summaryrefslogtreecommitdiff
path: root/drivers/iio/accel
AgeCommit message (Collapse)Author
25 hoursMerge branch 'headers' of git://git.infradead.org/users/willy/pagecache.gitMark Brown
# Conflicts: # drivers/gpu/drm/amd/amdkfd/kfd_migrate.c # net/ceph/osd_client.c
26 hoursMerge branch 'togreg' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/jic23/iio.git # Conflicts: # drivers/iio/adc/ade9000.c
3 daysiio: accel: sca3000: reject devices without match dataJiale Yao
SPI driver_override allows a device to bind to this driver without matching either the OF or SPI device ID table. In that case, spi_get_device_match_data() returns NULL. sca3000_probe() immediately dereferences the returned chip information to set the IIO device name and channel layout, causing a NULL pointer dereference. Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match data") fixed the same driver_override issue in another SPI driver. Reject devices without match data before using the chip information. Fixes: d6ae9f202f61 ("iio: sca3000: simplify with spi_get_device_match_data()") Cc: stable@vger.kernel.org Signed-off-by: Jiale Yao <yaojiale02@163.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
3 daysiio: accel: adxl380: reject devices without match dataJiale Yao
SPI driver_override allows a device to bind to this driver without matching either the OF or SPI device ID table. In that case, spi_get_device_match_data() returns NULL. adxl380_spi_probe() passes the result to adxl380_probe(), which dereferences chip_info to set the IIO device name and operations, causing a NULL pointer dereference. Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match data") fixed the same driver_override issue in another SPI driver. Reject devices without match data in the SPI frontend. Fixes: df36de13677a ("iio: accel: add ADXL380 driver") Cc: stable@vger.kernel.org Signed-off-by: Jiale Yao <yaojiale02@163.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
3 daysiio: accel: adxl372: reject devices without match dataJiale Yao
SPI driver_override allows a device to bind to this driver without matching either the OF or SPI device ID table. In that case, spi_get_device_match_data() returns NULL. adxl372_spi_probe() passes the result to adxl372_probe(), which dereferences chip_info to set the IIO device name and capabilities, causing a NULL pointer dereference. Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match data") fixed the same driver_override issue in another SPI driver. Reject devices without match data in the SPI frontend. Fixes: 23d742859a2d ("iio: accel: adxl372: introduce chip_info structure") Cc: stable@vger.kernel.org Signed-off-by: Jiale Yao <yaojiale02@163.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
3 daysiio: accel: adxl313: reject devices without match dataJiale Yao
SPI driver_override allows a device to bind to this driver without matching either the OF or SPI device ID table. In that case, spi_get_device_match_data() returns NULL. adxl313_spi_probe() dereferences chip_data to select the regmap configuration, causing a NULL pointer dereference. Commit 572a00852635 ("iio: dac: ad5686: missing NULL check on match data") fixed the same driver_override issue in another SPI driver. Reject devices without match data before selecting the configuration. Fixes: d6e3ee74d16f ("iio: accel: adxl313: simplify with spi_get_device_match_data()") Cc: stable@vger.kernel.org Signed-off-by: Jiale Yao <yaojiale02@163.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
4 daysiio: accel: kxcjk-1013: reject duplicate event disableJiale Yao
The IIO core does not filter duplicate writes to the event enable attribute. kxcjk1013_write_event_config() already ignores repeated enable requests, but a repeated disable request still calls kxcjk1013_set_power_state(data, false), dropping a runtime PM reference that was not acquired for this request. This can underflow the runtime PM usage count and trigger a "Runtime PM usage count underflow" warning. Return early when the requested state already matches ev_enable_state. Fixes: b4b491c0832e ("iio: accel: kxcjk-1013: Support thresholds") Signed-off-by: Jiale Yao <yaojiale02@163.com> Cc: stable@vger.kernel.org Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
7 daysiio: accel: bma220: publish the SPI driver ACPI aliasPengpeng Hou
The SPI driver advertises an ACPI match for BMA0220 but does not export that table. A modular build therefore lacks the ACPI alias used to load the driver when the device is enumerated through ACPI. Export the ACPI table. Move the existing SPI export next to its SPI ID table so each export is adjacent to the table it describes. The issue was found by our static-analysis tool. Fixes: bf2a5600a3eb ("iio: accel: Add support for Bosch BMA220") Assisted-by: LLM Signed-off-by: Pengpeng Hou <hppiscas@163.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
9 daysiio: accel: kx022a: fix typo in commentCarlos Casadiego
Fix "usng" to "using" in a comment. Signed-off-by: Carlos Casadiego <cdcp206@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
11 daysiio: accel: adis16201: add ADIS16203 supportShehryar Ahmad
Add ADIS16203 from staging to mainline ADIS16201. ADIS16203 shares same SPI protocol and register addresses. Differing parameters are handled by adis16201_chip_info structure. ADIS16203 specific support includes DIAG_STAT_SELFTEST_FAIL_BIT, which is supported only on ADIS16203, a separate channel array and separate adis_data struct. Kconfig is updated accordingly. Signed-off-by: Shehryar Ahmad <shehryar.amd@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
11 daysiio: accel: adis16201: prepare driver to support additional partsShehryar Ahmad
Introduce adis16201_chip_info to hold per chip data and adis16201_state to wrap struct adis. Move adis16201 to this infrastructure. This prepares the driver to support additional chip variants by keeping chip-specific parameters in adis16201_chip_info. Additionally, adis16201_write_raw applies mask directly on value. Signed-off-by: Shehryar Ahmad <shehryar.amd@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
11 daysiio: accel: adis16201: add OF device ID tableShehryar Ahmad
Add of_device_id table for adis16201 and register it with MODULE_DEVICE_TABLE() to enable device tree based matching. Signed-off-by: Shehryar Ahmad <shehryar.amd@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
11 daysiio: accel: adis16201: add SPI device ID tableShehryar Ahmad
Add spi_device_id table for ADIS16201. Replace MODULE_ALIAS() with MODULE_DEVICE_TABLE() which automatically generates the same module alias. Signed-off-by: Shehryar Ahmad <shehryar.amd@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
11 daysiio: accel: adis16201: fix channel order for buffer modeShehryar Ahmad
Reshuffle adis16201_channels to ascending scan_index order to avoid data corruption during IIO core demultiplexing since the ADIS driver builds the buffer in channel array order, while the IIO core demultiplexes it in scan_index order. This changes the raw buffer byte layout for existing adis16201 users reading buffered data directly. Fixes: 591298e54cea ("Staging: iio: accel: adis16201: Move adis16201 driver out of staging") Cc: stable@vger.kernel.org Signed-off-by: Shehryar Ahmad <shehryar.amd@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-09-17iio: accel: mma9553: disable autosuspend on removeGuangshuo Li
mma9553_probe() enables runtime PM autosuspend with pm_runtime_use_autosuspend(). The probe error path correctly undoes this setting with pm_runtime_dont_use_autosuspend(), but the normal remove path only disables runtime PM. The runtime PM API requires pm_runtime_use_autosuspend() to be undone with pm_runtime_dont_use_autosuspend() at driver exit unless runtime PM was enabled with devm_pm_runtime_enable(). Leaving the autosuspend flag set therefore leaves the runtime PM state incompletely cleaned up after the driver is unbound. Add the missing pm_runtime_dont_use_autosuspend() call to the remove path. This issue was found by manual code inspection. Fixes: 40cb761306d6 ("iio: add driver for Freescale MMA9553") Cc: stable@vger.kernel.org Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com> Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-09-17iio: accel: mma9551: disable autosuspend on removeGuangshuo Li
mma9551_probe() enables runtime PM autosuspend with pm_runtime_use_autosuspend(). The probe error path correctly undoes this setting with pm_runtime_dont_use_autosuspend(), but the normal remove path only disables runtime PM. The runtime PM API requires pm_runtime_use_autosuspend() to be undone with pm_runtime_dont_use_autosuspend() at driver exit unless runtime PM was enabled with devm_pm_runtime_enable(). Leaving the autosuspend flag set therefore leaves the runtime PM state incompletely cleaned up after the driver is unbound. Add the missing pm_runtime_dont_use_autosuspend() call to the remove path. This issue was found by manual code inspection. Fixes: 6da93a6710a3 ("iio: accel: mma9551: Add runtime pm support") Cc: stable@vger.kernel.org Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com> Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-09-17iio: accel: kxcjk-1013: Disable autosuspend on removeGuangshuo Li
kxcjk1013_probe() enables runtime PM autosuspend with pm_runtime_use_autosuspend(). The probe error path correctly undoes this setting with pm_runtime_dont_use_autosuspend(), but the normal remove path only disables runtime PM. The runtime PM API requires pm_runtime_use_autosuspend() to be undone with pm_runtime_dont_use_autosuspend() at driver exit unless runtime PM was enabled with devm_pm_runtime_enable(). Leaving the autosuspend flag set therefore leaves the runtime PM state incompletely cleaned up after the driver is unbound. Add the missing pm_runtime_dont_use_autosuspend() call to the remove path. This issue was found by manual code inspection. Fixes: 124e1b1d0924 ("iio: accel: kxcjk-1013: support runtime pm") Cc: stable@vger.kernel.org Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com> Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com> Acked-by: Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-09-17iio: accel: adxl367: resolve interrupt mapping before device setupAntoniu Miclaus
adxl367_set_int_map_reg() uses fwnode_irq_get_byname(), which can return -EPROBE_DEFER. Running it after adxl367_setup() made every deferred probe repeat the reset and power the device up needlessly. Move it ahead of the regulator enable and reset; the lookup only reads firmware properties, so a deferral now returns before any hardware access. Signed-off-by: Antoniu Miclaus <antoniu.miclaus@analog.com> Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-09-10iio: accel: kionix-kx022a: Fix IPOL macro nameMatti Vaittinen
The "interrupt polarity high"-macro for KX022A variant is defined as: "#define KX022A_MASK_IPOL KX022A_MASK_IPOL1" However, the KX022A_MASK_IPOL1 is not defined anywhere, so actually using the KX022A_IPOL_HIGH would produce a compile error. Fix the define by using correct mask. Fixes: 7c1d1677b322 ("iio: accel: Support Kionix/ROHM KX022A accelerometer") Signed-off-by: Matti Vaittinen <mazziesaccount@gmail.com> Reviewed-by: Mehdi Djait <mehdi.djait@linux.intel.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-09-06iio: accel: kionix-kx022a: Prevent memory leak and fix stateMatti Vaittinen
The driver allocates memory for samples at buffer enable path. If regmap operation fails in the kx022a_fifo_enable() at the buffer enable path, the allocated memory is never freed. Furthermore, the state information and previous hardware configuration(s) aren't undone, potentially leaving WMI interrupts and buffers enabled, or driver state flags wrong. Free the memory and revert the hardware configuration and state flags on error path. Fixes: e7123a4dfcd7 ("iio: accel: kionix-kx022a: Refactor driver and add chip_info structure") Signed-off-by: Matti Vaittinen <mazziesaccount@gmail.com> Reviewed-by: Mehdi Djait <mehdi.djait@linux.intel.com> Cc: stable@vger.kernel.org Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-09-04iio: accel: adxl367: add support for INT2 interrupt pinAntoniu Miclaus
The ADXL367 provides two independent interrupt output pins, INT1 and INT2, each with its own event mapping register (INTMAP1_LOWER at 0x2A and INTMAP2_LOWER at 0x2B) sharing an identical bit layout. Until now the driver hardcoded INT1 for all interrupt mappings, so a board that routes only INT2 to the host could never receive activity, inactivity or FIFO watermark interrupts. Determine the connected pin from the interrupt-names device tree property using fwnode_irq_get_byname(), and route the interrupt mappings to the matching register. Use the interrupt number returned by the lookup for devm_request_threaded_irq() so the requested line always matches the routed INTMAP register, regardless of the order in which the interrupts are listed. When no interrupt-names are present, default to INT1 and the bus-provided interrupt to preserve the existing behaviour. Signed-off-by: Antoniu Miclaus <antoniu.miclaus@analog.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-09-04iio: accel: adxl367: use regmap_assign_bits()Antoniu Miclaus
Several helpers set or clear a fixed set of bits based on a boolean using the regmap_update_bits(reg, mask, en ? mask : 0) idiom. Replace these with regmap_assign_bits(), which expresses the same intent more concisely. No functional change intended. Signed-off-by: Antoniu Miclaus <antoniu.miclaus@analog.com> Reviewed-by: Marcelo Schmitt <marcelo.schmitt@analog.com> Reviewed-by: Nuno Sá <nuno.sa@analog.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-31iio: accel: sca3000: fix frequency divider condition checkSalah Triki
When setting the sampling frequency, the check for `base_freq / 2` is followed by an independent `if` statement for `base_freq / 4`. If `val` equals `base_freq / 2`, the second check fails and falls through to the `else if (val != base_freq)` branch, returning `-EINVAL` erroneously. Fix this by chaining the checks with `else if`. Fixes: e0f3fc9b47e6 ("iio: accel: sca3000_core: implemented IIO_CHAN_INFO_SAMP_FREQ") Signed-off-by: Salah Triki <salah.triki@gmail.com> Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com> Cc: stable@vger.kernel.org Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-31iio: accel: kionix-kx022a: Fix array boundary checkMatti Vaittinen
The driver performs a sanity check for an array size, when converting a register value to an array index. The check incorrectly accepts the sizeof(array) as a last index, when last valid index should be sizeof(array) - 1. Fix the check by bailing out when index >= sizeof(array). Fixes: 7c1d1677b322 ("iio: accel: Support Kionix/ROHM KX022A accelerometer") Signed-off-by: Matti Vaittinen <mazziesaccount@gmail.com> Reviewed-by: Mehdi Djait <mehdi.djait@linux.intel.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-31iio: accel: bma400: remove completed tasks from TODO listMarco Chen
Two of the four tasks in the TODO comment have been implemented. Interrupts were added by commit ffe0ab6a9698 ("iio: accel: bma400: Add triggered buffer support"). Support for events was added by commit 961db2da159d ("iio: accel: bma400: Add support for single and double tap events"), among others. The driver now has an interrupt handler pushing IIO events, and event configuration from read_event_config(), write_event_config(), read_event_value(), and write_event_value(). A step count channel was also added by commit d221de60eee3 ("iio: accel: bma400: Add separate channel for step counter"). The power management and sensor time channel TODOs remain unimplemented. Signed-off-by: Marco Chen <marcochen.dev@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-31iio: accel: adxl367: reject out-of-range FIFO entry countShengzhuo Wei
The FIFO entry count reported by the device can be as large as 1023 (the low byte plus the low two bits of the high byte), but fifo_buf[] only has room for ADXL367_FIFO_SIZE (512) entries. adxl367_push_fifo_data() passes the reported count straight to the FIFO read, so a count above ADXL367_FIFO_SIZE overflows fifo_buf, a heap out-of-bounds write of up to 1022 bytes into adjacent memory. Rather than clamp the count and silently drop the excess, abort the read: a count beyond the FIFO size means the device is returning garbage, so the data cannot be trusted. The message is ratelimited because a stuck device can raise the IRQ repeatedly. Assisted-by: GLM:5.2 Signed-off-by: Shengzhuo Wei <me@cherr.cc> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-31iio: accel: adxl380: reject out-of-range FIFO entry countShengzhuo Wei
The FIFO entry count is a 9-bit device-reported value, so it can be as large as 511, but fifo_buf[] only has room for ADXL380_FIFO_SAMPLES (315) entries. adxl380_irq_handler() uses the reported count directly as the length of a bulk FIFO read, so a count above ADXL380_FIFO_SAMPLES overflows fifo_buf, a heap out-of-bounds write of up to 392 bytes into adjacent memory. Rather than clamp the count and silently drop the excess, abort the read: a count beyond the FIFO size means the device is returning garbage, so the data cannot be trusted. The message is ratelimited because a stuck device can raise the watermark IRQ repeatedly. Assisted-by: GLM:5.2 Signed-off-by: Shengzhuo Wei <me@cherr.cc> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-31iio: accel: kionix-kx022a: use iio_push_to_buffers_with_ts()Gabriel Rondon
Replace the deprecated iio_push_to_buffers_with_timestamp() with iio_push_to_buffers_with_ts(), which takes the destination buffer size and checks it against scan_bytes at runtime. Signed-off-by: Gabriel Rondon <grondon@gmail.com> Reviewed-by: Matti Vaittinen <mazziesaccount@gmail.com> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-31iio: accel: kionix-kx022a: use scan struct for one-shot and trigger readsGabriel Rondon
The driver kept two separate staging areas that hold the same thing: buffer[8], a DMA-aligned area used by the one-shot read in kx022a_get_axis() and by the triggered handler, and the scan struct, used by the FIFO flush path. Both are three __le16 channels plus room for the timestamp. Drop buffer and route the one-shot read and the triggered handler through scan.channels, so the driver has a single staging area. Move the IIO_DMA_MINALIGN alignment onto scan, since it now backs the regmap bulk reads that buffer used to. No functional change. get_axis() only runs via read_raw() under iio_device_claim_direct(), so it cannot run while the triggered buffer is active, and the triggered handler only runs while it is; the two never touch scan concurrently, exactly as they previously shared buffer. Signed-off-by: Gabriel Rondon <grondon@gmail.com> Reviewed-by: Matti Vaittinen <mazziesaccount@gmail.com> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-31iio: accel: mma8452: use guard() to release mutexesSanjay Chitroda
Replace explicit mutex_lock() and mutex_unlock() with the guard() and scoped_guard() macro for cleaner and safer mutex handling. Signed-off-by: Sanjay Chitroda <sanjayembeddedse@gmail.com> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-31iio: accel: mma8452: Use IIO cleanup helpersSanjay Chitroda
Use IIO_DEV_ACQUIRE_DIRECT_MODE() helper to automatically release direct mode. Suggested-by: Jonathan Cameron <Jonathan.Cameron@huawei.com> Signed-off-by: Sanjay Chitroda <sanjayembeddedse@gmail.com> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-31iio: accel: mma8452: use local struct deviceSanjay Chitroda
Introduce a local struct device pointer derived from &client->dev. This avoids repeated &client->dev usage and improves readability. Signed-off-by: Sanjay Chitroda <sanjayembeddedse@gmail.com> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-31iio: accel: mma8452: convert to bulk regulator usageSanjay Chitroda
The "vdd" and "vddio" regulators are always controlled together. Switch to the regulator bulk API to handle setup, enable, and disable paths in a single call. No functional change intended. Suggested-by: Jonathan Cameron <Jonathan.Cameron@huawei.com> Signed-off-by: Sanjay Chitroda <sanjayembeddedse@gmail.com> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-08-25headers: Remove swap.h from suspend.hMatthew Wilcox (Oracle)
Nothing in suspend.h needs swap.h. However, many files indirectly depend on some of swap.h's dependencies, so this is a large cross-subsystem patch. Stats: 42 are missing includes of interrupt.h (the question of why swap.h brings in interrupt.h remains unanswered). 10 missing includes of seq_file.h 5 missing includes of swap.h (obviously all files could have just added swap.h, but I preferred to bring in a more minimal inclusion set) 3 missing includes of highmem.h 2 missing includes of device.h 2 missing includes of string_choices.h 1 missing include of cacheflush.h 1 missing include of dma-direction.h 1 missing include of kthread.h 1 missing include of pagemap.h 1 missing include of string_helpers.h 1 missing include of writeback.h I tried to follow whatever conventions appeared to be in use for the various subsystems I touched; for example I added string_choices.h to drm_print.h instead of individually to each driver which used the functions declared there. Signed-off-by: Matthew Wilcox (Oracle) <willy@infradead.org>
2026-08-19Merge tag 'iio-for-7.3a' of ↵Greg Kroah-Hartman
ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/jic23/iio into char-misc-next Jonathan writes: IIO new device support, features, cleanup for 7.3 Includes a merge of 7.2-rc2 to pick up the changes around mod_devicetable.h and reduce resulting conflicts around includes. New device support ------------------ adi,ad3530R - Add support for the AD3532R and AD3532 16 channel DACs. adi,ad4080 - Add support for the AD4883 ADC. adi,ad5686 - Add support for AD5313R, AD5317R, AD5674, AD5687R, AD5689, AD5689R DACs over SPI - Add support for AD5316R, AD5674, AD5697R and AD5696 DACs over I2C - Significant driver refactoring prior to these additions, partly to reduce bus traffic and to add triggered buffer and gain control support. An earlier set added support for missing supplies, reset and LDAC GPIO. adi,adf41513 - New driver to support this PLL frequency synthesizer that runs up to 26.5 GHz. - Included infrastructure to handle higher precision attributes with extensive tests adi,ltc2378-20 - New driver supporting LTC2338, LTC2364, LTC2367, LTC2368, LT2369, LTC2370 LTC2376, LTC2377, LTC2378, LTC2379 and LTC23980 ADCs with both high speed capture via appropriate backend and conventional triggered buffer SPI capture. invensense,icm42607 - New driver for this IMU. mediateck,mt6323 - New driver for this PMIC ADC. microchip,mcp47a1 - New driver for this I2C 6 bit DAC. nxp,mcf54415-dac - New driver for this DAC found in NXP SoCs. qst,qmc5884l - New driver for this 3 axis magnetometer. Included dt vendor entry for qst. qst,qmc6308 - New driver for this 3 axis magnetometer. sensiron,slf3s - New driver for this liquid flow sensor. Includes adding IIO_VOLUMEFLOW channel type. st,vl53l1x - Refactors to improve readability. ti,ads112c14 - New driver supporting the ADS112C14 and ADS122C14 ADCs. These bring some new ABI for input chopping, particular useful for resistive sensors like thermocouples or Wheatstone bridges. - Support CRC8 detection of corruption on the bus. - Support buffered reads. ti,tmp117 - (trivial) Add support for the tmp119 temperature sensor. xilinx,versal-sysmon - New ADC driver for this block found on various FPGAs including various bus interfaces, threshold and oversampling support. dt binding updates ------------------ new shared bindings - excitation-channels and excitation-current-nanoamp allow per channel specification of currents used for resistive sensor measurement. - reference-sources property to allow selection of a per channel reference. rockchip,saradc - Add RV1106 which is compatible with the RV3588. Features -------- buffer-dmaengine - Allow cyclic buffers, useful for repeating sequence generation with DACs. devantech,dmard09 - Implement read back of channel scale - previously interface always returned an error. hid,sensors-als - Enable separate channel scaling for hardware that supports it. invensense,timestamp library - Various precision improvements. invensense,icm42600 - Add support for hwfifo watermark interfaces. taos,tcs3472 - Support wait time and sampling frequency control. Cleanups, minor fixes --------------------- Minor cleanups not mentioned at all in this summary such as white space fixes or typos. Affecting various drivers - Cleanup of conditionals that had no affect. - Drop some runtime pm local wrappers as now runtime_pm does the mark_last_busy part inside the put, these provide no useful code deduplication or readability advantages over directly calling the runtime_pm functions. - Return 0 from write_raw() on success. - Use of dev_err_probe() to simplify code and sometimes provide useful info for deferred probe debugging. - Drop some redundant error prints where the called function already provides information on errors. - Make some read only arrays in functions static. - Fix up missing handling of regcache_sync() errors. - Drop some false kernel-doc markings. - Add missing MODULE_DEVICE_TABLE for some of_match_id tables. - Use local variables for things like the struct device to shorten and improve readability of code. - Drop some unused structure elements. - Reorder dds.h macro parameters to be inline with others. - Header reorders and IWYU. Often part of a more significant series. - Remove abstractions designed to allow a driver to support multiple device types, when they have been around a long time and only the original part showed up. - Initialize spi_device_id arrays using member names following dropping of driver data from drivers that didn't actually use it. - Catch up with i2c_device_id tables added since previous effort to use named initializers for all those. - Use kernel types in a few places instead of standard C ones or bare unsigned. Misc - Update Xilinx AMS maintainer. - Update email address for Maxwell Doose. - Update email address for Siratul Islam. - Update email address for Tomasz Duszynski and re-add Tomasz to various maintainer entries. Docs - Encourage use of differential channel naming even when there is no flexibility in input to differential pair mapping. Intended to provide a strong signal to userspace that a channel is differential. adi,ad_sigma_delta - Allow COMPILE_TEST without any users. adi,ad2s1201 - Refactor trigger handler to avoid mix of guard() and goto. adi,ad5686 - Avoid potential NULL dereference is user forces a driver bind. adi,ad5696 - Add a couple of missing entries to the of_match_id table and update binding to match. atmel,ad91_adc - Use const char * for DT string property allowing a cast to be dropped. avia,hx711 - Various refactors and cleanup to enable support of additional parts (to come) - Add missing supply and gpio dt-bindings. bosch,bmc150 - Harden against device reporting too large a FIFO sample count. - Use FIELD_PREP() / FIELD_GET() to improve readability. freescale,fxls8962af - Harden against device reporting too large a FIFO sample count. hid-sensors-* - Reorder probe to not expose userspace interfaces until the rest of the setup is done to avoid potentially dropping data. honeywell,abp2030pa - Drop an unreachable return. invensens,icm45600 - Harden against bad value of FIFO sample count from device. - Use i2c_match_data if firmware table sourced match data isn't available. nxp,mpl1115 - Ensure runtime_pm is balanced on error in probe. rohm,bm1390 - Make the driver slightly more likely to recover from transient errors. sensiron,sgp30 - Handle thread creation errors. st,lsm6dsx - Update the enable mask when doing sensor fusion to avoid incorrect fifo data handling. st,stm32-dfsdm - Treat dt flags as booleans. ti,ads1015 - Switch to devm helpers which simplified code and closed a resource leak. ti,opt3001 - Split complicated opt3001_get_processed() logic into irq an no irq helper functions. - Use devm to simplify code. - Use guard() to simplify code. - Reorder probe so final call exposes userspace interfaces. - Various other more minor cleanup taos,tsl2772 - Fix calibscale readback to check right channel type. taos,tsl2583 - Use sysfs_emit() and sysfs_emit_at() to replace open coded equivalents. * tag 'iio-for-7.3a' of ssh://gitolite.kernel.org/pub/scm/linux/kernel/git/jic23/iio: (232 commits) iio: dac: mcp47a1: add support for new device dt-bindings: iio: dac: add support for mcp47a1 iio: Update email for Maxwell Doose iio: imu: st_lsm6dsx: Update enable mask when using sensor fusion iio: light: cm32181: return zero after writing calibscale iio: flow: add Sensirion SLF3S liquid flow sensor driver iio: core: add IIO_VAL_DECIMAL64_FEMTO format type dt-bindings: iio: flow: add Sensirion SLF3S liquid flow sensor iio: types: add IIO_VOLUMEFLOW channel type iio: ABI: Encourage differential voltage ABI usage iio: adc: ltc2378: Add support for LTC2338-18 iio: adc: ltc2378: Enable triggered buffer data capture iio: adc: ltc2378: Enable high-speed data capture iio: adc: ltc2378: Add support for LTC2378-20 and similar ADCs dt-bindings: iio: adc: Add ltc2378 iio: magnetometer: ak8974: remove conditional return with no effect iio: light: tsl2583: remove conditional return with no effect iio: adc: rcar-gyroadc: remove rcar_gyroadc_set_power() helper iio: light: vcnl4000: remove vcnl4000_set_pm_runtime_state() helper iio: light: vcnl4035: remove vcnl4035_set_pm_runtime_state() helper ...
2026-07-27iio: accel: Remove redundant dev_err()/dev_err_probe()Pan Chuang
Since commit 55b48e23f5c4 ("genirq/devres: Add error handling in devm_request_*_irq()"), devm_request_irq() and devm_request_threaded_irq() automatically log detailed error messages on failure. Remove the now-redundant driver-specific dev_err() and dev_err_probe() calls. Standardize on if (ret) check rather than if (ret < 0). Signed-off-by: Pan Chuang <panchuang@vivo.com> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-07-12Merge tag 'char-misc-7.2-rc3' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc Pull Android/IIO fixes from Greg KH: "Here is a set of bugfixes for 7.2-rc3 that resolve a bunch of reported issues in just the binder and iio codebases. Included in here are: - binder driver bugfixes for both the rust and c versions for reported problems - lots and lots of iio driver bugfixes for lots of reported issues (including a hid sensor driver bugfix) Full details are in the shortlog, all of these have been in linux-next with no reported issues" * tag 'char-misc-7.2-rc3' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc: (36 commits) iio: event: Fix event FIFO reset race iio: imu: inv_icm42600: fix timestamp clock period by using lower value iio: light: al3010: fix incorrect scale for the highest gain range iio: adc: nxp-sar-adc: Fix the delay calculation in nxp_sar_adc_wait_for() iio: light: tsl2591: return actual error from probe IRQ failure iio: imu: inv_icm42600: fix timestamping by limiting FIFO reading iio: imu: st_lsm6dsx: deselect shub page before reading whoami rust_binder: clear freeze listener on node removal rust_binder: reject context manager self-transaction rust_binder: use a u64 stride when cleaning up the offsets array binder: fix UAF in binder_free_transaction() binder: fix UAF in binder_thread_release() rust_binder: synchronize Rust Binder stats with freeze commands binder: cache secctx size before release zeroes it rust_binder: fix BINDER_GET_EXTENDED_ERROR iio: adc: ad7779: add missing 'select IIO_TRIGGERED_BUFFER' to Kconfig iio: adc: ad4130: add missing `select IIO_TRIGGERED_BUFFER` to Kconfig iio: adc: ti-ads124s08: Return reset GPIO lookup errors iio: temperature: Build mlx90635 with CONFIG_MLX90635 iio: light: al3320a: add missing REGMAP_I2C to Kconfig ...
2026-07-12iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALEMert Seftali
Reading the in_accel_scale attribute on the DMARD09 has always returned -EINVAL: the channels advertise scale via info_mask_shared_by_type so the IIO core exposes the attribute, but dmard09_read_raw() only handles IIO_CHAN_INFO_RAW, so a SCALE read falls through to 'default: return -EINVAL': $ cat .../iio:deviceX/in_accel_scale cat: in_accel_scale: Invalid argument leaving userspace with raw counts it cannot convert to m/s^2. The driver was written from a vendor source [1] without a datasheet, and the scale was declared but never implemented. The vendor source carries the sensitivity: its conversion is acc = raw * GRAVITY_EARTH_1000 / sensitivity (then / 1000 -> m/s^2) with sensitivity = 32 and GRAVITY_EARTH_1000 = 9807 ("about (9.80665)*1000"), i.e. 32 counts correspond to 1 g. That sensitivity applies to the value this driver already reports as raw: the vendor reduces each 16-bit sample to a signed 9-bit value, and the preparation in dmard09_read_raw() yields the same value. It is self-consistent: 256 counts / 32 = 8 g full scale, matching the +/-8g range. Implement the scale derived from that sensitivity using standard gravity: scale = 9.80665 / 32 = 0.3064578125 m/s^2 per LSB Link: https://github.com/minstrelsy/mediatek/blob/1f49d8c87b839651bc89afc870277e8e0f2e2d55/custom/common/kernel/accelerometer/dmard09/dmard09.c [1] Fixes: a4fa6509dda4 ("iio: accel: add support for the Domintech DMARD09 3-axis accelerometer") Signed-off-by: Mert Seftali <mertsftl@gmail.com> Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com> Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
2026-07-07iio: hid-sensors: Use implicit NULL pointer checksSanjay Chitroda
Replace explicit NULL pointer comparisons with implicit checks across HID sensor IIO drivers to fix kernel coding style. CHECK: Comparison to NULL could be written ... No functional change. Signed-off-by: Sanjay Chitroda <sanjayembeddedse@gmail.com> Reviewed-by: Maxwell Doose <m32285159@gmail.com> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org>
2026-07-07iio: hid-sensors: align function parenthesis for readabilitySanjay Chitroda
Adjust alignment of parentheses across HID sensor IIO drivers to improve readability and maintain consistency with kernel coding style. While updating the formatting, group related arguments consistently in multi-line function signatures where appropriate. No functional change intended. Signed-off-by: Sanjay Chitroda <sanjayembeddedse@gmail.com> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org>
2026-07-06Merge tag 'v7.2-rc2' into togregJonathan Cameron
Linux 7.2-rc2 Done to resolve conflicts with header reorg around mod_devicetable.h and provide a base for other inflight series that touch the includes.
2026-07-03Replace <linux/mod_devicetable.h> by more specific <linux/device-id/*.h> (c ↵Uwe Kleine-König (The Capable Hub)
files) Replace the #include of <linux/mod_devicetable.h> by the more specific <linux/device-id/*.h> where applicable. For most cases the include can be dropped completely, only a few drivers need one or two headers added. Acked-by: Danilo Krummrich <dakr@kernel.org> Acked-by: Takashi Sakamoto <o-takashi@sakamocchi.jp> Acked-by: Bjorn Helgaas <bhelgaas@google.com> Link: https://patch.msgid.link/1a3f2007c5c5dcf555c09a4035ce3ae8ef1b6c49.1782808461.git.u.kleine-koenig@baylibre.com Signed-off-by: Uwe Kleine-König (The Capable Hub) <u.kleine-koenig@baylibre.com>
2026-07-02iio: accel: hid-sensor-accel-3d: Avoid race between callback setup and ↵Sanjay Chitroda
device exposure The driver currently exposes the IIO device to userspace before completing sensor hub callback registration, and similarly removes callbacks while the device can still be accessed during teardown. This creates a timing window where userspace may enable the buffer before callbacks are available. In such cases: - samples can be dropped, - buffered reads may observe stale or no data. Reorder probe and remove paths to ensure callbacks are active before device exposure and are removed after device is no longer accessible. This avoids a race window leading to data loss. Signed-off-by: Sanjay Chitroda <sanjayembeddedse@gmail.com> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Acked-by: Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org>
2026-06-30iio: Initialize spi_device_id arrays using member namesUwe Kleine-König (The Capable Hub)
While being less compact, using named initializers allows to more easily see which members of the structs are assigned which value without having to lookup the declaration of the struct. And it's also more robust against changes to the struct definition. The mentioned robustness is relevant for a planned change to struct spi_device_id that replaces .driver_data by an anonymous union. This patch doesn't modify the compiled arrays, only their representation in source form benefits. The former was confirmed with x86 and arm64 builds. Signed-off-by: Uwe Kleine-König (The Capable Hub) <u.kleine-koenig@baylibre.com> Acked-by: Linus Walleij <linusw@kernel.org> Reviewed-by: Nuno Sá <nuno.sa@analog.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org>
2026-06-30iio: Drop unused assignment of spi_device_id driver dataUwe Kleine-König (The Capable Hub)
The drivers explicitly set the .driver_data member of struct spi_device_id to zero without relying on that value. Drop these unused assignments. While touching these arrays unify spacing and use named initializers for .name. This patch doesn't modify the compiled arrays, only their representation in source form benefits. The former was confirmed with x86 and arm64 builds. Signed-off-by: Uwe Kleine-König (The Capable Hub) <u.kleine-koenig@baylibre.com> Reviewed-by: Nuno Sá <nuno.sa@analog.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org>
2026-06-30iio: accel: bmc150: Explicitly set spi .driver_dataUwe Kleine-König (The Capable Hub)
There is one id entry that has an explicit assignment to .driver_data. To make the intention clearer, assign BOSCH_UNKNOWN (which is also 0) for all previously ids that had .driver_data = 0 implicitly before. While touching all entries in this array, convert to named initializers. This change is similar to commit e50856dc41e8 ("iio: accel: bmc150: Explicitly set .driver_data") but cares for the driver's spi part instead of i2c. Signed-off-by: Uwe Kleine-König (The Capable Hub) <u.kleine-koenig@baylibre.com> Reviewed-by: Nuno Sá <nuno.sa@analog.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org>
2026-06-30iio: accel: fxls8962af: clamp the device-reported FIFO sample countBryam Vargas
fxls8962af_fifo_flush() transfers the sample count the device reports in BUF_STATUS into an on-stack buffer sized for FXLS8962AF_FIFO_LENGTH (32) samples, but the count is a 6-bit field (0..63) that is only checked for zero. A device, or an attacker on the I2C/SPI bus, reporting 33..63 overflows the buffer by up to 186 bytes: a stack out-of-bounds write. Clamp the count to FXLS8962AF_FIFO_LENGTH before the transfer, mirroring the clamp already applied in fxls8962af_set_watermark(). Conforming hardware reports at most that many samples and is unaffected. Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org>
2026-06-30iio: accel: bmc150: clamp the device-reported FIFO frame countBryam Vargas
__bmc150_accel_fifo_flush() transfers the frame count the device reports in FIFO_STATUS into an on-stack buffer sized for BMC150_ACCEL_FIFO_LENGTH (32) samples, but the count is masked to 7 bits (0..127) and the optional caller budget does not bound the flush-all path. A device, or an attacker on the I2C/SPI bus, reporting up to 127 frames overflows the buffer by up to 570 bytes: a stack out-of-bounds write. Clamp the count to BMC150_ACCEL_FIFO_LENGTH before the transfer, mirroring the clamp already applied in bmc150_accel_set_watermark(). Conforming hardware reports at most that many frames and is unaffected. Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me> Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org>
2026-06-30iio: accel: stk8ba50: Update includes to match IWYUMiao Li
Update the list of included headers in stk8ba50.c using Include-What-You-Use (IWYU) tool, mainly to remove kernel.h and add missing headers such as array_size.h, bitops.h, dev_printk.h, etc. Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com> Signed-off-by: Miao Li <limiao@kylinos.cn> Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com> Signed-off-by: Jonathan Cameron <jic23@kernel.org>
2026-06-29iio: accel: kxsd9: fix runtime PM imbalance on write_raw() errorBiren Pandya
kxsd9_write_raw() takes a runtime PM reference with pm_runtime_get_sync() but returns -EINVAL directly when a scale with a non-zero integer part is requested, skipping the matching pm_runtime_put_autosuspend(). This leaks a runtime PM usage-counter reference on every such write, after which the device can no longer autosuspend. Set the error code and fall through to the existing put instead of returning early. Fixes: 9a9a369d6178 ("iio: accel: kxsd9: Deploy system and runtime PM") Signed-off-by: Biren Pandya <birenpandya@gmail.com> Assisted-by: Claude:claude-opus-4-8 coccinelle Cc: <Stable@vger.kernel.org> Signed-off-by: Jonathan Cameron <jic23@kernel.org>