[PATCH v7 9/9] serial: max310x: don't transmit while an RS485 reconfigure is pending
From: Tapio Reijonen
Date: Mon Oct 05 2026 - 09:24:16 EST
TIOCSRS485 applies its register changes asynchronously: rs485_config()
stores the new configuration and schedules rs_work, which programs
HDPIXDELAY, MODE1.TRNSCVCTRL and the RTS path. A write() issued right
after the ioctl therefore transmits against the old, half-switched
state. On a single core the ordering is even deterministic: start_tx()
picks the stale path first, then rs_work reprograms the chip, then
tx_work pumps the data - with the transceiver already released. A
TIOCSRS485 switching from the hardware to the software RTS path
followed immediately by a write puts the whole transfer on the wire
with the transceiver disabled: nothing reaches the bus and no error is
reported anywhere. The inverse direction is as old as the asynchronous
reconfigure itself: enabling RS485 and writing immediately shifts the
first bytes out before rs_work has enabled the chip's auto-RTS.
Defer instead: rs485_config() marks the reconfigure pending under
port->lock, start_tx() leaves the data in the kfifo while the mark is
set, and rs_work restarts the transmission itself once the new
configuration is fully applied. The rs485-disable path's direct
tx_work kick is replaced by the same mechanism, which also orders that
flush after the reconfigure instead of before it.
The restart kick also checks port->x_char: uart_send_xchar() reaches
start_tx() too, and a lone x_char deferred by the pending gate leaves
the kfifo empty, so the kick would otherwise skip it and nothing else
would ever send it - an idle chip FIFO raises no TXEMPTY interrupt.
And start_tx() re-checks the pending mark after the
hrtimer_try_to_cancel(-1) path retakes the dropped lock, mirroring the
tx_teardown re-check there: a TIOCSRS485 posted inside that window
would otherwise let the transmission proceed on the stale path.
rs_work takes port->lock for that restart through
uart_port_lock_irqsave(): start_tx() may drop and retake the lock
through the uart_port API on its hrtimer_try_to_cancel(-1) path, and a
raw spinlock guard around the call would unbalance the nbcon console
handling underneath.
The restart also rewinds a send state adopted for the deferred write
itself: set_rts_ctl_params() cannot tell data the pending gate
deferred apart from an in-flight transfer's refill by the xmit buffer
alone, and a deferred write pumped in the adopted send phase would
skip the configured before-send delay. With the chip FIFO empty the
adopted state can only be the deferred write: rewind it and let the
restart run the full envelope.
Fixes: 5bdb48b501e8 ("serial: max310x: Fix RS485 handling")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Tapio Reijonen <tapio.reijonen@xxxxxxxxxxx>
---
drivers/tty/serial/max310x.c | 51 ++++++++++++++++++++++++++++++++++++--------
1 file changed, 42 insertions(+), 9 deletions(-)
diff --git a/drivers/tty/serial/max310x.c b/drivers/tty/serial/max310x.c
index 5fdb9dfca6027ff0a9284ed994000a5d7587408c..833ab4d461235d89438b1a7c84c46609fff64453 100644
--- a/drivers/tty/serial/max310x.c
+++ b/drivers/tty/serial/max310x.c
@@ -319,6 +319,7 @@ struct max310x_one {
bool sw_rts_during_tx;
bool cancel_tx_delay_tmr;
bool tx_teardown; /* envelope being torn down */
+ bool rs485_pending; /* rs_work not yet applied */
bool tx_break; /* break_ctl() owns the transceiver */
enum max310x_tx_state tx_state;
@@ -979,6 +980,16 @@ static void max310x_start_tx(struct uart_port *port)
if (one->tx_teardown)
return;
+ /*
+ * An RS485 reconfigure is scheduled but not applied yet: transmitting
+ * now would use the old path against half-programmed registers - a
+ * TIOCSRS485 switching paths followed immediately by a write puts the
+ * data on the wire with the transceiver released. Leave the data in
+ * the kfifo; rs_work restarts TX once the configuration is applied.
+ */
+ if (one->rs485_pending)
+ return;
+
if (READ_ONCE(one->sw_rts_during_tx)) {
/*
* The before- and after-send phases share one delay timer. If an
@@ -997,9 +1008,10 @@ static void max310x_start_tx(struct uart_port *port)
uart_port_lock(port);
/*
* The lock was dropped: a teardown may have run to
- * completion meanwhile. Re-check before starting.
+ * completion or a reconfigure may have been posted
+ * meanwhile. Re-check before starting.
*/
- if (one->tx_teardown)
+ if (one->tx_teardown || one->rs485_pending)
return;
}
@@ -1445,6 +1457,8 @@ static void max310x_rs_proc(struct work_struct *ws)
{
struct max310x_one *one = container_of(ws, struct max310x_one, rs_work);
unsigned int mode2 = 0;
+ unsigned long flags;
+ bool chip_tx_empty;
/*
* Serialize against break_ctl() and set_termios(), which run under
@@ -1465,6 +1479,31 @@ static void max310x_rs_proc(struct work_struct *ws)
max310x_port_update(&one->port, MAX310X_MODE2_REG,
MAX310X_MODE2_ECHOSUPR_BIT, mode2);
+
+ /*
+ * The configuration is applied: release any TX that start_tx()
+ * deferred while the reconfigure was pending, now on the right
+ * path. start_tx() can drop and retake the lock through the
+ * uart_port API - a raw spinlock guard here would unbalance it.
+ */
+ chip_tx_empty = !max310x_port_read(&one->port,
+ MAX310X_TXFIFOLVL_REG);
+
+ uart_port_lock_irqsave(&one->port, &flags);
+ one->rs485_pending = false;
+ if (one->port.x_char ||
+ !kfifo_is_empty(&one->port.state->port.xmit_fifo)) {
+ /*
+ * A send state adopted without chip data is the deferred
+ * write itself: restart it as a fresh envelope so the
+ * before-send delay is honoured.
+ */
+ if (chip_tx_empty &&
+ READ_ONCE(one->tx_state) == MAX310X_TX_SEND)
+ WRITE_ONCE(one->tx_state, MAX310X_TX_OFF);
+ max310x_start_tx(&one->port);
+ }
+ uart_port_unlock_irqrestore(&one->port, flags);
}
/* called with port.lock taken and irqs off */
@@ -1490,17 +1529,11 @@ static int max310x_rs485_config(struct uart_port *port, struct ktermios *termios
}
WRITE_ONCE(one->tx_state, MAX310X_TX_OFF);
one->tx_teardown = false;
- /*
- * The port stays alive, and a write that raced the teardown
- * may have left data queued with no envelope left to pump it.
- * Kick tx_work; RS485 is disabled, so the plain path is right.
- */
- if (!kfifo_is_empty(&port->state->port.xmit_fifo))
- schedule_work(&one->tx_work);
}
port->rs485 = *rs485;
+ one->rs485_pending = true;
schedule_work(&one->rs_work);
return 0;
--
2.47.3