mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Richard Weinberger" <richard@nod.at>,
	"Takahiro Kuwano" <takahiro.kuwano@infineon.com>,
	"Miquel Raynal" <miquel.raynal@bootlin.com>,
	"Pratyush Yadav" <pratyush@kernel.org>,
	"Vignesh Raghavendra" <vigneshr@ti.com>,
	"Michael Walle" <mwalle@kernel.org>
Cc: linux-mtd@lists.infradead.org, "Steam Lin" <STLin2@winbond.com>,
	"Thomas Petazzoni" <thomas.petazzoni@bootlin.com>,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH 06/15] mtd: spi-nor: Fix WRSR with ODTR chips
Date: Fri, 02 Oct 2026 12:34:31 +0000	[thread overview]
Message-ID: <20261002123432.42F6E1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20261002-winbond-master-spi-nor-w35t-v1-6-a22a2f95c26e@bootlin.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] mtd: spi-nor: state leak in spi_nor_write_sr_ll() due to missing WEL cleanup
- [High] mtd: spi-nor: 16-bit status register writes erroneously rejected in 8-8-8 DTR mode
--

commit 4a237a858739ae2cb0d065925cac15d3e9009a72
Author: Miquel Raynal <miquel.raynal@bootlin.com>

mtd: spi-nor: Fix WRSR with ODTR chips

The ODTR interface requires an even number of bytes in each section of
the operation. spi_nor_spimem_setup_op() takes care of the opcode phase,
but we have to adapt the rest of the operation ourself.

> diff --git a/drivers/mtd/spi-nor/core.c b/drivers/mtd/spi-nor/core.c
> index cf23094021daa..381bbc13f82ff 100644
> --- a/drivers/mtd/spi-nor/core.c
> +++ b/drivers/mtd/spi-nor/core.c
> @@ -791,6 +791,17 @@ static int spi_nor_write_sr_ll(struct spi_nor *nor, u8 opcode, const u8 *sr,
>  	if (nor->spimem) {
>  		struct spi_mem_op op = SPI_NOR_WRSR_OP(opcode,
>  						       nor->bouncebuf, len);
> +		if (nor->reg_proto == SNOR_PROTO_8_8_8_DTR) {
> +			if (len != 1)
> +				return -EOPNOTSUPP;

[Severity: High]
Does this early return leak the Write Enable Latch state?

In spi_nor_write_sr_ll(), spi_nor_write_enable() is called before this code
is reached, which transmits the WREN opcode to the flash chip and sets its
internal Write Enable Latch.

If len is not 1, this early return bypasses the execution of the intended WRSR
command and does not call spi_nor_write_disable() to manually clear the latch
bit.

Could this leave the flash globally write-enabled and vulnerable to accidental
data corruption?

[Severity: High]
Does this condition unintentionally reject 16-bit status register writes
in 8-8-8 DTR mode?

Callers like spi_nor_write_sr1_and_sr2() natively invoke spi_nor_write_sr_ll()
with len = 2 to write 16-bit status registers:

drivers/mtd/spi-nor/core.c:spi_nor_write_sr1_and_sr2() {
    ...
	if (params->opcodes.write_sr1_and_sr2)
		return spi_nor_write_sr_ll(nor,
					   params->opcodes.write_sr1_and_sr2,
					   sr, 2);
    ...
}

Returning -EOPNOTSUPP here blocks these valid operations without a fallback.

> +
> +			/*
> +			 * We don't want to write only one byte in DTR mode. So,
> +			 * duplicate the buffer and write 2.
> +			 */
> +			op.data.nbytes = 2;
> +			nor->bouncebuf[1] = nor->bouncebuf[0];
> +		}
>  
>  		spi_nor_spimem_setup_op(nor, &op, nor->reg_proto);
>

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002-winbond-master-spi-nor-w35t-v1-0-a22a2f95c26e@bootlin.com?part=6

  reply	other threads:[~2026-10-02 12:34 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 12:21 [PATCH 00/15] mtd: spi-nor: winbond: Add support for the W35TxxNW family Miquel Raynal
2026-10-02 12:21 ` [PATCH 01/15] mtd: spi-nor: Only switch to ODTR if the chip has a callback for it Miquel Raynal
2026-10-02 12:21 ` [PATCH 02/15] mtd: spi-nor: Fix spacing between arguments Miquel Raynal
2026-10-02 12:21 ` [PATCH 03/15] mtd: spi-nor: Fix comment indentation to clarify the intent Miquel Raynal
2026-10-02 12:21 ` [PATCH 04/15] mtd: spi-nor: sfdp: Enhance a comment Miquel Raynal
2026-10-02 12:21 ` [PATCH 05/15] mtd: spi-nor: Drop stale values Miquel Raynal
2026-10-02 12:21 ` [PATCH 06/15] mtd: spi-nor: Fix WRSR with ODTR chips Miquel Raynal
2026-10-02 12:34   ` sashiko-bot [this message]
2026-10-02 12:21 ` [PATCH 07/15] mtd: spi-nor: Allow configuring the actual number of dummy cycles Miquel Raynal
2026-10-02 12:34   ` sashiko-bot
2026-10-02 12:21 ` [PATCH 08/15] mtd: spi-nor: Fix SWP for octal DTR chips Miquel Raynal
2026-10-02 12:29   ` sashiko-bot
2026-10-02 12:21 ` [PATCH 09/15] mtd: spi-nor: winbond: Prepare the introduction of W35TxxNW parts Miquel Raynal
2026-10-02 12:45   ` sashiko-bot
2026-10-02 12:21 ` [PATCH 10/15] mtd: spi-nor: winbond: Add support for W35T64NW-C Miquel Raynal
2026-10-02 12:21 ` [PATCH 11/15] mtd: spi-nor: winbond: Add support for W35T12NW-C Miquel Raynal
2026-10-02 12:21 ` [PATCH 12/15] mtd: spi-nor: winbond: Add support for W35T25NW-C/E Miquel Raynal
2026-10-02 12:21 ` [PATCH 13/15] mtd: spi-nor: winbond: Add support for W35T51NW-C/E Miquel Raynal
2026-10-02 12:32   ` sashiko-bot
2026-10-02 12:21 ` [PATCH 14/15] mtd: spi-nor: winbond: Add support for W35T01NW-C/E Miquel Raynal
2026-10-02 12:21 ` [PATCH 15/15] mtd: spi-nor: winbond: Add support for W35T02NW-C/E Miquel Raynal

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002123432.42F6E1F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=STLin2@winbond.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mtd@lists.infradead.org \
    --cc=miquel.raynal@bootlin.com \
    --cc=mwalle@kernel.org \
    --cc=pratyush@kernel.org \
    --cc=richard@nod.at \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=takahiro.kuwano@infineon.com \
    --cc=thomas.petazzoni@bootlin.com \
    --cc=vigneshr@ti.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®