[PATCH v6 9/9] serial: max310x: don't transmit while an RS485 reconfigure is pending
From: Tapio Reijonen
Date: Sun Oct 04 2026 - 08:21:31 EST
TIOCSRS485 applies its register changes asynchronously: rs485_config()
stores the new configuration and schedules rs_work, which programs
HDPIXDELAY, MODE1.TRNSCVCTRL and the RTS path. A write() issued right
after the ioctl therefore transmits against the old, half-switched
state. On a single core the ordering is even deterministic: start_tx()
picks the stale path first, then rs_work reprograms the chip, then
tx_work pumps the data - with the transceiver already released. A
TIOCSRS485 switching from the hardware to the software RTS path
followed immediately by a write puts the whole transfer on the wire
with the transceiver disabled: nothing reaches the bus and no error is
reported anywhere. The inverse direction is as old as the asynchronous
reconfigure itself: enabling RS485 and writing immediately shifts the
first bytes out before rs_work has enabled the chip's auto-RTS.
Defer instead: rs485_config() marks the reconfigure pending under
port->lock, start_tx() leaves the data in the kfifo while the mark is
set, and rs_work restarts the transmission itself once the new
configuration is fully applied. The rs485-disable path's direct
tx_work kick is replaced by the same mechanism, which also orders that
flush after the reconfigure instead of before it.
The restart kick also checks port->x_char: uart_send_xchar() reaches
start_tx() too, and a lone x_char deferred by the pending gate leaves
the kfifo empty, so the kick would otherwise skip it and nothing else
would ever send it - an idle chip FIFO raises no TXEMPTY interrupt.
And start_tx() re-checks the pending mark after the
hrtimer_try_to_cancel(-1) path retakes the dropped lock, mirroring the
tx_teardown re-check there: a TIOCSRS485 posted inside that window
would otherwise let the transmission proceed on the stale path.
Fixes: 5bdb48b501e8 ("serial: max310x: Fix RS485 handling")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Tapio Reijonen <tapio.reijonen@xxxxxxxxxxx>
---
drivers/tty/serial/max310x.c | 35 ++++++++++++++++++++++++++---------
1 file changed, 26 insertions(+), 9 deletions(-)
diff --git a/drivers/tty/serial/max310x.c b/drivers/tty/serial/max310x.c
index eb1d2e3bc870e9097d649eadb1e6e8703033fc94..f8247cf0358ba74c7d1979e64be2990feb5e2627 100644
--- a/drivers/tty/serial/max310x.c
+++ b/drivers/tty/serial/max310x.c
@@ -319,6 +319,7 @@ struct max310x_one {
bool sw_rts_during_tx;
bool cancel_tx_delay_tmr;
bool tx_teardown; /* envelope being torn down */
+ bool rs485_pending; /* rs_work not yet applied */
bool tx_break; /* break_ctl() owns the transceiver */
enum max310x_tx_state tx_state;
@@ -979,6 +980,16 @@ static void max310x_start_tx(struct uart_port *port)
if (one->tx_teardown)
return;
+ /*
+ * An RS485 reconfigure is scheduled but not applied yet: transmitting
+ * now would use the old path against half-programmed registers - a
+ * TIOCSRS485 switching paths followed immediately by a write puts the
+ * data on the wire with the transceiver released. Leave the data in
+ * the kfifo; rs_work restarts TX once the configuration is applied.
+ */
+ if (one->rs485_pending)
+ return;
+
if (READ_ONCE(one->sw_rts_during_tx)) {
/*
* The before- and after-send phases share one delay timer. If an
@@ -997,9 +1008,10 @@ static void max310x_start_tx(struct uart_port *port)
uart_port_lock(port);
/*
* The lock was dropped: a teardown may have run to
- * completion meanwhile. Re-check before starting.
+ * completion or a reconfigure may have been posted
+ * meanwhile. Re-check before starting.
*/
- if (one->tx_teardown)
+ if (one->tx_teardown || one->rs485_pending)
return;
}
@@ -1453,6 +1465,17 @@ static void max310x_rs_proc(struct work_struct *ws)
max310x_port_update(&one->port, MAX310X_MODE2_REG,
MAX310X_MODE2_ECHOSUPR_BIT, mode2);
+
+ /*
+ * The configuration is applied: release any TX that start_tx()
+ * deferred while the reconfigure was pending, now on the right path.
+ */
+ scoped_guard(spinlock_irqsave, &one->port.lock) {
+ one->rs485_pending = false;
+ if (one->port.x_char ||
+ !kfifo_is_empty(&one->port.state->port.xmit_fifo))
+ max310x_start_tx(&one->port);
+ }
}
/* called with port.lock taken and irqs off */
@@ -1478,17 +1501,11 @@ static int max310x_rs485_config(struct uart_port *port, struct ktermios *termios
}
WRITE_ONCE(one->tx_state, MAX310X_TX_OFF);
one->tx_teardown = false;
- /*
- * The port stays alive, and a write that raced the teardown
- * may have left data queued with no envelope left to pump it.
- * Kick tx_work; RS485 is disabled, so the plain path is right.
- */
- if (!kfifo_is_empty(&port->state->port.xmit_fifo))
- schedule_work(&one->tx_work);
}
port->rs485 = *rs485;
+ one->rs485_pending = true;
schedule_work(&one->rs_work);
return 0;
--
2.47.3