* [PATCH 1/9] dt-bindings: nvmem: qfprom: Add compatible for Qualcomm Maili
2026-10-02 10:13 [PATCH 0/9] nvmem: patches for 7.4 srini
@ 2026-10-02 10:13 ` srini
2026-10-02 10:13 ` [PATCH 2/9] dt-bindings: nvmem: uniphier-efuse: Add ti,am62p-efuse compatible srini
` (7 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: srini @ 2026-10-02 10:13 UTC (permalink / raw)
To: gregkh; +Cc: linux-kernel, Jingyi Wang, Rob Herring (Arm), Srinivas Kandagatla
From: Jingyi Wang <jingyi.wang@oss.qualcomm.com>
Document compatible string for the QFPROM on Qualcomm Maili platform.
Signed-off-by: Jingyi Wang <jingyi.wang@oss.qualcomm.com>
Acked-by: Rob Herring (Arm) <robh@kernel.org>
Signed-off-by: Srinivas Kandagatla <srini@kernel.org>
---
Documentation/devicetree/bindings/nvmem/qcom,qfprom.yaml | 1 +
1 file changed, 1 insertion(+)
diff --git a/Documentation/devicetree/bindings/nvmem/qcom,qfprom.yaml b/Documentation/devicetree/bindings/nvmem/qcom,qfprom.yaml
index bc0a0898b9e4..566304ed4c78 100644
--- a/Documentation/devicetree/bindings/nvmem/qcom,qfprom.yaml
+++ b/Documentation/devicetree/bindings/nvmem/qcom,qfprom.yaml
@@ -31,6 +31,7 @@ properties:
- qcom,ipq9574-qfprom
- qcom,ipq9650-qfprom
- qcom,kaanapali-qfprom
+ - qcom,maili-qfprom
- qcom,milos-qfprom
- qcom,msm8226-qfprom
- qcom,msm8916-qfprom
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH 2/9] dt-bindings: nvmem: uniphier-efuse: Add ti,am62p-efuse compatible
2026-10-02 10:13 [PATCH 0/9] nvmem: patches for 7.4 srini
2026-10-02 10:13 ` [PATCH 1/9] dt-bindings: nvmem: qfprom: Add compatible for Qualcomm Maili srini
@ 2026-10-02 10:13 ` srini
2026-10-02 10:13 ` [PATCH 3/9] nvmem: uniphier-efuse: Enable for K3 SoCs srini
` (6 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: srini @ 2026-10-02 10:13 UTC (permalink / raw)
To: gregkh
Cc: linux-kernel, Judith Mendez, Kunihiko Hayashi,
Krzysztof Kozlowski, Srinivas Kandagatla
From: Judith Mendez <jm@ti.com>
Add ti,am62p-efuse as a compatible string to the uniphier-efuse binding.
The uniphier-efuse driver can be used to read AM62P efuse registers as
well for GP_SW silicon revision detection.
Signed-off-by: Judith Mendez <jm@ti.com>
Reviewed-by: Kunihiko Hayashi <hayashi.kunihiko@socionext.com>
Acked-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Srinivas Kandagatla <srini@kernel.org>
---
.../devicetree/bindings/nvmem/socionext,uniphier-efuse.yaml | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/Documentation/devicetree/bindings/nvmem/socionext,uniphier-efuse.yaml b/Documentation/devicetree/bindings/nvmem/socionext,uniphier-efuse.yaml
index e27cbae2d63a..d26b3d2a3eba 100644
--- a/Documentation/devicetree/bindings/nvmem/socionext,uniphier-efuse.yaml
+++ b/Documentation/devicetree/bindings/nvmem/socionext,uniphier-efuse.yaml
@@ -16,7 +16,11 @@ allOf:
properties:
compatible:
- const: socionext,uniphier-efuse
+ oneOf:
+ - const: socionext,uniphier-efuse
+ - items:
+ - const: ti,am62p-efuse
+ - const: socionext,uniphier-efuse
reg:
maxItems: 1
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH 3/9] nvmem: uniphier-efuse: Enable for K3 SoCs
2026-10-02 10:13 [PATCH 0/9] nvmem: patches for 7.4 srini
2026-10-02 10:13 ` [PATCH 1/9] dt-bindings: nvmem: qfprom: Add compatible for Qualcomm Maili srini
2026-10-02 10:13 ` [PATCH 2/9] dt-bindings: nvmem: uniphier-efuse: Add ti,am62p-efuse compatible srini
@ 2026-10-02 10:13 ` srini
2026-10-02 10:13 ` [PATCH 4/9] nvmem: core: Add const to pattrs allocation type srini
` (5 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: srini @ 2026-10-02 10:13 UTC (permalink / raw)
To: gregkh; +Cc: linux-kernel, Judith Mendez, Kunihiko Hayashi, Srinivas Kandagatla
From: Judith Mendez <jm@ti.com>
Add ARCH_K3 dependency and set to always build for K3 architecture.
The uniphier-efuse driver must be builtin to support early probe of
k3-socinfo during boot. The k3-socinfo driver requires the efuse
provider for reading silicon revision information on AM62p device.
Signed-off-by: Judith Mendez <jm@ti.com>
Reviewed-by: Kunihiko Hayashi <hayashi.kunihiko@socionext.com>
Signed-off-by: Srinivas Kandagatla <srini@kernel.org>
---
drivers/nvmem/Kconfig | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/nvmem/Kconfig b/drivers/nvmem/Kconfig
index c36c2a4c2a0b..df65e7ecfa21 100644
--- a/drivers/nvmem/Kconfig
+++ b/drivers/nvmem/Kconfig
@@ -541,8 +541,9 @@ config NVMEM_U_BOOT_ENV
config NVMEM_UNIPHIER_EFUSE
tristate "UniPhier SoCs eFuse support"
- depends on ARCH_UNIPHIER || COMPILE_TEST
+ depends on ARCH_UNIPHIER || ARCH_K3 || COMPILE_TEST
depends on HAS_IOMEM
+ default y if ARCH_K3
help
This is a simple driver to dump specified values of UniPhier SoC
from eFuse.
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH 4/9] nvmem: core: Add const to pattrs allocation type
2026-10-02 10:13 [PATCH 0/9] nvmem: patches for 7.4 srini
` (2 preceding siblings ...)
2026-10-02 10:13 ` [PATCH 3/9] nvmem: uniphier-efuse: Enable for K3 SoCs srini
@ 2026-10-02 10:13 ` srini
2026-10-02 10:13 ` [PATCH 5/9] nvmem: layouts: Support fixed-layout as the nvmem device node itself srini
` (4 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: srini @ 2026-10-02 10:13 UTC (permalink / raw)
To: gregkh; +Cc: linux-kernel, Kees Cook, Srinivas Kandagatla
From: Kees Cook <kees+treewide@kernel.org>
In preparation for making the devm_kmalloc family of allocators type
aware, we need to make sure that the returned type from the allocation
matches the type of the variable being assigned. (Before, the allocator
would always return "void *", which can be implicitly cast to any
pointer type.)
The assigned type is "const struct bin_attribute **", but the converted
allocation type would be "struct bin_attribute **", which is the same
type without the const qualifier. As there is no general way to safely
add const qualifiers, take the size from the assignment target instead.
No change in allocation size results.
Build tested ARCH=x86_64 allmodconfig with GCC 16.2.0:
drivers/nvmem/core.o
Assisted-by: LLM coccinelle
Signed-off-by: Kees Cook <kees+treewide@kernel.org>
Signed-off-by: Srinivas Kandagatla <srini@kernel.org>
---
drivers/nvmem/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/nvmem/core.c b/drivers/nvmem/core.c
index 0556d140170a..19edc9ab0282 100644
--- a/drivers/nvmem/core.c
+++ b/drivers/nvmem/core.c
@@ -485,7 +485,7 @@ static int nvmem_populate_sysfs_cells(struct nvmem_device *nvmem)
/* Allocate an array of attributes with a sentinel */
ncells = list_count_nodes(&nvmem->cells);
pattrs = devm_kcalloc(&nvmem->dev, ncells + 1,
- sizeof(struct bin_attribute *), GFP_KERNEL);
+ sizeof(*pattrs), GFP_KERNEL);
if (!pattrs)
return -ENOMEM;
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH 5/9] nvmem: layouts: Support fixed-layout as the nvmem device node itself
2026-10-02 10:13 [PATCH 0/9] nvmem: patches for 7.4 srini
` (3 preceding siblings ...)
2026-10-02 10:13 ` [PATCH 4/9] nvmem: core: Add const to pattrs allocation type srini
@ 2026-10-02 10:13 ` srini
2026-10-02 10:13 ` [PATCH 6/9] dt-bindings: mfd: mediatek: mt6397: add mt6323 PMIC EFUSE srini
` (3 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: srini @ 2026-10-02 10:13 UTC (permalink / raw)
To: gregkh
Cc: linux-kernel, Loic Poulain, Bartosz Golaszewski, Srinivas Kandagatla
From: Loic Poulain <loic.poulain@oss.qualcomm.com>
of_nvmem_layout_get_container() only looks for a child node named
"nvmem-layout" to locate the cell definitions. This does not cover
providers whose device tree node is itself the fixed-layout container,
such as an eMMC boot partition block device whose fwnode points directly
at a "fixed-layout" compatible partitions node.
When no "nvmem-layout" child is present, fall back to returning the nvmem
device node itself if it is compatible with "fixed-layout", so that its
cells are parsed by nvmem_add_cells_from_fixed_layout().
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Signed-off-by: Srinivas Kandagatla <srini@kernel.org>
---
drivers/nvmem/layouts.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/drivers/nvmem/layouts.c b/drivers/nvmem/layouts.c
index 07a34be9669c..409909e3244f 100644
--- a/drivers/nvmem/layouts.c
+++ b/drivers/nvmem/layouts.c
@@ -156,7 +156,18 @@ static int nvmem_layout_bus_populate(struct nvmem_device *nvmem,
struct device_node *of_nvmem_layout_get_container(struct nvmem_device *nvmem)
{
- return of_get_child_by_name(nvmem->dev.of_node, "nvmem-layout");
+ struct device_node *np;
+
+ /* Search for nvmem-layout child */
+ np = of_get_child_by_name(nvmem->dev.of_node, "nvmem-layout");
+ if (np)
+ return np;
+
+ /* The nvmem of_node is itself a fixed-layout node */
+ if (of_device_is_compatible(nvmem->dev.of_node, "fixed-layout"))
+ return of_node_get(nvmem->dev.of_node);
+
+ return NULL;
}
EXPORT_SYMBOL_GPL(of_nvmem_layout_get_container);
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH 6/9] dt-bindings: mfd: mediatek: mt6397: add mt6323 PMIC EFUSE
2026-10-02 10:13 [PATCH 0/9] nvmem: patches for 7.4 srini
` (4 preceding siblings ...)
2026-10-02 10:13 ` [PATCH 5/9] nvmem: layouts: Support fixed-layout as the nvmem device node itself srini
@ 2026-10-02 10:13 ` srini
2026-10-02 10:13 ` [PATCH 7/9] nvmem: add mt6323 PMIC EFUSE driver srini
` (2 subsequent siblings)
8 siblings, 0 replies; 10+ messages in thread
From: srini @ 2026-10-02 10:13 UTC (permalink / raw)
To: gregkh
Cc: linux-kernel, Roman Vivchar, Rob Herring (Arm),
Conor Dooley, Srinivas Kandagatla
From: Roman Vivchar <rva333@protonmail.com>
The MediaTek mt6323 PMIC includes an EFUSE used for storing calibration
data.
Add the devicetree binding documentation for the MediaTek mt6323 EFUSE.
Reviewed-by: Rob Herring (Arm) <robh@kernel.org>
Acked-by: Conor Dooley <conor.dooley@microchip.com>
Signed-off-by: Roman Vivchar <rva333@protonmail.com>
Signed-off-by: Srinivas Kandagatla <srini@kernel.org>
---
.../bindings/mfd/mediatek,mt6397.yaml | 21 +++++++++++++++++++
1 file changed, 21 insertions(+)
diff --git a/Documentation/devicetree/bindings/mfd/mediatek,mt6397.yaml b/Documentation/devicetree/bindings/mfd/mediatek,mt6397.yaml
index 3cbc0dc12c31..d2de227ae7a6 100644
--- a/Documentation/devicetree/bindings/mfd/mediatek,mt6397.yaml
+++ b/Documentation/devicetree/bindings/mfd/mediatek,mt6397.yaml
@@ -159,6 +159,23 @@ properties:
required:
- compatible
+ efuse:
+ type: object
+ unevaluatedProperties: false
+ description:
+ The efuse is responsible for storing calibration data, such as thermal
+ sensor calibration.
+
+ properties:
+ compatible:
+ const: mediatek,mt6323-efuse
+
+ nvmem-layout:
+ $ref: /schemas/nvmem/layouts/nvmem-layout.yaml#
+
+ required:
+ - compatible
+
leds:
type: object
additionalProperties: false
@@ -307,6 +324,10 @@ examples:
interrupt-controller;
#interrupt-cells = <2>;
+ efuse {
+ compatible = "mediatek,mt6323-efuse";
+ };
+
leds {
compatible = "mediatek,mt6323-led";
#address-cells = <1>;
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH 7/9] nvmem: add mt6323 PMIC EFUSE driver
2026-10-02 10:13 [PATCH 0/9] nvmem: patches for 7.4 srini
` (5 preceding siblings ...)
2026-10-02 10:13 ` [PATCH 6/9] dt-bindings: mfd: mediatek: mt6397: add mt6323 PMIC EFUSE srini
@ 2026-10-02 10:13 ` srini
2026-10-02 10:13 ` [PATCH 8/9] nvmem: remove duplicated reference counting srini
2026-10-02 10:13 ` [PATCH 9/9] nvmem: protect nvmem_device::ops with SRCU srini
8 siblings, 0 replies; 10+ messages in thread
From: srini @ 2026-10-02 10:13 UTC (permalink / raw)
To: gregkh
Cc: linux-kernel, Roman Vivchar, Ben Grisdale, Andy Shevchenko,
Srinivas Kandagatla
From: Roman Vivchar <rva333@protonmail.com>
Add support for the EFUSE controller found in the Mediatek MT6323 PMIC.
The MT6323 EFUSE stores 24 bytes of hardware-related data, such as
thermal sensor calibration values.
Tested-by: Ben Grisdale <bengris32@protonmail.ch> # Amazon Echo Dot (2nd Generation)
Reviewed-by: Andy Shevchenko <andy@kernel.org>
Signed-off-by: Roman Vivchar <rva333@protonmail.com>
Signed-off-by: Srinivas Kandagatla <srini@kernel.org>
---
MAINTAINERS | 5 +++
drivers/nvmem/Kconfig | 11 +++++
drivers/nvmem/Makefile | 2 +
drivers/nvmem/mt6323-efuse.c | 83 ++++++++++++++++++++++++++++++++++++
4 files changed, 101 insertions(+)
create mode 100644 drivers/nvmem/mt6323-efuse.c
diff --git a/MAINTAINERS b/MAINTAINERS
index 3a19da74d00c..6ec0ed61260c 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS
@@ -16718,6 +16718,11 @@ S: Maintained
F: drivers/iio/adc/mt6323-auxadc.c
F: include/dt-bindings/iio/adc/mediatek,mt6323-auxadc.h
+MEDIATEK MT6323 PMIC NVMEM DRIVER
+M: Roman Vivchar <rva333@protonmail.com>
+S: Maintained
+F: drivers/nvmem/mt6323-efuse.c
+
MEDIATEK MT6735 CLOCK & RESET DRIVERS
M: Yassine Oudjana <y.oudjana@protonmail.com>
L: linux-clk@vger.kernel.org
diff --git a/drivers/nvmem/Kconfig b/drivers/nvmem/Kconfig
index df65e7ecfa21..083a5e528960 100644
--- a/drivers/nvmem/Kconfig
+++ b/drivers/nvmem/Kconfig
@@ -328,6 +328,17 @@ config NVMEM_MTK_EFUSE
This driver can also be built as a module. If so, the module
will be called efuse-mtk.
+config NVMEM_MT6323_EFUSE
+ tristate "MediaTek MT6323 PMIC EFUSE support"
+ depends on ARCH_MEDIATEK || COMPILE_TEST
+ depends on MFD_MT6397
+ help
+ This is a driver to access hardware related data like sensor
+ calibration, etc.
+
+ This driver can also be built as a module. If so, the module
+ will be called efuse-mt6323.
+
config NVMEM_MXS_OCOTP
tristate "Freescale MXS On-Chip OTP Memory Support"
depends on ARCH_MXS || COMPILE_TEST
diff --git a/drivers/nvmem/Makefile b/drivers/nvmem/Makefile
index 2bbfb9ff1885..5e70bad9f0f9 100644
--- a/drivers/nvmem/Makefile
+++ b/drivers/nvmem/Makefile
@@ -53,6 +53,8 @@ obj-$(CONFIG_NVMEM_MESON_MX_EFUSE) += nvmem_meson_mx_efuse.o
nvmem_meson_mx_efuse-y := meson-mx-efuse.o
obj-$(CONFIG_NVMEM_MICROCHIP_OTPC) += nvmem-microchip-otpc.o
nvmem-microchip-otpc-y := microchip-otpc.o
+obj-$(CONFIG_NVMEM_MT6323_EFUSE) += nvmem_mt6323-efuse.o
+nvmem_mt6323-efuse-y := mt6323-efuse.o
obj-$(CONFIG_NVMEM_MTK_EFUSE) += nvmem_mtk-efuse.o
nvmem_mtk-efuse-y := mtk-efuse.o
obj-$(CONFIG_NVMEM_MXS_OCOTP) += nvmem-mxs-ocotp.o
diff --git a/drivers/nvmem/mt6323-efuse.c b/drivers/nvmem/mt6323-efuse.c
new file mode 100644
index 000000000000..de5e30215c22
--- /dev/null
+++ b/drivers/nvmem/mt6323-efuse.c
@@ -0,0 +1,83 @@
+// SPDX-License-Identifier: GPL-2.0+
+/*
+ * Copyright (c) 2026 Roman Vivchar <rva333@protonmail.com>
+ */
+
+#include <linux/err.h>
+#include <linux/mfd/mt6397/core.h>
+#include <linux/module.h>
+#include <linux/nvmem-provider.h>
+#include <linux/platform_device.h>
+#include <linux/regmap.h>
+#include <linux/types.h>
+
+#include <linux/mfd/mt6323/registers.h>
+
+#define MT6323_EFUSE_DOUT_BASE MT6323_EFUSE_DOUT_0_15
+#define MT6323_EFUSE_SIZE 24
+
+static int mt6323_efuse_read(void *context, unsigned int offset, void *val,
+ size_t bytes)
+{
+ struct regmap *map = context;
+ u16 *buf = val;
+ u32 tmp;
+ int ret;
+
+ /*
+ * A manual loop using regmap_read is required because PWRAP is not
+ * a continuous MMIO space, but rather a FSM that doesn't implement the
+ * necessary read callback for the regmap_read_raw and regmap_read_bulk
+ * functions.
+ */
+ for (size_t i = 0; i < bytes; i += sizeof(*buf)) {
+ ret = regmap_read(map, MT6323_EFUSE_DOUT_BASE + offset + i, &tmp);
+ if (ret)
+ return ret;
+
+ *buf++ = tmp;
+ }
+
+ return 0;
+}
+
+static int mt6323_efuse_probe(struct platform_device *pdev)
+{
+ struct mt6397_chip *mt6323 = dev_get_drvdata(pdev->dev.parent);
+ struct device *dev = &pdev->dev;
+ struct nvmem_config config = {
+ .name = "mt6323-efuse",
+ .stride = 2,
+ .word_size = 2,
+ .size = MT6323_EFUSE_SIZE,
+ .reg_read = mt6323_efuse_read,
+ };
+ struct nvmem_device *nvmem;
+
+ if (!mt6323 || !mt6323->regmap)
+ return dev_err_probe(dev, -ENODEV, "failed to get parent\n");
+
+ config.dev = dev;
+ config.priv = mt6323->regmap;
+
+ nvmem = devm_nvmem_register(dev, &config);
+ return PTR_ERR_OR_ZERO(nvmem);
+}
+
+static const struct of_device_id mt6323_efuse_of_match[] = {
+ { .compatible = "mediatek,mt6323-efuse" },
+ { }
+};
+MODULE_DEVICE_TABLE(of, mt6323_efuse_of_match);
+
+static struct platform_driver mt6323_efuse_driver = {
+ .probe = mt6323_efuse_probe,
+ .driver = {
+ .name = "mt6323-efuse",
+ .of_match_table = mt6323_efuse_of_match,
+ },
+};
+module_platform_driver(mt6323_efuse_driver);
+
+MODULE_DESCRIPTION("MediaTek MT6323 PMIC EFUSE driver");
+MODULE_LICENSE("GPL");
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH 8/9] nvmem: remove duplicated reference counting
2026-10-02 10:13 [PATCH 0/9] nvmem: patches for 7.4 srini
` (6 preceding siblings ...)
2026-10-02 10:13 ` [PATCH 7/9] nvmem: add mt6323 PMIC EFUSE driver srini
@ 2026-10-02 10:13 ` srini
2026-10-02 10:13 ` [PATCH 9/9] nvmem: protect nvmem_device::ops with SRCU srini
8 siblings, 0 replies; 10+ messages in thread
From: srini @ 2026-10-02 10:13 UTC (permalink / raw)
To: gregkh; +Cc: linux-kernel, Bartosz Golaszewski, Srinivas Kandagatla
From: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Commit c1de7f43bd84 ("nvmem: use kref") introduced reference counting
with kref to an already reference counted nvmem_device structure. We
only need one refcount so use the one provded by device's kobject and
drop the kref field from struct nvmem_device.
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Srinivas Kandagatla <srini@kernel.org>
---
drivers/nvmem/core.c | 80 +++++++++++++++++----------------------
drivers/nvmem/internals.h | 1 -
2 files changed, 34 insertions(+), 47 deletions(-)
diff --git a/drivers/nvmem/core.c b/drivers/nvmem/core.c
index 19edc9ab0282..8f4f65139966 100644
--- a/drivers/nvmem/core.c
+++ b/drivers/nvmem/core.c
@@ -535,24 +535,6 @@ static void nvmem_sysfs_remove_compat(struct nvmem_device *nvmem)
#endif /* CONFIG_NVMEM_SYSFS */
-static void nvmem_release(struct device *dev)
-{
- struct nvmem_device *nvmem = to_nvmem_device(dev);
-
- ida_free(&nvmem_ida, nvmem->id);
- gpiod_put(nvmem->wp_gpio);
- kfree(nvmem->ops);
- kfree(nvmem);
-}
-
-static const struct device_type nvmem_provider_type = {
- .release = nvmem_release,
-};
-
-static const struct bus_type nvmem_bus_type = {
- .name = "nvmem",
-};
-
static void nvmem_cell_entry_drop(struct nvmem_cell_entry *cell)
{
blocking_notifier_call_chain(&nvmem_notifier, NVMEM_CELL_REMOVE, cell);
@@ -571,6 +553,25 @@ static void nvmem_device_remove_all_cells(const struct nvmem_device *nvmem)
nvmem_cell_entry_drop(cell);
}
+static void nvmem_release(struct device *dev)
+{
+ struct nvmem_device *nvmem = to_nvmem_device(dev);
+
+ gpiod_put(nvmem->wp_gpio);
+ nvmem_device_remove_all_cells(nvmem);
+ ida_free(&nvmem_ida, nvmem->id);
+ kfree(nvmem->ops);
+ kfree(nvmem);
+}
+
+static const struct device_type nvmem_provider_type = {
+ .release = nvmem_release,
+};
+
+static const struct bus_type nvmem_bus_type = {
+ .name = "nvmem",
+};
+
static void nvmem_cell_entry_add(struct nvmem_cell_entry *cell)
{
scoped_guard(mutex, &nvmem_mutex)
@@ -918,6 +919,7 @@ struct nvmem_device *nvmem_register(const struct nvmem_config *config)
nvmem->dev.type = &nvmem_provider_type;
nvmem->dev.bus = &nvmem_bus_type;
nvmem->dev.parent = config->dev;
+ INIT_LIST_HEAD(&nvmem->cells);
nvmem->ops = ops;
device_initialize(&nvmem->dev);
@@ -931,8 +933,6 @@ struct nvmem_device *nvmem_register(const struct nvmem_config *config)
goto err_put_device;
}
- kref_init(&nvmem->refcnt);
- INIT_LIST_HEAD(&nvmem->cells);
nvmem->fixup_dt_cell_info = config->fixup_dt_cell_info;
ops->reg_read = config->reg_read;
@@ -993,20 +993,20 @@ struct nvmem_device *nvmem_register(const struct nvmem_config *config)
if (config->cells) {
rval = nvmem_add_cells(nvmem, config->cells, config->ncells);
if (rval)
- goto err_remove_cells;
+ goto err_remove_compat;
}
if (config->add_legacy_fixed_of_cells) {
rval = nvmem_add_cells_from_legacy_of(nvmem);
if (rval)
- goto err_remove_cells;
+ goto err_remove_compat;
}
dev_dbg(&nvmem->dev, "Registering nvmem device %s\n", config->name);
rval = device_add(&nvmem->dev);
if (rval)
- goto err_remove_cells;
+ goto err_remove_compat;
rval = nvmem_populate_layout(nvmem);
if (rval)
@@ -1032,8 +1032,7 @@ struct nvmem_device *nvmem_register(const struct nvmem_config *config)
#endif
err_remove_dev:
device_del(&nvmem->dev);
-err_remove_cells:
- nvmem_device_remove_all_cells(nvmem);
+err_remove_compat:
nvmem_sysfs_remove_compat(nvmem);
err_put_device:
put_device(&nvmem->dev);
@@ -1042,21 +1041,6 @@ struct nvmem_device *nvmem_register(const struct nvmem_config *config)
}
EXPORT_SYMBOL_GPL(nvmem_register);
-static void nvmem_device_release(struct kref *kref)
-{
- struct nvmem_device *nvmem;
-
- nvmem = container_of(kref, struct nvmem_device, refcnt);
-
- blocking_notifier_call_chain(&nvmem_notifier, NVMEM_REMOVE, nvmem);
-
- nvmem_sysfs_remove_compat(nvmem);
-
- nvmem_device_remove_all_cells(nvmem);
- nvmem_destroy_layout(nvmem);
- device_unregister(&nvmem->dev);
-}
-
/**
* nvmem_unregister() - Unregister previously registered nvmem device
*
@@ -1064,8 +1048,15 @@ static void nvmem_device_release(struct kref *kref)
*/
void nvmem_unregister(struct nvmem_device *nvmem)
{
- if (nvmem)
- kref_put(&nvmem->refcnt, nvmem_device_release);
+ if (!nvmem)
+ return;
+
+ blocking_notifier_call_chain(&nvmem_notifier, NVMEM_REMOVE, nvmem);
+
+ nvmem_sysfs_remove_compat(nvmem);
+ nvmem_destroy_layout(nvmem);
+
+ device_unregister(&nvmem->dev);
}
EXPORT_SYMBOL_GPL(nvmem_unregister);
@@ -1126,8 +1117,6 @@ static struct nvmem_device *nvmem_device_match(void *data,
return ERR_PTR(-EINVAL);
}
- kref_get(&nvmem->refcnt);
-
return nvmem;
}
@@ -1243,9 +1232,8 @@ EXPORT_SYMBOL_GPL(devm_nvmem_device_put);
*/
void nvmem_device_put(struct nvmem_device *nvmem)
{
- put_device(&nvmem->dev);
module_put(nvmem->owner);
- kref_put(&nvmem->refcnt, nvmem_device_release);
+ put_device(&nvmem->dev);
}
EXPORT_SYMBOL_GPL(nvmem_device_put);
diff --git a/drivers/nvmem/internals.h b/drivers/nvmem/internals.h
index 4e610deeaa7b..2c3645a27272 100644
--- a/drivers/nvmem/internals.h
+++ b/drivers/nvmem/internals.h
@@ -19,7 +19,6 @@ struct nvmem_device {
int stride;
int word_size;
int id;
- struct kref refcnt;
size_t size;
bool read_only;
bool root_only;
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH 9/9] nvmem: protect nvmem_device::ops with SRCU
2026-10-02 10:13 [PATCH 0/9] nvmem: patches for 7.4 srini
` (7 preceding siblings ...)
2026-10-02 10:13 ` [PATCH 8/9] nvmem: remove duplicated reference counting srini
@ 2026-10-02 10:13 ` srini
8 siblings, 0 replies; 10+ messages in thread
From: srini @ 2026-10-02 10:13 UTC (permalink / raw)
To: gregkh; +Cc: linux-kernel, Bartosz Golaszewski, Srinivas Kandagatla
From: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
With the provider-owned data split out into a separate 'ops' structure,
we can now protect it with SRCU.
Protect all dereferences of nvmem->ops with an SRCU read lock.
Synchronize SRCU in nvmem_unregister() after setting the implementation
pointer to NULL. This has the effect of numbing down the device after
nvmem_unregister() returns - it will no longer accept any consumer calls
and return -ENODEV. The actual device will live on for as long as there
are references to it but we will no longer reach into the consumer's
memory which may be gone by this time.
Nvmem cell entries are destroyed in .release() now as they may be still
dereferenced via the nvmem_cell handles after nvmem_release(). The
actual calls will still go through SRCU and fail with -ENODEV if the
provider is gone.
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Srinivas Kandagatla <srini@kernel.org>
---
drivers/nvmem/core.c | 44 +++++++++++++++++++++++++++++++++------
drivers/nvmem/internals.h | 4 +++-
2 files changed, 41 insertions(+), 7 deletions(-)
diff --git a/drivers/nvmem/core.c b/drivers/nvmem/core.c
index 8f4f65139966..0a7a9e8fa1a4 100644
--- a/drivers/nvmem/core.c
+++ b/drivers/nvmem/core.c
@@ -57,7 +57,12 @@ static BLOCKING_NOTIFIER_HEAD(nvmem_notifier);
static int __nvmem_reg_read(struct nvmem_device *nvmem, unsigned int offset,
void *val, size_t bytes)
{
- struct nvmem_operations *ops = nvmem->ops;
+ struct nvmem_operations *ops;
+
+ guard(srcu)(&nvmem->srcu);
+ ops = srcu_dereference(nvmem->ops, &nvmem->srcu);
+ if (!ops)
+ return -ENODEV;
if (!ops->reg_read)
return -EOPNOTSUPP;
@@ -68,9 +73,14 @@ static int __nvmem_reg_read(struct nvmem_device *nvmem, unsigned int offset,
static int __nvmem_reg_write(struct nvmem_device *nvmem, unsigned int offset,
void *val, size_t bytes)
{
- struct nvmem_operations *ops = nvmem->ops;
+ struct nvmem_operations *ops;
int ret, wr_ok;
+ guard(srcu)(&nvmem->srcu);
+ ops = srcu_dereference(nvmem->ops, &nvmem->srcu);
+ if (!ops)
+ return -ENODEV;
+
if (!ops->reg_write)
return -EOPNOTSUPP;
@@ -289,7 +299,7 @@ static ssize_t bin_attr_nvmem_write(struct file *filp, struct kobject *kobj,
static umode_t nvmem_bin_attr_get_umode(struct nvmem_device *nvmem)
{
- struct nvmem_operations *ops = nvmem->ops;
+ struct nvmem_operations *ops = rcu_dereference_raw(nvmem->ops);
umode_t mode = 0400;
@@ -333,7 +343,7 @@ static umode_t nvmem_attr_is_visible(struct kobject *kobj,
{
struct device *dev = kobj_to_dev(kobj);
struct nvmem_device *nvmem = to_nvmem_device(dev);
- struct nvmem_operations *ops = nvmem->ops;
+ struct nvmem_operations *ops = rcu_dereference_raw(nvmem->ops);
/*
* If the device has no .reg_write operation, do not allow
@@ -560,7 +570,7 @@ static void nvmem_release(struct device *dev)
gpiod_put(nvmem->wp_gpio);
nvmem_device_remove_all_cells(nvmem);
ida_free(&nvmem_ida, nvmem->id);
- kfree(nvmem->ops);
+ cleanup_srcu_struct(&nvmem->srcu);
kfree(nvmem);
}
@@ -920,7 +930,20 @@ struct nvmem_device *nvmem_register(const struct nvmem_config *config)
nvmem->dev.bus = &nvmem_bus_type;
nvmem->dev.parent = config->dev;
INIT_LIST_HEAD(&nvmem->cells);
- nvmem->ops = ops;
+
+ /*
+ * Must happen before we assign the release() callback in
+ * device_initialize().
+ */
+ rval = init_srcu_struct(&nvmem->srcu);
+ if (rval) {
+ ida_free(&nvmem_ida, nvmem->id);
+ kfree(ops);
+ kfree(nvmem);
+ return ERR_PTR(rval);
+ }
+
+ rcu_assign_pointer(nvmem->ops, ops);
device_initialize(&nvmem->dev);
@@ -1035,7 +1058,10 @@ struct nvmem_device *nvmem_register(const struct nvmem_config *config)
err_remove_compat:
nvmem_sysfs_remove_compat(nvmem);
err_put_device:
+ ops = rcu_replace_pointer(nvmem->ops, NULL, true);
+ synchronize_srcu(&nvmem->srcu);
put_device(&nvmem->dev);
+ kfree(ops);
return ERR_PTR(rval);
}
@@ -1048,13 +1074,19 @@ EXPORT_SYMBOL_GPL(nvmem_register);
*/
void nvmem_unregister(struct nvmem_device *nvmem)
{
+ struct nvmem_operations *ops;
+
if (!nvmem)
return;
blocking_notifier_call_chain(&nvmem_notifier, NVMEM_REMOVE, nvmem);
+ ops = rcu_replace_pointer(nvmem->ops, NULL, true);
+ synchronize_srcu(&nvmem->srcu);
+
nvmem_sysfs_remove_compat(nvmem);
nvmem_destroy_layout(nvmem);
+ kfree(ops);
device_unregister(&nvmem->dev);
}
diff --git a/drivers/nvmem/internals.h b/drivers/nvmem/internals.h
index 2c3645a27272..bc7a99f5aefb 100644
--- a/drivers/nvmem/internals.h
+++ b/drivers/nvmem/internals.h
@@ -6,6 +6,7 @@
#include <linux/device.h>
#include <linux/nvmem-consumer.h>
#include <linux/nvmem-provider.h>
+#include <linux/srcu.h>
/* Hold pointers to callbacks owned by the nvmem provider module. */
struct nvmem_operations {
@@ -16,6 +17,7 @@ struct nvmem_operations {
struct nvmem_device {
struct module *owner;
struct device dev;
+ struct srcu_struct srcu;
int stride;
int word_size;
int id;
@@ -33,7 +35,7 @@ struct nvmem_device {
unsigned int nkeepout;
struct gpio_desc *wp_gpio;
struct nvmem_layout *layout;
- struct nvmem_operations *ops;
+ struct nvmem_operations __rcu *ops;
void *priv;
bool sysfs_cells_populated;
};
--
2.53.0
^ permalink raw reply [flat|nested] 10+ messages in thread