From: Pavel Machek <pavel@ucw.cz>
To: cooloney@gmail.com, rpurdie@rpsys.net,
linux-leds@vger.kernel.org, linux-kernel@vger.kernel.org,
milo.kim@ti.com
Cc: pali.rohar@gmail.com, sre@debian.org, sre@ring0.de,
kernel list <linux-kernel@vger.kernel.org>
Subject: Broken locking in leds-lp5523.c
Date: Tue, 7 Jan 2014 21:42:33 +0100 [thread overview]
Message-ID: <20140107204233.GA22413@amd.pavel.ucw.cz> (raw)
Hi!
There's some locking weirdness, and few missing comments in lp5523
driver.
Now, this is untested patch from my reverse-engineering. I hope I
understood things right...
In particular, there's unbalanced unlock in
lp5523_update_program_memory, and lp5523_update_program_memory needs
to be protected by the lock.
Comments? Does someone maintain this?
Thanks,
Pavel
Signed-off-by: Pavel Machek <pavel@ucw.cz>
diff --git a/drivers/leds/leds-lp5523.c b/drivers/leds/leds-lp5523.c
index c00f55e4..e8b83e9 100644
--- a/drivers/leds/leds-lp5523.c
+++ b/drivers/leds/leds-lp5523.c
@@ -34,7 +34,15 @@
#include "leds-lp55xx-common.h"
-#define LP5523_PROGRAM_LENGTH 32
+#define LP5523_PROGRAM_LENGTH 32 /* bytes */
+/* Memory is used like this:
+ 0x00 engine 1 program
+ 0x10 engine 2 program
+ 0x20 engine 3 program
+ 0x30 engine 1 muxing info
+ 0x40 engine 2 muxing info
+ 0x50 engine 3 muxing info
+ ...and offsets are hard-coded all around :-( */
#define LP5523_MAX_LEDS 9
/* Registers */
@@ -265,20 +273,25 @@ static int lp5523_init_program_engine(struct lp55xx_chip *chip)
/* one pattern per engine setting LED MUX start and stop addresses */
static const u8 pattern[][LP5523_PROGRAM_LENGTH] = {
{ 0x9c, 0x30, 0x9c, 0xb0, 0x9d, 0x80, 0xd8, 0x00, 0},
+ /* 9c30 -- mux_map_start(0x30)
+ 9cb0 -- mux_ld_end(0x50)
+ 9d80 -- mux_sel???(0x00)
+ d800 -- invalid?? */
{ 0x9c, 0x40, 0x9c, 0xc0, 0x9d, 0x80, 0xd8, 0x00, 0},
{ 0x9c, 0x50, 0x9c, 0xd0, 0x9d, 0x80, 0xd8, 0x00, 0},
};
- /* hardcode 32 bytes of memory for each engine from program memory */
+ /* hardcode LP5523_PROGRAM_LENGTH bytes of memory for each
+ engine from program memory */
ret = lp55xx_write(chip, LP5523_REG_CH1_PROG_START, 0x00);
if (ret)
return ret;
- ret = lp55xx_write(chip, LP5523_REG_CH2_PROG_START, 0x10);
+ ret = lp55xx_write(chip, LP5523_REG_CH2_PROG_START, LP5523_PROGRAM_LENGTH / 2);
if (ret)
return ret;
- ret = lp55xx_write(chip, LP5523_REG_CH3_PROG_START, 0x20);
+ ret = lp55xx_write(chip, LP5523_REG_CH3_PROG_START, LP5523_PROGRAM_LENGTH);
if (ret)
return ret;
@@ -346,10 +359,8 @@ static int lp5523_update_program_memory(struct lp55xx_chip *chip,
for (i = 0; i < LP5523_PROGRAM_LENGTH; i++) {
ret = lp55xx_write(chip, LP5523_REG_PROG_MEM + i, pattern[i]);
- if (ret) {
- mutex_unlock(&chip->lock);
+ if (ret)
return -EINVAL;
- }
}
return size;
@@ -551,15 +562,17 @@ static ssize_t store_engine_load(struct device *dev,
{
struct lp55xx_led *led = i2c_get_clientdata(to_i2c_client(dev));
struct lp55xx_chip *chip = led->chip;
+ ssize_t res;
mutex_lock(&chip->lock);
chip->engine_idx = nr;
lp5523_load_engine_and_select_page(chip);
+ res = lp5523_update_program_memory(chip, buf, len);
mutex_unlock(&chip->lock);
- return lp5523_update_program_memory(chip, buf, len);
+ return res;
}
store_load(1)
store_load(2)
diff --git a/drivers/leds/leds-lp8501.c b/drivers/leds/leds-lp8501.c
index 8d55a780..ae5c6fe 100644
--- a/drivers/leds/leds-lp8501.c
+++ b/drivers/leds/leds-lp8501.c
@@ -262,7 +262,7 @@ static void lp8501_firmware_loaded(struct lp55xx_chip *chip)
}
/*
- * Program momery sequence
+ * Program memory sequence
* 1) set engine mode to "LOAD"
* 2) write firmware data into program memory
*/
--
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html
next reply other threads:[~2014-01-07 20:42 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-01-07 20:42 Pavel Machek [this message]
2014-01-07 23:57 ` Bryan Wu
2014-01-09 23:08 ` Pavel Machek
2014-01-08 0:32 ` Bryan Wu
2014-01-09 14:24 ` Pali Rohár
2014-01-09 17:51 ` Bryan Wu
2014-01-09 22:45 ` Pavel Machek
2014-01-09 23:13 ` [trivial] Comment improvements for lp5523 and friend Pavel Machek
2014-02-06 19:36 ` Bryan Wu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140107204233.GA22413@amd.pavel.ucw.cz \
--to=pavel@ucw.cz \
--cc=cooloney@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-leds@vger.kernel.org \
--cc=milo.kim@ti.com \
--cc=pali.rohar@gmail.com \
--cc=rpurdie@rpsys.net \
--cc=sre@debian.org \
--cc=sre@ring0.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®