From 13aa36a5a62eb2490a8bfdf18c356425cc5ad5df Mon Sep 17 00:00:00 2001 From: Hubert Wyrzykiewicz Date: Sat, 5 Sep 2026 17:06:21 +0200 Subject: [PATCH 1/2] MIPS: PS2: IOP: Fix iop_write{b,w,l}() issuing the LOADFILE read RPC iop_rpc_write() sends its { addr, type, data } argument with rpo_get_addr (3) instead of rpo_set_addr (2). LOADFILE therefore performs a read at addr, discards data, and returns the current value, which iop_rpc_write() passes on as a non-negative "status". Every caller that tests for err < 0 sees success while nothing has been written. Measured on an SCPH-30004 (ROM 0150) by replaying the exp_dev_init() sequence from iop-dev9.c through iop_writel()/iop_writew() and reading the registers back over the SIF: with rpo_get_addr all writes "succeed" and the SSBUS registers 0x1418/0x141c/0x1420 keep their reset values 000000ff/001a1055/000510ff and DEV9 power stays 0000; with rpo_set_addr the same sequence reads back e01a3043/ef1a3043/00051011 and DEV9 power becomes 0005, the expansion bay powers up and the SPEED chip answers. Nothing in the tree besides the dead code in iop_dev9_init() calls the write helpers yet, which is why this went unnoticed. Fixes: 2e3a8389d92a ("FIXME: iop_read[bwl] and iop_write[bwl]") Co-Authored-By: Claude Fable 5.1 Signed-off-by: Hubert Wyrzykiewicz --- drivers/ps2/iop-module-request.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/ps2/iop-module-request.c b/drivers/ps2/iop-module-request.c index 9f246d051fb7ab..83e758722bb77a 100644 --- a/drivers/ps2/iop-module-request.c +++ b/drivers/ps2/iop-module-request.c @@ -932,7 +932,7 @@ static int iop_rpc_write(const u32 data, s32 status; int err; - err = sif_rpc(&load_file_rpc_client, rpo_get_addr, + err = sif_rpc(&load_file_rpc_client, rpo_set_addr, &arg, sizeof(arg), &status, sizeof(status)); return err < 0 ? err : status; From 7ed4ab540a12b5335b5e95cce0882c32b6ff9a51 Mon Sep 17 00:00:00 2001 From: Hubert Wyrzykiewicz Date: Sat, 5 Sep 2026 17:06:22 +0200 Subject: [PATCH 2/2] MIPS: PS2: IOP: Actually initialise the DEV9 expansion bay iop_dev9_init() returns right after iop_module_request("dev9", ...), leaving exp_dev_init() -- the SSBUS setup, bay power-up and reset -- as dead code. The expansion bay therefore stays unpowered and the SPEED chip (ATA and SMAP Ethernet) is unreachable: a read of its registers from the EE at 0xb4000000 raises a data bus error. Remove the early return so the module does what it was written to do. Together with the iop_rpc_write() fix this brings the bay up at module load. Measured on an SCPH-30004 (ROM 0150): DEV9 power register 0000 -> 0005, SPEED rev1 0011 rev3 0003 rev8 0002, EMAC3 soft reset completes, PHY DP83846 rev 3 answers on MII address 1 and reports link up at 100 Mbit full duplex with a cable plugged in and link down without, the MAC address reads from the serial EEPROM with a matching checksum, and the EE can read the SPEED registers directly once the bay is powered. Co-Authored-By: Claude Fable 5.1 Signed-off-by: Hubert Wyrzykiewicz --- drivers/ps2/iop-dev9.c | 2 -- 1 file changed, 2 deletions(-) diff --git a/drivers/ps2/iop-dev9.c b/drivers/ps2/iop-dev9.c index a91cdd97023e54..dbebed60ef0e33 100644 --- a/drivers/ps2/iop-dev9.c +++ b/drivers/ps2/iop-dev9.c @@ -252,8 +252,6 @@ static int __init iop_dev9_init(void) if (err < 0) return err; - return 0; - err = iop_dev9_read_rev(&dev9.rev); if (err < 0) { printk("iop_dev9_init: err %d\n", err);