[RFC PATCH] usb: dwc3: Ignore late xferNotReady event to prevent halt timeout

Kuen-Han Tsai posted 1 patch 2 months ago
drivers/usb/dwc3/gadget.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
[RFC PATCH] usb: dwc3: Ignore late xferNotReady event to prevent halt timeout
Posted by Kuen-Han Tsai 2 months ago
During a device-initiated disconnect, an xferNotReady event for an ISOC
IN endpoint can be received after the End Transfer command has already
completed.

This late event incorrectly triggers a new Start Transfer, which
prevents the controller from halting and results in a DSTS.DEVCTRLHLT
bit polling timeout.

Ignore the late xferNotReady event if the controller is already in a
disconnected state.

Signed-off-by: Kuen-Han Tsai <khtsai@google.com>
---
Tracing:

# Stop active transfers by sending End Transfer commands
 android.hardwar-913     [004] d..1.  6172.855517: dwc3_gadget_ep_cmd: ep1out: cmd 'End Transfer' [20d08] params 00000000 00000000 00000000 --> status: Successful
 android.hardwar-913     [004] dn.1.  6172.855734: dwc3_gadget_ep_cmd: ep1in: cmd 'End Transfer' [40d08] params 00000000 00000000 00000000 --> status: Successful
 ...
# Recieve an xferNotReady event on an ISOC IN endpoint
    irq/991-dwc3-29741   [000] D..1.  6172.856166: dwc3_event: event (35d010c6): ep1in: Transfer Not Ready [000035d0] (Not Active)
    irq/991-dwc3-29741   [000] D..1.  6172.856190: dwc3_gadget_ep_cmd: ep1in: cmd 'Start Transfer' [35d60406] params 00000000 ffffb620 00000000 --> status: Successful
 android.hardwar-913     [004] dn.1.  6172.868130: dwc3_gadget_ep_cmd: ep2in: cmd 'End Transfer' [30d08] params 00000000 00000000 00000000 --> status: Timed Out
 ...
# Start polling DSTS.DEVCTRLHLT
 android.hardwar-913     [000] .....  6172.869253: dwc3_gadget_run_stop: start polling DWC3_DSTS_DEVCTRLHLT
 ...
# HALT timeout and show the endpoint status for debugging
 android.hardwar-913     [004] .....  6177.479946: dwc3_gadget_run_stop: finish polling DWC3_DSTS_DEVCTRLHLT, is_on=0, reg=0
 android.hardwar-913     [004] .....  6177.479957: dwc3_gadget_ep_status: ep1out: mps 1024/2765 streams 16 burst 5 ring 64/56 flags E:swbp:>
 android.hardwar-913     [004] .....  6177.479958: dwc3_gadget_ep_status: ep1in: mps 1024/1024 streams 16 burst 2 ring 21/64 flags E:swBp:<
 android.hardwar-913     [004] .....  6177.479959: dwc3_gadget_ep_status: ep2out: mps 1024/2765 streams 16 burst 5 ring 56/48 flags e:swbp:>

---
 drivers/usb/dwc3/gadget.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/usb/dwc3/gadget.c b/drivers/usb/dwc3/gadget.c
index 25db36c63951..506391699a10 100644
--- a/drivers/usb/dwc3/gadget.c
+++ b/drivers/usb/dwc3/gadget.c
@@ -3896,7 +3896,8 @@ static void dwc3_endpoint_interrupt(struct dwc3 *dwc,
 		dwc3_gadget_endpoint_transfer_in_progress(dep, event);
 		break;
 	case DWC3_DEPEVT_XFERNOTREADY:
-		dwc3_gadget_endpoint_transfer_not_ready(dep, event);
+		if (dwc->connected)
+			dwc3_gadget_endpoint_transfer_not_ready(dep, event);
 		break;
 	case DWC3_DEPEVT_EPCMDCMPLT:
 		dwc3_gadget_endpoint_command_complete(dep, event);
--
2.50.1.565.gc32cd1483b-goog
Re: [RFC PATCH] usb: dwc3: Ignore late xferNotReady event to prevent halt timeout
Posted by Greg KH 2 months ago
On Mon, Aug 04, 2025 at 04:08:05PM +0800, Kuen-Han Tsai wrote:
> During a device-initiated disconnect, an xferNotReady event for an ISOC
> IN endpoint can be received after the End Transfer command has already
> completed.
> 
> This late event incorrectly triggers a new Start Transfer, which
> prevents the controller from halting and results in a DSTS.DEVCTRLHLT
> bit polling timeout.
> 
> Ignore the late xferNotReady event if the controller is already in a
> disconnected state.
> 
> Signed-off-by: Kuen-Han Tsai <khtsai@google.com>
> ---
> Tracing:
> 
> # Stop active transfers by sending End Transfer commands
>  android.hardwar-913     [004] d..1.  6172.855517: dwc3_gadget_ep_cmd: ep1out: cmd 'End Transfer' [20d08] params 00000000 00000000 00000000 --> status: Successful
>  android.hardwar-913     [004] dn.1.  6172.855734: dwc3_gadget_ep_cmd: ep1in: cmd 'End Transfer' [40d08] params 00000000 00000000 00000000 --> status: Successful
>  ...
> # Recieve an xferNotReady event on an ISOC IN endpoint
>     irq/991-dwc3-29741   [000] D..1.  6172.856166: dwc3_event: event (35d010c6): ep1in: Transfer Not Ready [000035d0] (Not Active)
>     irq/991-dwc3-29741   [000] D..1.  6172.856190: dwc3_gadget_ep_cmd: ep1in: cmd 'Start Transfer' [35d60406] params 00000000 ffffb620 00000000 --> status: Successful
>  android.hardwar-913     [004] dn.1.  6172.868130: dwc3_gadget_ep_cmd: ep2in: cmd 'End Transfer' [30d08] params 00000000 00000000 00000000 --> status: Timed Out
>  ...
> # Start polling DSTS.DEVCTRLHLT
>  android.hardwar-913     [000] .....  6172.869253: dwc3_gadget_run_stop: start polling DWC3_DSTS_DEVCTRLHLT
>  ...
> # HALT timeout and show the endpoint status for debugging
>  android.hardwar-913     [004] .....  6177.479946: dwc3_gadget_run_stop: finish polling DWC3_DSTS_DEVCTRLHLT, is_on=0, reg=0
>  android.hardwar-913     [004] .....  6177.479957: dwc3_gadget_ep_status: ep1out: mps 1024/2765 streams 16 burst 5 ring 64/56 flags E:swbp:>
>  android.hardwar-913     [004] .....  6177.479958: dwc3_gadget_ep_status: ep1in: mps 1024/1024 streams 16 burst 2 ring 21/64 flags E:swBp:<
>  android.hardwar-913     [004] .....  6177.479959: dwc3_gadget_ep_status: ep2out: mps 1024/2765 streams 16 burst 5 ring 56/48 flags e:swbp:>
> 
> ---
>  drivers/usb/dwc3/gadget.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)

Why is this RFC?  What needs to happen to make it an actual submission
that you wish to have applied?

thanks,

greg k-h
Re: [RFC PATCH] usb: dwc3: Ignore late xferNotReady event to prevent halt timeout
Posted by Kuen-Han Tsai 2 months ago
Hi Greg,

On Tue, Aug 5, 2025 at 12:43 AM Greg KH <gregkh@linuxfoundation.org> wrote:
>
> On Mon, Aug 04, 2025 at 04:08:05PM +0800, Kuen-Han Tsai wrote:
> > During a device-initiated disconnect, an xferNotReady event for an ISOC
> > IN endpoint can be received after the End Transfer command has already
> > completed.
> >
> > This late event incorrectly triggers a new Start Transfer, which
> > prevents the controller from halting and results in a DSTS.DEVCTRLHLT
> > bit polling timeout.
> >
> > Ignore the late xferNotReady event if the controller is already in a
> > disconnected state.
> >
> > Signed-off-by: Kuen-Han Tsai <khtsai@google.com>
> > ---
> > Tracing:
> >
> > # Stop active transfers by sending End Transfer commands
> >  android.hardwar-913     [004] d..1.  6172.855517: dwc3_gadget_ep_cmd: ep1out: cmd 'End Transfer' [20d08] params 00000000 00000000 00000000 --> status: Successful
> >  android.hardwar-913     [004] dn.1.  6172.855734: dwc3_gadget_ep_cmd: ep1in: cmd 'End Transfer' [40d08] params 00000000 00000000 00000000 --> status: Successful
> >  ...
> > # Recieve an xferNotReady event on an ISOC IN endpoint
> >     irq/991-dwc3-29741   [000] D..1.  6172.856166: dwc3_event: event (35d010c6): ep1in: Transfer Not Ready [000035d0] (Not Active)
> >     irq/991-dwc3-29741   [000] D..1.  6172.856190: dwc3_gadget_ep_cmd: ep1in: cmd 'Start Transfer' [35d60406] params 00000000 ffffb620 00000000 --> status: Successful
> >  android.hardwar-913     [004] dn.1.  6172.868130: dwc3_gadget_ep_cmd: ep2in: cmd 'End Transfer' [30d08] params 00000000 00000000 00000000 --> status: Timed Out
> >  ...
> > # Start polling DSTS.DEVCTRLHLT
> >  android.hardwar-913     [000] .....  6172.869253: dwc3_gadget_run_stop: start polling DWC3_DSTS_DEVCTRLHLT
> >  ...
> > # HALT timeout and show the endpoint status for debugging
> >  android.hardwar-913     [004] .....  6177.479946: dwc3_gadget_run_stop: finish polling DWC3_DSTS_DEVCTRLHLT, is_on=0, reg=0
> >  android.hardwar-913     [004] .....  6177.479957: dwc3_gadget_ep_status: ep1out: mps 1024/2765 streams 16 burst 5 ring 64/56 flags E:swbp:>
> >  android.hardwar-913     [004] .....  6177.479958: dwc3_gadget_ep_status: ep1in: mps 1024/1024 streams 16 burst 2 ring 21/64 flags E:swBp:<
> >  android.hardwar-913     [004] .....  6177.479959: dwc3_gadget_ep_status: ep2out: mps 1024/2765 streams 16 burst 5 ring 56/48 flags e:swbp:>
> >
> > ---
> >  drivers/usb/dwc3/gadget.c | 3 ++-
> >  1 file changed, 2 insertions(+), 1 deletion(-)
>
> Why is this RFC?  What needs to happen to make it an actual submission
> that you wish to have applied?

I'm not sure if this solution is acceptable since I couldn't find any
guidance in the programming guide about ignoring xferNotReady events
depending on the controller's status. I was thinking marking this as
an RFC is more appropriate to solicit feedback on the solution.

I will send a new patch without the RFC tag soon.

Regards,
Kuen-Han
Re: [RFC PATCH] usb: dwc3: Ignore late xferNotReady event to prevent halt timeout
Posted by Thinh Nguyen 2 months ago
Hi,

On Mon, Aug 04, 2025, Kuen-Han Tsai wrote:
> During a device-initiated disconnect, an xferNotReady event for an ISOC
> IN endpoint can be received after the End Transfer command has already
> completed.

Some more info for clarity: the controller generates xferNotReady event
once when the host requests to send/receive data to an endpoint. The End
Transfer command resets the event filter and allow the controller to
generate the xferNotReady event again. This can occur in the middle of
device-initiated disconnect and before the controller is halted.

> 
> This late event incorrectly triggers a new Start Transfer, which
> prevents the controller from halting and results in a DSTS.DEVCTRLHLT
> bit polling timeout.
> 
> Ignore the late xferNotReady event if the controller is already in a
> disconnected state.
> 
> Signed-off-by: Kuen-Han Tsai <khtsai@google.com>

Please also add Fixes tag and Cc stable.

> ---
> Tracing:
> 
> # Stop active transfers by sending End Transfer commands
>  android.hardwar-913     [004] d..1.  6172.855517: dwc3_gadget_ep_cmd: ep1out: cmd 'End Transfer' [20d08] params 00000000 00000000 00000000 --> status: Successful
>  android.hardwar-913     [004] dn.1.  6172.855734: dwc3_gadget_ep_cmd: ep1in: cmd 'End Transfer' [40d08] params 00000000 00000000 00000000 --> status: Successful
>  ...
> # Recieve an xferNotReady event on an ISOC IN endpoint
>     irq/991-dwc3-29741   [000] D..1.  6172.856166: dwc3_event: event (35d010c6): ep1in: Transfer Not Ready [000035d0] (Not Active)
>     irq/991-dwc3-29741   [000] D..1.  6172.856190: dwc3_gadget_ep_cmd: ep1in: cmd 'Start Transfer' [35d60406] params 00000000 ffffb620 00000000 --> status: Successful
>  android.hardwar-913     [004] dn.1.  6172.868130: dwc3_gadget_ep_cmd: ep2in: cmd 'End Transfer' [30d08] params 00000000 00000000 00000000 --> status: Timed Out
>  ...
> # Start polling DSTS.DEVCTRLHLT
>  android.hardwar-913     [000] .....  6172.869253: dwc3_gadget_run_stop: start polling DWC3_DSTS_DEVCTRLHLT
>  ...
> # HALT timeout and show the endpoint status for debugging
>  android.hardwar-913     [004] .....  6177.479946: dwc3_gadget_run_stop: finish polling DWC3_DSTS_DEVCTRLHLT, is_on=0, reg=0
>  android.hardwar-913     [004] .....  6177.479957: dwc3_gadget_ep_status: ep1out: mps 1024/2765 streams 16 burst 5 ring 64/56 flags E:swbp:>
>  android.hardwar-913     [004] .....  6177.479958: dwc3_gadget_ep_status: ep1in: mps 1024/1024 streams 16 burst 2 ring 21/64 flags E:swBp:<
>  android.hardwar-913     [004] .....  6177.479959: dwc3_gadget_ep_status: ep2out: mps 1024/2765 streams 16 burst 5 ring 56/48 flags e:swbp:>
> 
> ---
>  drivers/usb/dwc3/gadget.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/usb/dwc3/gadget.c b/drivers/usb/dwc3/gadget.c
> index 25db36c63951..506391699a10 100644
> --- a/drivers/usb/dwc3/gadget.c
> +++ b/drivers/usb/dwc3/gadget.c
> @@ -3896,7 +3896,8 @@ static void dwc3_endpoint_interrupt(struct dwc3 *dwc,
>  		dwc3_gadget_endpoint_transfer_in_progress(dep, event);
>  		break;
>  	case DWC3_DEPEVT_XFERNOTREADY:
> -		dwc3_gadget_endpoint_transfer_not_ready(dep, event);
> +		if (dwc->connected)

Move this check in dwc3_gadget_endpoint_transfer_not_ready().

> +			dwc3_gadget_endpoint_transfer_not_ready(dep, event);
>  		break;
>  	case DWC3_DEPEVT_EPCMDCMPLT:
>  		dwc3_gadget_endpoint_command_complete(dep, event);
> --
> 2.50.1.565.gc32cd1483b-goog
> 

And remove the RFC tag in $subject.

Thanks,
Thinh
Re: [RFC PATCH] usb: dwc3: Ignore late xferNotReady event to prevent halt timeout
Posted by Kuen-Han Tsai 2 months ago
Hi Thinh,

On Tue, Aug 5, 2025 at 2:22 AM Thinh Nguyen <Thinh.Nguyen@synopsys.com> wrote:
>
> Hi,
>
> On Mon, Aug 04, 2025, Kuen-Han Tsai wrote:
> > During a device-initiated disconnect, an xferNotReady event for an ISOC
> > IN endpoint can be received after the End Transfer command has already
> > completed.
>
> Some more info for clarity: the controller generates xferNotReady event
> once when the host requests to send/receive data to an endpoint. The End
> Transfer command resets the event filter and allow the controller to
> generate the xferNotReady event again. This can occur in the middle of
> device-initiated disconnect and before the controller is halted.

Thanks for adding more details. I've revised the problem description
in the new submission.

>
> >
> > This late event incorrectly triggers a new Start Transfer, which
> > prevents the controller from halting and results in a DSTS.DEVCTRLHLT
> > bit polling timeout.
> >
> > Ignore the late xferNotReady event if the controller is already in a
> > disconnected state.
> >
> > Signed-off-by: Kuen-Han Tsai <khtsai@google.com>
>
> Please also add Fixes tag and Cc stable.
>
> > ---
> > Tracing:
> >
> > # Stop active transfers by sending End Transfer commands
> >  android.hardwar-913     [004] d..1.  6172.855517: dwc3_gadget_ep_cmd: ep1out: cmd 'End Transfer' [20d08] params 00000000 00000000 00000000 --> status: Successful
> >  android.hardwar-913     [004] dn.1.  6172.855734: dwc3_gadget_ep_cmd: ep1in: cmd 'End Transfer' [40d08] params 00000000 00000000 00000000 --> status: Successful
> >  ...
> > # Recieve an xferNotReady event on an ISOC IN endpoint
> >     irq/991-dwc3-29741   [000] D..1.  6172.856166: dwc3_event: event (35d010c6): ep1in: Transfer Not Ready [000035d0] (Not Active)
> >     irq/991-dwc3-29741   [000] D..1.  6172.856190: dwc3_gadget_ep_cmd: ep1in: cmd 'Start Transfer' [35d60406] params 00000000 ffffb620 00000000 --> status: Successful
> >  android.hardwar-913     [004] dn.1.  6172.868130: dwc3_gadget_ep_cmd: ep2in: cmd 'End Transfer' [30d08] params 00000000 00000000 00000000 --> status: Timed Out
> >  ...
> > # Start polling DSTS.DEVCTRLHLT
> >  android.hardwar-913     [000] .....  6172.869253: dwc3_gadget_run_stop: start polling DWC3_DSTS_DEVCTRLHLT
> >  ...
> > # HALT timeout and show the endpoint status for debugging
> >  android.hardwar-913     [004] .....  6177.479946: dwc3_gadget_run_stop: finish polling DWC3_DSTS_DEVCTRLHLT, is_on=0, reg=0
> >  android.hardwar-913     [004] .....  6177.479957: dwc3_gadget_ep_status: ep1out: mps 1024/2765 streams 16 burst 5 ring 64/56 flags E:swbp:>
> >  android.hardwar-913     [004] .....  6177.479958: dwc3_gadget_ep_status: ep1in: mps 1024/1024 streams 16 burst 2 ring 21/64 flags E:swBp:<
> >  android.hardwar-913     [004] .....  6177.479959: dwc3_gadget_ep_status: ep2out: mps 1024/2765 streams 16 burst 5 ring 56/48 flags e:swbp:>
> >
> > ---
> >  drivers/usb/dwc3/gadget.c | 3 ++-
> >  1 file changed, 2 insertions(+), 1 deletion(-)
> >
> > diff --git a/drivers/usb/dwc3/gadget.c b/drivers/usb/dwc3/gadget.c
> > index 25db36c63951..506391699a10 100644
> > --- a/drivers/usb/dwc3/gadget.c
> > +++ b/drivers/usb/dwc3/gadget.c
> > @@ -3896,7 +3896,8 @@ static void dwc3_endpoint_interrupt(struct dwc3 *dwc,
> >               dwc3_gadget_endpoint_transfer_in_progress(dep, event);
> >               break;
> >       case DWC3_DEPEVT_XFERNOTREADY:
> > -             dwc3_gadget_endpoint_transfer_not_ready(dep, event);
> > +             if (dwc->connected)
>
> Move this check in dwc3_gadget_endpoint_transfer_not_ready().

Done.

>
> > +                     dwc3_gadget_endpoint_transfer_not_ready(dep, event);
> >               break;
> >       case DWC3_DEPEVT_EPCMDCMPLT:
> >               dwc3_gadget_endpoint_command_complete(dep, event);
> > --
> > 2.50.1.565.gc32cd1483b-goog
> >
>
> And remove the RFC tag in $subject.

I sent out a new change without the RFC tag.
https://lore.kernel.org/linux-usb/20250805063413.2934208-1-khtsai@google.com/

Regards,
Kuen-Han