[PATCH 2/5] mtd: spi-nor: Add support for panic writes

From: Paul Cercueil

Date: Mon Oct 05 2026 - 04:12:55 EST


From: Tanmay Jagdale <tanmay@xxxxxxxxxxx>

If the SPI controller supports it, provide the functionality of doing a
panic write.

Update the spi-nor core code and controllers to make sure they won't try
to grab locked mutexes or sleep when doing a panic write, as preemption
and IRQs are disabled.

The information is carried down to the SPI controller driver through the
spi_mem_op structure. If the corresponding flag is set there, and the
SPI driver does support panic writes, it then has to respect the same
rules.

Signed-off-by: Tanmay Jagdale <tanmay@xxxxxxxxxxx>
Co-developed-by: Paul Cercueil <paul.cercueil@xxxxxxxxxxx>
Signed-off-by: Paul Cercueil <paul.cercueil@xxxxxxxxxxx>
---
drivers/mtd/spi-nor/core.c | 67 ++++++++++++++++++++++++++++++++++++--
1 file changed, 64 insertions(+), 3 deletions(-)

diff --git a/drivers/mtd/spi-nor/core.c b/drivers/mtd/spi-nor/core.c
index 8bc117b46e02..2cdeebf3e25b 100644
--- a/drivers/mtd/spi-nor/core.c
+++ b/drivers/mtd/spi-nor/core.c
@@ -96,6 +96,9 @@ void spi_nor_spimem_setup_op(const struct spi_nor *nor,
if (op->data.nbytes)
op->data.buswidth = spi_nor_get_protocol_data_nbits(proto);

+ if (nor->mtd.oops_panic_write)
+ op->panic_write = true;
+
if (spi_nor_protocol_is_dtr(proto)) {
/*
* SPIMEM supports mixed DTR modes, but right now we can only
@@ -281,7 +284,7 @@ static ssize_t spi_nor_spimem_write_data(struct spi_nor *nor, loff_t to,
if (spi_nor_spimem_bounce(nor, &op))
memcpy(nor->bouncebuf, buf, op.data.nbytes);

- if (nor->dirmap.wdesc) {
+ if (nor->dirmap.wdesc && !nor->mtd.oops_panic_write) {
nbytes = spi_mem_dirmap_write(nor->dirmap.wdesc, op.addr.val,
op.data.nbytes, op.data.buf.out);
} else {
@@ -664,6 +667,9 @@ static void spi_nor_rww_end_rdst(struct spi_nor *nor)

static int spi_nor_lock_rdst(struct spi_nor *nor)
{
+ if (nor->mtd.oops_panic_write)
+ return 0;
+
if (spi_nor_use_parallel_locking(nor))
return spi_nor_rww_start_rdst(nor);

@@ -672,6 +678,9 @@ static int spi_nor_lock_rdst(struct spi_nor *nor)

static void spi_nor_unlock_rdst(struct spi_nor *nor)
{
+ if (nor->mtd.oops_panic_write)
+ return;
+
if (spi_nor_use_parallel_locking(nor)) {
spi_nor_rww_end_rdst(nor);
wake_up(&nor->rww.wait);
@@ -729,7 +738,10 @@ static int spi_nor_wait_till_ready_with_timeout(struct spi_nor *nor,
if (ret)
return 0;

- cond_resched();
+ if (nor->mtd.oops_panic_write)
+ cpu_relax();
+ else
+ cond_resched();
}

dev_dbg(nor->dev, "flash operation timed out\n");
@@ -1291,6 +1303,9 @@ static void spi_nor_rww_end_io(struct spi_nor *nor)

static int spi_nor_lock_device(struct spi_nor *nor)
{
+ if (nor->mtd.oops_panic_write)
+ return 0;
+
if (!spi_nor_use_parallel_locking(nor))
return 0;

@@ -1299,6 +1314,9 @@ static int spi_nor_lock_device(struct spi_nor *nor)

static void spi_nor_unlock_device(struct spi_nor *nor)
{
+ if (nor->mtd.oops_panic_write)
+ return;
+
if (spi_nor_use_parallel_locking(nor)) {
spi_nor_rww_end_io(nor);
wake_up(&nor->rww.wait);
@@ -1336,6 +1354,9 @@ int spi_nor_prep_and_lock(struct spi_nor *nor)
{
int ret;

+ if (nor->mtd.oops_panic_write)
+ return 0;
+
ret = spi_nor_prep(nor);
if (ret)
return ret;
@@ -1351,6 +1372,9 @@ int spi_nor_prep_and_lock(struct spi_nor *nor)

void spi_nor_unlock_and_unprep(struct spi_nor *nor)
{
+ if (nor->mtd.oops_panic_write)
+ return;
+
if (!spi_nor_use_parallel_locking(nor)) {
mutex_unlock(&nor->lock);
} else {
@@ -1407,6 +1431,9 @@ static int spi_nor_prep_and_lock_pe(struct spi_nor *nor, loff_t start, size_t le
{
int ret;

+ if (nor->mtd.oops_panic_write)
+ return 0;
+
ret = spi_nor_prep(nor);
if (ret)
return ret;
@@ -1422,6 +1449,9 @@ static int spi_nor_prep_and_lock_pe(struct spi_nor *nor, loff_t start, size_t le

static void spi_nor_unlock_and_unprep_pe(struct spi_nor *nor, loff_t start, size_t len)
{
+ if (nor->mtd.oops_panic_write)
+ return;
+
if (!spi_nor_use_parallel_locking(nor)) {
mutex_unlock(&nor->lock);
} else {
@@ -1480,6 +1510,9 @@ static int spi_nor_prep_and_lock_rd(struct spi_nor *nor, loff_t start, size_t le
{
int ret;

+ if (nor->mtd.oops_panic_write)
+ return 0;
+
ret = spi_nor_prep(nor);
if (ret)
return ret;
@@ -1495,6 +1528,9 @@ static int spi_nor_prep_and_lock_rd(struct spi_nor *nor, loff_t start, size_t le

static void spi_nor_unlock_and_unprep_rd(struct spi_nor *nor, loff_t start, size_t len)
{
+ if (nor->mtd.oops_panic_write)
+ return;
+
if (!spi_nor_use_parallel_locking(nor)) {
mutex_unlock(&nor->lock);
} else {
@@ -3393,6 +3429,26 @@ static void spi_nor_soft_reset(struct spi_nor *nor)
usleep_range(SPI_NOR_SRST_SLEEP_MIN, SPI_NOR_SRST_SLEEP_MAX);
}

+static int spi_nor_panic_write(struct mtd_info *mtd, loff_t to, size_t len,
+ size_t *retlen, const u_char *buf)
+{
+ struct spi_nor *nor = mtd_to_spi_nor(mtd);
+
+ /*
+ * At this point preemption and local interrupts are disabled, so we
+ * can't get the lock if it's taken.
+ */
+ if (mutex_is_locked(&nor->lock))
+ return -EPERM;
+
+ if (spi_nor_use_parallel_locking(nor) &&
+ (nor->rww.ongoing_io || nor->rww.ongoing_rd)) {
+ return -EPERM;
+ }
+
+ return spi_nor_write(mtd, to, len, retlen, buf);
+}
+
/* mtd suspend handler */
static int spi_nor_suspend(struct mtd_info *mtd)
{
@@ -3596,8 +3652,13 @@ static int spi_nor_set_mtd_info(struct spi_nor *nor)
mtd->size = nor->params->size;
mtd->_read = spi_nor_read;
/* Might be already set by some SST flashes. */
- if (!mtd->_write)
+ if (!mtd->_write) {
mtd->_write = spi_nor_write;
+ if (nor->spimem &&
+ spi_mem_controller_is_capable(nor->spimem->spi->controller, panic_write)) {
+ mtd->_panic_write = spi_nor_panic_write;
+ }
+ }
mtd->_suspend = spi_nor_suspend;
mtd->_resume = spi_nor_resume;
mtd->_get_device = spi_nor_get_device;
--
2.47.3