Re: [PATCH net-next v8 2/2] net: wwan: mhi_wwan_ctrl: drive DTR/RTS via the IP_CTRL channel

From: Loic Poulain

Date: Thu Oct 08 2026 - 11:31:25 EST


On Wed, Oct 7, 2026 at 8:23 PM Peter Hunt <peter.hunt@xxxxxxxxxxxx> wrote:
>
> Qualcomm/Sierra SDX55/SDX65 modems withhold unsolicited AT result codes
> (URCs such as +CREG, and the +DMI OMA-DM/LwM2M session indications) on
> an AT port until the host asserts DTR. mhi_wwan_ctrl exposed the AT
> (DUN) ports but had no way to signal DTR, so URCs never reached
> userspace.
>
> Carry the host serial-control lines to the modem over the dedicated
> IP_CTRL MHI channel, which this module now also binds. IP_CTRL uses a
> separate mhi_driver with its own callbacks so the AT/QMI/MBIM data path
> is untouched; the control-channel device for each MHI controller is
> tracked in a small registry so an AT port drives the IP_CTRL channel of
> its own modem (multiple modems are supported).
>
> The IP_CTRL channel has to be declared in the controller's channel config
> for this driver to bind. For the Sierra EM919x/EM929x this is done by
> commit 83c29a55b89e ("bus: mhi: host: pci_generic: Add IP_CTRL channel
> for Sierra EM919x/EM929x") in the MHI tree. On controllers that do not
> declare IP_CTRL the driver does not bind and ->dtr_rts is a no-op.
>
> The wwan core (patch 1) raises DTR/RTS on first open and drops them on
> last close (if HUPCL is set) for any AT port whose driver implements
> ->dtr_rts, so no open/close handling is needed here. The new ->dtr_rts
> op lets userspace assert or de-assert them via
> TIOCMSET/TIOCMBIC/TIOCMBIS. Received device->host serial state messages
> are silently discarded; a single recycled sink buffer keeps the IP_CTRL
> DL ring live so the modem's transmit path does not stall.
>
> ->dtr_rts is void, following the tty_port_operations model it is modelled
> on. Delivery is best-effort: at_data.mdmbits always reflects the committed
> userspace intent for TIOCMGET regardless of whether the IP_CTRL message was
> queued, and the next ioctl or open/close cycle will resynchronise the modem
> state. If requeueing the DL sink buffer fails with a transient -ENOMEM it
> is retried from a work item, so the DL ring does not stay empty.
>
> Signed-off-by: Peter Hunt <peter.hunt@xxxxxxxxxxxx>
> ---
> v8: No changes
> v7: Retry a failed DL sink buffer requeue from a delayed work item on
> -ENOMEM, and log other failures. Note the dependency on the IP_CTRL
> channel entry in pci_generic, now in the MHI tree. Both from the
> Sashiko review of v6
> v6: Rebase onto net-next. Allocate the IP_CTRL DL sink buffer separately
> instead of embedding it in struct mhi_wwan_dtr, so DMA cache
> maintenance on non-coherent platforms cannot touch neighbouring fields.
> Do not requeue the sink buffer from the DL callback when the transfer
> completes with an error (e.g. -ENOTCONN during channel teardown)
> v5: Implement ->dtr_rts(port, mdmbits) and drive DTR and RTS
> independently. Pre-queue an RX sink buffer in probe and requeue it in
> the DL callback so the IP_CTRL DL ring does not run empty and stall
> the modem's transmit path
> v4: Add dev_dbg when IP_CTRL channel is not enumerated for this controller
> and when mhi_queue_buf fails, to aid diagnosis of the "URCs missing"
> case on controllers that do not declare IP_CTRL
> v3: Remove is_at_port, implement ->dtr_rts instead of ->tiocmset,
> open/close DTR raise/drop handled by wwan core (Loic Poulain)
> ---
> drivers/net/wwan/mhi_wwan_ctrl.c | 239 ++++++++++++++++++++++++++++++-
> 1 file changed, 238 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/net/wwan/mhi_wwan_ctrl.c b/drivers/net/wwan/mhi_wwan_ctrl.c
> index a31d8540fbb8..feb9c03b6392 100644
> --- a/drivers/net/wwan/mhi_wwan_ctrl.c
> +++ b/drivers/net/wwan/mhi_wwan_ctrl.c
> @@ -1,8 +1,13 @@
> // SPDX-License-Identifier: GPL-2.0-only
> /* Copyright (c) 2021, Linaro Ltd <loic.poulain@xxxxxxxxxx> */
> #include <linux/kernel.h>
> +#include <linux/list.h>
> #include <linux/mhi.h>
> #include <linux/module.h>
> +#include <linux/mutex.h>
> +#include <linux/slab.h>
> +#include <linux/termios.h>
> +#include <linux/workqueue.h>
> #include <linux/wwan.h>
>
> /* MHI wwan flags */
> @@ -14,6 +19,32 @@ enum mhi_wwan_flags {
>
> #define MHI_WWAN_MAX_MTU 0x8000
>
> +/* IP_CTRL channel message that sets the modem's DTR/RTS control lines */
> +struct mhi_dtr_ctrl_msg {
> + __le32 preamble;
> + __le32 msg_id;
> + __le32 dest_id;
> + __le32 size;
> + __le32 msg;
> +} __packed;
> +
> +#define MHI_DTR_CTRL_MAGIC 0x4C525443 /* 'CTRL' */
> +#define MHI_DTR_MSG_DTR BIT(0)
> +#define MHI_DTR_MSG_RTS BIT(1)
> +#define MHI_DTR_HOST_STATE 0x10
> +
> +/* Per-controller IP_CTRL channel, used to signal DTR/RTS to that modem */
> +struct mhi_wwan_dtr {
> + struct mhi_controller *cntrl;
> + struct mhi_device *mhi_dev;
> + struct list_head node;
> + struct mhi_dtr_ctrl_msg *rx_buf; /* DL sink, separate allocation for DMA safety */
> + struct delayed_work rx_refill; /* retries a failed sink buffer requeue */
> +};
> +
> +static LIST_HEAD(mhi_wwan_dtr_list);
> +static DEFINE_MUTEX(mhi_wwan_dtr_lock);
> +
> struct mhi_wwan_dev {
> /* Lower level is a mhi dev, upper level is a wwan port */
> struct mhi_device *mhi_dev;
> @@ -103,6 +134,61 @@ static void mhi_wwan_ctrl_refill_work(struct work_struct *work)
> }
> }
>
> +/* Signal the modem's DTR/RTS lines over its own controller's IP_CTRL channel */
> +static int mhi_wwan_ctrl_send_dtr(struct mhi_wwan_dev *mhiwwan, unsigned int mdmbits)
> +{
> + struct mhi_controller *cntrl = mhiwwan->mhi_dev->mhi_cntrl;
> + struct mhi_device *ctrl_dev = NULL;
> + struct mhi_dtr_ctrl_msg *dtr_msg;
> + struct mhi_wwan_dtr *dtr;
> + u32 msg = 0;
> + int ret;
> +
> + guard(mutex)(&mhi_wwan_dtr_lock);
> +
> + list_for_each_entry(dtr, &mhi_wwan_dtr_list, node) {
> + if (dtr->cntrl == cntrl) {
> + ctrl_dev = dtr->mhi_dev;
> + break;
> + }
> + }
> + if (!ctrl_dev) {
> + dev_dbg(&mhiwwan->mhi_dev->dev,
> + "IP_CTRL not enumerated; DTR/RTS not signalled to modem\n");
> + return 0;
> + }
> +
> + dtr_msg = kzalloc_obj(*dtr_msg);
> + if (!dtr_msg)
> + return -ENOMEM;
> +
> + if (mdmbits & TIOCM_DTR)
> + msg |= MHI_DTR_MSG_DTR;
> + if (mdmbits & TIOCM_RTS)
> + msg |= MHI_DTR_MSG_RTS;
> +
> + dtr_msg->preamble = cpu_to_le32(MHI_DTR_CTRL_MAGIC);
> + dtr_msg->msg_id = cpu_to_le32(MHI_DTR_HOST_STATE);
> + dtr_msg->dest_id = cpu_to_le32(mhiwwan->mhi_dev->ul_chan_id);
> + dtr_msg->size = cpu_to_le32(sizeof(__le32));
> + dtr_msg->msg = cpu_to_le32(msg);
> +
> + ret = mhi_queue_buf(ctrl_dev, DMA_TO_DEVICE, dtr_msg, sizeof(*dtr_msg),
> + MHI_EOT);
> + if (ret) {
> + dev_dbg(&mhiwwan->mhi_dev->dev,
> + "failed to queue DTR/RTS signal: %d\n", ret);
> + kfree(dtr_msg);
> + }
> +
> + return ret;
> +}
> +
> +static void mhi_wwan_ctrl_dtr_rts(struct wwan_port *port, unsigned int mdmbits)
> +{
> + mhi_wwan_ctrl_send_dtr(wwan_port_get_drvdata(port), mdmbits);
> +}
> +
> static int mhi_wwan_ctrl_start(struct wwan_port *port)
> {
> struct mhi_wwan_dev *mhiwwan = wwan_port_get_drvdata(port);
> @@ -163,6 +249,7 @@ static const struct wwan_port_ops wwan_pops = {
> .start = mhi_wwan_ctrl_start,
> .stop = mhi_wwan_ctrl_stop,
> .tx = mhi_wwan_ctrl_tx,
> + .dtr_rts = mhi_wwan_ctrl_dtr_rts,
> };
>
> static void mhi_ul_xfer_cb(struct mhi_device *mhi_dev,
> @@ -255,6 +342,118 @@ static void mhi_wwan_ctrl_remove(struct mhi_device *mhi_dev)
> kfree(mhiwwan);
> }
>
> +/* IP_CTRL channel driver, bound separately so the data-port path is untouched */
> +static void mhi_wwan_dtr_ul_xfer_cb(struct mhi_device *mhi_dev,
> + struct mhi_result *mhi_result)
> +{
> + /* MHI core has done with the buffer, release it */
> + kfree(mhi_result->buf_addr);
> +}
> +
> +/* Requeue the single DL sink buffer so the IP_CTRL DL ring never runs empty.
> + * A transient mapping failure is retried from a work item, other errors mean
> + * the channel is going away and the next probe queues a fresh buffer.
> + */
> +static void mhi_wwan_dtr_queue_rx(struct mhi_wwan_dtr *dtr)
> +{
> + int ret;
> +
> + ret = mhi_queue_buf(dtr->mhi_dev, DMA_FROM_DEVICE, dtr->rx_buf,
> + sizeof(*dtr->rx_buf), MHI_EOT);
> + if (ret == -ENOMEM) {
> + dev_warn_ratelimited(&dtr->mhi_dev->dev,
> + "failed to requeue IP_CTRL RX buffer, retrying\n");
> + schedule_delayed_work(&dtr->rx_refill, msecs_to_jiffies(100));
> + } else if (ret) {
> + dev_dbg(&dtr->mhi_dev->dev,
> + "failed to requeue IP_CTRL RX buffer: %d\n", ret);
> + }
> +}
> +
> +static void mhi_wwan_dtr_refill_work(struct work_struct *work)
> +{
> + struct mhi_wwan_dtr *dtr = container_of(to_delayed_work(work),
> + struct mhi_wwan_dtr, rx_refill);
> +
> + mhi_wwan_dtr_queue_rx(dtr);
> +}
> +
> +static void mhi_wwan_dtr_dl_xfer_cb(struct mhi_device *mhi_dev,
> + struct mhi_result *mhi_result)
> +{
> + struct mhi_wwan_dtr *dtr = dev_get_drvdata(&mhi_dev->dev);
> +
> + /* Channel is being torn down (e.g. -ENOTCONN), do not requeue */
> + if (mhi_result->transaction_status &&
> + mhi_result->transaction_status != -EOVERFLOW)
> + return;
> +
> + /* Modem serial state not needed, requeue the sink buffer to keep DL ring live */
> + mhi_wwan_dtr_queue_rx(dtr);
> +}
> +
> +static int mhi_wwan_dtr_probe(struct mhi_device *mhi_dev,
> + const struct mhi_device_id *id)
> +{
> + struct mhi_wwan_dtr *dtr;
> + int ret;
> +
> + dtr = kzalloc_obj(*dtr);
> + if (!dtr)
> + return -ENOMEM;
> +
> + dtr->rx_buf = kmalloc_obj(*dtr->rx_buf);
> + if (!dtr->rx_buf) {
> + ret = -ENOMEM;
> + goto err_free_dtr;
> + }
> + INIT_DELAYED_WORK(&dtr->rx_refill, mhi_wwan_dtr_refill_work);
> +
> + ret = mhi_prepare_for_transfer(mhi_dev);
> + if (ret)
> + goto err_free_buf;
> +
> + dtr->cntrl = mhi_dev->mhi_cntrl;
> + dtr->mhi_dev = mhi_dev;
> + dev_set_drvdata(&mhi_dev->dev, dtr);
> +
> + ret = mhi_queue_buf(mhi_dev, DMA_FROM_DEVICE, dtr->rx_buf,
> + sizeof(*dtr->rx_buf), MHI_EOT);
> + if (ret)
> + goto err_unprepare;
> +
> + mutex_lock(&mhi_wwan_dtr_lock);
> + list_add(&dtr->node, &mhi_wwan_dtr_list);
> + mutex_unlock(&mhi_wwan_dtr_lock);
> +
> + return 0;
> +
> +err_unprepare:
> + mhi_unprepare_from_transfer(mhi_dev);
> +err_free_buf:
> + kfree(dtr->rx_buf);
> +err_free_dtr:
> + kfree(dtr);
> + return ret;
> +}
> +
> +static void mhi_wwan_dtr_remove(struct mhi_device *mhi_dev)
> +{
> + struct mhi_wwan_dtr *dtr = dev_get_drvdata(&mhi_dev->dev);
> +
> + mutex_lock(&mhi_wwan_dtr_lock);
> + list_del(&dtr->node);
> + mutex_unlock(&mhi_wwan_dtr_lock);
> +
> + mhi_unprepare_from_transfer(mhi_dev);
> + /* No DL callbacks after unprepare, and a pending retry now fails on
> + * the disabled channel without rescheduling
> + */
> + cancel_delayed_work_sync(&dtr->rx_refill);

This function ensures that the work is either cancelled or has
completed, but it does not prevent it from being requeued
concurrently. That can happen when rx_refill is rescheduled from
mhi_wwan_dtr_queue_rx(). Using disable_delayed_work_sync() here would
be preferable.


> + kfree(dtr->rx_buf);
> + kfree(dtr);
> +}
> +
> static const struct mhi_device_id mhi_wwan_ctrl_match_table[] = {
> { .chan = "DUN", .driver_data = WWAN_PORT_AT },
> { .chan = "DUN2", .driver_data = WWAN_PORT_AT },
> @@ -278,7 +477,45 @@ static struct mhi_driver mhi_wwan_ctrl_driver = {
> },
> };
>
> -module_mhi_driver(mhi_wwan_ctrl_driver);
> +static const struct mhi_device_id mhi_wwan_dtr_match_table[] = {
> + { .chan = "IP_CTRL" },
> + {},
> +};
> +MODULE_DEVICE_TABLE(mhi, mhi_wwan_dtr_match_table);
> +
> +static struct mhi_driver mhi_wwan_dtr_driver = {
> + .id_table = mhi_wwan_dtr_match_table,
> + .remove = mhi_wwan_dtr_remove,
> + .probe = mhi_wwan_dtr_probe,
> + .ul_xfer_cb = mhi_wwan_dtr_ul_xfer_cb,
> + .dl_xfer_cb = mhi_wwan_dtr_dl_xfer_cb,
> + .driver = {
> + .name = "mhi_wwan_dtr",
> + },
> +};
> +
> +static int __init mhi_wwan_ctrl_init(void)
> +{
> + int ret;
> +
> + ret = mhi_driver_register(&mhi_wwan_dtr_driver);
> + if (ret)
> + return ret;
> +
> + ret = mhi_driver_register(&mhi_wwan_ctrl_driver);
> + if (ret)
> + mhi_driver_unregister(&mhi_wwan_dtr_driver);
> +
> + return ret;
> +}
> +module_init(mhi_wwan_ctrl_init);
> +
> +static void __exit mhi_wwan_ctrl_exit(void)
> +{
> + mhi_driver_unregister(&mhi_wwan_ctrl_driver);
> + mhi_driver_unregister(&mhi_wwan_dtr_driver);
> +}
> +module_exit(mhi_wwan_ctrl_exit);
>
> MODULE_LICENSE("GPL v2");
> MODULE_DESCRIPTION("MHI WWAN CTRL Driver");
> --
> 2.43.0
>