Re: [PATCH v5 02/13] gpio: mxc: fix both_edges bit operations

From: Frank Li

Date: Fri Oct 09 2026 - 14:59:39 EST


On Sat, Oct 10, 2026 at 02:05:23AM +0800, Peng Fan (OSS) wrote:
> From: Peng Fan <peng.fan@xxxxxxx>
>
> gpio_set_irq_type() can be called concurrently for different pins on
> the same port. The IRQ core serializes per irq descriptor, but
> different pins have different descriptors, so on SMP systems two
> concurrent gpio_set_irq_type() calls for pins on the same port run
> without mutual exclusion.
>
> The read-modify-write of port->both_edges is performed outside the
> port-wide scoped_guard(gpio_generic_lock_irqsave) section, so
> concurrent updates for different pins can overwrite each other,
> causing missed interrupts or stuck IRQ lines on dual-edge triggered
> pins.
>
> The original uniprocessor MXC SoCs were not affected; the race
> became reachable on multi-core i.MX7 and i.MX8 SoCs that reuse this
> driver.
>
> Convert both_edges from u32 to unsigned long and use set_bit(),
> clear_bit(), and test_bit() to make the modifications atomic.
>
> Fixes: 910862ec092c ("mxc: emulate GPIO interrupt on both-edges")
> Signed-off-by: Peng Fan <peng.fan@xxxxxxx>
> ---

Reviewed-by: Frank Li <Frank.Li@xxxxxxx>

> drivers/gpio/gpio-mxc.c | 8 ++++----
> 1 file changed, 4 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/gpio/gpio-mxc.c b/drivers/gpio/gpio-mxc.c
> index e05f276a50e8..2f83a0f076bf 100644
> --- a/drivers/gpio/gpio-mxc.c
> +++ b/drivers/gpio/gpio-mxc.c
> @@ -68,7 +68,7 @@ struct mxc_gpio_port {
> struct irq_domain *domain;
> struct gpio_generic_chip gen_gc;
> struct device *dev;
> - u32 both_edges;
> + unsigned long both_edges;
> struct mxc_gpio_reg_saved gpio_saved_reg;
> bool power_off;
> u32 wakeup_pads;
> @@ -168,7 +168,7 @@ static int gpio_set_irq_type(struct irq_data *d, u32 type)
> int edge;
> void __iomem *reg = port->base;
>
> - port->both_edges &= ~(1 << gpio_idx);
> + clear_bit(gpio_idx, &port->both_edges);
> switch (type) {
> case IRQ_TYPE_EDGE_RISING:
> edge = GPIO_INT_RISE_EDGE;
> @@ -188,7 +188,7 @@ static int gpio_set_irq_type(struct irq_data *d, u32 type)
> edge = GPIO_INT_HIGH_LEV;
> pr_debug("mxc: set GPIO %d to high trigger\n", gpio_idx);
> }
> - port->both_edges |= 1 << gpio_idx;
> + set_bit(gpio_idx, &port->both_edges);
> }
> break;
> case IRQ_TYPE_LEVEL_LOW:
> @@ -259,7 +259,7 @@ static void mxc_gpio_irq_handler(struct mxc_gpio_port *port, u32 irq_stat)
> while (irq_stat != 0) {
> int irqoffset = fls(irq_stat) - 1;
>
> - if (port->both_edges & (1 << irqoffset))
> + if (test_bit(irqoffset, &port->both_edges))
> mxc_flip_edge(port, irqoffset);
>
> generic_handle_domain_irq(port->domain, irqoffset);
>
> --
> 2.51.0
>
>