mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines
@ 2026-10-01 16:11 Imre Kaloz
  2026-10-01 16:11 ` [PATCH 01/38] MIPS: Xtalk: guard the widget identification table from assembly Imre Kaloz
                   ` (37 more replies)
  0 siblings, 38 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

This series adds support for the SGI machines built around the Bedrock
hub (IP35), such as Fuel and Tezro, to the IP27 platform code.


Patches 1-17 teach the IP27 code the Bedrock hub: detection, the node
address layout and register windows, the node id, CPU slots, memory
banks, both PIs and the kernel load address.

Patches 18-27 add the crossbar, bridge and I/O parts of these machines:
PXBow, XBridge, PIC and IOC4.

Patches 28-38 add the L1 system controller and what it provides, the
Odyssey graphics widget, the KLCONFIG console and a topology package
id per CPU.

Tested on SGI Fuel and Tezro. The NMI dump reaches the 8250 console
only with "MIPS: SGI-IP27: print the NMI dump on an nbcon console",
posted separately.

On IP27 (Hub) machines:
- patch 17 moves the kernel up by 144KB, and the 144KB below it stays
  reserved and unused;
- with patch 21 SWIOTLB takes 64MB of node 0 on a multi-node Origin;
- the XBridge DMA window (patch 21) and the w1 change (patch 33) do
  nothing on a Hub with classic Bridges.

Given I have no IP27 boxes, none of this was booted on one.
ip27_defconfig and ip30_defconfig build at every patch.

An XBridge or PIC on a Bedrock hub takes its board setup from the
first board part number the L1 reports that the setup table knows
(patch 30), so on a machine with several bricks every such bridge gets
that one board's setup.

Patch 36 registers the Odyssey graphics widget as the "sgi-odyssey"
platform device used by the Odyssey DRM driver, a separate series.

checkpatch reports "spaces required around that ':'" in patches 9 and
16 for the GAS numeric local labels 1: and 2: in assembler macros.

Imre Kaloz (38):
  MIPS: Xtalk: guard the widget identification table from assembly
  MIPS: SGI-IP27: dump the NMI save areas the CPU scan recorded
  MIPS: SGI-IP27: add REMOTE_HUB_PI_S()/REMOTE_HUB_PI_L()
  MIPS: SGI-IP27: detect Bedrock hubs at boot
  MIPS: SGI-IP27: widen Kconfig for the Bedrock-based machines
  MIPS: SGI-IP27: fold the dead SN1 arm out of klconfig.h
  MIPS: SGI-IP27: choose the node address layout at runtime
  MIPS: SGI-IP27: add the Bedrock hub register windows
  MIPS: SGI-IP27: decode a Bedrock hub's node id and system size
  MIPS: SGI-IP27: put a Bedrock hub's boot CPU in slot 0
  MIPS: SGI-IP27: lay out node memory in 1GB banks on Bedrock hubs
  MIPS: SGI-IP27: reserve the bottom 64MB of node 0 on Bedrock hubs
  MIPS: SGI-IP27: route interrupt masks and slices through both PIs
  MIPS: SGI-IP27: address a CPU's own PI for NMI, IPI and RT counter
  MIPS: SGI-IP27: take a CPU's node from the CPU table in per_cpu_init()
  MIPS: SGI-IP27: resolve the mapped-kernel node shift at runtime
  MIPS: SGI-IP27: load the kernel at node offset 0x40000
  MIPS: SGI-IP27: xbow_probe(): recognize KLTYPE_PBRICK_XBOW
  MIPS: ip27_defconfig: enable the IOC3 MFD, its cell drivers and tg3
  net: ethernet: sgi: ioc3-eth: apply the DMA attributes only to 64-bit
    addresses
  MIPS: SGI-IP27: route XBridge and PIC DMA through the 32-bit window
  MIPS: SGI-IP27: recognize the PXBow crossbar
  MIPS: PCI: xtalk-bridge: recognize the PIC widget's 64-bit-only
    registers
  MIPS: PCI: xtalk-bridge: match PIC's register-level differences
  rtc: m48t35: support the SGI IP35 timekeeper's 1968 year base
  mfd: ioc3: add support for IOC4
  MIPS: SGI-IP27: dispatch the early console between IOC3 and IOC4
  MIPS: SGI-IP27: add L1 system controller support
  MIPS: SGI-IP27: wire the L1 into reset and the Ethernet address
  MIPS: PCI: xtalk-bridge: take the board part number from the L1
  mfd: ioc3: add IP34 system-board entry to ioc3_infos[]
  net: ethernet: sgi: ioc3-eth: fall back to the platform MAC address
  MIPS: SGI-IP27: don't register a w1 master on an XBridge or PIC
  MIPS: SGI-IP27: report a Bedrock machine as SGI IP35
  MIPS: SGI-IP27: identify the machine by the L1 brick type
  MIPS: SGI-IP27: register the Odyssey graphics widget
  MIPS: SGI-IP27: take the console from the KLCONFIG header on IP35
  MIPS: SGI-IP27: give each CPU its own topology package id

 arch/mips/Kconfig                             |  11 +-
 arch/mips/configs/ip27_defconfig              |   4 +
 .../include/asm/mach-ip27/kernel-entry-init.h |  33 +-
 arch/mips/include/asm/pci/bridge.h            |  83 +-
 arch/mips/include/asm/sn/addrs.h              |  39 +-
 arch/mips/include/asm/sn/agent.h              |   5 +-
 arch/mips/include/asm/sn/arch.h               |   8 +
 arch/mips/include/asm/sn/intr.h               |  14 +-
 arch/mips/include/asm/sn/ioc4.h               | 130 +++
 arch/mips/include/asm/sn/klconfig.h           |  19 +-
 arch/mips/include/asm/sn/kldir.h              |   1 +
 arch/mips/include/asm/sn/l1.h                 |  22 +
 arch/mips/include/asm/sn/mapped_kernel.h      |   6 +-
 arch/mips/include/asm/sn/sn0/addrs.h          |   8 +-
 arch/mips/include/asm/sn/sn0/hub.h            |  37 +-
 arch/mips/include/asm/sn/sn0/hubni.h          |   3 +
 arch/mips/include/asm/sn/sn1/addrs.h          |  22 +
 arch/mips/include/asm/sn/sn1/hub.h            |  40 +
 arch/mips/include/asm/sn/sn1/kldir.h          |  14 +
 arch/mips/include/asm/xtalk/xwidget.h         |  11 +-
 arch/mips/pci/pci-xtalk-bridge.c              | 124 ++-
 arch/mips/sgi-ip27/Makefile                   |   4 +-
 arch/mips/sgi-ip27/Platform                   |  11 +-
 arch/mips/sgi-ip27/ip27-berr.c                |   4 +-
 arch/mips/sgi-ip27/ip27-console.c             |  47 +-
 arch/mips/sgi-ip27/ip27-init.c                | 126 ++-
 arch/mips/sgi-ip27/ip27-irq.c                 |  17 +-
 arch/mips/sgi-ip27/ip27-l1.c                  | 817 ++++++++++++++++++
 arch/mips/sgi-ip27/ip27-memory.c              |  53 +-
 arch/mips/sgi-ip27/ip27-nmi.c                 |  54 +-
 arch/mips/sgi-ip27/ip27-reset.c               |  47 +-
 arch/mips/sgi-ip27/ip27-smp.c                 |  37 +-
 arch/mips/sgi-ip27/ip27-timer.c               |  12 +-
 arch/mips/sgi-ip27/ip27-xtalk.c               | 127 ++-
 drivers/mfd/ioc3.c                            | 335 ++++++-
 drivers/net/ethernet/sgi/ioc3-eth.c           |  37 +-
 drivers/rtc/rtc-m48t35.c                      |  29 +-
 drivers/tty/serial/8250/8250_ioc3.c           |   5 +-
 include/linux/platform_data/sgi-ioc3-serial.h |  13 +
 include/linux/platform_data/xtalk-bridge.h    |   2 +
 40 files changed, 2186 insertions(+), 225 deletions(-)
 create mode 100644 arch/mips/include/asm/sn/ioc4.h
 create mode 100644 arch/mips/include/asm/sn/l1.h
 create mode 100644 arch/mips/include/asm/sn/sn1/addrs.h
 create mode 100644 arch/mips/include/asm/sn/sn1/hub.h
 create mode 100644 arch/mips/include/asm/sn/sn1/kldir.h
 create mode 100644 arch/mips/sgi-ip27/ip27-l1.c
 create mode 100644 include/linux/platform_data/sgi-ioc3-serial.h


base-commit: 5dd1818b15d98d4a20806cd00b1b40320b06004f
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 01/38] MIPS: Xtalk: guard the widget identification table from assembly
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 02/38] MIPS: SGI-IP27: dump the NMI save areas the CPU scan recorded Imre Kaloz
                   ` (36 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

Only the constant definitions in this header are usable from assembly;
the widget identification table and the struct it is built from are not.
Put those behind __ASSEMBLER__ so the header can be included from an
assembly file.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/xtalk/xwidget.h | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/arch/mips/include/asm/xtalk/xwidget.h b/arch/mips/include/asm/xtalk/xwidget.h
index efcfe4494576..6dae5d9628f7 100644
--- a/arch/mips/include/asm/xtalk/xwidget.h
+++ b/arch/mips/include/asm/xtalk/xwidget.h
@@ -112,6 +112,7 @@
 #define WIDGET_XBRDG_PART_NUM	0xd002
 #define WIDGET_NULL_PART_NUM	-1
 
+#ifndef __ASSEMBLER__
 /* For Xtalk Widget identification */
 struct widget_ident {
 	u32 mfgr;
@@ -195,6 +196,7 @@ static const struct widget_ident __initconst widget_idents[] = {
 		{NULL},
 	}
 };
+#endif /* !__ASSEMBLER__ */
 
 /*
  * according to the crosstalk spec, only 32-bits access to the widget
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 02/38] MIPS: SGI-IP27: dump the NMI save areas the CPU scan recorded
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
  2026-10-01 16:11 ` [PATCH 01/38] MIPS: Xtalk: guard the widget identification table from assembly Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 03/38] MIPS: SGI-IP27: add REMOTE_HUB_PI_S()/REMOTE_HUB_PI_L() Imre Kaloz
                   ` (35 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

nmi_node_eframe_save() walks a fixed two slices per node, so the crash
dump can print a register set and a hub interrupt state for a slice the
node's CPU scan never recorded. Walk the recorded slices instead.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-nmi.c | 16 ++++++++--------
 1 file changed, 8 insertions(+), 8 deletions(-)

diff --git a/arch/mips/sgi-ip27/ip27-nmi.c b/arch/mips/sgi-ip27/ip27-nmi.c
index fc2816398d0c..07d63d020d22 100644
--- a/arch/mips/sgi-ip27/ip27-nmi.c
+++ b/arch/mips/sgi-ip27/ip27-nmi.c
@@ -4,6 +4,7 @@
 #include <linux/nodemask.h>
 #include <linux/spinlock.h>
 #include <linux/smp.h>
+#include <linux/topology.h>
 #include <linux/atomic.h>
 #include <asm/sn/types.h>
 #include <asm/sn/addrs.h>
@@ -13,12 +14,6 @@
 
 #include "ip27-common.h"
 
-#if 0
-#define NODE_NUM_CPUS(n)	CNODE_NUM_CPUS(n)
-#else
-#define NODE_NUM_CPUS(n)	CPUS_PER_NODE
-#endif
-
 #define SEND_NMI(_nasid, _slice)	\
 	REMOTE_HUB_S((_nasid),  (PI_NMI_A + ((_slice) * PI_NMI_OFFSET)), 1)
 
@@ -148,13 +143,18 @@ static void nmi_dump_hub_irq(nasid_t nasid, int slice)
  */
 static void nmi_node_eframe_save(nasid_t nasid)
 {
-	int slice;
+	int cpu;
 
 	if (nasid == INVALID_NASID)
 		return;
 
 	/* Save the registers into eframe for each cpu */
-	for (slice = 0; slice < NODE_NUM_CPUS(slice); slice++) {
+	for_each_possible_cpu(cpu) {
+		int slice = cputoslice(cpu);
+
+		if (cputonasid(cpu) != nasid)
+			continue;
+
 		nmi_cpu_eframe_save(nasid, slice);
 		nmi_dump_hub_irq(nasid, slice);
 	}
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 03/38] MIPS: SGI-IP27: add REMOTE_HUB_PI_S()/REMOTE_HUB_PI_L()
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
  2026-10-01 16:11 ` [PATCH 01/38] MIPS: Xtalk: guard the widget identification table from assembly Imre Kaloz
  2026-10-01 16:11 ` [PATCH 02/38] MIPS: SGI-IP27: dump the NMI save areas the CPU scan recorded Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 04/38] MIPS: SGI-IP27: detect Bedrock hubs at boot Imre Kaloz
                   ` (34 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

Some hub generations split each hub's PI registers across two
subnode blocks instead of one, so a remote access needs a subnode
selector on top of REMOTE_HUB_ADDR()'s node selector. Passing
subnode 0 reduces the new form to plain REMOTE_HUB_L()/REMOTE_HUB_S().

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/sn/addrs.h | 21 +++++++++++++++++++++
 1 file changed, 21 insertions(+)

diff --git a/arch/mips/include/asm/sn/addrs.h b/arch/mips/include/asm/sn/addrs.h
index 7c675fecbf9a..d5c7cfea7761 100644
--- a/arch/mips/include/asm/sn/addrs.h
+++ b/arch/mips/include/asm/sn/addrs.h
@@ -267,6 +267,27 @@
 
 #endif /* !__ASSEMBLER__ */
 
+/*
+ * Some hub generations split each hub's PI registers across two subnode
+ * blocks HUBPI_OFFSET apart; REMOTE_HUB_ADDR() always targets subnode 0.
+ */
+#define HUBPI_OFFSET		0x00200000
+
+#define REMOTE_HUB_PI_ADDR(_n, _sn, _x) \
+	(REMOTE_HUB_ADDR((_n), (_x)) + ((_sn) ? HUBPI_OFFSET : 0))
+
+#ifndef __ASSEMBLER__
+
+#define REMOTE_HUB_PI_PTR(_n, _sn, _x)	\
+	((u64 *)REMOTE_HUB_PI_ADDR((_n), (_sn), (_x)))
+
+#define REMOTE_HUB_PI_L(_n, _sn, _r)		\
+	__raw_readq(REMOTE_HUB_PI_PTR((_n), (_sn), (_r)))
+#define REMOTE_HUB_PI_S(_n, _sn, _r, _d)	\
+	__raw_writeq((_d), REMOTE_HUB_PI_PTR((_n), (_sn), (_r)))
+
+#endif /* !__ASSEMBLER__ */
+
 /*
  * Software structure locations -- permanently fixed
  *    See diagram in kldir.h
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 04/38] MIPS: SGI-IP27: detect Bedrock hubs at boot
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (2 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 03/38] MIPS: SGI-IP27: add REMOTE_HUB_PI_S()/REMOTE_HUB_PI_L() Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 05/38] MIPS: SGI-IP27: widen Kconfig for the Bedrock-based machines Imre Kaloz
                   ` (33 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

Read a hub's widget-ID register as the first thing prom_init() does
and record whether it is a Bedrock ASIC, so later code can branch on
that instead of a compile-time select. A local alias read needs no
nasid, so this runs first.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/sn/addrs.h | 6 ++++++
 arch/mips/sgi-ip27/ip27-init.c   | 9 +++++++++
 2 files changed, 15 insertions(+)

diff --git a/arch/mips/include/asm/sn/addrs.h b/arch/mips/include/asm/sn/addrs.h
index d5c7cfea7761..51161fd5130b 100644
--- a/arch/mips/include/asm/sn/addrs.h
+++ b/arch/mips/include/asm/sn/addrs.h
@@ -35,6 +35,12 @@
 
 #endif /* __ASSEMBLER__ */
 
+#ifndef __ASSEMBLER__
+
+extern bool system_is_ip35;
+
+#endif /* __ASSEMBLER__ */
+
 
 #define NASID_GET_META(_n)	((_n) >> NASID_LOCAL_BITS)
 #ifdef CONFIG_SGI_IP27
diff --git a/arch/mips/sgi-ip27/ip27-init.c b/arch/mips/sgi-ip27/ip27-init.c
index a4daf8ccd16c..6394c2076041 100644
--- a/arch/mips/sgi-ip27/ip27-init.c
+++ b/arch/mips/sgi-ip27/ip27-init.c
@@ -31,6 +31,7 @@
 #include <asm/thread_info.h>
 #include <asm/sn/launch.h>
 #include <asm/sn/mapped_kernel.h>
+#include <asm/xtalk/xwidget.h>
 
 #include "ip27-common.h"
 
@@ -38,6 +39,7 @@
 
 static DECLARE_BITMAP(hub_init_mask, MAX_NUMNODES);
 nasid_t master_nasid = INVALID_NASID;
+bool system_is_ip35;
 
 struct cpuinfo_ip27 sn_cpu_info[NR_CPUS];
 EXPORT_SYMBOL_GPL(sn_cpu_info);
@@ -139,8 +141,15 @@ const char *get_system_type(void)
 	return "SGI Origin";
 }
 
+static inline bool hub_is_bedrock(void)
+{
+	return XWIDGET_PART_NUM(LOCAL_HUB_L(IIO_WID)) == WIDGET_BDRCK_PART_NUM;
+}
+
 void __init prom_init(void)
 {
+	system_is_ip35 = hub_is_bedrock();
+
 	prom_init_cmdline(fw_arg0, (LONG *)fw_arg1);
 	prom_meminit();
 }
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 05/38] MIPS: SGI-IP27: widen Kconfig for the Bedrock-based machines
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (3 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 04/38] MIPS: SGI-IP27: detect Bedrock hubs at boot Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 06/38] MIPS: SGI-IP27: fold the dead SN1 arm out of klconfig.h Imre Kaloz
                   ` (32 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

CONFIG_SGI_IP27 now also covers the Bedrock-based IP35 machines such as
Fuel and Tezro, told apart from Origin 200/2000 at runtime rather than by
a separate config symbol. Update the prompt and help text.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/Kconfig | 9 +++++----
 1 file changed, 5 insertions(+), 4 deletions(-)

diff --git a/arch/mips/Kconfig b/arch/mips/Kconfig
index e2eb9627bd14..eb291fa7fd08 100644
--- a/arch/mips/Kconfig
+++ b/arch/mips/Kconfig
@@ -757,7 +757,7 @@ config SGI_IP22
 	  that runs on these, say Y here.
 
 config SGI_IP27
-	bool "SGI IP27 (Origin200/2000)"
+	bool "SGI IP27 (Origin200/2000) and IP35 (Fuel, Tezro)"
 	select ARCH_HAS_PHYS_TO_DMA
 	select ARCH_SPARSEMEM_ENABLE
 	select FW_ARC
@@ -782,9 +782,10 @@ config SGI_IP27
 	select MIPS_L1_CACHE_SHIFT_7
 	select NUMA
 	help
-	  This are the SGI Origin 200, Origin 2000 and Onyx 2 Graphics
-	  workstations.  To compile a Linux kernel that runs on these, say Y
-	  here.
+	  These are the SGI Origin 200, Origin 2000 and Onyx 2 Graphics
+	  workstations, and the IP35 machines built around the Bedrock hub
+	  ASIC, such as Fuel and Tezro.  To compile a Linux kernel that runs
+	  on these, say Y here.
 
 config SGI_IP28
 	bool "SGI IP28 (Indigo2 R10k)"
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 06/38] MIPS: SGI-IP27: fold the dead SN1 arm out of klconfig.h
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (4 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 05/38] MIPS: SGI-IP27: widen Kconfig for the Bedrock-based machines Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 07/38] MIPS: SGI-IP27: choose the node address layout at runtime Imre Kaloz
                   ` (31 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

klconfig.h's CONFIG_SGI_IP35 branch is unreachable: that symbol is
never selected, and the branch names headers that do not exist in
this tree. Fold its shared includes into the CONFIG_SGI_IP27 branch
and drop the unreachable rest.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/sn/klconfig.h | 19 ++-----------------
 1 file changed, 2 insertions(+), 17 deletions(-)

diff --git a/arch/mips/include/asm/sn/klconfig.h b/arch/mips/include/asm/sn/klconfig.h
index 3d1670b3e052..433d2d05aba3 100644
--- a/arch/mips/include/asm/sn/klconfig.h
+++ b/arch/mips/include/asm/sn/klconfig.h
@@ -40,26 +40,11 @@
 //#include <sys/graph.h>
 //#include <sys/xtalk/xbow.h>
 
-#elif defined(CONFIG_SGI_IP35)
-
-#include <asm/sn/sn1/addrs.h>
-#include <sys/sn/router.h>
-#include <sys/graph.h>
-#include <asm/xtalk/xbow.h>
-
-#endif /* !CONFIG_SGI_IP27 && !CONFIG_SGI_IP35 */
-
-#if defined(CONFIG_SGI_IP27) || defined(CONFIG_SGI_IP35)
 #include <asm/sn/agent.h>
 #include <asm/fw/arc/types.h>
 #include <asm/fw/arc/hinv.h>
-#if defined(CONFIG_SGI_IP35)
-// The hack file has to be before vector and after sn0_fru....
-#include <asm/hack.h>
-#include <asm/sn/vector.h>
-#include <asm/xtalk/xtalk.h>
-#endif /* CONFIG_SGI_IP35 */
-#endif /* CONFIG_SGI_IP27 || CONFIG_SGI_IP35 */
+
+#endif /* CONFIG_SGI_IP27 */
 
 typedef u64  nic_t;
 
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 07/38] MIPS: SGI-IP27: choose the node address layout at runtime
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (5 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 06/38] MIPS: SGI-IP27: fold the dead SN1 arm out of klconfig.h Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 08/38] MIPS: SGI-IP27: add the Bedrock hub register windows Imre Kaloz
                   ` (30 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

A Bedrock node owns twice the address space a Hub node does, putting
the nasid one bit higher. Take the shift and the node size from the
generation detected at boot; head.S runs before that and keeps Hub's
values.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/sn/addrs.h     | 12 +++++++++++-
 arch/mips/include/asm/sn/sn0/addrs.h |  8 ++++----
 arch/mips/include/asm/sn/sn1/addrs.h | 22 ++++++++++++++++++++++
 3 files changed, 37 insertions(+), 5 deletions(-)
 create mode 100644 arch/mips/include/asm/sn/sn1/addrs.h

diff --git a/arch/mips/include/asm/sn/addrs.h b/arch/mips/include/asm/sn/addrs.h
index 51161fd5130b..499615abd501 100644
--- a/arch/mips/include/asm/sn/addrs.h
+++ b/arch/mips/include/asm/sn/addrs.h
@@ -20,7 +20,6 @@
 
 #if defined(CONFIG_SGI_IP27)
 #include <asm/sn/sn0/addrs.h>
-#elif defined(CONFIG_SGI_IP35)
 #include <asm/sn/sn1/addrs.h>
 #endif
 
@@ -39,6 +38,17 @@
 
 extern bool system_is_ip35;
 
+#define NASID_SHFT		(system_is_ip35 ? SN1_NASID_SHFT :	\
+				 SN0_NASID_SHFT)
+#define NODE_SIZE_BITS		(system_is_ip35 ? SN1_NODE_SIZE_BITS :	\
+				 SN0_NODE_SIZE_BITS)
+
+#else /* __ASSEMBLER__ */
+
+/* The entry paths run before prom_init() reads the hub's part number. */
+#define NASID_SHFT		SN0_NASID_SHFT
+#define NODE_SIZE_BITS		SN0_NODE_SIZE_BITS
+
 #endif /* __ASSEMBLER__ */
 
 
diff --git a/arch/mips/include/asm/sn/sn0/addrs.h b/arch/mips/include/asm/sn/sn0/addrs.h
index a28158a91ecf..f1a161913ae4 100644
--- a/arch/mips/include/asm/sn/sn0/addrs.h
+++ b/arch/mips/include/asm/sn/sn0/addrs.h
@@ -50,12 +50,12 @@
 
 #ifdef CONFIG_SGI_SN_N_MODE
 
-#define NODE_SIZE_BITS		31
+#define SN0_NODE_SIZE_BITS	31
 #define BWIN_SIZE_BITS		28
 
 #define NASID_BITS		9
 #define NASID_BITMASK		(0x1ffLL)
-#define NASID_SHFT		31
+#define SN0_NASID_SHFT		31
 #define NASID_META_BITS		5
 #define NASID_LOCAL_BITS	4
 
@@ -64,12 +64,12 @@
 
 #else /* !defined(CONFIG_SGI_SN_N_MODE), assume that M-mode is desired */
 
-#define NODE_SIZE_BITS		32
+#define SN0_NODE_SIZE_BITS	32
 #define BWIN_SIZE_BITS		29
 
 #define NASID_BITMASK		(0xffLL)
 #define NASID_BITS		8
-#define NASID_SHFT		32
+#define SN0_NASID_SHFT		32
 #define NASID_META_BITS		4
 #define NASID_LOCAL_BITS	4
 
diff --git a/arch/mips/include/asm/sn/sn1/addrs.h b/arch/mips/include/asm/sn/sn1/addrs.h
new file mode 100644
index 000000000000..58878a5b4710
--- /dev/null
+++ b/arch/mips/include/asm/sn/sn1/addrs.h
@@ -0,0 +1,22 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+/*
+ * SN1 (Bedrock) address space layout.
+ *
+ * Copyright (C) 2026 Imre Kaloz <kaloz@kernel.org>
+ */
+#ifndef _ASM_SN_SN1_ADDRS_H
+#define _ASM_SN_SN1_ADDRS_H
+
+#ifdef CONFIG_SGI_SN_N_MODE
+
+#define SN1_NODE_SIZE_BITS	32
+#define SN1_NASID_SHFT		32
+
+#else /* !defined(CONFIG_SGI_SN_N_MODE), assume that M-mode is desired */
+
+#define SN1_NODE_SIZE_BITS	33
+#define SN1_NASID_SHFT		33
+
+#endif /* !defined(CONFIG_SGI_SN_N_MODE) */
+
+#endif /* _ASM_SN_SN1_ADDRS_H */
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 08/38] MIPS: SGI-IP27: add the Bedrock hub register windows
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (6 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 07/38] MIPS: SGI-IP27: choose the node address layout at runtime Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 09/38] MIPS: SGI-IP27: decode a Bedrock hub's node id and system size Imre Kaloz
                   ` (29 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

Bedrock places its hub register blocks at different offsets than Hub
does. Add a header for them and include it next to the Hub one, since
one kernel has to reach either generation's blocks.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/sn/agent.h   |  3 +--
 arch/mips/include/asm/sn/sn1/hub.h | 15 +++++++++++++++
 2 files changed, 16 insertions(+), 2 deletions(-)
 create mode 100644 arch/mips/include/asm/sn/sn1/hub.h

diff --git a/arch/mips/include/asm/sn/agent.h b/arch/mips/include/asm/sn/agent.h
index 7e9b3271737a..8873eb34e31b 100644
--- a/arch/mips/include/asm/sn/agent.h
+++ b/arch/mips/include/asm/sn/agent.h
@@ -16,9 +16,8 @@
 
 #if defined(CONFIG_SGI_IP27)
 #include <asm/sn/sn0/hub.h>
-#elif defined(CONFIG_SGI_IP35)
 #include <asm/sn/sn1/hub.h>
-#endif	/* !CONFIG_SGI_IP27 && !CONFIG_SGI_IP35 */
+#endif /* CONFIG_SGI_IP27 */
 
 /*
  * NIC register macros
diff --git a/arch/mips/include/asm/sn/sn1/hub.h b/arch/mips/include/asm/sn/sn1/hub.h
new file mode 100644
index 000000000000..db41bcb3d34a
--- /dev/null
+++ b/arch/mips/include/asm/sn/sn1/hub.h
@@ -0,0 +1,15 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+/*
+ * SN1 (Bedrock) hub register windows.
+ *
+ * Copyright (C) 2026 Imre Kaloz <kaloz@kernel.org>
+ */
+#ifndef _ASM_SN_SN1_HUB_H
+#define _ASM_SN_SN1_HUB_H
+
+#define HUBLBBASE_IP35		0x00600000
+#define HUBNIBASE_IP35		0x00680000
+#define HUBXBBASE_IP35		0x00700000
+#define HUBMDBASE_IP35		0x00780000
+
+#endif /* _ASM_SN_SN1_HUB_H */
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 09/38] MIPS: SGI-IP27: decode a Bedrock hub's node id and system size
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (7 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 08/38] MIPS: SGI-IP27: add the Bedrock hub register windows Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 10/38] MIPS: SGI-IP27: put a Bedrock hub's boot CPU in slot 0 Imre Kaloz
                   ` (28 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

Bedrock's LB_REV_ID holds the node id in bits 39:32 and the system
size, which sets N mode and the region size, in bits 47:46. Decode
both by hub generation; the assembly form, built only for
MAPPED_KERNEL, keys on the widget ID.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 .../include/asm/mach-ip27/kernel-entry-init.h |  8 +++-
 arch/mips/include/asm/sn/agent.h              |  2 +-
 arch/mips/include/asm/sn/sn0/hub.h            | 37 +++++++++++++++++--
 arch/mips/include/asm/sn/sn0/hubni.h          |  3 ++
 arch/mips/include/asm/sn/sn1/hub.h            | 14 +++++++
 arch/mips/include/asm/xtalk/xwidget.h         |  2 +-
 arch/mips/sgi-ip27/ip27-init.c                |  6 ++-
 7 files changed, 63 insertions(+), 9 deletions(-)

diff --git a/arch/mips/include/asm/mach-ip27/kernel-entry-init.h b/arch/mips/include/asm/mach-ip27/kernel-entry-init.h
index 3e54f605a70b..cd50e6d3d966 100644
--- a/arch/mips/include/asm/mach-ip27/kernel-entry-init.h
+++ b/arch/mips/include/asm/mach-ip27/kernel-entry-init.h
@@ -65,8 +65,10 @@
  * arch/mips/mach-xxx/kernel-entry-init.h when necessary.
  */
 	.macro	kernel_entry_setup
-	GET_NASID_ASM	t1
+#ifdef CONFIG_MAPPED_KERNEL
+	GET_NASID_ASM	t1, t0
 	move		t2, t1			# text and data are here
+#endif
 	MAPPED_KERNEL_SETUP_TLB
 	.endm
 
@@ -74,7 +76,8 @@
  * Do SMP slave processor setup necessary before we can safely execute C code.
  */
 	.macro	smp_slave_setup
-	GET_NASID_ASM	t1
+#ifdef CONFIG_MAPPED_KERNEL
+	GET_NASID_ASM	t1, t0
 	dli	t0, KLDIR_OFFSET + (KLI_KERN_VARS * KLDIR_ENT_SIZE) + \
 		    KLDIR_OFF_POINTER + CAC_BASE
 	dsll	t1, NASID_SHFT
@@ -82,6 +85,7 @@
 	ld	t0, 0(t0)			# t0 points to kern_vars struct
 	lh	t1, KV_RO_NASID_OFFSET(t0)
 	lh	t2, KV_RW_NASID_OFFSET(t0)
+#endif
 	MAPPED_KERNEL_SETUP_TLB
 
 	/*
diff --git a/arch/mips/include/asm/sn/agent.h b/arch/mips/include/asm/sn/agent.h
index 8873eb34e31b..1d6d0cd5e5fd 100644
--- a/arch/mips/include/asm/sn/agent.h
+++ b/arch/mips/include/asm/sn/agent.h
@@ -15,8 +15,8 @@
 #include <asm/sn/arch.h>
 
 #if defined(CONFIG_SGI_IP27)
-#include <asm/sn/sn0/hub.h>
 #include <asm/sn/sn1/hub.h>
+#include <asm/sn/sn0/hub.h>
 #endif /* CONFIG_SGI_IP27 */
 
 /*
diff --git a/arch/mips/include/asm/sn/sn0/hub.h b/arch/mips/include/asm/sn/sn0/hub.h
index 916394319af5..c5429dbddc7a 100644
--- a/arch/mips/include/asm/sn/sn0/hub.h
+++ b/arch/mips/include/asm/sn/sn0/hub.h
@@ -31,6 +31,8 @@
 #include <asm/sn/sn0/hubni.h>
 //#include <asm/sn/sn0/hubcore.h>
 
+#include <asm/xtalk/xwidget.h>
+
 /* Translation of uncached attributes */
 #define UATTR_HSPEC	0
 #define UATTR_IO	1
@@ -39,13 +41,35 @@
 
 #ifdef __ASSEMBLER__
 /*
- * Returns the local nasid into res.
+ * Clears tmp on a Bedrock hub.  Nothing has read the hub's part number
+ * this early, so take it from the widget ID.
  */
-	.macro GET_NASID_ASM res
+	.macro GET_HUB_GEN_ASM tmp
+	dli	\tmp, LOCAL_HUB_ADDR(IIO_WID)
+	ld	\tmp, (\tmp)
+	dsrl	\tmp, WIDGET_PART_NUM_SHFT
+	andi	\tmp, (WIDGET_PART_NUM >> WIDGET_PART_NUM_SHFT)
+	xori	\tmp, WIDGET_BDRCK_PART_NUM
+	.endm
+
+/*
+ * Returns the local nasid into res, clobbering tmp.
+ */
+	.macro GET_NASID_ASM res, tmp
+	.set	push
+	.set	reorder
+	GET_HUB_GEN_ASM \tmp
 	dli	\res, LOCAL_HUB_ADDR(NI_STATUS_REV_ID)
 	ld	\res, (\res)
+	beqz	\tmp, 1f
 	and	\res, NSRI_NODEID_MASK
 	dsrl	\res, NSRI_NODEID_SHFT
+	b	2f
+1:
+	dsrl	\res, LRI_NODEID_SHFT_IP35
+	andi	\res, LRI_NODEID_MASK_IP35
+2:
+	.set	pop
 	.endm
 #else
 
@@ -54,8 +78,13 @@
  */
 static inline nasid_t get_nasid(void)
 {
-	return (nasid_t)((LOCAL_HUB_L(NI_STATUS_REV_ID) & NSRI_NODEID_MASK)
-			 >> NSRI_NODEID_SHFT);
+	u64 id = LOCAL_HUB_L(NI_STATUS_REV_ID);
+
+	if (system_is_ip35)
+		return (nasid_t)((id >> LRI_NODEID_SHFT_IP35) &
+				 LRI_NODEID_MASK_IP35);
+
+	return (nasid_t)((id & NSRI_NODEID_MASK) >> NSRI_NODEID_SHFT);
 }
 #endif
 
diff --git a/arch/mips/include/asm/sn/sn0/hubni.h b/arch/mips/include/asm/sn/sn0/hubni.h
index 4830bae723e4..ff7df5e27f66 100644
--- a/arch/mips/include/asm/sn/sn0/hubni.h
+++ b/arch/mips/include/asm/sn/sn0/hubni.h
@@ -252,6 +252,9 @@ typedef union	hubni_port_error_u {
 
 static inline int get_region_shift(void)
 {
+	if (system_is_ip35)
+		return LRI_SYSTEM_SIZE_IP35(LOCAL_HUB_L(NI_STATUS_REV_ID));
+
 	if (LOCAL_HUB_L(NI_STATUS_REV_ID) & NSRI_REGIONSIZE_MASK)
 		return NASID_TO_FINEREG_SHFT;
 
diff --git a/arch/mips/include/asm/sn/sn1/hub.h b/arch/mips/include/asm/sn/sn1/hub.h
index db41bcb3d34a..71ccd2ba3698 100644
--- a/arch/mips/include/asm/sn/sn1/hub.h
+++ b/arch/mips/include/asm/sn/sn1/hub.h
@@ -12,4 +12,18 @@
 #define HUBXBBASE_IP35		0x00700000
 #define HUBMDBASE_IP35		0x00780000
 
+/*
+ * LB_REV_ID, at the base of the LB block and so at Hub's NI_STATUS_REV_ID
+ * offset, holds the node id in bits 39:32.
+ */
+#define LRI_NODEID_SHFT_IP35	32
+#define LRI_NODEID_MASK_IP35	0xff
+
+/*
+ * Bits 47:46 give the system size: 0, 1 or 2 is log2 of the nodes per
+ * region, and 2 is N mode.
+ */
+#define LRI_SYSTEM_SIZE_IP35(id)	(((id) >> 46) & 0x3)
+#define LRI_SYSTEM_SIZE_NMODE_IP35	2
+
 #endif /* _ASM_SN_SN1_HUB_H */
diff --git a/arch/mips/include/asm/xtalk/xwidget.h b/arch/mips/include/asm/xtalk/xwidget.h
index 6dae5d9628f7..978877e8a090 100644
--- a/arch/mips/include/asm/xtalk/xwidget.h
+++ b/arch/mips/include/asm/xtalk/xwidget.h
@@ -122,7 +122,7 @@ struct widget_ident {
 };
 
 /* Known Xtalk Widgets */
-static const struct widget_ident __initconst widget_idents[] = {
+static const struct widget_ident widget_idents[] __initconst __maybe_unused = {
 	{
 		WIDGET_XBOW_MFGR_NUM,
 		WIDGET_XBOW_PART_NUM,
diff --git a/arch/mips/sgi-ip27/ip27-init.c b/arch/mips/sgi-ip27/ip27-init.c
index 6394c2076041..108d90908763 100644
--- a/arch/mips/sgi-ip27/ip27-init.c
+++ b/arch/mips/sgi-ip27/ip27-init.c
@@ -121,7 +121,11 @@ void __init plat_mem_setup(void)
 	 * Try to catch kernel missconfigurations and give user an
 	 * indication what option to select.
 	 */
-	n_mode = LOCAL_HUB_L(NI_STATUS_REV_ID) & NSRI_MORENODES_MASK;
+	if (system_is_ip35)
+		n_mode = LRI_SYSTEM_SIZE_IP35(LOCAL_HUB_L(NI_STATUS_REV_ID)) ==
+			 LRI_SYSTEM_SIZE_NMODE_IP35;
+	else
+		n_mode = LOCAL_HUB_L(NI_STATUS_REV_ID) & NSRI_MORENODES_MASK;
 	printk("Machine is in %c mode.\n", n_mode ? 'N' : 'M');
 #ifdef CONFIG_SGI_SN_N_MODE
 	if (!n_mode)
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 10/38] MIPS: SGI-IP27: put a Bedrock hub's boot CPU in slot 0
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (8 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 09/38] MIPS: SGI-IP27: decode a Bedrock hub's node id and system size Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 11/38] MIPS: SGI-IP27: lay out node memory in 1GB banks on Bedrock hubs Imre Kaloz
                   ` (27 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

ip27_smp_setup() takes CPU 0 to be the boot CPU. On a Bedrock hub, find
the boot CPU's sn_cpu_info[] entry by its nasid and PI_CPU_NUM slice and
swap it into slot 0. The PROM's virtids, which set the possible mask, run
densely from 0 in board-list order and so match the table's slots.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-smp.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/arch/mips/sgi-ip27/ip27-smp.c b/arch/mips/sgi-ip27/ip27-smp.c
index 62733e049570..159dbd6ddda8 100644
--- a/arch/mips/sgi-ip27/ip27-smp.c
+++ b/arch/mips/sgi-ip27/ip27-smp.c
@@ -80,6 +80,15 @@ void cpu_node_probe(void)
 		highest = node_scan_cpus(nasid, highest);
 	}
 
+	/* The boot CPU must be CPU 0 wherever the board list puts it. */
+	for (i = 1; system_is_ip35 && i <= highest; i++) {
+		if (cputonasid(i) == master_nasid &&
+		    cputoslice(i) == LOCAL_HUB_L(PI_CPU_NUM)) {
+			swap(sn_cpu_info[0], sn_cpu_info[i]);
+			break;
+		}
+	}
+
 	printk("Discovered %d cpus on %d nodes\n", highest + 1, num_online_nodes());
 }
 
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 11/38] MIPS: SGI-IP27: lay out node memory in 1GB banks on Bedrock hubs
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (9 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 10/38] MIPS: SGI-IP27: put a Bedrock hub's boot CPU in slot 0 Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 12/38] MIPS: SGI-IP27: reserve the bottom 64MB of node 0 " Imre Kaloz
                   ` (26 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

Hub describes a node's memory as 128MB slots, four slots to a
klconfig bank entry. Bedrock gives each bank entry a 1GB slot of its
own and sizes it in megabytes. Take the slot shift, the slot count and
the bank size from the hub generation.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-memory.c | 25 ++++++++++++++++++++-----
 1 file changed, 20 insertions(+), 5 deletions(-)

diff --git a/arch/mips/sgi-ip27/ip27-memory.c b/arch/mips/sgi-ip27/ip27-memory.c
index 4317f5ae1fd1..0204dc8bb1bb 100644
--- a/arch/mips/sgi-ip27/ip27-memory.c
+++ b/arch/mips/sgi-ip27/ip27-memory.c
@@ -31,9 +31,16 @@
 
 #include "ip27-common.h"
 
-#define SLOT_PFNSHIFT		(SLOT_SHIFT - PAGE_SHIFT)
 #define PFN_NASIDSHFT		(NASID_SHFT - PAGE_SHIFT)
 
+/* A Bedrock node's memory comes in 1GB banks. */
+#define BEDROCK_SLOT_SHIFT	30
+
+static unsigned int __init slot_shift(void)
+{
+	return system_is_ip35 ? BEDROCK_SLOT_SHIFT : SLOT_SHIFT;
+}
+
 struct node_data *__node_data[MAX_NUMNODES];
 EXPORT_SYMBOL(__node_data);
 
@@ -230,7 +237,8 @@ static void __init dump_topology(void)
 
 static unsigned long __init slot_getbasepfn(nasid_t nasid, int slot)
 {
-	return ((unsigned long)nasid << PFN_NASIDSHFT) | (slot << SLOT_PFNSHIFT);
+	return ((unsigned long)nasid << PFN_NASIDSHFT) |
+	       ((unsigned long)slot << (slot_shift() - PAGE_SHIFT));
 }
 
 static unsigned long __init slot_psize_compute(nasid_t nasid, int slot)
@@ -249,6 +257,12 @@ static unsigned long __init slot_psize_compute(nasid_t nasid, int slot)
 	if (!banks)
 		return 0;
 
+	/* Bedrock bank entry N sizes the 1GB slot N, in megabytes. */
+	if (system_is_ip35) {
+		size = (unsigned long)banks->membnk_bnksz[slot];
+		return (size << 20) >> PAGE_SHIFT;
+	}
+
 	/* Size in _Megabytes_ */
 	size = (unsigned long)banks->membnk_bnksz[slot/4];
 
@@ -315,12 +329,13 @@ static void __init mlreset(void)
 static void __init szmem(void)
 {
 	unsigned long slot_psize, slot0sz = 0, nodebytes;	/* Hack to detect problem configs */
+	int slots = system_is_ip35 ? MD_MEM_BANKS : MAX_MEM_SLOTS;
 	int slot;
 	nasid_t node;
 
 	for_each_online_node(node) {
 		nodebytes = 0;
-		for (slot = 0; slot < MAX_MEM_SLOTS; slot++) {
+		for (slot = 0; slot < slots; slot++) {
 			slot_psize = slot_psize_compute(node, slot);
 			if (slot == 0)
 				slot0sz = slot_psize;
@@ -328,7 +343,7 @@ static void __init szmem(void)
 			 * We need to refine the hack when we have replicated
 			 * kernel text.
 			 */
-			nodebytes += (1LL << SLOT_SHIFT);
+			nodebytes += (1LL << slot_shift());
 
 			if (!slot_psize)
 				continue;
@@ -337,7 +352,7 @@ static void __init szmem(void)
 						(slot0sz << PAGE_SHIFT)) {
 				pr_info("Ignoring slot %d onwards on node %d\n",
 								slot, node);
-				slot = MAX_MEM_SLOTS;
+				slot = slots;
 				continue;
 			}
 			memblock_add_node(PFN_PHYS(slot_getbasepfn(node, slot)),
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 12/38] MIPS: SGI-IP27: reserve the bottom 64MB of node 0 on Bedrock hubs
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (10 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 11/38] MIPS: SGI-IP27: lay out node memory in 1GB banks on Bedrock hubs Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 13/38] MIPS: SGI-IP27: route interrupt masks and slices through both PIs Imre Kaloz
                   ` (25 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

On Bedrock hubs, reserve the first 64MB of physical memory, the bottom
of node 0, and place node 0's node data above it. node_getfirstfree()
covers only the kernel image, so the area needs a reservation of its
own.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-memory.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/arch/mips/sgi-ip27/ip27-memory.c b/arch/mips/sgi-ip27/ip27-memory.c
index 0204dc8bb1bb..98184dfcd8c5 100644
--- a/arch/mips/sgi-ip27/ip27-memory.c
+++ b/arch/mips/sgi-ip27/ip27-memory.c
@@ -17,6 +17,7 @@
 #include <linux/mmzone.h>
 #include <linux/export.h>
 #include <linux/nodemask.h>
+#include <linux/sizes.h>
 #include <linux/swap.h>
 #include <linux/pfn.h>
 #include <linux/highmem.h>
@@ -36,6 +37,9 @@
 /* A Bedrock node's memory comes in 1GB banks. */
 #define BEDROCK_SLOT_SHIFT	30
 
+/* Reserved at the bottom of node 0, which starts at physical 0. */
+#define BEDROCK_RSVD_SIZE	SZ_64M
+
 static unsigned int __init slot_shift(void)
 {
 	return system_is_ip35 ? BEDROCK_SLOT_SHIFT : SLOT_SHIFT;
@@ -370,6 +374,10 @@ static void __init node_mem_init(nasid_t node)
 
 	get_pfn_range_for_nid(node, &start_pfn, &end_pfn);
 
+	/* Keep the node data above the reserved area. */
+	if (system_is_ip35 && node == 0)
+		slot_freepfn = max(slot_freepfn, PFN_UP(BEDROCK_RSVD_SIZE));
+
 	/*
 	 * Allocate the node data structures on the node first.
 	 */
@@ -410,6 +418,10 @@ void __init prom_meminit(void)
 
 	mlreset();
 	szmem();
+
+	if (system_is_ip35)
+		memblock_reserve(0, BEDROCK_RSVD_SIZE);
+
 	max_low_pfn = PHYS_PFN(memblock_end_of_DRAM());
 
 	for (node = 0; node < MAX_NUMNODES; node++) {
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 13/38] MIPS: SGI-IP27: route interrupt masks and slices through both PIs
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (11 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 12/38] MIPS: SGI-IP27: reserve the bottom 64MB of node 0 " Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 14/38] MIPS: SGI-IP27: address a CPU's own PI for NMI, IPI and RT counter Imre Kaloz
                   ` (24 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

cputoslice() and PI_CPU_NUM return a physid, 0-3 across a Bedrock hub's
two PIs, where a Hub has a plain A/B bit. Add helpers splitting it into
A/B slot and PI block, and give every remote access the slice's PI
block. Local accesses already reach the running CPU's own PI.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/sn/arch.h |  8 ++++++++
 arch/mips/include/asm/sn/intr.h | 10 ++++++----
 arch/mips/sgi-ip27/ip27-berr.c  |  4 ++--
 arch/mips/sgi-ip27/ip27-irq.c   | 17 +++++++++--------
 arch/mips/sgi-ip27/ip27-smp.c   | 16 +++++++++-------
 arch/mips/sgi-ip27/ip27-timer.c |  4 ++--
 6 files changed, 36 insertions(+), 23 deletions(-)

diff --git a/arch/mips/include/asm/sn/arch.h b/arch/mips/include/asm/sn/arch.h
index 9a9682543e89..602219f98b04 100644
--- a/arch/mips/include/asm/sn/arch.h
+++ b/arch/mips/include/asm/sn/arch.h
@@ -18,7 +18,15 @@
 #endif
 
 #define cputonasid(cpu)		(sn_cpu_info[(cpu)].p_nasid)
+/*
+ * The slice is the CPU's physid: on a Bedrock hub 0-3 across two PI blocks,
+ * bit 0 selecting a PI's A/B register slot and bit 1 the PI block.
+ */
 #define cputoslice(cpu)		(sn_cpu_info[(cpu)].p_slice)
+#define slicetoab(slice)	((slice) & 1)
+#define slicetosubnode(slice)	(((slice) >> 1) & 1)
+#define cputoab(cpu)		slicetoab(cputoslice(cpu))
+#define cputosubnode(cpu)	slicetosubnode(cputoslice(cpu))
 
 #define INVALID_NASID		(nasid_t)-1
 #define INVALID_PNODEID		(pnodeid_t)-1
diff --git a/arch/mips/include/asm/sn/intr.h b/arch/mips/include/asm/sn/intr.h
index 3d6954d370dc..90b613f68623 100644
--- a/arch/mips/include/asm/sn/intr.h
+++ b/arch/mips/include/asm/sn/intr.h
@@ -29,13 +29,15 @@ do {								\
 	LOCAL_HUB_L(PI_INT_PEND0);				\
 } while (0);
 
-#define REMOTE_HUB_CLR_INTR(hub, level)				\
+/* An interrupt is pending in the PI block of the CPU it is routed to. */
+#define REMOTE_HUB_PI_CLR_INTR(hub, sn, level)			\
 do {								\
 	nasid_t	 __hub = (hub);					\
+	int __sn = (sn);					\
 								\
-	REMOTE_HUB_S(__hub, PI_INT_PEND_MOD, (level));		\
-	REMOTE_HUB_L(__hub, PI_INT_PEND0);			\
-} while (0);
+	REMOTE_HUB_PI_S(__hub, __sn, PI_INT_PEND_MOD, (level));	\
+	REMOTE_HUB_PI_L(__hub, __sn, PI_INT_PEND0);		\
+} while (0)
 
 /*
  * Hard-coded interrupt levels:
diff --git a/arch/mips/sgi-ip27/ip27-berr.c b/arch/mips/sgi-ip27/ip27-berr.c
index 9eb497cb5d52..b176856aa77c 100644
--- a/arch/mips/sgi-ip27/ip27-berr.c
+++ b/arch/mips/sgi-ip27/ip27-berr.c
@@ -63,7 +63,7 @@ static int ip27_be_handler(struct pt_regs *regs, int is_fixup)
 {
 	unsigned long errst0, errst1;
 	int data = regs->cp0_cause & 4;
-	int cpu = LOCAL_HUB_L(PI_CPU_NUM);
+	int cpu = slicetoab(LOCAL_HUB_L(PI_CPU_NUM));
 
 	if (is_fixup)
 		return MIPS_BE_FIXUP;
@@ -84,7 +84,7 @@ static int ip27_be_handler(struct pt_regs *regs, int is_fixup)
 void __init ip27_be_init(void)
 {
 	/* XXX Initialize all the Hub & Bridge error handling here.  */
-	int cpu = LOCAL_HUB_L(PI_CPU_NUM);
+	int cpu = slicetoab(LOCAL_HUB_L(PI_CPU_NUM));
 	int cpuoff = cpu << 8;
 
 	mips_set_be_handler(ip27_be_handler);
diff --git a/arch/mips/sgi-ip27/ip27-irq.c b/arch/mips/sgi-ip27/ip27-irq.c
index 7e5aa04c6695..02a49bb8529d 100644
--- a/arch/mips/sgi-ip27/ip27-irq.c
+++ b/arch/mips/sgi-ip27/ip27-irq.c
@@ -72,7 +72,7 @@ static void disable_hub_irq(struct irq_data *d)
 static void setup_hub_mask(struct hub_irq_data *hd, const struct cpumask *mask)
 {
 	nasid_t nasid;
-	int cpu;
+	int cpu, sn;
 
 	cpu = cpumask_first_and(mask, cpu_online_mask);
 	if (cpu >= nr_cpu_ids)
@@ -80,12 +80,13 @@ static void setup_hub_mask(struct hub_irq_data *hd, const struct cpumask *mask)
 
 	nasid = cpu_to_node(cpu);
 	hd->cpu = cpu;
-	if (!cputoslice(cpu)) {
-		hd->irq_mask[0] = REMOTE_HUB_PTR(nasid, PI_INT_MASK0_A);
-		hd->irq_mask[1] = REMOTE_HUB_PTR(nasid, PI_INT_MASK1_A);
+	sn = cputosubnode(cpu);
+	if (!cputoab(cpu)) {
+		hd->irq_mask[0] = REMOTE_HUB_PI_PTR(nasid, sn, PI_INT_MASK0_A);
+		hd->irq_mask[1] = REMOTE_HUB_PI_PTR(nasid, sn, PI_INT_MASK1_A);
 	} else {
-		hd->irq_mask[0] = REMOTE_HUB_PTR(nasid, PI_INT_MASK0_B);
-		hd->irq_mask[1] = REMOTE_HUB_PTR(nasid, PI_INT_MASK1_B);
+		hd->irq_mask[0] = REMOTE_HUB_PI_PTR(nasid, sn, PI_INT_MASK0_B);
+		hd->irq_mask[1] = REMOTE_HUB_PI_PTR(nasid, sn, PI_INT_MASK1_B);
 	}
 }
 
@@ -147,7 +148,7 @@ static int hub_domain_alloc(struct irq_domain *domain, unsigned int virq,
 	info->nasid = cpu_to_node(hd->cpu);
 
 	/* Make sure it's not already pending when we connect it. */
-	REMOTE_HUB_CLR_INTR(info->nasid, swlevel);
+	REMOTE_HUB_PI_CLR_INTR(info->nasid, cputosubnode(hd->cpu), swlevel);
 
 	desc = irq_to_desc(virq);
 	desc->irq_common_data.node = info->nasid;
@@ -253,7 +254,7 @@ void install_ipi(void)
 {
 	int cpu = smp_processor_id();
 	unsigned long *mask = per_cpu(irq_enable_mask, cpu);
-	int slice = LOCAL_HUB_L(PI_CPU_NUM);
+	int slice = slicetoab(LOCAL_HUB_L(PI_CPU_NUM));
 	int resched, call;
 
 	resched = CPU_RESCHED_A_IRQ + slice;
diff --git a/arch/mips/sgi-ip27/ip27-smp.c b/arch/mips/sgi-ip27/ip27-smp.c
index 159dbd6ddda8..ac960023d334 100644
--- a/arch/mips/sgi-ip27/ip27-smp.c
+++ b/arch/mips/sgi-ip27/ip27-smp.c
@@ -94,15 +94,17 @@ void cpu_node_probe(void)
 
 static __init void intr_clear_all(nasid_t nasid)
 {
-	int i;
+	int i, sn, pis = system_is_ip35 ? 2 : 1;
 
-	REMOTE_HUB_S(nasid, PI_INT_MASK0_A, 0);
-	REMOTE_HUB_S(nasid, PI_INT_MASK0_B, 0);
-	REMOTE_HUB_S(nasid, PI_INT_MASK1_A, 0);
-	REMOTE_HUB_S(nasid, PI_INT_MASK1_B, 0);
+	for (sn = 0; sn < pis; sn++) {
+		REMOTE_HUB_PI_S(nasid, sn, PI_INT_MASK0_A, 0);
+		REMOTE_HUB_PI_S(nasid, sn, PI_INT_MASK0_B, 0);
+		REMOTE_HUB_PI_S(nasid, sn, PI_INT_MASK1_A, 0);
+		REMOTE_HUB_PI_S(nasid, sn, PI_INT_MASK1_B, 0);
 
-	for (i = 0; i < 128; i++)
-		REMOTE_HUB_CLR_INTR(nasid, i);
+		for (i = 0; i < 128; i++)
+			REMOTE_HUB_PI_CLR_INTR(nasid, sn, i);
+	}
 }
 
 static void ip27_send_ipi_single(int destid, unsigned int action)
diff --git a/arch/mips/sgi-ip27/ip27-timer.c b/arch/mips/sgi-ip27/ip27-timer.c
index 5f4da05cb2c9..aee14a7aad8a 100644
--- a/arch/mips/sgi-ip27/ip27-timer.c
+++ b/arch/mips/sgi-ip27/ip27-timer.c
@@ -30,7 +30,7 @@
 static int rt_next_event(unsigned long delta, struct clock_event_device *evt)
 {
 	unsigned int cpu = smp_processor_id();
-	int slice = cputoslice(cpu);
+	int slice = cputoab(cpu);
 	unsigned long cnt;
 
 	cnt = LOCAL_HUB_L(PI_RT_COUNT);
@@ -47,7 +47,7 @@ static irqreturn_t hub_rt_counter_handler(int irq, void *dev_id)
 {
 	unsigned int cpu = smp_processor_id();
 	struct clock_event_device *cd = &per_cpu(hub_rt_clockevent, cpu);
-	int slice = cputoslice(cpu);
+	int slice = cputoab(cpu);
 
 	/*
 	 * Ack
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 14/38] MIPS: SGI-IP27: address a CPU's own PI for NMI, IPI and RT counter
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (12 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 13/38] MIPS: SGI-IP27: route interrupt masks and slices through both PIs Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 15/38] MIPS: SGI-IP27: take a CPU's node from the CPU table in per_cpu_init() Imre Kaloz
                   ` (23 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

REMOTE_HUB_SEND_INTR(), SEND_NMI() and nmi_dump_hub_irq() reach the first
PI only; address a CPU's own PI. Call hub_rtc_init() once per PI; its
LOCAL_HUB writes reach the calling CPU's own PI. Read the clocksource from
the boot CPU's PI and enable the Bedrock NI reset for NMI.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/sn/intr.h      |  4 +--
 arch/mips/include/asm/sn/kldir.h     |  1 +
 arch/mips/include/asm/sn/sn1/hub.h   | 11 ++++++++
 arch/mips/include/asm/sn/sn1/kldir.h | 14 ++++++++++
 arch/mips/sgi-ip27/ip27-init.c       | 14 +++++++---
 arch/mips/sgi-ip27/ip27-nmi.c        | 38 +++++++++++++++++++---------
 arch/mips/sgi-ip27/ip27-smp.c        |  4 +--
 arch/mips/sgi-ip27/ip27-timer.c      |  8 ++++--
 8 files changed, 73 insertions(+), 21 deletions(-)
 create mode 100644 arch/mips/include/asm/sn/sn1/kldir.h

diff --git a/arch/mips/include/asm/sn/intr.h b/arch/mips/include/asm/sn/intr.h
index 90b613f68623..4927232fafc3 100644
--- a/arch/mips/include/asm/sn/intr.h
+++ b/arch/mips/include/asm/sn/intr.h
@@ -14,8 +14,8 @@
 
 #define LOCAL_HUB_SEND_INTR(level)				\
 	LOCAL_HUB_S(PI_INT_PEND_MOD, (0x100 | (level)))
-#define REMOTE_HUB_SEND_INTR(hub, level)			\
-	REMOTE_HUB_S((hub), PI_INT_PEND_MOD, (0x100 | (level)))
+#define REMOTE_HUB_PI_SEND_INTR(hub, sn, level)			\
+	REMOTE_HUB_PI_S((hub), (sn), PI_INT_PEND_MOD, (0x100 | (level)))
 
 /*
  * When clearing the interrupt, make sure this clear does make it
diff --git a/arch/mips/include/asm/sn/kldir.h b/arch/mips/include/asm/sn/kldir.h
index f394b1e0c956..23999dd43eb2 100644
--- a/arch/mips/include/asm/sn/kldir.h
+++ b/arch/mips/include/asm/sn/kldir.h
@@ -31,6 +31,7 @@ typedef struct kldir_ent_s {
 
 #ifdef CONFIG_SGI_IP27
 #include <asm/sn/sn0/kldir.h>
+#include <asm/sn/sn1/kldir.h>
 #endif
 
 #endif /* _ASM_SN_KLDIR_H */
diff --git a/arch/mips/include/asm/sn/sn1/hub.h b/arch/mips/include/asm/sn/sn1/hub.h
index 71ccd2ba3698..60e0f249852f 100644
--- a/arch/mips/include/asm/sn/sn1/hub.h
+++ b/arch/mips/include/asm/sn/sn1/hub.h
@@ -26,4 +26,15 @@
 #define LRI_SYSTEM_SIZE_IP35(id)	(((id) >> 46) & 0x3)
 #define LRI_SYSTEM_SIZE_NMODE_IP35	2
 
+/*
+ * Network interface port reset: bit 0 sends a link reset, bit 2 resets
+ * the local Bedrock.  Bit 0 of the reset enable register lets a reset
+ * arriving over the link reset this Bedrock.
+ */
+#define NI_PORT_RESET_IP35	(HUBNIBASE_IP35 + 0x000008)
+#define NI_RESET_ACTION_IP35	0x01
+#define NI_RESET_LOCAL_IP35	0x04
+#define NI_RESET_ENABLE_IP35	(HUBNIBASE_IP35 + 0x000010)
+#define NI_RESET_OK_IP35	0x01
+
 #endif /* _ASM_SN_SN1_HUB_H */
diff --git a/arch/mips/include/asm/sn/sn1/kldir.h b/arch/mips/include/asm/sn/sn1/kldir.h
new file mode 100644
index 000000000000..c95dccb3ce55
--- /dev/null
+++ b/arch/mips/include/asm/sn/sn1/kldir.h
@@ -0,0 +1,14 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+/*
+ * SN1 (Bedrock) kldir constants.
+ *
+ * Copyright (C) 2026 Imre Kaloz <kaloz@kernel.org>
+ */
+#ifndef _ASM_SN_SN1_KLDIR_H
+#define _ASM_SN_SN1_KLDIR_H
+
+/* Save area of kernel NMI regs in the PROM format. */
+#define IP35_NMI_KREGS_OFFSET		0x9000
+#define IP35_NMI_KREGS_CPU_SIZE	0x400
+
+#endif /* _ASM_SN_SN1_KLDIR_H */
diff --git a/arch/mips/sgi-ip27/ip27-init.c b/arch/mips/sgi-ip27/ip27-init.c
index 108d90908763..88d79c50d9a7 100644
--- a/arch/mips/sgi-ip27/ip27-init.c
+++ b/arch/mips/sgi-ip27/ip27-init.c
@@ -37,7 +37,11 @@
 
 #define CPU_NONE		(cpuid_t)-1
 
+/* A Bedrock hub has two PI register blocks; a Hub has one. */
+#define PIS_PER_HUB		2
+
 static DECLARE_BITMAP(hub_init_mask, MAX_NUMNODES);
+static DECLARE_BITMAP(pi_init_mask, MAX_NUMNODES * PIS_PER_HUB);
 nasid_t master_nasid = INVALID_NASID;
 bool system_is_ip35;
 
@@ -46,9 +50,15 @@ EXPORT_SYMBOL_GPL(sn_cpu_info);
 
 static void per_hub_init(nasid_t nasid)
 {
+	int cpu = smp_processor_id();
 	struct hub_data *hub = hub_data(nasid);
+	int subnode = cputosubnode(cpu);
 
-	cpumask_set_cpu(smp_processor_id(), &hub->h_cpus);
+	cpumask_set_cpu(cpu, &hub->h_cpus);
+
+	/* A second pass would zero the counter under a CPU already ticking. */
+	if (!test_and_set_bit(nasid * PIS_PER_HUB + subnode, pi_init_mask))
+		hub_rtc_init(nasid);
 
 	if (test_and_set_bit(nasid, hub_init_mask))
 		return;
@@ -58,8 +68,6 @@ static void per_hub_init(nasid_t nasid)
 	REMOTE_HUB_S(nasid, IIO_ICTP, 0x800);
 	REMOTE_HUB_S(nasid, IIO_ICTO, 0xff);
 
-	hub_rtc_init(nasid);
-
 	if (nasid) {
 		/* copy exception handlers from first node to current node */
 		memcpy((void *)NODE_OFFSET_TO_K0(nasid, 0),
diff --git a/arch/mips/sgi-ip27/ip27-nmi.c b/arch/mips/sgi-ip27/ip27-nmi.c
index 07d63d020d22..53875b93cca1 100644
--- a/arch/mips/sgi-ip27/ip27-nmi.c
+++ b/arch/mips/sgi-ip27/ip27-nmi.c
@@ -14,8 +14,9 @@
 
 #include "ip27-common.h"
 
-#define SEND_NMI(_nasid, _slice)	\
-	REMOTE_HUB_S((_nasid),  (PI_NMI_A + ((_slice) * PI_NMI_OFFSET)), 1)
+#define SEND_NMI(_nasid, _slice)					\
+	REMOTE_HUB_PI_S((_nasid), slicetosubnode(_slice),		\
+		(PI_NMI_A + (slicetoab(_slice) * PI_NMI_OFFSET)), 1)
 
 typedef unsigned long machreg_t;
 
@@ -44,12 +45,18 @@ void install_cpu_nmi_handler(int slice)
 static void nmi_cpu_eframe_save(nasid_t nasid, int slice)
 {
 	struct reg_struct *nr;
+	int kregs_offset, kregs_cpu_size;
 	int		i;
 
+	kregs_offset = system_is_ip35 ? IP35_NMI_KREGS_OFFSET :
+					  IP27_NMI_KREGS_OFFSET;
+	kregs_cpu_size = system_is_ip35 ? IP35_NMI_KREGS_CPU_SIZE :
+					    IP27_NMI_KREGS_CPU_SIZE;
+
 	/* Get the pointer to the current cpu's register set. */
 	nr = (struct reg_struct *)
-		(TO_UNCAC(TO_NODE(nasid, IP27_NMI_KREGS_OFFSET)) +
-		slice * IP27_NMI_KREGS_CPU_SIZE);
+		(TO_UNCAC(TO_NODE(nasid, kregs_offset)) +
+		slice * kregs_cpu_size);
 
 	pr_emerg("NMI nasid %d: slice %d\n", nasid, slice);
 
@@ -119,18 +126,19 @@ static void nmi_cpu_eframe_save(nasid_t nasid, int slice)
 
 static void nmi_dump_hub_irq(nasid_t nasid, int slice)
 {
+	int subnode = slicetosubnode(slice);
 	u64 mask0, mask1, pend0, pend1;
 
-	if (slice == 0) {				/* Slice A */
-		mask0 = REMOTE_HUB_L(nasid, PI_INT_MASK0_A);
-		mask1 = REMOTE_HUB_L(nasid, PI_INT_MASK1_A);
+	if (!slicetoab(slice)) {			/* Slice A */
+		mask0 = REMOTE_HUB_PI_L(nasid, subnode, PI_INT_MASK0_A);
+		mask1 = REMOTE_HUB_PI_L(nasid, subnode, PI_INT_MASK1_A);
 	} else {					/* Slice B */
-		mask0 = REMOTE_HUB_L(nasid, PI_INT_MASK0_B);
-		mask1 = REMOTE_HUB_L(nasid, PI_INT_MASK1_B);
+		mask0 = REMOTE_HUB_PI_L(nasid, subnode, PI_INT_MASK0_B);
+		mask1 = REMOTE_HUB_PI_L(nasid, subnode, PI_INT_MASK1_B);
 	}
 
-	pend0 = REMOTE_HUB_L(nasid, PI_INT_PEND0);
-	pend1 = REMOTE_HUB_L(nasid, PI_INT_PEND1);
+	pend0 = REMOTE_HUB_PI_L(nasid, subnode, PI_INT_PEND0);
+	pend1 = REMOTE_HUB_PI_L(nasid, subnode, PI_INT_PEND1);
 
 	pr_emerg("PI_INT_MASK0: %16llx PI_INT_MASK1: %16llx\n", mask0, mask1);
 	pr_emerg("PI_INT_PEND0: %16llx PI_INT_PEND1: %16llx\n", pend0, pend1);
@@ -227,5 +235,11 @@ static void nmi_dump(void)
 	 * Save the nmi cpu registers for all cpu in the eframe format.
 	 */
 	nmi_eframes_save();
-	LOCAL_HUB_S(NI_PORT_RESET, NPR_PORTRESET | NPR_LOCALRESET);
+	if (system_is_ip35) {
+		LOCAL_HUB_S(NI_RESET_ENABLE_IP35, NI_RESET_OK_IP35);
+		LOCAL_HUB_S(NI_PORT_RESET_IP35,
+			    NI_RESET_ACTION_IP35 | NI_RESET_LOCAL_IP35);
+	} else {
+		LOCAL_HUB_S(NI_PORT_RESET, NPR_PORTRESET | NPR_LOCALRESET);
+	}
 }
diff --git a/arch/mips/sgi-ip27/ip27-smp.c b/arch/mips/sgi-ip27/ip27-smp.c
index ac960023d334..fc4d9379a93e 100644
--- a/arch/mips/sgi-ip27/ip27-smp.c
+++ b/arch/mips/sgi-ip27/ip27-smp.c
@@ -122,13 +122,13 @@ static void ip27_send_ipi_single(int destid, unsigned int action)
 		panic("sendintr");
 	}
 
-	irq += cputoslice(destid);
+	irq += cputoab(destid);
 
 	/*
 	 * Set the interrupt bit associated with the CPU we want to
 	 * send the interrupt to.
 	 */
-	REMOTE_HUB_SEND_INTR(cpu_to_node(destid), irq);
+	REMOTE_HUB_PI_SEND_INTR(cpu_to_node(destid), cputosubnode(destid), irq);
 }
 
 static void ip27_send_ipi_mask(const struct cpumask *mask, unsigned int action)
diff --git a/arch/mips/sgi-ip27/ip27-timer.c b/arch/mips/sgi-ip27/ip27-timer.c
index aee14a7aad8a..14df8608b14b 100644
--- a/arch/mips/sgi-ip27/ip27-timer.c
+++ b/arch/mips/sgi-ip27/ip27-timer.c
@@ -100,9 +100,13 @@ static void __init hub_rt_clock_event_global_init(void)
 				   "hub-rt", &hub_rt_clockevent));
 }
 
+/*
+ * Each PI of a Bedrock hub has its own RT counter, zeroed when that PI's
+ * first CPU comes up; the timebase is the boot CPU's.
+ */
 static u64 hub_rt_read(struct clocksource *cs)
 {
-	return REMOTE_HUB_L(cputonasid(0), PI_RT_COUNT);
+	return REMOTE_HUB_PI_L(cputonasid(0), cputosubnode(0), PI_RT_COUNT);
 }
 
 struct clocksource hub_rt_clocksource = {
@@ -115,7 +119,7 @@ struct clocksource hub_rt_clocksource = {
 
 static u64 notrace hub_rt_read_sched_clock(void)
 {
-	return REMOTE_HUB_L(cputonasid(0), PI_RT_COUNT);
+	return REMOTE_HUB_PI_L(cputonasid(0), cputosubnode(0), PI_RT_COUNT);
 }
 
 static void __init hub_rt_clocksource_init(void)
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 15/38] MIPS: SGI-IP27: take a CPU's node from the CPU table in per_cpu_init()
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (13 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 14/38] MIPS: SGI-IP27: address a CPU's own PI for NMI, IPI and RT counter Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 16/38] MIPS: SGI-IP27: resolve the mapped-kernel node shift at runtime Imre Kaloz
                   ` (22 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

cpu_node_probe() records every CPU's node before the first secondary
launches. Take it from there, so a CPU coming up inherits its node from
the boot CPU's scan instead of reading the hub again.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-init.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/mips/sgi-ip27/ip27-init.c b/arch/mips/sgi-ip27/ip27-init.c
index 88d79c50d9a7..15811fb3cdee 100644
--- a/arch/mips/sgi-ip27/ip27-init.c
+++ b/arch/mips/sgi-ip27/ip27-init.c
@@ -81,7 +81,7 @@ static void per_hub_init(nasid_t nasid)
 void per_cpu_init(void)
 {
 	int cpu = smp_processor_id();
-	nasid_t nasid = get_nasid();
+	nasid_t nasid = cputonasid(cpu);
 
 	clear_c0_status(ST0_IM);
 
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 16/38] MIPS: SGI-IP27: resolve the mapped-kernel node shift at runtime
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (14 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 15/38] MIPS: SGI-IP27: take a CPU's node from the CPU table in per_cpu_init() Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 17/38] MIPS: SGI-IP27: load the kernel at node offset 0x40000 Imre Kaloz
                   ` (21 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

A Bedrock hub puts the nasid one bit higher in an address than a Hub
does.  MAPPED_KERNEL_SETUP_TLB builds its wired entry and smp_slave_setup()
reaches the kernel variables before any C runs, so take the shift from
the hub's Crosstalk widget ID.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 .../include/asm/mach-ip27/kernel-entry-init.h | 23 ++++++++++++++++---
 1 file changed, 20 insertions(+), 3 deletions(-)

diff --git a/arch/mips/include/asm/mach-ip27/kernel-entry-init.h b/arch/mips/include/asm/mach-ip27/kernel-entry-init.h
index cd50e6d3d966..1bedd3c3bc58 100644
--- a/arch/mips/include/asm/mach-ip27/kernel-entry-init.h
+++ b/arch/mips/include/asm/mach-ip27/kernel-entry-init.h
@@ -21,6 +21,21 @@
 #define PAGE_DIRTY		(1 << 8)
 #define CACHE_CACHABLE_COW	(5 << 9)
 
+	/*
+	 * A Bedrock hub puts the nasid one bit higher in an address than a
+	 * Hub does.  Returns the shift in \shft, clobbering \tmp.
+	 */
+	.macro	GET_NASID_SHFT shft, tmp
+	.set	push
+	.set	reorder
+	GET_HUB_GEN_ASM \tmp
+	li	\shft, SN1_NASID_SHFT
+	beqz	\tmp, 1f
+	li	\shft, SN0_NASID_SHFT
+1:
+	.set	pop
+	.endm
+
 	/*
 	 * inputs are the text nasid in t1, data nasid in t2.
 	 */
@@ -33,9 +48,10 @@
 	 */
 	dli	t0, 0xffffffffc0000000
 	dmtc0	t0, CP0_ENTRYHI
+	GET_NASID_SHFT	t3, t0
 	li	t0, 0x1c000		# Offset of text into node memory
-	dsll	t1, NASID_SHFT		# Shift text nasid into place
-	dsll	t2, NASID_SHFT		# Same for data nasid
+	dsllv	t1, t1, t3		# Shift text nasid into place
+	dsllv	t2, t2, t3		# Same for data nasid
 	or	t1, t1, t0		# Physical load address of kernel text
 	or	t2, t2, t0		# Physical load address of kernel data
 	dsrl	t1, 12			# 4K pfn
@@ -78,9 +94,10 @@
 	.macro	smp_slave_setup
 #ifdef CONFIG_MAPPED_KERNEL
 	GET_NASID_ASM	t1, t0
+	GET_NASID_SHFT	t3, t0
 	dli	t0, KLDIR_OFFSET + (KLI_KERN_VARS * KLDIR_ENT_SIZE) + \
 		    KLDIR_OFF_POINTER + CAC_BASE
-	dsll	t1, NASID_SHFT
+	dsllv	t1, t1, t3
 	or	t0, t0, t1
 	ld	t0, 0(t0)			# t0 points to kern_vars struct
 	lh	t1, KV_RO_NASID_OFFSET(t0)
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 17/38] MIPS: SGI-IP27: load the kernel at node offset 0x40000
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (15 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 16/38] MIPS: SGI-IP27: resolve the mapped-kernel node shift at runtime Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 18/38] MIPS: SGI-IP27: xbow_probe(): recognize KLTYPE_PBRICK_XBOW Imre Kaloz
                   ` (20 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

A Bedrock machine's PROM owns node memory below offset 0x40000. Link
both the mapped and the unmapped kernel there instead of at 0x1c000.
On an Origin 200/2000 the kernel moves up by 144KB, and the 144KB
below it stays reserved and unused.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/mach-ip27/kernel-entry-init.h |  2 +-
 arch/mips/include/asm/sn/mapped_kernel.h            |  6 +++---
 arch/mips/sgi-ip27/Platform                         | 11 ++++++-----
 3 files changed, 10 insertions(+), 9 deletions(-)

diff --git a/arch/mips/include/asm/mach-ip27/kernel-entry-init.h b/arch/mips/include/asm/mach-ip27/kernel-entry-init.h
index 1bedd3c3bc58..958f4b390df8 100644
--- a/arch/mips/include/asm/mach-ip27/kernel-entry-init.h
+++ b/arch/mips/include/asm/mach-ip27/kernel-entry-init.h
@@ -49,7 +49,7 @@
 	dli	t0, 0xffffffffc0000000
 	dmtc0	t0, CP0_ENTRYHI
 	GET_NASID_SHFT	t3, t0
-	li	t0, 0x1c000		# Offset of text into node memory
+	li	t0, 0x40000		# Offset of text into node memory
 	dsllv	t1, t1, t3		# Shift text nasid into place
 	dsllv	t2, t2, t3		# Same for data nasid
 	or	t1, t1, t0		# Physical load address of kernel text
diff --git a/arch/mips/include/asm/sn/mapped_kernel.h b/arch/mips/include/asm/sn/mapped_kernel.h
index 3f1049807018..28227718e391 100644
--- a/arch/mips/include/asm/sn/mapped_kernel.h
+++ b/arch/mips/include/asm/sn/mapped_kernel.h
@@ -10,7 +10,7 @@
 
 /*
  * Note on how mapped kernels work: the text and data section is
- * compiled at cksseg segment (LOADADDR = 0xc001c000), and the
+ * compiled at cksseg segment (LOADADDR = 0xc0040000), and the
  * init/setup/data section gets a 16M virtual address bump in the
  * ld.script file (so that tlblo0 and tlblo1 maps the sections).
  * The vmlinux.64 section addresses are put in the xkseg range
@@ -18,8 +18,8 @@
  * on IRIX to see where the sections go. The Origin loader loads
  * the two sections contiguously in physical memory. The loader
  * sets the entry point into kernel_entry using a xkphys address,
- * but instead of using 0xa800000001160000, it uses the address
- * 0xa800000000160000, which is where it physically loaded that
+ * but instead of using 0xa800000001184000, it uses the address
+ * 0xa800000000184000, which is where it physically loaded that
  * code. So no jumps can be done before we have switched to using
  * cksseg addresses.
  */
diff --git a/arch/mips/sgi-ip27/Platform b/arch/mips/sgi-ip27/Platform
index e734ee6abd44..b312bf69bce1 100644
--- a/arch/mips/sgi-ip27/Platform
+++ b/arch/mips/sgi-ip27/Platform
@@ -1,16 +1,17 @@
 #
 # SGI-IP27 (Origin200/2000)
 #
-# Set the load address to >= 0xc000000000300000 if you want to leave space for
-# symmon, 0xc00000000001c000 for production kernels.  Note that the value must
-# be 16kb aligned or the handling of the current variable will break.
+# A Bedrock machine's PROM owns node memory below offset 0x40000, so that is
+# where the kernel loads.  Set the load address to >= 0xc000000000300000
+# instead if you want to leave space for symmon.  Note that the value must be
+# 16kb aligned or the handling of the current variable will break.
 #
 cflags-$(CONFIG_SGI_IP27)	+= -I$(srctree)/arch/mips/include/asm/mach-ip27
 ifdef CONFIG_MAPPED_KERNEL
-load-$(CONFIG_SGI_IP27)		+= 0xc00000004001c000
+load-$(CONFIG_SGI_IP27)		+= 0xc000000040040000
 OBJCOPYFLAGS			:= --change-addresses=0x3fffffff80000000
 dataoffset-$(CONFIG_SGI_IP27)	+= 0x01000000
 else
-load-$(CONFIG_SGI_IP27)		+= 0xa80000000001c000
+load-$(CONFIG_SGI_IP27)		+= 0xa800000000040000
 OBJCOPYFLAGS			:= --change-addresses=0x57ffffff80000000
 endif
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 18/38] MIPS: SGI-IP27: xbow_probe(): recognize KLTYPE_PBRICK_XBOW
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (16 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 17/38] MIPS: SGI-IP27: load the kernel at node offset 0x40000 Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 19/38] MIPS: ip27_defconfig: enable the IOC3 MFD, its cell drivers and tg3 Imre Kaloz
                   ` (19 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

An IP35-family chassis records its crossbar board as KLTYPE_PBRICK_XBOW
rather than the KLTYPE_MIDPLANE8 an Origin 200/2000 midplane carries, so
xbow_probe() found no board record and never set up the crossbar. Fall
back to the brick type when the midplane lookup misses, and warn when
neither matches.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-xtalk.c | 15 +++++++++++++--
 1 file changed, 13 insertions(+), 2 deletions(-)

diff --git a/arch/mips/sgi-ip27/ip27-xtalk.c b/arch/mips/sgi-ip27/ip27-xtalk.c
index 10834880c261..baa937b474a8 100644
--- a/arch/mips/sgi-ip27/ip27-xtalk.c
+++ b/arch/mips/sgi-ip27/ip27-xtalk.c
@@ -159,8 +159,19 @@ static int xbow_probe(nasid_t nasid)
 	 * need to probe xbow
 	 */
 	brd = find_lboard((lboard_t *)KL_CONFIG_INFO(nasid), KLTYPE_MIDPLANE8);
-	if (!brd)
-		return -ENODEV;
+	if (!brd) {
+		/*
+		 * An IP35-family chassis records its crossbar as
+		 * KLTYPE_PBRICK_XBOW instead.
+		 */
+		brd = find_lboard((lboard_t *)KL_CONFIG_INFO(nasid),
+				  KLTYPE_PBRICK_XBOW);
+		if (!brd) {
+			pr_warn("xtalk:n%d no midplane/xbow board found\n",
+				nasid);
+			return -ENODEV;
+		}
+	}
 
 	xbow_p = (klxbow_t *)find_component(brd, NULL, KLSTRUCT_XBOW);
 	if (!xbow_p)
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 19/38] MIPS: ip27_defconfig: enable the IOC3 MFD, its cell drivers and tg3
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (17 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 18/38] MIPS: SGI-IP27: xbow_probe(): recognize KLTYPE_PBRICK_XBOW Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 20/38] net: ethernet: sgi: ioc3-eth: apply the DMA attributes only to 64-bit addresses Imre Kaloz
                   ` (18 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

CONFIG_SGI_MFD_IOC3 was unset, leaving the MFD core out of the built
kernel and the existing CONFIG_SGI_IOC3_ETH=y line unsatisfiable, since
that driver depends on it. Enable it with the 8250 and PS/2 cell
drivers, and enable tg3, which drives the Tezro's Gigabit Ethernet.

Fixes: 0ce5ebd24d25 ("mfd: ioc3: Add driver for SGI IOC3 chip")
Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/configs/ip27_defconfig | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/arch/mips/configs/ip27_defconfig b/arch/mips/configs/ip27_defconfig
index ac885ff5b712..73abeb534550 100644
--- a/arch/mips/configs/ip27_defconfig
+++ b/arch/mips/configs/ip27_defconfig
@@ -140,6 +140,7 @@ CONFIG_ATL2=m
 CONFIG_ATL1E=m
 CONFIG_ATL1C=m
 CONFIG_B44=m
+CONFIG_TIGON3=y
 CONFIG_BNX2X=m
 CONFIG_ENIC=m
 CONFIG_BE2NET=m
@@ -219,6 +220,7 @@ CONFIG_RTL8180=m
 CONFIG_WL1251=m
 CONFIG_WL12XX=m
 # CONFIG_INPUT is not set
+CONFIG_SERIO_SGI_IOC3=m
 CONFIG_SERIO_LIBPS2=m
 CONFIG_SERIO_RAW=m
 CONFIG_SERIO_ALTERA_PS2=m
@@ -229,6 +231,7 @@ CONFIG_SERIAL_8250_CONSOLE=y
 CONFIG_SERIAL_8250_EXTENDED=y
 CONFIG_SERIAL_8250_MANY_PORTS=y
 CONFIG_SERIAL_8250_SHARE_IRQ=y
+CONFIG_SERIAL_8250_IOC3=y
 CONFIG_HW_RANDOM_TIMERIOMEM=m
 CONFIG_I2C_CHARDEV=m
 CONFIG_I2C_ALI1535=m
@@ -260,6 +263,7 @@ CONFIG_LEDS_TRIGGER_TIMER=m
 CONFIG_LEDS_TRIGGER_HEARTBEAT=m
 CONFIG_LEDS_TRIGGER_BACKLIGHT=m
 CONFIG_LEDS_TRIGGER_DEFAULT_ON=m
+CONFIG_SGI_MFD_IOC3=y
 CONFIG_RTC_CLASS=y
 CONFIG_RTC_DRV_M48T35=y
 CONFIG_UIO=y
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 20/38] net: ethernet: sgi: ioc3-eth: apply the DMA attributes only to 64-bit addresses
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (18 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 19/38] MIPS: ip27_defconfig: enable the IOC3 MFD, its cell drivers and tg3 Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 21/38] MIPS: SGI-IP27: route XBridge and PIC DMA through the 32-bit window Imre Kaloz
                   ` (17 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer
  Cc: linux-mips, linux-kernel, Andrew Lunn, David S. Miller,
	Eric Dumazet, Jakub Kicinski, Paolo Abeni, netdev

A Bridge 64-bit direct-mapped DMA address carries the target widget and
the DMA attributes. An address in a bridge's 2GB 32-bit direct window
carries neither, so attributes OR-ed onto one form a 64-bit address
aimed at widget 0, and every receive raises a PCI error.

Apply the attributes, and the RX barrier's upper address bits, only to
64-bit addresses, in preparation for driving an XBridge through its
32-bit window.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 drivers/net/ethernet/sgi/ioc3-eth.c | 24 +++++++++++++++++++++---
 1 file changed, 21 insertions(+), 3 deletions(-)

diff --git a/drivers/net/ethernet/sgi/ioc3-eth.c b/drivers/net/ethernet/sgi/ioc3-eth.c
index 009f37105eaf..8702dfdf4c36 100644
--- a/drivers/net/ethernet/sgi/ioc3-eth.c
+++ b/drivers/net/ethernet/sgi/ioc3-eth.c
@@ -152,19 +152,37 @@ static inline int ioc3_alloc_skb(struct ioc3_private *ip, struct sk_buff **skb,
 }
 
 #ifdef CONFIG_PCI_XTALK_BRIDGE
+/* A Bridge 64-bit direct-mapped DMA address carries the target widget in
+ * bits 63:60 and the DMA attributes below it.  An XBridge is driven through
+ * its 32-bit direct window instead, where an address carries neither, so
+ * attributes OR-ed onto one form a 64-bit address aimed at widget 0.
+ */
 static inline unsigned long ioc3_map(dma_addr_t addr, unsigned long attr)
 {
+	if (!(addr & PCI64_ATTR_TARG_MASK))
+		return addr;
+
 	return (addr & ~PCI64_ATTR_BAR) | attr;
 }
 
-#define ERBAR_VAL	(ERBAR_BARRIER_BIT << ERBAR_RXBARR_SHIFT)
+/* The RX barrier's upper address bits follow the same form. */
+static inline u32 ioc3_erbar(dma_addr_t addr)
+{
+	if (!(addr & PCI64_ATTR_TARG_MASK))
+		return 0;
+
+	return ERBAR_BARRIER_BIT << ERBAR_RXBARR_SHIFT;
+}
 #else
 static inline unsigned long ioc3_map(dma_addr_t addr, unsigned long attr)
 {
 	return addr;
 }
 
-#define ERBAR_VAL	0
+static inline u32 ioc3_erbar(dma_addr_t addr)
+{
+	return 0;
+}
 #endif
 
 static int ioc3eth_nvmem_match(struct device *dev, const void *data)
@@ -727,7 +745,7 @@ static void ioc3_init(struct net_device *dev)
 	readl(&regs->emcr);
 
 	/* Misc registers  */
-	writel(ERBAR_VAL, &regs->erbar);
+	writel(ioc3_erbar(ip->rxr_dma), &regs->erbar);
 	readl(&regs->etcdc);			/* Clear on read */
 	writel(15, &regs->ercsr);		/* RX low watermark  */
 	writel(0, &regs->ertr);			/* Interrupt immediately */
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 21/38] MIPS: SGI-IP27: route XBridge and PIC DMA through the 32-bit window
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (19 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 20/38] net: ethernet: sgi: ioc3-eth: apply the DMA attributes only to 64-bit addresses Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 22/38] MIPS: SGI-IP27: recognize the PXBow crossbar Imre Kaloz
                   ` (16 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

XBridge does not honour the SN0-style 64-bit direct-mapped DMA address:
commands complete but no data moves. PIC moves no data either. Route
both through the 2GB 32-bit window and cap bus_dma_limit at its top, so
SWIOTLB bounces anything above it. PIC is flagged once a following
patch enumerates it.

Only XBridge (part 0xd002) is flagged; a Bridge (0xc002) behind a Hub
keeps the 64-bit direct map. The 64MB bounce pool comes from node 0
whenever DRAM passes 2GB, on Hub any multi-node machine. A PIC bus in
PCI-X mode takes the window too; IRIX does not.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/Kconfig                          |  1 +
 arch/mips/include/asm/pci/bridge.h         |  2 ++
 arch/mips/pci/pci-xtalk-bridge.c           | 26 ++++++++++++++++++++++
 arch/mips/sgi-ip27/ip27-memory.c           | 16 +++++++++++++
 arch/mips/sgi-ip27/ip27-xtalk.c            | 15 ++++++++++---
 include/linux/platform_data/xtalk-bridge.h |  2 ++
 6 files changed, 59 insertions(+), 3 deletions(-)

diff --git a/arch/mips/Kconfig b/arch/mips/Kconfig
index eb291fa7fd08..20212194e763 100644
--- a/arch/mips/Kconfig
+++ b/arch/mips/Kconfig
@@ -773,6 +773,7 @@ config SGI_IP27
 	select NR_CPUS_DEFAULT_64
 	select PCI_DRIVERS_GENERIC
 	select PCI_XTALK_BRIDGE
+	select SWIOTLB
 	select SYS_HAS_CPU_R10000
 	select SYS_SUPPORTS_64BIT_KERNEL
 	select SYS_SUPPORTS_BIG_ENDIAN
diff --git a/arch/mips/include/asm/pci/bridge.h b/arch/mips/include/asm/pci/bridge.h
index eaeafccd82c7..2ea0f1e2cd76 100644
--- a/arch/mips/include/asm/pci/bridge.h
+++ b/arch/mips/include/asm/pci/bridge.h
@@ -810,6 +810,8 @@ struct bridge_controller {
 	unsigned int		int_mapping[8][2];
 	u32			ioc3_sid[8];
 	nasid_t			nasid;
+	bool			is_xbridge;
+	bool			is_pic;
 };
 
 #define BRIDGE_CONTROLLER(bus) \
diff --git a/arch/mips/pci/pci-xtalk-bridge.c b/arch/mips/pci/pci-xtalk-bridge.c
index cf115abb54e0..c5dec9b0f72d 100644
--- a/arch/mips/pci/pci-xtalk-bridge.c
+++ b/arch/mips/pci/pci-xtalk-bridge.c
@@ -31,14 +31,38 @@ dma_addr_t phys_to_dma(struct device *dev, phys_addr_t paddr)
 	struct pci_dev *pdev = to_pci_dev(dev);
 	struct bridge_controller *bc = BRIDGE_CONTROLLER(pdev->bus);
 
+	/*
+	 * XBridge and PIC move no data for this direct-mapped address; use
+	 * the 2GB 32-bit window instead. An address above the window is not
+	 * clamped here: pcibios_bus_add_device() caps bus_dma_limit at the
+	 * window's top, so such a buffer is bounced through SWIOTLB.
+	 */
+	if (bc->is_xbridge || bc->is_pic)
+		return BRIDGE_DMA_DIRECT_BASE + paddr;
+
 	return bc->baddr + paddr;
 }
 
 phys_addr_t dma_to_phys(struct device *dev, dma_addr_t dma_addr)
 {
+	struct pci_dev *pdev = to_pci_dev(dev);
+	struct bridge_controller *bc = BRIDGE_CONTROLLER(pdev->bus);
+
+	if (bc->is_xbridge || bc->is_pic)
+		return dma_addr - BRIDGE_DMA_DIRECT_BASE;
+
 	return dma_addr & ~(0xffUL << 56);
 }
 
+/* Bounce a widened DMA mask's out-of-window addresses through SWIOTLB. */
+void pcibios_bus_add_device(struct pci_dev *pdev)
+{
+	struct bridge_controller *bc = BRIDGE_CONTROLLER(pdev->bus);
+
+	if (bc->is_xbridge || bc->is_pic)
+		pdev->dev.bus_dma_limit = 0xffffffff;
+}
+
 /*
  * Most of the IOC3 PCI config register aren't present
  * we emulate what is needed for a normal PCI enumeration
@@ -663,6 +687,8 @@ static int bridge_probe(struct platform_device *pdev)
 	bc->baddr = (u64)bd->masterwid << 60 | PCI64_ATTR_BAR;
 	bc->base = (struct bridge_regs *)bd->bridge_addr;
 	bc->intr_addr = bd->intr_addr;
+	bc->is_xbridge = bd->is_xbridge;
+	bc->is_pic = bd->is_pic;
 
 	/*
 	 * Clear all pending interrupts.
diff --git a/arch/mips/sgi-ip27/ip27-memory.c b/arch/mips/sgi-ip27/ip27-memory.c
index 98184dfcd8c5..d51e02ce12a6 100644
--- a/arch/mips/sgi-ip27/ip27-memory.c
+++ b/arch/mips/sgi-ip27/ip27-memory.c
@@ -19,8 +19,10 @@
 #include <linux/nodemask.h>
 #include <linux/sizes.h>
 #include <linux/swap.h>
+#include <linux/swiotlb.h>
 #include <linux/pfn.h>
 #include <linux/highmem.h>
+#include <asm/bootinfo.h>
 #include <asm/page.h>
 #include <asm/pgalloc.h>
 #include <asm/sections.h>
@@ -437,3 +439,17 @@ void __init arch_zone_limits_init(unsigned long *max_zone_pfns)
 {
 	max_zone_pfns[ZONE_NORMAL] = max_low_pfn;
 }
+
+/*
+ * XBridge and PIC are driven through their 2GB 32-bit DMA window, so
+ * cap the bounce pool there; which widgets exist isn't known this early,
+ * so reserve it whenever node memory reaches past the window.
+ */
+void __init plat_swiotlb_setup(void)
+{
+	phys_addr_t old_limit = memblock_get_current_limit();
+
+	memblock_set_current_limit(min_t(phys_addr_t, old_limit, SZ_2G));
+	swiotlb_init(max_low_pfn > PFN_DOWN(SZ_2G), SWIOTLB_VERBOSE);
+	memblock_set_current_limit(old_limit);
+}
diff --git a/arch/mips/sgi-ip27/ip27-xtalk.c b/arch/mips/sgi-ip27/ip27-xtalk.c
index baa937b474a8..bd2ac24452f5 100644
--- a/arch/mips/sgi-ip27/ip27-xtalk.c
+++ b/arch/mips/sgi-ip27/ip27-xtalk.c
@@ -23,7 +23,13 @@
 #define XXBOW_WIDGET_PART_NUM	0xd000	/* Xbow in Xbridge */
 #define BASE_XBOW_PORT		8     /* Lowest external port */
 
-static void bridge_platform_create(nasid_t nasid, int widget, int masterwid)
+enum xtalk_bridge_type {
+	XTALK_BRIDGE,
+	XTALK_XBRIDGE,
+};
+
+static void bridge_platform_create(nasid_t nasid, int widget, int masterwid,
+				   enum xtalk_bridge_type type)
 {
 	struct xtalk_bridge_platform_data *bd;
 	struct sgi_w1_platform_data *wd;
@@ -85,6 +91,7 @@ static void bridge_platform_create(nasid_t nasid, int widget, int masterwid)
 	bd->intr_addr	= BIT_ULL(47) + 0x01800000 + PI_INT_PEND_MOD;
 	bd->nasid	= nasid;
 	bd->masterwid	= masterwid;
+	bd->is_xbridge	= type == XTALK_XBRIDGE;
 
 	bd->mem.name	= "Bridge PCI MEM";
 	bd->mem.start	= offset + (widget << SWIN_SIZE_BITS) + BRIDGE_DEVIO0;
@@ -136,8 +143,10 @@ static int probe_one_port(nasid_t nasid, int widget, int masterwid)
 
 	switch (partnum) {
 	case BRIDGE_WIDGET_PART_NUM:
+		bridge_platform_create(nasid, widget, masterwid, XTALK_BRIDGE);
+		break;
 	case XBRIDGE_WIDGET_PART_NUM:
-		bridge_platform_create(nasid, widget, masterwid);
+		bridge_platform_create(nasid, widget, masterwid, XTALK_XBRIDGE);
 		break;
 	default:
 		pr_info("xtalk:n%d/%d unknown widget (0x%x)\n",
@@ -228,7 +237,7 @@ static void xtalk_probe_node(nasid_t nasid)
 
 	switch (partnum) {
 	case BRIDGE_WIDGET_PART_NUM:
-		bridge_platform_create(nasid, 0x8, 0xa);
+		bridge_platform_create(nasid, 0x8, 0xa, XTALK_BRIDGE);
 		break;
 	case XBOW_WIDGET_PART_NUM:
 	case XXBOW_WIDGET_PART_NUM:
diff --git a/include/linux/platform_data/xtalk-bridge.h b/include/linux/platform_data/xtalk-bridge.h
index 51e5001f2c05..171b5bcf56e4 100644
--- a/include/linux/platform_data/xtalk-bridge.h
+++ b/include/linux/platform_data/xtalk-bridge.h
@@ -17,6 +17,8 @@ struct xtalk_bridge_platform_data {
 	unsigned long io_offset;
 	nasid_t	nasid;
 	int	masterwid;
+	bool	is_xbridge;
+	bool	is_pic;
 };
 
 #endif /* PLATFORM_DATA_XTALK_BRIDGE_H */
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 22/38] MIPS: SGI-IP27: recognize the PXBow crossbar
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (20 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 21/38] MIPS: SGI-IP27: route XBridge and PIC DMA through the 32-bit window Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 23/38] MIPS: PCI: xtalk-bridge: recognize the PIC widget's 64-bit-only registers Imre Kaloz
                   ` (15 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

A Tezro's crossbar is a PXBow, widget part number 0xd100. Without
recognizing it, xtalk_probe_node() logs the widget as unknown and never
calls xbow_probe(), leaving every IO widget behind it unenumerated.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/xtalk/xwidget.h | 7 +++++++
 arch/mips/sgi-ip27/ip27-xtalk.c       | 2 ++
 2 files changed, 9 insertions(+)

diff --git a/arch/mips/include/asm/xtalk/xwidget.h b/arch/mips/include/asm/xtalk/xwidget.h
index 978877e8a090..6a98e87b4711 100644
--- a/arch/mips/include/asm/xtalk/xwidget.h
+++ b/arch/mips/include/asm/xtalk/xwidget.h
@@ -109,6 +109,7 @@
 #define WIDGET_BDRCK_PART_NUM	0xc110
 #define WIDGET_TPU_PART_NUM	0xc202
 #define WIDGET_XXBOW_PART_NUM	0xd000
+#define WIDGET_PXBOW_PART_NUM	0xd100
 #define WIDGET_XBRDG_PART_NUM	0xd002
 #define WIDGET_NULL_PART_NUM	-1
 
@@ -183,6 +184,12 @@ static const struct widget_ident widget_idents[] __initconst __maybe_unused = {
 		"xxbow",
 		{NULL, "1.0", "2.0", NULL},
 	},
+	{
+		WIDGET_XXBOW_MFGR_NUM,
+		WIDGET_PXBOW_PART_NUM,
+		"pxbow",
+		{NULL, "1.0", NULL},
+	},
 	{
 		WIDGET_XBRDG_MFGR_NUM,
 		WIDGET_XBRDG_PART_NUM,
diff --git a/arch/mips/sgi-ip27/ip27-xtalk.c b/arch/mips/sgi-ip27/ip27-xtalk.c
index bd2ac24452f5..105977316391 100644
--- a/arch/mips/sgi-ip27/ip27-xtalk.c
+++ b/arch/mips/sgi-ip27/ip27-xtalk.c
@@ -21,6 +21,7 @@
 
 #define XBOW_WIDGET_PART_NUM	0x0
 #define XXBOW_WIDGET_PART_NUM	0xd000	/* Xbow in Xbridge */
+#define PXBOW_WIDGET_PART_NUM	0xd100	/* PXbow */
 #define BASE_XBOW_PORT		8     /* Lowest external port */
 
 enum xtalk_bridge_type {
@@ -241,6 +242,7 @@ static void xtalk_probe_node(nasid_t nasid)
 		break;
 	case XBOW_WIDGET_PART_NUM:
 	case XXBOW_WIDGET_PART_NUM:
+	case PXBOW_WIDGET_PART_NUM:
 		pr_info("xtalk:n%d/0 xbow widget\n", nasid);
 		xbow_probe(nasid);
 		break;
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 23/38] MIPS: PCI: xtalk-bridge: recognize the PIC widget's 64-bit-only registers
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (21 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 22/38] MIPS: SGI-IP27: recognize the PXBow crossbar Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:11 ` [PATCH 24/38] MIPS: PCI: xtalk-bridge: match PIC's register-level differences Imre Kaloz
                   ` (14 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

PIC replicates the Bridge/XBridge register layout, twice in one widget
window for its two PCI buses, and does not accept a 32-bit write to half
of a 64-bit register. Flag it, widen the register accessors to the
double word, and spawn a controller per bus.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/pci/bridge.h | 70 +++++++++++++++++++++++++++---
 arch/mips/sgi-ip27/ip27-xtalk.c    | 30 ++++++++++---
 2 files changed, 89 insertions(+), 11 deletions(-)

diff --git a/arch/mips/include/asm/pci/bridge.h b/arch/mips/include/asm/pci/bridge.h
index 2ea0f1e2cd76..76c5db983748 100644
--- a/arch/mips/include/asm/pci/bridge.h
+++ b/arch/mips/include/asm/pci/bridge.h
@@ -12,6 +12,8 @@
 #ifndef _ASM_PCI_BRIDGE_H
 #define _ASM_PCI_BRIDGE_H
 
+#include <linux/build_bug.h>
+#include <linux/stddef.h>
 #include <linux/types.h>
 #include <linux/pci.h>
 #include <asm/xtalk/xwidget.h>		/* generic widget header */
@@ -39,6 +41,9 @@
 #define BRIDGE_SSRAM_64K	0x00010000	/* 64kB */
 #define BRIDGE_SSRAM_0K		0x00000000	/* 0kB */
 
+/* PIC replicates its register block twice within one widget's 16MB window. */
+#define PIC_BUS1_OFFSET		0x800000
+
 /* ========================================================================
  *    Bridge address map
  */
@@ -264,6 +269,15 @@ struct bridge_regs {
 	} b_external_flash;			/* 0xC00000 */
 };
 
+/*
+ * Pin b_device[]/b_rrb_map[]'s low-half placement: bridge_readl() and
+ * bridge_writel() rely on it.
+ */
+static_assert(offsetof(struct bridge_regs, b_device[0].reg) == 0x204);
+static_assert(offsetof(struct bridge_regs, b_device[1].reg) == 0x20c);
+static_assert(offsetof(struct bridge_regs, b_rrb_map[0].reg) == 0x284);
+static_assert(offsetof(struct bridge_regs, b_rrb_map[1].reg) == 0x28c);
+
 /*
  * Field formats for Error Command Word and Auxiliary Error Command Word
  * of bridge.
@@ -394,6 +408,7 @@ struct bridge_err_cmdword {
 /* Widget part number of bridge */
 #define BRIDGE_WIDGET_PART_NUM		0xc002
 #define XBRIDGE_WIDGET_PART_NUM		0xd002
+#define PIC_WIDGET_PART_NUM		0xd102
 
 /* Manufacturer of bridge */
 #define BRIDGE_WIDGET_MFGR_NUM		0x036
@@ -817,11 +832,54 @@ struct bridge_controller {
 #define BRIDGE_CONTROLLER(bus) \
 	((struct bridge_controller *)((bus)->sysdata))
 
-#define bridge_read(bc, reg)		__raw_readl(&bc->base->reg)
-#define bridge_write(bc, reg, val)	__raw_writel(val, &bc->base->reg)
-#define bridge_set(bc, reg, val)	\
-	__raw_writel(__raw_readl(&bc->base->reg) | (val), &bc->base->reg)
-#define bridge_clr(bc, reg, val)	\
-	__raw_writel(__raw_readl(&bc->base->reg) & ~(val), &bc->base->reg)
+/*
+ * PIC does not accept a 32-bit write to half of a 64-bit register, so
+ * widen each access to the 8-byte-aligned double word and extract or
+ * insert the 32-bit value at its byte position. The pointer is
+ * volatile-qualified because widget_cfg_t is, and b_widget sits in
+ * every bridge_regs.
+ */
+static inline u32 bridge_readl(struct bridge_controller *bc, volatile u32 *reg)
+{
+	void *dw;
+	unsigned int shift;
+
+	if (likely(!bc->is_pic))
+		return __raw_readl(reg);
+
+	dw = (void *)((unsigned long)reg & ~7UL);
+	shift = ((unsigned long)reg & 4) ? 0 : 32;
+
+	return __raw_readq(dw) >> shift;
+}
+
+static inline void bridge_writel(struct bridge_controller *bc,
+				 volatile u32 *reg, u32 val)
+{
+	void *dw;
+	unsigned int shift;
+	u64 tmp;
+
+	if (likely(!bc->is_pic)) {
+		__raw_writel(val, reg);
+		return;
+	}
+
+	dw = (void *)((unsigned long)reg & ~7UL);
+	shift = ((unsigned long)reg & 4) ? 0 : 32;
+
+	tmp = __raw_readq(dw);
+	tmp = (tmp & ~(0xffffffffULL << shift)) | ((u64)val << shift);
+	__raw_writeq(tmp, dw);
+}
+
+#define bridge_read(bc, reg)		bridge_readl(bc, &bc->base->reg)
+#define bridge_write(bc, reg, val)	bridge_writel(bc, &bc->base->reg, val)
+#define bridge_set(bc, reg, val)				\
+	bridge_writel(bc, &bc->base->reg,			\
+		      bridge_readl(bc, &bc->base->reg) | (val))
+#define bridge_clr(bc, reg, val)				\
+	bridge_writel(bc, &bc->base->reg,			\
+		      bridge_readl(bc, &bc->base->reg) & ~(val))
 
 #endif /* _ASM_PCI_BRIDGE_H */
diff --git a/arch/mips/sgi-ip27/ip27-xtalk.c b/arch/mips/sgi-ip27/ip27-xtalk.c
index 105977316391..73b2eef96bdb 100644
--- a/arch/mips/sgi-ip27/ip27-xtalk.c
+++ b/arch/mips/sgi-ip27/ip27-xtalk.c
@@ -27,6 +27,8 @@
 enum xtalk_bridge_type {
 	XTALK_BRIDGE,
 	XTALK_XBRIDGE,
+	XTALK_PIC_BUS0,
+	XTALK_PIC_BUS1,
 };
 
 static void bridge_platform_create(nasid_t nasid, int widget, int masterwid,
@@ -88,21 +90,32 @@ static void bridge_platform_create(nasid_t nasid, int widget, int masterwid,
 	}
 
 
-	bd->bridge_addr = RAW_NODE_SWIN_BASE(nasid, widget);
+	bd->bridge_addr = RAW_NODE_SWIN_BASE(nasid, widget) +
+			  (type == XTALK_PIC_BUS1 ? PIC_BUS1_OFFSET : 0);
 	bd->intr_addr	= BIT_ULL(47) + 0x01800000 + PI_INT_PEND_MOD;
 	bd->nasid	= nasid;
 	bd->masterwid	= masterwid;
 	bd->is_xbridge	= type == XTALK_XBRIDGE;
+	bd->is_pic	= type == XTALK_PIC_BUS0 || type == XTALK_PIC_BUS1;
 
+	/* Split a PIC's window at bus 1 or its resource request fails. */
 	bd->mem.name	= "Bridge PCI MEM";
-	bd->mem.start	= offset + (widget << SWIN_SIZE_BITS) + BRIDGE_DEVIO0;
-	bd->mem.end	= offset + (widget << SWIN_SIZE_BITS) + SWIN_SIZE - 1;
+	bd->mem.start	= offset + (widget << SWIN_SIZE_BITS) +
+			  (type == XTALK_PIC_BUS1 ? PIC_BUS1_OFFSET : 0) +
+			  BRIDGE_DEVIO0;
+	bd->mem.end	= offset + (widget << SWIN_SIZE_BITS) +
+			  (type == XTALK_PIC_BUS0 ? PIC_BUS1_OFFSET :
+						    SWIN_SIZE) - 1;
 	bd->mem.flags	= IORESOURCE_MEM;
 	bd->mem_offset	= offset;
 
 	bd->io.name	= "Bridge PCI IO";
-	bd->io.start	= offset + (widget << SWIN_SIZE_BITS) + BRIDGE_DEVIO0;
-	bd->io.end	= offset + (widget << SWIN_SIZE_BITS) + SWIN_SIZE - 1;
+	bd->io.start	= offset + (widget << SWIN_SIZE_BITS) +
+			  (type == XTALK_PIC_BUS1 ? PIC_BUS1_OFFSET : 0) +
+			  BRIDGE_DEVIO0;
+	bd->io.end	= offset + (widget << SWIN_SIZE_BITS) +
+			  (type == XTALK_PIC_BUS0 ? PIC_BUS1_OFFSET :
+						    SWIN_SIZE) - 1;
 	bd->io.flags	= IORESOURCE_IO;
 	bd->io_offset	= offset;
 
@@ -149,6 +162,13 @@ static int probe_one_port(nasid_t nasid, int widget, int masterwid)
 	case XBRIDGE_WIDGET_PART_NUM:
 		bridge_platform_create(nasid, widget, masterwid, XTALK_XBRIDGE);
 		break;
+	case PIC_WIDGET_PART_NUM:
+		/* PIC always has both buses in silicon: probe each. */
+		bridge_platform_create(nasid, widget, masterwid,
+				       XTALK_PIC_BUS0);
+		bridge_platform_create(nasid, widget, masterwid,
+				       XTALK_PIC_BUS1);
+		break;
 	default:
 		pr_info("xtalk:n%d/%d unknown widget (0x%x)\n",
 			nasid, widget, partnum);
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 24/38] MIPS: PCI: xtalk-bridge: match PIC's register-level differences
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (22 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 23/38] MIPS: PCI: xtalk-bridge: recognize the PIC widget's 64-bit-only registers Imre Kaloz
@ 2026-10-01 16:11 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 25/38] rtc: m48t35: support the SGI IP35 timekeeper's 1968 year base Imre Kaloz
                   ` (13 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:11 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

PIC's config space puts the ASIC at device 0 and the slots at 1-4, its
write-request RAM needs clearing, and b_int_addr[] takes a full XIO
address. Handle each in the config accessors and in bridge_probe(),
which also clears PIC's NO_SNOOP and RELAX_ORDER control bits.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/pci/bridge.h | 11 ++++++
 arch/mips/pci/pci-xtalk-bridge.c   | 61 +++++++++++++++++++++++-------
 2 files changed, 59 insertions(+), 13 deletions(-)

diff --git a/arch/mips/include/asm/pci/bridge.h b/arch/mips/include/asm/pci/bridge.h
index 76c5db983748..81204c3d211d 100644
--- a/arch/mips/include/asm/pci/bridge.h
+++ b/arch/mips/include/asm/pci/bridge.h
@@ -372,6 +372,12 @@ struct bridge_err_cmdword {
 
 #define BRIDGE_ATE_RAM		0x00010000	/* Internal Addr Xlat Ram */
 
+/* PIC Write Request RAM: three 256-entry, 64-bit arrays. */
+#define PIC_WR_REQ_BUFSIZE	256
+#define PIC_WR_REQ_LOWER	0x00018000
+#define PIC_WR_REQ_UPPER	0x00018800
+#define PIC_WR_REQ_PARITY	0x00019000
+
 #define BRIDGE_TYPE0_CFG_DEV0	0x00020000	/* Type 0 Cfg, Device 0 */
 #define BRIDGE_TYPE0_CFG_SLOT_OFF	0x00001000	/* Type 0 Cfg Slot Offset (1..7) */
 #define BRIDGE_TYPE0_CFG_FUNC_OFF	0x00000100	/* Type 0 Cfg Func Offset (1..7) */
@@ -389,6 +395,7 @@ struct bridge_err_cmdword {
 /* Byte offset macros for Bridge device IO spaces */
 
 #define BRIDGE_DEV_CNT		8	/* Up to 8 devices per bridge */
+#define PIC_NSLOTS		4	/* PIC: 4 devices per bus */
 #define BRIDGE_DEVIO0		0x00200000	/* Device IO 0 Addr */
 #define BRIDGE_DEVIO1		0x00400000	/* Device IO 1 Addr */
 #define BRIDGE_DEVIO2		0x00600000	/* Device IO 2 Addr */
@@ -458,6 +465,10 @@ struct bridge_err_cmdword {
 #define BRIDGE_CTRL_WIDGET_ID(n)	((n) << 0)
 #define BRIDGE_CTRL_WIDGET_ID_MASK	(BRIDGE_CTRL_WIDGET_ID(0xf))
 
+/* PIC-only widget control bits, upper 32 bits of the register. */
+#define PIC_CTRL_NO_SNOOP		(0x1ull << 62)
+#define PIC_CTRL_RELAX_ORDER		(0x1ull << 61)
+
 /* Bridge Response buffer Error Upper Register bit fields definition */
 #define BRIDGE_RESP_ERRUPPR_DEVNUM_SHFT (20)
 #define BRIDGE_RESP_ERRUPPR_DEVNUM_MASK (0x7 << BRIDGE_RESP_ERRUPPR_DEVNUM_SHFT)
diff --git a/arch/mips/pci/pci-xtalk-bridge.c b/arch/mips/pci/pci-xtalk-bridge.c
index c5dec9b0f72d..35ae7c423973 100644
--- a/arch/mips/pci/pci-xtalk-bridge.c
+++ b/arch/mips/pci/pci-xtalk-bridge.c
@@ -146,12 +146,14 @@ static int pci_conf0_read_config(struct pci_bus *bus, unsigned int devfn,
 	struct bridge_controller *bc = BRIDGE_CONTROLLER(bus);
 	struct bridge_regs *bridge = bc->base;
 	int slot = PCI_SLOT(devfn);
+	/* PIC config-space device 0 is the PIC ASIC; devices start at 1. */
+	int cfgslot = bc->is_pic ? slot + 1 : slot;
 	int fn = PCI_FUNC(devfn);
 	void *addr;
 	u32 cf;
 	int res;
 
-	addr = &bridge->b_type0_cfg_dev[slot].f[fn].c[PCI_VENDOR_ID];
+	addr = &bridge->b_type0_cfg_dev[cfgslot].f[fn].c[PCI_VENDOR_ID];
 	if (get_dbe(cf, (u32 *)addr))
 		return PCIBIOS_DEVICE_NOT_FOUND;
 
@@ -160,12 +162,12 @@ static int pci_conf0_read_config(struct pci_bus *bus, unsigned int devfn,
 	 * generic PCI code a chance to look at it for real ...
 	 */
 	if (cf == (PCI_VENDOR_ID_SGI | (PCI_DEVICE_ID_SGI_IOC3 << 16))) {
-		addr = &bridge->b_type0_cfg_dev[slot].f[fn].l[where >> 2];
+		addr = &bridge->b_type0_cfg_dev[cfgslot].f[fn].l[where >> 2];
 		return ioc3_cfg_rd(addr, where, size, value,
 				   bc->ioc3_sid[slot]);
 	}
 
-	addr = &bridge->b_type0_cfg_dev[slot].f[fn].c[where ^ (4 - size)];
+	addr = &bridge->b_type0_cfg_dev[cfgslot].f[fn].c[where ^ (4 - size)];
 
 	if (size == 1)
 		res = get_dbe(*value, (u8 *)addr);
@@ -231,12 +233,14 @@ static int pci_conf0_write_config(struct pci_bus *bus, unsigned int devfn,
 	struct bridge_controller *bc = BRIDGE_CONTROLLER(bus);
 	struct bridge_regs *bridge = bc->base;
 	int slot = PCI_SLOT(devfn);
+	/* See the matching comment in pci_conf0_read_config(). */
+	int cfgslot = bc->is_pic ? slot + 1 : slot;
 	int fn = PCI_FUNC(devfn);
 	void *addr;
 	u32 cf;
 	int res;
 
-	addr = &bridge->b_type0_cfg_dev[slot].f[fn].c[PCI_VENDOR_ID];
+	addr = &bridge->b_type0_cfg_dev[cfgslot].f[fn].c[PCI_VENDOR_ID];
 	if (get_dbe(cf, (u32 *)addr))
 		return PCIBIOS_DEVICE_NOT_FOUND;
 
@@ -245,11 +249,11 @@ static int pci_conf0_write_config(struct pci_bus *bus, unsigned int devfn,
 	 * generic PCI code a chance to look at it for real ...
 	 */
 	if (cf == (PCI_VENDOR_ID_SGI | (PCI_DEVICE_ID_SGI_IOC3 << 16))) {
-		addr = &bridge->b_type0_cfg_dev[slot].f[fn].l[where >> 2];
+		addr = &bridge->b_type0_cfg_dev[cfgslot].f[fn].l[where >> 2];
 		return ioc3_cfg_wr(addr, where, size, value);
 	}
 
-	addr = &bridge->b_type0_cfg_dev[slot].f[fn].c[where ^ (4 - size)];
+	addr = &bridge->b_type0_cfg_dev[cfgslot].f[fn].c[where ^ (4 - size)];
 
 	if (size == 1)
 		res = put_dbe(value, (u8 *)addr);
@@ -324,6 +328,22 @@ struct bridge_irq_chip_data {
 	nasid_t nasid;
 };
 
+/* PIC takes the full 48-bit XIO address here, source in bits 55:48. */
+static void bridge_set_int_addr(struct bridge_controller *bc, int pin,
+				int bit, nasid_t nasid)
+{
+	if (bc->is_pic) {
+		void *addr = &bc->base->b_int_addr[pin];
+		u64 xio = bc->intr_addr & ((1ULL << 48) - 1);
+
+		__raw_writeq(((u64)bit << 48) | xio, addr);
+	} else {
+		bridge_write(bc, b_int_addr[pin].addr,
+			     (((bc->intr_addr >> 30) & 0x30000) |
+			      bit | (nasid << 8)));
+	}
+}
+
 static int bridge_set_affinity(struct irq_data *d, const struct cpumask *mask,
 			       bool force)
 {
@@ -337,9 +357,7 @@ static int bridge_set_affinity(struct irq_data *d, const struct cpumask *mask,
 	if (ret >= 0) {
 		cpu = cpumask_first_and(mask, cpu_online_mask);
 		data->nasid = cpu_to_node(cpu);
-		bridge_write(data->bc, b_int_addr[pin].addr,
-			     (((data->bc->intr_addr >> 30) & 0x30000) |
-			      bit | (data->nasid << 8)));
+		bridge_set_int_addr(data->bc, pin, bit, data->nasid);
 		bridge_read(data->bc, b_wid_tflush);
 	}
 	return ret;
@@ -403,9 +421,7 @@ static int bridge_domain_activate(struct irq_domain *domain,
 	int pin = irqd->hwirq;
 	u32 device;
 
-	bridge_write(bc, b_int_addr[pin].addr,
-		     (((bc->intr_addr >> 30) & 0x30000) |
-		      bit | (data->nasid << 8)));
+	bridge_set_int_addr(bc, pin, bit, data->nasid);
 	bridge_set(bc, b_int_enable, (1 << pin));
 	bridge_set(bc, b_int_enable, 0x7ffffe00); /* more stuff in int_enable */
 
@@ -711,6 +727,24 @@ static int bridge_probe(struct platform_device *pdev)
 	bridge_set(bc, b_wid_control, BRIDGE_CTRL_PAGE_SIZE);
 #endif
 
+	if (bc->is_pic) {
+		unsigned long ctrl = (unsigned long)&bc->base->b_wid_control;
+		void *ctrl64 = (void *)(ctrl & ~7UL);
+		int i;
+
+		/* Keep DMA snooped and ordered. */
+		__raw_writeq(__raw_readq(ctrl64) &
+			     ~(PIC_CTRL_NO_SNOOP | PIC_CTRL_RELAX_ORDER),
+			     ctrl64);
+
+		/* Clear so a stale entry can't trip a parity error. */
+		for (i = 0; i < PIC_WR_REQ_BUFSIZE * 8; i += 8) {
+			__raw_writeq(0, (u8 *)bc->base + PIC_WR_REQ_LOWER + i);
+			__raw_writeq(0, (u8 *)bc->base + PIC_WR_REQ_UPPER + i);
+			__raw_writeq(0, (u8 *)bc->base + PIC_WR_REQ_PARITY + i);
+		}
+	}
+
 	/*
 	 * Hmm...  IRIX sets additional bits in the address which
 	 * are documented as reserved in the bridge docs.
@@ -721,7 +755,8 @@ static int bridge_probe(struct platform_device *pdev)
 	bridge_write(bc, b_dir_map, (bd->masterwid << 20));	/* DMA */
 	bridge_write(bc, b_int_enable, 0);
 
-	for (slot = 0; slot < 8; slot++) {
+	for (slot = 0; slot < (bc->is_pic ? PIC_NSLOTS : BRIDGE_DEV_CNT);
+	     slot++) {
 		bridge_set(bc, b_device[slot].reg, BRIDGE_DEV_SWAP_DIR);
 		bc->pci_int[slot][0] = -1;
 		bc->pci_int[slot][1] = -1;
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 25/38] rtc: m48t35: support the SGI IP35 timekeeper's 1968 year base
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (23 preceding siblings ...)
  2026-10-01 16:11 ` [PATCH 24/38] MIPS: PCI: xtalk-bridge: match PIC's register-level differences Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 26/38] mfd: ioc3: add support for IOC4 Imre Kaloz
                   ` (12 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer
  Cc: linux-mips, linux-kernel, Alexandre Belloni, linux-rtc

The M48T35 of SGI IP35-family machines counts its year from 1968. Take
the epoch from a platform id table, "rtc-m48t35" for IP27 and
"rtc-m48t35-ip35" for IP35, and bound the year to the part's century: on
IP27 a year past 2069 now fails to set.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 drivers/rtc/rtc-m48t35.c | 29 +++++++++++++++--------------
 1 file changed, 15 insertions(+), 14 deletions(-)

diff --git a/drivers/rtc/rtc-m48t35.c b/drivers/rtc/rtc-m48t35.c
index 92f19bf997b2..69c313b4b6e8 100644
--- a/drivers/rtc/rtc-m48t35.c
+++ b/drivers/rtc/rtc-m48t35.c
@@ -49,6 +49,7 @@ struct m48t35_priv {
 	struct m48t35_rtc __iomem *reg;
 	size_t size;
 	unsigned long baseaddr;
+	unsigned int epoch;
 	spinlock_t lock;
 };
 
@@ -86,10 +87,7 @@ static int m48t35_read_time(struct device *dev, struct rtc_time *tm)
 	 * Account for differences between how the RTC uses the values
 	 * and how they are defined in a struct rtc_time;
 	 */
-	tm->tm_year += 70;
-	if (tm->tm_year <= 69)
-		tm->tm_year += 100;
-
+	tm->tm_year += priv->epoch - 1900;
 	tm->tm_mon--;
 	return 0;
 }
@@ -108,18 +106,10 @@ static int m48t35_set_time(struct device *dev, struct rtc_time *tm)
 	min = tm->tm_min;
 	sec = tm->tm_sec;
 
-	if (yrs < 1970)
-		return -EINVAL;
-
-	yrs -= 1970;
-	if (yrs > 255)    /* They are unsigned */
+	if (yrs < priv->epoch || yrs >= priv->epoch + 100)
 		return -EINVAL;
 
-	if (yrs > 169)
-		return -EINVAL;
-
-	if (yrs >= 100)
-		yrs -= 100;
+	yrs -= priv->epoch;
 
 	sec = bin2bcd(sec);
 	min = bin2bcd(min);
@@ -164,6 +154,7 @@ static int m48t35_probe(struct platform_device *pdev)
 				     pdev->name))
 		return -EBUSY;
 
+	priv->epoch = platform_get_device_id(pdev)->driver_data;
 	priv->baseaddr = res->start;
 	priv->reg = devm_ioremap(&pdev->dev, priv->baseaddr, priv->size);
 	if (!priv->reg)
@@ -178,11 +169,20 @@ static int m48t35_probe(struct platform_device *pdev)
 	return PTR_ERR_OR_ZERO(priv->rtc);
 }
 
+/* The year register on SGI IP35-family machines counts from 1968. */
+static const struct platform_device_id m48t35_id_table[] = {
+	{ "rtc-m48t35", 1970 },
+	{ "rtc-m48t35-ip35", 1968 },
+	{ }
+};
+MODULE_DEVICE_TABLE(platform, m48t35_id_table);
+
 static struct platform_driver m48t35_platform_driver = {
 	.driver		= {
 		.name	= "rtc-m48t35",
 	},
 	.probe		= m48t35_probe,
+	.id_table	= m48t35_id_table,
 };
 
 module_platform_driver(m48t35_platform_driver);
@@ -191,3 +191,4 @@ MODULE_AUTHOR("Thomas Bogendoerfer <tsbogend@alpha.franken.de>");
 MODULE_DESCRIPTION("M48T35 RTC driver");
 MODULE_LICENSE("GPL");
 MODULE_ALIAS("platform:rtc-m48t35");
+MODULE_ALIAS("platform:rtc-m48t35-ip35");
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 26/38] mfd: ioc3: add support for IOC4
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (24 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 25/38] rtc: m48t35: support the SGI IP35 timekeeper's 1968 year base Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 27/38] MIPS: SGI-IP27: dispatch the early console between IOC3 and IOC4 Imre Kaloz
                   ` (11 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer
  Cc: linux-mips, linux-kernel, Lee Jones, Greg Kroah-Hartman,
	Jiri Slaby, mfd, linux-serial

IOC4 is IOC3's successor on IP35 Origin 350-class boards. Its serial and
PS/2 cores reuse IOC3's drivers and its interrupt status splits into two
banks.

The serial, interrupt and GPIO register definitions in asm/sn/ioc4.h
follow include/linux/ioc4.h and drivers/tty/serial/ioc4_serial.c, removed
by commit f7bc6e42bf12 ("drivers: remove the SGI SN2 IOC4 base support")
and commit a017ef17cfd8 ("tty/serial: remove the ioc4_serial driver").

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/sn/ioc4.h               | 130 ++++++++
 drivers/mfd/ioc3.c                            | 289 +++++++++++++++---
 drivers/tty/serial/8250/8250_ioc3.c           |   5 +-
 include/linux/platform_data/sgi-ioc3-serial.h |  13 +
 4 files changed, 391 insertions(+), 46 deletions(-)
 create mode 100644 arch/mips/include/asm/sn/ioc4.h
 create mode 100644 include/linux/platform_data/sgi-ioc3-serial.h

diff --git a/arch/mips/include/asm/sn/ioc4.h b/arch/mips/include/asm/sn/ioc4.h
new file mode 100644
index 000000000000..fca363c10035
--- /dev/null
+++ b/arch/mips/include/asm/sn/ioc4.h
@@ -0,0 +1,130 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+/*
+ * IOC4 -- SGI's I/O ASIC on Tezro/Origin 350-class boards.
+ *
+ * Copyright (C) 2003-2006 Silicon Graphics, Inc.
+ */
+#ifndef MIPS_SN_IOC4_H
+#define MIPS_SN_IOC4_H
+
+#include <linux/types.h>
+
+struct ioc4_serialregs {
+	u32	sscr;
+	u32	stpir;
+	u32	stcir;
+	u32	srpir;
+	u32	srcir;
+	u32	srtr;
+	u32	shadow;
+};
+
+struct ioc4_uartregs {
+	u8	i4u_lcr;
+	union {
+		u8	i4u_iir;	/* read only */
+		u8	i4u_fcr;	/* write only */
+	};
+	union {
+		u8	i4u_ier;	/* DLAB == 0 */
+		u8	i4u_dlm;	/* DLAB == 1 */
+	};
+	union {
+		u8	i4u_rbr;	/* read only, DLAB == 0 */
+		u8	i4u_thr;	/* write only, DLAB == 0 */
+		u8	i4u_dll;	/* DLAB == 1 */
+	};
+	u8	i4u_scr;
+	u8	i4u_msr;
+	u8	i4u_lsr;
+	u8	i4u_mcr;
+};
+
+struct ioc4_serioregs {
+	u32	km_csr;
+	u32	k_rd;
+	u32	m_rd;
+	u32	k_wd;
+	u32	m_wd;
+};
+
+/* Register layout of IOC4 in PCI BAR0. */
+struct ioc4 {
+	u32	pci_err_addr_l;	/* 0x00000 */
+	u32	pci_err_addr_h;	/* 0x00004 */
+	u32	sio_ir;		/* 0x00008 */
+	u32	other_ir;	/* 0x0000c */
+	u32	sio_ies;	/* 0x00010 */
+	u32	other_ies;	/* 0x00014 */
+	u32	sio_iec;	/* 0x00018 */
+	u32	other_iec;	/* 0x0001c */
+	u32	sio_cr;		/* 0x00020 */
+	u32	pad0;		/* 0x00024 */
+	u32	int_out;	/* 0x00028 */
+	u32	pad1;		/* 0x0002c */
+	u32	gpcr_s;		/* 0x00030 */
+	u32	gpcr_c;		/* 0x00034 */
+	u32	gpdr;		/* 0x00038 */
+	u32	pad2;		/* 0x0003c */
+	u32	gppr[8];	/* 0x00040 */
+
+	u32	pad3[(0x200 - 0x60) / 4];
+
+	struct ioc4_serioregs	serio;	/* 0x00200, IOC4_KBC_BASE */
+
+	u32	pad4[(0x300 - 0x214) / 4];
+
+	u32	sbbr01_l;	/* 0x00300 */
+	u32	sbbr01_h;	/* 0x00304 */
+	u32	sbbr23_l;	/* 0x00308 */
+	u32	sbbr23_h;	/* 0x0030c */
+
+	struct ioc4_serialregs	port[4];	/* 0x00310 */
+	struct ioc4_uartregs	uart[4];	/* 0x00380 */
+};
+
+/* Bytebus device 0, where the TOD chip sits. */
+#define IOC4_BYTEBUS_DEV0	0x80000L
+
+/* sio_ir carries serial events only, one 8-bit group per port. */
+#define IOC4_SIO_IR_TX_MT	0x01	/* TX ring buffer empty */
+#define IOC4_SIO_IR_RX_FULL	0x02	/* RX ring buffer full */
+#define IOC4_SIO_IR_RX_HIGH	0x04	/* RX high-water exceeded */
+#define IOC4_SIO_IR_RX_TIMER	0x08	/* RX timer has triggered */
+#define IOC4_SIO_IR_DELTA_DCD	0x10	/* DELTA_DCD seen */
+#define IOC4_SIO_IR_DELTA_CTS	0x20	/* DELTA_CTS seen */
+#define IOC4_SIO_IR_INT		0x40	/* UART pass-through interrupt */
+#define IOC4_SIO_IR_TX_EXPLICIT	0x80	/* TX, MCW, or delay complete */
+
+#define IOC4_SIO_IR_PORT_SHIFT(port)	((port) * 8)
+#define IOC4_SIO_IR_PORT_INT(port) \
+	(IOC4_SIO_IR_INT << IOC4_SIO_IR_PORT_SHIFT(port))
+
+/* Bit index of IOC4_SIO_IR_INT; DEFINE_RES_IRQ() needs a constant. */
+#define IOC4_SIO_IR_INT_BIT		6
+#define IOC4_SIO_IR_PORT_INT_BIT(port) \
+	(IOC4_SIO_IR_PORT_SHIFT(port) + IOC4_SIO_IR_INT_BIT)
+
+#define IOC4_OTHER_IR_ATA_INT		0x00000001	/* ATA passthru */
+#define IOC4_OTHER_IR_ATA_MEMERR	0x00000002	/* ATA PCI error */
+#define IOC4_OTHER_IR_S0_MEMERR		0x00000004	/* port 0 PCI error */
+#define IOC4_OTHER_IR_S1_MEMERR		0x00000008	/* port 1 PCI error */
+#define IOC4_OTHER_IR_S2_MEMERR		0x00000010	/* port 2 PCI error */
+#define IOC4_OTHER_IR_S3_MEMERR		0x00000020	/* port 3 PCI error */
+/* The IX-brick wires this bit to the PS/2 ports. */
+#define IOC4_OTHER_IR_KBD_INT		0x00000040
+#define IOC4_OTHER_IR_RT_INT		0x00800000	/* INT_OUT latch */
+#define IOC4_OTHER_IR_GEN_INT		0xff000000	/* generic pins */
+
+#define IOC4_OTHER_IR_KBD_INT_BIT	6	/* bit index */
+
+#define IOC4_SSCR_DMA_EN	0x10000000	/* enable ring buffer DMA */
+
+/* GPIO pins 4-7 select RS232 or RS422 mode for the four UARTs. */
+#define IOC4_GPCR_UART_MODESEL(port)		(0x10 << (port))
+#define IOC4_GPPR_UART_MODESEL_PIN(port)	(4 + (port))
+
+/* The serial core runs off the PCI bus clock, 66MHz in the IX-brick. */
+#define IOC4_UARTCLK	66666667
+
+#endif /* MIPS_SN_IOC4_H */
diff --git a/drivers/mfd/ioc3.c b/drivers/mfd/ioc3.c
index 5f8ac364b610..fd50bae0f10b 100644
--- a/drivers/mfd/ioc3.c
+++ b/drivers/mfd/ioc3.c
@@ -19,11 +19,13 @@
 #include <linux/module.h>
 #include <linux/pci.h>
 #include <linux/platform_device.h>
+#include <linux/platform_data/sgi-ioc3-serial.h>
 #include <linux/platform_data/sgi-w1.h>
 #include <linux/rtc/ds1685.h>
 
 #include <asm/pci/bridge.h>
 #include <asm/sn/ioc3.h>
+#include <asm/sn/ioc4.h>
 
 #define IOC3_IRQ_SERIAL_A	6
 #define IOC3_IRQ_SERIAL_B	15
@@ -37,9 +39,33 @@
 /* 1.2 us latency timer (40 cycles at 33 MHz) */
 #define IOC3_LATENCY	40
 
+struct ioc3_priv_data;
+
+/*
+ * One interrupt bank: an ir/ies/iec register triplet covering 32 hwirqs.
+ * IOC3 has a single bank. IOC4 keeps only the four serial ports in
+ * sio_ir and moves ATA, memory-error, keyboard, RT and generic-pin
+ * events into a second bank, other_ir.
+ */
+struct ioc3_irq_bank {
+	u16 ir, ies, iec;	/* BAR0 offsets */
+	u32 lvl_mask;		/* hwirqs needing level-triggered handling */
+};
+
+struct ioc3_variant {
+	const char *name;
+	struct irq_chip *chip;
+	const struct ioc3_irq_bank *banks;
+	unsigned int nr_banks;
+	unsigned int nr_irqs;
+	u16 pci_command;	/* extra PCI_COMMAND bits to set at probe */
+	int (*setup)(struct ioc3_priv_data *ipd);
+};
+
 struct ioc3_priv_data {
 	struct irq_domain *domain;
-	struct ioc3 __iomem *regs;
+	void __iomem *base;
+	const struct ioc3_variant *var;
 	struct pci_dev *pdev;
 	int domain_irq;
 };
@@ -48,24 +74,27 @@ static void ioc3_irq_ack(struct irq_data *d)
 {
 	struct ioc3_priv_data *ipd = irq_data_get_irq_chip_data(d);
 	unsigned int hwirq = irqd_to_hwirq(d);
+	const struct ioc3_irq_bank *bank = &ipd->var->banks[hwirq / 32];
 
-	writel(BIT(hwirq), &ipd->regs->sio_ir);
+	writel(BIT(hwirq % 32), ipd->base + bank->ir);
 }
 
 static void ioc3_irq_mask(struct irq_data *d)
 {
 	struct ioc3_priv_data *ipd = irq_data_get_irq_chip_data(d);
 	unsigned int hwirq = irqd_to_hwirq(d);
+	const struct ioc3_irq_bank *bank = &ipd->var->banks[hwirq / 32];
 
-	writel(BIT(hwirq), &ipd->regs->sio_iec);
+	writel(BIT(hwirq % 32), ipd->base + bank->iec);
 }
 
 static void ioc3_irq_unmask(struct irq_data *d)
 {
 	struct ioc3_priv_data *ipd = irq_data_get_irq_chip_data(d);
 	unsigned int hwirq = irqd_to_hwirq(d);
+	const struct ioc3_irq_bank *bank = &ipd->var->banks[hwirq / 32];
 
-	writel(BIT(hwirq), &ipd->regs->sio_ies);
+	writel(BIT(hwirq % 32), ipd->base + bank->ies);
 }
 
 static struct irq_chip ioc3_irq_chip = {
@@ -75,16 +104,25 @@ static struct irq_chip ioc3_irq_chip = {
 	.irq_unmask	= ioc3_irq_unmask,
 };
 
+static struct irq_chip ioc4_irq_chip = {
+	.name		= "IOC4",
+	.irq_ack	= ioc3_irq_ack,
+	.irq_mask	= ioc3_irq_mask,
+	.irq_unmask	= ioc3_irq_unmask,
+};
+
 static int ioc3_irq_domain_map(struct irq_domain *d, unsigned int irq,
 			      irq_hw_number_t hwirq)
 {
-	/* Set level IRQs for every interrupt contained in IOC3_LVL_MASK */
-	if (BIT(hwirq) & IOC3_LVL_MASK)
-		irq_set_chip_and_handler(irq, &ioc3_irq_chip, handle_level_irq);
+	struct ioc3_priv_data *ipd = d->host_data;
+	const struct ioc3_irq_bank *bank = &ipd->var->banks[hwirq / 32];
+
+	if (BIT(hwirq % 32) & bank->lvl_mask)
+		irq_set_chip_and_handler(irq, ipd->var->chip, handle_level_irq);
 	else
-		irq_set_chip_and_handler(irq, &ioc3_irq_chip, handle_edge_irq);
+		irq_set_chip_and_handler(irq, ipd->var->chip, handle_edge_irq);
 
-	irq_set_chip_data(irq, d->host_data);
+	irq_set_chip_data(irq, ipd);
 	return 0;
 }
 
@@ -103,17 +141,21 @@ static void ioc3_irq_handler(struct irq_desc *desc)
 {
 	struct irq_domain *domain = irq_desc_get_handler_data(desc);
 	struct ioc3_priv_data *ipd = domain->host_data;
-	struct ioc3 __iomem *regs = ipd->regs;
-	u32 pending, mask;
+	unsigned int i;
 
-	pending = readl(&regs->sio_ir);
-	mask = readl(&regs->sio_ies);
-	pending &= mask; /* Mask off not enabled interrupts */
+	for (i = 0; i < ipd->var->nr_banks; i++) {
+		const struct ioc3_irq_bank *bank = &ipd->var->banks[i];
+		u32 pending = readl(ipd->base + bank->ir) &
+			      readl(ipd->base + bank->ies);
 
-	if (pending)
-		generic_handle_domain_irq(domain, __ffs(pending));
-	else
-		spurious_interrupt();
+		if (pending) {
+			generic_handle_domain_irq(domain,
+						  i * 32 + __ffs(pending));
+			return;
+		}
+	}
+
+	spurious_interrupt();
 }
 
 /*
@@ -134,11 +176,12 @@ static int ioc3_irq_domain_setup(struct ioc3_priv_data *ipd, int irq)
 	struct irq_domain *domain;
 	struct fwnode_handle *fn;
 
-	fn = irq_domain_alloc_named_fwnode("IOC3");
+	fn = irq_domain_alloc_named_fwnode(ipd->var->name);
 	if (!fn)
 		goto err;
 
-	domain = irq_domain_create_linear(fn, 24, &ioc3_irq_domain_ops, ipd);
+	domain = irq_domain_create_linear(fn, ipd->var->nr_irqs,
+					  &ioc3_irq_domain_ops, ipd);
 	if (!domain) {
 		irq_domain_free_fwnode(fn);
 		goto err;
@@ -182,21 +225,19 @@ static struct mfd_cell ioc3_serial_cells[] = {
 
 static int ioc3_serial_setup(struct ioc3_priv_data *ipd)
 {
+	struct ioc3 __iomem *regs = ipd->base;
 	int ret;
 
 	/* Set gpio pins for RS232/RS422 mode selection */
-	writel(GPCR_UARTA_MODESEL | GPCR_UARTB_MODESEL,
-		&ipd->regs->gpcr_s);
+	writel(GPCR_UARTA_MODESEL | GPCR_UARTB_MODESEL, &regs->gpcr_s);
 	/* Select RS232 mode for uart a */
-	writel(0, &ipd->regs->gppr[6]);
+	writel(0, &regs->gppr[6]);
 	/* Select RS232 mode for uart b */
-	writel(0, &ipd->regs->gppr[7]);
+	writel(0, &regs->gppr[7]);
 
 	/* Switch both ports to 16650 mode */
-	writel(readl(&ipd->regs->port_a.sscr) & ~SSCR_DMA_EN,
-	       &ipd->regs->port_a.sscr);
-	writel(readl(&ipd->regs->port_b.sscr) & ~SSCR_DMA_EN,
-	       &ipd->regs->port_b.sscr);
+	writel(readl(&regs->port_a.sscr) & ~SSCR_DMA_EN, &regs->port_a.sscr);
+	writel(readl(&regs->port_b.sscr) & ~SSCR_DMA_EN, &regs->port_b.sscr);
 	udelay(1000); /* Wait until mode switch is done */
 
 	ret = mfd_add_devices(&ipd->pdev->dev, PLATFORM_DEVID_AUTO,
@@ -270,10 +311,11 @@ static struct mfd_cell ioc3_eth_cells[] = {
 
 static int ioc3_eth_setup(struct ioc3_priv_data *ipd)
 {
+	struct ioc3 __iomem *regs = ipd->base;
 	int ret;
 
 	/* Enable One-Wire bus */
-	writel(GPCR_MLAN_EN, &ipd->regs->gpcr_s);
+	writel(GPCR_MLAN_EN, &regs->gpcr_s);
 
 	/* Generate unique identifier */
 	snprintf(ioc3_w1_platform_data.dev_id,
@@ -539,14 +581,12 @@ static struct {
 
 static int ioc3_setup(struct ioc3_priv_data *ipd)
 {
+	struct ioc3 __iomem *regs = ipd->base;
 	u32 sid;
 	int i;
 
-	/* Clear IRQs */
-	writel(~0, &ipd->regs->sio_iec);
-	writel(~0, &ipd->regs->sio_ir);
-	writel(0, &ipd->regs->eth.eier);
-	writel(~0, &ipd->regs->eth.eisr);
+	writel(0, &regs->eth.eier);
+	writel(~0, &regs->eth.eisr);
 
 	/* Read subsystem vendor id and subsystem id */
 	pci_read_config_dword(ipd->pdev, PCI_SUBSYSTEM_VENDOR_ID, &sid);
@@ -565,8 +605,11 @@ static int ioc3_setup(struct ioc3_priv_data *ipd)
 static int ioc3_mfd_probe(struct pci_dev *pdev,
 			  const struct pci_device_id *pci_id)
 {
+	const struct ioc3_variant *var = (void *)pci_id->driver_data;
 	struct ioc3_priv_data *ipd;
-	struct ioc3 __iomem *regs;
+	void __iomem *base;
+	unsigned int i;
+	u16 cmd;
 	int ret;
 
 	ret = pci_enable_device(pdev);
@@ -576,6 +619,12 @@ static int ioc3_mfd_probe(struct pci_dev *pdev,
 	pci_write_config_byte(pdev, PCI_LATENCY_TIMER, IOC3_LATENCY);
 	pci_set_master(pdev);
 
+	if (var->pci_command) {
+		pci_read_config_word(pdev, PCI_COMMAND, &cmd);
+		pci_write_config_word(pdev, PCI_COMMAND,
+				      cmd | var->pci_command);
+	}
+
 	ret = dma_set_mask_and_coherent(&pdev->dev, DMA_BIT_MASK(64));
 	if (ret) {
 		pr_err("%s: No usable DMA configuration, aborting.\n",
@@ -591,24 +640,31 @@ static int ioc3_mfd_probe(struct pci_dev *pdev,
 		goto out_disable_device;
 	}
 	ipd->pdev = pdev;
+	ipd->var = var;
 
 	/*
 	 * Map all IOC3 registers.  These are shared between subdevices
 	 * so the main IOC3 module manages them.
 	 */
-	regs = pci_ioremap_bar(pdev, 0);
-	if (!regs) {
+	base = pci_ioremap_bar(pdev, 0);
+	if (!base) {
 		dev_warn(&pdev->dev, "ioc3: Unable to remap PCI BAR for %s.\n",
 			 pci_name(pdev));
 		ret = -ENOMEM;
 		goto out_disable_device;
 	}
-	ipd->regs = regs;
+	ipd->base = base;
 
 	/* Track PCI-device specific data */
 	pci_set_drvdata(pdev, ipd);
 
-	ret = ioc3_setup(ipd);
+	/* Clear IRQs */
+	for (i = 0; i < var->nr_banks; i++) {
+		writel(~0, base + var->banks[i].iec);
+		writel(~0, base + var->banks[i].ir);
+	}
+
+	ret = var->setup(ipd);
 	if (ret) {
 		/* Remove all already added MFD devices */
 		mfd_remove_devices(&ipd->pdev->dev);
@@ -619,7 +675,7 @@ static int ioc3_mfd_probe(struct pci_dev *pdev,
 			irq_domain_free_fwnode(fn);
 			free_irq(ipd->domain_irq, (void *)ipd);
 		}
-		pci_iounmap(pdev, regs);
+		pci_iounmap(pdev, base);
 		goto out_disable_device;
 	}
 
@@ -633,12 +689,15 @@ static int ioc3_mfd_probe(struct pci_dev *pdev,
 static void ioc3_mfd_remove(struct pci_dev *pdev)
 {
 	struct ioc3_priv_data *ipd;
+	unsigned int i;
 
 	ipd = pci_get_drvdata(pdev);
 
 	/* Clear and disable all IRQs */
-	writel(~0, &ipd->regs->sio_iec);
-	writel(~0, &ipd->regs->sio_ir);
+	for (i = 0; i < ipd->var->nr_banks; i++) {
+		writel(~0, ipd->base + ipd->var->banks[i].iec);
+		writel(~0, ipd->base + ipd->var->banks[i].ir);
+	}
 
 	/* Release resources */
 	mfd_remove_devices(&ipd->pdev->dev);
@@ -649,12 +708,152 @@ static void ioc3_mfd_remove(struct pci_dev *pdev)
 		irq_domain_free_fwnode(fn);
 		free_irq(ipd->domain_irq, (void *)ipd);
 	}
-	pci_iounmap(pdev, ipd->regs);
+	pci_iounmap(pdev, ipd->base);
 	pci_disable_device(pdev);
 }
 
+static const struct ioc3_irq_bank ioc3_irq_banks[] = {
+	{
+		.ir = offsetof(struct ioc3, sio_ir),
+		.ies = offsetof(struct ioc3, sio_ies),
+		.iec = offsetof(struct ioc3, sio_iec),
+		.lvl_mask = IOC3_LVL_MASK,
+	},
+};
+
+static const struct ioc3_variant ioc3_variant = {
+	.name = "IOC3",
+	.chip = &ioc3_irq_chip,
+	.banks = ioc3_irq_banks,
+	.nr_banks = ARRAY_SIZE(ioc3_irq_banks),
+	.nr_irqs = 24,
+	.setup = ioc3_setup,
+};
+
+#define IOC4_NUM_PORTS		4
+
+/* hwirqs 0-31 are sio_ir's, 32-63 other_ir's. */
+#define IOC4_IRQ_OTHER_BASE	32
+#define IOC4_NUM_IRQS		64
+
+/* Only the four ports' UART pass-through bits are level triggered. */
+#define IOC4_LVL_MASK \
+	(IOC4_SIO_IR_PORT_INT(0) | IOC4_SIO_IR_PORT_INT(1) | \
+	 IOC4_SIO_IR_PORT_INT(2) | IOC4_SIO_IR_PORT_INT(3))
+
+#define IOC4_UART_RES(port) {						\
+	DEFINE_RES_MEM(offsetof(struct ioc4, uart[port]),		\
+		       sizeof_field(struct ioc4, uart[port])),		\
+	DEFINE_RES_IRQ(IOC4_SIO_IR_PORT_INT_BIT(port)),			\
+}
+
+static const struct resource ioc4_uart_resources[][2] = {
+	IOC4_UART_RES(0),
+	IOC4_UART_RES(1),
+	IOC4_UART_RES(2),
+	IOC4_UART_RES(3),
+};
+
+static const struct resource ioc4_kbd_resources[] = {
+	DEFINE_RES_MEM(offsetof(struct ioc4, serio),
+		       sizeof_field(struct ioc4, serio)),
+	DEFINE_RES_IRQ(IOC4_IRQ_OTHER_BASE + IOC4_OTHER_IR_KBD_INT_BIT)
+};
+
+static const struct resource ioc4_rtc_resources[] = {
+	DEFINE_RES_MEM(IOC4_BYTEBUS_DEV0, M48T35_REG_SIZE)
+};
+
+static const struct ioc3_serial8250_platform_data ioc4_serial_pdata = {
+	.uartclk = IOC4_UARTCLK,
+};
+
+#define IOC4_SERIAL_CELL(port) {					\
+	.name = "ioc3-serial8250",					\
+	.resources = ioc4_uart_resources[port],				\
+	.num_resources = ARRAY_SIZE(ioc4_uart_resources[port]),		\
+	.platform_data = &ioc4_serial_pdata,				\
+	.pdata_size = sizeof(ioc4_serial_pdata),			\
+}
+
+static struct mfd_cell ioc4_cells[] = {
+	IOC4_SERIAL_CELL(0),
+	IOC4_SERIAL_CELL(1),
+	IOC4_SERIAL_CELL(2),
+	IOC4_SERIAL_CELL(3),
+	{
+		.name = "ioc3-kbd",
+		.resources = ioc4_kbd_resources,
+		.num_resources = ARRAY_SIZE(ioc4_kbd_resources),
+	},
+	{
+		.name = "rtc-m48t35-ip35",
+		.resources = ioc4_rtc_resources,
+		.num_resources = ARRAY_SIZE(ioc4_rtc_resources),
+	},
+};
+
+static int ioc4_setup(struct ioc3_priv_data *ipd)
+{
+	struct ioc4 __iomem *regs = ipd->base;
+	int ret, i;
+
+	ret = ioc3_irq_domain_setup(ipd, ipd->pdev->irq);
+	if (ret)
+		return ret;
+
+	/* Set gpio pins for RS232/RS422 mode selection */
+	writel(IOC4_GPCR_UART_MODESEL(0) | IOC4_GPCR_UART_MODESEL(1) |
+	       IOC4_GPCR_UART_MODESEL(2) | IOC4_GPCR_UART_MODESEL(3),
+	       &regs->gpcr_s);
+
+	for (i = 0; i < IOC4_NUM_PORTS; i++) {
+		/* Select RS232 mode, and switch the port to 16650 mode */
+		writel(0, &regs->gppr[IOC4_GPPR_UART_MODESEL_PIN(i)]);
+		writel(readl(&regs->port[i].sscr) & ~IOC4_SSCR_DMA_EN,
+		       &regs->port[i].sscr);
+	}
+	udelay(1000); /* Wait until mode switch is done */
+
+	ret = mfd_add_devices(&ipd->pdev->dev, PLATFORM_DEVID_AUTO,
+			      ioc4_cells, ARRAY_SIZE(ioc4_cells),
+			      &ipd->pdev->resource[0], 0, ipd->domain);
+	if (ret)
+		dev_err(&ipd->pdev->dev, "Failed to add IOC4 subdevs\n");
+
+	return ret;
+}
+
+static const struct ioc3_irq_bank ioc4_irq_banks[] = {
+	{
+		.ir = offsetof(struct ioc4, sio_ir),
+		.ies = offsetof(struct ioc4, sio_ies),
+		.iec = offsetof(struct ioc4, sio_iec),
+		.lvl_mask = IOC4_LVL_MASK,
+	},
+	{
+		.ir = offsetof(struct ioc4, other_ir),
+		.ies = offsetof(struct ioc4, other_ies),
+		.iec = offsetof(struct ioc4, other_iec),
+	},
+};
+
+static const struct ioc3_variant ioc4_variant = {
+	.name = "IOC4",
+	.chip = &ioc4_irq_chip,
+	.banks = ioc4_irq_banks,
+	.nr_banks = ARRAY_SIZE(ioc4_irq_banks),
+	.nr_irqs = IOC4_NUM_IRQS,
+	/* Parity and SERR# reporting, as the SN2 IOC4 core enabled them. */
+	.pci_command = PCI_COMMAND_PARITY | PCI_COMMAND_SERR,
+	.setup = ioc4_setup,
+};
+
 static struct pci_device_id ioc3_mfd_id_table[] = {
-	{ PCI_VENDOR_ID_SGI, PCI_DEVICE_ID_SGI_IOC3, PCI_ANY_ID, PCI_ANY_ID },
+	{ PCI_VENDOR_ID_SGI, PCI_DEVICE_ID_SGI_IOC3, PCI_ANY_ID, PCI_ANY_ID,
+	  0, 0, (kernel_ulong_t)&ioc3_variant },
+	{ PCI_VENDOR_ID_SGI, 0x100a, PCI_ANY_ID, PCI_ANY_ID,
+	  0, 0, (kernel_ulong_t)&ioc4_variant },
 	{ 0, },
 };
 MODULE_DEVICE_TABLE(pci, ioc3_mfd_id_table);
@@ -669,5 +868,5 @@ static struct pci_driver ioc3_mfd_driver = {
 module_pci_driver(ioc3_mfd_driver);
 
 MODULE_AUTHOR("Thomas Bogendoerfer <tbogendoerfer@suse.de>");
-MODULE_DESCRIPTION("SGI IOC3 MFD driver");
+MODULE_DESCRIPTION("SGI IOC3/IOC4 MFD driver");
 MODULE_LICENSE("GPL v2");
diff --git a/drivers/tty/serial/8250/8250_ioc3.c b/drivers/tty/serial/8250/8250_ioc3.c
index 28e28076782b..5d3c0190f19e 100644
--- a/drivers/tty/serial/8250/8250_ioc3.c
+++ b/drivers/tty/serial/8250/8250_ioc3.c
@@ -11,6 +11,7 @@
 #include <linux/module.h>
 #include <linux/errno.h>
 #include <linux/io.h>
+#include <linux/platform_data/sgi-ioc3-serial.h>
 #include <linux/platform_device.h>
 
 #include "8250.h"
@@ -33,6 +34,7 @@ static void ioc3_serial_out(struct uart_port *p, unsigned int offset, u32 value)
 
 static int serial8250_ioc3_probe(struct platform_device *pdev)
 {
+	const struct ioc3_serial8250_platform_data *pdata;
 	struct ioc3_8250_data *data;
 	struct uart_8250_port up;
 	struct resource *r;
@@ -56,9 +58,10 @@ static int serial8250_ioc3_probe(struct platform_device *pdev)
 		irq = 0; /* no interrupt -> use polling */
 
 	/* Register serial ports with 8250.c */
+	pdata = dev_get_platdata(&pdev->dev);
 	memset(&up, 0, sizeof(struct uart_8250_port));
 	up.port.iotype = UPIO_MEM;
-	up.port.uartclk = IOC3_UARTCLK;
+	up.port.uartclk = pdata ? pdata->uartclk : IOC3_UARTCLK;
 	up.port.type = PORT_16550A;
 	up.port.irq = irq;
 	up.port.flags = (UPF_BOOT_AUTOCONF | UPF_SHARE_IRQ);
diff --git a/include/linux/platform_data/sgi-ioc3-serial.h b/include/linux/platform_data/sgi-ioc3-serial.h
new file mode 100644
index 000000000000..ae4690f33125
--- /dev/null
+++ b/include/linux/platform_data/sgi-ioc3-serial.h
@@ -0,0 +1,13 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+/*
+ * SGI IOC3/IOC4 8250-compatible UART cells
+ */
+
+#ifndef PLATFORM_DATA_SGI_IOC3_SERIAL_H
+#define PLATFORM_DATA_SGI_IOC3_SERIAL_H
+
+struct ioc3_serial8250_platform_data {
+	unsigned int uartclk;
+};
+
+#endif /* PLATFORM_DATA_SGI_IOC3_SERIAL_H */
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 27/38] MIPS: SGI-IP27: dispatch the early console between IOC3 and IOC4
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (25 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 26/38] mfd: ioc3: add support for IOC4 Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 28/38] MIPS: SGI-IP27: add L1 system controller support Imre Kaloz
                   ` (10 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

ip27-console.c casts the console UART to struct ioc3 unconditionally,
wrong for a Tezro's IOC4, whose UARTs sit at other offsets.

console_t.type reads back 0x0300fafa there, neither chip's PCI id, so on
IP35 dispatch on uart_base, which both chips populate correctly. A Hub
keeps the IOC3 path.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-console.c | 47 ++++++++++++++++++++++++++++++-
 1 file changed, 46 insertions(+), 1 deletion(-)

diff --git a/arch/mips/sgi-ip27/ip27-console.c b/arch/mips/sgi-ip27/ip27-console.c
index 7737a88c6569..a1bcb4376f66 100644
--- a/arch/mips/sgi-ip27/ip27-console.c
+++ b/arch/mips/sgi-ip27/ip27-console.c
@@ -12,6 +12,7 @@
 #include <asm/sn/agent.h>
 #include <asm/sn/klconfig.h>
 #include <asm/sn/ioc3.h>
+#include <asm/sn/ioc4.h>
 
 #include <linux/serial.h>
 #include <linux/serial_core.h>
@@ -32,9 +33,53 @@ static inline struct ioc3_uartregs *console_uart(void)
 	return &ioc3->sregs.uarta;
 }
 
+/*
+ * On IP35 a Tezro drives its console off IOC4, a Fuel off IOC3.
+ * console_t.type cannot tell them apart -- a Tezro reads it back as
+ * 0x0300fafa, which is neither chip's PCI id -- while uart_base is
+ * populated on both, so dispatch on whether that lands on IOC3's own UART.
+ */
+static inline bool console_is_ioc4(nasid_t nasid)
+{
+	unsigned long uart_base;
+
+	if (!system_is_ip35)
+		return false;
+
+	uart_base = KL_CONFIG_CH_CONS_INFO(nasid)->uart_base;
+	if (!uart_base)
+		return false;
+
+	/* NODE_SWIN_ADDR() aliases widget 0 away; the console sits on 0xf. */
+	if (uart_base < RAW_NODE_SWIN_BASE(nasid, 0) ||
+	    uart_base >= RAW_NODE_SWIN_BASE(nasid, SWIN_WIDGET_MASK) +
+			 SWIN_SIZE)
+		return false;
+
+	return uart_base != (unsigned long)console_uart();
+}
+
+static inline struct ioc4_uartregs *console_uart_ioc4(nasid_t nasid)
+{
+	return (struct ioc4_uartregs *)KL_CONFIG_CH_CONS_INFO(nasid)->uart_base;
+}
+
 void prom_putchar(char c)
 {
-	struct ioc3_uartregs *uart = console_uart();
+	struct ioc3_uartregs *uart;
+	nasid_t nasid;
+
+	nasid = (master_nasid == INVALID_NASID) ? get_nasid() : master_nasid;
+	if (console_is_ioc4(nasid)) {
+		struct ioc4_uartregs *ioc4_uart = console_uart_ioc4(nasid);
+
+		while ((readb(&ioc4_uart->i4u_lsr) & 0x20) == 0)
+			;
+		writeb(c, &ioc4_uart->i4u_thr);
+		return;
+	}
+
+	uart = console_uart();
 
 	while ((readb(&uart->iu_lsr) & 0x20) == 0)
 		;
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 28/38] MIPS: SGI-IP27: add L1 system controller support
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (26 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 27/38] MIPS: SGI-IP27: dispatch the early console between IOC3 and IOC4 Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 29/38] MIPS: SGI-IP27: wire the L1 into reset and the Ethernet address Imre Kaloz
                   ` (9 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

IP35-family (Bedrock hub) machines carry an L1 system controller on a
polled UART with RFC 1662 async-HDLC framing. Add the transport, the
request/response core and l1_exec_command(); on a Hub every request
fails with -ENODEV.

Ported from OpenBSD sys/arch/sgi/sgi/l1.c and licensed ISC like it,
keeping its notice.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/Kconfig             |   1 +
 arch/mips/include/asm/sn/l1.h |  14 ++
 arch/mips/sgi-ip27/Makefile   |   4 +-
 arch/mips/sgi-ip27/ip27-l1.c  | 423 ++++++++++++++++++++++++++++++++++
 4 files changed, 440 insertions(+), 2 deletions(-)
 create mode 100644 arch/mips/include/asm/sn/l1.h
 create mode 100644 arch/mips/sgi-ip27/ip27-l1.c

diff --git a/arch/mips/Kconfig b/arch/mips/Kconfig
index 20212194e763..348217328c9d 100644
--- a/arch/mips/Kconfig
+++ b/arch/mips/Kconfig
@@ -764,6 +764,7 @@ config SGI_IP27
 	select FW_ARC64
 	select ARC_CMDLINE_ONLY
 	select BOOT_ELF64
+	select CRC_CCITT
 	select DEFAULT_SGI_PARTITION
 	select FORCE_PCI
 	select SYS_HAS_EARLY_PRINTK
diff --git a/arch/mips/include/asm/sn/l1.h b/arch/mips/include/asm/sn/l1.h
new file mode 100644
index 000000000000..e61935e2fac8
--- /dev/null
+++ b/arch/mips/include/asm/sn/l1.h
@@ -0,0 +1,14 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+/*
+ * Entry points into the SGI L1 system controller driver.
+ *
+ * Copyright (C) 2026 Imre Kaloz <kaloz@kernel.org>
+ */
+#ifndef __ASM_SN_L1_H
+#define __ASM_SN_L1_H
+
+#include <linux/types.h>
+
+int l1_exec_command(const char *cmd);
+
+#endif /* __ASM_SN_L1_H */
diff --git a/arch/mips/sgi-ip27/Makefile b/arch/mips/sgi-ip27/Makefile
index 9877fcc512b1..4b6aa641ccc6 100644
--- a/arch/mips/sgi-ip27/Makefile
+++ b/arch/mips/sgi-ip27/Makefile
@@ -4,8 +4,8 @@
 #
 
 obj-y	:= ip27-berr.o ip27-irq.o ip27-init.o ip27-klconfig.o \
-	   ip27-klnuma.o ip27-memory.o ip27-nmi.o ip27-reset.o ip27-timer.o \
-	   ip27-xtalk.o
+	   ip27-klnuma.o ip27-l1.o ip27-memory.o ip27-nmi.o ip27-reset.o \
+	   ip27-timer.o ip27-xtalk.o
 
 obj-$(CONFIG_EARLY_PRINTK)	+= ip27-console.o
 obj-$(CONFIG_SMP)		+= ip27-smp.o
diff --git a/arch/mips/sgi-ip27/ip27-l1.c b/arch/mips/sgi-ip27/ip27-l1.c
new file mode 100644
index 000000000000..da3095b66cf1
--- /dev/null
+++ b/arch/mips/sgi-ip27/ip27-l1.c
@@ -0,0 +1,423 @@
+// SPDX-License-Identifier: ISC
+/*
+ * Copyright (C) 2026 Imre Kaloz <kaloz@kernel.org>
+ *
+ * SGI L1 system controller communication, ported from OpenBSD/sgi's
+ * l1.c:
+ *
+ * Copyright (c) 2009 Miodrag Vallat.
+ *
+ * Permission to use, copy, modify, and distribute this software for any
+ * purpose with or without fee is hereby granted, provided that the above
+ * copyright notice and this permission notice appear in all copies.
+ *
+ * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
+ * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
+ * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
+ * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
+ * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
+ * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
+ * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
+ *
+ * The L1 is the IP35-family (Bedrock hub) system controller, reached
+ * over a polled UART with async-HDLC (PPP) framing. Every request fails
+ * with -ENODEV on an IP27 (Hub) machine.
+ */
+#include <linux/kernel.h>
+#include <linux/errno.h>
+#include <linux/serial_reg.h>
+#include <linux/spinlock.h>
+#include <linux/stdarg.h>
+#include <linux/string.h>
+#include <linux/types.h>
+#include <linux/unaligned.h>
+#include <linux/crc-ccitt.h>
+#include <linux/io.h>
+
+#include <asm/sn/addrs.h>
+#include <asm/sn/agent.h>
+#include <asm/sn/l1.h>
+#include <asm/sn/types.h>
+
+/* packet types */
+#define L1PKT_REQUEST		0x00
+#define L1PKT_RESPONSE		0x20
+
+/* packet subchannels */
+#define L1CH_MISC		0x10	/* available for operating system */
+
+/* argument encoding */
+#define L1_ARG_INT		0x00	/* followed by 32 bit BE value */
+#define L1_ARG_ASCII		0x01	/* followed by NUL terminated string */
+#define L1_ARG_BINARY		0x80	/* length in low 7 bits */
+
+/* command types and destination addresses */
+#define L1_ADDRESS(type, addr)	(((type) << 28) | (addr))
+
+#define L1_TYPE_L1		0x00
+
+#define L1_ADDRESS_RACK_LOCAL	0x3ff
+#define L1_ADDRESS_RACK_SHIFT	18
+#define L1_ADDRESS_BAY_LOCAL	0x3f
+#define L1_ADDRESS_BAY_SHIFT	12
+
+#define L1_ADDRESS_LOCAL \
+	((L1_ADDRESS_RACK_LOCAL << L1_ADDRESS_RACK_SHIFT) | \
+	 (L1_ADDRESS_BAY_LOCAL << L1_ADDRESS_BAY_SHIFT))
+
+#define L1_TASK_COMMAND		0x03
+
+/* response codes */
+#define L1_RESP_OK		((u32)0)
+#define L1_RESP_NXDATA		((u32)-0x68)
+#define L1_RESP_INVAL		((u32)-0x6b)
+
+/* L1_TASK_COMMAND requests */
+#define L1_REQ_EXEC_CMD		0x0000	/* interpret plaintext command */
+
+/* Async-HDLC framing bytes; linux/ppp_defs.h would drag in skbuff.h. */
+#define L1_FLAG			0x7e
+#define L1_ESC			0x7d
+#define L1_TRANS		0x20
+#define L1_FCS_INIT		0xffff
+#define L1_FCS_GOOD		0xf0b8
+
+/* A raw iteration count, not a time bound: this can run before jiffies. */
+#define L1_POLL_ITERATIONS	1000000
+
+/*
+ * The L1 UART sits in the HSPEC "local register" window, reached
+ * through the "remote HSPEC" indirection even for the local node.
+ */
+#define L1_RHSPEC_OFFSET	0x20000000	/* remote-HSPEC indirection */
+#define L1_LREG_OFFSET		0x10000000	/* local register window */
+#define L1_UART_REG(r)		(L1_LREG_OFFSET + 0x80 + ((r) << 3))
+
+#define L1_UART_ADDRESS(nasid, r) \
+	((u64 *)(NODE_HSPEC_BASE(nasid) + L1_RHSPEC_OFFSET + L1_UART_REG(r)))
+
+static int l1_serial_getc(nasid_t nasid)
+{
+	unsigned int n;
+	u64 lsr;
+
+	for (n = L1_POLL_ITERATIONS; n != 0; n--) {
+		lsr = __raw_readq(L1_UART_ADDRESS(nasid, UART_LSR));
+		if (lsr & UART_LSR_DR)
+			break;
+		cpu_relax();
+	}
+	if (n == 0)
+		return -ETIMEDOUT;
+
+	return __raw_readq(L1_UART_ADDRESS(nasid, UART_RX)) & 0xff;
+}
+
+static int l1_serial_putc(nasid_t nasid, u8 val)
+{
+	unsigned int n;
+	u64 lsr;
+
+	for (n = L1_POLL_ITERATIONS; n != 0; n--) {
+		lsr = __raw_readq(L1_UART_ADDRESS(nasid, UART_LSR));
+		if (lsr & UART_LSR_THRE)
+			break;
+		cpu_relax();
+	}
+	if (n == 0)
+		return -ETIMEDOUT;
+
+	__raw_writeq(val, L1_UART_ADDRESS(nasid, UART_TX));
+	return 0;
+}
+
+static int l1_serial_ppp_write(nasid_t nasid, u16 *crc, u8 data, bool escape)
+{
+	int rc;
+
+	if (crc)
+		*crc = crc_ccitt_byte(*crc, data);
+
+	if (escape && (data == L1_FLAG || data == L1_ESC)) {
+		rc = l1_serial_putc(nasid, L1_ESC);
+		if (rc)
+			return rc;
+		data ^= L1_TRANS;
+	}
+
+	return l1_serial_putc(nasid, data);
+}
+
+static int l1_packet_put(nasid_t nasid, const u8 *packet, size_t len)
+{
+	u16 crc = L1_FCS_INIT;
+	int rc;
+
+	rc = l1_serial_ppp_write(nasid, NULL, L1_FLAG, false);
+	if (rc)
+		return rc;
+
+	while (len-- != 0) {
+		rc = l1_serial_ppp_write(nasid, &crc, *packet++, true);
+		if (rc)
+			return rc;
+	}
+
+	crc ^= L1_FCS_INIT;
+	rc = l1_serial_ppp_write(nasid, NULL, crc & 0xff, true);
+	if (rc)
+		return rc;
+	rc = l1_serial_ppp_write(nasid, NULL, (crc >> 8) & 0xff, true);
+	if (rc)
+		return rc;
+
+	return l1_serial_ppp_write(nasid, NULL, L1_FLAG, false);
+}
+
+static int l1_packet_get(nasid_t nasid, u8 *buf, size_t buflen, size_t *rlen)
+{
+	u16 crc;
+	size_t rcvlen;
+	int data;
+
+	for (;;) {
+		data = l1_serial_getc(nasid);
+		if (data < 0)
+			return data;
+		if (data == L1_FLAG)
+			break;
+	}
+
+	rcvlen = 0;
+	crc = L1_FCS_INIT;
+	for (;;) {
+		data = l1_serial_getc(nasid);
+		if (data < 0)
+			return data;
+		if (data == L1_FLAG)	/* end of packet */
+			break;
+		if (data == L1_ESC) {
+			data = l1_serial_getc(nasid);
+			if (data < 0)
+				return data;
+			data ^= L1_TRANS;
+		}
+		if (rcvlen < buflen)
+			buf[rcvlen] = data;
+		rcvlen++;
+		crc = crc_ccitt_byte(crc, data);
+	}
+
+	if (rcvlen > buflen)
+		return -EMSGSIZE;	/* did not fit the buffer */
+	if (rcvlen < 2)
+		return -EBADMSG;	/* short packet */
+
+	rcvlen -= 2;			/* crc bytes */
+	if (crc != L1_FCS_GOOD)
+		return -EBADMSG;	/* CRC error */
+
+	*rlen = rcvlen;
+	return 0;
+}
+
+/*
+ * Returns the would-be length even when the buffer is too small, and
+ * SIZE_MAX for an unknown argument type.
+ */
+static size_t l1_command_build(u8 *buf, size_t buflen, u32 address,
+			       u16 request, int nargs, va_list ap)
+{
+	u32 data;
+	size_t len = 0;
+	int argtype;
+	const char *str;
+
+	if (buflen >= 1) {
+		*buf++ = L1PKT_REQUEST | L1CH_MISC;
+		buflen--;
+	}
+	len++;
+
+	if (buflen >= 4) {
+		put_unaligned_be32(address, buf);
+		buf += 4;
+		buflen -= 4;
+	}
+	len += 4;
+
+	if (buflen >= 2) {
+		put_unaligned_be16(request, buf);
+		buf += 2;
+		buflen -= 2;
+	}
+	len += 2;
+
+	if (buflen >= 1) {
+		*buf++ = nargs;
+		buflen--;
+	}
+	len++;
+
+	while (nargs-- != 0) {
+		argtype = va_arg(ap, int);
+		switch (argtype) {
+		case L1_ARG_INT:
+			data = va_arg(ap, u32);
+			if (buflen >= 5) {
+				*buf++ = L1_ARG_INT;
+				put_unaligned_be32(data, buf);
+				buf += 4;
+				buflen -= 5;
+			}
+			len += 5;
+			break;
+		case L1_ARG_ASCII:
+			str = va_arg(ap, const char *);
+			data = strlen(str);
+			if (buflen >= data + 2) {
+				*buf++ = L1_ARG_ASCII;
+				memcpy(buf, str, data + 1);
+				buf += data + 1;
+				buflen -= data + 2;
+			}
+			len += data + 2;
+			break;
+		case L1_ARG_BINARY:
+			data = (u32)va_arg(ap, size_t);	/* size */
+			str = va_arg(ap, const char *);	/* data */
+			if (buflen >= 1 + data) {
+				*buf++ = L1_ARG_BINARY | data;
+				memcpy(buf, str, data);
+				buf += data;
+				buflen -= data + 1;
+			}
+			len += data + 1;
+			break;
+		default:
+			WARN_ON_ONCE(1);
+			return SIZE_MAX;
+		}
+	}
+
+	return len;
+}
+
+/* The L1 multiplexes unsolicited event and console traffic onto one wire. */
+static int l1_receive_response(nasid_t nasid, u8 *pkt, size_t *pktlen)
+{
+	size_t rcvlen;
+	int rc;
+
+	for (;;) {
+		rc = l1_packet_get(nasid, pkt, *pktlen, &rcvlen);
+		if (rc == -ETIMEDOUT)
+			return rc;
+		if (rc)		/* bad packet */
+			continue;
+		if (pkt[0] != (L1PKT_RESPONSE | L1CH_MISC))
+			continue;
+
+		*pktlen = rcvlen;
+		return 0;
+	}
+}
+
+static int l1_response_to_errno(u32 response)
+{
+	switch (response) {
+	case L1_RESP_OK:
+		return 0;
+	case L1_RESP_INVAL:
+		return -EINVAL;
+	case L1_RESP_NXDATA:
+		return -ENXIO;
+	default:
+		return -EIO;
+	}
+}
+
+/*
+ * One request and its response are a single transaction on the wire,
+ * so every entry point holds this.
+ */
+static DEFINE_SPINLOCK(l1_lock);
+
+/*
+ * Run one request/response exchange in pkt, which has to be large enough
+ * for both; returns the response's argument count.
+ */
+static int l1_transact(nasid_t nasid, u8 *pkt, size_t pktsize, u32 address,
+		       u16 request, u8 **rargs, size_t *rarglen, int nargs, ...)
+{
+	va_list ap;
+	size_t pktlen;
+	int rc;
+
+	if (!system_is_ip35)
+		return -ENODEV;
+
+	va_start(ap, nargs);
+	pktlen = l1_command_build(pkt, pktsize, address, request, nargs, ap);
+	va_end(ap);
+	if (pktlen > pktsize)
+		return -ENOMEM;
+
+	rc = l1_packet_put(nasid, pkt, pktlen);
+	if (rc)
+		return rc;
+
+	pktlen = pktsize;
+	rc = l1_receive_response(nasid, pkt, &pktlen);
+	if (rc)
+		return rc;
+
+	if (pktlen < 6)
+		return -EIO;
+
+	rc = l1_response_to_errno(get_unaligned_be32(&pkt[1]));
+	if (rc)
+		return rc;
+
+	if (rargs) {
+		*rargs = pkt + 6;
+		*rarglen = pktlen - 6;
+	}
+
+	return pkt[5];
+}
+
+/*
+ * Send a plaintext command to the L1's own console command parser, the
+ * same strings a human types at the L1 console. Such a command can reset
+ * the Hub, or cut power to it, before the L1 answers, so an error here
+ * means "no response", never "retry".
+ */
+int l1_exec_command(const char *cmd)
+{
+	u32 address = L1_ADDRESS(L1_TYPE_L1,
+				 L1_ADDRESS_LOCAL | L1_TASK_COMMAND);
+	u8 pkt[64 + 64];	/* command and response packet buffer */
+	unsigned long flags;
+	bool locked;
+	int rc;
+
+	/*
+	 * Reset and poweroff reach this after smp_send_stop(), so a stopped
+	 * CPU may hold the lock for good; go to the wire either way.
+	 */
+	locked = spin_trylock_irqsave(&l1_lock, flags);
+
+	rc = l1_transact(get_nasid(), pkt, sizeof(pkt), address,
+			 L1_REQ_EXEC_CMD, NULL, NULL, 1,
+			 L1_ARG_ASCII, cmd);
+
+	if (locked)
+		spin_unlock_irqrestore(&l1_lock, flags);
+
+	if (rc < 0)
+		return rc;
+
+	/* nothing is expected back besides the response code */
+	return rc == 0 ? 0 : -EIO;
+}
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 29/38] MIPS: SGI-IP27: wire the L1 into reset and the Ethernet address
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (27 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 28/38] MIPS: SGI-IP27: add L1 system controller support Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 30/38] MIPS: PCI: xtalk-bridge: take the board part number from the L1 Imre Kaloz
                   ` (8 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

On Bedrock hubs restart, halt and poweroff go through the L1 system
controller, and ioc3-eth takes its MAC address from the L1's board
information area.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-l1.c    | 266 ++++++++++++++++++++++++++++++++
 arch/mips/sgi-ip27/ip27-reset.c |  47 +++++-
 2 files changed, 305 insertions(+), 8 deletions(-)

diff --git a/arch/mips/sgi-ip27/ip27-l1.c b/arch/mips/sgi-ip27/ip27-l1.c
index da3095b66cf1..25f9be350c0b 100644
--- a/arch/mips/sgi-ip27/ip27-l1.c
+++ b/arch/mips/sgi-ip27/ip27-l1.c
@@ -25,6 +25,8 @@
  */
 #include <linux/kernel.h>
 #include <linux/errno.h>
+#include <linux/etherdevice.h>
+#include <linux/hex.h>
 #include <linux/serial_reg.h>
 #include <linux/spinlock.h>
 #include <linux/stdarg.h>
@@ -66,6 +68,7 @@
 	 (L1_ADDRESS_BAY_LOCAL << L1_ADDRESS_BAY_SHIFT))
 
 #define L1_TASK_COMMAND		0x03
+#define L1_TASK_GENERAL		0x06
 
 /* response codes */
 #define L1_RESP_OK		((u32)0)
@@ -75,6 +78,27 @@
 /* L1_TASK_COMMAND requests */
 #define L1_REQ_EXEC_CMD		0x0000	/* interpret plaintext command */
 
+/* L1_TASK_GENERAL requests */
+#define L1_REQ_EEPROM		0x0006	/* access eeprom */
+
+/* L1_REQ_EEPROM additional argument values (non C-brick component) */
+#define L1_EEP_LOGIC		0x01	/* logic board */
+/* ia code */
+#define L1_EEP_BOARD		0x02	/* board ia */
+
+#define EEPROM_CHUNK		0x40
+
+/*
+ * Information Area type/length byte: bits 7-6 are the type (0 binary,
+ * 1 BCD, 2 packed 6-bit ascii, 3 8-bit ascii), bits 5-0 the length.
+ */
+#define IA_TYPE_SHIFT		6
+#define IA_TYPE_BINARY		0
+#define IA_TYPE_ASCII		3
+#define IA_LENGTH_MASK		0x3f
+#define IA_TL(t, l)		(((t) << IA_TYPE_SHIFT) | (l))
+#define IA_EOF			IA_TL(IA_TYPE_ASCII, 1)
+
 /* Async-HDLC framing bytes; linux/ppp_defs.h would drag in skbuff.h. */
 #define L1_FLAG			0x7e
 #define L1_ESC			0x7d
@@ -96,6 +120,10 @@
 #define L1_UART_ADDRESS(nasid, r) \
 	((u64 *)(NODE_HSPEC_BASE(nasid) + L1_RHSPEC_OFFSET + L1_UART_REG(r)))
 
+/* Board IA record buffer; the probed length is checked against it. */
+#define L1_IA_BUF_SIZE		512
+static u8 l1_ia_buf[L1_IA_BUF_SIZE];
+
 static int l1_serial_getc(nasid_t nasid)
 {
 	unsigned int n;
@@ -221,6 +249,48 @@ static int l1_packet_get(nasid_t nasid, u8 *buf, size_t buflen, size_t *rlen)
 	return 0;
 }
 
+static int l1_packet_get_int(u8 **buf, size_t *buflen, u32 *rval)
+{
+	u8 *b = *buf;
+
+	if (*buflen < 5)
+		return -EIO;
+	if (*b++ != L1_ARG_INT)
+		return -EINVAL;
+
+	*rval = get_unaligned_be32(b);
+	b += 4;
+	*buf = b;
+	*buflen -= 5;
+
+	return 0;
+}
+
+static int l1_packet_get_binary(u8 **buf, size_t *buflen, u8 **rval,
+				size_t *rlen)
+{
+	u8 *b = *buf;
+	size_t datalen;
+
+	if (*buflen < 1)
+		return -EIO;
+	if ((*b & L1_ARG_BINARY) == 0)
+		return -EINVAL;
+
+	datalen = *b & ~L1_ARG_BINARY;
+	if (*buflen < 1 + datalen)
+		return -ENOMEM;
+
+	b++;
+	*rval = b;
+	*rlen = datalen;
+	*buflen -= 1 + datalen;
+	b += datalen;
+	*buf = b;
+
+	return 0;
+}
+
 /*
  * Returns the would-be length even when the buffer is too small, and
  * SIZE_MAX for an unknown argument type.
@@ -421,3 +491,199 @@ int l1_exec_command(const char *cmd)
 	/* nothing is expected back besides the response code */
 	return rc == 0 ? 0 : -EIO;
 }
+
+/* Read a component's board IA record from EEPROM. */
+static int l1_read_board_ia(nasid_t nasid, int type, unsigned int component,
+			    u8 **ria, size_t *rialen)
+{
+	u32 address = L1_ADDRESS(type, L1_ADDRESS_LOCAL | L1_TASK_GENERAL);
+	u8 pkt[64 + EEPROM_CHUNK];
+	u8 *args, *chunk;
+	size_t arglen, chunklen, ialen, iapos;
+	u32 data;
+	int rc;
+
+	rc = l1_transact(nasid, pkt, sizeof(pkt), address, L1_REQ_EEPROM,
+			 &args, &arglen, 4,
+			 L1_ARG_INT, (u32)component,
+			 L1_ARG_INT, (u32)L1_EEP_BOARD,
+			 L1_ARG_INT, (u32)0,	/* offset */
+			 L1_ARG_INT, (u32)0);	/* size (0 = probe) */
+	if (rc < 0)
+		return rc;
+	if (rc != 1)
+		return -EIO;
+
+	rc = l1_packet_get_int(&args, &arglen, &data);
+	if (rc)
+		return -EIO;
+
+	ialen = (size_t)data;
+	if (ialen == 0 || ialen > L1_IA_BUF_SIZE)
+		return -ENOMEM;
+
+	iapos = 0;
+	while (iapos < ialen) {
+		rc = l1_transact(nasid, pkt, sizeof(pkt), address,
+				 L1_REQ_EEPROM, &args, &arglen, 4,
+				 L1_ARG_INT, (u32)component,
+				 L1_ARG_INT, (u32)L1_EEP_BOARD,
+				 L1_ARG_INT, (u32)iapos,
+				 L1_ARG_INT, (u32)EEPROM_CHUNK);
+		if (rc < 0)
+			return rc;
+		if (rc != 2)
+			return -EIO;
+
+		rc = l1_packet_get_int(&args, &arglen, &data);
+		if (rc)
+			return -EIO;
+
+		rc = l1_packet_get_binary(&args, &arglen, &chunk, &chunklen);
+		if (rc)
+			return -EIO;
+
+		/* should not happen; the bound keeps the loop finite */
+		if (chunklen == 0)
+			return -EIO;
+
+		if (chunklen > ialen - iapos)
+			chunklen = ialen - iapos;
+
+		memcpy(l1_ia_buf + iapos, chunk, chunklen);
+		iapos += chunklen;
+	}
+
+	/* the sum of all IA bytes has to be 0 mod 256 */
+	data = 0;
+	for (iapos = 0; iapos < ialen; iapos++)
+		data += l1_ia_buf[iapos];
+	if ((data & 0xff) != 0)
+		return -EINVAL;
+
+	*ria = l1_ia_buf;
+	*rialen = ialen;
+	return 0;
+}
+
+/* IA record walk helper: advance past one record, without passing EOF. */
+static size_t ia_skip(const u8 *ia, size_t iapos, size_t ialen)
+{
+	size_t npos;
+
+	if (ia[iapos] == IA_EOF)
+		return iapos;
+
+	npos = iapos + 1 + (ia[iapos] & IA_LENGTH_MASK);
+	return npos >= ialen ? iapos : npos;
+}
+
+static int l1_get_brick_ethernet_address(nasid_t nasid, u8 *enaddr)
+{
+	u8 *ia;
+	u8 group;
+	size_t iapos, ialen;
+	int i, rc;
+
+	/* assumes the local brick's L1 answers for this node */
+	rc = l1_read_board_ia(nasid, L1_TYPE_L1, L1_EEP_LOGIC, &ia, &ialen);
+	if (rc)
+		return rc;
+
+	/*
+	 * ia[0] is the board-IA format version. Below 2 the encryption-key
+	 * (G/P/Y) and Ethernet-address groups follow the fixed records
+	 * implicitly; from 2 on an extra selector record comes first: 0
+	 * keys only, 1 keys then address, 2 neither, 3 a config group.
+	 * Otherwise the walk follows l1_get_brick_ethernet_address() in
+	 * OpenBSD/sgi's l1.c.
+	 */
+	if (ia[1] < 2 || ia[1] * 8UL > ialen)
+		return -EINVAL;
+
+	/* skip the fixed part, then mfg, product, serial, part */
+	iapos = 6;
+	iapos = ia_skip(ia, iapos, ialen);
+	iapos = ia_skip(ia, iapos, ialen);
+	iapos = ia_skip(ia, iapos, ialen);
+	iapos = ia_skip(ia, iapos, ialen);
+	/* skip FRU (1 raw byte) */
+	if (iapos < ialen - 1)
+		iapos++;
+	/* skip board rev, eeprom size, temp waiver */
+	iapos = ia_skip(ia, iapos, ialen);
+	iapos = ia_skip(ia, iapos, ialen);
+	iapos = ia_skip(ia, iapos, ialen);
+
+	if (ia[0] >= 2) {
+		if (iapos + 1 >= ialen)
+			return -ENXIO;
+		group = ia[iapos + 1];
+		iapos = ia_skip(ia, iapos, ialen);
+		if (group != 1)
+			return -ENXIO;	/* no ethernet-address group here */
+		/* the three encryption-key records precede the address */
+		iapos = ia_skip(ia, iapos, ialen);
+		iapos = ia_skip(ia, iapos, ialen);
+		iapos = ia_skip(ia, iapos, ialen);
+	} else {
+		if (iapos < ialen && ia[iapos] == IA_TL(IA_TYPE_BINARY, 4)) {
+			iapos = ia_skip(ia, iapos, ialen);
+			iapos = ia_skip(ia, iapos, ialen);
+			iapos = ia_skip(ia, iapos, ialen);
+		}
+	}
+
+	if (iapos >= ialen - 1 - 12 || ia[iapos] != IA_TL(IA_TYPE_ASCII, 12))
+		return -EINVAL;
+
+	iapos++;
+	for (i = 0; i < ETH_ALEN; i++) {
+		int hi = hex_to_bin(ia[iapos + i * 2]);
+		int lo = hex_to_bin(ia[iapos + i * 2 + 1]);
+
+		if (hi < 0 || lo < 0)
+			return -EINVAL;
+		enaddr[i] = (hi << 4) | lo;
+	}
+
+	return is_valid_ether_addr(enaddr) ? 0 : -EINVAL;
+}
+
+static u8 ip27_l1_mac_addr[ETH_ALEN];
+static bool ip27_l1_mac_addr_valid;
+static bool ip27_l1_mac_addr_tried;
+
+/*
+ * A board that sources its MAC elsewhere, such as Tezro's tg3, yields
+ * nothing here, so a failure logs at debug level rather than warning.
+ */
+unsigned char *arch_get_platform_mac_address(void)
+{
+	unsigned long flags;
+	int rc;
+
+	if (!system_is_ip35)
+		return NULL;
+
+	spin_lock_irqsave(&l1_lock, flags);
+
+	if (!ip27_l1_mac_addr_tried) {
+		ip27_l1_mac_addr_tried = true;
+
+		rc = l1_get_brick_ethernet_address(get_nasid(),
+						   ip27_l1_mac_addr);
+		if (rc) {
+			pr_debug("l1: EEPROM MAC address read failed (%d)\n",
+				 rc);
+		} else {
+			ip27_l1_mac_addr_valid = true;
+			pr_info("l1: EEPROM Ethernet address %pM\n",
+				ip27_l1_mac_addr);
+		}
+	}
+
+	spin_unlock_irqrestore(&l1_lock, flags);
+
+	return ip27_l1_mac_addr_valid ? ip27_l1_mac_addr : NULL;
+}
diff --git a/arch/mips/sgi-ip27/ip27-reset.c b/arch/mips/sgi-ip27/ip27-reset.c
index 5ac5ad638734..1e55636393f0 100644
--- a/arch/mips/sgi-ip27/ip27-reset.c
+++ b/arch/mips/sgi-ip27/ip27-reset.c
@@ -3,12 +3,17 @@
  * License.  See the file "COPYING" in the main directory of this archive
  * for more details.
  *
- * Reset an IP27.
+ * Reset an IP27, or an IP35-family (Bedrock hub) machine.
+ *
+ * On Bedrock hubs restart and halt ask the L1 system controller to reset
+ * the machine and fall back to an NI port reset if it has not acted
+ * within five seconds; poweroff asks the L1 to cut power.
  *
  * Copyright (C) 1997, 1998, 1999, 2000, 06 by Ralf Baechle
  * Copyright (C) 1999, 2000 Silicon Graphics, Inc.
  */
 #include <linux/compiler.h>
+#include <linux/delay.h>
 #include <linux/kernel.h>
 #include <linux/sched.h>
 #include <linux/timer.h>
@@ -25,6 +30,7 @@
 #include <asm/sn/agent.h>
 #include <asm/sn/arch.h>
 #include <asm/sn/gda.h>
+#include <asm/sn/l1.h>
 
 #include "ip27-common.h"
 
@@ -34,6 +40,15 @@ void machine_power_off(void) __noreturn;
 
 #define noreturn while(1);				/* Silence gcc.	 */
 
+static void ip35_reset(void)
+{
+	l1_exec_command("rst");
+	mdelay(5000);
+	LOCAL_HUB_S(NI_RESET_ENABLE_IP35, NI_RESET_OK_IP35);
+	LOCAL_HUB_S(NI_PORT_RESET_IP35,
+		    NI_RESET_ACTION_IP35 | NI_RESET_LOCAL_IP35);
+}
+
 /* XXX How to pass the reboot command to the firmware??? */
 static void ip27_machine_restart(char *command)
 {
@@ -45,12 +60,16 @@ static void ip27_machine_restart(char *command)
 #ifdef CONFIG_SMP
 	smp_send_stop();
 #endif
+	if (system_is_ip35) {
+		ip35_reset();
+	} else {
 #if 0
-	for_each_online_node(i)
-		REMOTE_HUB_S(i, PROMOP_REG, PROMOP_REBOOT);
+		for_each_online_node(i)
+			REMOTE_HUB_S(i, PROMOP_REG, PROMOP_REBOOT);
 #else
-	LOCAL_HUB_S(NI_PORT_RESET, NPR_PORTRESET | NPR_LOCALRESET);
+		LOCAL_HUB_S(NI_PORT_RESET, NPR_PORTRESET | NPR_LOCALRESET);
 #endif
+	}
 	noreturn;
 }
 
@@ -61,15 +80,27 @@ static void ip27_machine_halt(void)
 #ifdef CONFIG_SMP
 	smp_send_stop();
 #endif
-	for_each_online_node(i)
-		REMOTE_HUB_S(i, PROMOP_REG, PROMOP_RESTART);
-	LOCAL_HUB_S(NI_PORT_RESET, NPR_PORTRESET | NPR_LOCALRESET);
+	if (system_is_ip35) {
+		ip35_reset();
+	} else {
+		for_each_online_node(i)
+			REMOTE_HUB_S(i, PROMOP_REG, PROMOP_RESTART);
+		LOCAL_HUB_S(NI_PORT_RESET, NPR_PORTRESET | NPR_LOCALRESET);
+	}
 	noreturn;
 }
 
 static void ip27_machine_power_off(void)
 {
-	/* To do ...  */
+	if (system_is_ip35) {
+#ifdef CONFIG_SMP
+		smp_send_stop();
+#endif
+		l1_exec_command("pwr d");
+		mdelay(5000);
+		pr_info("Please power off the system manually.\n");
+	}
+	/* IP27 (Hub) has no software poweroff path. */
 	noreturn;
 }
 
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 30/38] MIPS: PCI: xtalk-bridge: take the board part number from the L1
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (28 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 29/38] MIPS: SGI-IP27: wire the L1 into reset and the Ethernet address Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 31/38] mfd: ioc3: add IP34 system-board entry to ioc3_infos[] Imre Kaloz
                   ` (7 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

An XBridge answers nothing on the b_nic 1-wire pin, so
bridge_get_partnum() finds no PROM and the probe defers forever. Stop
waiting on XBridge and PIC widgets; on Bedrock hubs read the assembly
number from the L1 instead.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/sn/l1.h    |  7 +++
 arch/mips/pci/pci-xtalk-bridge.c | 37 +++++++++++++-
 arch/mips/sgi-ip27/ip27-l1.c     | 83 ++++++++++++++++++++++++++++++++
 3 files changed, 125 insertions(+), 2 deletions(-)

diff --git a/arch/mips/include/asm/sn/l1.h b/arch/mips/include/asm/sn/l1.h
index e61935e2fac8..1a3b7fa0e213 100644
--- a/arch/mips/include/asm/sn/l1.h
+++ b/arch/mips/include/asm/sn/l1.h
@@ -9,6 +9,13 @@
 
 #include <linux/types.h>
 
+/*
+ * Which L1 EEPROM component id carries which board is undocumented and
+ * differs from machine to machine, so a caller walks the whole range.
+ */
+#define L1_BOARD_COMPONENT_MAX	8
+
 int l1_exec_command(const char *cmd);
+int l1_read_board_partnum(unsigned int component, char *buf, size_t len);
 
 #endif /* __ASM_SN_L1_H */
diff --git a/arch/mips/pci/pci-xtalk-bridge.c b/arch/mips/pci/pci-xtalk-bridge.c
index 35ae7c423973..c97533653ef6 100644
--- a/arch/mips/pci/pci-xtalk-bridge.c
+++ b/arch/mips/pci/pci-xtalk-bridge.c
@@ -18,7 +18,9 @@
 #include <asm/pci/bridge.h>
 #include <asm/paccess.h>
 #include <asm/sn/irq_alloc.h>
+#include <asm/sn/addrs.h>
 #include <asm/sn/ioc3.h>
+#include <asm/sn/l1.h>
 
 #define CRC16_INIT	0
 #define CRC16_VALID	0xb001
@@ -583,6 +585,29 @@ static const struct {
 	BRIDGE_BOARD_SETUP("030-1707-", bridge_setup_ip34_fuel_sysboard),
 };
 
+/*
+ * The L1 answers one board information area per EEPROM component id, and
+ * which id carries which board is undocumented. Ask for each in turn and take
+ * the first answer the table above knows.
+ */
+static int bridge_l1_partnum(char *partnum, size_t len)
+{
+	unsigned int component;
+	int i;
+
+	for (component = 0; component < L1_BOARD_COMPONENT_MAX; component++) {
+		if (l1_read_board_partnum(component, partnum, len))
+			continue;
+
+		for (i = 0; i < ARRAY_SIZE(bridge_ioc3_devid); i++)
+			if (!strncmp(partnum, bridge_ioc3_devid[i].match,
+				     strlen(bridge_ioc3_devid[i].match)))
+				return 0;
+	}
+
+	return -ENODEV;
+}
+
 static void bridge_setup_board(struct bridge_controller *bc, char *partnum)
 {
 	int i;
@@ -657,8 +682,16 @@ static int bridge_probe(struct platform_device *pdev)
 	int err;
 
 	/* get part number from one wire prom */
-	if (bridge_get_partnum(virt_to_phys((void *)bd->bridge_addr), partnum))
-		return -EPROBE_DEFER; /* not available yet */
+	if (bridge_get_partnum(virt_to_phys((void *)bd->bridge_addr),
+			       partnum)) {
+		/* Only a classic Bridge waits for its 1-wire PROM. */
+		if (!bd->is_xbridge && !bd->is_pic)
+			return -EPROBE_DEFER; /* not available yet */
+
+		if (!IS_ENABLED(CONFIG_SGI_IP27) || !system_is_ip35 ||
+		    bridge_l1_partnum(partnum, sizeof(partnum)))
+			partnum[0] = '\0';
+	}
 
 	parent = irq_get_default_domain();
 	if (!parent)
diff --git a/arch/mips/sgi-ip27/ip27-l1.c b/arch/mips/sgi-ip27/ip27-l1.c
index 25f9be350c0b..173a506595da 100644
--- a/arch/mips/sgi-ip27/ip27-l1.c
+++ b/arch/mips/sgi-ip27/ip27-l1.c
@@ -650,6 +650,89 @@ static int l1_get_brick_ethernet_address(nasid_t nasid, u8 *enaddr)
 	return is_valid_ether_addr(enaddr) ? 0 : -EINVAL;
 }
 
+/*
+ * The L1 stores SGI assembly numbers with underscores where the printed
+ * form has dashes: "030_1707_003" for "030-1707-003".
+ */
+static int l1_get_board_partnum(nasid_t nasid, unsigned int component,
+				char *buf, size_t len)
+{
+	size_t iapos, ialen, fieldlen, i;
+	u8 *ia;
+	int rc;
+
+	rc = l1_read_board_ia(nasid, L1_TYPE_L1, component, &ia, &ialen);
+	if (rc)
+		return rc;
+
+	if (ia[1] < 2 || ia[1] * 8UL > ialen)
+		return -EINVAL;
+
+	/* skip the fixed part, then mfg, product, serial */
+	iapos = 6;
+	iapos = ia_skip(ia, iapos, ialen);
+	iapos = ia_skip(ia, iapos, ialen);
+	iapos = ia_skip(ia, iapos, ialen);
+
+	if (iapos >= ialen || (ia[iapos] >> IA_TYPE_SHIFT) != IA_TYPE_ASCII)
+		return -EINVAL;
+
+	fieldlen = ia[iapos] & IA_LENGTH_MASK;
+	if (fieldlen == 0 || iapos + 1 + fieldlen > ialen || fieldlen >= len)
+		return -EINVAL;
+
+	iapos++;
+	for (i = 0; i < fieldlen; i++)
+		buf[i] = ia[iapos + i] == '_' ? '-' : ia[iapos + i];
+	buf[fieldlen] = '\0';
+
+	return 0;
+}
+
+/*
+ * Part numbers cannot change at runtime, so failures are cached along
+ * with successes and each component is queried once.
+ */
+#define L1_PARTNUM_SIZE		24
+static char l1_partnum[L1_BOARD_COMPONENT_MAX][L1_PARTNUM_SIZE];
+static int l1_partnum_rc[L1_BOARD_COMPONENT_MAX];
+static bool l1_partnum_cached[L1_BOARD_COMPONENT_MAX];
+
+int l1_read_board_partnum(unsigned int component, char *buf, size_t len)
+{
+	unsigned long flags;
+
+	if (component >= L1_BOARD_COMPONENT_MAX)
+		return -EINVAL;
+
+	spin_lock_irqsave(&l1_lock, flags);
+
+	if (!l1_partnum_cached[component]) {
+		l1_partnum_rc[component] =
+			l1_get_board_partnum(get_nasid(), component,
+					     l1_partnum[component],
+					     sizeof(l1_partnum[component]));
+		l1_partnum_cached[component] = true;
+
+		if (l1_partnum_rc[component])
+			pr_debug("l1: component %u: no part number (%d)\n",
+				 component, l1_partnum_rc[component]);
+		else
+			pr_debug("l1: component %u: part number %s\n",
+				 component, l1_partnum[component]);
+	}
+
+	spin_unlock_irqrestore(&l1_lock, flags);
+
+	if (l1_partnum_rc[component])
+		return l1_partnum_rc[component];
+
+	if (strscpy(buf, l1_partnum[component], len) < 0)
+		return -E2BIG;
+
+	return 0;
+}
+
 static u8 ip27_l1_mac_addr[ETH_ALEN];
 static bool ip27_l1_mac_addr_valid;
 static bool ip27_l1_mac_addr_tried;
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 31/38] mfd: ioc3: add IP34 system-board entry to ioc3_infos[]
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (29 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 30/38] MIPS: PCI: xtalk-bridge: take the board part number from the L1 Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 32/38] net: ethernet: sgi: ioc3-eth: fall back to the platform MAC address Imre Kaloz
                   ` (6 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel, Lee Jones, mfd

Register the Fuel system board's on-board IOC3 and its M48T35, whose
year register counts from 1968 as on other IP35-family machines.
Bridge-side detection was already merged in commit 2c4288719806 ("MIPS:
PCI: Add detection of IOC3 on IO7, IO8, IO9 and Fuel"), which matches
the board part number "030-1707-"; the cell table had no entry to go
with it. Without one the IOC3 falls to the CAD DUO default, which
instantiates no serial cell, so Fuel comes up with no ttyS0.

Fixes: 2c4288719806 ("MIPS: PCI: Add detection of IOC3 on IO7, IO8, IO9 and Fuel")
Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 drivers/mfd/ioc3.c | 46 ++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 46 insertions(+)

diff --git a/drivers/mfd/ioc3.c b/drivers/mfd/ioc3.c
index fd50bae0f10b..34dbf42087ee 100644
--- a/drivers/mfd/ioc3.c
+++ b/drivers/mfd/ioc3.c
@@ -517,6 +517,51 @@ static int ip30_sysboard_setup(struct ioc3_priv_data *ipd)
 	return ioc3_led_setup(ipd);
 }
 
+static struct mfd_cell ip34_m48t35_cells[] = {
+	{
+		.name = "rtc-m48t35-ip35",
+		.resources = ioc3_m48t35_resources,
+		.num_resources = ARRAY_SIZE(ioc3_m48t35_resources),
+	}
+};
+
+/*
+ * Fuel's timekeeper is the M48T35 at IOC3_BYTEBUS_DEV0. A read at IP30's
+ * DS1685 address never completes on the Fuel system board.
+ */
+static int ip34_sysboard_setup(struct ioc3_priv_data *ipd)
+{
+	int ret, io_irq;
+
+	io_irq = ioc3_map_irq(ipd->pdev, PCI_SLOT(ipd->pdev->devfn),
+			      PCI_INTERRUPT_INTB);
+	ret = ioc3_irq_domain_setup(ipd, io_irq);
+	if (ret)
+		return ret;
+
+	ret = ioc3_eth_setup(ipd);
+	if (ret)
+		return ret;
+
+	ret = ioc3_serial_setup(ipd);
+	if (ret)
+		return ret;
+
+	ret = mfd_add_devices(&ipd->pdev->dev, PLATFORM_DEVID_AUTO,
+			      ip34_m48t35_cells, ARRAY_SIZE(ip34_m48t35_cells),
+			      &ipd->pdev->resource[0], 0, ipd->domain);
+	if (ret) {
+		dev_err(&ipd->pdev->dev, "Failed to add M48T35 subdev\n");
+		return ret;
+	}
+
+	ret = ioc3_kbd_setup(ipd);
+	if (ret)
+		return ret;
+
+	return ioc3_led_setup(ipd);
+}
+
 static int ioc3_menet_setup(struct ioc3_priv_data *ipd)
 {
 	int ret, io_irq;
@@ -574,6 +619,7 @@ static struct {
 	IOC3_SID("IP27 BaseIO", IP27_BASEIO, &ip27_baseio_setup),
 	IOC3_SID("IP29 System Board", IP29_SYSBOARD, &ip27_baseio6g_setup),
 	IOC3_SID("IP30 System Board", IP30_SYSBOARD, &ip30_sysboard_setup),
+	IOC3_SID("IP34 System Board", IP34_SYSBOARD, &ip34_sysboard_setup),
 	IOC3_SID("MENET", MENET, &ioc3_menet_setup),
 	IOC3_SID("MENET4", MENET4, &ioc3_menet4_setup)
 };
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 32/38] net: ethernet: sgi: ioc3-eth: fall back to the platform MAC address
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (30 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 31/38] mfd: ioc3: add IP34 system-board entry to ioc3_infos[] Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 33/38] MIPS: SGI-IP27: don't register a w1 master on an XBridge or PIC Imre Kaloz
                   ` (5 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer
  Cc: linux-mips, linux-kernel, Andrew Lunn, David S. Miller,
	Eric Dumazet, Jakub Kicinski, Paolo Abeni, netdev

The IOC3 on Fuel's system board has no MAC PROM on its 1-wire bus, so
ioc3eth_get_mac_addr() cannot succeed there and the probe defers for
ever. Ask eth_platform_get_mac_address() before deferring; on IP35
machines it answers from the L1 system controller. Once deferred probing
gives up with neither source answering, use a random address.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 drivers/net/ethernet/sgi/ioc3-eth.c | 13 ++++++++++---
 1 file changed, 10 insertions(+), 3 deletions(-)

diff --git a/drivers/net/ethernet/sgi/ioc3-eth.c b/drivers/net/ethernet/sgi/ioc3-eth.c
index 8702dfdf4c36..85b49e7b0f79 100644
--- a/drivers/net/ethernet/sgi/ioc3-eth.c
+++ b/drivers/net/ethernet/sgi/ioc3-eth.c
@@ -857,9 +857,16 @@ static int ioc3eth_probe(struct platform_device *pdev)
 		dev_err(&pdev->dev, "Invalid resource\n");
 		return -EINVAL;
 	}
-	/* get mac addr from one wire prom */
-	if (ioc3eth_get_mac_addr(regs, mac_addr))
-		return -EPROBE_DEFER; /* not available yet */
+	/* get mac addr from one wire prom, or from the platform */
+	if (ioc3eth_get_mac_addr(regs, mac_addr) &&
+	    eth_platform_get_mac_address(&pdev->dev, mac_addr)) {
+		err = driver_deferred_probe_check_state(&pdev->dev);
+		if (err == -EPROBE_DEFER)
+			return err; /* not available yet */
+
+		dev_warn(&pdev->dev, "no MAC address, using a random one\n");
+		eth_random_addr(mac_addr);
+	}
 
 	dev = alloc_etherdev(sizeof(struct ioc3_private));
 	if (!dev)
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 33/38] MIPS: SGI-IP27: don't register a w1 master on an XBridge or PIC
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (31 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 32/38] net: ethernet: sgi: ioc3-eth: fall back to the platform MAC address Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 34/38] MIPS: SGI-IP27: report a Bedrock machine as SGI IP35 Imre Kaloz
                   ` (4 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

On an XBridge the b_nic register's 1-wire bit-bang path reads back a
constant mcr, so a sgi_w1 master registered there enumerates nothing but
phantom slave IDs. Move the w1 registration into bridge_w1_create() and
call it for classic Bridges only. On IP35 the L1 supplies the board part
number and MAC address instead.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-xtalk.c | 41 +++++++++++++++++++++++++--------
 1 file changed, 31 insertions(+), 10 deletions(-)

diff --git a/arch/mips/sgi-ip27/ip27-xtalk.c b/arch/mips/sgi-ip27/ip27-xtalk.c
index 73b2eef96bdb..091186cb7a04 100644
--- a/arch/mips/sgi-ip27/ip27-xtalk.c
+++ b/arch/mips/sgi-ip27/ip27-xtalk.c
@@ -31,13 +31,10 @@ enum xtalk_bridge_type {
 	XTALK_PIC_BUS1,
 };
 
-static void bridge_platform_create(nasid_t nasid, int widget, int masterwid,
-				   enum xtalk_bridge_type type)
+static struct platform_device *bridge_w1_create(nasid_t nasid, int widget)
 {
-	struct xtalk_bridge_platform_data *bd;
 	struct sgi_w1_platform_data *wd;
 	struct platform_device *pdev_wd;
-	struct platform_device *pdev_bd;
 	struct resource w1_res;
 	unsigned long offset;
 
@@ -46,7 +43,7 @@ static void bridge_platform_create(nasid_t nasid, int widget, int masterwid,
 	wd = kzalloc_obj(*wd);
 	if (!wd) {
 		pr_warn("xtalk:n%d/%x bridge create out of memory\n", nasid, widget);
-		return;
+		return NULL;
 	}
 
 	snprintf(wd->dev_id, sizeof(wd->dev_id), "bridge-%012lx",
@@ -77,6 +74,35 @@ static void bridge_platform_create(nasid_t nasid, int widget, int masterwid,
 	}
 	/* platform_device_add_data() duplicates the data */
 	kfree(wd);
+	return pdev_wd;
+
+err_put_pdev_wd:
+	platform_device_put(pdev_wd);
+err_kfree_wd:
+	kfree(wd);
+	return NULL;
+}
+
+static void bridge_platform_create(nasid_t nasid, int widget, int masterwid,
+				   enum xtalk_bridge_type type)
+{
+	struct xtalk_bridge_platform_data *bd;
+	struct platform_device *pdev_wd = NULL;
+	struct platform_device *pdev_bd;
+	unsigned long offset;
+
+	offset = NODE_OFFSET(nasid);
+
+	/*
+	 * An XBridge's b_nic register reads back a constant mcr on the
+	 * 1-wire bit-bang path, so a sgi_w1 master there enumerates only
+	 * phantom slave IDs. Only a classic Bridge gets one.
+	 */
+	if (type == XTALK_BRIDGE) {
+		pdev_wd = bridge_w1_create(nasid, widget);
+		if (!pdev_wd)
+			return;
+	}
 
 	bd = kzalloc_obj(*bd);
 	if (!bd) {
@@ -139,11 +165,6 @@ static void bridge_platform_create(nasid_t nasid, int widget, int masterwid,
 err_unregister_pdev_wd:
 	platform_device_unregister(pdev_wd);
 	return;
-err_put_pdev_wd:
-	platform_device_put(pdev_wd);
-err_kfree_wd:
-	kfree(wd);
-	return;
 }
 
 static int probe_one_port(nasid_t nasid, int widget, int masterwid)
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 34/38] MIPS: SGI-IP27: report a Bedrock machine as SGI IP35
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (32 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 33/38] MIPS: SGI-IP27: don't register a w1 master on an XBridge or PIC Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 35/38] MIPS: SGI-IP27: identify the machine by the L1 brick type Imre Kaloz
                   ` (3 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

get_system_type() answers "SGI Origin" on either hub generation, but a
Fuel or Tezro is no Origin. Return "SGI IP35" on a Bedrock hub and in
the node banner.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-init.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/arch/mips/sgi-ip27/ip27-init.c b/arch/mips/sgi-ip27/ip27-init.c
index 15811fb3cdee..c92f1bef692e 100644
--- a/arch/mips/sgi-ip27/ip27-init.c
+++ b/arch/mips/sgi-ip27/ip27-init.c
@@ -111,7 +111,8 @@ void __init plat_mem_setup(void)
 	 * hub_rtc init and cpu clock intr enabled for later calibrate_delay.
 	 */
 	nid = get_nasid();
-	printk("IP27: Running on node %d.\n", nid);
+	pr_info("%s: Running on node %d.\n",
+		system_is_ip35 ? "IP35" : "IP27", nid);
 
 	p = LOCAL_HUB_L(PI_CPU_PRESENT_A) & 1;
 	e = LOCAL_HUB_L(PI_CPU_ENABLE_A) & 1;
@@ -150,7 +151,7 @@ void __init plat_mem_setup(void)
 
 const char *get_system_type(void)
 {
-	return "SGI Origin";
+	return system_is_ip35 ? "SGI IP35" : "SGI Origin";
 }
 
 static inline bool hub_is_bedrock(void)
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 35/38] MIPS: SGI-IP27: identify the machine by the L1 brick type
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (33 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 34/38] MIPS: SGI-IP27: report a Bedrock machine as SGI IP35 Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 36/38] MIPS: SGI-IP27: register the Odyssey graphics widget Imre Kaloz
                   ` (2 subsequent siblings)
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

On a Bedrock hub, name the machine after the brick-type code the L1
reports for its chassis. Attached graphics makes an Origin an Onyx, so
a graphics-class KLCONFIG board picks between the two names. An
unlisted code keeps "SGI IP35".

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/include/asm/sn/l1.h  |  1 +
 arch/mips/sgi-ip27/ip27-init.c | 68 ++++++++++++++++++++++++++++++++++
 arch/mips/sgi-ip27/ip27-l1.c   | 45 ++++++++++++++++++++++
 3 files changed, 114 insertions(+)

diff --git a/arch/mips/include/asm/sn/l1.h b/arch/mips/include/asm/sn/l1.h
index 1a3b7fa0e213..f9fa8a8051e6 100644
--- a/arch/mips/include/asm/sn/l1.h
+++ b/arch/mips/include/asm/sn/l1.h
@@ -17,5 +17,6 @@
 
 int l1_exec_command(const char *cmd);
 int l1_read_board_partnum(unsigned int component, char *buf, size_t len);
+int l1_read_brick_type(void);
 
 #endif /* __ASM_SN_L1_H */
diff --git a/arch/mips/sgi-ip27/ip27-init.c b/arch/mips/sgi-ip27/ip27-init.c
index c92f1bef692e..7f16d7f437c9 100644
--- a/arch/mips/sgi-ip27/ip27-init.c
+++ b/arch/mips/sgi-ip27/ip27-init.c
@@ -13,12 +13,15 @@
 #include <linux/mm.h>
 #include <linux/export.h>
 #include <linux/cpumask.h>
+#include <linux/ctype.h>
 #include <asm/bootinfo.h>
 #include <asm/cpu.h>
 #include <asm/io.h>
+#include <asm/prom.h>
 #include <asm/sgialib.h>
 #include <asm/time.h>
 #include <asm/sn/agent.h>
+#include <asm/sn/l1.h>
 #include <asm/sn/types.h>
 #include <asm/sn/klconfig.h>
 #include <asm/sn/ioc3.h>
@@ -98,6 +101,69 @@ void per_cpu_init(void)
 	enable_percpu_irq(IP27_HUB_PEND1_IRQ, IRQ_TYPE_NONE);
 }
 
+/*
+ * The boot brick's L1 type character names the machine family. What makes
+ * an Origin an Onyx is attached graphics, so a graphics-class board in the
+ * KLCONFIG picks between the two names; gfx_model is NULL for a family
+ * that has only one.
+ */
+static const struct {
+	char brick_type;
+	const char *model;
+	const char *gfx_model;
+} ip27_models[] = {
+	{ '4', "SGI Origin 300", "SGI Onyx 300" },
+	{ '7', "SGI Origin 350", "SGI Onyx 350" },
+	{ '8', "SGI Onyx 350", NULL },		/* graphics blade */
+	{ '9', "SGI Tezro", NULL },		/* deskside */
+	{ 'A', "SGI Fuel", NULL },
+	{ 'C', "SGI Origin 3000", "SGI Onyx 3000" },
+	{ 'Q', "SGI Tezro Rackmount", NULL },
+};
+
+static bool __init ip27_has_graphics(void)
+{
+	nasid_t nasid;
+
+	for_each_online_node(nasid)
+		if (find_lboard_class((lboard_t *)KL_CONFIG_INFO(nasid),
+				      KLCLASS_GFX))
+			return true;
+
+	return false;
+}
+
+static void __init ip27_set_machine_name(void)
+{
+	int brick_type, i;
+	bool gfx;
+
+	if (!system_is_ip35)
+		return;
+
+	brick_type = l1_read_brick_type();
+	if (brick_type < 0)
+		return;
+
+	gfx = ip27_has_graphics();
+
+	for (i = 0; i < ARRAY_SIZE(ip27_models); i++) {
+		if (ip27_models[i].brick_type != brick_type)
+			continue;
+
+		if (gfx && ip27_models[i].gfx_model)
+			mips_set_machine_name(ip27_models[i].gfx_model);
+		else
+			mips_set_machine_name(ip27_models[i].model);
+		return;
+	}
+
+	mips_set_machine_name(get_system_type());
+	pr_info("Unlisted L1 brick type 0x%02x '%c', %s a graphics board\n",
+		brick_type, isprint(brick_type) ? brick_type : '?',
+		gfx ? "with" : "without");
+}
+
 void __init plat_mem_setup(void)
 {
 	u64 p, e, n_mode;
@@ -147,6 +213,8 @@ void __init plat_mem_setup(void)
 	ioport_resource.start = 0;
 	ioport_resource.end = ~0UL;
 	set_io_port_base(IO_BASE);
+
+	ip27_set_machine_name();
 }
 
 const char *get_system_type(void)
diff --git a/arch/mips/sgi-ip27/ip27-l1.c b/arch/mips/sgi-ip27/ip27-l1.c
index 173a506595da..98c94d14bd5f 100644
--- a/arch/mips/sgi-ip27/ip27-l1.c
+++ b/arch/mips/sgi-ip27/ip27-l1.c
@@ -79,6 +79,7 @@
 #define L1_REQ_EXEC_CMD		0x0000	/* interpret plaintext command */
 
 /* L1_TASK_GENERAL requests */
+#define L1_REQ_BRICK_ID		0x0003	/* rack, slot and brick type */
 #define L1_REQ_EEPROM		0x0006	/* access eeprom */
 
 /* L1_REQ_EEPROM additional argument values (non C-brick component) */
@@ -733,6 +734,50 @@ int l1_read_board_partnum(unsigned int component, char *buf, size_t len)
 	return 0;
 }
 
+/*
+ * The L1 answers two integers; the low byte of the second is the
+ * one-character brick-type code of its chassis.
+ */
+static int l1_get_brick_type(void)
+{
+	u32 address = L1_ADDRESS(L1_TYPE_L1,
+				 L1_ADDRESS_LOCAL | L1_TASK_GENERAL);
+	u8 pkt[64];		/* command and response packet buffer */
+	u8 *args;
+	size_t arglen;
+	u32 rack_slot, brick_type;
+	int rc;
+
+	rc = l1_transact(get_nasid(), pkt, sizeof(pkt), address,
+			 L1_REQ_BRICK_ID, &args, &arglen, 0);
+	if (rc < 0)
+		return rc;
+	if (rc != 2)
+		return -EIO;
+
+	rc = l1_packet_get_int(&args, &arglen, &rack_slot);
+	if (rc)
+		return rc;
+
+	rc = l1_packet_get_int(&args, &arglen, &brick_type);
+	if (rc)
+		return rc;
+
+	return brick_type & 0xff;
+}
+
+int l1_read_brick_type(void)
+{
+	unsigned long flags;
+	int rc;
+
+	spin_lock_irqsave(&l1_lock, flags);
+	rc = l1_get_brick_type();
+	spin_unlock_irqrestore(&l1_lock, flags);
+
+	return rc;
+}
+
 static u8 ip27_l1_mac_addr[ETH_ALEN];
 static bool ip27_l1_mac_addr_valid;
 static bool ip27_l1_mac_addr_tried;
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 36/38] MIPS: SGI-IP27: register the Odyssey graphics widget
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (34 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 35/38] MIPS: SGI-IP27: identify the machine by the L1 brick type Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 37/38] MIPS: SGI-IP27: take the console from the KLCONFIG header on IP35 Imre Kaloz
  2026-10-01 16:12 ` [PATCH 38/38] MIPS: SGI-IP27: give each CPU its own topology package id Imre Kaloz
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

The Odyssey (VPro) graphics widget is a direct xtalk widget with no PCI
bridge in front of it, so it needs a platform_device of its own rather
than piggybacking on bridge_platform_create(). Its register aperture is
the widget's small window, and the sgi-odyssey DRM driver binds it.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-xtalk.c | 28 ++++++++++++++++++++++++++++
 1 file changed, 28 insertions(+)

diff --git a/arch/mips/sgi-ip27/ip27-xtalk.c b/arch/mips/sgi-ip27/ip27-xtalk.c
index 091186cb7a04..b754bbb3ca33 100644
--- a/arch/mips/sgi-ip27/ip27-xtalk.c
+++ b/arch/mips/sgi-ip27/ip27-xtalk.c
@@ -7,6 +7,7 @@
  * Generic XTALK initialization code
  */
 
+#include <linux/err.h>
 #include <linux/kernel.h>
 #include <linux/smp.h>
 #include <linux/platform_device.h>
@@ -24,6 +25,9 @@
 #define PXBOW_WIDGET_PART_NUM	0xd100	/* PXbow */
 #define BASE_XBOW_PORT		8     /* Lowest external port */
 
+/* Odyssey's register aperture, as sized by the sgi-odyssey driver. */
+#define ODYSSEY_REG_SIZE		0x00410000
+
 enum xtalk_bridge_type {
 	XTALK_BRIDGE,
 	XTALK_XBRIDGE,
@@ -167,6 +171,27 @@ static void bridge_platform_create(nasid_t nasid, int widget, int masterwid,
 	return;
 }
 
+static void odyssey_platform_create(nasid_t nasid, int widget)
+{
+	struct platform_device *pdev;
+	struct resource res;
+
+	memset(&res, 0, sizeof(res));
+	res.name = "sgi-odyssey";
+	res.start = NODE_OFFSET(nasid) + (widget << SWIN_SIZE_BITS);
+	res.end = res.start + ODYSSEY_REG_SIZE - 1;
+	res.flags = IORESOURCE_MEM;
+
+	pr_info("xtalk:n%d/%x odyssey widget: reg=[%pa-%pa]\n",
+		nasid, widget, &res.start, &res.end);
+
+	pdev = platform_device_register_simple("sgi-odyssey",
+					       PLATFORM_DEVID_AUTO, &res, 1);
+	if (IS_ERR(pdev))
+		pr_warn("xtalk:n%d/%x odyssey platform device registration failed: %ld\n",
+			nasid, widget, PTR_ERR(pdev));
+}
+
 static int probe_one_port(nasid_t nasid, int widget, int masterwid)
 {
 	widgetreg_t		widget_id;
@@ -190,6 +215,9 @@ static int probe_one_port(nasid_t nasid, int widget, int masterwid)
 		bridge_platform_create(nasid, widget, masterwid,
 				       XTALK_PIC_BUS1);
 		break;
+	case WIDGET_ODYS_PART_NUM:
+		odyssey_platform_create(nasid, widget);
+		break;
 	default:
 		pr_info("xtalk:n%d/%d unknown widget (0x%x)\n",
 			nasid, widget, partnum);
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 37/38] MIPS: SGI-IP27: take the console from the KLCONFIG header on IP35
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (35 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 36/38] MIPS: SGI-IP27: register the Odyssey graphics widget Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  2026-10-01 16:12 ` [PATCH 38/38] MIPS: SGI-IP27: give each CPU its own topology package id Imre Kaloz
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

An IP35 PROM records its console UART and baud rate in the KLCONFIG
header. That UART is ttyS0 on Fuel and Tezro, so when the record is
present and the command line names no console, prefer ttyS0 at that baud
rate.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-init.c | 22 ++++++++++++++++++++++
 1 file changed, 22 insertions(+)

diff --git a/arch/mips/sgi-ip27/ip27-init.c b/arch/mips/sgi-ip27/ip27-init.c
index 7f16d7f437c9..6a15ba577b60 100644
--- a/arch/mips/sgi-ip27/ip27-init.c
+++ b/arch/mips/sgi-ip27/ip27-init.c
@@ -6,6 +6,7 @@
  * Copyright (C) 2000 - 2001 by Kanoj Sarcar (kanoj@sgi.com)
  * Copyright (C) 2000 - 2001 by Silicon Graphics, Inc.
  */
+#include <linux/console.h>
 #include <linux/kernel.h>
 #include <linux/init.h>
 #include <linux/sched.h>
@@ -164,6 +165,26 @@ static void __init ip27_set_machine_name(void)
 		gfx ? "with" : "without");
 }
 
+/*
+ * Prefer ttyS0 at the baud rate the IP35 PROM recorded for its console
+ * UART in the KLCONFIG header.
+ */
+static void __init ip27_setup_console(void)
+{
+	static char options[8];
+	console_t *cons;
+
+	if (!system_is_ip35 || strstr(arcs_cmdline, "console="))
+		return;
+
+	cons = KL_CONFIG_CH_CONS_INFO(master_nasid);
+	if (!cons->uart_base)
+		return;
+
+	snprintf(options, sizeof(options), "%d", cons->baud);
+	add_preferred_console("ttyS", 0, options);
+}
+
 void __init plat_mem_setup(void)
 {
 	u64 p, e, n_mode;
@@ -215,6 +236,7 @@ void __init plat_mem_setup(void)
 	set_io_port_base(IO_BASE);
 
 	ip27_set_machine_name();
+	ip27_setup_console();
 }
 
 const char *get_system_type(void)
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

* [PATCH 38/38] MIPS: SGI-IP27: give each CPU its own topology package id
  2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
                   ` (36 preceding siblings ...)
  2026-10-01 16:12 ` [PATCH 37/38] MIPS: SGI-IP27: take the console from the KLCONFIG header on IP35 Imre Kaloz
@ 2026-10-01 16:12 ` Imre Kaloz
  37 siblings, 0 replies; 39+ messages in thread
From: Imre Kaloz @ 2026-10-01 16:12 UTC (permalink / raw)
  To: Thomas Bogendoerfer; +Cc: linux-mips, linux-kernel

cpu_data[].package is left at its zero-init default, so /proc/cpuinfo
and cpu_core_map treat every CPU in the system as one package, though
each PI slice is a separate physical processor. Derive it from the
klconfig nasid and physid node_scan_cpus() already records as the
CPU's slice.

Signed-off-by: Imre Kaloz <kaloz@kernel.org>
---
 arch/mips/sgi-ip27/ip27-smp.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/arch/mips/sgi-ip27/ip27-smp.c b/arch/mips/sgi-ip27/ip27-smp.c
index fc4d9379a93e..c155582699d4 100644
--- a/arch/mips/sgi-ip27/ip27-smp.c
+++ b/arch/mips/sgi-ip27/ip27-smp.c
@@ -47,6 +47,13 @@ static int node_scan_cpus(nasid_t nasid, int highest)
 				set_cpu_possible(cpuid, true);
 				cputonasid(cpus_found) = nasid;
 				cputoslice(cpus_found) = acpu->cpu_info.physid;
+				/*
+				 * Each PI slice is a separate physical CPU
+				 * package; these processors have no on-die
+				 * multiprocessing, so core is 0.
+				 */
+				cpu_data[cpus_found].package =
+					(nasid << 2) | acpu->cpu_info.physid;
 				sn_cpu_info[cpus_found].p_speed =
 							acpu->cpu_speed;
 				cpus_found++;
@@ -85,6 +92,7 @@ void cpu_node_probe(void)
 		if (cputonasid(i) == master_nasid &&
 		    cputoslice(i) == LOCAL_HUB_L(PI_CPU_NUM)) {
 			swap(sn_cpu_info[0], sn_cpu_info[i]);
+			swap(cpu_data[0].package, cpu_data[i].package);
 			break;
 		}
 	}
-- 
2.47.3


^ permalink raw reply	[flat|nested] 39+ messages in thread

end of thread, other threads:[~2026-10-01 16:14 UTC | newest]

Thread overview: 39+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-01 16:11 [PATCH 00/38] MIPS: SGI-IP27: add support for the IP35 (Bedrock hub) machines Imre Kaloz
2026-10-01 16:11 ` [PATCH 01/38] MIPS: Xtalk: guard the widget identification table from assembly Imre Kaloz
2026-10-01 16:11 ` [PATCH 02/38] MIPS: SGI-IP27: dump the NMI save areas the CPU scan recorded Imre Kaloz
2026-10-01 16:11 ` [PATCH 03/38] MIPS: SGI-IP27: add REMOTE_HUB_PI_S()/REMOTE_HUB_PI_L() Imre Kaloz
2026-10-01 16:11 ` [PATCH 04/38] MIPS: SGI-IP27: detect Bedrock hubs at boot Imre Kaloz
2026-10-01 16:11 ` [PATCH 05/38] MIPS: SGI-IP27: widen Kconfig for the Bedrock-based machines Imre Kaloz
2026-10-01 16:11 ` [PATCH 06/38] MIPS: SGI-IP27: fold the dead SN1 arm out of klconfig.h Imre Kaloz
2026-10-01 16:11 ` [PATCH 07/38] MIPS: SGI-IP27: choose the node address layout at runtime Imre Kaloz
2026-10-01 16:11 ` [PATCH 08/38] MIPS: SGI-IP27: add the Bedrock hub register windows Imre Kaloz
2026-10-01 16:11 ` [PATCH 09/38] MIPS: SGI-IP27: decode a Bedrock hub's node id and system size Imre Kaloz
2026-10-01 16:11 ` [PATCH 10/38] MIPS: SGI-IP27: put a Bedrock hub's boot CPU in slot 0 Imre Kaloz
2026-10-01 16:11 ` [PATCH 11/38] MIPS: SGI-IP27: lay out node memory in 1GB banks on Bedrock hubs Imre Kaloz
2026-10-01 16:11 ` [PATCH 12/38] MIPS: SGI-IP27: reserve the bottom 64MB of node 0 " Imre Kaloz
2026-10-01 16:11 ` [PATCH 13/38] MIPS: SGI-IP27: route interrupt masks and slices through both PIs Imre Kaloz
2026-10-01 16:11 ` [PATCH 14/38] MIPS: SGI-IP27: address a CPU's own PI for NMI, IPI and RT counter Imre Kaloz
2026-10-01 16:11 ` [PATCH 15/38] MIPS: SGI-IP27: take a CPU's node from the CPU table in per_cpu_init() Imre Kaloz
2026-10-01 16:11 ` [PATCH 16/38] MIPS: SGI-IP27: resolve the mapped-kernel node shift at runtime Imre Kaloz
2026-10-01 16:11 ` [PATCH 17/38] MIPS: SGI-IP27: load the kernel at node offset 0x40000 Imre Kaloz
2026-10-01 16:11 ` [PATCH 18/38] MIPS: SGI-IP27: xbow_probe(): recognize KLTYPE_PBRICK_XBOW Imre Kaloz
2026-10-01 16:11 ` [PATCH 19/38] MIPS: ip27_defconfig: enable the IOC3 MFD, its cell drivers and tg3 Imre Kaloz
2026-10-01 16:11 ` [PATCH 20/38] net: ethernet: sgi: ioc3-eth: apply the DMA attributes only to 64-bit addresses Imre Kaloz
2026-10-01 16:11 ` [PATCH 21/38] MIPS: SGI-IP27: route XBridge and PIC DMA through the 32-bit window Imre Kaloz
2026-10-01 16:11 ` [PATCH 22/38] MIPS: SGI-IP27: recognize the PXBow crossbar Imre Kaloz
2026-10-01 16:11 ` [PATCH 23/38] MIPS: PCI: xtalk-bridge: recognize the PIC widget's 64-bit-only registers Imre Kaloz
2026-10-01 16:11 ` [PATCH 24/38] MIPS: PCI: xtalk-bridge: match PIC's register-level differences Imre Kaloz
2026-10-01 16:12 ` [PATCH 25/38] rtc: m48t35: support the SGI IP35 timekeeper's 1968 year base Imre Kaloz
2026-10-01 16:12 ` [PATCH 26/38] mfd: ioc3: add support for IOC4 Imre Kaloz
2026-10-01 16:12 ` [PATCH 27/38] MIPS: SGI-IP27: dispatch the early console between IOC3 and IOC4 Imre Kaloz
2026-10-01 16:12 ` [PATCH 28/38] MIPS: SGI-IP27: add L1 system controller support Imre Kaloz
2026-10-01 16:12 ` [PATCH 29/38] MIPS: SGI-IP27: wire the L1 into reset and the Ethernet address Imre Kaloz
2026-10-01 16:12 ` [PATCH 30/38] MIPS: PCI: xtalk-bridge: take the board part number from the L1 Imre Kaloz
2026-10-01 16:12 ` [PATCH 31/38] mfd: ioc3: add IP34 system-board entry to ioc3_infos[] Imre Kaloz
2026-10-01 16:12 ` [PATCH 32/38] net: ethernet: sgi: ioc3-eth: fall back to the platform MAC address Imre Kaloz
2026-10-01 16:12 ` [PATCH 33/38] MIPS: SGI-IP27: don't register a w1 master on an XBridge or PIC Imre Kaloz
2026-10-01 16:12 ` [PATCH 34/38] MIPS: SGI-IP27: report a Bedrock machine as SGI IP35 Imre Kaloz
2026-10-01 16:12 ` [PATCH 35/38] MIPS: SGI-IP27: identify the machine by the L1 brick type Imre Kaloz
2026-10-01 16:12 ` [PATCH 36/38] MIPS: SGI-IP27: register the Odyssey graphics widget Imre Kaloz
2026-10-01 16:12 ` [PATCH 37/38] MIPS: SGI-IP27: take the console from the KLCONFIG header on IP35 Imre Kaloz
2026-10-01 16:12 ` [PATCH 38/38] MIPS: SGI-IP27: give each CPU its own topology package id Imre Kaloz

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®