[PATCH] spi: spi-qpic-snand: skip BBM copy on regular raw reads

From: Gabor Juhos

Date: Mon Oct 05 2026 - 13:43:47 EST


Trying to read the raw flash contents with nanddump, the second byte
of the OOB area contains 0xff instead of the real data in the flash.
This happens because the qcom_spi_read_last_cw() function unconditionally
copies the bad block marker into the second byte of the output buffer.

Add a new flag to the controller's private data structure, and set it
when only the first two bytes of the OOB area being read in raw mode.
Also change the bad block copying code to run only when the flag is set.

This ensures that the SPI NAND framework still can read the BBM bytes,
but on regular raw read, the output does not contain the duplicated
marker byte.

Fixes: 7304d1909080 ("spi: spi-qpic: add driver for QCOM SPI NAND flash Interface")
Signed-off-by: Gabor Juhos <j4g8y7@xxxxxxxxx>
---
drivers/spi/spi-qpic-snand.c | 14 +++++++++++++-
1 file changed, 13 insertions(+), 1 deletion(-)

diff --git a/drivers/spi/spi-qpic-snand.c b/drivers/spi/spi-qpic-snand.c
index 001e4bd8bb4b..c90c2001ee8d 100644
--- a/drivers/spi/spi-qpic-snand.c
+++ b/drivers/spi/spi-qpic-snand.c
@@ -115,6 +115,7 @@ struct qpic_spi_nand {
__le32 addr2;
__le32 cmd;
u32 num_cw;
+ bool bbm_read;
bool oob_rw;
bool page_rw;
bool raw_rw;
@@ -457,6 +458,16 @@ static int qcom_spi_ecc_prepare_io_req_pipelined(struct nand_device *nand,
if (req->mode == MTD_OPS_RAW)
snandc->qspi->raw_rw = true;

+ /*
+ * Try to detect when the SPI NAND framework reads the first
+ * two bytes of the OOB area searching for bad block marker
+ * bytes.
+ */
+ snandc->qspi->bbm_read = req->mode == MTD_OPS_RAW &&
+ req->type == NAND_PAGE_READ &&
+ req->dataoffs == 0 && req->datalen == 0 &&
+ req->ooboffs == 0 && req->ooblen == 2;
+
return 0;
}

@@ -666,7 +677,8 @@ static int qcom_spi_read_last_cw(struct qcom_nand_controller *snandc,
* This can be removed once single-byte bad block marker support
* gets implemented in the SPINAND code.
*/
- snandc->data_buffer[bbpos + 1] = snandc->data_buffer[bbpos];
+ if (snandc->qspi->bbm_read)
+ snandc->data_buffer[bbpos + 1] = snandc->data_buffer[bbpos];

memcpy(op->data.buf.in, snandc->data_buffer + bbpos, op->data.nbytes);


---
base-commit: 65766f75dce38103e5cbfa40eefffdc285645084
change-id: 20261005-qpic-snand-skip-bbm-copy-f2d5c0219e7e

Best regards,
--
Gabor Juhos <j4g8y7@xxxxxxxxx>