Thread (26 messages) 26 messages, 2 authors, 7d ago

Re: [PATCH v10 11/19] spi: cadence-quadspi: enable PHY for direct reads

From: sashiko-bot@kernel.org
Date: 2026-09-29 06:59:36

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] spi: cadence-quadspi: hardware state leak on PHY read disable timeout
--

commit 439a6492544eb30602326054af398141c453e461
Author: Santhosh Kumar K [off-list ref]

spi: cadence-quadspi: enable PHY for direct reads

Add cqspi_tune_phy_read() to toggle PHY mode around a direct-mode DMA
read. On enable, it reprograms the DLL from the per-CS calibration result,
configures read-capture for the tuned delay, and asserts PHY_EN and
PHY_PIPELINE in CONFIG. A fallback mechanism drops the clock to the base
rate for operations that cannot use the tuned PHY.
quoted hunk ↗ jump to hunk
diff --git a/drivers/spi/spi-cadence-quadspi.c b/drivers/spi/spi-cadence-quadspi.c
index 494008b953cd6..ad99e72578337 100644
--- a/drivers/spi/spi-cadence-quadspi.c
+++ b/drivers/spi/spi-cadence-quadspi.c
[ ... ]
quoted hunk ↗ jump to hunk
@@ -1075,6 +1076,105 @@ static int cqspi_resync_dll(struct cqspi_st *cqspi)
[ ... ]
quoted hunk ↗ jump to hunk
+static int cqspi_tune_phy_read(struct cqspi_flash_pdata *f_pdata, bool enable)
+{
+	struct cqspi_st *cqspi = f_pdata->cqspi;
+	void __iomem *reg_base = cqspi->iobase;
+	u32 reg;
+	u8 dummy;
+	int ret;
+
+	/* Wait for idle before touching CONFIG/RD_INSTR either direction. */
+	ret = cqspi_wait_idle(cqspi);
+	if (ret)
+		return ret;
[Severity: High]
Does returning early here on a timeout during disable leak the PHY state?

In cqspi_direct_read_execute(), a direct read is initiated and then the PHY
is disabled via cqspi_tune_phy_read(f_pdata, false). If the direct read
operation stalls and cqspi_wait_idle() times out here, the early return
bypasses the cleanup in cqspi_phy_restore_read_config().

This would leave the CQSPI_REG_CONFIG_PHY_EN and CQSPI_REG_CONFIG_PHY_PIPELINE
bits permanently set in the controller's configuration register. Could this
cause subsequent untuned or indirect operations (which do not clear these
bits) to execute with the PHY unexpectedly active, leading to timing
mismatches or data corruption?
quoted hunk ↗ jump to hunk
+
+	if (!enable) {
+		cqspi_phy_restore_read_config(f_pdata);
+		return 0;
+	}
-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929063529.1235417-1-s-k6@ti.com?part=11
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help