Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [Medium] drm/dp: 0-length final I2C message leaves MOT bit set hanging the bus
--

commit 1eb9f4115ff3f3b4a53072c0af9a5f8cf025a748
Author: Finn Zeruhn <[email protected]>

drm/dp: keep MOT set between messages when no_zero_sized is set

This commit modifies drm_dp_i2c_xfer() to clear the Middle-Of-Transaction
(MOT) bit only on the last packet of the last message when aux->no_zero_sized
is set. This addresses an issue where EDID blocks 2 and up reads break
because the stop after the first message resets the segment pointer.

Link: https://lore.kernel.org/all/[email protected]/

> diff --git a/drivers/gpu/drm/display/drm_dp_helper.c 
> b/drivers/gpu/drm/display/drm_dp_helper.c
> index 488fd123a01ad..7676285c19f87 100644
> --- a/drivers/gpu/drm/display/drm_dp_helper.c
> +++ b/drivers/gpu/drm/display/drm_dp_helper.c
> @@ -2192,7 +2192,8 @@ static int drm_dp_i2c_xfer(struct i2c_adapter *adapter, 
> struct i2c_msg *msgs,
>                       msg.buffer = msgs[i].buf + j;
>                       msg.size = min(transfer_size, msgs[i].len - j);
>  
> -                     if (j + msg.size == msgs[i].len && aux->no_zero_sized)
> +                     if (aux->no_zero_sized && i == num - 1 &&
> +                         j + msg.size == msgs[i].len)
>                               msg.request &= ~DP_AUX_I2C_MOT;

[Severity: Medium]
Will this leave the MOT bit set and hang the bus if the final message has a
length of 0?

If a caller issues a multi-message transfer where the final message
(msgs[num-1]) has a length of 0, the inner loop:

    for (j = 0; j < msgs[i].len; j += msg.size) {

is bypassed entirely for that message.

Because the clearing of the DP_AUX_I2C_MOT bit is now restricted to
i == num - 1 inside this loop, the MOT flag would never be cleared for
the preceding messages.

Furthermore, because aux->no_zero_sized prevents the driver from sending
the fallback bare address packet at the end of the function, the hardware
is never signaled to terminate the transaction.

>                       err = drm_dp_i2c_drain_msg(aux, &msg);
>

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=1

Reply via email to