mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Tim auf der Landwehr <tadl-git@taufderl.de>
To: Kristian Brox <isyourbrainfoss@proton.me>
Cc: David Heidelberg <david@ixit.cz>,
	luca.weiss@fairphone.com, oe-linux-nfc@lists.linux.dev,
	linux-kernel@vger.kernel.org,
	Tim auf der Landwehr <tadl-git@taufderl.de>
Subject: [PATCH 3/3] nfc: st-nci: treat the idle 0x7e read as no-data
Date: Wed, 30 Sep 2026 00:41:25 +0200	[thread overview]
Message-ID: <20260929224125.3656680-4-tadl-git@taufderl.de> (raw)
In-Reply-To: <20260902-fp5-st21nfcd-v4-v4-0-ded2f1c501be@proton.me>

In the raw-NCI read path the controller returns 0x7e as the first byte
when it has nothing to send, and its IRQ can fire without a frame behind
it. The driver took buf[2] of that idle read as a frame length, logged
"invalid frame len", and read the following bytes at the wrong offset,
desyncing the next real frame on the bus.

On the Fairphone 4 this produced repeated "invalid frame len" during
polling. Return -ENODATA when the first byte is the idle marker, and treat
it like the other benign read outcomes in the IRQ handler.

Signed-off-by: Tim auf der Landwehr <tadl-git@taufderl.de>
---
 drivers/nfc/st-nci/i2c.c | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/drivers/nfc/st-nci/i2c.c b/drivers/nfc/st-nci/i2c.c
index 16f643b3a..3a99dc23f 100644
--- a/drivers/nfc/st-nci/i2c.c
+++ b/drivers/nfc/st-nci/i2c.c
@@ -29,6 +29,7 @@
 
 #define ST_NCI_I2C_MIN_SIZE 4   /* PCB(1) + NCI Packet header(3) */
 #define ST_NCI_NCI_HDR_SIZE 3   /* raw NCI: MT/PBF/GID + OID + len */
+#define ST_NCI_IDLE_BYTE 0x7e /* first read byte when the controller is idle (observed) */
 #define ST_NCI_I2C_MAX_SIZE 250 /* req 4.2.1 */
 
 enum st_nci_i2c_proto {
@@ -157,6 +158,15 @@ static int st_nci_i2c_read(struct st_nci_i2c_phy *phy,
 		if (r != ST_NCI_NCI_HDR_SIZE)
 			return -EREMOTEIO;
 
+		/*
+		 * The controller returns 0x7e as the first byte when it has
+		 * nothing to send; its IRQ can assert without a frame behind it.
+		 * Treat that as no-data, otherwise buf[2] is taken as a length and
+		 * the next real frame is read off the bus at the wrong offset.
+		 */
+		if (buf[0] == ST_NCI_IDLE_BYTE)
+			return -ENODATA;
+
 		len = buf[2];
 		if (len > ST_NCI_I2C_MAX_SIZE) {
 			nfc_err(&client->dev, "invalid frame len\n");
@@ -247,7 +257,7 @@ static irqreturn_t st_nci_irq_thread_fn(int irq, void *phy_id)
 	}
 
 	r = st_nci_i2c_read(phy, &skb);
-	if (r == -EREMOTEIO || r == -ENOMEM || r == -EBADMSG)
+	if (r == -EREMOTEIO || r == -ENOMEM || r == -EBADMSG || r == -ENODATA)
 		return IRQ_HANDLED;
 
 	ndlc_recv(phy->ndlc, skb);
-- 
2.55.0


      parent reply	other threads:[~2026-09-29 22:50 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-02 21:22 [PATCH v4 0/3] nfc: st-nci: Fairphone 5 NFC bring-up (ST21NFCD) Kristian Brox
2026-09-02 21:22 ` [PATCH v4 1/3] dt-bindings: net: nfc: add st,st21nfcd Kristian Brox
2026-09-03 13:47   ` Krzysztof Kozlowski
2026-09-02 21:22 ` [PATCH v4 2/3] nfc: st-nci: add raw NCI path for ST21NFCD Kristian Brox
2026-09-02 21:22 ` [PATCH v4 3/3] arm64: dts: qcom: qcm6490-fairphone-fp5: add ST21NFCD NFC Kristian Brox
2026-09-03  6:49   ` Konrad Dybcio
2026-09-03  7:49   ` Abel Vesa
2026-09-18  8:08 ` [PATCH v4 0/3] nfc: st-nci: Fairphone 5 NFC bring-up (ST21NFCD) Luca Weiss
2026-09-23 19:35   ` Kristian Brox
2026-09-29 22:41 ` [PATCH 0/3] nfc: st-nci: three ST21NFCD fixes found bringing v4 up on the Fairphone 4 Tim auf der Landwehr
2026-09-29 22:41 ` [PATCH 1/3] nfc: st-nci: map proprietary RF 0x90 to MIFARE Tim auf der Landwehr
2026-09-29 22:41 ` [PATCH 2/3] nfc: st-nci: restart the reference clock on power-up Tim auf der Landwehr
2026-09-29 22:41 ` Tim auf der Landwehr [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929224125.3656680-4-tadl-git@taufderl.de \
    --to=tadl-git@taufderl.de \
    --cc=david@ixit.cz \
    --cc=isyourbrainfoss@proton.me \
    --cc=linux-kernel@vger.kernel.org \
    --cc=luca.weiss@fairphone.com \
    --cc=oe-linux-nfc@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®