summaryrefslogtreecommitdiff
path: root/drivers/power
AgeCommit message (Collapse)Author
3 hoursMerge branch 'headers' of git://git.infradead.org/users/willy/pagecache.gitMark Brown
# Conflicts: # drivers/gpu/drm/amd/amdkfd/kfd_migrate.c # net/ceph/osd_client.c
3 hoursMerge branch 'pwrseq/for-next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux.git
8 hoursMerge branch 'for-next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/sre/linux-power-supply.git
9 hoursMerge branch 'fixes' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/sre/linux-power-supply.git
5 dayspower: supply: sbs-battery: disable polling before supply teardownMyeonghun Pak
The managed poll-work cancellation is registered before the power supply, so cleanup unregisters the supply before draining polling. A pending or running poller can then call power_supply_changed() on the released supply. Commit 8d59cf3887fb ("power: supply: sbs-battery: Fix use-after-free in power_supply_changed()") moved the IRQ request after supply registration, but did not change the poll-work cancellation order. Add a later managed action that disables and drains polling before supply teardown. Its retained disabled state prevents external-power callbacks from rearming the poll work after it has been drained. Keep the original autocancel to initialize work before supply callbacks can run and to cover failed supply registration. The teardown ordering issue was found by static analysis. Fixes: 6d0c5de2fd84 ("power: supply: Clean-up few drivers by using managed work init") Cc: stable@vger.kernel.org # 6.10+ Assisted-by: LLM Co-developed-by: Ijae Kim <ae878000@gmail.com> Signed-off-by: Ijae Kim <ae878000@gmail.com> Signed-off-by: Myeonghun Pak <mhun512@gmail.com> Link: https://patch.msgid.link/20261004041019.1123723-1-mhun512@gmail.com Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: pf1550: drain IRQ work before unregistering suppliesMyeonghun Pak
The VBUS work calls power_supply_changed(), but its managed cancellation is registered before the supplies. Cleanup can therefore unregister a supply while IRQ-triggered work is still pending. Commit 838767f50747 ("power: supply: pf1550: Fix use-after-free in power_supply_changed()") moved IRQ requests after supply registration, but left work cancellation before the supplies. That change protects the direct IRQ callbacks, while this fix drains the work they queue. Register the three work items after both supplies and before the IRQs. Cleanup then frees the IRQ producers, drains the work, and unregisters the supplies. The teardown ordering issue was found by static analysis. Fixes: 4b6b6433a97d ("power: supply: pf1550: add battery charger support") Cc: stable@vger.kernel.org Assisted-by: LLM Co-developed-by: Ijae Kim <ae878000@gmail.com> Signed-off-by: Ijae Kim <ae878000@gmail.com> Signed-off-by: Myeonghun Pak <mhun512@gmail.com> Link: https://patch.msgid.link/20261004043728.1140015-1-mhun512@gmail.com Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: bq256xx: Expose VBUS state through extconReza Kurniawan
Useful for USB controllers needing to sense VBUS state changes. This is needed for devices like Xiaomi Redmi 5A (riva) that doesn't have its VBUS session comparator wired directly to the USB connector pin to automatically enable certain USB functions upon the presence of a USB power input. Signed-off-by: Reza Kurniawan <imkyufie@gmail.com> Link: https://patch.msgid.link/20260912-riva-usb-v2-1-997fe0171ee5@gmail.com Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_fg: Avoid reserved AB8505 CCConf bitLinus Walleij
AB8500 defines CCConf bit 1 as CCDeepSleepEna, but AB8505 reserves bits 7:1 and only defines bit 0, CCPwrUpEna. The fuel-gauge driver currently writes both bits whenever it starts the coulomb counter. The Samsung-GT-S7710-Skomer and related Samsung product trees use the same unconditional value in their fuel-gauge drivers, so they provide no AB8505 workaround to carry over. Select the value from the detected PMIC variant instead, retaining the deep-sleep enable bit on all existing non-AB8505 paths and avoiding the reserved bit on AB8505. Fixes: a982362c1723 ("mfd: Support for the AB8500 AB8505 variant") Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-15-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_fg: Finalize current measurementsLinus Walleij
ab8500_fg_inst_curr_start() returns with cc_lock held and the CCEOC IRQ enabled. The bounded sampling loop in the load-compensated voltage path returns without calling ab8500_fg_inst_curr_finalize() when it expires, leaving both resources active. The next fuel-gauge work item then blocks on cc_lock and all cached power-supply values stop updating. The Samsung-GT-I8530-Gavini, Samsung-GT-S7710-Skomer, Samsung-SGH-I407-Kyle and Samsung-SGH-T599-Codina-TMO product trees use a bounded sampling loop in drivers/battery/abb_fuelgauge.c but still call the finalizer. Follow that pattern so the normal completion timeout also performs the required cleanup. Check the start result as well and return an uncompensated voltage if the instantaneous current transaction cannot be started or completed. Fixes: edc400e1632f ("power: supply: ab8500_fg: Break loop for measurement") Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-14-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_charger: Recover inactive AB8505 chargerLinus Walleij
UsbChCtrl1.UsbChEna can remain set while UsbChStatus1.UsbChOn is clear. The existing recovery only checks the control bit, so it considers the charger enabled and leaves charging stopped. The Samsung-GT-S7710-Skomer, Samsung-SGH-I407-Kyle, and Samsung-SGH-T599-Codina-TMO product trees are reference points for checking both bits and cycling the charger when they disagree. Extend the USB charger check to detect this AB8505 state and enable the check in the charging algorithm for AB8505. Only cycle the charger when VBUS is debounced and no charger-not-OK, thermal, overvoltage, or watchdog fault accounts for the inactive hardware. Fixes: 4dcdf57773fd ("ab8500-bm: Quick re-attach charging behaviour") Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-13-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_charger: Retry AB8505 USB detectionLinus Walleij
AB8505 reports UsbLink1Status state 14 when the USB charger port is not OK. The manual says that software can return the port detector to the detection state by setting the self-clearing ChargerCtrl.DropCountReset bit. The Samsung-GT-S7710-Skomer, Samsung-SGH-I407-Kyle, and Samsung-SGH-T599-Codina-TMO product trees are reference points for a workaround that cycles the USB charger and retries detection three times before rejecting VBUS. Only the Kyle tree writes 1 to DropCountReset; the other two write 0 and therefore do not request the documented reset. Add the same bounded recovery for AB8505, preserving the configured USB charger control bits across each cycle. Keep the charger connected while recovering, then report the fault and disconnect it if all three attempts fail. Leave AB8500 behavior unchanged. Fixes: d4337660d069 ("ab8500-charger: Add AB8505_USB_LINK_STATUS") Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-12-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_charger: Skip absent AB8505 main chargerLinus Walleij
AB8505 contains only the USB charger. It has no integrated main charger, main-charger status register, or main-charger interrupts. Avoid reading the missing status register, requesting the five missing interrupts, or disabling an AC charger which was never enabled. This lets the driver bind using only the AB8505 USB charger resources. Fixes: d4337660d069 ("ab8500-charger: Add AB8505_USB_LINK_STATUS") Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-11-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_charger: Handle detection errorsLinus Walleij
ab8500_charger_detect_chargers() returns either a charger bitmask or a negative register-access error. The probe and component-bind paths use a negative return value as a bitmask, making failed reads appear as both AC and USB connections. Propagate detection errors and release the bind-time workqueue on failure. Fixes: 84edbeeab67c ("ab8500-charger: AB8500 charger driver") Fixes: 1c1f13a006ed ("power: supply: ab8500: Move to componentized binding") Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-10-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_charger: Respect AB8505 register layoutLinus Walleij
Several AB8505 charger fields differ from AB8500. Its long VBUS falling debounce is 300 ms rather than 100 ms, and its VBUS overvoltage selector has a different encoding programmed through OTP. Writing the AB8500 6.3 V value selects 9 V on AB8505. AB8505 revision 3 also defines SwControlFallback as reserved, correcting older documentation which led the driver to support autopower there. Preserve the AB8505 overvoltage setting, wait for its documented debounce, and reject the unsupported autopower setting. Fixes: 0ed5107fa860 ("ab8500-charger: Do not touch VBUSOVV bits") Fixes: b016322293c7 ("ab8500-charger: Add support for autopower on AB8505 and AB9540") Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-9-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_charger: Decode AB8505 USB statusLinus Walleij
AB8505 keeps USB link status in the same bit position as AB8500 but defines a different five-bit value table. Reusing the AB8500 enum treats several reserved AB8505 values as chargers and misidentifies the AB8505 charger-fault and DM-high states. Add an AB8505 decoder, reject reserved and non-charging states, and retain conservative current limits for supported charger types. Restrict the invalid-link workaround to AB8500 and stop processing when the status register cannot be read. Fixes: d4337660d069 ("ab8500-charger: Add AB8505_USB_LINK_STATUS") Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-8-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_charger: Fix AC charger re-enableLinus Walleij
The AC check-enable callback passes the embedded USB charger object to ab8500_charger_ac_en(). That helper derives the parent with the AC charger offset, so the wrong object yields an invalid ab8500_charger pointer. Pass the AC charger object when re-enabling AC charging. Fixes: bc6e02871402 ("power: supply: ab8500: Standardize CV voltage") Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-7-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500: Preserve battery termination currentLinus Walleij
The battery-info parser uses a negative value for an unspecified termination current. Testing the value as a boolean instead replaces every valid positive current from the battery description with 200 mA. Apply the default only when the property is unspecified so batteries retain their described charging termination current. Fixes: 9c20899da46b ("power: supply: ab8500: Standardize termination current") Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-6-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_btemp: Fix event temperature reportingLinus Walleij
The event-aware path initializes its local temperature to zero and compares that zero against the thermal thresholds. Consequently some events report the measured temperature after it crosses the event threshold, while others always report the threshold. Start with the measured temperature, clamp it according to the active event, and convert to tenths of a degree only once. This path is used by AB8505 and later variants. Fixes: 1f855824757e ("ab8500-btemp: AB8500 battery temperature driver") Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-5-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_fg: Drop nonexistent AB8505 controlsLinus Walleij
The AB8505 RTC register map has no register at offset 0x15, but the fuel-gauge driver initializes and exposes that offset as a power-cut flag-time control. PcutCtlAndStatus bit 4, exposed as powercut_flag, is reserved as well. Remove both nonexistent controls and their internal configuration field so the driver no longer accesses reserved hardware locations. Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-4-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500: Correct register definitionsLinus Walleij
The charger LED PWM register encodes its duty cycle as (N + 1) / 256. The value for 252/256 is therefore 0xfb, not 0xbf. Both output-current codes 0xe and 0xf select 1.5 A, while 0x3f cannot fit in the four-bit field. Also correct the AB8505 BatCtrl bit 0 current source from 18 uA to 8 uA. Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-3-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_fg: Report sub-percent charge changesLinus Walleij
The fuel gauge updates bat_cap.mah from the coulomb counter but exposes bat_cap.prev_mah through CHARGE_NOW and ENERGY_NOW. It only refreshes prev_mah when the rounded integer capacity percentage changes, making the momentary properties appear frozen between percentage steps. Refresh prev_mah and notify userspace whenever the new charge remains within the currently accepted percentage. If a discharge estimate tries to cross upward into a higher percentage, the existing rejection still leaves both the reported percentage and charge unchanged. The AB8500 fuel-gauge implementations in the Samsung-GT-I8160-Codina, Samsung-GT-I8160_HD-Codina, Samsung-GT-I8530-Gavini, Samsung-GT-S7710-Skomer, Samsung-SGH-I407-Kyle and Samsung-SGH-T599-Codina-TMO product trees retain the same percentage-gated prev_mah update and contain no finer-grained reporting workaround. Fixes: 13151631b5bd ("ab8500-fg: A8500 fuel gauge driver") Cc: stable@vger.kernel.org Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-2-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ab8500_fg: Accept status from supplied powerLinus Walleij
Commit dc77721ea4aa ("power: supply: ab8500: Set typing and props") changed the charging algorithm power supply type from battery to unknown so userspace would not mistake it for a second battery. The fuel gauge, however, processes status changes only from battery-type supplies. It therefore never learns that charging started and keeps running its discharge state machine. The power supply relationship already limits the callback to supplies naming the fuel gauge in supplied_to. Accept status from any such supply while retaining the battery type checks for battery-specific properties. The Samsung-GT-I8160-Codina and Samsung-GT-I8160_HD-Codina product trees keep the charging algorithm typed as a battery. The Samsung-GT-I8530-Gavini, Samsung-GT-S7710-Skomer, Samsung-SGH-I407-Kyle and Samsung-SGH-T599-Codina-TMO alternative fuel-gauge drivers instead pass cable state directly. Both approaches preserve the charging state handoff that was lost in mainline. Fixes: dc77721ea4aa ("power: supply: ab8500: Set typing and props") Cc: stable@vger.kernel.org Assisted-by: LLM Signed-off-by: Linus Walleij <linusw@kernel.org> Link: https://patch.msgid.link/20260916-ab8500-charging-v1-1-e986ed321cc6@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: max17042_battery: Make the fractional macros safeBabanpreet Singh
The fractional LSB macros expand to a plain division, so they only work when multiplied first and evaluate to 0 anywhere else. Take the value as a macro argument and apply it with mult_frac(), which properly handles it. Reported-by: kernel test robot <lkp@intel.com> Reported-by: Dan Carpenter <error27@gmail.com> Closes: https://lore.kernel.org/r/202606062322.TyvCPB3l-lkp@intel.com/ Assisted-by: LLM Signed-off-by: Babanpreet Singh <bbnpreetsingh@gmail.com> Link: https://patch.msgid.link/20260915052529.7-1-bbnpreetsingh@gmail.com [fixed commit message, dropped useless AI comment] Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: Use %pe to print error pointers symbolicallySumeet Pawnikar
Replace PTR_ERR() and %ld/%li with %pe and pass the original pointer directly to dev_info(), dev_Warn and dev_dbg(). The %pe format specifier prints a symbolic error name (e.g. -ENOMEM) when CONFIG_SYMBOLIC_ERRNAME is enabled, otherwise it falls back gracefully and prints the raw integer value. This makes messages more readable without any functional change. Signed-off-by: Sumeet Pawnikar <sumeet4linux@gmail.com> Link: https://patch.msgid.link/20260912191156.185448-2-sumeet4linux@gmail.com Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: use tabs in power_supply_get_property_directIván Ezequiel Rodriguez
The return statement was indented with spaces; use tabs to match kernel coding style and silence checkpatch. Signed-off-by: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com> Link: https://patch.msgid.link/20260831155339.181487-6-ivanrwcm25@gmail.com Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: restore hwmon if extension update failsIván Ezequiel Rodriguez
power_supply_update_sysfs_and_hwmon() removes the existing hwmon group before recreating it. If recreation fails, register_extension() rolled back the extension but left hwmon absent. After tearing down the failed extension, best-effort recreate hwmon so the supply keeps its previous monitoring attributes when possible. Signed-off-by: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com> Link: https://patch.msgid.link/20260831155339.181487-3-ivanrwcm25@gmail.com Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: return -ENOMEM on OCV table alloc failureIván Ezequiel Rodriguez
power_supply_get_battery_info() maps a failed kcalloc() for the OCV capacity table to -EINVAL. Return -ENOMEM instead, matching the resistance-temp-table allocation path in the same function. Signed-off-by: Iván Ezequiel Rodriguez <ivanrwcm25@gmail.com> Link: https://patch.msgid.link/20260831155339.181487-2-ivanrwcm25@gmail.com Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: bq257xx: Convert parameters setup to the new .init callbackAlexey Charkov
Switch the battery parsing and hardware initialization from happening inside the probe routine (after the power supply is registered) to the new .init callback which gets run during the registration, thus avoiding the exposure of a not-yet-fully-configured power supply to the rest of the system. Signed-off-by: Alexey Charkov <alchark@flipper.net> Link: https://patch.msgid.link/20260910-bq257xx-init-v3-3-4e219a1a04a5@flipper.net Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: bq257xx: Use psy directly instead of driver dataAlexey Charkov
bq257xx_external_power_changed() is handed the power supply it is called for, but passes pdata->charger to power_supply_am_i_supplied(). Those are not equivalent during probe or teardown, and a supplier's changed_work can reach power_supply_external_power_changed() when pdata->charger doesn't point anywhere meaningful (e.g. freed memory during teardown). Use the psy argument, which is valid whenever the callback runs. Fixes: 1cc017b7f9c7 ("power: supply: bq257xx: Add support for BQ257XX charger") Signed-off-by: Alexey Charkov <alchark@flipper.net> Link: https://patch.msgid.link/20260910-bq257xx-init-v3-2-4e219a1a04a5@flipper.net Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: core: prevent unregistering a power supply while a callback runsAlexey Charkov
Once a power supply is registered, its callbacks can immediately start firing from other contexts, such as external_power_changed() triggered by the TCPM stack. If a power supply is unregistered while the callback is still running, the driver data can already be freed when the callback tries to access it, leading to a use-after-free. This happens e.g. when the hardware bus carrying the power supply device malfunctions (e.g. I2C is hogged down by another malfunctioning device) immediately after the power supply is registered, and thus the core is still processing the callbacks which were queued up when the driver starts the removal, leading in some cases to a kernel crash, e.g.: [ 11.645942] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000005 [ 11.646751] Mem abort info: [ 11.647006] ESR = 0x0000000096000004 [ 11.647338] EC = 0x25: DABT (current EL), IL = 32 bits [ 11.647806] SET = 0, FnV = 0 [ 11.648077] EA = 0, S1PTW = 0 [ 11.648356] FSC = 0x04: level 0 translation fault [ 11.648785] Data abort info: [ 11.649041] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 11.649524] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 11.649981] GCS = 0, Overlay = 0, DirtyBit = 0 [ 11.650390] [0000000000000005] user address but active_mm is swapper [ 11.650955] Internal error: Oops: 0000000096000004 [#1] SMP [ 11.651460] Modules linked in: [ 11.651742] CPU: 1 UID: 0 PID: 144 Comm: kworker/1:2 Not tainted 7.2.0-rc6-g62a9297af2cd #1 PREEMPT [ 11.652553] Hardware name: Flipper One rev. F0B1C2 (DT) [ 11.653024] Workqueue: events power_supply_changed_work [ 11.653511] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 11.654135] pc : __power_supply_is_supplied_by+0x18/0x100 [ 11.654624] lr : __power_supply_am_i_supplied+0x40/0xb8 [ 11.655098] sp : ffff80008192bb30 [ 11.655399] x29: ffff80008192bb30 x28: 0000000000000000 x27: 0000000000000000 [ 11.656049] x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000 [ 11.656695] x23: ffff0000c19f4200 x22: ffffdb2232ba4ea8 x21: ffff80008192bc28 [ 11.657344] x20: ffff0000c1eef000 x19: ffff80008192bc18 x18: 00000000a0886e62 [ 11.657991] x17: 000000040044ffff x16: 04500072b5503510 x15: 0000000000000000 [ 11.658639] x14: 0000000000000000 x13: 0000000000000220 x12: 0000000000000000 [ 11.659286] x11: 0000000000000000 x10: ffff0000c1fdb2b0 x9 : ffffdb2232ba5590 [ 11.659934] x8 : 00000000e5b906e6 x7 : ffff0000c2502778 x6 : ffffdb22339793d0 [ 11.660581] x5 : ffff80008192bc18 x4 : ffff0000c19cbca0 x3 : 0000000000000000 [ 11.661228] x2 : ffff0000c1fdaf40 x1 : ffffffffffffffed x0 : ffff0000c1eef000 [ 11.661878] Call trace: [ 11.662103] __power_supply_is_supplied_by+0x18/0x100 (P) [ 11.662596] __power_supply_am_i_supplied+0x40/0xb8 [ 11.663040] psy_for_each_psy_cb+0x20/0x40 [ 11.663416] class_for_each_device+0x110/0x150 [ 11.663825] power_supply_am_i_supplied+0x68/0x100 [ 11.664262] bq257xx_external_power_changed+0x58/0x140 [ 11.664733] __power_supply_changed_work+0x60/0x80 [ 11.665170] psy_for_each_psy_cb+0x20/0x40 [ 11.665545] class_for_each_device+0x110/0x150 [ 11.665953] power_supply_changed_work+0x98/0x1b8 [ 11.666382] process_one_work+0x164/0x4c0 [ 11.666758] worker_thread+0x19c/0x320 [ 11.667104] kthread+0x138/0x150 [ 11.667408] ret_from_fork+0x10/0x20 [ 11.667744] Code: d503233f a9bd7bfd 910003fd a90153f3 (f9400c34) [ 11.668294] ---[ end trace 0000000000000000 ]--- Add a read-write semaphore between external_power_changed() and power_supply_unregister() to prevent the latter from returning (and thus the driver from freeing its data) while the callback is still running. Fixes: bc1540561c9e ("power_supply: Add API for safe access of power supply function attrs") Signed-off-by: Alexey Charkov <alchark@flipper.net> Link: https://patch.msgid.link/20260910-bq257xx-init-v3-1-4e219a1a04a5@flipper.net Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: ltc2941: Fix of_node reference leak in ltc294x_i2c_probe()Wentao Liang
ltc294x_i2c_probe() takes a reference on the device node with of_node_get(), but never drops it, so the reference leaks on every return path, including the success path. The node is only used to read the battery properties and to set info->supply_desc.name, so release it after its last use and also on the lltc,resistor-sense error path. Fixes: 085bc24d1553 ("Add LTC2941/LTC2943 Battery Gauge Driver") Cc: stable@vger.kernel.org Signed-off-by: Wentao Liang <vulab@iscas.ac.cn> Link: https://patch.msgid.link/20260917142127.2156568-1-vulab@iscas.ac.cn Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: bq27xxx: add support for BQ28Z620Alexey Charkov
Match the BQ28Z620 under its own chip ID so that code touching its relocated data flash can tell it apart from the BQ28Z610. Reuse the BQ28Z610 register map and properties, as the standard commands the driver reads are unchanged. Keep the 10 mW scaling of AveragePower() even though the BQ28Z620 TRM lists it in mW: readings on hardware match V * I only in 10 mW units. Signed-off-by: Alexey Charkov <alchark@flipper.net> Link: https://patch.msgid.link/20261002-bq28z620-v1-2-bdcc10d42519@flipper.net Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: qcom_smbx: Remove const from desc allocation typeKees Cook
In preparation for making the devm_kmalloc family of allocators type aware, we need to make sure that the returned type from the allocation matches the type of the variable being assigned. (Before, the allocator would always return "void *", which can be implicitly cast to any pointer type.) The assigned type is "struct power_supply_desc *", but the converted allocation type would be "const struct power_supply_desc *", as the size was taken from "smb_psy_desc", which is a "static const struct power_supply_desc". As there is no general way to remove const qualifiers, take the size from the assignment target instead. No change in allocation size results. Build tested ARCH=x86_64 allmodconfig with GCC 16.2.0: drivers/power/supply/qcom_smbx.o Assisted-by: LLM coccinelle Signed-off-by: Kees Cook <kees+treewide@kernel.org> Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com> Link: https://patch.msgid.link/20260917211309.i.765-kees@kernel.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: axp20x_usb: Improve probe error reportingUwe Kleine-König
Don't be silent about probe fail issues. Just having axp20x-usb-power-supply in /sys/kernel/debug/devices_deferred without a reason is making it harder than necessary to debug the actual issue. So be a bit more cooperative and add an error message for the typical failure points. Exit paths where the error is -ENOMEM and register write failures are skipped, these should be quite obvious even without a dedicated error message. Signed-off-by: Uwe Kleine-König <ukleinek@debian.org> Reviewed-by: Chen-Yu Tsai <wens@kernel.org> Link: https://patch.msgid.link/b699f8251afed736af454a981630926e45eb7da7.1789983244.git.ukleinek@debian.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: axp20x_usb: Introduce a helper variable for &pdev->devUwe Kleine-König
With the next commit adding several new usages of &pdev->dev, a helper variable is well justified. To not clutter that commit, split out the introduction of the helper out in this separate change to simplify review. Signed-off-by: Uwe Kleine-König <ukleinek@debian.org> Reviewed-by: Chen-Yu Tsai <wens@kernel.org> Link: https://patch.msgid.link/f0e6c7ff8dce9f1a0903d83ff3ef782a18cd63d2.1789983244.git.ukleinek@debian.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: axp20x*: Drop check for disabled devicesUwe Kleine-König
Since commit 6b5c350648b8 ("mfd: mfd-core: Honour Device Tree's request to disable a child-device") the mfd core checks for disabled devices, so there is no use in doing that again in the mfd child driver. Drop the check in the two power drivers. Signed-off-by: Uwe Kleine-König <ukleinek@debian.org> Reviewed-by: Chen-Yu Tsai <wens@kernel.org> Link: https://patch.msgid.link/c17a6c915abdb99612a52d2bb8cff78050f6b0a6.1789983244.git.ukleinek@debian.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: qcom_battmgr: Report capacity on X1E80100Liviu Nicoara
Commit 3f87baacea4d ("power: supply: qcom_battmgr: Report battery capacity") added POWER_SUPPLY_PROP_CAPACITY to the SC8280XP battery properties, computed from the firmware's charge and last-full values. When commit cc3e883a0625 ("power: supply: qcom_battmgr: Add charge control support") later gave X1E80100 a property table of its own, the table was copied without the capacity property, so X1E80100 machines expose energy_now and energy_full but no capacity. The percentage is already computed for this variant in the shared SC8280XP callback; only the property list is missing it. Add it, in the same place it sits in the SC8280XP table. Tested on a Dell XPS 13 9345: capacity reads 94 with energy_now 52640000 and energy_full 55540000. Fixes: cc3e883a0625 ("power: supply: qcom_battmgr: Add charge control support") Signed-off-by: Liviu Nicoara <lnicoara@thinkoid.org> Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com> Link: https://patch.msgid.link/20260920193402.2402-1-lnicoara@thinkoid.org Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: core: Honor supplied-from with CONFIG_OF=yMaurizio Casciano
The supplied-from device property is the name-based counterpart to firmware-node power-supplies references. It was added for non-DT platforms, but its parser is compiled only when CONFIG_OF is disabled. CONFIG_OF is a global kernel option, so x86 systems commonly enable it even when individual power supplies are described by software nodes. Consequently, these consumers never populate supplied_from and supplier notifications do not reach their external_power_changed() callbacks. On a Lenovo Yoga Book YB1-X91L, ftrace showed the Whiskey Cove supplier notification running without invoking the BQ25892 callback, leaving the input current limit at its boot-time value. Use a single power_supply_check_supplies() implementation for all configurations. Preserve firmware-node power-supplies references as the preferred firmware description and use the name-based supplied-from property only when no references are specified. Continue to honor an explicitly provided supplied_from list first and propagate errors from specified firmware references. With the fix, ftrace shows the BQ25892 callback on hotplug. A boot-offline test changes its input current limit from 500 mA to 2 A. Fixes: 58a36bb06891 ("power: supply: core: Add support for supplied-from device-property") Cc: stable@vger.kernel.org Assisted-by: LLM Signed-off-by: Maurizio Casciano <mauriziocasciano7@gmail.com> Link: https://patch.msgid.link/20260924225152.985489-1-mauriziocasciano7@gmail.com Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
5 dayspower: supply: generic-adc-battery: Fix temperature IIO channel conversionSvyatoslav Ryhel
Temperature IIO channel data is provided in milli-degrees, while POWER_SUPPLY_PROP_TEMP is expected to be in deci-degrees. Adjust the existing logic to reflect this conversion properly. Fixes: 33088c0513818 ("power: supply: generic-adc-battery: add temperature support") Signed-off-by: Svyatoslav Ryhel <clamor95@gmail.com> Link: https://patch.msgid.link/20260926142905.206215-2-clamor95@gmail.com Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
6 dayspower: supply: bq24190_charger: don't reset registers across system suspendRyan Brue
bq24190_pm_suspend() calls bq24190_register_reset(), which returns every register to its power-on default, and bq24190_pm_resume() does it again before re-applying the probe-time configuration. On any board that wires the charger's interrupt this makes system suspend unusable. The reset re-arms the chip's 40 s i2c watchdog. bq24190_set_config() turns that watchdog off at probe, deliberately: as the comment there explains, the same write also takes the part out of default mode into host mode. Nothing pets it while the system is asleep, so it expires, resets the registers again and pulses INT. The charger interrupt is a system wake source -- armed unconditionally in probe since commit f385e6e2a153 ("power: bq24190_charger: Use PM runtime autosuspend"), and still enabled by default after the conversion to the wake irq API [1] -- so the pulse wakes the machine. Measured on an MT8173 board (Amazon Fire HD 10 2017, BQ24297) by swapping only this driver between builds with and without this change, asking for a 150 s suspend each time: on charger, with the reset: 41-43 s, 7 runs of 7 on charger, without the reset: 150 s, 3 runs of 3 on battery, with the reset: 40-41 s, 3 runs of 3 on battery, without the reset: 150 s, 3 runs of 3 It is not a charging-only problem. The watchdog runs from VBUS or from the battery, so an unplugged tablet loses suspend in the same way. ftrace names the wake source. Across the resume, the first device interrupt after the machine comes back is the charger: 1270.760799: suspend_resume: machine_suspend[3] end 1270.775683: irq_handler_entry: irq=25 name=bq24190-charger 1270.776156: irq_handler_entry: irq=250 name=11010000.i2c Everything between is IPI and arch_timer from bringing the secondary CPUs back up, and no RTC interrupt appears anywhere in the trace -- the 150 s wake alarm never fired. The cause leaves nothing behind for userspace to find, because WATCHDOG_FAULT is in the latch-on-read fault register and the driver's own interrupt handler has already consumed it. The reset also discards host configuration that nothing restores. Resume calls bq24190_set_config(), which writes only the watchdog, SYS_MIN, IPRECHG, ITERM, ICHG and VREG, so: - IINLIM returns to its power-on default. Boards without a charger-type detector set the input limit from userspace; measured here, one ordinary suspend/resume silently took input_current_limit from 1500 mA to 500 mA, and to 100 mA when running from the battery, where the default differs. - EN_HIZ is cleared, so a charger the host put into high-impedance mode starts drawing from VBUS again the moment the system sleeps. There is no way to have both. Default mode is what the reset is for, and on this part default mode and a disarmed watchdog are mutually exclusive: a write to any register moves the chip into host mode, and it only returns to default mode when the watchdog times out. Parking it in default mode for the sleep therefore always leaves a timer armed that will fire, and on any board that wires INT that firing is a wake. A per-board opt-out would not be choosing between two workable configurations, only between a working suspend and a broken one. Resetting in suspend buys nothing worth this. The part is in host mode with its watchdog off; it charges on its own, switching from constant current to constant voltage and terminating when the battery is full, and nothing in it can expire or change while the host sleeps. Resetting on resume is weaker still: the host is awake and about to reconfigure the chip, so the reset only guarantees the loss. The one thing the reset does guard against is a host that never comes back: a chip in host mode keeps whatever it was last told, where default mode would revert to the power-on values. But that is the state the driver leaves it in for all of normal runtime operation already, so sleep is not special, and the part still makes its own constant-current to constant-voltage transition and terminates when the battery is full. So drop it in both directions. The suspend callback has nothing left to do and goes away. Resume re-applies the probe-time configuration, which is idempotent and also recovers a part that did somehow fall back to default mode, since bq24190_set_config() starts by turning the watchdog off. This has been proposed before. Hans de Goede sent the same change in 2017 [2] and Sebastian Reichel agreed with the reasoning [3], but v6 kept the reset on by default and added the "disable-reset" device property instead [4]. That property cannot answer this: it is set only from x86 platform code -- i2c-cht-wc and x86-android-tablets -- and is not in bq24190.yaml, so no DT board can reach it. Every in-tree DT user of this driver (tegra124-xiaomi-mocha, qcom-msm8974-lge-nexus5-hammerhead, qcom-msm8974pro-oneplus-bacon, rk3188-bqedison2qc) wires the charger interrupt and so has the same wake armed, with no way to opt out. If some board does want the reset, it would be better expressed the other way round. The vendor kernel for this board does not reset across suspend either: its driver, drivers/power/mt81xx/bq24297.c, only masks the charger interrupt on suspend and unmasks it on resume. Reproduced on a BQ24297. The reasoning applies to the family, but the other parts were not available to test. [1] https://lore.kernel.org/all/20260908-rbrue-suez-upstreaming-bq24190_charger-use-wake-irq-api-v1-1-c3f10ae2a34a@gmail.com/ [2] https://lore.kernel.org/all/20170322145536.30570-5-hdegoede@redhat.com/ [3] https://lore.kernel.org/all/20170323112052.ukyazi4pnji7n6st@earth/ [4] https://lore.kernel.org/all/20170414165233.4532-1-hdegoede@redhat.com/ Fixes: d7bf353fd0aa ("bq24190_charger: Add support for TI BQ24190 Battery Charger") Assisted-by: LLM Signed-off-by: Ryan Brue <ryanbrue.dev@gmail.com> Reviewed-by: Hans de Goede <johannes.goede@oss.qualcomm.com> Link: https://patch.msgid.link/20260928-rbrue-suez-upstreaming-bq24190_charger-no-reset-regs-sys-suspend-v1-1-9a7689f12c05@gmail.com Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
9 dayspower: sequencing: pcie-m2: Fix leaking array from of_regulator_bulk_get_all()Alexey Charkov
of_regulator_bulk_get_all() allocates the consumers array and hands it to the caller, who is expected to free it at an appropriate time. pwrseq-pcie-m2.c never did, leading to a memory leak. Add an explicit kfree() for the consumers array. Cc: stable@vger.kernel.org Fixes: 52e7b5bd62ba ("power: sequencing: Add the Power Sequencing driver for the PCIe M.2 connectors") Signed-off-by: Alexey Charkov <alchark@flipper.net> Link: https://patch.msgid.link/20260930-m2-pwrseq-kfree-v1-1-82678b02c126@flipper.net Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-09-22power: sequencing: pcie-m2: Add Lenovo ThinkPad T14s gen6 WCN7850 subsystem ↵Hans de Goede
PCI ids Commit a39ac4651e3b ("power: sequencing: pcie-m2: Match WCN6855 and WCN7851 UART BT variants by subdevice ID") has caused the serdev for the WCN7850 on the Lenovo ThinkPad T14s gen6 WCN7850 no longer getting created. Add a new match using the PCI subdev ids from the T14s gen6 to fix this. Fixes: a39ac4651e3b ("power: sequencing: pcie-m2: Match WCN6855 and WCN7851 UART BT variants by subdevice ID") Signed-off-by: Hans de Goede <johannes.goede@oss.qualcomm.com> Link: https://patch.msgid.link/20260918093838.6645-1-johannes.goede@oss.qualcomm.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-09-21Merge tag 'pwrseq-is-controllable-for-v7.4' of ↵Bartosz Golaszewski
git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux into pwrseq/for-next Add a new core power sequencing consumer functions: pwrseq_is_controllable(). This allows users to check whether the sequencer's target is actually host-controllable.
2026-09-21power: sequencing: qcom-wcn: Report power controllabilityLoic Poulain
The "bluetooth" and "wlan" targets drive the BT_EN and WLAN_EN GPIOs to gate the respective functions. These GPIOs are optional, on some boards they are hardwired to an always-on pull-up and not routed to a host GPIO. In that case the corresponding enable/disable callbacks are no-ops, so the consumer cannot gate or reset that function on its own. Implement the .is_controllable() callback on the "bluetooth" and "wlan" targets so that consumers can query this via the pwrseq API. Reviewed-by: Manivannan Sadhasivam <mani@kernel.org> Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com> Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com> Signed-off-by: Loic Poulain <loic.poulain@oss.qualcomm.com> Link: https://patch.msgid.link/20260904-monza-wireless-v6-5-d8c5042b3efd@oss.qualcomm.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-09-21power: sequencing: pcie-m2: Report power controllabilityLoic Poulain
The M.2 Key E connector gates/resets its functions through the W_DISABLE1# (PCIe/WiFi) and W_DISABLE2# (Bluetooth) signals. When a signal is not routed to a host GPIO, the corresponding enable/disable callbacks are no-ops, so the consumer cannot gate or reset that function on its own. Implement the .is_controllable() callback on the "uart" and "pcie" targets so that consumers can query this per instance (based on the runtime presence of the W_DISABLE2#/W_DISABLE1# GPIOs) via pwrseq_is_controllable(). Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com> Reviewed-by: Manivannan Sadhasivam <mani@kernel.org> Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com> Signed-off-by: Loic Poulain <loic.poulain@oss.qualcomm.com> Link: https://patch.msgid.link/20260904-monza-wireless-v6-4-d8c5042b3efd@oss.qualcomm.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-09-21power: sequencing: Add pwrseq_is_controllable() APILoic Poulain
On some boards a power sequencing target has no host-controllable enable for its function, for instance when the enable line is not wired up to a GPIO and is hardwired to an always-on level. The pcie-m2 "uart" target is one such example: when the M.2 connector does not route the W_DISABLE2# signal to a host GPIO, its enable/disable are no-ops and the consumer cannot gate the Bluetooth function at all or exclusively. Add a generic pwrseq_is_controllable() helper. It reports whether the target's final unit provides a host-controllable dedicated power actuator. The target can implement a new optional is_controllable() callback, reporting whether that actuator is effective on this target (for example depending on GPIO presence). If the target does not provide the callback, it is assumed to be controllable. Note this only describes the target's own enable actuator. It does not imply that a power-off reaches an electrical OFF state, since a target may have multiple consumers. It also does not mean that power is uncontrolled for the target's dependencies: those may still be gated on their own. And it does not restrict consumers from calling pwrseq_power_off() either, which remains valid to drop this consumer's vote on the (possibly shared) resources and dependencies of the target. Reviewed-by: Manivannan Sadhasivam <mani@kernel.org> Acked-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com> Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com> Signed-off-by: Loic Poulain <loic.poulain@oss.qualcomm.com> Link: https://patch.msgid.link/20260904-monza-wireless-v6-3-d8c5042b3efd@oss.qualcomm.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-09-21power: sequencing: add kunit test casesBartosz Golaszewski
Add a set of kunit test-cases for the power sequencing subsystem. Verify several use-cases such as detecting circural dependencies, tracking of the enable-count, shared dependencies, swnode lookup, missing target on matching provider, etc. Link: https://patch.msgid.link/20260909-pwrseq-kunit-v2-4-ef496afc89d2@oss.qualcomm.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
2026-09-21Merge tag 'v7.3-rc4' of ↵Bartosz Golaszewski
git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux into pwrseq/for-next Linux 7.3-rc4
2026-09-17Merge tag 'pwrseq-fixes-for-v7.3-rc4' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux Pull power sequencing fixes from Bartosz Golaszewski: - fix kconfig issue in pwrseq-thread-gpu - fix error path logic in pwrseq_unit_enable() - fix two NULL-pointer dereference bugs in power sequencing core * tag 'pwrseq-fixes-for-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/brgl/linux: power: sequencing: fix NULL-pointer dereference in pwrseq_device_register() power: sequencing: fix NULL-pointer dereference in pwrseq_unit_new() power: sequencing: don't call .post_enable() if pwrseq_unit_enable() failed power: sequencing: Fix build issue with COMPILE_TEST
2026-09-14power: sequencing: fix NULL-pointer dereference in pwrseq_device_register()Bartosz Golaszewski
If dev_set_name() fails in pwrseq_device_register(), we jump to the err_put_pwrseq label before initializing pwrseq->targets. pwrseq_release() will try to iterate over targets unconditionally and subsequently dereference an invalid pointer. Move the call to dev_set_name() after the list head is initialized. Fixes: 249ebf3f65f8 ("power: sequencing: implement the pwrseq core") Cc: stable@vger.kernel.org Reported-by: sashiko-bot <sashiko-bot@kernel.org> Closes: https://sashiko.dev/#/patchset/20260903-pwrseq-kunit-v1-0-1f893d2cabc2%40oss.qualcomm.com?part=2 Link: https://patch.msgid.link/20260909-pwrseq-kunit-v2-3-ef496afc89d2@oss.qualcomm.com Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>