From nobody Fri Sep 25 21:02:42 2026 Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D1984F649C for ; Mon, 21 Sep 2026 18:25:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.12 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790015143; cv=none; b=HNmAZqs/0awe6xtJgB7S5fsPHGRjoSFC20avkYw5yypZPe/iuWytfwPY3wdbZYvXGHAmz2bWoFkw1IRMMWlIBU4Vl3BJdBKfmHNu7MfbsbHxHt0tO/3kAB45a9KYERGGKsYDHz/UsC+9AFxKFipq+5cR7WUTzhq33k4MlDuwzss= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790015143; c=relaxed/simple; bh=Zw7I68dk/dfQhHon05xSczDRBjRS89SCdhc9Ul/iA8c=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=I4ty9m0AcVYkqCb1DuzbxyTza4JXyJrDVwsh5wAb1tuCmPX/Sq5yc0ZTVJ8CnfVuyfgqJWP4kP/SAWzdJ41UPgxpJKnKytxpCe8rGc5gyAR13O/Q0AyXg+uXQKQS+5yBCCeJQBTdHMaCUpDZhdcLNMWtGvCWFRd7chPMtPEhT+g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=XfW6T/6s; arc=none smtp.client-ip=74.125.228.12 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="XfW6T/6s" Received: by mail-pz2-f12.google.com with SMTP id 41be03b00d2f7-cc4c3304833so2326794a12.3 for ; Mon, 21 Sep 2026 11:25:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1790015141; x=1790619941; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=gnxM12bjAU6l32+T085J4xBzZcACDHL6vkRV2pEi6lg=; b=XfW6T/6stA8FS2kESvEUyJAdokPmDCtfrGOwDx7culklUvV6VSGutSOcyUaMpeA0rW B9zW5vL8hhOI9d0hHY65W8k0u1mvP4u5kBddnlPzCZXKEZVyQjcsKTzQWboqqoCdxleg ZAZbGkl8zWGLCJHXIiBYN/8ACjVy1VllwVFVPKSWmJWYiawCGQWX80Xi27+j60JI0dNF XnmqKZzbiQRLtrE0RJnMI/0rb1F7Z9Er7pHpC8+6LvxB7CvpEYjS4LPsylvKzL8j/sE1 MqMUV6u54RN7G4o9rZfPLeTo8EDAzH8R9Zn+d5nU3J4oFpRPyNSSQ4wvP1zUIyp/5Sqm nn2A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790015141; x=1790619941; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=gnxM12bjAU6l32+T085J4xBzZcACDHL6vkRV2pEi6lg=; b=Ubs//dcRXbsPGtvfbFn1F4Hqk8/b4ytL6GazLACCnuApujLz8aWgrvehNVqzfbZZrj n4ccRr792gibQGssdOE6HKnN3dwJyCVi//ETZbBiiLjRNJ5WOaRwYh/Vkuo/CooIZjSF Xhbkyods/KVRU/0tjxygeQOvLj++tJLJdkwug3yQ2G9YFGeBt2tYBnuM1miM7VSHqHFW TL2XbuCuHSPNCuMSX1EL+J3t6CEKgavpEhcvsf+mkY3Oo4yffGCD1n+GGpjqbD5wByr7 EyW+zwu/JkSto/Ib7ZyM8XTrfENb9d10/Um83AeY0JmToPiySXOuZ8xyZQ+sWqmdSOrW ONcw== X-Forwarded-Encrypted: i=1; AKwUvBzaQN2j0uTKAb3+gd6unAUJpq16oFCDPiWtW0GfDQuCtMzfxjgPAGX9AtmQaOp2+ty86g/G96bd/UYaU8A=@vger.kernel.org X-Gm-Message-State: AFuF++kOhcfe7V7c5RuZ+upF4y4AHR6Jn5Vn9IoDoH2mVyrB8dPd1lqz VfLL/JGSy7vCsOThkpjy4P83kb5QFOB2C33JDR9FQzhUxhozUQrQ5W3XIPbuwM72LKu4fEyJvl9 5IhxpTPg= X-Gm-Gg: AYBFou2oD+e8y1yAoc8q+xltvkjd7dC/mEVEm42z5wDP0vOuQI3KWu8iwhXosdd2Hwh pmG/m0BF97RCFwUw1uGGTmM2qksPt3y7zvu1nlxIJ6f4PCdqfeVs7g9GWHnvSgoelNr0iVfZmPf Clldeg9rjVKj/4PK/R7t/qYm+TcC9kgCuBfwd1Lg5pK1RsujURfEk+ZAjo8fTd7o394t/Zmf8CB tSj930G0kje1nMPEhEEqPmPU3dDLXIPe3/mhwDdHfjs/nKORqaaIXbR7hmbindv1WqZWV9Ywe9W Z7ItotWb+NSWJHt/o+7mxMrFH89A1m+CPJzNw6RHn++GhVB5r1oYWIUkDYUhDZoquu9z/0Msxor AeYGsmYaJDdSt3vm9WlZGz+hy5UPJaE2PrjuwplgPMMZSPgWVVpMeQyuQCsu/OJ9PHrw3a5Ns9P 8HbQVS38gIkZnaRhGUN97iS1CbMM32f8OIaep5TsPUxoR6DD1og7BPQ0WkGu8WsdIEppCIPtacR Q== X-Received: by 2002:a05:6a21:4c81:b0:3dd:a196:906c with SMTP id adf61e73a8af0-3dda196a65dmr12713643637.54.1790015140904; Mon, 21 Sep 2026 11:25:40 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-144df9ad683sm12408974c88.6.2026.09.21.11.25.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Sep 2026 11:25:40 -0700 (PDT) From: Abdurrahman Hussain Date: Mon, 21 Sep 2026 11:25:36 -0700 Subject: [PATCH v5 1/3] i2c: xiic: preserve PEC byte length in SMBus block read setup Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260921-i2c-xiic-v5-1-2fca81e810ea@nexthop.ai> References: <20260921-i2c-xiic-v5-0-2fca81e810ea@nexthop.ai> In-Reply-To: <20260921-i2c-xiic-v5-0-2fca81e810ea@nexthop.ai> To: Michal Simek , Andi Shyti , Wolfram Sang , Raviteja Narayanam , Wolfram Sang , Manikanta Guntupalli Cc: Shubhrajyoti Datta , linux-arm-kernel@lists.infradead.org, linux-i2c@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain , stable@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1790015138; l=5861; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=Zw7I68dk/dfQhHon05xSczDRBjRS89SCdhc9Ul/iA8c=; b=hWgnVzhwB+BfXuq7pCDIDcjklKC5IdWFIUMjL8pPfjX0kmLkMe4PrklykCUOBH/adfk1HVV5R EgV2AvU1Y+QDLMH4+f1sMsEQwD0FWzQQyzkIBoIi1+4AskvkK1f4AEi X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= xiic_smbus_block_read_setup() recalculates i2c->rx_msg->len based on the length byte returned by the device, but historically clobbered the PEC byte expectation the SMBus core had baked into msg->len. That dropped the PEC byte from the caller's buffer on the normal and chunked receive-fifo branches. Compute pec_len up-front as (i2c->rx_msg->len - 1) and add it to the new length in every branch: - chunked (rxmsg_len + pec_len > IIC_RX_FIFO_DEPTH): set the drain target to rxmsg_len + 1 + pec_len. - deferred (small enough to drain in one fill but >=3D MIN_LEN total): same. - padded (1 + rxmsg_len + pec_len < SMBUS_BLOCK_READ_MIN_LEN): the hardware needs at least 3 bytes on the bus to exit the read cleanly (the second byte is already being clocked in by the time the ISR reads the length byte and is too late to NACK), so we still pad rx_msg->len up to SMBUS_BLOCK_READ_MIN_LEN. The dummy trailing byte that gets drained must then be trimmed off before handing the message back to the SMBus core; otherwise i2c_smbus_check_pec() reads buf[len-1] (=3D dummy) instead of the real PEC byte at buf[1] and rejects every clean zero-length block read with -EBADMSG. Record the true valid byte count in a new field i2c->smbus_actual_len and have xiic_process()'s RX_FULL completion site trim rx_msg->len down to it before clearing rx_msg. smbus_actual_len is per-receive state, so xiic_start_recv() clears it before every receive. Only the padded branch ever sets it, and a block read aborted by arbitration loss or a TX error never reaches the completion site, so without that clear a stale value would trim the length of an unrelated later read. Widen the branch condition from the old "(rxmsg_len =3D=3D 1) || (rxmsg_len =3D=3D 0)" to "(1 + rxmsg_len + pec_len) < MIN_LEN" so that user requests with multi-byte trailing bytes (e.g. pec_len =3D=3D 2 on a zero-length block) flow through the deferred branch instead of getting truncated to MIN_LEN here. Fixes: e4c1ff772e1a ("i2c: xiic: Add smbus_block_read functionality") Cc: stable@vger.kernel.org Acked-by: Michal Simek Signed-off-by: Abdurrahman Hussain --- drivers/i2c/busses/i2c-xiic.c | 33 ++++++++++++++++++++++++++------- 1 file changed, 26 insertions(+), 7 deletions(-) diff --git a/drivers/i2c/busses/i2c-xiic.c b/drivers/i2c/busses/i2c-xiic.c index 3e7735e1dae0..22367a069ded 100644 --- a/drivers/i2c/busses/i2c-xiic.c +++ b/drivers/i2c/busses/i2c-xiic.c @@ -73,6 +73,9 @@ enum i2c_scl_freq { * @prev_msg_tx: Previous message is Tx * @quirks: To hold platform specific bug info * @smbus_block_read: Flag to handle block read + * @smbus_actual_len: Valid byte count (length + payload + optional PEC) o= f a + * padded SMBus block read. msg->len is trimmed to this on completion. + * Zero when no trimming is needed. * @input_clk: Input clock to I2C controller * @i2c_clk: I2C SCL frequency * @atomic: Mode of transfer @@ -98,6 +101,7 @@ struct xiic_i2c { bool prev_msg_tx; u32 quirks; bool smbus_block_read; + unsigned int smbus_actual_len; unsigned long input_clk; unsigned int i2c_clk; bool atomic; @@ -539,6 +543,8 @@ static void xiic_smbus_block_read_setup(struct xiic_i2c= *i2c) =20 /* Check if received length is valid */ if (rxmsg_len <=3D I2C_SMBUS_BLOCK_MAX) { + unsigned int pec_len =3D i2c->rx_msg->len - 1; + /* Set Receive fifo depth */ if (rxmsg_len > IIC_RX_FIFO_DEPTH) { /* @@ -546,23 +552,26 @@ static void xiic_smbus_block_read_setup(struct xiic_i= 2c *i2c) * Receive fifo depth should set to Rx fifo capacity minus 1 */ rfd_set =3D IIC_RX_FIFO_DEPTH - 1; - i2c->rx_msg->len =3D rxmsg_len + 1; - } else if ((rxmsg_len =3D=3D 1) || - (rxmsg_len =3D=3D 0)) { + i2c->rx_msg->len =3D rxmsg_len + 1 + pec_len; + } else if (1 + rxmsg_len + pec_len < SMBUS_BLOCK_READ_MIN_LEN) { /* - * Minimum of 3 bytes required to exit cleanly. 1 byte - * already received, Second byte is being received. Have - * to set NACK in read_rx before receiving the last byte + * The HW needs SMBUS_BLOCK_READ_MIN_LEN bytes on the + * bus to exit cleanly: by the time the ISR reads the + * length byte the second byte is already being clocked + * in, too late to NACK. Pad the drain target and record + * the real length, trimmed back on completion so the + * PEC check sees the right byte. */ rfd_set =3D 0; i2c->rx_msg->len =3D SMBUS_BLOCK_READ_MIN_LEN; + i2c->smbus_actual_len =3D 1 + rxmsg_len + pec_len; } else { /* * When Rx msg len less than Rx fifo capacity * Receive fifo depth should set to Rx msg len minus 2 */ rfd_set =3D rxmsg_len - 2; - i2c->rx_msg->len =3D rxmsg_len + 1; + i2c->rx_msg->len =3D rxmsg_len + 1 + pec_len; } xiic_setreg8(i2c, XIIC_RFD_REG_OFFSET, rfd_set); =20 @@ -797,6 +806,13 @@ static irqreturn_t xiic_process(int irq, void *dev_id) =20 xiic_read_rx(i2c); if (xiic_rx_space(i2c) =3D=3D 0) { + /* + * Undo the setup-time padding before rx_msg is cleared, + * so the PEC check sees the right byte. + */ + if (i2c->rx_msg && i2c->smbus_actual_len) + i2c->rx_msg->len =3D i2c->smbus_actual_len; + /* this is the last part of the message */ i2c->rx_msg =3D NULL; =20 @@ -955,6 +971,9 @@ static void xiic_start_recv(struct xiic_i2c *i2c) u8 cr =3D 0, rfd_set =3D 0; struct i2c_msg *msg =3D i2c->rx_msg =3D i2c->tx_msg; =20 + /* A stale value from an aborted block read would truncate this msg. */ + i2c->smbus_actual_len =3D 0; + if (!i2c->atomic) dev_dbg(i2c->adap.dev.parent, "%s entry, ISR: 0x%x, CR: 0x%x\n", __func__, xiic_getreg32(i2c, XIIC_IISR_OFFSET), --=20 2.54.0 From nobody Fri Sep 25 21:02:42 2026 Received: from mail-pz2-f32.google.com (mail-pz2-f32.google.com [74.125.228.32]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AF8E24F7CA0 for ; Mon, 21 Sep 2026 18:25:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.32 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790015144; cv=none; b=PZrqs3eY/bkpWlbEn39uD/aLPQqceNFiB1xQCb+15CV1zmL9PpiTsHMzF4pvkZyVLhUb5/8zopl3K22wbKGcbnJtA0YSL09iUFCrLTZuqKcGfAcWbXIzQyyNCyRXXX/YtLj7LZmQvKBXQW1Ue0NCZAz21/sp0KzCiD2QijUY3Vo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790015144; c=relaxed/simple; bh=/8Wrq+rYYeuzHylPud9tnFtGR3R2iGFzmcbe02TkznE=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=o1OfZgtxAFrhbDiNEZtF6tED7GLAli16JT4V+WFBpxO3catFD2fRUYNjTpwiGOlyccrrXJvgAGslZO6xn6DfJYpBdd7SmeAVgvCMnfomkiXNoC4sXBuPU5v468QnUBW7VtH0ql6MT9tAUYzoiyo119kQHIU9mXr35fOA056NF+A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=cChmHgOg; arc=none smtp.client-ip=74.125.228.32 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="cChmHgOg" Received: by mail-pz2-f32.google.com with SMTP id 41be03b00d2f7-cc4d04d73b8so2795383a12.1 for ; Mon, 21 Sep 2026 11:25:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1790015142; x=1790619942; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0cquRnCIn6mlXF5rqmfxuhHyvgmYvV6WRP7O37Nb5MQ=; b=cChmHgOgrOV/Z98IinDbJFq2nN5Xt4u3o/pO5D2dcfcThwF/qIv6z92qX1wwzv6UxE aTL/g4iXapKaiT6PDwVhJpRnQYTWs3SlafuR78kMsLVLgiCoMtQTjTlVSrqktgx7bD3Y RrzRj3TauzlXHBy10eDYsS1hZYEDUHTpIvdGAQhI5UzqfXn4Lop5NzQM0hLh3E7AjFaD 3Giot/qs4OyFOeoY+/Z5ZAzHJX4+gOYoNgOPk53J+CXNem1JkcePOuC8CWATMQNoJme7 RIWjK9gIpCdbilXy4ppTEjKB/RqWFA/kmG8BSYdWzRRBQIgquxogpq9yw1rg9x19HwGm m06Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790015142; x=1790619942; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=0cquRnCIn6mlXF5rqmfxuhHyvgmYvV6WRP7O37Nb5MQ=; b=c4TvWVz2o2jV/Aqr2Qy9jIfI84nMFOok9enYSHYR4HXKZ6IkzHwULkfKVvbE/NFEN2 PkLxVneO4BAakzAhxCuWgptSG/qmVFHg6mkROmH63MHiTwjv/WdXZO8S/OpwIauQlH2D Dwf2mCALFcbBVNXN7YBCYLo/4rhKfjxQqjBoYxF2Pi+GN0SW1Kp5iE0zZk/zAqfFsOBv w1A79VH+fXbFnjy0t/fOrZfkPTNNbltzEbtXx+LGj0n3h7KirUOBoZ2nbsna6PxsNTcZ LICRr6vD++WkkkHcMJDsZgdslH64RlRtJJoNuMJLZBUDp7M3AON2iv7QlyD7zYYOwKea xl8A== X-Forwarded-Encrypted: i=1; AKwUvByzfq1X/xVPlGojVkxLJ0iivVU45qtBq5Xqoo5KYQTnvhinJqfcHeS/sHYjPecitAbBD7ryQ4mppJTcdzk=@vger.kernel.org X-Gm-Message-State: AFuF++nwLiR3sAEvodc3Sss1ZGeyT/YRKY26hFcE3IeVjeC5aRBL34Ee IWNVDVLbpFJmgdXaOy290ylH6vgjd2L0H+oJjMltmz/Tqo2XP0Udc4TlFgfdLj9Yn8jSQqOy1qa 8uSkz9B4= X-Gm-Gg: AYBFou0AhYsdKegdGnGcw4DMxi4ocxwpY5i8Ss6b88n0k8hUIBWCHXbThahfQe8QzFU APq4Z6uWPaZE5rGWvg4Um2PeVbm4bxpkWRuoghxiO7ZEaJL80PlNfSwmrn9eWM+1ghKgVkG3SBI h/YJMjp0JwSfQJosWmOeOuFVVz8485AnCj1lj9R8/FKL9Ud4YBSXZFcIzrEyVRqqU46Nj5liVv5 jydeLXByNY0rn4w7vKB4d59eqFMwhobLUXPfJNhDEdthrT9nfqdX5c7OAUEOnJPX3VV3O6YtQsV XWTTeIce00yhKM3LOralS2WrCBLpzSl6OzJUcTQcARmQAMv7nqRA77Mu+ZApRXQNUR0h9ZSBuyr 8IsrohGxvBk0ljg+Je3BfSht0za0pN1emrEfOoB9jLmFbUQ0y2WIUyNThtYVRK9qtvA6qV4GafK kXuJ2vWzlRDvkbgqS+w2x/e5yOgHPGwN774TbjlyxcQ0lJMP52FSmhpdDJh9SrbzV1xquYZxQqv w== X-Received: by 2002:a05:6a21:78b:b0:3dd:a006:ed90 with SMTP id adf61e73a8af0-3dda006ee59mr12176552637.38.1790015141934; Mon, 21 Sep 2026 11:25:41 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-144df9ad683sm12408974c88.6.2026.09.21.11.25.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Sep 2026 11:25:41 -0700 (PDT) From: Abdurrahman Hussain Date: Mon, 21 Sep 2026 11:25:37 -0700 Subject: [PATCH v5 2/3] i2c: xiic: defer RX_FULL until all trailing bytes are in FIFO Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260921-i2c-xiic-v5-2-2fca81e810ea@nexthop.ai> References: <20260921-i2c-xiic-v5-0-2fca81e810ea@nexthop.ai> In-Reply-To: <20260921-i2c-xiic-v5-0-2fca81e810ea@nexthop.ai> To: Michal Simek , Andi Shyti , Wolfram Sang , Raviteja Narayanam , Wolfram Sang , Manikanta Guntupalli Cc: Shubhrajyoti Datta , linux-arm-kernel@lists.infradead.org, linux-i2c@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain , stable@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1790015138; l=2996; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=/8Wrq+rYYeuzHylPud9tnFtGR3R2iGFzmcbe02TkznE=; b=ubMp+70iyM/WFu2SL6u7ETfFM1C/uksEYesAWisxSq70C57ilk420Kkkx3zFsOacHFpd326ZC M+PBTrV7qDXBMzYY1xS+Z5RGXOLlN/FxyN7fsWzYAs0IouoYUBerFqo X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= For the normal path of xiic_smbus_block_read_setup() (rxmsg_len less than IIC_RX_FIFO_DEPTH), RFD was programmed to rxmsg_len - 2, which fires the RX_FULL interrupt while the last payload byte is still in flight. xiic_read_rx()'s bytes_rem =3D=3D 1 branch then sets NACK on that byte still on the wire, truncating the read in the PEC-enabled case. Raise the threshold so RX_FULL fires only once every remaining byte (payload plus optional PEC) is already buffered in the FIFO. That routes the drain through xiic_read_rx()'s bytes_rem =3D=3D 0 path, which reads everything out and emits the stop cleanly. For the non-PEC path the full payload is still read out through the same bytes_rem =3D=3D 0 branch; the only user-visible change is that the controller waits one extra byte-time before servicing the interrupt. The deferred-fire formula is rxmsg_len + pec_len - 1, and the RFD register at XIIC_RFD_REG_OFFSET is a 4-bit field. Widen the chunk-vs-defer guard to (rxmsg_len + pec_len > IIC_RX_FIFO_DEPTH) so the boundary case rxmsg_len =3D=3D IIC_RX_FIFO_DEPTH with PEC enabled cannot write 16 into that 4-bit register; it routes through the chunked drain instead, which already caps RFD at IIC_RX_FIFO_DEPTH - 1. Fixes: e4c1ff772e1a ("i2c: xiic: Add smbus_block_read functionality") Cc: stable@vger.kernel.org Acked-by: Michal Simek Signed-off-by: Abdurrahman Hussain --- drivers/i2c/busses/i2c-xiic.c | 14 ++++++-------- 1 file changed, 6 insertions(+), 8 deletions(-) diff --git a/drivers/i2c/busses/i2c-xiic.c b/drivers/i2c/busses/i2c-xiic.c index 22367a069ded..15fd17b703bc 100644 --- a/drivers/i2c/busses/i2c-xiic.c +++ b/drivers/i2c/busses/i2c-xiic.c @@ -546,10 +546,11 @@ static void xiic_smbus_block_read_setup(struct xiic_i= 2c *i2c) unsigned int pec_len =3D i2c->rx_msg->len - 1; =20 /* Set Receive fifo depth */ - if (rxmsg_len > IIC_RX_FIFO_DEPTH) { + if (rxmsg_len + pec_len > IIC_RX_FIFO_DEPTH) { /* - * When Rx msg len greater than or equal to Rx fifo capacity - * Receive fifo depth should set to Rx fifo capacity minus 1 + * Trailing payload (data + optional PEC) exceeds Rx FIFO + * capacity; drain in chunks. Fire RX_FULL when the FIFO is + * full and let the ISR re-arm for the remainder. */ rfd_set =3D IIC_RX_FIFO_DEPTH - 1; i2c->rx_msg->len =3D rxmsg_len + 1 + pec_len; @@ -566,11 +567,8 @@ static void xiic_smbus_block_read_setup(struct xiic_i2= c *i2c) i2c->rx_msg->len =3D SMBUS_BLOCK_READ_MIN_LEN; i2c->smbus_actual_len =3D 1 + rxmsg_len + pec_len; } else { - /* - * When Rx msg len less than Rx fifo capacity - * Receive fifo depth should set to Rx msg len minus 2 - */ - rfd_set =3D rxmsg_len - 2; + /* Defer RX_FULL until all trailing bytes are in FIFO. */ + rfd_set =3D rxmsg_len + pec_len - 1; i2c->rx_msg->len =3D rxmsg_len + 1 + pec_len; } xiic_setreg8(i2c, XIIC_RFD_REG_OFFSET, rfd_set); --=20 2.54.0 From nobody Fri Sep 25 21:02:42 2026 Received: from mail-pz2-f41.google.com (mail-pz2-f41.google.com [74.125.228.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B44F94F85D2 for ; Mon, 21 Sep 2026 18:25:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790015146; cv=none; b=XLYNXN+ADR+7lvTmy2gSDVM4OSlaZr5zi/g6jNUhNwM7hQZt4np8DKbFAAG3ooXTHR/YyK7qOQ2ZxDbK5GO3d5O010CBgOIn4qh0BhoDs2U7AndNrSv8BTcwrmRpK1CVrmiOU69j741402DvPIV/Q054OWgxudYEGtp1JvgISGk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790015146; c=relaxed/simple; bh=3PrQCnt7nbZH4iGz2QKgl18h5LexXtxJs2Js8bqLN/I=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=ZvaRytjZpHBL/FAkmu3UehYiLTHf2WP5muGoFZme6wIFkVmrGQusGs3EQU/EAKOk34xPs/wn1oBE+kPBqnUqw5sEbXo1NzhwGpjjcf9omq39Zk4Q/3HSskQ4Zo+GEisAovy2WEM/tFBeOi6tNfvMLsC87VRJSqWuNOmwDfulPBY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=YeNDycI2; arc=none smtp.client-ip=74.125.228.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="YeNDycI2" Received: by mail-pz2-f41.google.com with SMTP id d2e1a72fcca58-8693af0d7c4so3659280b3a.3 for ; Mon, 21 Sep 2026 11:25:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1790015143; x=1790619943; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=bI4n9nsSaz78+BIYtu5OrBqpRPgWw2YHv3oM1NI7hyQ=; b=YeNDycI2+4f6RI3ZJHgpYqE16crQHERefAt/AwaHe/g9vPyw6/FMj47Z+iwFcBSz/j 43uyyRjnB9kanAlAq6jGclTt0Y+RZmnDvqQK3Br+0eNfXczZcEE1oHqaYHcKEZHWfCPb bEoNYRyKDDoq4RxvScubIK3v+btx2NnomvH++7em++rilGP1yLhPEJm9IKyLOH3lFl8e FHsLyg8A9BItbuq8+X8Volc2f+oWQUXjIhzZqIyzPEzFN1HgWxg+PLkmJSV5nQZ1CByo iWSM1AX/TYvOWf1YPhfqucD3wErYuogSCXV8BMlCKHVDkON3P3O43Noo+/pY3DZNI6dK uNJA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790015143; x=1790619943; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=bI4n9nsSaz78+BIYtu5OrBqpRPgWw2YHv3oM1NI7hyQ=; b=NkPOAEJtdNd5oe/033gbUbEwAfuq191YkwJD1adawI9Xf8u83tMnOTB6mApEleSmqy lCJ2YXSEJ1Wllr/iPrTbQB1u/ZxRFueTLwRB/5QdD9YvLgO8VqvlYXb0hrKp/701zP0B 3N+320bC4JxmGeZj2JL/IDcF57Tntoo0czzyKH7fFhOJHiFo9Z7KgDzFLZzVqYTfTxFn 8hFET0cKF4rHmDt8mj4SaHnF0g64SCGW1zE3QjNsUlpUrb9GHWClXTWNzTaM8Jz37jJR EiEk19GRTCsu0G+giQwyA58PEuuN/6nMhrFmVmAzzTbo9nBbvA4/4zimi7+ZF1Ujnnn1 wN7A== X-Forwarded-Encrypted: i=1; AKwUvBzHB571wL1sbVhIIHD4mnWoCOEN5MzNqbfC95HkDcVYXrayFeaxYhBja8fKbrHNUBNnX4KLKWKM3trCp4s=@vger.kernel.org X-Gm-Message-State: AFuF++nWCTJRch40EMAQM+bTMWC8+eCnZmBNXTUPfLs5aZLgihaz/jan r3R42QypBnos/vi0ysXc2g0Ph5GfcjZ+5iaY7X4uW937ad/7A6WrMK5ODkLFJIe1v1Po/Vexovm 1qP/H3sA= X-Gm-Gg: AYBFou3MgthnAFqjkN5o/niyV5sgKaVGrE9KUUnGNQ5YehcgkQoNrtkX2h8EwB3XGdZ ROGENZvwQ8Tjk3/8CrK2cXuPXm1Tk6WNvKRGHnmzDV/5Z9JzmG+A7O1Nceg9cKJYTfvn73kebhm 8/cAMrr2xaF1PHGLAonIIeBfXhm7TKRejUUNjokwWU+cVObWsiO5QZepUcSiUba3pCme/ouns8a GhLaMlk5gVVmtARGsESH5T/777ENNBHOA4+AdInDcB6rq+nAhnIwrWNNDx8F5skfwtm+LZNCFtt WlMmPVwyCJ5XFrEGmna0vnXEr7v0ejtFInrV1HK3y176b3gwT66qowpkcrYwF2uMsdvq+HALupd ymeChNLajxE85ouN/S5vx+bdnamUvCkcRGGc2Kt1rUWTztTNV82vxcC6C2ZpKgOErpnA6+8Do+X YPfdXkdemy4nz+scnITt+2YsG/sC3LeuXWpjZqVYtwVj6Ce8XEvanbNhfB7lBPW1RJXW87HtXlr SNMcCn9QvXF X-Received: by 2002:a05:6300:48:b0:3dd:a197:cf1e with SMTP id adf61e73a8af0-3dda197d894mr11470586637.66.1790015143079; Mon, 21 Sep 2026 11:25:43 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-144df9ad683sm12408974c88.6.2026.09.21.11.25.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 21 Sep 2026 11:25:42 -0700 (PDT) From: Abdurrahman Hussain Date: Mon, 21 Sep 2026 11:25:38 -0700 Subject: [PATCH v5 3/3] i2c: xiic: don't clobber msg->len to signal block-read completion Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260921-i2c-xiic-v5-3-2fca81e810ea@nexthop.ai> References: <20260921-i2c-xiic-v5-0-2fca81e810ea@nexthop.ai> In-Reply-To: <20260921-i2c-xiic-v5-0-2fca81e810ea@nexthop.ai> To: Michal Simek , Andi Shyti , Wolfram Sang , Raviteja Narayanam , Wolfram Sang , Manikanta Guntupalli Cc: Shubhrajyoti Datta , linux-arm-kernel@lists.infradead.org, linux-i2c@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain , stable@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1790015138; l=2009; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=3PrQCnt7nbZH4iGz2QKgl18h5LexXtxJs2Js8bqLN/I=; b=QpYMk3wrZCPsBPJzi7e5IC/yKs9xc3WDRsvHMvbgmZ/JbIufqHEZJ+oMndO7RLskhkFHF8Dfm W10xBDmcpW3AiecVrKdpTJV3FKT6eEkSAmnb6uidqNVds4cIB9Kssiz X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= At the end of a SMBus block read the BNB handler force-set tx_msg->len =3D 1 to push xiic_tx_space() to zero so the STATE_DONE branch would fire. Two problems: 1. tx_msg and rx_msg alias the same i2c_msg struct during a receive (see xiic_start_recv), so overwriting tx_msg->len also changes rx_msg->len. The i2c core's i2c_smbus_check_pec() then reads the PEC from the wrong offset -- buf[0] instead of buf[rxmsg_len + 1] -- and either mis-validates or returns -EBADMSG. 2. xiic_start_recv sets tx_pos =3D msg->len (typically 2 when PEC is enabled). xiic_tx_space() is unsigned msg->len - tx_pos, so setting msg->len =3D 1 with tx_pos =3D 2 underflows to 0xFFFFFFFF and xiic_tx_space() never compares equal to 0 -- the STATE_DONE check falls through to STATE_ERROR, giving -EIO. Instead, advance tx_pos up to msg->len. That drives tx_space to 0 without touching msg->len, preserving the buffer length that xiic_smbus_block_read_setup() already grew to cover the length byte, the payload and the optional PEC byte. Fixes: e4c1ff772e1a ("i2c: xiic: Add smbus_block_read functionality") Cc: stable@vger.kernel.org Acked-by: Michal Simek Signed-off-by: Abdurrahman Hussain --- drivers/i2c/busses/i2c-xiic.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/drivers/i2c/busses/i2c-xiic.c b/drivers/i2c/busses/i2c-xiic.c index 15fd17b703bc..d5e7b089a2b8 100644 --- a/drivers/i2c/busses/i2c-xiic.c +++ b/drivers/i2c/busses/i2c-xiic.c @@ -879,8 +879,11 @@ static irqreturn_t xiic_process(int irq, void *dev_id) =20 if (i2c->tx_msg && i2c->smbus_block_read) { i2c->smbus_block_read =3D false; - /* Set requested message len=3D1 to indicate STATE_DONE */ - i2c->tx_msg->len =3D 1; + /* + * Drive xiic_tx_space() to 0 to signal STATE_DONE + * without truncating the rx_msg length. + */ + i2c->tx_pos =3D i2c->tx_msg->len; } =20 if (!i2c->tx_msg) --=20 2.54.0