[PATCH 3/5] i3c: master: Do not release the addresses when reattach fails

Adrian Hunter adrian.hunter at intel.com
Tue Aug 4 10:56:43 PDT 2026


On 04/08/2026 13:12, Akhil R wrote:
> i3c_master_reattach_i3c_dev_locked() releases the address slots of the
> device when the controller callback fails, even though the target keeps
> responding to its dynamic address on the bus.
> 
> i3c_master_early_i3c_dev_add() cannot take that address back afterwards.
> It jumps to err_rstdaa to reset the target, but i3c_master_rstdaa_locked()
> only accepts an address that is marked as assigned. It rejects the request
> with -EINVAL and sends no CCC, leaving the target responding to an address
> that the core considers free and hands out during dynamic address
> assignment.
> 
> i3c_master_reconcile_dyn_addrs() ignores the return value, so the device

i3c_master_reconcile_dyn_addrs() doesn't call i3c_master_reattach_i3c_dev_locked()
but __i3c_master_add_i3c_dev_locked() does.

> stays attached and in the bus list at the address that SETNEWDA just
> assigned to it, while the core is free to give the same address to another
> device.
> 
> Leave the address slots to the callers. Those that cannot use the device
> any longer detach it, which releases the slots in
> i3c_master_detach_i3c_dev().
> 
> No in-tree controller fails its ->reattach_i3c_dev callback today, so
> there is no known trigger for this. It is a robustness fix for the error
> path only.
> 
> Fixes: 3a379bbcea0a ("i3c: Add core I3C infrastructure")
> Reported-by: Sashiko AI review <sashiko-bot at kernel.org>
> Closes: https://lore.kernel.org/all/20260721043058.C02B31F000E9@smtp.kernel.org/
> Assisted-by: Cursor:claude-opus-5
> Signed-off-by: Akhil R <akhilrajeev at nvidia.com>
> ---
>  drivers/i3c/master.c | 4 +---
>  1 file changed, 1 insertion(+), 3 deletions(-)
> 
> diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c
> index 568788e4cdb5..23557ca2df68 100644
> --- a/drivers/i3c/master.c
> +++ b/drivers/i3c/master.c
> @@ -1944,10 +1944,8 @@ int i3c_master_reattach_i3c_dev_locked(struct i3c_dev_desc *dev,
>  
>  	if (master->ops->reattach_i3c_dev) {
>  		ret = master->ops->reattach_i3c_dev(dev, old_dyn_addr);
> -		if (ret) {
> -			i3c_master_put_i3c_addrs(dev);
> +		if (ret)
>  			return ret;
> -		}
>  	}

That becomes just:

	if (master->ops->reattach_i3c_dev)
		return master->ops->reattach_i3c_dev(dev, old_dyn_addr);

and 'ret' goes away.

>  
>  	return 0;




More information about the linux-i3c mailing list