From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D747230DD2F for ; Wed, 30 Sep 2026 05:57:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790747829; cv=none; b=GkOw3XWpLZ0MmS4BMYdrVBPZgDfdF5IJaMYuvY6WJUj01PpVMInvDnvQx6IOM3o8/r0am+cNPQH3Agh99AH0pk3U3RMFeDvoF9hi0zo1/OaRTV2cfGv6t1/VRc2Zk5bKlyN5U26HAqMiZWa8vkOBzcZrjaSpE73NM05Rg1B3+zE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790747829; c=relaxed/simple; bh=7hDT9ijRUqs84SbsacWmodAEcXjxGZGqdCHnJ1MPieY=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=U5+G+qXB1x2tB+nMmajss/MoDsk0wKnhb0RZEr4dZfJAvgY0FOtthCht+dADDaZfjbOlE4hQw96mFaWwSU8s+miMPwVWZxSzWjXqe9vhqB+jWWFfYS/YcjOd/kFR4+IveSWf6uzzytf/rNjg3DdtEQCwwTSMAwwHCojdhSO7nVA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=fq2Pk2EM; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=Vl1DdP+x; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="fq2Pk2EM"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="Vl1DdP+x" Received: from pps.filterd (m0279872.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 68U1AQXc1264055 for ; Wed, 30 Sep 2026 05:57:05 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= Q0GPd3zTZFYp2lJxk97RxyfRjqzFT4bjAoTIW7luDbo=; b=fq2Pk2EMKZELqvbn 3q6FtSuW0Mjbp52tVuR4vo+w9tr1/3QBt/LLnKGd8IZQjDCa/muUF5Hs74hiyt9j kUkJPmTa1hRZuK2oQVqFvVGjZT06LS3La/bVpG9Jtb8Cz9nNUEIZ1PMtYWTT5DWl wkE0vgMWH1BRYPC1J9IUIKh3S+RpxCV7AG9NTqajOBv29gIEC1ydSJi7XzSIX6WE dUPLdEiE3vkaI2+ALozFq178Fb2maioZ0tvpdNzfubMPdT/7rya2LqZjRBKvmC3H 0f2SD5QYYuxTpumUmgH17YiOKzjl8gd/bPgd6JJv29s/79srUf0TY3FhCRPBNLs9 WDvFmg== Received: from mail-pf1-f198.google.com (mail-pf1-f198.google.com [209.85.210.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4h0rheh3tg-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 30 Sep 2026 05:57:05 +0000 (GMT) Received: by mail-pf1-f198.google.com with SMTP id d2e1a72fcca58-8710450f731so3494208b3a.0 for ; Tue, 29 Sep 2026 22:57:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1790747824; x=1791352624; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Q0GPd3zTZFYp2lJxk97RxyfRjqzFT4bjAoTIW7luDbo=; b=Vl1DdP+xD7OBj0rGIVjwyQLQLtbiZbZoV5z0wyT/+fb8E9I2zxdntUe/EhkWT1s2/V JtjkRACV9SFnAu/gyGg1nTmcs2Trpa9GiSomfCKoM+F8xg6IUJhN1JeERijdm3Kg2BLF 0hx/XiJ55s7TnKim9IGWuPZlUN5pEXZD/QYlXrnOLJTlfEgfyZCqDl6DgyJ87kpzKzps srybmj3x8MLrt5i8oOpuMTSd7uV2VprDUvI+sSZ5DNysGYIjLbG1ogm9BM31mbgIUxj7 oTPhD/IisR1VUt0v/vTlLZpf2+oLq4rCO83PbhjaUzZCegmVpEM3d4QNoQ0dpBze4jD6 VkBg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790747824; x=1791352624; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Q0GPd3zTZFYp2lJxk97RxyfRjqzFT4bjAoTIW7luDbo=; b=Amq/X6mwg4LiByTRwRo7P/LMvTucEScwJqIKwRHgKIr/S0QVtT6u44fUzlyawmYXCH 0hDPgJwCrRVWjFN8X5VBSu9T67yWkGqW3tGyrb4NcdA20jRvo2R2B0soVFuKQA9J71uc 9CamVis1QiaqlyI9YiyEVqpja2yMw+Vef4ho2vx1gpJ5iVAJ4fvye0PyC2g4s0W9/HeK s90Lbuu5kzR2zrKZ3ogFouAjbdTxJN5f+T0R77zS4K9pkC41lX/1CHXbRD+482MZA+Zg XiEuaxT7uHe1oO358sqGpntkPdWCC9Dr/JxCNdxOU0WekW8LslduyWSrXORNmH3eJFFw lOVw== X-Forwarded-Encrypted: i=1; AKwUvBzuweOykAaqn2omIONGas/5PW6edhaIWm47tVuLfNcYU7BpPuH4MEHXv5TbijnnpWSGwYSZFI46PDBd74M=@vger.kernel.org X-Gm-Message-State: AFuF++mLtcjLb8AI6qo6qHn1zTSVrRQoFhZeZsvxK6Ufg1YW/GqY2yvP uukZ/EczTJm9H9Gp8PqDVPB8VKLtpX8rPyLt6K2nEcYD55rZYxmxGr7ezBgMYtARUzNt9QAzmKs cU8ae4wl6hTeX9wxYnA2CxKBfGet8osp3bYm86BnSm9K0IRvUwzlvkCCLofx8gSzIV8NJEZXjjc 0= X-Gm-Gg: AYBFou1q4xcwtwlaWGHkDCr97+oW7VcWo6D59FqmgnbHaNNxP/IDz8M7bHXRduLDThr wFcrZzSv/IhSZJ0ZhAjJpZ1FRMztcOx8tILo/SQKJzv3bwoTxUiFmgWc++Vsyt9G5ca458cV/yk TdFyIb5Uo8q2MIvLODLA7XaFZnIObvn1ZdEGw6BfcedqvtfCPx7gm0HoyIytJJlct2IQWYIo75D tqOo7EQEpwDReJguvFf1i5nEFst550ouTNaiHhsRhw2O5H9ZYw0bh9nWPTKBv2KvNxM8VDwA2SM T4KvTtSOB/mShVq/9cCFQqQNH4u+o29d66BFp07igzG+7sFwZgIXK6DiqHKB2FIMP8DpBc/JMbK EgRPyQ3gu4k4nRsuqaPv8Ki3tpi+L X-Received: by 2002:a05:6a00:14d3:b0:878:3507:8d62 with SMTP id d2e1a72fcca58-8874ed0a74fmr201178b3a.41.1790747824344; Tue, 29 Sep 2026 22:57:04 -0700 (PDT) X-Received: by 2002:a05:6a00:14d3:b0:878:3507:8d62 with SMTP id d2e1a72fcca58-8874ed0a74fmr201157b3a.41.1790747823603; Tue, 29 Sep 2026 22:57:03 -0700 (PDT) Received: from [10.217.216.255] ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-88726441614sm239987b3a.49.2026.09.29.22.57.01 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 29 Sep 2026 22:57:03 -0700 (PDT) Message-ID: Date: Wed, 30 Sep 2026 11:26:59 +0530 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v6 1/3] bus: mhi: host: clients: Add loopback driver with sysfs interface To: Manivannan Sadhasivam Cc: Jeff Hugo , mhi@lists.linux.dev, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, Krishna Chaitanya Chundru References: <20260908-lb-v6-0-66755ceb16cc@oss.qualcomm.com> <20260908-lb-v6-1-66755ceb16cc@oss.qualcomm.com> Content-Language: en-US From: Sumit Kumar In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Proofpoint-GUID: 7bcRG3aeziF_nHa5ehHsld29H9kJ9s0H X-Proofpoint-ORIG-GUID: 7bcRG3aeziF_nHa5ehHsld29H9kJ9s0H X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTMwMDAyMyBTYWx0ZWRfXwLz7v4EnMwna lduXV2nqDya79vW1qVv8dXqrzrnTfyHb5FGkGzBYAmZ2XlRqGVZRAS4SVXzPriZULEVR00wJABO dckmARV3DZ6ImJzxXs8f+mEBCwOEiEAkyACb0/YNa6gZnVP2S+hkmEooM2II8Gkx3p73jpYz8D6 hhAzO4HNGn/IZuBeDGvsgU+sV7qEP1RdWs4OLiyXO1c1iOWH3SWKo2EwjlfTDDP1y/HOo+KRShD v0fu/Q9jnwpMM+slLV1EQREdgF8kFWKjJSrlYCfX5tR0wd4ovmV2A+Z2m3My/n74zY3LeL2cOS3 xdZnOPzobbS6REiRbOxQqVHc+oYz9Vc99r70DExLhuj0kUw5lmtXMzpS4D6fQ6J033Cg8yz/8Hu HLICXAyRtBROMdHBzNx/VvCPZmLebk5YQMWSaLtD8NnIJfCDrV6eM6EsbbFuRX8cGvcF6Dnelcm vhOEjRl7r6dgwsZmxkw== X-Proofpoint-Spam-Info: AW1haW4tMjYwOTMwMDAyMyBTYWx0ZWRfXwo0wtWGkrKAE jgFdxS10ZcpRkRFypo2+pZuvAvn6b+w76zOTBdMAm5I9hpX2JRGXRyd3Ge8VLnhMEtozNKLxLpK CmhW7yU9WPhp+nvJEfkV1XwHMuisONk= X-Authority-Analysis: v=2.4 cv=Tu1zFzXh c=1 sm=1 tr=0 ts=6abca4b1 cx=c_pps a=m5Vt/hrsBiPMCU0y4gIsQw==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=yx91gb_oNiZeI1HMLzn7:22 a=EUspDBNiAAAA:8 a=VwQbUJbxAAAA:8 a=xgnnbfARpDOHo6esDpYA:9 a=QEXdDO2ut3YA:10 a=IoOABgeZipijB_acs4fv:22 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-29_05,2026-09-21_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 spamscore=0 malwarescore=0 suspectscore=0 phishscore=0 lowpriorityscore=0 adultscore=0 clxscore=1015 bulkscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2609040000 definitions=main-2609300023 On 9/26/2026 4:36 PM, Manivannan Sadhasivam wrote: > On Tue, Sep 08, 2026 at 02:57:22PM +0530, Sumit Kumar wrote: >> The MHI specification defines a LOOPBACK channel. The endpoint firmware >> echoes back whatever the host sends on this channel. Without a host-side >> driver, there is no way to exercise this channel to validate MHI data path >> integrity between host and endpoint. >> >> Add a host-side loopback driver that binds to the LOOPBACK channel and >> expose a sysfs interface for data path testing. The sysfs interface allows >> users to configure TRE buffer size and count, trigger a loopback test, and >> read the result. >> >> The new sysfs ABI is documented under Documentation/ABI/testing/, not >> stable/, since this is a new interface without established API >> guarantees yet. It is unrelated to the existing stable MHI sysfs ABI >> documented in Documentation/ABI/stable/sysfs-bus-mhi, despite both >> being covered by the same MAINTAINERS entry. >> >> Co-developed-by: Krishna Chaitanya Chundru >> Signed-off-by: Krishna Chaitanya Chundru >> Signed-off-by: Sumit Kumar >> --- >> .../ABI/testing/sysfs-bus-mhi-devices-loopback | 40 +++ >> MAINTAINERS | 1 + >> drivers/bus/mhi/host/Kconfig | 1 + >> drivers/bus/mhi/host/Makefile | 1 + >> drivers/bus/mhi/host/clients/Kconfig | 17 ++ >> drivers/bus/mhi/host/clients/Makefile | 2 + >> drivers/bus/mhi/host/clients/loopback.c | 287 +++++++++++++++++++++ >> 7 files changed, 349 insertions(+) >> >> diff --git a/Documentation/ABI/testing/sysfs-bus-mhi-devices-loopback b/Documentation/ABI/testing/sysfs-bus-mhi-devices-loopback >> new file mode 100644 >> index 0000000000000000000000000000000000000000..9e47e8443f309199691a50d70adadf84f3237037 >> --- /dev/null >> +++ b/Documentation/ABI/testing/sysfs-bus-mhi-devices-loopback >> @@ -0,0 +1,40 @@ >> +What: /sys/bus/mhi/devices/mhi_LOOPBACK/tre_size >> +Date: August 2026 >> +KernelVersion: 7.4 >> +Contact: mhi@lists.linux.dev >> +Description: >> + (RW) Size of each Transfer Ring Element (TRE) buffer in bytes >> + used for the loopback test. Valid range is 1 to the value >> + reported by max_tre_size. Default value is 32 bytes. >> + >> +What: /sys/bus/mhi/devices/mhi_LOOPBACK/max_tre_size >> +Date: August 2026 >> +KernelVersion: 7.4 >> +Contact: mhi@lists.linux.dev >> +Description: >> + (RO) Maximum allowed Transfer Ring Element (TRE) size in bytes. >> + Reading this file returns the upper bound for the tre_size >> + attribute. >> + >> +What: /sys/bus/mhi/devices/mhi_LOOPBACK/num_tre >> +Date: August 2026 >> +KernelVersion: 7.4 >> +Contact: mhi@lists.linux.dev >> +Description: >> + (RW) Number of Transfer Ring Elements (TREs) to use per >> + loopback test. Must be greater than zero and must not exceed >> + the channel ring capacity. Default value is 1. > How does the user know 'channel ring capacity'? If the user enters a number greater than the ring capacity the error will log the max num_tre value. Would you prefer having a new sysfs entry similar to 'max_tre_size'? something like 'max_num_tre'. > >> + >> +What: /sys/bus/mhi/devices/mhi_LOOPBACK/start >> +Date: August 2026 >> +KernelVersion: 7.4 >> +Contact: mhi@lists.linux.dev >> +Description: >> + (WO) Write any value to trigger a loopback test. The driver >> + sends random data to the endpoint using the configured tre_size >> + and num_tre parameters, waits for the endpoint to echo it back, >> + and verifies the received data matches what was sent. >> + >> + This is a blocking write that returns when the test completes >> + or times out after 5 seconds. The write returns an error code >> + if the test fails or times out. >> diff --git a/MAINTAINERS b/MAINTAINERS >> index 70663089f071c4eaa07fe7b9baf9003d8b981c07..b10f8cd592954e1450e5851045962bf05dcf1a50 100644 >> --- a/MAINTAINERS >> +++ b/MAINTAINERS >> @@ -17628,6 +17628,7 @@ L: linux-arm-msm@vger.kernel.org >> S: Maintained >> T: git git://git.kernel.org/pub/scm/linux/kernel/git/mani/mhi.git >> F: Documentation/ABI/stable/sysfs-bus-mhi >> +F: Documentation/ABI/testing/sysfs-bus-mhi-devices-loopback >> F: Documentation/mhi/ >> F: drivers/bus/mhi/ >> F: drivers/pci/endpoint/functions/pci-epf-mhi.c >> diff --git a/drivers/bus/mhi/host/Kconfig b/drivers/bus/mhi/host/Kconfig >> index da5cd0c9fc620ab595e742c422f1a22a2a84c7b9..627c57948235aa52348179ae8b2d0826ebaed01e 100644 >> --- a/drivers/bus/mhi/host/Kconfig >> +++ b/drivers/bus/mhi/host/Kconfig >> @@ -29,3 +29,4 @@ config MHI_BUS_PCI_GENERIC >> This driver provides MHI PCI controller driver for devices such as >> Qualcomm SDX55 based PCIe modems. >> >> +source "drivers/bus/mhi/host/clients/Kconfig" >> diff --git a/drivers/bus/mhi/host/Makefile b/drivers/bus/mhi/host/Makefile >> index 859c2f38451c669b3d3014c374b2b957c99a1cfe..2a16008aeb38127494782bbff4e1656428d2b776 100644 >> --- a/drivers/bus/mhi/host/Makefile >> +++ b/drivers/bus/mhi/host/Makefile >> @@ -4,3 +4,4 @@ mhi-$(CONFIG_MHI_BUS_DEBUG) += debugfs.o >> >> obj-$(CONFIG_MHI_BUS_PCI_GENERIC) += mhi_pci_generic.o >> mhi_pci_generic-y += pci_generic.o >> +obj-y += clients/ >> diff --git a/drivers/bus/mhi/host/clients/Kconfig b/drivers/bus/mhi/host/clients/Kconfig >> new file mode 100644 >> index 0000000000000000000000000000000000000000..8bb5715e61d0d6e64a51012b4e1594ba46e5bfc1 >> --- /dev/null >> +++ b/drivers/bus/mhi/host/clients/Kconfig >> @@ -0,0 +1,17 @@ >> +# SPDX-License-Identifier: GPL-2.0 >> + >> +config MHI_BUS_LOOPBACK >> + tristate "MHI LOOPBACK client driver" >> + depends on MHI_BUS >> + help >> + MHI LOOPBACK client driver that binds to the MHI LOOPBACK channel >> + as defined in the MHI specification. The LOOPBACK channel is >> + implemented by MHI-based devices (e.g. modems, WLAN) in the field, >> + where the endpoint firmware echoes back whatever the host sends. >> + >> + This driver exposes a sysfs interface for testing MHI data path >> + integrity between host and endpoint. Users can configure the TRE >> + size and count, and trigger a loopback test. >> + >> + To compile this driver as a module, choose M here. The module >> + will be called mhi_loopback. >> diff --git a/drivers/bus/mhi/host/clients/Makefile b/drivers/bus/mhi/host/clients/Makefile >> new file mode 100644 >> index 0000000000000000000000000000000000000000..3811b6928f42b38f94b1167941cf3b0fe512d32b >> --- /dev/null >> +++ b/drivers/bus/mhi/host/clients/Makefile >> @@ -0,0 +1,2 @@ >> +obj-$(CONFIG_MHI_BUS_LOOPBACK) += mhi_loopback.o >> +mhi_loopback-y += loopback.o >> diff --git a/drivers/bus/mhi/host/clients/loopback.c b/drivers/bus/mhi/host/clients/loopback.c >> new file mode 100644 >> index 0000000000000000000000000000000000000000..058a8b587933245230eaae61bb7fe3361d4a362a >> --- /dev/null >> +++ b/drivers/bus/mhi/host/clients/loopback.c >> @@ -0,0 +1,287 @@ >> +// SPDX-License-Identifier: GPL-2.0 >> +/* >> + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. >> + */ >> + >> +#include >> +#include >> +#include >> +#include >> +#include >> +#include >> +#include >> +#include >> +#include >> +#include >> +#include >> +#include >> +#include >> + >> +#define MHI_LOOPBACK_DEFAULT_TRE_SIZE 32 >> +#define MHI_LOOPBACK_DEFAULT_NUM_TRE 1 >> +#define MHI_LOOPBACK_TIMEOUT_MS 5000 >> +#define MHI_LOOPBACK_MAX_TRE_SIZE (SZ_64K - 1) >> + >> +struct mhi_loopback { >> + struct mhi_device *mdev; >> + /* Serializes the sysfs attributes against a running test */ >> + struct mutex lb_mutex; >> + struct completion comp; >> + /* Tracks outstanding DL+UL completions; comp fires when it hits zero */ > This variable is only used in dl_callback. > >> + atomic_t tre_pending; >> + u32 num_tre; >> + u32 tre_size; >> +}; >> + >> +static ssize_t tre_size_show(struct device *dev, >> + struct device_attribute *attr, char *buf) >> +{ >> + struct mhi_loopback *loopback = dev_get_drvdata(dev); >> + >> + return sysfs_emit(buf, "%u\n", loopback->tre_size); >> +} >> + >> +static ssize_t tre_size_store(struct device *dev, >> + struct device_attribute *attr, >> + const char *buf, size_t count) >> +{ >> + struct mhi_loopback *loopback = dev_get_drvdata(dev); >> + u32 val; >> + >> + if (kstrtou32(buf, 0, &val)) >> + return -EINVAL; >> + >> + if (val == 0 || val > MHI_LOOPBACK_MAX_TRE_SIZE) >> + return -EINVAL; >> + >> + guard(mutex)(&loopback->lb_mutex); >> + loopback->tre_size = val; >> + >> + return count; >> +} >> +static DEVICE_ATTR_RW(tre_size); >> + >> +static ssize_t max_tre_size_show(struct device *dev, >> + struct device_attribute *attr, char *buf) >> +{ >> + return sysfs_emit(buf, "%u\n", MHI_LOOPBACK_MAX_TRE_SIZE); >> +} >> +static DEVICE_ATTR_RO(max_tre_size); >> + >> +static ssize_t num_tre_show(struct device *dev, >> + struct device_attribute *attr, char *buf) >> +{ >> + struct mhi_loopback *loopback = dev_get_drvdata(dev); >> + >> + return sysfs_emit(buf, "%u\n", loopback->num_tre); >> +} >> + >> +static ssize_t num_tre_store(struct device *dev, >> + struct device_attribute *attr, >> + const char *buf, size_t count) >> +{ >> + struct mhi_loopback *loopback = dev_get_drvdata(dev); >> + u32 val; >> + int el_num; >> + >> + if (kstrtou32(buf, 0, &val)) >> + return -EINVAL; >> + >> + if (val == 0) >> + return -EINVAL; >> + >> + guard(mutex)(&loopback->lb_mutex); >> + >> + el_num = min(mhi_get_free_desc_count(loopback->mdev, DMA_TO_DEVICE), >> + mhi_get_free_desc_count(loopback->mdev, DMA_FROM_DEVICE)); >> + if (val > el_num) { >> + dev_err(dev, "num_tre (%u) exceeds ring capacity (%d)\n", val, el_num); >> + return -EINVAL; >> + } >> + >> + loopback->num_tre = val; >> + >> + return count; >> +} >> +static DEVICE_ATTR_RW(num_tre); >> + >> +static ssize_t start_store(struct device *dev, >> + struct device_attribute *attr, >> + const char *buf, size_t count) >> +{ >> + struct mhi_loopback *loopback = dev_get_drvdata(dev); >> + u32 total_size, tre_count, tre_size; >> + int i, ret; >> + >> + guard(mutex)(&loopback->lb_mutex); >> + >> + tre_size = loopback->tre_size; >> + tre_count = loopback->num_tre; >> + total_size = size_mul(tre_count, tre_size); >> + >> + if (total_size > KMALLOC_MAX_SIZE) >> + return -EINVAL; >> + >> + if (tre_count > mhi_get_free_desc_count(loopback->mdev, DMA_TO_DEVICE) || >> + tre_count > mhi_get_free_desc_count(loopback->mdev, DMA_FROM_DEVICE)) { >> + dev_err(dev, "Not enough ring space for %u TREs\n", tre_count); >> + return -ENOSPC; >> + } >> + >> + void *recv_buf __free(kfree) = kzalloc(total_size, GFP_KERNEL); >> + if (!recv_buf) >> + return -ENOMEM; >> + >> + void *send_buf __free(kfree) = kzalloc(total_size, GFP_KERNEL); >> + if (!send_buf) >> + return -ENOMEM; >> + >> + get_random_bytes(send_buf, total_size); >> + >> + atomic_set(&loopback->tre_pending, tre_count); >> + reinit_completion(&loopback->comp); >> + >> + for (i = 0; i < tre_count; i++) { >> + ret = mhi_queue_buf(loopback->mdev, DMA_FROM_DEVICE, >> + recv_buf + (i * tre_size), tre_size, MHI_EOT); >> + if (ret) { >> + dev_err(dev, "Unable to queue read TRE %d: %d\n", i, ret); >> + if (atomic_sub_and_test(tre_count - i, &loopback->tre_pending)) >> + complete(&loopback->comp); >> + return ret; > Both recv_buf and send_buf are allocated with '__free' cleanup. So these buffers > will get freed once this function exits. But these buffer might've already > queued to the device in past iterations, making these pointers dangling. > > Maybe you should reset the channel as you've done below for completion timeout? will create a reset channel function and will call that in both paths. > >> + } >> + } >> + >> + for (i = 0; i < tre_count - 1; i++) { >> + ret = mhi_queue_buf(loopback->mdev, DMA_TO_DEVICE, >> + send_buf + (i * tre_size), tre_size, MHI_CHAIN); >> + if (ret) { >> + dev_err(dev, "Unable to queue send TRE %d: %d\n", i, ret); >> + return ret; >> + } >> + } >> + >> + ret = mhi_queue_buf(loopback->mdev, DMA_TO_DEVICE, >> + send_buf + (i * tre_size), tre_size, MHI_EOT); >> + if (ret) { >> + dev_err(dev, "Unable to queue final TRE: %d\n", ret); >> + return ret; >> + } >> + >> + if (!wait_for_completion_timeout(&loopback->comp, >> + msecs_to_jiffies(MHI_LOOPBACK_TIMEOUT_MS))) { >> + dev_err(dev, "Loopback test timed out\n"); >> + /* Reset the channel to reclaim the TREs still pointing at the buffers */ >> + mhi_unprepare_from_transfer(loopback->mdev); >> + ret = mhi_prepare_for_transfer(loopback->mdev); >> + if (ret) >> + dev_err(dev, "Failed to re-prepare channel for transfers: %d\n", ret); >> + >> + return -ETIMEDOUT; >> + } >> + >> + if (memcmp(send_buf, recv_buf, total_size)) { >> + dev_err(dev, "Loopback data mismatch\n"); >> + return -EIO; >> + } >> + >> + return count; >> +} >> +static DEVICE_ATTR_WO(start); >> + >> +static void mhi_loopback_dl_callback(struct mhi_device *mhi_dev, >> + struct mhi_result *mhi_res) >> +{ >> + struct mhi_loopback *loopback = dev_get_drvdata(&mhi_dev->dev); >> + >> + if (mhi_res->transaction_status && mhi_res->transaction_status != -ENOTCONN) >> + dev_err(&mhi_dev->dev, "DL callback error: status %d\n", >> + mhi_res->transaction_status); >> + >> + if (atomic_dec_and_test(&loopback->tre_pending)) >> + complete(&loopback->comp); >> +} >> + >> +static void mhi_loopback_ul_callback(struct mhi_device *mhi_dev, >> + struct mhi_result *mhi_res) >> +{ >> + if (mhi_res->transaction_status && mhi_res->transaction_status != -ENOTCONN) >> + dev_err(&mhi_dev->dev, "UL callback error: status %d\n", >> + mhi_res->transaction_status); >> +} >> + >> +static struct attribute *mhi_loopback_attrs[] = { >> + &dev_attr_tre_size.attr, >> + &dev_attr_max_tre_size.attr, >> + &dev_attr_num_tre.attr, >> + &dev_attr_start.attr, >> + NULL >> +}; >> + >> +static const struct attribute_group mhi_loopback_group = { >> + .attrs = mhi_loopback_attrs, >> +}; >> + >> +static int mhi_loopback_probe(struct mhi_device *mhi_dev, >> + const struct mhi_device_id *id) >> +{ >> + struct mhi_loopback *loopback; >> + int ret; >> + >> + loopback = devm_kzalloc(&mhi_dev->dev, sizeof(*loopback), GFP_KERNEL); >> + if (!loopback) >> + return -ENOMEM; >> + >> + loopback->mdev = mhi_dev; >> + loopback->tre_size = MHI_LOOPBACK_DEFAULT_TRE_SIZE; >> + loopback->num_tre = MHI_LOOPBACK_DEFAULT_NUM_TRE; >> + >> + mutex_init(&loopback->lb_mutex); >> + init_completion(&loopback->comp); >> + >> + dev_set_drvdata(&mhi_dev->dev, loopback); >> + >> + ret = mhi_prepare_for_transfer(mhi_dev); >> + if (ret) >> + return dev_err_probe(&mhi_dev->dev, ret, "Failed to prepare for transfers\n"); >> + >> + ret = sysfs_create_group(&mhi_dev->dev.kobj, &mhi_loopback_group); >> + if (ret) { >> + dev_err(&mhi_dev->dev, "Failed to create sysfs attributes: %d\n", ret); >> + mhi_unprepare_from_transfer(mhi_dev); >> + return ret; >> + } > You can use mhi_driver->driver.dev_groups to let the driver core create sysfs > groups for you. > > - Mani >