From nobody Fri Oct 2 06:57:24 2026 Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 86FCA171B1 for ; Tue, 4 Aug 2026 10:02:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785837753; cv=none; b=C11HV2MOy43kD/8xjdTP0MdvujqbtwDXvJwSjQ/UN3OhcmuQDnN7aPauHU6yN4DH6ivFPP66v1zQ/9XuLCSH4j4LOB1SAujO91AnGtiXs4lXTdQwsr51wGsm+VkDfHWCXOdIvUSP2AgM2wOoSvz1fvCEpsWthbsGWh/98OfYneI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785837753; c=relaxed/simple; bh=JxbxhSi0ikTARZZqD063b3g0IiJDbZr8KLUrF9HY2A8=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=d9UlvpP/NeL49oIJAN0ZVMX3MFgNH5ANPIsQmEkx19v9u20H9J06YeinA+lVbnWrvhHP6AN75jmdZKsToEvGDkyOLxW97LMPPToopKaHRnNuAt7jOuhacNVpnaS6qhVxuwQt7EGaIYtwQb/grY3NHffHpEBLUR7xLzp1G6Uw9AA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=MzRmkEK9; arc=none smtp.client-ip=209.85.128.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="MzRmkEK9" Received: by mail-wm1-f45.google.com with SMTP id 5b1f17b1804b1-4955aa106b1so27687185e9.0 for ; Tue, 04 Aug 2026 03:02:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785837750; x=1786442550; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=y/lteXKHrsjzDmStTxqHbNUy74XpdlBSY16dLUMkL84=; b=MzRmkEK96Ci8t9QFCHO6glDWY3DL9GihoFV8iieb2zFefNBdx0i6KMe7ufEUMebnab jgu+BcT39vYvwgrWI0hdX0y4ryNnUBHUa1VfC9e1SsdEkw4j96yDr/+sbVO9+yCrwvM0 XVpErEA09tjlu1la4DKfQud7+ykt71UMXtVzWnq+hqoN0wmuewbjY1KYv6TW8sBHC0e1 lu3zr8LkZmhXTWWKkvLa9cK+P3lobwDmr3iaQnw832+ACxLxP8Xcx6lAKfglg3kDVGXT pBx3EMmmZhpbC6ke9/7seizfKlOAaa9Xsf+fXLGzJwn9rnjeU1RtZLo8EWRoHEFQnddb ESNQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785837750; x=1786442550; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=y/lteXKHrsjzDmStTxqHbNUy74XpdlBSY16dLUMkL84=; b=WOQsv0Z1lsne5r6SyXsdMAPnftdPmmk6Bw75kccCNdF0DtuDaf/uV9xVrXjH3PH89q fGXhnn35M/cK+k6nEaVtqtjxdni0CLOuo1KmPmJy3Lpmurb9KMh2RuFvlzwSZh0sLJQY n7ihuM/GYgT7dbjKd1Lbub+nu4KxneFYp1y7adsAEEI56S8mWVqpnQo3cHr1DyHPEtXC jNMpf/qzHAYY3IZOehvn6iP401RQeozAwLhdLusfQmBSuGJ7xm5Hr7YoLj87+ASnxRey h93unB0YgZOM5q8o6UPOBAAjNq8RiVf6fXjzLwgriyqgIvu5TeOB+a7cWkINCtjv4WBL 2oQw== X-Forwarded-Encrypted: i=1; AHgh+RqbUmAg+6C4LwyVn0WszVGxHmvtR81i00vB/Tz9V0ikbOdzg46rSWw1Jk1I3XqTFGVbAgvF6W1GOF/vans=@vger.kernel.org X-Gm-Message-State: AOJu0YwHgFOb8AIvsp1ww/SNdQgQy6DHkmIn40hFrAenCj0wAIztZGdQ eRYcC/6/y4TGZdyZ0D9My/mdpS4XYOnx0P9SS1gS0evY8x633OHpdmzMH+RXeQ== X-Gm-Gg: AR+sD12ky+Bynr9PHYvqGVyszrNDyeA7EPRVI1MPqNdbvaOzkqoQEARC9BHiGUBJ1AW yzg1aw0DY/gHm+/xhdsmW79tGZTIru1Si78/MRc6kgucd8epw8SfUbJzUfuS3ik0xixuhQYfp16 3ojMwlaWr6W+7DvvYvPEaiiU5X+KWLZyqbYt5VlEow+CKY++ycMi5tnZ31izCFHQXS4I62iqd4E jrXu7SSsR2y1vUoTWXXXYNN4Ygxg2QAezTwwxBdmVJ9JSkf+yIy63Bs0Z6A92fhAq5G4y80xUKk 0oYSfWkjcL5cr810Zs5fFsMN2SeYe8wAxZ+NKg4riKl8bieMs4NjHreK7dd09oewrcMP5l/d72o pkoEJnyQRwTonNB8/G5aJ3OcSPDNv9spxHYhc/s3kC3hwq1u8Qxd1fDN7+cUK14/vZXzzCKAYrf U6S1otEKWPXizhrdSOxF/kpGpSbfKsHkexhpFPVlc55TsSJhl98vcdMjqfXhgwgnUt2Y93iA/e X-Received: by 2002:a05:600c:1910:b0:493:cc25:85cb with SMTP id 5b1f17b1804b1-4980ee9bd7fmr270480725e9.8.1785837749626; Tue, 04 Aug 2026 03:02:29 -0700 (PDT) Received: from foxbook (bgt135.neoplus.adsl.tpnet.pl. [83.28.83.135]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b85be7sm392930275e9.2.2026.08.04.03.02.28 (version=TLS1_2 cipher=AES128-SHA bits=128/128); Tue, 04 Aug 2026 03:02:29 -0700 (PDT) Date: Tue, 4 Aug 2026 12:02:26 +0200 From: Michal Pecio To: Mathias Nyman , Greg Kroah-Hartman Cc: Bart Nagel , linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 1/5] usb: xhci: Handle bogus TRB pointers in Missed Service Error events Message-ID: <20260804120226.1e72ff24.michal.pecio@gmail.com> In-Reply-To: <20260804120110.01bda0e2.michal.pecio@gmail.com> References: <20260804120110.01bda0e2.michal.pecio@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" xHCI 1.0 allowed these pointers to be zero. Some Intel chipsets from the era usually set it to zero, but sometimes (apparently) to the next TRB after the one referenced by the previous transfer event on the endpoint. Usually that's indeed the missed TD, but it may also be the last TRB of a two-TRB TD already completed with Short Packet on its first TRB. Then the driver skips all pending TDs, failing to find a match. When handling Missed Service Error, scan TD list twice and only really skip TDs in the second pass if the first pass found a match. This won't catch bogus pointers to wrong TDs, but such a bug would be practically impossible to detect automatically and isn't known to exist. Reported-by: Bart Nagel Closes: https://lore.kernel.org/linux-usb/al_hchyOdPoPWKEo@spiral/ Suggested-by: Mathias Nyman Fixes: d0b619599e52 ("usb: xhci: Expedite skipping missed isoch TDs on mode= rn HCs") Cc: stable@vger.kernel.org Signed-off-by: Michal Pecio --- drivers/usb/host/xhci-ring.c | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c index dfe42822dde5..38a0f895553a 100644 --- a/drivers/usb/host/xhci-ring.c +++ b/drivers/usb/host/xhci-ring.c @@ -2605,6 +2605,17 @@ static bool xhci_spurious_success_tx_event(struct xh= ci_hcd *xhci, } } =20 +static struct xhci_td *find_td_by_dma(struct xhci_ring *ep_ring, dma_addr_= t dma) +{ + struct xhci_td *td; + + if (dma) + list_for_each_entry(td, &ep_ring->td_list, td_list) + if (trb_in_td(td, dma)) + return td; + return NULL; +} + /* * If this function returns an error condition, it means it got a Transfer * event with a corrupted Slot ID, Endpoint ID, or TRB DMA address. @@ -2799,8 +2810,11 @@ static int handle_tx_event(struct xhci_hcd *xhci, xhci_dequeue_td(xhci, td, ep_ring, td->status); } =20 - /* If the TRB pointer is NULL, missed TDs will be skipped on the next eve= nt */ - if (trb_comp_code =3D=3D COMP_MISSED_SERVICE_ERROR && !ep_trb_dma) + /* + * We don't know how many TDs were missed when ep_trb_dma is zero (as per= mitted by + * xHCI 1.0) or bogus. Bail out leaving ep->skip set, next event will sor= t it out. + */ + if (trb_comp_code =3D=3D COMP_MISSED_SERVICE_ERROR && !find_td_by_dma(ep_= ring, ep_trb_dma)) return 0; =20 if (list_empty(&ep_ring->td_list)) { --=20 2.48.1 From nobody Fri Oct 2 06:57:24 2026 Received: from mail-wr1-f46.google.com (mail-wr1-f46.google.com [209.85.221.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4DB454457C9 for ; Tue, 4 Aug 2026 10:03:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.46 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785837802; cv=none; b=sWSGKiNeh/IiYBWeFk4QzpiTD9p0lY9lx/HC1AF1bITOCw0SHCvpBjMFt57IgBUySKkQDR383vwdQ5jwXxTtsjElau9OWweGCnGUD4kaUzbMTCOxcmKc9Bvr8ZKXeN+ERG4FmCDGP2v3A2sVw9SEv8eiF4IVyX7jIaPSmrJmX3A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785837802; c=relaxed/simple; bh=MU350OP6kB1rEDUkj+DOlrGzj1MoS0IisNveTm2dqus=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=bmSB6Xzj9nT7NsI9MU/ygY8XeoZsZm/McKoUa3bkY0PSyl11zmA+DucigpbVrVeTqci0uhFQU/Y8itta/J57+ZTIE3TcmzY9YTtYh0sDuP0N9Pk/kTgCgc5GGJn9nKijo7vG3jqkUH6tb/a9tcgGZL1hjA7/Mr5DGNfHqCMUsHM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=kDmfPnO2; arc=none smtp.client-ip=209.85.221.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="kDmfPnO2" Received: by mail-wr1-f46.google.com with SMTP id ffacd0b85a97d-47f6609c657so2192148f8f.2 for ; Tue, 04 Aug 2026 03:03:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785837798; x=1786442598; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=mKNdCd7BfihSdT/4/OO50sBOOdXqsgqCXHHpY928Dwk=; b=kDmfPnO2ovj/FFsT4TngDNbAfrHWNcx9h7a1sB6WZAMAbEsmDAb8OFvXqxpcceXAJ0 nvJ/rDu2MEMEHT/TRdcVgW963VpwftwcVDlnlSzl83oK1+s8WEBtFiHsjdKSBvDfOq3L VKQZDZUhXimT1CTaz/ZREW/HKsiq8AxYiQlq1TroWAoYOZRzTv8GAtM5HsDu3VvvGOKC 1FQynDqaSlSepFl3Ux1jvCa2gH9hdUChGm8/DL6TU2fJoB0R54o3POx3+pjrlmZPSfxi je+2zfs0DQQYYsbz0wOtGPf0KlhAQFuJzkhivHws3VyO8S3Q13FjwTkPsHkHeeTUb4BE 1AUg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785837798; x=1786442598; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=mKNdCd7BfihSdT/4/OO50sBOOdXqsgqCXHHpY928Dwk=; b=QlFCAlTD2zx4sU0o6xCJ3KC1mqK9Ja8WQ7Qgb1QZZhqgw5hRxLU01H9jasOb/NseIH zMVrqRvuDxG96Tnx7ZG6h0eU1pInsvBDm4CRnkKQtssFaFuyphbQ34ybDGA6l/qHMrse Dz9YA575+oGf4JXoRRbtoVZ3brc+df+tws084ccNM2iDVi0vceNULgnNF3OfBHpn9f++ ZQqZY+xQQG/5a08uR/jTYy25LI2QmrCRJrGcnLV5wlNQ8HPPIKNRB5MtpBvh65GYMbAz 6GdLcCPNKPRAgVQnSdvn0yCMzep/pcINWA0DjwieWL3djGHA9fHvOk9A7/mKMoSJeHnZ tXYQ== X-Forwarded-Encrypted: i=1; AHgh+Ro2TIwEw2IDSJr+IDHNcTF4zfhts/k6RoR2Bu2kJn60w/RPHoru0A0Sla5i//krEdwSHGEo4xlYf1hrnl8=@vger.kernel.org X-Gm-Message-State: AOJu0Yz5JfDjrMKX911+Dju0MI/f3syQX1eaXiV2sAQ/W5QZ5PYolysI vp74dYMVoDdTWuAK1Jm6rX0SpR1/nixbhvprp6FXmthVGBLGW4k/Suv/YImUGA== X-Gm-Gg: AR+sD12rgUaH0p0a5B+sVKvpH8ZI7/oe5jNSLIDf9HvVEvMNhVIbSCyOGPNkX1Tz6M3 sHOpWGLOWexAISK5tKOu6Q9yGOgtyqxvSY0vYCz3kHmM4XKuDVicu+oF1ag8U7fjx0flzCKsGO4 r3QozpYZ8Y9QLXNsGVLSN3voQCO9e7hKMPeyX+IA0/vFiSDKQoQGSpHrHc76Zh5F1E6PHhg0hh3 3KZmwtoXq4dUyHf7YUhyoDa2ISRfVshsdE6pHUkDzRloELI91nQbmhT7VFP29IZm4H4xsA8Pn9I Yak6JiLY7b9v6ku8xi2EyuwoUR1fFDsT6DRqV8QeEXFzAU5rUykXj6FqKr/ibh8lmorFGTwWv0B m01ZXVX0zEm0+hk/s8c2UfpdC3iGSZsWO+7adV3yKUlNaI6Y6yMCWrkkZiTktjKYReufj4QluxD BoV6VQdHcLteps+nYMFKVvez7fw0GKwrLW1IPQDxu8YxhpzMxFhKqVoZVer3VL/OZhgCocxEyE X-Received: by 2002:a05:6000:4693:b0:45e:73eb:5119 with SMTP id ffacd0b85a97d-47fd72d4819mr26233578f8f.22.1785837798381; Tue, 04 Aug 2026 03:03:18 -0700 (PDT) Received: from foxbook (bgt135.neoplus.adsl.tpnet.pl. [83.28.83.135]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47fd42d91bfsm44715531f8f.15.2026.08.04.03.03.17 (version=TLS1_2 cipher=AES128-SHA bits=128/128); Tue, 04 Aug 2026 03:03:18 -0700 (PDT) Date: Tue, 4 Aug 2026 12:03:14 +0200 From: Michal Pecio To: Mathias Nyman , Greg Kroah-Hartman Cc: Bart Nagel , linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 2/5] usb: xhci: Guarantee URB giveback on Ring Underrun/Overrun Message-ID: <20260804120314.0a3203e7.michal.pecio@gmail.com> In-Reply-To: <20260804120110.01bda0e2.michal.pecio@gmail.com> References: <20260804120110.01bda0e2.michal.pecio@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In this case we know that the xHC has released ownership of all missed TDs, we only don't know which were missed and which were queued later. URBs are queued atomically, so we can safely give back all TDs of the currently executing URB. Unlike the previous policy, this does actually ensure that the class driver will learn about the error and won't see all of its URBs still in progress when all TDs are missed on xHCI 1.0. Signed-off-by: Michal Pecio --- drivers/usb/host/xhci-ring.c | 32 +++++++++++++++++++------------- 1 file changed, 19 insertions(+), 13 deletions(-) diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c index 38a0f895553a..8eed56b72c30 100644 --- a/drivers/usb/host/xhci-ring.c +++ b/drivers/usb/host/xhci-ring.c @@ -2630,6 +2630,7 @@ static int handle_tx_event(struct xhci_hcd *xhci, unsigned int slot_id; int ep_index; struct xhci_td *td =3D NULL; + struct urb *missed_urb =3D NULL; dma_addr_t ep_trb_dma; union xhci_trb *ep_trb; int status =3D -EINPROGRESS; @@ -2849,26 +2850,31 @@ static int handle_tx_event(struct xhci_hcd *xhci, return 0; =20 /* - * TD was missed, skip it. Core already initialized frame->status - * to -EXDEV and frame->actual_length to 0, nothing more to do. + * If skip flag is still set at xrun, we are on xHCI 1.0 and our TRB + * pointer is zero again. All missed TDs can be given back, but we + * don't know which were missed and which were queued after the xrun + * occurred. We can safely give back the first pending URB. */ - xhci_dequeue_td(xhci, td, ep_ring, 0); + if (ring_xrun_event) { + if (!missed_urb) + missed_urb =3D td->urb; =20 - if (!list_empty(&ep_ring->td_list)) { - if (ring_xrun_event) { - /* - * If we are here, we are on xHCI 1.0 host with no - * idea how many TDs were missed or where the xrun - * occurred. New TDs may have been added after the - * xrun, so skip only one TD to be safe. - */ - xhci_dbg(xhci, "Skipped one TD for slot %u ep %u", + if (td->urb !=3D missed_urb) { + xhci_dbg(xhci, "Skipped one URB for slot %u ep %u", slot_id, ep_index); return 0; } - continue; } =20 + /* + * TD was missed, skip it. Core already initialized frame->status + * to -EXDEV and frame->actual_length to 0, nothing more to do. + */ + xhci_dequeue_td(xhci, td, ep_ring, 0); + + if (!list_empty(&ep_ring->td_list)) + continue; + xhci_dbg(xhci, "All TDs skipped for slot %u ep %u. Clear skip flag.\n", slot_id, ep_index); ep->skip =3D false; --=20 2.48.1 From nobody Fri Oct 2 06:57:24 2026 Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 85C4B443AB1 for ; Tue, 4 Aug 2026 10:04:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785837844; cv=none; b=QMpSSAdJsF0PP9Hqmmcc5Wr5CeBo5PJ9K9/rT53/ZUrdpISTj50KdN8JrUJa/IB1YfzERzT+Ztbn4TE/CCEI0Sc3wa1lHo2L9auLiiR8ZNAw27oSfHp9aFgxkFzyDpTv28u/X5bEQk/RVfXlq8TZBrqYB/2rYBE9xf71DwYyfkU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785837844; c=relaxed/simple; bh=V5RWXyjpVGh3i0A+4CrqmjGtiyY6FHhADkCnDHoo5LE=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=uOFecYwNZhYE776vcUI801U+8c4SMneItBe9rmXsF/ipZtJDd2mOeO+VnR3/xmISgeMoV9yarIV4KagWRt/OBQiOFYyJGI3b0UP3ii88Xw3AxHpY1hv8VJnKit1imFS1nBCtKg3EO/miIO+f15XS/9Yl/OPm9REnOc0RACAgEWE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=gEJ78mo0; arc=none smtp.client-ip=209.85.221.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="gEJ78mo0" Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-472326ca506so3057732f8f.2 for ; Tue, 04 Aug 2026 03:04:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785837840; x=1786442640; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=g5sbX7LPbmxKznY3becilAKwjNokPaVAppuK6EGQWgc=; b=gEJ78mo0Wk6/V0h43f0Jf319a07aSgL0/aOjrMdAxVZq07t9BRhXTiLhgkNnBnmn1G /b1klYK6DE8mPnH/t+f6eQtiMJVoikneHhNpVjc/zTs2WHKBtd7mgZ5uOg/pky47F6Zs C6aH8wRckp2ZJ23L5ue9asrmbu2jWyI4yGAo5bOnF01+UROoVC+H5VtT2eluW1iieN+5 p8gNgoYAxtKH2yNLzew5Ic12GPPYtog+qVrvPOKebufN2BiKglbhm3iDF9UESA/z4/Qz 9aMbSAiZMHVzzrRIJXJzoycZtsi4icEgPJtS1XzQ5DMYkaCvQl5Xcc2b9Eyv4DuliBi/ w1cA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785837840; x=1786442640; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=g5sbX7LPbmxKznY3becilAKwjNokPaVAppuK6EGQWgc=; b=MYLox7uxAFBRaq/jzMlQVvK8DzELbytQup0sWaCq5h0/mVZyU3bCPeJInyBOSYfmJl HhGmYYOyg23maOT7en5GIBEGgNOYiRWXUS5sVjuHRXm8TYZeGzLQ4lG2MSLV4yf7xQEA od8pNr/AZzPQdPUBLLvxyhUJAoWlFnPPlkb8s1A1r/1ZzHxZrXoSqgaBf1218tal05ID nD5hgAIUNvSxKV93khvcIeP5LVry5FOAqEGUzKHXw8PLemunb/jJOkoLUk/07ML+ocYy eX1v1H2/hDwDFfucQZ1BiFdX+DGjqhDqcMNVW7GLm/hbY8SoBUdjb98nUY9fM24kEXpi 2ZFg== X-Forwarded-Encrypted: i=1; AHgh+Rp9vQ+41FaIsCA0+O2aYTYcszkdAVUW+3/76Q9Iqsvk3zA5WlNnybd3KwMpdUk7uf7XaadjaPB3x63aAZE=@vger.kernel.org X-Gm-Message-State: AOJu0YxMLcmtm1y1GYKyIDeeqqI8ByUMs2ZsXRAigUmVMN2y5wr/gEYW g4IawPOqDyaUcKp28W/lD9r/DH1hXeXPXB0L7J4e9Ce9KiZmAyU8ptdVLVi85Q== X-Gm-Gg: AR+sD13Q+FRob+z/2jTDcvgDuEQvn/2tniXKr6JtQEjkG1NPrKbCqWZTsBkgOaif00G qdpi3gO6TnfXq+dVyNEMV5th83NKuDMkaGou+GdYVReF/chb0Wymkc85U4jhneuRRowRnrEDs5e Wk7aVV1TUppK+F+QloDLCfBfn9HZORPw06VneM82sfX//iU86fGnEEK47exrJCvniedAZURPbHC VzfYFRbFtqwnRn1I33KF4iL2tF82wI6+kG+3aVWa7VzNLCqxAlxXZZpPNfZlI5gnsQbgp+MSgcH g4rtX/BSeCpc0m6PB08hQucQoUNSfFH7guBzYUJchLzDLBDpxDzEZAxTWZgfjsBWh0IDCMz9xu8 4WuHYFy5tFQj4SXujN/QOmtTW7kmXqVxC5ALfx+e9h9Ebd7GBvuhjdcDCfN3INWDZbYjux3NbiH Ua+jd83nf9K4nJg7FKpGaw2mIJlK57wTSdcw48AjF7aHE1+SPnH2kMLmhJWhoYn/+kkJZEI/qp X-Received: by 2002:a05:600c:3b99:b0:498:519:e660 with SMTP id 5b1f17b1804b1-4980c66d8b0mr317127735e9.4.1785837840308; Tue, 04 Aug 2026 03:04:00 -0700 (PDT) Received: from foxbook (bgt135.neoplus.adsl.tpnet.pl. [83.28.83.135]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49949fd8919sm69114595e9.8.2026.08.04.03.03.59 (version=TLS1_2 cipher=AES128-SHA bits=128/128); Tue, 04 Aug 2026 03:04:00 -0700 (PDT) Date: Tue, 4 Aug 2026 12:03:56 +0200 From: Michal Pecio To: Mathias Nyman , Greg Kroah-Hartman Cc: Bart Nagel , linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 3/5] usb: xhci: Don't set the skip flag on non-isoc endpoints Message-ID: <20260804120356.470fab4b.michal.pecio@gmail.com> In-Reply-To: <20260804120110.01bda0e2.michal.pecio@gmail.com> References: <20260804120110.01bda0e2.michal.pecio@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" These events are unique to isochronous endpoints, ignore them otherwise. Update debug messages to reflect new policies. We could also log invalid events as errors, but it seems nobody has ever had problems with that, so don't bother. This allows dropping the isoc check when skipping TDs. Signed-off-by: Michal Pecio --- drivers/usb/host/xhci-ring.c | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c index 8eed56b72c30..8270c63ec3bf 100644 --- a/drivers/usb/host/xhci-ring.c +++ b/drivers/usb/host/xhci-ring.c @@ -2759,16 +2759,18 @@ static int handle_tx_event(struct xhci_hcd *xhci, * Set skip flag of the ep_ring; Complete the missed tds as * short transfer when process the ep_ring next time. */ - ep->skip =3D true; + if (ep_ring->type =3D=3D TYPE_ISOC) + ep->skip =3D true; xhci_dbg(xhci, - "Miss service interval error for slot %u ep %u, set skip flag%s\n", - slot_id, ep_index, ep_trb_dma ? ", skip now" : ""); + "Missed Service Error for slot %u ep %u, skip %d, try now %d\n", + slot_id, ep_index, ep->skip, !!ep_trb_dma); break; case COMP_NO_PING_RESPONSE_ERROR: - ep->skip =3D true; + if (ep_ring->type =3D=3D TYPE_ISOC) + ep->skip =3D true; xhci_dbg(xhci, - "No Ping response error for slot %u ep %u, Skip one Isoc TD\n", - slot_id, ep_index); + "No Ping response error for slot %u ep %u, skip %d\n", + slot_id, ep_index, ep->skip); return 0; =20 case COMP_INCOMPATIBLE_DEVICE_ERROR: @@ -2844,7 +2846,7 @@ static int handle_tx_event(struct xhci_hcd *xhci, /* Is this TRB not part of the currently executing TD? */ if (!trb_in_td(td, ep_trb_dma)) { =20 - if (ep->skip && usb_endpoint_xfer_isoc(&td->urb->ep->desc)) { + if (ep->skip) { /* this event is unlikely to match any TD, don't skip them all */ if (trb_comp_code =3D=3D COMP_STOPPED_LENGTH_INVALID) return 0; --=20 2.48.1 From nobody Fri Oct 2 06:57:24 2026 Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3E64E4570DE for ; Tue, 4 Aug 2026 10:04:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785837882; cv=none; b=X+GI4EUnYO4GwjGxxapK0UkbsdJMudTi6LsPGO2VklIyo2dCE5O7ljtqzvmutkwEyQAsWIAh3p4/Y+OPcXy8XvcN7URhXuc1Xm4kVOBLO3bt7/cJjrc6MnfXanbMo2LgzlW4GOFUWZAJPybzRY7771xwckkNrEj18wiG8L/S68M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785837882; c=relaxed/simple; bh=IqAhJCxRkb6lfpuaonAkPepeYUWJNOqAdbIiKh1yC5s=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=OpGteY6C6IGtZI003m2Db1Fo9iAiQgVpgX7LIiUy9VkKz0UvBiOTFRDEyovvyss2mqIl4ZFsPoIonRS9U7+JetHce9+XnkFmlqIIB5n+aZPNu2e/plJTRFUXqTkm1XgZJ7DQDd6oPCQfgoXC4Xjt2d9Vu3doEvPkCPYBo2/tf4o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=YW5zlJbD; arc=none smtp.client-ip=209.85.128.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="YW5zlJbD" Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-4980dc26022so20566145e9.1 for ; Tue, 04 Aug 2026 03:04:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785837879; x=1786442679; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=HpDn3hiVuA1sei69QrJvJ/J82fmpj8mowHCqmySopVY=; b=YW5zlJbDc2eYIYQ/8ROPIs28g9poWX4kbYFvtJUeLix7Zh9QNRlaX79EOYxbTvVUVY /zpPGuCI5Sn3htqr/ED0/8mxl6/bSwStaCXLZdiJ9Cqx3YJdKlLszXwyCZHT7OUa7yui 3n2zUaQAJZDpWtN0jQxxuAZBBnRZiQ2W1uQWkT5rbx4c3ULPBM7yZf5Pgv8Wm4UCMc7I gKNwGPaF6DLCzKw+o+1hIs7VSSD+ljuzHTbJ4QuXB/FRUcXkf6LSQuJllwsLzWN3g6gb rpJJzcZK1zpqlruOkhfcSJrnZSMoJYzXQbLVbnvm3J17n/Gw+L/T/mPZVH+/ckqOr1yJ vbcQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785837879; x=1786442679; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=HpDn3hiVuA1sei69QrJvJ/J82fmpj8mowHCqmySopVY=; b=iMliXLkMPCM65IRyo1VHvlaXD6AnfdQOClhwGEzC3I5Ha6uDGJi3EaVtzyIjlXZqKP d9rGn3XtabqRAcetIOKOwrQ2QK5Lwf/EadascnwckBKiSnkJS6eUkRSrhgDd04hIKeEI 4UgckRSJaMxsilW5R2Rm2oLr0cDNKElVw0yp1A9yOpaRxavmvs9+BPRbLx4BYlMD2lxR kpmjAMpmGQEBp0s40LxFK+surtbQtlDrG8U6jzBo85IykCzCKhLkC1NSlFPfnMM8mOfJ ToHfgn8R8nYrvT2hsJCnLBshkZzJ/ygHa15DByjzlL4a0AEqyx6g4y7ODFu9iYgbUow+ DiUQ== X-Forwarded-Encrypted: i=1; AHgh+Rph2oVWSWNyDcMKAo0jvU4BEbYl6pDIHFMMqdaUgawokhhCzoAlaqiptV/xmEN58jhgPWC+GvYWhN6ixf0=@vger.kernel.org X-Gm-Message-State: AOJu0YzMALFBUWBbIisNrcFianUUB4eZ65JKB+AsB5TD9bWHbz57K6bw VPKT2R69rQz75MtIhl7y8l2r+rHBoOPyARRi5zEekHoiNI9o6yAbP66l X-Gm-Gg: AR+sD11WlRKiSm7DqmsCzbcTMI55bKnIln4r5j/RQqGB8XtXRQ2csNrsFyHmY60WLUO 97+SrLoZVFtUjYs+87zhXoqtp2cB//ditHtVEiKVbp2nYHKQXFKAhbGxRIjgy+fw2QETcg/pDsr NTrNQCjRW2IWDx+FNsrXY+aHcZvp9ss7pkHyQMOoXCLT1oMGDIPIEAuQynMrRye6zD7Dk1jbnpg XfiEdLEAH4XPMcRKZm81hcnbdIzlceh1jOV9tXkejOrXCsr50mu6YXHrwk2FZtJ0x/8vgKfbckB 5ejmviv4hhsg/Et4njvVAZAn3W/s1Vmu5qf4JENQ58s0qHHI3yZ4ssQmWINgTiUA9EJsyN4cE8o z0smf1o40qXfZhk2X66pIMREK5yM+5/YsDh/n0IG15KFBQvJDB1DSw3lnQTqRtYq/ZhHXpxE/P8 8ntICZbVt71l1GrqsYdM/ej2B2PWGEmJVHgGmAErSz3Smi9r7xuTdcDcG1UFW7/KokP4vp2Yd1 X-Received: by 2002:a05:600c:4444:b0:493:f6f0:d66b with SMTP id 5b1f17b1804b1-4980c6458aamr294474585e9.1.1785837879422; Tue, 04 Aug 2026 03:04:39 -0700 (PDT) Received: from foxbook (bgt135.neoplus.adsl.tpnet.pl. [83.28.83.135]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49949fcb46esm86659055e9.5.2026.08.04.03.04.38 (version=TLS1_2 cipher=AES128-SHA bits=128/128); Tue, 04 Aug 2026 03:04:39 -0700 (PDT) Date: Tue, 4 Aug 2026 12:04:36 +0200 From: Michal Pecio To: Mathias Nyman , Greg Kroah-Hartman Cc: Bart Nagel , linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 4/5] usb: xhci: Shorten the TD skipping loop Message-ID: <20260804120436.0832eea2.michal.pecio@gmail.com> In-Reply-To: <20260804120110.01bda0e2.michal.pecio@gmail.com> References: <20260804120110.01bda0e2.michal.pecio@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Half of this loop is code which only executes once to deal with cases where no TD matches the event and then it returns. This code needs not to be in any kind of loop, so get it out. Optimize conditionals remaining in the loop body. Signed-off-by: Michal Pecio --- drivers/usb/host/xhci-ring.c | 69 +++++++++++++++++------------------- 1 file changed, 33 insertions(+), 36 deletions(-) diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c index 8270c63ec3bf..1f0cb6a701c5 100644 --- a/drivers/usb/host/xhci-ring.c +++ b/drivers/usb/host/xhci-ring.c @@ -2843,10 +2843,9 @@ static int handle_tx_event(struct xhci_hcd *xhci, td =3D list_first_entry(&ep_ring->td_list, struct xhci_td, td_list); =20 - /* Is this TRB not part of the currently executing TD? */ - if (!trb_in_td(td, ep_trb_dma)) { + if (ep->skip) { =20 - if (ep->skip) { + if (!trb_in_td(td, ep_trb_dma)) { /* this event is unlikely to match any TD, don't skip them all */ if (trb_comp_code =3D=3D COMP_STOPPED_LENGTH_INVALID) return 0; @@ -2884,38 +2883,6 @@ static int handle_tx_event(struct xhci_hcd *xhci, goto check_endpoint_halted; } =20 - /* TD was queued after xrun, maybe xrun was on a link, don't panic yet = */ - if (ring_xrun_event) - return 0; - - /* - * Skip the Force Stopped Event. The 'ep_trb' of FSE is not in the curr= ent - * TD pointed by 'ep_ring->dequeue' because that the hardware dequeue - * pointer still at the previous TRB of the current TD. The previous TRB - * maybe a Link TD or the last TRB of the previous TD. The command - * completion handle will take care the rest. - */ - if (trb_comp_code =3D=3D COMP_STOPPED || - trb_comp_code =3D=3D COMP_STOPPED_LENGTH_INVALID) { - return 0; - } - - /* - * Some hosts give a spurious success event after a short - * transfer or error on last TRB. Ignore it. - */ - if (xhci_spurious_success_tx_event(xhci, ep_ring)) { - xhci_dbg(xhci, "Spurious event dma %pad, comp_code %u after %u\n", - &ep_trb_dma, trb_comp_code, ep_ring->old_trb_comp_code); - ep_ring->old_trb_comp_code =3D 0; - return 0; - } - - /* HC is busted, give up! */ - goto debug_finding_td; - } - - if (ep->skip) { xhci_dbg(xhci, "Found td. Clear skip flag for slot %u ep %u.\n", slot_id, ep_index); @@ -2932,10 +2899,40 @@ static int handle_tx_event(struct xhci_hcd *xhci, =20 ep_ring->old_trb_comp_code =3D trb_comp_code; =20 - /* Get out if a TD was queued at enqueue after the xrun occurred */ + /* + * Underrun handling ends here. Any TD pointed by the event was enqueued = after the event + * occurred, so wait for its completion now. And it's not a bug if no suc= h TD exists. + */ if (ring_xrun_event) return 0; =20 + /* Handle events not referencing the current TD */ + if (!trb_in_td(td, ep_trb_dma)) { + /* + * Skip the Force Stopped Event. The 'ep_trb' of FSE is not in the curre= nt + * TD pointed by 'ep_ring->dequeue' because that the hardware dequeue + * pointer still at the previous TRB of the current TD. The previous TRB + * maybe a Link TD or the last TRB of the previous TD. The command + * completion handle will take care the rest. + */ + if (trb_comp_code =3D=3D COMP_STOPPED || trb_comp_code =3D=3D COMP_STOPP= ED_LENGTH_INVALID) + return 0; + + /* + * Some hosts give a spurious success event after a short + * transfer or error on last TRB. Ignore it. + */ + if (xhci_spurious_success_tx_event(xhci, ep_ring)) { + xhci_dbg(xhci, "Spurious event dma %pad, comp_code %u after %u\n", + &ep_trb_dma, trb_comp_code, ep_ring->old_trb_comp_code); + ep_ring->old_trb_comp_code =3D 0; + return 0; + } + + /* HC is busted, give up! */ + goto debug_finding_td; + } + trace_xhci_handle_transfer(ep_ring, (struct xhci_generic_trb *) ep_trb, e= p_trb_dma); =20 /* --=20 2.48.1 From nobody Fri Oct 2 06:57:24 2026 Received: from mail-wr1-f50.google.com (mail-wr1-f50.google.com [209.85.221.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6165C45FFD0 for ; Tue, 4 Aug 2026 10:05:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785837945; cv=none; b=m2IneqTJiPauJ6qFN/tz4IZnPgFa+XLh4kruO0KiWZK9Ph/L3p6BUPLILuBBzWdrNXTsPFf6CFRF1XzHKSOR41NAqxs+Jooj26UWPMoKj03p1WJZOiq96F9D0IQHENm8FdbLcRUls6mePWcIPpVf08MnfjB9QLRTAnJ2IXar1U8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785837945; c=relaxed/simple; bh=0LboO2Wzvm8VqKeGaVT01ngopn2Nr9Qeiwbqzf0FPT4=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=s5EfQkkuDWefBUEaDhdMn78D3/cNnPYvHQWxNdgKxopgI1rotTTg+sBcYShZw7pO+ZSEVDFuG7bQ318EsxRf7o+rV7YhpOZGxd2eIboSPnbC9edc4FbOXzeCCCMgsghKqM4pGVYc3KBTtmwMbRWWdrwx4dec3pv5jen6cWEj7gY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ch9/LWPm; arc=none smtp.client-ip=209.85.221.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ch9/LWPm" Received: by mail-wr1-f50.google.com with SMTP id ffacd0b85a97d-47f84023916so4264653f8f.3 for ; Tue, 04 Aug 2026 03:05:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785837942; x=1786442742; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=OPvlax79e2vC8TjmBy8SZ+anL5Hc0LnpGK9pcZKkYAQ=; b=ch9/LWPmvBe54R2i3uRRqGg+WsiQkhW2BaH6nlsV8aC5qqzPCX2l9XVN3GFY2y1pLv /ybsePvWRuTC2pRRM5Tj37R3QvYsiazoEm5zZaFx3XLvCK0sXu+6sLEU2aQJI8hqURLz v9FMTI4GqGcfnz4ezw3iApFWuqRtMyE8PYxNUwouaq+OTcBxDx530eidhLel5JEx1isH N2zpD7wKwIGWv3k+p+wFq27DaHyD+6GMt66YTF16Mz6291LevRGDCHP7Mw/3xwPFx7FS i2y1xhxgg5YTiQ3B4WcfPf3sKIyMtz7JXa64WmAXShXpMxHZDocBYs7kGGsxQqVFOCVe USMw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785837942; x=1786442742; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=OPvlax79e2vC8TjmBy8SZ+anL5Hc0LnpGK9pcZKkYAQ=; b=dxpJECmViCeMk9xKXQ12vilbjoWNCueoVm27NrDEL36iiR1pTjmn6qbRjHaqKceyXR bC8BIzbMfeW4NsZD2EdHXzdQUQrOzPTJ1Gv+nPMfbTSlwUcLux0/1K5RAowgP2ytBDRi BVGoR1Ds3QxZ1vedBq8MwKvHZ7QT4FrMlvfWv5biv+VNyZv5BRy+lzHfyhfxzLB2V/EP B1bsxHJ5qsJNT6QSSHANFYYZ/56xa9JiIvhfQXPK8BXApk67zVN9GLoIB72IxfY9yoCN uIy7Tf+hD+Y5khHFh9pSJX1CqkV9wQ1E4xMQcyCUwifXJvlHjh1zCDpqYqYbL7W77u0T MphA== X-Forwarded-Encrypted: i=1; AHgh+Rp8GyGCrC0Dlr74UCqtvZQwsjOtHi33M2RtB17LVZsDi4d+oOJWnGEg5i348Huhx/GZpYI7lRdMDnKPcKw=@vger.kernel.org X-Gm-Message-State: AOJu0YyLTWYDRSdczVGbCDXAsfQQHEBa96Yd/JhykMlAsBtfb7Of2yA7 HpBIYPZoHtEMrQgjMHjorcEOPo10cdR5lnZ/W3ajikk9L4L6mn/Jevdp X-Gm-Gg: AR+sD11Za6NE04xAhWucY24FNJLlDZdUIwTdMpe3+cb2D7TllLJThKe8DyCO/HAxtum PQF4UGgD8AqOtHYsrHg7IF/+sPVlzJDAks+6yIIFeiQRg+ILj0eJu5rbJaBKTXTuBvT7I8ftaC9 FhuEdRTVjonyU3azh0HXg+9wzGuC9KxugUHV3IxPFgroswlq81qM+mSafyRcE8ztqkVjy4RndF4 KMzxdvC7e4XRWInL1jTmYVAwnOkvE48goD3uUWnaXY4BGWoqZceiDQElgpZVTiPqVOTuqbpxqBf dosJjcFHvpx50vJ7Ap/82dm7Tg9tDllfP1k/n+uCcfVkay+kl4gQN55dXW2Sji15ynGN/b+tqr6 NNFczd2ezN116n7Nqy2fbE36+oyzQTe5Ka9ArzacXKQaTtbL9wC+IAL6+wJJA6K5J5sh1MiiFEc JUX4Pp4Q7SiQVgmHbfOL+x3cLivba5cLiL507sBPHuFDoXFd/CfAHnjgPY8VPSa2WHf7eQYuKe7 g== X-Received: by 2002:a05:6000:4410:b0:47f:7129:6e2d with SMTP id ffacd0b85a97d-47fd72c753dmr26264167f8f.17.1785837941391; Tue, 04 Aug 2026 03:05:41 -0700 (PDT) Received: from foxbook (bgt135.neoplus.adsl.tpnet.pl. [83.28.83.135]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47fd458b73asm39207883f8f.29.2026.08.04.03.05.40 (version=TLS1_2 cipher=AES128-SHA bits=128/128); Tue, 04 Aug 2026 03:05:41 -0700 (PDT) Date: Tue, 4 Aug 2026 12:05:37 +0200 From: Michal Pecio To: Mathias Nyman , Greg Kroah-Hartman Cc: Bart Nagel , linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH 5/5] usb: xhci: Rework and improve the TD matching and skipping logic Message-ID: <20260804120537.5c30554e.michal.pecio@gmail.com> In-Reply-To: <20260804120110.01bda0e2.michal.pecio@gmail.com> References: <20260804120110.01bda0e2.michal.pecio@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Matching events with TDs and giving back missed TDs is carried out by a complicated loop. Replace it with a simpler linear logic: 0. Having verified that 'td_list' isn't empty, 1. Scan it to find the matching TD and count missed TDs, 2. Perform necessary adjustments for corner cases, 3. Give back missed TDs, if applicable, using a short and tidy loop, 4. Check if the event refers to the expected TD and proceed as usual. Besides cleaning up the code, this provides a few improvements: - when the skip flag is set, no TD is given back unless we found a match or otherwise know how many TDs should be given back - when the skip flag is clear, we know if the event refers to a "future" TD so we can log this in the Scary Error Message to aid debugging. While altering the error message, drop a pointless goto. Signed-off-by: Michal Pecio --- drivers/usb/host/xhci-ring.c | 137 ++++++++++++++++------------------- 1 file changed, 61 insertions(+), 76 deletions(-) diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c index 1f0cb6a701c5..d94146ceb178 100644 --- a/drivers/usb/host/xhci-ring.c +++ b/drivers/usb/host/xhci-ring.c @@ -125,11 +125,16 @@ static bool link_trb_toggles_cycle(union xhci_trb *tr= b) return le32_to_cpu(trb->link.control) & LINK_TOGGLE; } =20 -static bool last_td_in_urb(struct xhci_td *td) +static int num_tds_not_done(struct urb *urb) { - struct urb_priv *urb_priv =3D td->urb->hcpriv; + struct urb_priv *urb_priv =3D urb->hcpriv; =20 - return urb_priv->num_tds_done =3D=3D urb_priv->num_tds; + return urb_priv->num_tds - urb_priv->num_tds_done; +} + +static bool last_td_in_urb(struct xhci_td *td) +{ + return !num_tds_not_done(td->urb); } =20 static bool unhandled_event_trb(struct xhci_ring *ring) @@ -2605,14 +2610,19 @@ static bool xhci_spurious_success_tx_event(struct x= hci_hcd *xhci, } } =20 -static struct xhci_td *find_td_by_dma(struct xhci_ring *ep_ring, dma_addr_= t dma) +static struct xhci_td *find_td_by_dma(struct xhci_ring *ep_ring, int *miss= ed_tds, dma_addr_t dma) { struct xhci_td *td; =20 - if (dma) + if (dma) { list_for_each_entry(td, &ep_ring->td_list, td_list) if (trb_in_td(td, dma)) return td; + else + (*missed_tds)++; + } + + *missed_tds =3D 0; return NULL; } =20 @@ -2629,8 +2639,8 @@ static int handle_tx_event(struct xhci_hcd *xhci, struct xhci_ring *ep_ring; unsigned int slot_id; int ep_index; - struct xhci_td *td =3D NULL; - struct urb *missed_urb =3D NULL; + struct xhci_td *td; + int missed_tds =3D 0; dma_addr_t ep_trb_dma; union xhci_trb *ep_trb; int status =3D -EINPROGRESS; @@ -2813,13 +2823,6 @@ static int handle_tx_event(struct xhci_hcd *xhci, xhci_dequeue_td(xhci, td, ep_ring, td->status); } =20 - /* - * We don't know how many TDs were missed when ep_trb_dma is zero (as per= mitted by - * xHCI 1.0) or bogus. Bail out leaving ep->skip set, next event will sor= t it out. - */ - if (trb_comp_code =3D=3D COMP_MISSED_SERVICE_ERROR && !find_td_by_dma(ep_= ring, ep_trb_dma)) - return 0; - if (list_empty(&ep_ring->td_list)) { /* * Don't print wanings if ring is empty due to a stopped endpoint genera= ting an @@ -2839,63 +2842,47 @@ static int handle_tx_event(struct xhci_hcd *xhci, goto check_endpoint_halted; } =20 - do { - td =3D list_first_entry(&ep_ring->td_list, struct xhci_td, - td_list); - - if (ep->skip) { - - if (!trb_in_td(td, ep_trb_dma)) { - /* this event is unlikely to match any TD, don't skip them all */ - if (trb_comp_code =3D=3D COMP_STOPPED_LENGTH_INVALID) - return 0; - - /* - * If skip flag is still set at xrun, we are on xHCI 1.0 and our TRB - * pointer is zero again. All missed TDs can be given back, but we - * don't know which were missed and which were queued after the xrun - * occurred. We can safely give back the first pending URB. - */ - if (ring_xrun_event) { - if (!missed_urb) - missed_urb =3D td->urb; - - if (td->urb !=3D missed_urb) { - xhci_dbg(xhci, "Skipped one URB for slot %u ep %u", - slot_id, ep_index); - return 0; - } - } - - /* - * TD was missed, skip it. Core already initialized frame->status - * to -EXDEV and frame->actual_length to 0, nothing more to do. - */ - xhci_dequeue_td(xhci, td, ep_ring, 0); + td =3D find_td_by_dma(ep_ring, &missed_tds, ep_trb_dma); =20 - if (!list_empty(&ep_ring->td_list)) - continue; + if (ep->skip) { + if (!td) { + /* + * xHCI 1.0 allowed MSE events to have zero TRB pointers. Some old chips + * also generate bogus non-zero pointers. We know, don't bother warning. + * Missed TDs will be given back by the next event with a valid pointer. + */ + if (trb_comp_code =3D=3D COMP_MISSED_SERVICE_ERROR && + xhci->hci_version <=3D 0x100) + return 0; + /* + * If skip flag is still set at xrun, we are on xHCI 1.0 and our TRB po= inter + * is zero again. All missed TDs can be given back, but we don't know w= hich + * were missed and which were queued after the xrun occurred. We can sa= fely + * give back the first pending URB to let the class driver know. + */ + if (ring_xrun_event) + missed_tds =3D num_tds_not_done(list_first_entry(&ep_ring->td_list, + struct xhci_td, td_list)->urb); + /* In other cases missed_tds is zero */ + } =20 - xhci_dbg(xhci, "All TDs skipped for slot %u ep %u. Clear skip flag.\n", - slot_id, ep_index); - ep->skip =3D false; - td =3D NULL; - goto check_endpoint_halted; - } + /* + * Give back missed TDs. Core already initialized their frame->status to= -EXDEV + * and frame->actual_length to 0, nothing more to do. + */ + for (int i =3D 0; i < missed_tds; i++) + xhci_dequeue_td(xhci, + list_first_entry(&ep_ring->td_list, struct xhci_td, td_list), + ep_ring, 0); =20 - xhci_dbg(xhci, - "Found td. Clear skip flag for slot %u ep %u.\n", - slot_id, ep_index); + /* the list may become empty on ring_xrun_event */ + if (td || list_empty(&ep_ring->td_list)) ep->skip =3D false; - } =20 - /* - * If ep->skip is set, it means there are missed tds on the - * endpoint ring need to take care of. - * Process them as short transfer until reach the td pointed by - * the event. - */ - } while (ep->skip); + xhci_dbg(xhci, "Skipped %d TDs on slot %u ep %u comp_code %u, TD found %= d, skip flag %d\n", + missed_tds, slot_id, ep_index, trb_comp_code, !!td, ep->skip); + missed_tds =3D 0; + } =20 ep_ring->old_trb_comp_code =3D trb_comp_code; =20 @@ -2907,7 +2894,7 @@ static int handle_tx_event(struct xhci_hcd *xhci, return 0; =20 /* Handle events not referencing the current TD */ - if (!trb_in_td(td, ep_trb_dma)) { + if (!td || missed_tds) { /* * Skip the Force Stopped Event. The 'ep_trb' of FSE is not in the curre= nt * TD pointed by 'ep_ring->dequeue' because that the hardware dequeue @@ -2930,7 +2917,13 @@ static int handle_tx_event(struct xhci_hcd *xhci, } =20 /* HC is busted, give up! */ - goto debug_finding_td; + td =3D list_first_entry(&ep_ring->td_list, struct xhci_td, td_list); + xhci_err(xhci, "Event dma %pad for ep %d comp_code %u not part of TD at = %016llx - %016llx, missed %d\n", + &ep_trb_dma, ep_index, trb_comp_code, + (u64)xhci_trb_virt_to_dma(td->start_seg, td->start_trb), + (u64)xhci_trb_virt_to_dma(td->end_seg, td->end_trb), + missed_tds); + return -ESHUTDOWN; } =20 trace_xhci_handle_transfer(ep_ring, (struct xhci_generic_trb *) ep_trb, e= p_trb_dma); @@ -2962,14 +2955,6 @@ static int handle_tx_event(struct xhci_hcd *xhci, =20 return 0; =20 -debug_finding_td: - xhci_err(xhci, "Event dma %pad for ep %d status %d not part of TD at %016= llx - %016llx\n", - &ep_trb_dma, ep_index, trb_comp_code, - (unsigned long long)xhci_trb_virt_to_dma(td->start_seg, td->start_trb), - (unsigned long long)xhci_trb_virt_to_dma(td->end_seg, td->end_trb)); - - return -ESHUTDOWN; - err_out: xhci_err(xhci, "@%016llx %08x %08x %08x %08x\n", (unsigned long long) xhci_trb_virt_to_dma( --=20 2.48.1