[PATCH V3] drivers/mtd: rawnand: nandsim: Fix stale NAND_ROW_ADDR_3 with overridesize
wang wei
a929244872 at 163.com
Thu Oct 1 19:47:09 PDT 2026
The overridesize module parameter changes the size of the simulated
device after nand_scan() has completed. It updates nsmtd->size,
memorg->eraseblocks_per_lun, chip->chip_shift and chip->pagemask to
match the new geometry, but leaves the NAND_ROW_ADDR_3 option
untouched, even though nand_scan_ident() set it from the geometry
decoded out of the ID bytes.
When the ID bytes describe a device larger than 128 MiB and
overridesize shrinks the simulation to 128 MiB or less, the stale
option makes the core emit one extra row address byte (page >> 16,
always zero given the reduced page count) in every read, program and
erase operation, while the simulator state machine expects one byte
less. All accesses then fail with:
nandsim: error: write_byte: address (0x0) isn't expected, expected
state is STATE_CMD_READSTART, switch to STATE_READY
The opposite direction is equally broken: growing a small device past
128 MiB keeps NAND_ROW_ADDR_3 cleared, so the third row address byte
is dropped and the wrong pages are silently addressed.
This used to work before commit 14157f861437 ("mtd: nand: introduce
NAND_ROW_ADDR_3 flag"). Back then nandsim kept chip->chipsize in sync
with the override, and nand_command_lp() decided at run time, per
command, whether the third row address cycle was needed by testing
chip->chipsize against 128 MiB. This code thus always saw the
overridden size. The above commit moved the decision to
nand_scan_ident(), which encodes it once into NAND_ROW_ADDR_3 at
scan time -- before nandsim applies the override -- and the
overridesize path was never taught to re-evaluate the flag.
Re-evaluate NAND_ROW_ADDR_3 right after overriding chip_shift, using
the same test as nand_scan_ident().
The core encodes the third row address cycle as "the row address is
wider than 16 bits", ie. more than 65536 pages, regardless of the
page size. ns_init() however derives its expectation from the total
size with a hardcoded 128 MiB threshold, which is only equivalent
for 2 KiB-page devices. For 4 KiB-page devices between 128 MiB and
256 MiB (32768 < pgnum <= 65536) the row address still fits in two
bytes, so the core drops the third byte while ns_init() keeps
expecting it. Fix ns_init() to derive the row address width from the
page count as well, which also matches the small-page branch (32 MiB
of 512-byte pages is exactly 65536 pages).
Fixes: 14157f861437 ("mtd: nand: introduce NAND_ROW_ADDR_3 flag")
Cc: stable at vger.kernel.org
Signed-off-by: wang wei <a929244872 at 163.com>
---
Changes in v3:
- Drop the comment block on the flag re-evaluation.
- Also derive ns_init()'s pgaddrbytes/secaddrbytes from the page
count instead of the hardcoded 128 MiB threshold: re-evaluating
the flag alone would regress 4 KiB-page devices overridden into
the 128-256 MiB range, where the stale flag used to match
ns_init()'s (incorrect) 5-byte expectation serendipitously.
Reported by reviewer.
Changes in v2:
Remove unnecessary comments
---
drivers/mtd/nand/raw/nandsim.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/mtd/nand/raw/nandsim.c b/drivers/mtd/nand/raw/nandsim.c
index fe96803..90dbb93 100644
--- a/drivers/mtd/nand/raw/nandsim.c
+++ b/drivers/mtd/nand/raw/nandsim.c
@@ -686,7 +686,7 @@ static int __init ns_init(struct mtd_info *mtd)
ns->geom.secaddrbytes = 3;
}
} else {
- if (ns->geom.totsz <= (128 << 20)) {
+ if (ns->geom.pgnum <= (1 << 16)) {
ns->geom.pgaddrbytes = 4;
ns->geom.secaddrbytes = 2;
} else {
@@ -2359,6 +2359,11 @@ static int __init ns_init_module(void)
targetsize = nanddev_target_size(&chip->base);
chip->chip_shift = ffs(nsmtd->erasesize) + overridesize - 1;
chip->pagemask = (targetsize >> chip->page_shift) - 1;
+
+ if (chip->chip_shift - chip->page_shift > 16)
+ chip->options |= NAND_ROW_ADDR_3;
+ else
+ chip->options &= ~NAND_ROW_ADDR_3;
}
ret = ns_setup_wear_reporting(nsmtd);
--
2.55.0.windows.3
More information about the linux-mtd
mailing list