From nobody Sat Sep 26 19:59:29 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1789969676; cv=none; d=zohomail.com; s=zohoarc; b=FgBu8ZDLiFkBGsWlk3dYlhmWIgRoLOiKy7KEohQw9cPk+KUD92dCrmETV9zm8Ida6iTLD/tGkxT+/rxB0dhtFlrOXl/bkb6qsoD9XLK/YS99M6RoEdIbMU+eRwjyV2ds6QOvZit/xesK5C/KMd/DBc/LDuqeJ/NEK9vP94v4Ggg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789969676; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=AHQZqXzgXj84j+YmD2SLsQ1eOJXsVx86D8rUJRf1/uA=; b=gzZ5Lq0kokb4meOWFLRp2RANWuNHoT2OwUsxxroKEU0DCsNxFo9MNEzPoDBVgInSgIbEYxfWlYjvkfPxutO4HEydM0pUC+sNP0PhRi2mEel4HViCZRk17n/+0tWIkfSrD8PFgZ1DN4ByHOG0rXdEZHaFo45MAxLiJY5EuIYjwXI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789969676030539.3852306661186; Sun, 20 Sep 2026 22:47:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x8Wri-0000sH-6X; Mon, 21 Sep 2026 01:46:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x8WrX-0000r2-RM; Mon, 21 Sep 2026 01:46:48 -0400 Received: from mgamail.intel.com ([192.198.163.12]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x8WrW-000307-4N; Mon, 21 Sep 2026 01:46:47 -0400 Received: from fmviesa013.fm.intel.com ([10.60.135.153]) by fmvoesa106.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 20 Sep 2026 22:46:43 -0700 Received: from junjie-desk-dev.bj.intel.com ([10.238.152.71]) by smtpauth.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 20 Sep 2026 22:46:41 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1789969606; x=1821505606; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=xCSUpaggvBwRUFlLr6UpPDjFdEpyrwriyO0y25l3RsM=; b=iqqY86crmT0G/tCJQ2xZS3kEt2HjxYRP712cp83Md0IpHF9dRzOVM4OH HzWaBdUgKxqoqOEwOjUAi6O/N/qxZGGVPV5L4VBp3QMao2ZuI1KOfmRin 6fyVVYBdEyLnEw1bb6y4Gwc1oegPZ8JByBTmLLQIZ+Lf8dDdN7E2IqDtI MZS4iKx8C8eEdpbeiNxfzJSUT3u2rm0wQKo1duxroXZK4xF5EpWujc+ZA jwOzc6qidlcls6lFTNkIMcTiEzidBj+GzARhMo3K128tpfbVPSAa9epr0 ZOAsEN02gCtJyvTi2lFR5xniWP0EL90hXtQ5H06hukDD/JUsT71BVCuSz g==; X-CSE-ConnectionGUID: IQxkWYg8TJe6Vtyl2QfYsQ== X-CSE-MsgGUID: s0ITQ2FyRzy8anVPHJ+epQ== X-IronPort-AV: E=McAfee;i="6800,10657,11911"; a="94287027" X-IronPort-AV: E=Sophos;i="6.27,114,1787036400"; d="scan'208";a="94287027" X-CSE-ConnectionGUID: lMRAczBoSr60I0zEPk8i4g== X-CSE-MsgGUID: FmVE5xMaSuKafZH7WPUbDg== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.27,114,1787036400"; d="scan'208";a="3815191" From: Junjie Cao To: qemu-devel@nongnu.org Cc: Thomas Huth , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Gerd Hoffmann , Fabiano Rosas , Laurent Vivier , Paolo Bonzini , Nicholas Piggin , Feifan Qian , qemu-stable@nongnu.org Subject: [PATCH 1/4] hw/usb/hcd-xhci: fix interval alignment after MFINDEX passes 2^32 Date: Mon, 21 Sep 2026 13:46:29 +0800 Message-ID: <52c9f935428f2cfc65e4dee7e37638fcb965c6b2.1789968699.git.junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.12; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1789969679663158500 Content-Type: text/plain; charset="utf-8" epctx->interval is an unsigned int, so ~(epctx->interval - 1) is a 32-bit mask that is zero-extended when and-ed with the 64-bit microframe index. Once mfindex no longer fits in 32 bits (2^32 * 125us, about 6.2 days after the controller was started), asap loses its upper half and always compares below mfindex. Isoch TDs with SIA are then run at once instead of at the next interval boundary. xhci_calc_intr_kick() has the same expression. Use ROUND_UP(), which builds the mask in the type of mfindex. The interval is always a power of two. The reporter of #3973 also saw the symptom with UHCI. This change does not explain that. Fixes: 3d1396842d ("xhci: iso xfer support") Fixes: 4d7a81c06f ("xhci: emulate intr endpoint intervals correctly") Link: https://gitlab.com/qemu-project/qemu/-/issues/3973 Cc: qemu-stable@nongnu.org Signed-off-by: Junjie Cao Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- hw/usb/hcd-xhci.c | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/hw/usb/hcd-xhci.c b/hw/usb/hcd-xhci.c index d342aa2739..ce042e74bd 100644 --- a/hw/usb/hcd-xhci.c +++ b/hw/usb/hcd-xhci.c @@ -1742,8 +1742,7 @@ static int xhci_fire_ctl_transfer(XHCIState *xhci, XH= CITransfer *xfer) static void xhci_calc_intr_kick(XHCIState *xhci, XHCITransfer *xfer, XHCIEPContext *epctx, uint64_t mfindex) { - uint64_t asap =3D ((mfindex + epctx->interval - 1) & - ~(epctx->interval-1)); + uint64_t asap =3D ROUND_UP(mfindex, epctx->interval); uint64_t kick =3D epctx->mfindex_last + epctx->interval; =20 assert(epctx->interval !=3D 0); @@ -1754,8 +1753,7 @@ static void xhci_calc_iso_kick(XHCIState *xhci, XHCIT= ransfer *xfer, XHCIEPContext *epctx, uint64_t mfindex) { if (xfer->trbs[0].control & TRB_TR_SIA) { - uint64_t asap =3D ((mfindex + epctx->interval - 1) & - ~(epctx->interval-1)); + uint64_t asap =3D ROUND_UP(mfindex, epctx->interval); if (asap >=3D epctx->mfindex_last && asap <=3D epctx->mfindex_last + epctx->interval * 4) { xfer->mfindex_kick =3D epctx->mfindex_last + epctx->interval; --=20 2.43.0 From nobody Sat Sep 26 19:59:29 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1789969681; cv=none; d=zohomail.com; s=zohoarc; b=jXWrK6dA414EBTmG78Bk2SaONmhHsneO5YpP6bI7q04TzVevCdtYdyAIYOqEOEWMXzMj1t6YxhjlYKCccavQnu/8pu2E+cdPk+vX6dp82QYZGYwDrY7beUwgyu+N3Ll0jlFGGX49tP3hRcAinOZBhJCeYICqbvcGEr9txAKVD/4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789969681; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rPWkg1tYwp+leYWsMcGPsArLZJ+tMUbG2f3Gd9GU0cw=; b=jL933IjAxr6f9qSCyewI5VS3wHDQgnuhPd1Q34YfzsrWoTA7XqVfEjTOqfGOpuwJK3Qa/1yxDmGNhWPHEvWkKfMkRuZzloNjXmEKWpA4Le3kX4mVcQ1d+H5s0zBw9O6rOZ9ZU7wwJHraD55a0Y1N4rBGPueWlWvF+ccux8METCU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789969681968954.7660934072577; Sun, 20 Sep 2026 22:48:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x8Wrk-0000sp-Bz; Mon, 21 Sep 2026 01:47:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x8WrZ-0000rJ-3X; Mon, 21 Sep 2026 01:46:51 -0400 Received: from mgamail.intel.com ([192.198.163.12]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x8WrX-000300-DY; Mon, 21 Sep 2026 01:46:48 -0400 Received: from fmviesa013.fm.intel.com ([10.60.135.153]) by fmvoesa106.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 20 Sep 2026 22:46:46 -0700 Received: from junjie-desk-dev.bj.intel.com ([10.238.152.71]) by smtpauth.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 20 Sep 2026 22:46:44 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1789969607; x=1821505607; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=WwFnVAWQhsH1iFCpZolWcz8dYoU5erTKAAmttsMHl3o=; b=ehNaQdGwX18/oBtAfN3rsdficm/yd6PvUOTeRb3aUNAViOpMhraUf3uX UpolN8Q4t3fkdbicD40uTqhfrbHRhiSX0zMoKi53PSLPAcBmqFPGFjBT0 LKy9fasIgVBaRUWGzYQh+rixUm/eoynDT0RA0meEd5i5Jz1tJYCmlUwzN Xt1sL9rMnXZuCv/UcLZ1GOUNomNH0M2vJhp59c/v1ICtbJYlvLrB9mKTq DlxTDRkrGKSTV6NWgLEaLYG/JRtVNWdikk9CIjlLVTQ93yIpTp+yPE5Rp RCgwtvKCCRIyqd4ATB9LWjASGWmOCn0btklcBsk4fs00KcxvlKJAcdGt0 w==; X-CSE-ConnectionGUID: LV1a2rt3TUqJJDS4AXRnJg== X-CSE-MsgGUID: gUhyeXTVQ/qdf49ujBHmOQ== X-IronPort-AV: E=McAfee;i="6800,10657,11911"; a="94287038" X-IronPort-AV: E=Sophos;i="6.27,114,1787036400"; d="scan'208";a="94287038" X-CSE-ConnectionGUID: uPelgDRBQfC42ikuRGA4jg== X-CSE-MsgGUID: cWrc4d0gS0uONYxG9oQnYw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.27,114,1787036400"; d="scan'208";a="3815204" From: Junjie Cao To: qemu-devel@nongnu.org Cc: Thomas Huth , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Gerd Hoffmann , Fabiano Rosas , Laurent Vivier , Paolo Bonzini , Nicholas Piggin , Feifan Qian , qemu-stable@nongnu.org Subject: [PATCH 2/4] hw/usb/hcd-xhci: don't assert on NAK when retrying an isoch transfer Date: Mon, 21 Sep 2026 13:46:30 +0800 Message-ID: <44227b05b22064a22f4c135e025ff0b1d838b9e3.1789968699.git.junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.12; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1789969682968158500 Content-Type: text/plain; charset="utf-8" The endpoint type in the xHCI endpoint context comes from the guest and is not checked against the device. A guest can configure the interrupt IN endpoint of usb-kbd as Isoch IN. The idle HID endpoint NAKs, and as soon as the transfer goes through the retry path in xhci_kick_epctx() it hits assert(xfer->packet.status !=3D USB_RET_NAK); No device model NAKs on an isoch endpoint, so this only triggers with a mismatched endpoint type. The two retry branches differ only in what they do on NAK: the isoch one asserts, the other keeps the transfer pending. Merge them. Fixes: 3d1396842d ("xhci: iso xfer support") Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3886 Reported-by: Feifan Qian Cc: qemu-stable@nongnu.org Signed-off-by: Junjie Cao Reviewed-by: Thomas Huth --- hw/usb/hcd-xhci.c | 27 ++++++++------------------- 1 file changed, 8 insertions(+), 19 deletions(-) diff --git a/hw/usb/hcd-xhci.c b/hw/usb/hcd-xhci.c index ce042e74bd..6cd5ac87b8 100644 --- a/hw/usb/hcd-xhci.c +++ b/hw/usb/hcd-xhci.c @@ -1912,26 +1912,15 @@ static void xhci_kick_epctx(XHCIEPContext *epctx, u= nsigned int streamid) xfer->timed_xfer =3D 0; xfer->running_retry =3D 1; } - if (xfer->iso_xfer) { - /* retry iso transfer */ - if (xhci_setup_packet(xfer) < 0) { - return; - } - usb_handle_packet(xfer->packet.ep->dev, &xfer->packet); - assert(xfer->packet.status !=3D USB_RET_NAK); - xhci_try_complete_packet(xfer); - } else { - /* retry nak'ed transfer */ - if (xhci_setup_packet(xfer) < 0) { - return; - } - usb_handle_packet(xfer->packet.ep->dev, &xfer->packet); - if (xfer->packet.status =3D=3D USB_RET_NAK) { - xhci_xfer_unmap(xfer); - return; - } - xhci_try_complete_packet(xfer); + if (xhci_setup_packet(xfer) < 0) { + return; + } + usb_handle_packet(xfer->packet.ep->dev, &xfer->packet); + if (xfer->packet.status =3D=3D USB_RET_NAK) { + xhci_xfer_unmap(xfer); + return; } + xhci_try_complete_packet(xfer); assert(!xfer->running_retry); if (xfer->complete) { /* update ring dequeue ptr */ --=20 2.43.0 From nobody Sat Sep 26 19:59:29 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1789969676; cv=none; d=zohomail.com; s=zohoarc; b=l/cHsLKB89wSnAUlsZgk5jBKoKJgLwleLYYdeJbO0k+VwcsASTa0ouDojlJLWIY1v4dYu3mGbd0wyPPT/44itwepUkAXQqouydGNJRyiVhMeg0pAsn7ue8VG7QGTVJePb9fGWkfKV/oh4zj0+MZQvhyMKrkHccYKSQxD2yT5AvA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789969676; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=FCjBPNYAIfVvgp0FZnGJKxo0yHC2ZMRsJIE0OW21cCk=; b=NYFSmlbjf6nK9PUqqqG81PkUML9RW56TjrzmlF4i3zdb39WHX/NxGd0KDazOLLAGZs8sp+J5Hdarpkl28DxEnfn2xW+IE2CutGhm18vXZRBoIFn7Wrtjdns6cSx3frXBAHBKRL+5EwtHs8O1cUgKFgKdC8VLwBxsi81sKnttOJo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789969675980253.35908486141102; Sun, 20 Sep 2026 22:47:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x8Wrm-0000uM-Qc; Mon, 21 Sep 2026 01:47:03 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x8Wrc-0000rZ-4T for qemu-devel@nongnu.org; Mon, 21 Sep 2026 01:46:53 -0400 Received: from mgamail.intel.com ([192.198.163.12]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x8WrZ-000300-Jc for qemu-devel@nongnu.org; Mon, 21 Sep 2026 01:46:51 -0400 Received: from fmviesa013.fm.intel.com ([10.60.135.153]) by fmvoesa106.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 20 Sep 2026 22:46:49 -0700 Received: from junjie-desk-dev.bj.intel.com ([10.238.152.71]) by smtpauth.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 20 Sep 2026 22:46:46 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1789969610; x=1821505610; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=F06gF5AxE40O5dV0R8Tn1Lvj92h/DgdArPH82PTnkRY=; b=nEcXQ6ziFsuhrHM5LAO0F3QGRsilviEe7RgLOI+2rCkQljyBDKmqoLVl 5SFIqVf0HWa+HMLJ13FiFfRWbmK9bIbI4aCzd9WaG8iF+0lrshr8EjgRn uKXkzeHgFe3Dy4+Fjb31XMYZQU6fAUEughBIBOtLIjQyVATIPNQrro0MR 2kbqY6nsjk8EcbgajyxWr4om8TYi3c7avWxduDaMBZ/tza79sdid0+2dC 7utk7WvGDlEW/gXg2LIqj/sWleAkAXs4XX4dNhuw3fuWcHS8/hsXeHEfb LY4VmNXZqYu0JLgn994qZoazvENs117L6F7Cp/WAtWeu/XPXc7Z9ZBy75 w==; X-CSE-ConnectionGUID: mLTY3uV+S76xUCiB8F1Wfw== X-CSE-MsgGUID: dXQAiZlaSjOOuvJZrGHNPw== X-IronPort-AV: E=McAfee;i="6800,10657,11911"; a="94287048" X-IronPort-AV: E=Sophos;i="6.27,114,1787036400"; d="scan'208";a="94287048" X-CSE-ConnectionGUID: uLcMlhsjTC+DL0wkXSaH5g== X-CSE-MsgGUID: SqshMQn9SfWPmd9Xmx9X4g== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.27,114,1787036400"; d="scan'208";a="3815209" From: Junjie Cao To: qemu-devel@nongnu.org Cc: Thomas Huth , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Gerd Hoffmann , Fabiano Rosas , Laurent Vivier , Paolo Bonzini , Nicholas Piggin , Feifan Qian Subject: [PATCH 3/4] tests/qtest/usb-hcd-xhci: test isoch pacing with MFINDEX above 2^32 Date: Mon, 21 Sep 2026 13:46:31 +0800 Message-ID: X-Mailer: git-send-email 2.43.0 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.12; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1789969679650158500 Content-Type: text/plain; charset="utf-8" Add the minimum needed to drive a transfer ring from the test. Use it to queue an isoch TD with SIA on usb-audio after stepping the clock past 2^32 microframes, and check that the TD waits for the next interval boundary. Before the ROUND_UP() change it completed as soon as the doorbell was rung. The machine is started with pit=3Doff. With the i8254 present the clock step takes 26s in an ASan build instead of well under a second. Signed-off-by: Junjie Cao Acked-by: Philippe Mathieu-Daud=C3=A9 --- Notes: Nick Piggin's v4 series has a fuller xhci ring harness for qtest: https://lore.kernel.org/qemu-devel/20250502033047.102465-1-npiggin@gmai= l.com/ The helpers here are self-contained so that the fixes do not depend on it. I can rebase onto that harness if it is revived. tests/qtest/usb-hcd-xhci-test.c | 283 ++++++++++++++++++++++++++++++++ 1 file changed, 283 insertions(+) diff --git a/tests/qtest/usb-hcd-xhci-test.c b/tests/qtest/usb-hcd-xhci-tes= t.c index b58fa1e2da..61eca37b15 100644 --- a/tests/qtest/usb-hcd-xhci-test.c +++ b/tests/qtest/usb-hcd-xhci-test.c @@ -10,8 +10,68 @@ #include "qemu/osdep.h" #include "libqtest-single.h" #include "libqos/usb.h" +#include "libqos/malloc-pc.h" #include "qobject/qdict.h" =20 +/* capability registers */ +#define XHCI_CAPLENGTH 0x00 +#define XHCI_HCSPARAMS1 0x04 +#define XHCI_DBOFF 0x14 +#define XHCI_RTSOFF 0x18 +/* operational registers */ +#define XHCI_USBCMD 0x00 +#define XHCI_USBSTS 0x04 +#define XHCI_CRCR 0x18 +#define XHCI_DCBAAP 0x30 +#define XHCI_CONFIG 0x38 +#define XHCI_PORTSC(n) (0x400 + 0x10 * (n)) +/* interrupter 0, relative to the runtime registers */ +#define XHCI_ERSTSZ 0x28 +#define XHCI_ERSTBA 0x30 +#define XHCI_ERDP 0x38 + +#define USBCMD_RS (1 << 0) +#define USBCMD_HCRST (1 << 1) +#define USBSTS_HCH (1 << 0) +#define PORTSC_CCS (1 << 0) +#define PORTSC_PR (1 << 4) +#define PORTSC_PP (1 << 9) +#define CRCR_RCS (1 << 0) +#define ERDP_EHB (1 << 3) + +#define TRB_C (1 << 0) +#define TRB_TR_IOC (1 << 5) +#define TRB_TR_SIA (1U << 31) +#define TRB_TYPE(t) ((t) << 10) +#define TRB_GET_TYPE(control) (((control) >> 10) & 0x3f) +#define TRB_GET_CCODE(status) ((status) >> 24) +#define TRB_GET_SLOT(control) ((control) >> 24) + +#define TR_ISOCH 5 +#define CR_ENABLE_SLOT 9 +#define CR_ADDRESS_DEVICE 11 +#define CR_CONFIGURE_ENDPOINT 12 +#define ER_TRANSFER 32 +#define ER_COMMAND_COMPLETE 33 +#define CC_SUCCESS 1 + +#define EP_TYPE_ISOCH_OUT 1 +#define EP_TYPE_CONTROL 4 + +#define XHCI_RING_TRBS 64 +#define XHCI_MICROFRAME_NS 125000 + +typedef struct XHCITest { + QTestState *qts; + QGuestAllocator alloc; + QPCIBus *bus; + struct qhc hc; + uint32_t oper, runtime, doorbell; + uint64_t cmd_ring, event_ring, input_ctx; + unsigned int cmd_idx, event_idx; + unsigned int port, slot; +} XHCITest; + static void wait_device_deleted_event(QTestState *qtest, const char *id) { QDict *resp, *data; @@ -109,6 +169,227 @@ static void test_usb_ccid_hotplug(void) qtest_qmp_device_del(qts, "ccid"); } =20 +static uint32_t xhci_readl(XHCITest *x, uint32_t off) +{ + return qpci_io_readl(x->hc.dev, x->hc.bar, off); +} + +static void xhci_writel(XHCITest *x, uint32_t off, uint32_t val) +{ + qpci_io_writel(x->hc.dev, x->hc.bar, off, val); +} + +static void xhci_writeq(XHCITest *x, uint32_t off, uint64_t val) +{ + xhci_writel(x, off, val); + xhci_writel(x, off + 4, val >> 32); +} + +static uint64_t xhci_alloc_page(XHCITest *x) +{ + uint64_t addr =3D guest_alloc(&x->alloc, 0x1000); + + qtest_memset(x->qts, addr, 0, 0x1000); + return addr; +} + +static void xhci_write_trb(XHCITest *x, uint64_t addr, uint64_t parameter, + uint32_t status, uint32_t control) +{ + qtest_writeq(x->qts, addr, parameter); + qtest_writel(x->qts, addr + 8, status); + qtest_writel(x->qts, addr + 12, control); +} + +/* Fetch the next event if there is one. Does not advance the clock. */ +static bool xhci_next_event(XHCITest *x, uint32_t *status, uint32_t *contr= ol) +{ + uint64_t addr =3D x->event_ring + 16 * x->event_idx; + uint32_t c =3D qtest_readl(x->qts, addr + 12); + + if (!(c & TRB_C)) { + return false; + } + if (status) { + *status =3D qtest_readl(x->qts, addr + 8); + } + if (control) { + *control =3D c; + } + x->event_idx++; + g_assert_cmpuint(x->event_idx, <, XHCI_RING_TRBS); + xhci_writeq(x, x->runtime + XHCI_ERDP, (addr + 16) | ERDP_EHB); + return true; +} + +static unsigned int xhci_command(XHCITest *x, uint64_t parameter, + uint32_t control) +{ + uint32_t status; + + g_assert_cmpuint(x->cmd_idx, <, XHCI_RING_TRBS); + xhci_write_trb(x, x->cmd_ring + 16 * x->cmd_idx++, parameter, 0, + control | TRB_C); + xhci_writel(x, x->doorbell, 0); + + g_assert_true(xhci_next_event(x, &status, &control)); + g_assert_cmpuint(TRB_GET_TYPE(control), =3D=3D, ER_COMMAND_COMPLETE); + g_assert_cmpuint(TRB_GET_CCODE(status), =3D=3D, CC_SUCCESS); + return TRB_GET_SLOT(control); +} + +/* + * Start qemu-xhci with one USB device, run the controller and bring the + * device to the Addressed state. + */ +static void xhci_test_start(XHCITest *x, const char *usb_device) +{ + uint64_t dcbaa, erst, ep0_ring; + unsigned int maxports; + + memset(x, 0, sizeof(*x)); + /* pit=3Doff: a long clock step would run the i8254 timer all the way = */ + x->qts =3D qtest_initf("-machine pc,pit=3Doff -nodefaults " + "-device qemu-xhci,id=3Dxhci,addr=3D04.0 %s", usb= _device); + pc_alloc_init(&x->alloc, x->qts, ALLOC_NO_FLAGS); + x->bus =3D qpci_new_pc(x->qts, NULL); + qusb_pci_init_one(x->bus, &x->hc, QPCI_DEVFN(4, 0), 0); + + x->oper =3D qpci_io_readb(x->hc.dev, x->hc.bar, XHCI_CAPLENGTH); + x->runtime =3D xhci_readl(x, XHCI_RTSOFF) & ~0x1f; + x->doorbell =3D xhci_readl(x, XHCI_DBOFF) & ~0x3; + maxports =3D xhci_readl(x, XHCI_HCSPARAMS1) >> 24; + + xhci_writel(x, x->oper + XHCI_USBCMD, USBCMD_HCRST); + g_assert_false(xhci_readl(x, x->oper + XHCI_USBCMD) & USBCMD_HCRST); + + dcbaa =3D xhci_alloc_page(x); + erst =3D xhci_alloc_page(x); + x->cmd_ring =3D xhci_alloc_page(x); + x->event_ring =3D xhci_alloc_page(x); + x->input_ctx =3D xhci_alloc_page(x); + + xhci_writel(x, x->oper + XHCI_CONFIG, 1); + xhci_writeq(x, x->oper + XHCI_DCBAAP, dcbaa); + qtest_writeq(x->qts, erst, x->event_ring); + qtest_writel(x->qts, erst + 8, XHCI_RING_TRBS); + xhci_writel(x, x->runtime + XHCI_ERSTSZ, 1); + xhci_writeq(x, x->runtime + XHCI_ERSTBA, erst); + xhci_writeq(x, x->runtime + XHCI_ERDP, x->event_ring | ERDP_EHB); + xhci_writeq(x, x->oper + XHCI_CRCR, x->cmd_ring | CRCR_RCS); + xhci_writel(x, x->oper + XHCI_USBCMD, USBCMD_RS); + g_assert_false(xhci_readl(x, x->oper + XHCI_USBSTS) & USBSTS_HCH); + + for (x->port =3D 0; x->port < maxports; x->port++) { + if (xhci_readl(x, x->oper + XHCI_PORTSC(x->port)) & PORTSC_CCS) { + break; + } + } + g_assert_cmpuint(x->port, <, maxports); + xhci_writel(x, x->oper + XHCI_PORTSC(x->port), PORTSC_PP | PORTSC_PR); + while (xhci_next_event(x, NULL, NULL)) { + /* drop the port status change events */ + } + + x->slot =3D xhci_command(x, 0, TRB_TYPE(CR_ENABLE_SLOT)); + qtest_writeq(x->qts, dcbaa + 8 * x->slot, xhci_alloc_page(x)); + + /* input control context: add slot and ep0 */ + qtest_writel(x->qts, x->input_ctx + 0x04, 0x3); + /* slot context: one context entry, root hub port */ + qtest_writel(x->qts, x->input_ctx + 0x20, 1 << 27); + qtest_writel(x->qts, x->input_ctx + 0x24, (x->port + 1) << 16); + /* ep0 context */ + ep0_ring =3D xhci_alloc_page(x); + qtest_writel(x->qts, x->input_ctx + 0x44, + (64 << 16) | (EP_TYPE_CONTROL << 3)); + qtest_writeq(x->qts, x->input_ctx + 0x48, ep0_ring | 1); + xhci_command(x, x->input_ctx, + TRB_TYPE(CR_ADDRESS_DEVICE) | (x->slot << 24)); +} + +/* Returns the address of the transfer ring. */ +static uint64_t xhci_configure_ep(XHCITest *x, unsigned int epid, + unsigned int type, unsigned int interval, + unsigned int max_packet) +{ + uint64_t ring =3D xhci_alloc_page(x); + uint64_t epctx =3D x->input_ctx + 0x20 * (epid + 1); + + qtest_memset(x->qts, x->input_ctx, 0, 0x1000); + qtest_writel(x->qts, x->input_ctx + 0x04, (1 << epid) | 1); + qtest_writel(x->qts, x->input_ctx + 0x20, epid << 27); + qtest_writel(x->qts, x->input_ctx + 0x24, (x->port + 1) << 16); + qtest_writel(x->qts, epctx + 0x00, interval << 16); + qtest_writel(x->qts, epctx + 0x04, (max_packet << 16) | (type << 3)); + qtest_writeq(x->qts, epctx + 0x08, ring | 1); + xhci_command(x, x->input_ctx, + TRB_TYPE(CR_CONFIGURE_ENDPOINT) | (x->slot << 24)); + return ring; +} + +static void xhci_test_end(XHCITest *x) +{ + g_free(x->hc.dev); + qpci_free_pc(x->bus); + alloc_destroy(&x->alloc); + qtest_quit(x->qts); +} + +static bool xhci_test_supported(const char *usb_device) +{ + const char *arch =3D qtest_get_arch(); + + if (strcmp(arch, "i386") !=3D 0 && strcmp(arch, "x86_64") !=3D 0) { + g_test_skip("Test only runs on x86 (pc machine)"); + return false; + } + if (!qtest_has_device("qemu-xhci") || !qtest_has_device(usb_device)) { + g_test_skip("Devices not available"); + return false; + } + return true; +} + +/* + * An isoch TD with SIA set is run at the next interval boundary. That has= to + * hold once the microframe index no longer fits in 32 bits as well. + */ +static void test_xhci_isoch_mfindex_32bit(void) +{ + const unsigned int interval =3D 6; + uint32_t control; + uint64_t ring; + XHCITest x; + + if (!xhci_test_supported("usb-audio")) { + return; + } + + xhci_test_start(&x, "-audiodev none,id=3Dsnd0 " + "-device usb-audio,audiodev=3Dsnd0"); + ring =3D xhci_configure_ep(&x, 2, EP_TYPE_ISOCH_OUT, interval, 64); + + /* Go past 2^32 microframes and stop off an interval boundary. */ + qtest_clock_step(x.qts, (1ULL << 32) * XHCI_MICROFRAME_NS); + qtest_clock_step(x.qts, 5 * XHCI_MICROFRAME_NS); + + xhci_write_trb(&x, ring, xhci_alloc_page(&x), 64, + TRB_TYPE(TR_ISOCH) | TRB_TR_SIA | TRB_TR_IOC | TRB_C); + xhci_writel(&x, x.doorbell + 4 * x.slot, 2); + g_assert_false(xhci_next_event(&x, NULL, NULL)); + + /* + * The streaming interface has not been enabled, so usb-audio stalls t= he + * TD. What matters is when that happens. + */ + qtest_clock_step(x.qts, XHCI_MICROFRAME_NS << interval); + g_assert_true(xhci_next_event(&x, NULL, &control)); + g_assert_cmpuint(TRB_GET_TYPE(control), =3D=3D, ER_TRANSFER); + + xhci_test_end(&x); +} + int main(int argc, char **argv) { int ret; @@ -123,6 +404,8 @@ int main(int argc, char **argv) if (qtest_has_device("usb-ccid")) { qtest_add_func("/xhci/pci/hotplug/usb-ccid", test_usb_ccid_hotplug= ); } + qtest_add_func("/xhci/pci/isoch/mfindex-32bit", + test_xhci_isoch_mfindex_32bit); =20 qtest_start("-device nec-usb-xhci,id=3Dxhci" " -drive id=3Ddrive0,if=3Dnone,file=3Dnull-co://," --=20 2.43.0 From nobody Sat Sep 26 19:59:29 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1789969676; cv=none; d=zohomail.com; s=zohoarc; b=kdw7Cxme71E0vB+ouzbF7wwtMLyydtB7caSRTkBba9Ax5c6Gi5cuYv1InJhDtusBB1m/bstAPudV2OhZRNdm5uT+tpzhY4r+4Ubv4+l+CiCDjj2lNtp96sX7sX1HO5hqNn6+sDh8TdfEaLu0+mZslDhVYkfYNNzxQxMmLn3ZGiw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789969676; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wiNmGjsXM6YIjdmq639aQZAsy7ofwtK9AKuQCN/DdF4=; b=J8eZuYC6G/vuJLiTtv5aJCO7IH2elfn+uRc73qm7WfPKHu3jg81o+WPCMVZLdwjtItjvquCaNKHvUD8rfcMweqsOzpP39O+y4VVoYBF2bM8kygdnbT3+eLqMznEkjGG9NT3xWpiv4jAUETkPwiKZnPgy3yfCtGksu7NDXlM/pjI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789969676030268.6802006184754; Sun, 20 Sep 2026 22:47:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x8Wro-0000w5-F8; Mon, 21 Sep 2026 01:47:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x8Wre-0000re-4I for qemu-devel@nongnu.org; Mon, 21 Sep 2026 01:46:56 -0400 Received: from mgamail.intel.com ([192.198.163.12]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x8Wrc-000300-Ft for qemu-devel@nongnu.org; Mon, 21 Sep 2026 01:46:53 -0400 Received: from fmviesa013.fm.intel.com ([10.60.135.153]) by fmvoesa106.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 20 Sep 2026 22:46:51 -0700 Received: from junjie-desk-dev.bj.intel.com ([10.238.152.71]) by smtpauth.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 20 Sep 2026 22:46:49 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1789969612; x=1821505612; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=JuW2CEC7Cmu/PgatyYuctFLm0GjvHfshVNmPDHk2gzQ=; b=gVRtN7jvaIUaz+DLEZ83WBBJx+GGpQ4HHs6vF0Jn55ih0F8Fa9/lnovA ofYGPvWRDf96w3lpAevEXOwZDCOoRkr22HgtJOmfaUO9hpoYNHUnq23Em 9buy4sQIqYVt57qD/8HE9/D3S+r0+lLH+ZBO1pSeN1wex+uo91GeXjll+ k2jl7/BYsjMxr2pwlSPuST8kBebwmA2l3efTwId34X1/V1dtb8UNLL4pQ 69FqmRjLcYwmakUYNmr46YZiiHUbhdntvxYcYUIVzDXbr+SUovGM7zK4M 19sO6pH4W0M5bPKIrBC9m56o+2GrSClvMe+JURGIYQ1HbbPOqBxlCvjcH g==; X-CSE-ConnectionGUID: 3BVL2QxuT1ecpvyVAvGYsQ== X-CSE-MsgGUID: ApAWKyzRRDSNvp6nopxGoQ== X-IronPort-AV: E=McAfee;i="6800,10657,11911"; a="94287057" X-IronPort-AV: E=Sophos;i="6.27,114,1787036400"; d="scan'208";a="94287057" X-CSE-ConnectionGUID: Hw3xCsrRSg+io6zCuLrIKg== X-CSE-MsgGUID: TaT83Ye0QfKlqGFMPsSi0w== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.27,114,1787036400"; d="scan'208";a="3815219" From: Junjie Cao To: qemu-devel@nongnu.org Cc: Thomas Huth , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Gerd Hoffmann , Fabiano Rosas , Laurent Vivier , Paolo Bonzini , Nicholas Piggin , Feifan Qian Subject: [PATCH 4/4] tests/qtest/usb-hcd-xhci: test isoch endpoint type mismatch Date: Mon, 21 Sep 2026 13:46:32 +0800 Message-ID: X-Mailer: git-send-email 2.43.0 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.12; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -43 X-Spam_score: -4.4 X-Spam_bar: ---- X-Spam_report: (-4.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1789969679643158500 Content-Type: text/plain; charset="utf-8" Configure the interrupt IN endpoint of usb-kbd as Isoch IN and queue one TD. The TD is deferred by a microframe, the kick timer retries it, usb-kbd NAKs, and a second doorbell retries it again. The TD has to stay pending both times and the controller has to keep running. Without the fix QEMU aborts in the timer retry. The endpoint setup is taken from the reproducer attached to #3886. Signed-off-by: Junjie Cao --- tests/qtest/usb-hcd-xhci-test.c | 35 +++++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) diff --git a/tests/qtest/usb-hcd-xhci-test.c b/tests/qtest/usb-hcd-xhci-tes= t.c index 61eca37b15..2e173af750 100644 --- a/tests/qtest/usb-hcd-xhci-test.c +++ b/tests/qtest/usb-hcd-xhci-test.c @@ -33,6 +33,7 @@ #define USBCMD_RS (1 << 0) #define USBCMD_HCRST (1 << 1) #define USBSTS_HCH (1 << 0) +#define USBSTS_HCE (1 << 12) #define PORTSC_CCS (1 << 0) #define PORTSC_PR (1 << 4) #define PORTSC_PP (1 << 9) @@ -57,6 +58,7 @@ =20 #define EP_TYPE_ISOCH_OUT 1 #define EP_TYPE_CONTROL 4 +#define EP_TYPE_ISOCH_IN 5 =20 #define XHCI_RING_TRBS 64 #define XHCI_MICROFRAME_NS 125000 @@ -390,6 +392,37 @@ static void test_xhci_isoch_mfindex_32bit(void) xhci_test_end(&x); } =20 +/* + * The endpoint type in the endpoint context is whatever the guest says. T= ell + * the controller that the interrupt endpoint of usb-kbd is isoch. The idle + * keyboard NAKs, and the TD has to stay pending when first the kick timer= and + * then a doorbell retry it. + */ +static void test_xhci_isoch_ep_type_mismatch(void) +{ + uint64_t ring; + XHCITest x; + + if (!xhci_test_supported("usb-kbd")) { + return; + } + + xhci_test_start(&x, "-device usb-kbd"); + ring =3D xhci_configure_ep(&x, 3, EP_TYPE_ISOCH_IN, 0, 8); + + xhci_write_trb(&x, ring, xhci_alloc_page(&x), 8, + TRB_TYPE(TR_ISOCH) | TRB_TR_SIA | TRB_TR_IOC | TRB_C); + xhci_writel(&x, x.doorbell + 4 * x.slot, 3); + qtest_clock_step(x.qts, 2 * XHCI_MICROFRAME_NS); + xhci_writel(&x, x.doorbell + 4 * x.slot, 3); + + g_assert_false(xhci_next_event(&x, NULL, NULL)); + g_assert_cmphex(xhci_readl(&x, x.oper + XHCI_USBSTS) & + (USBSTS_HCH | USBSTS_HCE), =3D=3D, 0); + + xhci_test_end(&x); +} + int main(int argc, char **argv) { int ret; @@ -406,6 +439,8 @@ int main(int argc, char **argv) } qtest_add_func("/xhci/pci/isoch/mfindex-32bit", test_xhci_isoch_mfindex_32bit); + qtest_add_func("/xhci/pci/isoch/ep-type-mismatch", + test_xhci_isoch_ep_type_mismatch); =20 qtest_start("-device nec-usb-xhci,id=3Dxhci" " -drive id=3Ddrive0,if=3Dnone,file=3Dnull-co://," --=20 2.43.0