From: Tim auf der Landwehr <tadl-git@taufderl.de>
To: Kristian Brox <isyourbrainfoss@proton.me>
Cc: David Heidelberg <david@ixit.cz>,
luca.weiss@fairphone.com, oe-linux-nfc@lists.linux.dev,
linux-kernel@vger.kernel.org,
Tim auf der Landwehr <tadl-git@taufderl.de>
Subject: [PATCH 3/3] nfc: st-nci: treat the idle 0x7e read as no-data
Date: Wed, 30 Sep 2026 00:41:25 +0200 [thread overview]
Message-ID: <20260929224125.3656680-4-tadl-git@taufderl.de> (raw)
In-Reply-To: <20260902-fp5-st21nfcd-v4-v4-0-ded2f1c501be@proton.me>
In the raw-NCI read path the controller returns 0x7e as the first byte
when it has nothing to send, and its IRQ can fire without a frame behind
it. The driver took buf[2] of that idle read as a frame length, logged
"invalid frame len", and read the following bytes at the wrong offset,
desyncing the next real frame on the bus.
On the Fairphone 4 this produced repeated "invalid frame len" during
polling. Return -ENODATA when the first byte is the idle marker, and treat
it like the other benign read outcomes in the IRQ handler.
Signed-off-by: Tim auf der Landwehr <tadl-git@taufderl.de>
---
drivers/nfc/st-nci/i2c.c | 12 +++++++++++-
1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/drivers/nfc/st-nci/i2c.c b/drivers/nfc/st-nci/i2c.c
index 16f643b3a..3a99dc23f 100644
--- a/drivers/nfc/st-nci/i2c.c
+++ b/drivers/nfc/st-nci/i2c.c
@@ -29,6 +29,7 @@
#define ST_NCI_I2C_MIN_SIZE 4 /* PCB(1) + NCI Packet header(3) */
#define ST_NCI_NCI_HDR_SIZE 3 /* raw NCI: MT/PBF/GID + OID + len */
+#define ST_NCI_IDLE_BYTE 0x7e /* first read byte when the controller is idle (observed) */
#define ST_NCI_I2C_MAX_SIZE 250 /* req 4.2.1 */
enum st_nci_i2c_proto {
@@ -157,6 +158,15 @@ static int st_nci_i2c_read(struct st_nci_i2c_phy *phy,
if (r != ST_NCI_NCI_HDR_SIZE)
return -EREMOTEIO;
+ /*
+ * The controller returns 0x7e as the first byte when it has
+ * nothing to send; its IRQ can assert without a frame behind it.
+ * Treat that as no-data, otherwise buf[2] is taken as a length and
+ * the next real frame is read off the bus at the wrong offset.
+ */
+ if (buf[0] == ST_NCI_IDLE_BYTE)
+ return -ENODATA;
+
len = buf[2];
if (len > ST_NCI_I2C_MAX_SIZE) {
nfc_err(&client->dev, "invalid frame len\n");
@@ -247,7 +257,7 @@ static irqreturn_t st_nci_irq_thread_fn(int irq, void *phy_id)
}
r = st_nci_i2c_read(phy, &skb);
- if (r == -EREMOTEIO || r == -ENOMEM || r == -EBADMSG)
+ if (r == -EREMOTEIO || r == -ENOMEM || r == -EBADMSG || r == -ENODATA)
return IRQ_HANDLED;
ndlc_recv(phy->ndlc, skb);
--
2.55.0
prev parent reply other threads:[~2026-09-29 22:50 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 21:22 [PATCH v4 0/3] nfc: st-nci: Fairphone 5 NFC bring-up (ST21NFCD) Kristian Brox
2026-09-02 21:22 ` [PATCH v4 1/3] dt-bindings: net: nfc: add st,st21nfcd Kristian Brox
2026-09-03 13:47 ` Krzysztof Kozlowski
2026-09-02 21:22 ` [PATCH v4 2/3] nfc: st-nci: add raw NCI path for ST21NFCD Kristian Brox
2026-09-02 21:22 ` [PATCH v4 3/3] arm64: dts: qcom: qcm6490-fairphone-fp5: add ST21NFCD NFC Kristian Brox
2026-09-03 6:49 ` Konrad Dybcio
2026-09-03 7:49 ` Abel Vesa
2026-09-18 8:08 ` [PATCH v4 0/3] nfc: st-nci: Fairphone 5 NFC bring-up (ST21NFCD) Luca Weiss
2026-09-23 19:35 ` Kristian Brox
2026-09-29 22:41 ` [PATCH 0/3] nfc: st-nci: three ST21NFCD fixes found bringing v4 up on the Fairphone 4 Tim auf der Landwehr
2026-09-29 22:41 ` [PATCH 1/3] nfc: st-nci: map proprietary RF 0x90 to MIFARE Tim auf der Landwehr
2026-09-29 22:41 ` [PATCH 2/3] nfc: st-nci: restart the reference clock on power-up Tim auf der Landwehr
2026-09-29 22:41 ` Tim auf der Landwehr [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929224125.3656680-4-tadl-git@taufderl.de \
--to=tadl-git@taufderl.de \
--cc=david@ixit.cz \
--cc=isyourbrainfoss@proton.me \
--cc=linux-kernel@vger.kernel.org \
--cc=luca.weiss@fairphone.com \
--cc=oe-linux-nfc@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®