[PATCH v17 4/6] spi: pxa2xx: overhaul teardown and suspend sequence to synchronize IRQ before clock gating

From: Shih-Yuan Lee

Date: Wed Sep 30 2026 - 12:17:40 EST


When removing the driver or suspending the device, the clock must not
be disabled while shared interrupts are still active. Gating the clock
before waiting for in-flight interrupt handlers to complete results
in race conditions where the handler performs unclocked MMIO accesses,
causing PCIe Completion Timeouts.

Overhaul the remove, suspend, and runtime_suspend paths to use a strict
synchronized teardown order:
1. In remove, call free_irq() (which internally synchronizes any in-flight
handlers) before disabling the clock via pxa2xx_spi_clk_disable().
2. In runtime_suspend, under clk_lock and only when the clock is enabled,
disable the SSP peripheral via pxa_ssp_disable(), clear 'clk_enabled'
via WRITE_ONCE() so that new interrupts immediately bail out with
IRQ_NONE, drain in-flight handlers via synchronize_irq() while the
clock is still running, and finally gate the clock with
clk_disable_unprepare().
3. In system suspend, suspend the controller queue and use
pm_runtime_force_suspend() to invoke runtime_suspend, ensuring
in-flight interrupts are drained before the clock is gated. If
pm_runtime_force_suspend() fails, resume the controller queue so
the controller remains operational since the system will stay awake.
4. In system resume, restore the device state using
pm_runtime_force_resume() before restarting the controller queue.
If pm_runtime_force_resume() fails, return the error immediately
without calling spi_controller_resume(), keeping the queue stopped
to prevent transferring messages against unclocked or unpowered
hardware. If the device was already runtime-suspended prior to
system sleep, pm_runtime_force_resume() leaves the clock gated until
the next transfer resumes it, optimizing idle power.

Throughout suspended states, 'clk_enabled' being false serves as the
primary invariant ensuring that any subsequent interrupt handler
invocation safely returns IRQ_NONE without accessing hardware registers.

Assisted-by: Antigravity:gemini-3.8-flash spin sparse
Signed-off-by: Shih-Yuan Lee <fourdollars@xxxxxxxxxx>
---
drivers/spi/spi-pxa2xx.c | 39 +++++++++++++++++++++++----------------
1 file changed, 23 insertions(+), 16 deletions(-)

diff --git a/drivers/spi/spi-pxa2xx.c b/drivers/spi/spi-pxa2xx.c
index b091434977af..2a3fa9ca7213 100644
--- a/drivers/spi/spi-pxa2xx.c
+++ b/drivers/spi/spi-pxa2xx.c
@@ -1520,31 +1520,33 @@ void pxa2xx_spi_remove(struct device *dev)

/* Disable the SSP at the peripheral and SOC level */
pxa_ssp_disable(ssp);
+
+ /* Release IRQ before gating the SOC clock */
+ free_irq(ssp->irq, drv_data);
+
+ /* Safe to disable the SSP clock now */
pxa2xx_spi_clk_disable(drv_data);

/* Release DMA */
if (drv_data->controller_info->enable_dma)
pxa2xx_spi_dma_release(drv_data);
-
- /* Release IRQ */
- free_irq(ssp->irq, drv_data);
}
EXPORT_SYMBOL_NS_GPL(pxa2xx_spi_remove, "SPI_PXA2xx");

static int pxa2xx_spi_suspend(struct device *dev)
{
struct driver_data *drv_data = dev_get_drvdata(dev);
- struct ssp_device *ssp = drv_data->ssp;
int ret;

ret = spi_controller_suspend(drv_data->controller);
if (ret)
return ret;

- pxa_ssp_disable(ssp);
-
- if (!pm_runtime_suspended(dev))
- pxa2xx_spi_clk_disable(drv_data);
+ ret = pm_runtime_force_suspend(dev);
+ if (ret) {
+ spi_controller_resume(drv_data->controller);
+ return ret;
+ }

return 0;
}
@@ -1554,14 +1556,10 @@ static int pxa2xx_spi_resume(struct device *dev)
struct driver_data *drv_data = dev_get_drvdata(dev);
int ret;

- /* Enable the SSP clock */
- if (!pm_runtime_suspended(dev)) {
- ret = pxa2xx_spi_clk_enable(drv_data);
- if (ret)
- return ret;
- }
+ ret = pm_runtime_force_resume(dev);
+ if (ret)
+ return ret;

- /* Start the queue running */
return spi_controller_resume(drv_data->controller);
}

@@ -1569,7 +1567,16 @@ static int pxa2xx_spi_runtime_suspend(struct device *dev)
{
struct driver_data *drv_data = dev_get_drvdata(dev);

- pxa2xx_spi_clk_disable(drv_data);
+ mutex_lock(&drv_data->clk_lock);
+ if (drv_data->clk_enabled) {
+ pxa_ssp_disable(drv_data->ssp);
+ WRITE_ONCE(drv_data->clk_enabled, false);
+ mutex_unlock(&drv_data->clk_lock);
+ synchronize_irq(drv_data->ssp->irq);
+ clk_disable_unprepare(drv_data->ssp->clk);
+ } else {
+ mutex_unlock(&drv_data->clk_lock);
+ }
return 0;
}

--
2.39.5