From: sashiko-bot@kernel.org
To: "Paul Cercueil" <paul.cercueil@bootlin.com>,
"Thomas Petazzoni" <thomas.petazzoni@bootlin.com>,
"Mark Brown" <broonie@kernel.org>,
"Takahiro Kuwano" <takahiro.kuwano@infineon.com>,
"Richard Weinberger" <richard@nod.at>,
"Vignesh Raghavendra" <vigneshr@ti.com>,
"Miquel Raynal" <miquel.raynal@bootlin.com>,
"Michael Walle" <mwalle@kernel.org>,
"Pratyush Yadav" <pratyush@kernel.org>
Cc: "Kees Cook" <kees@kernel.org>,
linux-kernel@vger.kernel.org, linux-spi@vger.kernel.org,
"Tanmay Jagdale" <tanmay@marvell.com>,
linux-mtd@lists.infradead.org,
"Guilherme G . Piccoli" <gpiccoli@igalia.com>,
"Tony Luck" <tony.luck@intel.com>
Subject: Re: [PATCH 4/5] spi: cadence-xspi: Don't use infinite timeout in register poll
Date: Mon, 05 Oct 2026 08:21:17 +0000 [thread overview]
Message-ID: <20261005082117.717511F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261005081141.33688-5-paul.cercueil@bootlin.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] spi: cadence-xspi: deadlock in panic writes due to non-atomic poll macro
--
commit 3f62b2245460c33dcb6fb6615d7fdf03de827776
Author: Tanmay Jagdale <tanmay@marvell.com>
spi: cadence-xspi: Don't use infinite timeout in register poll
The commit modifies the register polling functions to enforce a non-zero
timeout even when the sleep argument is false. This prevents busy-waits from
switching to infinite timeouts. The change anticipates future panic write
handling support.
> diff --git a/drivers/spi/spi-cadence-xspi.c b/drivers/spi/spi-cadence-xspi.c
> index 7cf52bcb05df6..09ed2afbd4af3 100644
> --- a/drivers/spi/spi-cadence-xspi.c
> +++ b/drivers/spi/spi-cadence-xspi.c
> @@ -374,7 +374,7 @@ static bool cdns_xspi_is_stig_ready(struct cdns_xspi_dev *cdns_xspi, bool sleep)
> ctrl_stat,
> ((ctrl_stat & BIT(3)) == 0),
> sleep ? MRVL_XSPI_POLL_DELAY_US : 0,
> - sleep ? MRVL_XSPI_POLL_TIMEOUT_US : 0);
> + MRVL_XSPI_POLL_TIMEOUT_US);
[Severity: High]
Does this unconditionally trigger timekeeping functions in panic contexts?
When sleep is false, the panic write handler can deadlock.
The readl_relaxed_poll_timeout() macro expands to poll_timeout_us(), which
unconditionally calls ktime_get() when a non-zero timeout is provided.
In a panic context, timekeeping is suspended.
If a system panic occurs while another CPU holds the timekeeping seqlock
(tk_core.seq) and is stopped, ktime_get() will spin endlessly in
read_seqcount_begin(), deadlocking the system.
This prevents oops/kmsg crash logs from being written to flash, which is why
the <linux/iopoll.h> API contract explicitly forbids using it in atomic
contexts with a non-zero timeout.
To safely poll without sleeping in panic contexts, should the driver
conditionally use readl_relaxed_poll_timeout_atomic(), which relies on
udelay() and cycle counting instead of ktime_get()?
> }
>
> static bool cdns_xspi_is_sdma_ready(struct cdns_xspi_dev *cdns_xspi, bool sleep)
> @@ -386,7 +386,7 @@ static bool cdns_xspi_is_sdma_ready(struct cdns_xspi_dev *cdns_xspi, bool sleep)
> ctrl_stat,
> (ctrl_stat & CDNS_XSPI_SDMA_TRIGGER),
> sleep ? MRVL_XSPI_POLL_DELAY_US : 0,
> - sleep ? MRVL_XSPI_POLL_TIMEOUT_US : 0);
> + MRVL_XSPI_POLL_TIMEOUT_US);
[Severity: High]
Can the same deadlock occur in the SDMA polling loop since this also calls
readl_relaxed_poll_timeout() with a non-zero timeout when sleep is false?
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261005081141.33688-1-paul.cercueil@bootlin.com?part=4
next prev parent reply other threads:[~2026-10-05 8:21 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 8:11 [PATCH 0/5] spi: Add support for panic mem writes Paul Cercueil
2026-10-05 8:11 ` [PATCH 1/5] spi: spi-mem: " Paul Cercueil
2026-10-05 8:24 ` sashiko-bot
2026-10-05 8:11 ` [PATCH 2/5] mtd: spi-nor: Add support for panic writes Paul Cercueil
2026-10-05 8:23 ` sashiko-bot
2026-10-05 8:11 ` [PATCH 3/5] spi: cadence-xspi: Add irq-less support Paul Cercueil
2026-10-05 8:24 ` sashiko-bot
2026-10-05 8:11 ` [PATCH 4/5] spi: cadence-xspi: Don't use infinite timeout in register poll Paul Cercueil
2026-10-05 8:21 ` sashiko-bot [this message]
2026-10-05 8:11 ` [PATCH 5/5] spi: cadence-xspi: Add support for panic writes Paul Cercueil
2026-10-05 8:26 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005082117.717511F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=broonie@kernel.org \
--cc=gpiccoli@igalia.com \
--cc=kees@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mtd@lists.infradead.org \
--cc=linux-spi@vger.kernel.org \
--cc=miquel.raynal@bootlin.com \
--cc=mwalle@kernel.org \
--cc=paul.cercueil@bootlin.com \
--cc=pratyush@kernel.org \
--cc=richard@nod.at \
--cc=sashiko-reviews@lists.linux.dev \
--cc=takahiro.kuwano@infineon.com \
--cc=tanmay@marvell.com \
--cc=thomas.petazzoni@bootlin.com \
--cc=tony.luck@intel.com \
--cc=vigneshr@ti.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®