From nobody Fri Sep 25 17:45:46 2026 Received: from mail-dy2-f12.google.com (mail-dy2-f12.google.com [74.125.229.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7CA0E1C862F for ; Fri, 25 Sep 2026 00:10:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.229.12 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790295043; cv=none; b=jgR0dgwN7kzDn3Vdu9Isp019x/n0EUiymnneFaH+vbNxVuYwQEVSoNz/2NixEIE7WWAaVgWqwOIOSxNQUUuqhKaqnXEAWgfQDNl3lG0ia51fRa5Tvtp9AwL+KQi/8FXOTP2IxPRp5xUuT0ECuE6G0vMXR33y4FUAkACC4UYAbaw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790295043; c=relaxed/simple; bh=eTX02wyE5ouxkmqtS51Q5M+dSBWGkFgKNZs9s5Tgfw8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Yo7x++46DvO1+JIV4cUoyUgDbfJroj011H7cg0zFMVogatQM21qQJsYSn/FSYSEP0ns9pl4mu6eJjEl8C1fkx0QekhnA/DnUcVdMYgIIs31CfiVEv2Z+YtgPdd7Xsa6j+3DA3lZCT9S+EVyJ3XQwhGSArP2k7REtpyz7DNwtXkI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=MVkZLOvi; arc=none smtp.client-ip=74.125.229.12 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="MVkZLOvi" Received: by mail-dy2-f12.google.com with SMTP id 5a478bee46e88-33b9e805130so188775eec.1 for ; Thu, 24 Sep 2026 17:10:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1790295040; x=1790899840; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pwla+qYJcPM+0e9z6oZqkKd9MiKwlDQWnaoxKLv8300=; b=MVkZLOviCDRDKzGLjEqNeqeohJjejwY9fqje9rGhCqZBRXgoIlitAuTo4HphBJDPvO gGT7zGtSPWqu6CCHCRMnfMBW9sJIoOWhkH7uife9gDnLq3vdi+8YQckHKgs9//JWf21x m4igREIqZOKIPlClcj/j6X8/5M40cZsIvwpRs1aXYMbZeXJ+j8vRY2pvrnKChHPFRp60 4d6WEAOBmDR34/BFhRk0qkN1oaiVEP3h3NSmsv7Lf07vtbD5pLiMM5GcduVIORaKetzp O0VaBiYRGTwZ0hUzo/iK7bhXUkOVyfb5TLi0QHAYTQ8py7DBkLqakHRcUFkNXFOOAjMW 63wA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790295040; x=1790899840; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=pwla+qYJcPM+0e9z6oZqkKd9MiKwlDQWnaoxKLv8300=; b=a+jlYT5AwOtPm+0adCZGiuAbXKxDbGzYXF837+/aoLm9yyTxXqhR16fkVGmKeFlVdH Tg6eXlvtIC5ekc9ZoLiRQrjh+sBm8k+bs9MPWR/cyF9B2nJo8MuztU7ci5eQjxDTh0pl YpJRux1Usf7IwGMvt8eBORFt0gHVe6pmHa6X8WRERlg+c/hSKgNBXrfzkENbN9iE9grT CcU7XYV7u3nJUt8aYjmcDbX0Oxrx5Up+umG5Yad0i/KmS+Yb+K2WCl5wy+Q41OhQesh5 rFXIJRTvHS1zmXn9mqPvdQOj3pN/LGwstkvyCv+h3rM9uZ9etuk502s8uoP3+qpZt5hD ye7Q== X-Forwarded-Encrypted: i=1; AKwUvBzBHgG71zpk/oLm/JlojdEPaaxUmO5E6TbAVlN0rOogSxpW7yVfsZMYDz4IX6bgxk/JWbD/7fxLqDkdFNM=@vger.kernel.org X-Gm-Message-State: AFuF++miYgDMFp+njQPom81S0ERag24JBz3HptwVaAr3T95xsWhj3/E0 gk/2WCMgRU6ptX8f48f+akuktuf9AKyWy0H0RYVU51D/UCRnbJd2BYQAgLpasZPE5BbHqexEEvp NwQbFmcs= X-Gm-Gg: AYBFou3s8eVAcjVjYe6t3m6fiT/OzLZub3lcl7k5zKzkvW98ffWfQabYEdH4KmeKZik O6IXDe8bSVWNO15OWK0GjRez6iQJDvqUSD9ff0NeqXtWjXuYD/PPA9xPRInAjjeD5Of9CZp012G VVItCm6racR6Pb2EdxaZSYQRxM8gKZWlfM+tNcnYKRpGUF8QIMZrauphk4BXCkecTWaLUVm/7/f UlZhDQTOaMWZCbpW35uNvRN+Amn3IJ04wT7yHu+zPB+pnunurUaB4sjtdzNHB5+e4wqOHEnePue pFrb2WEU+4svznDXhJD10787blOrkg/N0WGrsXwVxlKxhTM08OVgSA3sG/PhJcpXR++HnKok5G3 VeDWTpmb8oH0MiE/VZzaKQKdMt1ZbGygyihYaZh4d5koFFOSTYU8sOI3NThcWV3Wu7vZrG3Ex6U PVis1V5mh45+N1FLRrdsEkqPr8byif6sf/sekXXpZBKavjP6+D1oESfwGH1hOPeGYVL+XyvEEaV Q== X-Received: by 2002:a05:7300:ea06:b0:33b:ef1f:14b9 with SMTP id 5a478bee46e88-34004b8b691mr2871986eec.15.1790295040193; Thu, 24 Sep 2026 17:10:40 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-34145632298sm1787647eec.22.2026.09.24.17.10.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 24 Sep 2026 17:10:39 -0700 (PDT) From: Abdurrahman Hussain Date: Thu, 24 Sep 2026 17:10:35 -0700 Subject: [PATCH v7 1/3] i2c: xiic: preserve PEC byte length in SMBus block read setup Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260924-i2c-xiic-v7-1-df7e752332ef@nexthop.ai> References: <20260924-i2c-xiic-v7-0-df7e752332ef@nexthop.ai> In-Reply-To: <20260924-i2c-xiic-v7-0-df7e752332ef@nexthop.ai> To: Michal Simek , Andi Shyti , Wolfram Sang , Raviteja Narayanam , Wolfram Sang , Manikanta Guntupalli Cc: Shubhrajyoti Datta , linux-arm-kernel@lists.infradead.org, linux-i2c@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain , stable@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1790295038; l=7659; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=eTX02wyE5ouxkmqtS51Q5M+dSBWGkFgKNZs9s5Tgfw8=; b=Q5/svQRlhuGQRMYEZeJJuOrRs5jygK4L1lcoVPD2tvjABzzrUIY8/KC5yrUKakTQcQjaI2VID ClMbLuhatI9BVSbA9jhvfZ7FQg6QAb+f9LCoK7/U+te4iDr5kg7J4dO X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= xiic_smbus_block_read_setup() recalculates i2c->rx_msg->len based on the length byte returned by the device, but historically clobbered the PEC byte expectation the SMBus core had baked into msg->len. That dropped the PEC byte from the caller's buffer on the normal and chunked receive-fifo branches. Compute pec_len up-front as (i2c->rx_msg->len - 1) -- the trailing bytes the caller has already accounted for beyond the length byte, 1 when the SMBus core enabled PEC, and possibly more for an I2C_M_RECV_LEN request coming from i2c-dev -- and add it to the new length in every branch: - chunked: the trailing bytes do not fit in the Rx FIFO, so drain in chunks. The guard becomes (rxmsg_len + pec_len > IIC_RX_FIFO_DEPTH) rather than rxmsg_len alone, both because pec_len bytes also have to fit and because it is what bounds rfd_set in the else branch below to the 4 bits of XIIC_RFD_REG_OFFSET. - padded (1 + rxmsg_len + pec_len < SMBUS_BLOCK_READ_MIN_LEN): the hardware needs at least 3 bytes on the bus to exit the read cleanly (the second byte is already being clocked in by the time the ISR reads the length byte and is too late to NACK), so we still pad rx_msg->len up to SMBUS_BLOCK_READ_MIN_LEN. The dummy trailing byte that gets drained must then be trimmed off before handing the message back to the SMBus core; otherwise i2c_smbus_check_pec() reads buf[len-1] (=3D dummy) instead of the real PEC byte at buf[1] and rejects every clean zero-length block read with -EBADMSG. Record the true valid byte count in a new field i2c->smbus_actual_len and trim rx_msg->len down to it in xiic_smbus_trim_len(), called from both completion sites that clear rx_msg: xiic_process()'s RX_FULL branch and xiic_recv_atomic(), which drains the FIFO with interrupts off. smbus_actual_len is per-receive state, so xiic_start_recv() clears it before every receive. Only the padded branch ever sets it, and a block read aborted by arbitration loss or a TX error never reaches the completion site, so without that clear a stale value would trim the length of an unrelated later read. The condition is expressed in total bytes rather than the old "(rxmsg_len =3D=3D 1) || (rxmsg_len =3D=3D 0)" so that a request carryi= ng more than one trailing byte does not get padded: padding records a length the drain never reaches, which would hand the caller a byte that was never received. - normal: all trailing bytes fit in one FIFO fill. rfd_set gains pec_len for the same reason the length does. Because the padded branch above has already taken every case with fewer than SMBUS_BLOCK_READ_MIN_LEN total bytes, rxmsg_len + pec_len is at least 2 here and the subtraction cannot underflow the u8. Fixes: e4c1ff772e1a ("i2c: xiic: Add smbus_block_read functionality") Cc: stable@vger.kernel.org Acked-by: Michal Simek Signed-off-by: Abdurrahman Hussain --- drivers/i2c/busses/i2c-xiic.c | 54 ++++++++++++++++++++++++++++++++-------= ---- 1 file changed, 41 insertions(+), 13 deletions(-) diff --git a/drivers/i2c/busses/i2c-xiic.c b/drivers/i2c/busses/i2c-xiic.c index 3e7735e1dae0..0777de45bdf4 100644 --- a/drivers/i2c/busses/i2c-xiic.c +++ b/drivers/i2c/busses/i2c-xiic.c @@ -73,6 +73,9 @@ enum i2c_scl_freq { * @prev_msg_tx: Previous message is Tx * @quirks: To hold platform specific bug info * @smbus_block_read: Flag to handle block read + * @smbus_actual_len: Valid byte count (length + payload + optional PEC) o= f a + * padded SMBus block read. msg->len is trimmed to this on completion. + * Zero when no trimming is needed. * @input_clk: Input clock to I2C controller * @i2c_clk: I2C SCL frequency * @atomic: Mode of transfer @@ -98,6 +101,7 @@ struct xiic_i2c { bool prev_msg_tx; u32 quirks; bool smbus_block_read; + unsigned int smbus_actual_len; unsigned long input_clk; unsigned int i2c_clk; bool atomic; @@ -539,30 +543,38 @@ static void xiic_smbus_block_read_setup(struct xiic_i= 2c *i2c) =20 /* Check if received length is valid */ if (rxmsg_len <=3D I2C_SMBUS_BLOCK_MAX) { + unsigned int pec_len =3D i2c->rx_msg->len - 1; + /* Set Receive fifo depth */ - if (rxmsg_len > IIC_RX_FIFO_DEPTH) { + if (rxmsg_len + pec_len > IIC_RX_FIFO_DEPTH) { /* - * When Rx msg len greater than or equal to Rx fifo capacity - * Receive fifo depth should set to Rx fifo capacity minus 1 + * Trailing bytes (payload plus any PEC) exceed Rx FIFO + * capacity, so drain in chunks. This also keeps the + * else branch below from pushing rfd_set past the + * 4-bit XIIC_RFD_REG_OFFSET field. */ rfd_set =3D IIC_RX_FIFO_DEPTH - 1; - i2c->rx_msg->len =3D rxmsg_len + 1; - } else if ((rxmsg_len =3D=3D 1) || - (rxmsg_len =3D=3D 0)) { + i2c->rx_msg->len =3D rxmsg_len + 1 + pec_len; + } else if (1 + rxmsg_len + pec_len < SMBUS_BLOCK_READ_MIN_LEN) { /* - * Minimum of 3 bytes required to exit cleanly. 1 byte - * already received, Second byte is being received. Have - * to set NACK in read_rx before receiving the last byte + * The HW needs SMBUS_BLOCK_READ_MIN_LEN bytes on the + * bus to exit cleanly: by the time the ISR reads the + * length byte the second byte is already being clocked + * in, too late to NACK. Pad the drain target and record + * the real length, trimmed back on completion so the + * PEC check sees the right byte. */ rfd_set =3D 0; i2c->rx_msg->len =3D SMBUS_BLOCK_READ_MIN_LEN; + i2c->smbus_actual_len =3D 1 + rxmsg_len + pec_len; } else { /* - * When Rx msg len less than Rx fifo capacity - * Receive fifo depth should set to Rx msg len minus 2 + * All trailing bytes fit in the Rx FIFO. The widened + * condition above guarantees rxmsg_len + pec_len >=3D 2, + * so this cannot underflow. */ - rfd_set =3D rxmsg_len - 2; - i2c->rx_msg->len =3D rxmsg_len + 1; + rfd_set =3D rxmsg_len + pec_len - 2; + i2c->rx_msg->len =3D rxmsg_len + 1 + pec_len; } xiic_setreg8(i2c, XIIC_RFD_REG_OFFSET, rfd_set); =20 @@ -575,6 +587,16 @@ static void xiic_smbus_block_read_setup(struct xiic_i2= c *i2c) dev_err(i2c->adap.dev.parent, "smbus_block_read Invalid msg length\n"); } =20 +/* + * Undo the setup-time padding of a short SMBus block read before rx_msg is + * cleared, so the PEC check sees the right byte. + */ +static void xiic_smbus_trim_len(struct xiic_i2c *i2c) +{ + if (i2c->rx_msg && i2c->smbus_actual_len) + i2c->rx_msg->len =3D i2c->smbus_actual_len; +} + static void xiic_read_rx(struct xiic_i2c *i2c) { u8 bytes_in_fifo, cr =3D 0, bytes_to_read =3D 0; @@ -797,6 +819,8 @@ static irqreturn_t xiic_process(int irq, void *dev_id) =20 xiic_read_rx(i2c); if (xiic_rx_space(i2c) =3D=3D 0) { + xiic_smbus_trim_len(i2c); + /* this is the last part of the message */ i2c->rx_msg =3D NULL; =20 @@ -938,6 +962,7 @@ static void xiic_recv_atomic(struct xiic_i2c *i2c) return; } =20 + xiic_smbus_trim_len(i2c); i2c->rx_msg =3D NULL; xiic_irq_clr_en(i2c, XIIC_INTR_TX_ERROR_MASK); =20 @@ -955,6 +980,9 @@ static void xiic_start_recv(struct xiic_i2c *i2c) u8 cr =3D 0, rfd_set =3D 0; struct i2c_msg *msg =3D i2c->rx_msg =3D i2c->tx_msg; =20 + /* A stale value from an aborted block read would truncate this msg. */ + i2c->smbus_actual_len =3D 0; + if (!i2c->atomic) dev_dbg(i2c->adap.dev.parent, "%s entry, ISR: 0x%x, CR: 0x%x\n", __func__, xiic_getreg32(i2c, XIIC_IISR_OFFSET), --=20 2.54.0 From nobody Fri Sep 25 17:45:46 2026 Received: from mail-dl2-f43.google.com (mail-dl2-f43.google.com [74.125.229.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 75F6519CC0F for ; Fri, 25 Sep 2026 00:10:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.229.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790295043; cv=none; b=HncDYc/cOv7ixqwQrlEZWq9i+TvlJC9l4k/a/C9xzA3Xp62ilvhOlSDIoGF8h3LKqBFZ5g8u0JzYUEgHM2vwthYqvYxKpRiMbnWmWmg/K+i5NCeygBUQirK6+Hg6Et5ZXKit+Uew3b7UaCO+JMUZ+T8dQsBe+/nfd1Gp21e+OPw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790295043; c=relaxed/simple; bh=/cxIRdqKu8S8t3VbgiqidVXFl1GWt0Sm4m+5jxGzei8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=MZDDEe5VS3G7b2iW3oLyJoeB/9nWAJGpRoqZOp1LfhDGFBu14Ve+HEUv3odd/DFWSBZ+kVQcxlsnZVGfBqLF3AyBtQvKi7oPtxu8izMDS7RBhNkgK+c1YMuapqt3ucEiGN8IRxM1dv0slLWL/GDYsAuINZ7Oegtvd4bNeu/GlVc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=bDycZj2a; arc=none smtp.client-ip=74.125.229.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="bDycZj2a" Received: by mail-dl2-f43.google.com with SMTP id a92af1059eb24-142dd025d06so226597c88.1 for ; Thu, 24 Sep 2026 17:10:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1790295041; x=1790899841; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=YlaWOdm+KrKq03MPPT9DB6CjgbrirrQUyiKzlIWUgEo=; b=bDycZj2a3Klsn4a8TKNizRgS8FI+b6kIZmFjvP3/TJY0TKomOIvmRC+nvM05qjfTbR R8NuQdJhcPiZCpDS2Eg0gU/o4Y4G8mQLUHVrI50yLSolWJradMvbHoGkmZwGEa6Fq5r8 RhKwiNbd9xHWNvw3pIvkuP7Q4HJFTXC8vqibSyEpVChYE11JjRJa6PJ3eU0hoq0rfiUu V1XvashMRIdK0XfItuF/6Jp8pSaYJiUVyP9sZ2Jov+jIvFRMxtMoJYyOOG819+0u+JNy FfB053A8/D0rG7dPPdOL4QP7p8maZrf9JloX7A3TxE6mx4NCqooBhpzC2hH6mYlE0oTJ HLcg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790295041; x=1790899841; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=YlaWOdm+KrKq03MPPT9DB6CjgbrirrQUyiKzlIWUgEo=; b=sAusDHIlzPHbsACXm/KbMCKC4CIDHE/F4o0xKwkgJ8nLXUoT9npYOgI1aivYfIljOl cnF6233xOTnxAC/mYhiUJEqVnufq0g4JBMzYYIXL87QmQPB4nKGPLkQRIsKMCA+cqg/h axLNXkiJnfo//GYG0BJu44/he4wlvuWy14bcoX9Ef9a+eb6iShuugBGHE3FWlzX8KbOk WSGdUFqHnKZH3b6lN7Riin/Pp8kep/J5nLOqU7JnRjKnaev07MaLB6yltGx3c+Y99JhE JeP1X1taGCYs2hm8TIofHQNzkEFuvzMcB9FEkXw4nRXOY895WKPpS6y4nI3lKe1p02FT HCbw== X-Forwarded-Encrypted: i=1; AKwUvBwCOhdlj1Fi6D7bR4Zo+CVnNXUQQT0+aN53Y47hycvg3I4OKQETtEHpLbqBUSt+05YDZfRshvwX6Q0ZQz8=@vger.kernel.org X-Gm-Message-State: AFuF++n56k/gt8Hy/ueYI3aFtePkQ1tS5Rmpdy0hamV1GkNXKMa7n2MX kyga5WNEFACIIogq8NZVpPF63F6JA+tFU8zX/5nC3AKUB5wCBJmZqkXHHs5/zqYKQy/bBN+a8ok CmArfwXY= X-Gm-Gg: AYBFou2uVyhOThvo+tfJVLjWkiH1uuAIenHbPcyo7g4aXs2cw3I7pCL9Ca36DFpviKW hPdhPfXILdxDCEmuLEsPspJgo1jZv1HGHyoD3Kw2yd5HYQ2NTMLhdkDnHOz6g3uptVNGV/UJYhL iyNHMKBKsxpsSfygICrbmgt/CFwoVcnCB4L+uiiC9yZupyayawh6b3mmrRWxJ5rohvI6/pCoXrf 7pVGsc0k27Zgwr2gQDkjuvIPqH3THW09KS22S2HU16B8Lni4jS1s50IZVCrGFMDVu+vY9VEr4eV +DhUQyhci1eRM+q8GtkIPY6+8Jf7diU8nQy4bWOXe976ewVsOcLZ+3/lw1bxjIxohIIwzAXJN1o kMvmGKZ+cd5kDKtXwJUX49DIX8fiWmj/W5faO3fUko3QWJm4RA0HfbNYgb5HLQJ3RdKUDIen78B ddWnmylI3OHNnUvyIUu12E+w9R4t1HHWJF9Zw9GTXR/Vpu7ZDqavn/Q/ozMgPTnWBiEndGC/OBm A== X-Received: by 2002:a05:693c:87c3:10b0:33b:c478:a545 with SMTP id 5a478bee46e88-34002be4604mr2878731eec.8.1790295041240; Thu, 24 Sep 2026 17:10:41 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-34145632298sm1787647eec.22.2026.09.24.17.10.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 24 Sep 2026 17:10:40 -0700 (PDT) From: Abdurrahman Hussain Date: Thu, 24 Sep 2026 17:10:36 -0700 Subject: [PATCH v7 2/3] i2c: xiic: defer RX_FULL until all trailing bytes are in FIFO Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260924-i2c-xiic-v7-2-df7e752332ef@nexthop.ai> References: <20260924-i2c-xiic-v7-0-df7e752332ef@nexthop.ai> In-Reply-To: <20260924-i2c-xiic-v7-0-df7e752332ef@nexthop.ai> To: Michal Simek , Andi Shyti , Wolfram Sang , Raviteja Narayanam , Wolfram Sang , Manikanta Guntupalli Cc: Shubhrajyoti Datta , linux-arm-kernel@lists.infradead.org, linux-i2c@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain , stable@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1790295038; l=2278; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=/cxIRdqKu8S8t3VbgiqidVXFl1GWt0Sm4m+5jxGzei8=; b=a+pbWTcLJPiSEUJjIdHnPTS8tKRM1v4Eldm+PcCmLAtpHVPSWyDvgonMUJh9zoSaSWFyjR0YG CO5ORipMLjTAYdDSZY8+8zBXwdw4DNgwyluzbLCy8U3+O7iIeZNMm8L X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= For the normal path of xiic_smbus_block_read_setup() -- the trailing bytes all fit in one Rx FIFO fill -- RFD was programmed two below the byte count, which fires the RX_FULL interrupt while the last byte is still in flight. xiic_read_rx() then lands in its bytes_rem =3D=3D 1 branch and sets NACK on a byte still on the wire, truncating the read. Without PEC this is harmless: the truncated byte is the dummy one the caller never looks at. With PEC enabled it is the PEC byte itself, and i2c_smbus_check_pec() fails the transfer with -EBADMSG. Raise the threshold by one so RX_FULL fires only once every remaining byte is already buffered. That routes the drain through xiic_read_rx()'s bytes_rem =3D=3D 0 path, which reads everything out and emits the stop cleanly. The only change for the non-PEC case is that the controller waits one extra byte-time before servicing the interrupt. rfd_set stays inside the 4 bits of XIIC_RFD_REG_OFFSET: this branch is only reached when rxmsg_len + pec_len <=3D IIC_RX_FIFO_DEPTH, so the value is at most IIC_RX_FIFO_DEPTH - 1. Fixes: e4c1ff772e1a ("i2c: xiic: Add smbus_block_read functionality") Cc: stable@vger.kernel.org Acked-by: Michal Simek Signed-off-by: Abdurrahman Hussain --- drivers/i2c/busses/i2c-xiic.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/drivers/i2c/busses/i2c-xiic.c b/drivers/i2c/busses/i2c-xiic.c index 0777de45bdf4..5cd737c7608f 100644 --- a/drivers/i2c/busses/i2c-xiic.c +++ b/drivers/i2c/busses/i2c-xiic.c @@ -569,11 +569,11 @@ static void xiic_smbus_block_read_setup(struct xiic_i= 2c *i2c) i2c->smbus_actual_len =3D 1 + rxmsg_len + pec_len; } else { /* - * All trailing bytes fit in the Rx FIFO. The widened - * condition above guarantees rxmsg_len + pec_len >=3D 2, - * so this cannot underflow. + * All trailing bytes fit in the Rx FIFO. Defer RX_FULL + * until every one of them is buffered, so the drain + * takes xiic_read_rx()'s bytes_rem =3D=3D 0 path. */ - rfd_set =3D rxmsg_len + pec_len - 2; + rfd_set =3D rxmsg_len + pec_len - 1; i2c->rx_msg->len =3D rxmsg_len + 1 + pec_len; } xiic_setreg8(i2c, XIIC_RFD_REG_OFFSET, rfd_set); --=20 2.54.0 From nobody Fri Sep 25 17:45:46 2026 Received: from mail-dl1-f47.google.com (mail-dl1-f47.google.com [74.125.82.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2E1D51A6807 for ; Fri, 25 Sep 2026 00:10:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790295049; cv=none; b=lUeLC5uHXTNA0fcz1iMKU/zq3oZWY1Rq/Fs+VUbcC2nuNLhdmnxO2+77bXfVNiKiFsv5Qwxe1mTllGZuFn3R5llc2CGg95Gg4U0M5XXpfUYLExmEXa3CGrjDnz0E7/Md3R27eGG5g4PfIiLUe+osY12nwT/w7tO0Gn5q+Q6PDjM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790295049; c=relaxed/simple; bh=1rvaVBS5z3PcQvipdDAj9WVWm6JugqJIhc+zC3OYV1M=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=lO/mvmEEbG9xzbe7cmxnNEtDzLf6e0g/389bH1epH5uP9qfu6FYPcb3ezW8XtpWJEzUVCtp0Edk7DlGDCDJ7XxvLm4WfQp1/xie5+os+Szh9UTP/yeehRYHXnaiTk0zobyDBIKfQvJMCGbrdHrZ3xYvpsaO0aEe+uVw5+PKmm0c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai; spf=pass smtp.mailfrom=nexthop.ai; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b=EBdYKyLI; arc=none smtp.client-ip=74.125.82.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=nexthop.ai Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=nexthop.ai header.i=@nexthop.ai header.b="EBdYKyLI" Received: by mail-dl1-f47.google.com with SMTP id a92af1059eb24-13fc403e373so1528517c88.1 for ; Thu, 24 Sep 2026 17:10:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nexthop.ai; s=google; t=1790295047; x=1790899847; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uoMaAm02Pyqn85C4te1/bOInshnG9mfbEU4HCghL9sk=; b=EBdYKyLIywsel9vL2v0ZMC0C7AlLUSwzpcten36NL/AK8/zjsODH9r5iyS85MOf2NS vUjIKyUszy3/ciYK8N33oUrRXXW+E+aGhatSK0mqX6q2rY0qDIo+s06Ebp+AL4oTsiJL bEqdTtz1Lj+w4H1wJkNobd7Ju/3/NKD2Q1ImxpHMokwxClgILKTtDGtJg1499RZvSo1b 7SBqyE0CsBhSdYgd7Ce/Ag8SxCfTl4MEnejeqcvOwqQjWaiBMfqbU88TFMO07/bZwKO0 l7mHfvWnAW7hrjiBqR4rGGScRER2znSK/gmk28O55zsz6N9Tn4Nq/+wyCv4GAUYwW+Ix oUlw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790295047; x=1790899847; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=uoMaAm02Pyqn85C4te1/bOInshnG9mfbEU4HCghL9sk=; b=AxpCPvIMT6Y++4PrW5dEPudUP8cdGtSCvHX4GhGcll/5GGGDfmxfKzKpWBmQT6LvlK uhx70ieMJf0c3FOpP1i2V3vm55Ge0TOY1huoiq8mzWIxu0GtGmK5QMqvsqtevHfjwHrX ldOk4igSNDIAEbUHzsSXWZZOu9Y/EBVn9esAy+x5LMNCLb7kM6AruKGmNGkB9xFYxAgA Kfxhbmeb52j4wzOb5zbUu6JzZa0igjgu1XMiGsvNwV9LDObEMVdzZgqgTw2x0wf6Hbmt 9o53Th6ML9yBj/sH8XNhkKqbBrxuObT2HDpnA8/aGetfv5eFl8ISA7jaBIThfKnYbOu+ 7q4Q== X-Forwarded-Encrypted: i=1; AKwUvBwmYdjBiM4fODKh9jib5c6bw+Oo+NxoLcVZeusv/YhA4Li5K9pKkO0fmL2tamiIsVBzq8nBjagweTOgnJ4=@vger.kernel.org X-Gm-Message-State: AFuF++kWV4r8cNYzxZhpq/i9CEDqQe0dQCoGSKBt84GyBMoieK4GRDUt GtLtWYEYsgtZxw4PiwWAe/vR5l73GBRaD72XO+kCCbO8sdp59anM8tsSu2b4Y4f8PkemdlIPsED b57vzVj4= X-Gm-Gg: AYBFou2lolEjU+O9pknQwuyftJRfhNPQLsk+1cM5ws5r9X0ir6dSwBx1bzvMRXMdheO hQfOnqlBc+oRq3je6R+H17c6b2T7uitD851m8vf96x4mcykZKSTKtX4/Q/tgBWqLoeL3qecK3g8 8z5SgW6vSTF5bPwAd4DGmb74EqtaJ2PJ7aCIas8HeAKTbmUQCVQVZ7++oSFvT/8oQYJCwbsciMK xcUx4hFizSOHoaYt42Y/MbT+DBCLSTPN+gIFB1hIBu72W0Rph1r3i0q0zdDYFq9NdFrBgOSP3mD hsz9a/Bj9PJqWkfwLRgK9ugeWswmV0RzUtllDA/zca4/MCMVLsBZOhrXsidS//2YpsWCW+SONGB RCJR0yhGLenaRp4sKX6t/A6vpZLU+wK7TDgje4bxUpEGy/+qxV3EyDbtw1Wc5NndKPgn6CLu6qI FaKojYsJIXgfdhegzLIvN032xRbpWLB9NwWEPVJM/VxCEbbohTPYXU3K45jlK5kARTWDTkuSrhY g== X-Received: by 2002:a05:701b:4254:20b0:136:4bbe:9524 with SMTP id a92af1059eb24-1450403dc38mr3141393c88.10.1790295042387; Thu, 24 Sep 2026 17:10:42 -0700 (PDT) Received: from [127.0.0.2] ([50.145.100.174]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-34145632298sm1787647eec.22.2026.09.24.17.10.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 24 Sep 2026 17:10:41 -0700 (PDT) From: Abdurrahman Hussain Date: Thu, 24 Sep 2026 17:10:37 -0700 Subject: [PATCH v7 3/3] i2c: xiic: don't clobber msg->len to signal block-read completion Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260924-i2c-xiic-v7-3-df7e752332ef@nexthop.ai> References: <20260924-i2c-xiic-v7-0-df7e752332ef@nexthop.ai> In-Reply-To: <20260924-i2c-xiic-v7-0-df7e752332ef@nexthop.ai> To: Michal Simek , Andi Shyti , Wolfram Sang , Raviteja Narayanam , Wolfram Sang , Manikanta Guntupalli Cc: Shubhrajyoti Datta , linux-arm-kernel@lists.infradead.org, linux-i2c@vger.kernel.org, linux-kernel@vger.kernel.org, Abdurrahman Hussain , stable@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1790295038; l=2009; i=abdurrahman@nexthop.ai; s=20260510; h=from:subject:message-id; bh=1rvaVBS5z3PcQvipdDAj9WVWm6JugqJIhc+zC3OYV1M=; b=CeyCZ+j6PyXwi2IxNzqHNhjgrX9Og3sz3PrfkkWqKWWMlqelDQm1WAl8kwmODXCZf5TYFasH7 auvAVv5l3aKDqLqlLiHm/m/SAC2AwA1Kj6Zst3jMHnPM3mIuPqGGkse X-Developer-Key: i=abdurrahman@nexthop.ai; a=ed25519; pk=omTm9cCAbO0ZhS32aKfJDKue0W3sQGpG9ub5eYHif8I= At the end of a SMBus block read the BNB handler force-set tx_msg->len =3D 1 to push xiic_tx_space() to zero so the STATE_DONE branch would fire. Two problems: 1. tx_msg and rx_msg alias the same i2c_msg struct during a receive (see xiic_start_recv), so overwriting tx_msg->len also changes rx_msg->len. The i2c core's i2c_smbus_check_pec() then reads the PEC from the wrong offset -- buf[0] instead of buf[rxmsg_len + 1] -- and either mis-validates or returns -EBADMSG. 2. xiic_start_recv sets tx_pos =3D msg->len (typically 2 when PEC is enabled). xiic_tx_space() is unsigned msg->len - tx_pos, so setting msg->len =3D 1 with tx_pos =3D 2 underflows to 0xFFFFFFFF and xiic_tx_space() never compares equal to 0 -- the STATE_DONE check falls through to STATE_ERROR, giving -EIO. Instead, advance tx_pos up to msg->len. That drives tx_space to 0 without touching msg->len, preserving the buffer length that xiic_smbus_block_read_setup() already grew to cover the length byte, the payload and the optional PEC byte. Fixes: e4c1ff772e1a ("i2c: xiic: Add smbus_block_read functionality") Cc: stable@vger.kernel.org Acked-by: Michal Simek Signed-off-by: Abdurrahman Hussain --- drivers/i2c/busses/i2c-xiic.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/drivers/i2c/busses/i2c-xiic.c b/drivers/i2c/busses/i2c-xiic.c index 5cd737c7608f..5e397a7e63f6 100644 --- a/drivers/i2c/busses/i2c-xiic.c +++ b/drivers/i2c/busses/i2c-xiic.c @@ -889,8 +889,11 @@ static irqreturn_t xiic_process(int irq, void *dev_id) =20 if (i2c->tx_msg && i2c->smbus_block_read) { i2c->smbus_block_read =3D false; - /* Set requested message len=3D1 to indicate STATE_DONE */ - i2c->tx_msg->len =3D 1; + /* + * Drive xiic_tx_space() to 0 to signal STATE_DONE + * without truncating the rx_msg length. + */ + i2c->tx_pos =3D i2c->tx_msg->len; } =20 if (!i2c->tx_msg) --=20 2.54.0