queues the work + * before this runs, so a cancel may already have arrived. It is + * cleared once the upload is over, on every exit below and in + * cleanup(). + */ + if (!size || size % CPLD_PAGE_SIZE) { + WRITE_ONCE(bp->cpld_cancel, false); + return FW_UPLOAD_ERR_INVALID_SIZE; + } + + bp->cpld_in_config_mode =3D false; + + mutex_lock(&bp->cpld_lock); + + if (adva_x1_bus_claim(bp)) { + ret =3D FW_UPLOAD_ERR_TIMEOUT; + goto err_unlock; + } + + if (adva_x1_mux_select(bp, ADVA_MUX_CHANNEL)) { + ret =3D FW_UPLOAD_ERR_HW_ERROR; + goto err_release; + } + + /* Set before issuing EN_CFG_TP, not after it completes: the CPLD may + * have entered configuration mode even if the write reports an error + * or the wait below times out, and err_deselect only sends DIS_CFG + * when this is set. A DIS_CFG to a device that never entered the + * mode is harmless; leaving it enabled is not. + */ + bp->cpld_in_config_mode =3D true; + + if (adva_x1_cpld_write(bp, CPLD_CMD_EN_CFG_TP, en_args, 2) || + adva_x1_cpld_wait_ready(bp, 5000)) { + ret =3D adva_cpld_err(bp); + goto err_deselect; + } + + if (READ_ONCE(bp->cpld_cancel)) { + ret =3D FW_UPLOAD_ERR_CANCELED; + goto err_deselect; + } + + if (adva_x1_cpld_write(bp, CPLD_CMD_ERASE, era_args, 3) || + adva_x1_cpld_wait_ready(bp, 15000)) { + ret =3D adva_cpld_err(bp); + goto err_deselect; + } + + if (READ_ONCE(bp->cpld_cancel)) { + ret =3D FW_UPLOAD_ERR_CANCELED; + goto err_deselect; + } + + if (adva_x1_cpld_write(bp, CPLD_CMD_RESET_ADDR, zero3, 3)) { + ret =3D FW_UPLOAD_ERR_HW_ERROR; + goto err_deselect; + } + + /* cleanup() unlocks everything. fw_upload_main() only pairs it with + * a prepare() that succeeded, so the error paths below unlock here + * instead; hand the context to cleanup() for sparse's benefit. + */ + __release(&bp->cpld_lock); + return FW_UPLOAD_ERR_NONE; + +err_deselect: + if (bp->cpld_in_config_mode) { + adva_x1_cpld_write(bp, CPLD_CMD_DIS_CFG, dis_args, 2); + bp->cpld_in_config_mode =3D false; + } + adva_x1_mux_select(bp, -1); +err_release: + adva_x1_bus_release(bp); +err_unlock: + WRITE_ONCE(bp->cpld_cancel, false); + mutex_unlock(&bp->cpld_lock); + return ret; +} + +static enum fw_upload_err +adva_cpld_write(struct fw_upload *fwl, const u8 *data, + u32 offset, u32 size, u32 *written) +{ + struct ptp_ocp *bp =3D fwl->dd_handle; + u8 page_args[3 + CPLD_PAGE_SIZE]; + + lockdep_assert_held(&bp->cpld_lock); + + if (READ_ONCE(bp->cpld_cancel)) + return FW_UPLOAD_ERR_CANCELED; + + if (size < CPLD_PAGE_SIZE) + return FW_UPLOAD_ERR_INVALID_SIZE; + + page_args[0] =3D 0x00; + page_args[1] =3D 0x00; + page_args[2] =3D 0x01; + memcpy(&page_args[3], data + offset, CPLD_PAGE_SIZE); + + if (adva_x1_cpld_write(bp, CPLD_CMD_WRITE_PAGE, + page_args, 3 + CPLD_PAGE_SIZE) || + adva_x1_cpld_wait_ready(bp, 100)) + return adva_cpld_err(bp); + + *written =3D CPLD_PAGE_SIZE; + return FW_UPLOAD_ERR_NONE; +} + +static enum fw_upload_err +adva_cpld_poll_complete(struct fw_upload *fwl) +{ + static const u8 ref_args[2] =3D { 0x00, 0x00 }; + static const u8 zero3[3] =3D { 0 }; + struct ptp_ocp *bp =3D fwl->dd_handle; + int err; + u32 st; + + lockdep_assert_held(&bp->cpld_lock); + + if (READ_ONCE(bp->cpld_cancel)) + return FW_UPLOAD_ERR_CANCELED; + + if (adva_x1_cpld_write(bp, CPLD_CMD_SET_DONE, zero3, 3) || + adva_x1_cpld_wait_ready(bp, 1000)) + return adva_cpld_err(bp); + + if (adva_x1_cpld_read_status(bp, &st) || !(st & CPLD_STATUS_DONE)) + return FW_UPLOAD_ERR_HW_ERROR; + + if (adva_x1_cpld_write(bp, CPLD_CMD_REFRESH, ref_args, 2)) + return FW_UPLOAD_ERR_HW_ERROR; + + /* REFRESH reboots the CPLD out of configuration mode, so cleanup() + * must not send DIS_CFG afterwards even if the checks below fail. + */ + bp->cpld_in_config_mode =3D false; + + /* The new image is already running at this point, so a segment that + * is not back yet must not be reported as a failed update: retry the + * reselect instead of sampling the mux once at a fixed delay. + */ + msleep(1500); + if (read_poll_timeout(adva_x1_mux_select, err, !err, CPLD_POLL_US, + 3000 * USEC_PER_MSEC, false, + bp, ADVA_MUX_CHANNEL)) + return FW_UPLOAD_ERR_TIMEOUT; + + if (adva_x1_cpld_wait_ready(bp, 3000)) + return READ_ONCE(bp->cpld_cancel) ? FW_UPLOAD_ERR_CANCELED + : FW_UPLOAD_ERR_TIMEOUT; + + return FW_UPLOAD_ERR_NONE; +} + +static void +adva_cpld_cancel(struct fw_upload *fwl) +{ + struct ptp_ocp *bp =3D fwl->dd_handle; + + WRITE_ONCE(bp->cpld_cancel, true); +} + +static void +adva_cpld_cleanup(struct fw_upload *fwl) +{ + static const u8 dis_args[2] =3D { 0x00, 0x00 }; + struct ptp_ocp *bp =3D fwl->dd_handle; + + __acquire(&bp->cpld_lock); /* held since prepare() returned ok */ + lockdep_assert_held(&bp->cpld_lock); + + if (bp->cpld_in_config_mode) { + adva_x1_cpld_write(bp, CPLD_CMD_DIS_CFG, dis_args, 2); + bp->cpld_in_config_mode =3D false; + } + adva_x1_mux_select(bp, -1); + adva_x1_bus_release(bp); + WRITE_ONCE(bp->cpld_cancel, false); + mutex_unlock(&bp->cpld_lock); +} + +static const struct fw_upload_ops adva_cpld_upload_ops =3D { + .prepare =3D adva_cpld_prepare, + .write =3D adva_cpld_write, + .poll_complete =3D adva_cpld_poll_complete, + .cancel =3D adva_cpld_cancel, + .cleanup =3D adva_cpld_cleanup, +}; + static struct attribute *adva_timecard_attrs[] =3D { &dev_attr_serialnum.attr, &dev_attr_gnss_sync.attr, @@ -5186,6 +5488,15 @@ ptp_ocp_detach(struct ptp_ocp *bp) { int i; =20 + /* Must come first: cancels and flushes an in-flight upload while the + * I2C controller is still up, and drops cpld_lock so a cpld_status + * reader cannot stall ptp_ocp_attr_group_del() below. + */ + if (bp->cpld_fw_upload) { + firmware_upload_unregister(bp->cpld_fw_upload); + bp->cpld_fw_upload =3D NULL; + } + ptp_ocp_debugfs_remove_device(bp); ptp_ocp_detach_sysfs(bp); ptp_ocp_attr_group_del(bp); --=20 2.47.0