* Re: [PATCH net-next v17 6/6] net: dsa: mxl862xx: document devlink flash and info support
@ 2026-09-25 5:34 netdev-bot+sashiko
0 siblings, 0 replies; 2+ messages in thread
From: netdev-bot+sashiko @ 2026-09-25 5:34 UTC (permalink / raw)
To: daniel
Cc: jiri, davem, edumazet, kuba, pabeni, horms, corbet, skhan,
rdunlap, gregkh, rafael, dakr, andrew, olteanv, linux, netdev,
linux-doc, linux-kernel, driver-core
Thank you for your contribution! Sashiko AI review found more severe
issue(s) in other patches of this series. This mail is only an FYI, in case
you want to address the nit picks below when you respin.
Low priority / nit picks for your consideration:
- [Low] mxl862xx.rst says that "In the rare case that the reprobe cannot
be scheduled at all, ``devlink dev flash`` reports that error and the…
- [Low] The "Rescue lifecycle" overview comment at the top of
drivers/net/dsa/mxl862xx/mxl862xx-fw.c says "devlink dev info exposes…
--
net: dsa: mxl862xx: document devlink flash and info support
This adds Documentation/networking/devlink/mxl862xx.rst. The new file
describes the devlink info versions and how flash update behaves,
including recovery from MCUboot rescue mode. The file is linked from the
devlink index and added to the driver's MAINTAINERS entry.
> diff --git a/Documentation/networking/devlink/mxl862xx.rst b/Documentation/networking/devlink/mxl862xx.rst
> new file mode 100644
> index 0000000000000..793f3521f505f
> --- /dev/null
> +++ b/Documentation/networking/devlink/mxl862xx.rst
> @@ -0,0 +1,91 @@
[ ... ]
> +Flash Update
> +============
> +
> +The ``mxl862xx`` driver implements support for ``devlink dev flash``.
> +The signed firmware image is transferred to the switch over the same
> +MDIO bus which is also used to manage the switch, then verified and
> +installed by the MCUboot bootloader running on the switch. All ports
> +of the switch are closed for the duration of the update and the driver
> +reprobes the switch after it has rebooted into the new firmware; they
> +come back registered but down, so userspace brings them up again. A
> +complete flash and reprobe cycle takes about one minute. In the rare
> +case that the reprobe cannot be scheduled at all, ``devlink dev
> +flash`` reports that error and the driver stays bound to a switch it
> +no longer tracks until it is unbound and rebound. A reboot started
[Severity: Low]
Does this hold on every path through mxl862xx_devlink_flash_update()?
The reprobe scheduling error is only returned and logged when the
transfer succeeded:
drivers/net/dsa/mxl862xx/mxl862xx-fw.c:mxl862xx_devlink_flash_update() {
...
priv->skip_teardown = true;
mutex_unlock(&priv->mdiodev->bus->mdio_lock);
...
err = device_schedule_reprobe(ds->dev, MXL862XX_FW_REPROBE_DELAY_MS);
if (!ret && err)
dev_err(ds->dev,
"flash: new firmware is running but re-probe could not be scheduled (%pe); unbind and rebind to reinitialise\n",
ERR_PTR(err));
return ret ? ret : err;
}
Suppose mxl862xx_flash_firmware() or mxl862xx_wait_ready() failed, and
device_schedule_reprobe() then also returned -ENOMEM or -EINVAL. In that
case the reprobe error is not returned, and the dev_err() that tells the
user to rebind is skipped.
skip_teardown has already been set unconditionally. With no reprobe
pending, nothing clears it. Would every later flash then fail here until
a manual rebind?
if (priv->skip_teardown) {
NL_SET_ERR_MSG_MOD(extack,
"a previous flash awaits its reprobe");
return -EBUSY;
}
The document says -EBUSY only means that a rescue recovery is in
progress. Should the code report the reprobe failure on this path too?
Or should the document mention this -EBUSY and the rebind it needs?
> +while an update is running waits for the transfer to finish, and an
> +update requested after the system has begun shutting down is refused
> +with ``-ENODEV``.
[ ... ]
> +If the driver gives up on the recovery, ``devlink dev flash`` returns
> +``-EIO`` and says so in its extack message. The drain runs once and is
> +never resumed, so a failed MDIO transaction ends it as well. A loader
> +that stops answering the drain needs a power cycle; a completed drain
> +whose reprobe could not be scheduled, and a drain a bus error cut
> +short, need only a driver rebind. The driver re-examines the switch
> +when it binds and at no other time, so a power cycle on a board where
> +the switch can be cycled on its own still has to be followed by an
> +unbind and rebind for the recovered switch to be recognised.
[Severity: Low]
This paragraph documents the -EIO case. The rescue lifecycle comment at
the top of drivers/net/dsa/mxl862xx/mxl862xx-fw.c was added earlier in
this series, and it still says:
* devlink dev info exposes the fw version (the "flashable" signal) only once at
* READY; flash_update returns -EBUSY until then, and reprobes to WSP firmware
* on success.
However, once rescue_failed is set, mxl862xx_devlink_flash_update()
returns -EIO permanently:
if (READ_ONCE(priv->rescue_failed)) {
NL_SET_ERR_MSG_MOD(extack, "download recovery failed");
return -EIO;
}
rescue_failed is set in three cases:
- mxl862xx_rescue_heal_work_fn(), when the drain fails
- mxl862xx_rescue_heal_work_fn(), when the post-drain reprobe cannot be
scheduled
- mxl862xx_rescue_mode_detect(), for an interrupted opening handshake
In each of these cases the loader never reaches READY.
Could that comment be updated to mention the -EIO state, so that it
matches both the code and this document?
> +
> +A download interrupted during its opening handshake, before the image
> +header reached the loader, is reported the same way. The loader waits
> +for a header that no later session can supply, so that state needs a
> +power cycle.
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/cover.1790130482.git.daniel%40makrotopia.org
^ permalink raw reply [flat|nested] 2+ messages in thread
* [PATCH net-next v17 6/6] net: dsa: mxl862xx: document devlink flash and info support
2026-09-23 2:33 [PATCH net-next v17 0/6] net: dsa: mxl862xx: devlink flash and rescue Daniel Golle
@ 2026-09-23 2:36 ` Daniel Golle
0 siblings, 0 replies; 2+ messages in thread
From: Daniel Golle @ 2026-09-23 2:36 UTC (permalink / raw)
To: Jiri Pirko, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Simon Horman, Jonathan Corbet, Shuah Khan,
Randy Dunlap, Daniel Golle, Greg Kroah-Hartman,
Rafael J. Wysocki, Danilo Krummrich, Andrew Lunn,
Vladimir Oltean, Russell King, netdev, linux-doc, linux-kernel,
driver-core
Describe the devlink info versions and the flash update behaviour,
including the MCUboot rescue mode recovery, in a dedicated file under
Documentation/networking/devlink/ and link it from the index. Add the
new file to the driver's MAINTAINERS entry.
Assisted-by: LLM
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
---
v17: no changes
v16:
- document that a reboot waits for a running flash and that one
requested afterwards is refused, and that a bus error ends the
download recovery for good
- title-case the "Flash Update" heading, as the other devlink driver
documents do
- say that the ports come back down from a flash, that a reprobe which
cannot be scheduled needs a rebind, and which of the two recovery
failures needs a power cycle and which a rebind (found by Sashiko AI
review)
v15:
- asic.rev is read from the CHIP ID registers as well, not from one
register word shared with asic.id (found by Sashiko AI review)
- -EIO says the driver gave up on the recovery, which may need a driver
rebind rather than a power cycle, and an interrupted opening
handshake is reported the same way (found by Sashiko AI review)
v14: no changes
v13: no changes
v12: no changes
v11: no changes
v10: document that a switch power cycled on its own needs the driver
unbound and rebound before a failed recovery is re-examined
v9: no changes, picked up Andrew's v5 Reviewed-by
v8:
- asic.id and asic.rev are omitted whenever the part number reads
zero, not only in MCUboot rescue mode (found by Sashiko AI review)
- drop the claim that "0.0.0" marks a switch that never ran firmware;
rescue mode always reports it (found by Sashiko AI review)
- document devlink dev flash as the signal that says whether a
recovery is still running, including the -EIO it returns once the
recovery has failed (found by Sashiko AI review)
v7: no changes
v6: no changes
v5: new patch, splitting the devlink documentation out of the flash
update and rescue mode recovery patches so each keeps to code
(Jakub Kicinski asked for the documentation)
---
Documentation/networking/devlink/index.rst | 1 +
Documentation/networking/devlink/mxl862xx.rst | 91 +++++++++++++++++++
MAINTAINERS | 1 +
3 files changed, 93 insertions(+)
create mode 100644 Documentation/networking/devlink/mxl862xx.rst
diff --git a/Documentation/networking/devlink/index.rst b/Documentation/networking/devlink/index.rst
index 1af780c811ee..53d3ef16d13f 100644
--- a/Documentation/networking/devlink/index.rst
+++ b/Documentation/networking/devlink/index.rst
@@ -95,6 +95,7 @@ parameters, info versions, and other features it supports.
mlx5
mlxsw
mv88e6xxx
+ mxl862xx
netdevsim
nfp
octeontx2
diff --git a/Documentation/networking/devlink/mxl862xx.rst b/Documentation/networking/devlink/mxl862xx.rst
new file mode 100644
index 000000000000..793f3521f505
--- /dev/null
+++ b/Documentation/networking/devlink/mxl862xx.rst
@@ -0,0 +1,91 @@
+.. SPDX-License-Identifier: GPL-2.0
+
+========================
+mxl862xx devlink support
+========================
+
+This document describes the devlink features implemented by the
+``mxl862xx`` device driver.
+
+Info versions
+=============
+
+The ``mxl862xx`` driver reports the following versions
+
+.. list-table:: devlink info versions implemented
+ :widths: 5 5 5 85
+
+ * - Name
+ - Type
+ - Example
+ - Description
+ * - ``asic.id``
+ - fixed
+ - 8628
+ - The chip part number read from the CHIP ID registers. Omitted
+ when the part number reads as zero, which happens for a switch
+ sitting in MCUboot rescue mode (the registers need a running
+ firmware), for an unfused part, and after a failed flash.
+ * - ``asic.rev``
+ - fixed
+ - 0
+ - The chip version, read from the CHIP ID registers as well. Both
+ values are published behind the same check, so it is omitted
+ whenever ``asic.id`` is.
+ * - ``fw``
+ - running, stored
+ - 1.0.70
+ - Version of the firmware running on the switch, reported as both
+ running and stored since the switch boots it from its own flash.
+ It is omitted while no firmware version is known: after a failed
+ flash, and in MCUboot rescue mode while an interrupted download
+ is still being recovered in the background. Once the loader is
+ ready to accept a new image the version appears as "0.0.0",
+ which no released firmware reports, so version-comparing tools
+ offer any available release as an upgrade. Use ``devlink dev
+ flash`` to tell a recovering switch from a ready one, see below;
+ a missing version on its own does not say why.
+
+Flash Update
+============
+
+The ``mxl862xx`` driver implements support for ``devlink dev flash``.
+The signed firmware image is transferred to the switch over the same
+MDIO bus which is also used to manage the switch, then verified and
+installed by the MCUboot bootloader running on the switch. All ports
+of the switch are closed for the duration of the update and the driver
+reprobes the switch after it has rebooted into the new firmware; they
+come back registered but down, so userspace brings them up again. A
+complete flash and reprobe cycle takes about one minute. In the rare
+case that the reprobe cannot be scheduled at all, ``devlink dev
+flash`` reports that error and the driver stays bound to a switch it
+no longer tracks until it is unbound and rebound. A reboot started
+while an update is running waits for the transfer to finish, and an
+update requested after the system has begun shutting down is refused
+with ``-ENODEV``.
+
+A switch stuck in MCUboot rescue mode, e.g. after an interrupted
+update, is registered without user ports. If the previous download was
+interrupted mid-transfer the loader is wedged; the driver drains it
+back to a clean ready state in the background, one byte at a time,
+which takes tens of minutes for a large image and is reported through
+the kernel log as it progresses. During that recovery ``devlink dev
+flash`` returns ``-EBUSY`` with an extack message saying so, and
+``devlink dev info`` reports no firmware version. Once the loader is
+ready the firmware version appears and flashing a firmware image
+through the regular update flow recovers the switch.
+
+If the driver gives up on the recovery, ``devlink dev flash`` returns
+``-EIO`` and says so in its extack message. The drain runs once and is
+never resumed, so a failed MDIO transaction ends it as well. A loader
+that stops answering the drain needs a power cycle; a completed drain
+whose reprobe could not be scheduled, and a drain a bus error cut
+short, need only a driver rebind. The driver re-examines the switch
+when it binds and at no other time, so a power cycle on a board where
+the switch can be cycled on its own still has to be followed by an
+unbind and rebind for the recovered switch to be recognised.
+
+A download interrupted during its opening handshake, before the image
+header reached the loader, is reported the same way. The loader waits
+for a header that no later session can supply, so that state needs a
+power cycle.
diff --git a/MAINTAINERS b/MAINTAINERS
index e3ce77c839b0..db2b36581067 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS
@@ -16248,6 +16248,7 @@ M: Daniel Golle <daniel@makrotopia.org>
L: netdev@vger.kernel.org
S: Maintained
F: Documentation/devicetree/bindings/net/dsa/maxlinear,mxl862xx.yaml
+F: Documentation/networking/devlink/mxl862xx.rst
F: drivers/net/dsa/mxl862xx/
F: net/dsa/tag_mxl862xx.c
--
2.55.0
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-25 5:34 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-25 5:34 [PATCH net-next v17 6/6] net: dsa: mxl862xx: document devlink flash and info support netdev-bot+sashiko
-- strict thread matches above, loose matches on Subject: below --
2026-09-23 2:33 [PATCH net-next v17 0/6] net: dsa: mxl862xx: devlink flash and rescue Daniel Golle
2026-09-23 2:36 ` [PATCH net-next v17 6/6] net: dsa: mxl862xx: document devlink flash and info support Daniel Golle
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®