mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] phy: marvell: a3700-comphy: Guard missing polarity argument
@ 2026-10-01 15:19 Štěpán Dalecký
  2026-10-01 16:30 ` Miquel Raynal
  0 siblings, 1 reply; 3+ messages in thread
From: Štěpán Dalecký @ 2026-10-01 15:19 UTC (permalink / raw)
  To: Miquel Raynal, Vinod Koul
  Cc: Štěpán Dalecký,
	Neil Armstrong, Manivannan Sadhasivam, linux-phy, linux-kernel

The Armada 3700 COMPHY binding specifies #phy-cells = <1>, so PHY
references supply only the port argument. However,
mvebu_a3700_comphy_xlate() unconditionally reads args[1] to select TX
and RX polarity inversion. The PHY core does not initialize its
of_phandle_args structure, and the phandle parser fills only the
supplied cells, leaving args[1] uninitialized.

Using the unused cell can program unintended SerDes polarity. On a
Turris MOX with a Peridot switch running OpenWrt with Linux 6.18.54,
the CPU link reports RX CRC errors and fails to pass traffic. The
switch PCS does not record a partner advertisement despite link-up.

Check args_count before reading args[1], leaving polarity inversion
disabled when the second argument was not supplied. This does not
change the binding or introduce a supported two-cell interface.

The same change restores 2500BASE-X communication on the affected
MOX with no CRC errors. Cold boots, reboots and interface down/up
cycles were also tested successfully on Linux 6.18.54.

Fixes: 934337080c6c ("phy: marvell: phy-mvebu-a3700-comphy: Add native kernel implementation")
Cc: stable@vger.kernel.org
Closes: https://github.com/openwrt/openwrt/issues/24069
Assisted-by: LLM
Signed-off-by: Štěpán Dalecký <daleckystepan@gmail.com>
---
GitHub Copilot assisted with comparing the working and failing logs,
identifying the unused argument read, preparing the fix and changelog,
and checking the patch. The submitter performed the MOX hardware tests.

The reported hardware tests used OpenWrt with Linux 6.18.54. Mainline
runtime testing has not been performed. An isolated ARM64 mainline build
was attempted on macOS but failed while building host fixdep because
the host Clang could not use -fuse-ld=lld; the driver was not compiled.
A host C test of the changed expressions with poisoned unused argument
slots passed, as did strict checkpatch.

 drivers/phy/marvell/phy-mvebu-a3700-comphy.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/phy/marvell/phy-mvebu-a3700-comphy.c b/drivers/phy/marvell/phy-mvebu-a3700-comphy.c
index 1d1db1737422..d19f0fa9ba7c 100644
--- a/drivers/phy/marvell/phy-mvebu-a3700-comphy.c
+++ b/drivers/phy/marvell/phy-mvebu-a3700-comphy.c
@@ -1232,8 +1232,8 @@ static struct phy *mvebu_a3700_comphy_xlate(struct device *dev,
 		return ERR_PTR(-EINVAL);
 	}
 
-	lane->invert_tx = args->args[1] & BIT(0);
-	lane->invert_rx = args->args[1] & BIT(1);
+	lane->invert_tx = args->args_count > 1 && (args->args[1] & BIT(0));
+	lane->invert_rx = args->args_count > 1 && (args->args[1] & BIT(1));
 
 	return phy;
 }

base-commit: 551c722f40809618230001baccf219193e22fc5a
-- 
2.54.0 (Apple Git-157)


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] phy: marvell: a3700-comphy: Guard missing polarity argument
  2026-10-01 15:19 [PATCH] phy: marvell: a3700-comphy: Guard missing polarity argument Štěpán Dalecký
@ 2026-10-01 16:30 ` Miquel Raynal
  0 siblings, 0 replies; 3+ messages in thread
From: Miquel Raynal @ 2026-10-01 16:30 UTC (permalink / raw)
  To: Štěpán Dalecký
  Cc: Vinod Koul, Neil Armstrong, Manivannan Sadhasivam, linux-phy,
	linux-kernel

On 01/10/2026 at 17:19:38 +02, Štěpán Dalecký <daleckystepan@gmail.com> wrote:

> The Armada 3700 COMPHY binding specifies #phy-cells = <1>, so PHY
> references supply only the port argument. However,
> mvebu_a3700_comphy_xlate() unconditionally reads args[1] to select TX
> and RX polarity inversion. The PHY core does not initialize its
> of_phandle_args structure, and the phandle parser fills only the
> supplied cells, leaving args[1] uninitialized.
>
> Using the unused cell can program unintended SerDes polarity. On a
> Turris MOX with a Peridot switch running OpenWrt with Linux 6.18.54,
> the CPU link reports RX CRC errors and fails to pass traffic. The
> switch PCS does not record a partner advertisement despite link-up.
>
> Check args_count before reading args[1], leaving polarity inversion
> disabled when the second argument was not supplied. This does not
> change the binding or introduce a supported two-cell interface.
>
> The same change restores 2500BASE-X communication on the affected
> MOX with no CRC errors. Cold boots, reboots and interface down/up
> cycles were also tested successfully on Linux 6.18.54.
>
> Fixes: 934337080c6c ("phy: marvell: phy-mvebu-a3700-comphy: Add native kernel implementation")
> Cc: stable@vger.kernel.org
> Closes: https://github.com/openwrt/openwrt/issues/24069
> Assisted-by: LLM
> Signed-off-by: Štěpán Dalecký <daleckystepan@gmail.com>

Reviewed-by: Miquel Raynal <miquel.raynal@bootlin.com>

^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH] phy: marvell: a3700-comphy: Guard missing polarity argument
@ 2026-10-01 15:10 Štěpán Dalecký
  0 siblings, 0 replies; 3+ messages in thread
From: Štěpán Dalecký @ 2026-10-01 15:10 UTC (permalink / raw)
  To: Miquel Raynal, Vinod Koul
  Cc: Štěpán Dalecký,
	Neil Armstrong, Manivannan Sadhasivam, linux-phy, linux-kernel

The Armada 3700 COMPHY binding specifies #phy-cells = <1>, so PHY
references supply only the port argument. However,
mvebu_a3700_comphy_xlate() unconditionally reads args[1] to select TX
and RX polarity inversion. The PHY core does not initialize its
of_phandle_args structure, and the phandle parser fills only the
supplied cells, leaving args[1] uninitialized.

Using the unused cell can program unintended SerDes polarity. On a
Turris MOX with a Peridot switch running OpenWrt with Linux 6.18.54,
the CPU link reports RX CRC errors and fails to pass traffic. The
switch PCS does not record a partner advertisement despite link-up.

Check args_count before reading args[1], leaving polarity inversion
disabled when the second argument was not supplied. This does not
change the binding or introduce a supported two-cell interface.

The same change restores 2500BASE-X communication on the affected
MOX with no CRC errors. Cold boots, reboots and interface down/up
cycles were also tested successfully on Linux 6.18.54.

Fixes: 934337080c6c ("phy: marvell: phy-mvebu-a3700-comphy: Add native kernel implementation")
Cc: stable@vger.kernel.org
Closes: https://github.com/openwrt/openwrt/issues/24069
Assisted-by: LLM
Signed-off-by: Štěpán Dalecký <daleckystepan@gmail.com>
---
GitHub Copilot assisted with comparing the working and failing logs,
identifying the unused argument read, preparing the fix and changelog,
and checking the patch. The submitter performed the MOX hardware tests.

The reported hardware tests used OpenWrt with Linux 6.18.54. Mainline
runtime testing has not been performed. An isolated ARM64 mainline build
was attempted on macOS but failed while building host fixdep because
the host Clang could not use -fuse-ld=lld; the driver was not compiled.
A host C test of the changed expressions with poisoned unused argument
slots passed, as did strict checkpatch.

 drivers/phy/marvell/phy-mvebu-a3700-comphy.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/phy/marvell/phy-mvebu-a3700-comphy.c b/drivers/phy/marvell/phy-mvebu-a3700-comphy.c
index 1d1db1737422..d19f0fa9ba7c 100644
--- a/drivers/phy/marvell/phy-mvebu-a3700-comphy.c
+++ b/drivers/phy/marvell/phy-mvebu-a3700-comphy.c
@@ -1232,8 +1232,8 @@ static struct phy *mvebu_a3700_comphy_xlate(struct device *dev,
 		return ERR_PTR(-EINVAL);
 	}
 
-	lane->invert_tx = args->args[1] & BIT(0);
-	lane->invert_rx = args->args[1] & BIT(1);
+	lane->invert_tx = args->args_count > 1 && (args->args[1] & BIT(0));
+	lane->invert_rx = args->args_count > 1 && (args->args[1] & BIT(1));
 
 	return phy;
 }

base-commit: 551c722f40809618230001baccf219193e22fc5a
-- 
2.54.0 (Apple Git-157)


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-01 16:31 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-01 15:19 [PATCH] phy: marvell: a3700-comphy: Guard missing polarity argument Štěpán Dalecký
2026-10-01 16:30 ` Miquel Raynal
  -- strict thread matches above, loose matches on Subject: below --
2026-10-01 15:10 Štěpán Dalecký

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®