Skip to content

Commit 07fd938

Browse files
vjardinAndi Shyti
authored andcommitted
i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ)
SMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the interrupt-driven block-read state machine rejects it as -EPROTO. Worse, it returns without a NACK+STOP: the next receive cycle has already started, so the target keeps holding SDA and the bus stays stuck until a power cycle of this i2c controller. Accept count=0: NACK the in-flight dummy byte (TXAK) and set msg->len to 2 so i2c_imx_isr_read_continue() emits STOP via its normal last-byte path. The dummy byte is discarded; block-read callers only consume buf[0..count-1]. Reading I2DR has likewise already armed the next byte on the count > I2C_SMBUS_BLOCK_MAX error path, so NACK it (TXAK) before aborting with -EPROTO; otherwise the failing transfer's STOP cannot complete and the bus stays held. The atomic path regressed earlier (v3.16) and is fixed separately; this patch covers only the v6.13 state-machine rework. Fixes: 5f5c2d4 ("i2c: imx: prevent rescheduling in non dma mode") Signed-off-by: Vincent Jardin <vjardin@free.fr> Cc: <stable@vger.kernel.org> # v6.13+ Acked-by: Oleksij Rempel <o.rempel@pengutronix.de> Acked-by: Carlos Song <carlos.song@nxp.com> Reviewed-by: Stefan Eichenberger <eichest@gmail.com> Signed-off-by: Andi Shyti <andi.shyti@kernel.org> Link: https://lore.kernel.org/r/20260713-for-upstream-i2c-lx2160-fix-v1-v3-2-073ac9e103a5@free.fr
1 parent cb2fc37 commit 07fd938

1 file changed

Lines changed: 17 additions & 0 deletions

File tree

drivers/i2c/busses/i2c-imx.c

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1061,11 +1061,28 @@ static inline enum imx_i2c_state i2c_imx_isr_read_continue(struct imx_i2c_struct
10611061
static inline void i2c_imx_isr_read_block_data_len(struct imx_i2c_struct *i2c_imx)
10621062
{
10631063
u8 len = imx_i2c_read_reg(i2c_imx, IMX_I2C_I2DR);
1064+
unsigned int temp;
10641065

10651066
if (len == 0 || len > I2C_SMBUS_BLOCK_MAX) {
1067+
/*
1068+
* SMBus 3.1 6.5.7: support count byte of 0.
1069+
* I2C_SMBUS_BLOCK_MAX case should not hold the SDA either.
1070+
* So NACK it (TXAK) to not hold the bus.
1071+
*/
1072+
temp = imx_i2c_read_reg(i2c_imx, IMX_I2C_I2CR);
1073+
temp |= I2CR_TXAK;
1074+
imx_i2c_write_reg(temp, i2c_imx, IMX_I2C_I2CR);
1075+
1076+
if (len == 0) {
1077+
i2c_imx->msg->buf[i2c_imx->msg_buf_idx++] = 0;
1078+
i2c_imx->msg->len = 2;
1079+
return;
1080+
}
1081+
10661082
i2c_imx->isr_result = -EPROTO;
10671083
i2c_imx->state = IMX_I2C_STATE_FAILED;
10681084
wake_up(&i2c_imx->queue);
1085+
return;
10691086
}
10701087
i2c_imx->msg->len += len;
10711088
i2c_imx->msg->buf[i2c_imx->msg_buf_idx++] = len;

0 commit comments

Comments
 (0)