[PATCH 1/3] mtd: maps: only point() maps read through the simple accessors
From: Orgad Shaneh
Date: Sat Oct 10 2026 - 13:22:01 EST
map_is_linear() only checks that a map has a physical address. Map
drivers that install their own accessors keep one, and a pointer
bypasses whatever those accessors do:
- physmap's IXP4xx support: the expansion bus only takes 16-bit
accesses (the reason it cannot use memcpy_fromio()), and on
little-endian kernels every access also flips address bit 1 and
swaps bytes;
- physmap's Gemini support enables the flash pins only inside its
accessors;
- lantiq-flash serializes the external bus against PCI and copies byte
by byte because the EBU cannot take a prefetching memcpy;
- cobalt-flash reads at an offset inside a PCI BAR while leaving phys 0.
cfi_cmdset_0001 hands such pointers to jffs2 today, and the IXP4xx
boards carry Intel StrataFlash. Add map_is_simple(), true when the map
reads through the simple accessors (always true without
CONFIG_MTD_COMPLEX_MAPPINGS, where the accessors are inline), and
require it before enabling point(). Maps with custom accessors fall
back to copying through them; on big-endian IXP4xx, where pointed reads
happened to work, jffs2 mounts get slower.
Fixes: 9d3b5086f6d4 ("mtd: physmap_of_gemini: Handle pin control")
Fixes: 2aba2f2a704d ("mtd: physmap_of: add a hook for Intel IXP4xx flash probing")
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Orgad Shaneh <orgads@xxxxxxxxx>
Cc: Linus Walleij <linusw@xxxxxxxxxx>
Cc: Imre Kaloz <kaloz@xxxxxxxxxxx>
Cc: Hans Ulli Kroll <ulli.kroll@xxxxxxxxxxxxxx>
Cc: John Crispin <john@xxxxxxxxxxx>
---
drivers/mtd/chips/cfi_cmdset_0001.c | 2 +-
drivers/mtd/maps/map_funcs.c | 12 ++++++++++++
include/linux/mtd/map.h | 2 ++
3 files changed, 15 insertions(+), 1 deletion(-)
diff --git a/drivers/mtd/chips/cfi_cmdset_0001.c b/drivers/mtd/chips/cfi_cmdset_0001.c
index b73596a..3f3364c 100644
--- a/drivers/mtd/chips/cfi_cmdset_0001.c
+++ b/drivers/mtd/chips/cfi_cmdset_0001.c
@@ -299,7 +299,7 @@ static void fixup_LH28F640BF(struct mtd_info *mtd)
static void fixup_use_point(struct mtd_info *mtd)
{
struct map_info *map = mtd->priv;
- if (!mtd->_point && map_is_linear(map)) {
+ if (!mtd->_point && map_is_linear(map) && map_is_simple(map)) {
mtd->_point = cfi_intelext_point;
mtd->_unpoint = cfi_intelext_unpoint;
}
diff --git a/drivers/mtd/maps/map_funcs.c b/drivers/mtd/maps/map_funcs.c
index 1a4add9..ccf1dbf 100644
--- a/drivers/mtd/maps/map_funcs.c
+++ b/drivers/mtd/maps/map_funcs.c
@@ -41,5 +41,17 @@ void simple_map_init(struct map_info *map)
}
EXPORT_SYMBOL(simple_map_init);
+
+/*
+ * True when every access goes through the simple accessors, so a reader
+ * may use map->virt directly; a map with its own accessors (byte swaps,
+ * bus locking, address fixups) must not be pointed at.
+ */
+bool map_is_simple(struct map_info *map)
+{
+ return map->read == simple_map_read &&
+ map->copy_from == simple_map_copy_from;
+}
+EXPORT_SYMBOL(map_is_simple);
MODULE_DESCRIPTION("Out-of-line map I/O");
MODULE_LICENSE("GPL");
diff --git a/include/linux/mtd/map.h b/include/linux/mtd/map.h
index 75b0b2a..ebee3fe 100644
--- a/include/linux/mtd/map.h
+++ b/include/linux/mtd/map.h
@@ -449,6 +449,7 @@ static inline void inline_map_copy_to(struct map_info *map, unsigned long to, co
#define map_copy_to(map, to, from, len) (map)->copy_to(map, to, from, len)
extern void simple_map_init(struct map_info *);
+bool map_is_simple(struct map_info *map);
#define map_is_linear(map) (map->phys != NO_XIP)
#else
@@ -460,6 +461,7 @@ extern void simple_map_init(struct map_info *);
#define simple_map_init(map) BUG_ON(!map_bankwidth_supported((map)->bankwidth))
#define map_is_linear(map) ({ (void)(map); 1; })
+#define map_is_simple(map) ({ (void)(map); 1; })
#endif /* !CONFIG_MTD_COMPLEX_MAPPINGS */
--
2.53.0