From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.19]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 96EBA388361 for ; Wed, 10 Jun 2026 07:30:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.19 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781076615; cv=none; b=sMWybOnQIvzaYxc58k9h/UBL3930j1JAntCZ1i70ME3KsPzTcYi5rW7T6mPmCK3WuPQGfvjRBAShL7qEfCHRdwxediAHTkYdSLydV61Tv6dirqtYUdrxL7/CfQ1cLa3lQvYARzHnB+16GB1xpf85F86emnvxHWR5lcjJWnQF58U= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781076615; c=relaxed/simple; bh=nhYaNIDVR/9L2JokfiCSj09BFC6wC8LBW890q34vOu8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=iBha3aP8XnyBtfWowykyi1tBHsFkj3bp7gAhiu/e4KQ6Z3Hx/g/AGWQmBIdZ5LsO2YZslF3AUvOt8HcB8+h2JS74N5pwnJCK8rE9qz1i03Le7nGAwqZtc+pq8H1X4/pSk/F81XnbQzNmHugHfqujWs31PGKI9XAkyNLp64cikIQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=kW/xzt9C; arc=none smtp.client-ip=192.198.163.19 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="kW/xzt9C" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1781076612; x=1812612612; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=nhYaNIDVR/9L2JokfiCSj09BFC6wC8LBW890q34vOu8=; b=kW/xzt9CYWA/nhmZ1XvJxYjjIZKZGhm8aFbV01moyQhDUxP9PMRyHQm1 WN2QXxD32izVWU5V79MPBdflLc5epeV1RiL9nAqHajdQ0ySZHvDm1CnVM qsezWrDZ0RHPr0bUxr0/iB9gxFNayest506Um7HsknFo6G1ypnHZvgB5j zJ9OzSVdqxi1d3uT8XAHZUqLvx+IijaRhAen55G4EN4BB4EAFMKQ8RuXU 7aDZ1+btjYIwtuz2TQtbH0PHrwX5+rOdeqH5fHj2+D9dv5/o51MjPqxeC bs2ojZO6Iab3S9/XI9alYjknGHeAH0W/Izi6LIe9JdXAxQ9WJhdlkPuyH Q==; X-CSE-ConnectionGUID: xPUHJ8a9ThK2QTj0s+cXFw== X-CSE-MsgGUID: jEIZjQcMQA258Q8YmlCuwg== X-IronPort-AV: E=McAfee;i="6800,10657,11812"; a="80878395" X-IronPort-AV: E=Sophos;i="6.24,197,1774335600"; d="scan'208";a="80878395" Received: from fmviesa001.fm.intel.com ([10.60.135.141]) by fmvoesa113.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 10 Jun 2026 00:29:07 -0700 X-CSE-ConnectionGUID: U4Z0HwXEQz+D9GIOGO+vsg== X-CSE-MsgGUID: 5mgS0wZ9RKiMzs42EehYEA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.24,197,1774335600"; d="scan'208";a="270103430" Received: from mkosciow-mobl1.ger.corp.intel.com (HELO ahunter6-desk) ([10.245.245.210]) by smtpauth.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 10 Jun 2026 00:29:05 -0700 From: Adrian Hunter To: alexandre.belloni@bootlin.com Cc: Frank.Li@nxp.com, linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH V3 0/7] i3c: Fix IBI race, address handling, and reconcile DAA Date: Wed, 10 Jun 2026 10:28:45 +0300 Message-ID: <20260610072852.36934-1-adrian.hunter@intel.com> X-Mailer: git-send-email 2.51.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Organization: Intel Finland Oy, Registered Address: c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo, Business Identity Code: 0357606 - 4, Domiciled in Helsinki Content-Transfer-Encoding: 8bit Hi Patches 1-2 fix a use-after-free race in the MIPI I3C HCI driver's IBI handling and make IBI teardown resilient to DISEC failures. Patches 3-7 fix address management issues in the I3C core and HCI driver that arise when Dynamic Address Assignment (DAA) does not complete cleanly, culminating in a reconciliation step that detects and resolves inconsistencies between assigned address slots and registered devices. Patches are based on top of: [PATCH V3 0/8] i3c: Hot-Join improvements and MIPI HCI Hot-Join support https://lore.kernel.org/linux-i3c/20260608054312.10604-1-adrian.hunter@intel.com which, in turn, applies on top of: [PATCH V5 00/17] i3c: mipi-i3c-hci: DMA abort, recovery and related improvements https://lore.kernel.org/linux-i3c/20260603090754.16252-1-adrian.hunter@intel.com Changes in V3: i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev() i3c: mipi-i3c-hci: Ignore DISEC failures when disabling IBIs Add Frank's Rev'd-by i3c: master: Prevent reuse of dynamic address on device add failure Add note to commit message about Direct RSTDAA deprecation i3c: mipi-i3c-hci: Tolerate i3c_master_add_i3c_dev_locked() failures in DAA i3c: master: Make i3c_master_add_i3c_dev_locked() return void i3c: master: Move DAA API functions after i3c_master_add_i3c_dev_locked() Add Frank's Rev'd-by i3c: master: Reconcile dynamic addresses after DAA Add comment about the source of I3C_DEV_PROBE_* macro values. Also account for static_addr in i3c_master_reconcile_dyn_addrs() Changes in V2: i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev() Factor out __i3c_hci_disable_ibi() to facilitate also clearing ibi_devs[dat_idx] upon IBI free, and update commit message accordingly. Demote a message in PIO and DMA IBI handling, and update commit message accordingly. i3c: mipi-i3c-hci: Ignore DISEC failures when disabling IBIs Re-base due to changes in previous patch. i3c: master: Prevent reuse of dynamic address on device add failure Fix 'if (IS_ERR(newdev)' error path. Be defensive and do not change the addr_slot_status if it is not free, and update commit message accordingly. Amend commit message to note removal of unnecesary 'if (!master)' check. Add Fixes tag. i3c: mipi-i3c-hci: Tolerate i3c_master_add_i3c_dev_locked() failures in DAA None i3c: master: Make i3c_master_add_i3c_dev_locked() return void Re-base due to changes in previous patches. i3c: master: Move DAA API functions after i3c_master_add_i3c_dev_locked() None i3c: master: Reconcile dynamic addresses after DAA Add bitmap.h include for bitmap_zero() etc. Re-base due to changes in previous patches. Adrian Hunter (7): i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev() i3c: mipi-i3c-hci: Ignore DISEC failures when disabling IBIs i3c: master: Prevent reuse of dynamic address on device add failure i3c: mipi-i3c-hci: Tolerate i3c_master_add_i3c_dev_locked() failures in DAA i3c: master: Make i3c_master_add_i3c_dev_locked() return void i3c: master: Move DAA API functions after i3c_master_add_i3c_dev_locked() i3c: master: Reconcile dynamic addresses after DAA drivers/i3c/master.c | 279 ++++++++++++++++++++++--------- drivers/i3c/master/mipi-i3c-hci/cmd_v1.c | 4 +- drivers/i3c/master/mipi-i3c-hci/cmd_v2.c | 4 +- drivers/i3c/master/mipi-i3c-hci/core.c | 45 ++++- drivers/i3c/master/mipi-i3c-hci/dma.c | 7 +- drivers/i3c/master/mipi-i3c-hci/hci.h | 1 + drivers/i3c/master/mipi-i3c-hci/ibi.h | 13 +- drivers/i3c/master/mipi-i3c-hci/pio.c | 7 +- include/linux/i3c/master.h | 3 +- 9 files changed, 254 insertions(+), 109 deletions(-) Regards Adrian