From nobody Fri Sep 25 17:49:58 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6440A339375 for ; Thu, 10 Sep 2026 01:51:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789005069; cv=none; b=GmKVZHlMy7wU12IXBAZvUStoSEaSIftweYu8OIqUT/kVuC21Feaj0Gp6BUkVFz8CVz6MVRI0K12U6hLC6XRsWtsOMfW+9SVfooPPZ1Jaw5QLrp/7B1Ox0o7b3kek+6Q2luR/A0PFMYb9G1Qpjd7AI04CJxt0WAnRnKOe0M4mkpo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789005069; c=relaxed/simple; bh=MC8RF8exbnRdyxfzrjSNLOlOV7Cnba1woExTrACXBa8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=JKE8Hs1GkbvSIdl9vfwux0sg9nYbvE/kIMB3gfuYvnadOmyUzXCWmFR02ySde5zjCkTDMugXwwMnkQBcrjRapVBAne0PQ1E+cjIwehC0I9cd7z2q7LiRAPZ/j+mBIbHeL/8kIvk6QavSmDjsJ1t1ORoxDLv+u1vezJKf14YJsdI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=c7uCSFSc; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=d1tmFJl8; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="c7uCSFSc"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="d1tmFJl8" Received: from pps.filterd (m0279862.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 68A1lId93198384 for ; Thu, 10 Sep 2026 01:51:06 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= qLcKeVUAGDAqIIR+NcT+dw/2isBatO7SL2E+KRjKb9M=; b=c7uCSFScMMdi2itr 7EKgyuvAUenDol1uOUGw+354mn+uFnFCfxHZgkwhzYvJKv+PzHZYj2qdyvSfuc4g KRJQwBzRTpui2QsxO7XNpq+4fCOwpXtfvD19WsufLhtDxuA57C5O+QsEBBnoWKYl 7RfC1QMyVD543wc4/KH3WkteBM9ohwKBrUDht/avEW5Lq2fHePkTVvQLDI44eITm +R8sOaJFmldu0/dJZLACD7GrvcIiveTxd3cOjNt+ixhNhGbrugruS1uf+XHS8GWG namh1maIBVDx22dxviMpC8m0JOnSaIIEabUc1W9bECk5Q/ABrL+saCBcqpEd9m63 Fxs+eA== Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4gkcydshkp-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Thu, 10 Sep 2026 01:51:06 +0000 (GMT) Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-39906175917so8031724a91.2 for ; Wed, 09 Sep 2026 18:51:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1789005066; x=1789609866; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=qLcKeVUAGDAqIIR+NcT+dw/2isBatO7SL2E+KRjKb9M=; b=d1tmFJl8he0JspYrAHck4SZHHrMjMztuyblOdZ3ZQcp8wzqyBKM5LxGuJSPLBp4Czx ZQNxwlQ+lRoFJT8Ee7U5AQA0zMQamCof5NDfmZZOWMXzq+pDd04o/rPCQgpN25SfFz0H mNyuRXzCV7gS2ezUfgA24gTixK/wuJgUvka+d9MPem0AuDP+0tHymbhDgpfg2TGyRANS x0bqu04k31HtwwZ8/VPCKUat+A0EikP/znAlEG62KUfn+kmnV6b3ziUaBMz6GiDttETe wseXHIhtyEL5HPwgbJD4sJYdVIHtpZ+N2AZ029+G4FYcunEdJ0HPuBVvXPHX3NBBKlMC yyLg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789005066; x=1789609866; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=qLcKeVUAGDAqIIR+NcT+dw/2isBatO7SL2E+KRjKb9M=; b=Aj1GWK604KHjAKXyRenKdIH0QcgGrEMtees49QikpUEKksKELl28shFEqFPtOMv/Dr psW847Yl67sIEfut45/+uoeQaNIzOxExpIl4Q/HZhBvOcHdaJ7V2fVU6vH/+BnnXCvli a+/X6WiWpjIpLI6dL/MMARP6Pts7xRmUgjQaiKcv+NHnCaSQoAL8wUcgM+wtFEyKz+s/ kHcvtWcRzPW0CvEZda9swEuknfd0X3VIgBjifV3AtHwRSdC6QyyoRkpBst7uT3EAZ2TB nDNyZFoDofSYfKNr6EKNC4GbnHXF4JlvLxOAztieWIDFDHfNToIZIsLvNgub9raKbqiN mMSA== X-Forwarded-Encrypted: i=1; AKwUvBxDwoT5cGjlQyL9+K6uKQCePaj2lG8zcQ3+nquMxLu22nZTI+4mP8T+p/A9HL2kGDhSIulssCkUG5SrxPs=@vger.kernel.org X-Gm-Message-State: AFuF++kl2isPotSkVnrMU1UiBOyOiQGoFRdCmWMOwNbyXVJUcJ17OJjZ RYrjHA6dIWTkCfI4Fs6eiCQUH3VUm+8hnSO1E6ox3jlRcjwSqo3b/C4Z7EDvXLWXLfv5z4Zw56x qCPrTz2kBEGHKMqOX9tlKXW4o39XSUmzTmXzPnxePLa0BoVmPnacaqJ+JiqER8i2tb9NXuIPhRK 8= X-Gm-Gg: AYBFou3nzQc3hohZZmNMYRzn/NkS36XKzpkV9x4BR/agRrn6B0RvfUGSgZUB+Ymp3XV mUfrtHMMJfkDmbWDSQlHGf1dvSuDpHaj6WT/8hewQqyMLXqFqxeXT48S6en7FTyR0X6NuYHUETG AVlwpEobNZ6UrrOLAWiyivrymNg24EnhLQ1skt05KxiLngC6XesW8ZjspumSHhCBfSxyYZm98lW hQ6qPLuKRl3NsSJIZXhFKOpti9Vx/iiFH6ahny0w+81kaUS2rztcFoHO25xlioS0c7lxIdTPrFg PMrdvr2Q3YFTYlKO6zpxN0dgaFL3MseAmmcES0JEEMMQtQkr6RvdCYWyjAudCzoTDoZbaMTlbUU bk+EnFV0h9MKTZIUkbHe9jYt9/sBOfJOlJCl32uN9Jkzog9HBkdmB X-Received: by 2002:a17:90b:578c:b0:398:e6b6:acc2 with SMTP id 98e67ed59e1d1-39b261e7649mr61147008a91.12.1789005065864; Wed, 09 Sep 2026 18:51:05 -0700 (PDT) X-Received: by 2002:a17:90b:578c:b0:398:e6b6:acc2 with SMTP id 98e67ed59e1d1-39b261e7649mr61146945a91.12.1789005065352; Wed, 09 Sep 2026 18:51:05 -0700 (PDT) Received: from hu-wcheng-lv.qualcomm.com (Global_NAT1.qualcomm.com. [129.46.96.20]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3339aa33e96sm47446234eec.12.2026.09.09.18.51.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 18:51:04 -0700 (PDT) From: Wesley Cheng Date: Wed, 09 Sep 2026 18:50:57 -0700 Subject: [PATCH v4 1/5] usb: xhci: sideband: fix ring sg table for sub-page TRB segments Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260909-16k_offload_v1_b4-v4-1-f24a86617597@oss.qualcomm.com> References: <20260909-16k_offload_v1_b4-v4-0-f24a86617597@oss.qualcomm.com> In-Reply-To: <20260909-16k_offload_v1_b4-v4-0-f24a86617597@oss.qualcomm.com> To: Mathias Nyman , Greg Kroah-Hartman , Jaroslav Kysela , Takashi Iwai , Michal Pecio Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, linux-sound@vger.kernel.org, Wesley Cheng X-Mailer: b4 0.15.2 X-Authority-Analysis: v=2.4 cv=IfsSymqa c=1 sm=1 tr=0 ts=6aa20d0a cx=c_pps a=vVfyC5vLCtgYJKYeQD43oA==:117 a=ouPCqIW2jiPt+lZRy3xVPw==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_K5XuSEh1TEqbUxoQ0s3:22 a=EUspDBNiAAAA:8 a=aTe8jcWzyPiXfLMz6F4A:9 a=QEXdDO2ut3YA:10 a=rl5im9kqc5Lf4LNbBjHf:22 X-Proofpoint-GUID: B5VeBz84yCmo0efd9Es2iBOEtSF4Xty3 X-Proofpoint-ORIG-GUID: B5VeBz84yCmo0efd9Es2iBOEtSF4Xty3 X-Proofpoint-Spam-Info: AW1haW4tMjYwOTEwMDAxOCBTYWx0ZWRfX5farUu6CYMVf 3QGVMs3D/KxR4quU7fK1w7wmSKvXiCRlcyf4W1XaAEMib4eH2GzuyfQzV3kBemHmHlIH/5/VbWY WVx6sBuhtWDId8PLnt4FOu21Kss5mcI= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTEwMDAxOCBTYWx0ZWRfX3ykTGRJZk0tt BZJLs2eaUfN2/EBY1aqGGMtrpKf+mE86fmjsnDLms5vnRD0ZsoElIeyUx921ojspRiELUrP4Lq3 V+mbWjy/K5Ya+unJ5JvvOtOQw7etJaEIn8/v2hB0lmVAL9bcNS4q0BTvqT8cH6R/8bepFgxLOrJ 7p7sd5/OQHf4x4m1j4VLV5jKjE6E3IIbPdoS7Clv426SvevxD9VHFh2QxeeWdj1iwKBkf3viIza 86U0bNwQGiYl/jvJaDBQIv0yqtXpM3zSaH5xy4qgobz+mQr8crdVf4vIhTZdjXfGhVDZEz05DH8 o0EMM2hp6aHb9GQTrI6Xhlk8HTImTSlCbJC5yxB+LISZthqmDpKD7TQSrqg6yb/MGK8y7KPs951 Q4gXwRyLdAsPvWedXWuUeq4gOb2TSsqNFbE02t2OTwngCQUIi6dk2b3N3Z2eENkemO+dPLBYkyu F5S9pjf0PJu5v3UOG7g== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-10_01,2026-09-09_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 malwarescore=0 priorityscore=1501 lowpriorityscore=0 impostorscore=0 spamscore=0 adultscore=0 suspectscore=0 bulkscore=0 clxscore=1015 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2609040000 definitions=main-2609100018 xhci_ring_to_sgtable() populated its sg_table via dma_get_sgtable() per segment and sg_alloc_table_from_pages(), both of which only operate at whole PAGE_SIZE granularity. Since TRB_SEGMENT_SIZE (4096) can be smaller than PAGE_SIZE, multiple ring segments can share the same physical page on larger-PAGE_SIZE kernels (16K/64K), which these helpers cannot correctly represent. Build the sg_table directly instead: allocate one sg entry per ring segment with sg_alloc_table(), and fill each entry explicitly with sg_set_page() using the segment's own page (resolved via is_vmalloc_addr()/vmalloc_to_page() or virt_to_page()), TRB_SEGMENT_SIZE as the length, and offset_in_page() for the exact intra-page offset. This guarantees each segment gets its own sg entry regardless of page sharing. Assisted-by: Claude:claude-sonnet-5 Signed-off-by: Wesley Cheng --- drivers/usb/host/xhci-sideband.c | 57 +++++++++++++-----------------------= ---- 1 file changed, 18 insertions(+), 39 deletions(-) diff --git a/drivers/usb/host/xhci-sideband.c b/drivers/usb/host/xhci-sideb= and.c index a5deeee4d5dc..beb637407e47 100644 --- a/drivers/usb/host/xhci-sideband.c +++ b/drivers/usb/host/xhci-sideband.c @@ -9,57 +9,42 @@ */ =20 #include -#include =20 #include "xhci.h" =20 /* sideband internal helpers */ static struct sg_table * -xhci_ring_to_sgtable(struct xhci_sideband *sb, struct xhci_ring *ring) +xhci_ring_to_sgtable(struct xhci_ring *ring) { struct xhci_segment *seg; struct sg_table *sgt; - unsigned int n_pages; - struct page **pages; - struct device *dev; - size_t sz; + struct page *page; int i; =20 - dev =3D xhci_to_hcd(sb->xhci)->self.sysdev; - sz =3D ring->num_segs * TRB_SEGMENT_SIZE; - n_pages =3D PAGE_ALIGN(sz) >> PAGE_SHIFT; - pages =3D kvmalloc_objs(struct page *, n_pages); - if (!pages) + seg =3D ring->first_seg; + if (!seg) return NULL; =20 sgt =3D kzalloc_obj(*sgt); - if (!sgt) { - kvfree(pages); + if (!sgt) + return NULL; + + if (sg_alloc_table(sgt, ring->num_segs, GFP_KERNEL)) { + kfree(sgt); return NULL; } =20 - seg =3D ring->first_seg; - if (!seg) - goto err; - /* - * Rings can potentially have multiple segments, create an array that - * carries page references to allocated segments. Utilize the - * sg_alloc_table_from_pages() to create the sg table, and to ensure - * that page links are created. - */ for (i =3D 0; i < ring->num_segs; i++) { - dma_get_sgtable(dev, sgt, seg->trbs, seg->dma, - TRB_SEGMENT_SIZE); - pages[i] =3D sg_page(sgt->sgl); - sg_free_table(sgt); + if (is_vmalloc_addr(seg->trbs)) + page =3D vmalloc_to_page(seg->trbs); + else + page =3D virt_to_page(seg->trbs); + + sg_set_page(&sgt->sgl[i], page, TRB_SEGMENT_SIZE, + offset_in_page(seg->trbs)); seg =3D seg->next; } =20 - if (sg_alloc_table_from_pages(sgt, pages, n_pages, 0, sz, GFP_KERNEL)) - goto err; - - kvfree(pages); - /* * Save first segment dma address to sg dma_address field for the sideband * client to have access to the IOVA of the ring. @@ -67,12 +52,6 @@ xhci_ring_to_sgtable(struct xhci_sideband *sb, struct xh= ci_ring *ring) sg_dma_address(sgt->sgl) =3D ring->first_seg->dma; =20 return sgt; - -err: - kvfree(pages); - kfree(sgt); - - return NULL; } =20 /* Caller must hold sb->mutex */ @@ -254,7 +233,7 @@ xhci_sideband_get_endpoint_buffer(struct xhci_sideband = *sb, if (!ep || !ep->ring || !ep->sideband || ep->sideband !=3D sb) return NULL; =20 - return xhci_ring_to_sgtable(sb, ep->ring); + return xhci_ring_to_sgtable(ep->ring); } EXPORT_SYMBOL_GPL(xhci_sideband_get_endpoint_buffer); =20 @@ -276,7 +255,7 @@ xhci_sideband_get_event_buffer(struct xhci_sideband *sb) if (!sb || !sb->ir) return NULL; =20 - return xhci_ring_to_sgtable(sb, sb->ir->event_ring); + return xhci_ring_to_sgtable(sb->ir->event_ring); } EXPORT_SYMBOL_GPL(xhci_sideband_get_event_buffer); =20 --=20 2.34.1 From nobody Fri Sep 25 17:49:58 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BC3A0369D43 for ; Thu, 10 Sep 2026 01:51:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789005070; cv=none; b=JPOoEYbD1tFEmBEalVuuwU/lTlmW64GH6PjJ5s2TL3gITfxPC/Gugzyz1HoNWFVDf0iOOwwTwg/WPC3KvY19SZiuzkRl1/LJEgjyjDYUvFJkulHaOCi7zOnh8OprmU/D+kNTHdVlEbYs9OJ4Ji1bYhfaMylRi2hMlorSlYLSaX4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789005070; c=relaxed/simple; bh=YezSN2ajFgZ5BhO6JiinsBMA1oRGhgbu29Z0ApFTkJo=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=qo62nJ3AkxW7bW4/ImpXN50fr8AGrfrHVRuo3uEgGGHz1NEiO9BUtRpUz7UdixTHZird5hZ32z2hMpTJ8DD0Nfw1ylx4hXUEe2CjrNYPYUFzYnLZcwQ7tNZPjx7NYp6ES/XkiE12GIezHgERiVrJbMG+lZPgv0zGjjU/tk3LRk8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=lHdBkrRL; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=VrjTizf8; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="lHdBkrRL"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="VrjTizf8" Received: from pps.filterd (m0279863.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 68A1lBjV3730003 for ; Thu, 10 Sep 2026 01:51:08 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= EJT8o863eEHoJK98pu1Vs+VG+YrADer7sNUuCodL15M=; b=lHdBkrRLDdqSrI2R M4Xf36muJ0oNcSAz/2TRFVS/LJZWdPqa4maZ/10CiyrF6/gXSLrKLETvwai0uwMt kUjF5roCax8kJTj5vzdu3pp6+2OirSLhXwi6IgqhvmfatBrKjs/0A3Dvd561U0ZR YovF/Z9+N8qt55tZOze7XdagEWJ5pGr3eJ3BPn0ZnGArnLnUSfvpzx3sGsn9LSIV ktElPn5xQauSzITCqrQuHav3AMkPj9XJdFmp695ArHwIuauGMu6l0PcoZ2xU7vTl /P2wlGUFKUKyoDVOB9A9/tE2rAFL01tnYU+Y8GWju2A64GEeUxVcmJ3kYK5ZHcg6 67PwEQ== Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4gkcygsh81-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Thu, 10 Sep 2026 01:51:07 +0000 (GMT) Received: by mail-pl1-f197.google.com with SMTP id d9443c01a7336-2cee1ec30f2so79306345ad.3 for ; Wed, 09 Sep 2026 18:51:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1789005067; x=1789609867; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=EJT8o863eEHoJK98pu1Vs+VG+YrADer7sNUuCodL15M=; b=VrjTizf8j23TsvXENNpsM+vBoWjMLTHD0tEOsl4K3b7xOLiQ2H540xKTTtVBOf4ylH IAMraMTxNkEz1rhK6nesfkfbcmyLiB8YCdds/KTmP+PcbidwfWtCnGSn8J5eQ0c0oP20 ULeJ0z19PANPR90bLJ2acC546CN2f3ZapmzLqlpda/9GQK2P7xjfDDBsuwtqtSHvG0vu 4gaK2jdtFK3wZgZ6GvRK7mQgX67VRY6BbBYDZPNjgr0xcwjow6m5REIzZ03TcrFDY2QB kjzqaP9Vep+bUc+UcP1y7ilBa7rvXam8VfsVeiKx5HoNX/bzAHwFoH0tNHfoRdRl6TqW 7F4g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789005067; x=1789609867; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=EJT8o863eEHoJK98pu1Vs+VG+YrADer7sNUuCodL15M=; b=hTXzylhDHrShxNPolervBD2Oeol5bUUku80xZ/5sl6v047loSBmOiVjpM4j2tYAg95 8o4eQjN9Z/OUUV5NHwTlw8xwmIEI2ywa0GFWMFtKdBw1mU3144nkXselKK9+5/ms+Zku AHByKOzPTnQleiu9g+YntU3z1gZCu42JSs1/tavYVnpdHpd9FkRJqh+hlbs+jQrrKwAQ aclGat8hduF3rbnWJX0wwi4NU7VOD23DK6BXX5eduyiE4j9Ma6Lrf3gXJpZdFLIpOx9x VG52x/+7vAIG1KBBAYpkgCvy9o6mnwweqVcc3lBC6lxTQtxaVWxVDlzVcjT5Ofm3F1S3 CsbQ== X-Forwarded-Encrypted: i=1; AKwUvBwDp4grHrdgvvzvwrKhrhI/Nxa6e1aIi7Z8Epm5u5NsJSVD3kdTdngthoSNSf5gAYnAbcEUFGCKvb1mfqw=@vger.kernel.org X-Gm-Message-State: AFuF++nHKK4/deozbtvJgZiEKIoimXH0BSr+QoGvbGskfwydmUyqC1+B EEDupcEtpXEXDM2PR3tb4/k7tOO1kTROOPQ7jUV/+EEOEnNk8LWl3/ML02u7TaGi5BFNiNQm6pO QKLuD6qBfNOKt9Deg003+uyaYJDQoVeZZczPDN9CI0Q3fPt7MIOt8meEYiqGk5fMoT68= X-Gm-Gg: AYBFou0rndIjWOzf5rwzbmj1yvxuuyAyj5WPSIwW/QHWWnBYkl/rQqNe5wCFa01Al40 LcbOQWXTGGEoECWq0s3cNfkmmWlMGHGsmXU2glz0fFNBvn5c/9fcBe2GTCsue6Y1y4SgLXRFcjc 7M9SQ+8Dk6RPGowWlaO5WLPXHm5KkyD7kzal4ViFG1a/Ci6q22lcCWQ3tlrSgJY0l49bIANydey U+3YIsDlhKyr5yIlBoaYLzK2uAnGzZz2PYRaMh6C+vw0ecqirDemIU6E3xBoPDqExUsq1cmQX+B fgRSCEg89+oZZ12jUArtHURptiCIOxKGWDDzy7TkooKACvuxqrJbdbGilEXJtvJnBATfxE9/coU etmr/Wa1ddT4kcmAv8f3bMm+yknlegF9dX4L6v0FQzQpi1rcUelbd X-Received: by 2002:a17:902:cf10:b0:2d9:3636:d01a with SMTP id d9443c01a7336-2db126669d3mr560843355ad.15.1789005067297; Wed, 09 Sep 2026 18:51:07 -0700 (PDT) X-Received: by 2002:a17:902:cf10:b0:2d9:3636:d01a with SMTP id d9443c01a7336-2db126669d3mr560842685ad.15.1789005066790; Wed, 09 Sep 2026 18:51:06 -0700 (PDT) Received: from hu-wcheng-lv.qualcomm.com (Global_NAT1.qualcomm.com. [129.46.96.20]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3339aa33e96sm47446234eec.12.2026.09.09.18.51.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 18:51:05 -0700 (PDT) From: Wesley Cheng Date: Wed, 09 Sep 2026 18:50:58 -0700 Subject: [PATCH v4 2/5] usb: xhci: Allow to specify a different segment pool for allocations Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260909-16k_offload_v1_b4-v4-2-f24a86617597@oss.qualcomm.com> References: <20260909-16k_offload_v1_b4-v4-0-f24a86617597@oss.qualcomm.com> In-Reply-To: <20260909-16k_offload_v1_b4-v4-0-f24a86617597@oss.qualcomm.com> To: Mathias Nyman , Greg Kroah-Hartman , Jaroslav Kysela , Takashi Iwai , Michal Pecio Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, linux-sound@vger.kernel.org, Wesley Cheng X-Mailer: b4 0.15.2 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTEwMDAxOCBTYWx0ZWRfX7sSM1XvMUr+i JyNIMuVttmSmPfBlqp+rtIArp4/ajgzzI9m0a24AyKXL3sIQEyLttCLV/Aupm6Wp1vVZB728Gwt K67Qhop/RW6Plxb0aXf+iyRpnLGusY3u0rDZQwIqS/G4WAQQdFuIIejiaNL1NY8vrVkxSdxzqd8 UzYPNB7kdksRqK7Ctho1rdgY0u+ltp9kfPdSDdkCBOvRt4t9fk9fQTniOrwQodoCbHrI5xO4Nj9 oNkCZSRa4roGfYOtmhfpriQn4S1R68IH/eX0d/ZgVroUcH183QINszLm6M8BOmXG4np28dZWTw7 hyOi+IhDJQnwpHeIwQVV9LR+KPfaPFCPKjjd3B8U1oE12VrOiwAaF4M/GlLT1esMEYa4UMCtbiX tokr+Xhg4TT6v4Hkhs/imZYbelJ+vnMnw22q92P+h9gnfTGH3uecAOKE/Aao3+SX8YlywRp48CK tF4LqAj20+Cdp8Bfa0A== X-Proofpoint-Spam-Info: AW1haW4tMjYwOTEwMDAxOCBTYWx0ZWRfX1HCWBBRgtKtJ LsmfDrnKLonMpbIqvZB9vyn1Dh33C6TIcSZkBLmjbuIB/oIry+fzvi8l8bCf88ykOEPUH2x5YuJ OLTTPxR/IuBj/b7Cx2mpRBbyCFjUMVA= X-Proofpoint-ORIG-GUID: 8bWmvMBb094VF8FRYhleZ72B4iV11-K7 X-Authority-Analysis: v=2.4 cv=VONIDNPX c=1 sm=1 tr=0 ts=6aa20d0c cx=c_pps a=cmESyDAEBpBGqyK7t0alAg==:117 a=ouPCqIW2jiPt+lZRy3xVPw==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=yOCtJkima9RkubShWh1s:22 a=EUspDBNiAAAA:8 a=qt4-_lkRHfeKUwQPRJsA:9 a=QEXdDO2ut3YA:10 a=1OuFwYUASf3TG4hYMiVC:22 X-Proofpoint-GUID: 8bWmvMBb094VF8FRYhleZ72B4iV11-K7 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-10_01,2026-09-09_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 adultscore=0 phishscore=0 priorityscore=1501 bulkscore=0 clxscore=1015 suspectscore=0 lowpriorityscore=0 spamscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2609040000 definitions=main-2609100018 Ring segments are normally allocated from a shared DMA pool sized and aligned to TRB_SEGMENT_SIZE (4096 bytes). On kernels built with a larger PAGE_SIZE (e.g. 16K or 64K page arches), a segment can end up at a non-page-aligned offset within its enclosing CPU page, and multiple segments can share the same physical page. Modify existing xHCI allocation operations to accommodate for a separate DMA pool for segment allocations. This will safely partition ownership of segments between Linux xHCI and offload entities. Assisted-by: Claude:claude-sonnet-5 Signed-off-by: Wesley Cheng --- drivers/usb/host/xhci-mem.c | 63 ++++++++++++++++++++++++++----------= ---- drivers/usb/host/xhci-sideband.c | 4 +-- drivers/usb/host/xhci.h | 6 +++- 3 files changed, 48 insertions(+), 25 deletions(-) diff --git a/drivers/usb/host/xhci-mem.c b/drivers/usb/host/xhci-mem.c index 7a21ac81f9c8..6e52cefd6619 100644 --- a/drivers/usb/host/xhci-mem.c +++ b/drivers/usb/host/xhci-mem.c @@ -28,6 +28,7 @@ * "All components of all Command and Transfer TRBs shall be initialized t= o '0'" */ static struct xhci_segment *xhci_segment_alloc(struct xhci_hcd *xhci, + struct dma_pool *pool, unsigned int max_packet, unsigned int num, gfp_t flags) @@ -40,7 +41,7 @@ static struct xhci_segment *xhci_segment_alloc(struct xhc= i_hcd *xhci, if (!seg) return NULL; =20 - seg->trbs =3D dma_pool_zalloc(xhci->segment_pool, flags, &dma); + seg->trbs =3D dma_pool_zalloc(pool, flags, &dma); if (!seg->trbs) { kfree(seg); return NULL; @@ -50,7 +51,7 @@ static struct xhci_segment *xhci_segment_alloc(struct xhc= i_hcd *xhci, seg->bounce_buf =3D kzalloc_node(max_packet, flags, dev_to_node(dev)); if (!seg->bounce_buf) { - dma_pool_free(xhci->segment_pool, seg->trbs, dma); + dma_pool_free(pool, seg->trbs, dma); kfree(seg); return NULL; } @@ -62,10 +63,11 @@ static struct xhci_segment *xhci_segment_alloc(struct x= hci_hcd *xhci, return seg; } =20 -static void xhci_segment_free(struct xhci_hcd *xhci, struct xhci_segment *= seg) +static void xhci_segment_free(struct xhci_hcd *xhci, struct dma_pool *pool, + struct xhci_segment *seg) { if (seg->trbs) { - dma_pool_free(xhci->segment_pool, seg->trbs, seg->dma); + dma_pool_free(pool, seg->trbs, seg->dma); seg->trbs =3D NULL; } kfree(seg->bounce_buf); @@ -81,7 +83,7 @@ static void xhci_ring_segments_free(struct xhci_hcd *xhci= , struct xhci_ring *rin =20 while (seg) { next =3D seg->next; - xhci_segment_free(xhci, seg); + xhci_segment_free(xhci, ring->segment_pool, seg); seg =3D next; } } @@ -334,7 +336,7 @@ static int xhci_alloc_segments_for_ring(struct xhci_hcd= *xhci, struct xhci_ring struct xhci_segment *prev; unsigned int num =3D 0; =20 - prev =3D xhci_segment_alloc(xhci, ring->bounce_buf_len, num, flags); + prev =3D xhci_segment_alloc(xhci, ring->segment_pool, ring->bounce_buf_le= n, num, flags); if (!prev) return -ENOMEM; num++; @@ -343,7 +345,8 @@ static int xhci_alloc_segments_for_ring(struct xhci_hcd= *xhci, struct xhci_ring while (num < ring->num_segs) { struct xhci_segment *next; =20 - next =3D xhci_segment_alloc(xhci, ring->bounce_buf_len, num, flags); + next =3D xhci_segment_alloc(xhci, ring->segment_pool, ring->bounce_buf_l= en, + num, flags); if (!next) goto free_segments; =20 @@ -362,15 +365,10 @@ static int xhci_alloc_segments_for_ring(struct xhci_h= cd *xhci, struct xhci_ring return -ENOMEM; } =20 -/* - * Create a new ring with zero or more segments. - * - * Link each segment together into a ring. - * Set the end flag and the cycle toggle bit on the last segment. - * See section 4.9.1 and figures 15 and 16. - */ -struct xhci_ring *xhci_ring_alloc(struct xhci_hcd *xhci, unsigned int num_= segs, - enum xhci_ring_type type, unsigned int max_packet, gfp_t flags) +static struct xhci_ring * +xhci_ring_alloc_from_pool(struct xhci_hcd *xhci, unsigned int num_segs, + enum xhci_ring_type type, unsigned int max_packet, + struct dma_pool *pool, gfp_t flags) { struct xhci_ring *ring; int ret; @@ -382,6 +380,7 @@ struct xhci_ring *xhci_ring_alloc(struct xhci_hcd *xhci= , unsigned int num_segs, =20 ring->num_segs =3D num_segs; ring->bounce_buf_len =3D max_packet; + ring->segment_pool =3D pool; INIT_LIST_HEAD(&ring->td_list); ring->type =3D type; if (num_segs =3D=3D 0) @@ -398,6 +397,20 @@ struct xhci_ring *xhci_ring_alloc(struct xhci_hcd *xhc= i, unsigned int num_segs, return NULL; } =20 +/* + * Create a new ring with zero or more segments. + * + * Link each segment together into a ring. + * Set the end flag and the cycle toggle bit on the last segment. + * See section 4.9.1 and figures 15 and 16. + */ +struct xhci_ring *xhci_ring_alloc(struct xhci_hcd *xhci, unsigned int num_= segs, + enum xhci_ring_type type, unsigned int max_packet, gfp_t flags) +{ + return xhci_ring_alloc_from_pool(xhci, num_segs, type, max_packet, + xhci->segment_pool, flags); +} + void xhci_free_endpoint_ring(struct xhci_hcd *xhci, struct xhci_virt_device *virt_dev, unsigned int ep_index) @@ -422,6 +435,7 @@ int xhci_ring_expansion(struct xhci_hcd *xhci, struct x= hci_ring *ring, new_ring.num_segs =3D num_new_segs; new_ring.bounce_buf_len =3D ring->bounce_buf_len; new_ring.type =3D ring->type; + new_ring.segment_pool =3D ring->segment_pool; ret =3D xhci_alloc_segments_for_ring(xhci, &new_ring, flags); if (ret) return -ENOMEM; @@ -1424,6 +1438,7 @@ int xhci_endpoint_init(struct xhci_hcd *xhci, unsigned int mult; unsigned int avg_trb_len; unsigned int err_count =3D 0; + struct dma_pool *pool; =20 ep_index =3D xhci_get_endpoint_index(&ep->desc); ep_ctx =3D xhci_get_ep_ctx(xhci, virt_dev->in_ctx, ep_index); @@ -1487,8 +1502,10 @@ int xhci_endpoint_init(struct xhci_hcd *xhci, avg_trb_len =3D 8; =20 /* Set up the endpoint ring */ + pool =3D virt_dev->eps[ep_index].priv_seg_pool ? + virt_dev->eps[ep_index].priv_seg_pool : xhci->segment_pool; virt_dev->eps[ep_index].new_ring =3D - xhci_ring_alloc(xhci, 2, ring_type, max_packet, mem_flags); + xhci_ring_alloc_from_pool(xhci, 2, ring_type, max_packet, pool, mem_flag= s); if (!virt_dev->eps[ep_index].new_ring) return -ENOMEM; =20 @@ -2291,7 +2308,8 @@ static int xhci_setup_port_arrays(struct xhci_hcd *xh= ci, gfp_t flags) } =20 static struct xhci_interrupter * -xhci_alloc_interrupter(struct xhci_hcd *xhci, unsigned int segs, gfp_t fla= gs) +xhci_alloc_interrupter(struct xhci_hcd *xhci, unsigned int segs, + struct dma_pool *pool, gfp_t flags) { struct device *dev =3D xhci_to_hcd(xhci)->self.sysdev; struct xhci_interrupter *ir; @@ -2308,7 +2326,7 @@ xhci_alloc_interrupter(struct xhci_hcd *xhci, unsigne= d int segs, gfp_t flags) if (!ir) return NULL; =20 - ir->event_ring =3D xhci_ring_alloc(xhci, segs, TYPE_EVENT, 0, flags); + ir->event_ring =3D xhci_ring_alloc_from_pool(xhci, segs, TYPE_EVENT, 0, p= ool, flags); if (!ir->event_ring) { xhci_warn(xhci, "Failed to allocate interrupter event ring\n"); kfree(ir); @@ -2356,7 +2374,8 @@ void xhci_add_interrupter(struct xhci_hcd *xhci, unsi= gned int intr_num) =20 struct xhci_interrupter * xhci_create_secondary_interrupter(struct usb_hcd *hcd, unsigned int segs, - u32 imod_interval, unsigned int intr_num) + struct dma_pool *pool, u32 imod_interval, + unsigned int intr_num) { struct xhci_hcd *xhci =3D hcd_to_xhci(hcd); struct xhci_interrupter *ir; @@ -2367,7 +2386,7 @@ xhci_create_secondary_interrupter(struct usb_hcd *hcd= , unsigned int segs, intr_num >=3D xhci->max_interrupters) return NULL; =20 - ir =3D xhci_alloc_interrupter(xhci, segs, GFP_KERNEL); + ir =3D xhci_alloc_interrupter(xhci, segs, pool ? pool : xhci->segment_poo= l, GFP_KERNEL); if (!ir) return NULL; =20 @@ -2498,7 +2517,7 @@ int xhci_mem_init(struct xhci_hcd *xhci, gfp_t flags) if (!xhci->interrupters) goto fail; =20 - xhci->interrupters[0] =3D xhci_alloc_interrupter(xhci, 0, flags); + xhci->interrupters[0] =3D xhci_alloc_interrupter(xhci, 0, xhci->segment_p= ool, flags); if (!xhci->interrupters[0]) goto fail; =20 diff --git a/drivers/usb/host/xhci-sideband.c b/drivers/usb/host/xhci-sideb= and.c index beb637407e47..274da38f333d 100644 --- a/drivers/usb/host/xhci-sideband.c +++ b/drivers/usb/host/xhci-sideband.c @@ -315,8 +315,8 @@ xhci_sideband_create_interrupter(struct xhci_sideband *= sb, int num_seg, return -EBUSY; =20 sb->ir =3D xhci_create_secondary_interrupter(xhci_to_hcd(sb->xhci), - num_seg, imod_interval, - intr_num); + num_seg, NULL, + imod_interval, intr_num); if (!sb->ir) return -ENOMEM; =20 diff --git a/drivers/usb/host/xhci.h b/drivers/usb/host/xhci.h index c7bfa7f028d3..15ce0bb7aa3f 100644 --- a/drivers/usb/host/xhci.h +++ b/drivers/usb/host/xhci.h @@ -709,6 +709,8 @@ struct xhci_virt_ep { bool use_extended_tbc; /* set if this endpoint is controlled via sideband access*/ struct xhci_sideband *sideband; + /* dma pool to allocate this endpoint's ring segments from, if set */ + struct dma_pool *priv_seg_pool; }; =20 enum xhci_overhead_type { @@ -1380,6 +1382,7 @@ struct xhci_ring { enum xhci_ring_type type; u32 old_trb_comp_code; struct radix_tree_root *trb_address_map; + struct dma_pool *segment_pool; }; =20 struct xhci_erst_entry { @@ -1865,7 +1868,8 @@ void xhci_free_port_bw_ctx(struct xhci_hcd *xhci, struct xhci_container_ctx *ctx); struct xhci_interrupter * xhci_create_secondary_interrupter(struct usb_hcd *hcd, unsigned int segs, - u32 imod_interval, unsigned int intr_num); + struct dma_pool *pool, u32 imod_interval, + unsigned int intr_num); void xhci_remove_secondary_interrupter(struct usb_hcd *hcd, struct xhci_interrupter *ir); void xhci_skip_sec_intr_events(struct xhci_hcd *xhci, --=20 2.34.1 From nobody Fri Sep 25 17:49:58 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 78019375F81 for ; Thu, 10 Sep 2026 01:51:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789005072; cv=none; b=Zn+mvf2oxpPi75bFyiCFrNzQaHNdwwtNbThObYVjWskysv0k/kcpyP1qFr0X7sTMX00TUrlQvg0vralUnFm6CV/H6dE6usaOP1FhwOQBTJhRSeQG9UVFU3JTq3j1Zmc0rUUSEgCcDwDs3kOgixQRM/EdlLXsZBRaFw9CvyP7fDQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789005072; c=relaxed/simple; bh=ErTbnNhn3Icw19SWQ9dG6pRskDLs8W/CJuJN2DZ3Byo=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=SjZ9zRrZ9tRwig5YWfypGy/+SCzNkTJPK1Mpxb/G4z+P7lTBHLKLWPgkb5g94bt6MjYau1gAFqHL0PEnNvuLLsAHKDwZg5NS4t/QbTYe6NJ9t1ZIgAjWYMvMQimMrHI5r4HksJziG5R3uZlLU6HkSByTT8PdhliIg1w2/aj0oeo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=QCZ2aePf; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=Pr9mo189; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="QCZ2aePf"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="Pr9mo189" Received: from pps.filterd (m0279866.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 68A1l9U03029817 for ; Thu, 10 Sep 2026 01:51:09 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= imASvVJhKjiXPIqBSU3/Ev92EBtBW9MXWBIV8CDpb68=; b=QCZ2aePfCwk6CkJi eG7ML5uKb0zrPnRjAAExEo9Ux5kKKFXBMYoTL/5Wg/QSRXDXqIoHU49hgEhz5orm U4KVypIiOXJpsi0IPEJoHHhfEpQm9e7fxKruI/jkg8HyrBOO7B8G3I5T1R9VGT0L f5uU7sZNZhj432s+OQN/50wQacMZUTLhTG5ewGBHNom7UyZLPs2kULRpl/VOWmQt FLhyJyltuObi1ljvBktFF0+0Ou2+xxmUnSB0erP/legyYl4Z7zo5z+D1B9VvcDCl nJr1nHpmKGxtCqR5b4hT/IsErE0r42mW7HiqggJm1uaaWDNlKWepzB1zVz63b3go 4ClKFg== Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4gkcyehgbr-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Thu, 10 Sep 2026 01:51:09 +0000 (GMT) Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-39af92138f9so1002492a91.0 for ; Wed, 09 Sep 2026 18:51:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1789005069; x=1789609869; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=imASvVJhKjiXPIqBSU3/Ev92EBtBW9MXWBIV8CDpb68=; b=Pr9mo189r47dZqaCiSBNEMXcZJ8OWCxR3vDiBXhMBIMYEUhxd+YFREePSF49BKkkP+ enLs//NKwk6//ex+iGPGp1WJGMf2wFY/fjOizkVKc1Sk404h2GXTIqB9X6jyKq6Z14IY cOg1Q2+gj22UgizmdXPCnFH9WjzmTfs1lbFzdV+jGXd4zoGc7psV+bJgZiCKAoEWltIi 6cXRY8AHAzirEscNxt4vE0fE1frbu+jIWCe6FFJxs8SdxdSbpXHivsww3rD9eNNoUKMo AjxYhiNi/sbk6pPLa/bp7N0P6AzUgi1VpB23/5JKgU/ollEDJzDWygpyV6roGuLkXnT4 G9cA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789005069; x=1789609869; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=imASvVJhKjiXPIqBSU3/Ev92EBtBW9MXWBIV8CDpb68=; b=lEaGvORC+CfkNtjd3LxMxPRcB3oIki1hMlH04OcQ+cHsuIMr+uPn2l5uaSas62Ah6u QsFWD8EktFt4tJPlfKKsSq0EWrSNyQD9x7iTbIEbKGBERmKvC3y5UXY0v8+U/aQfXIde LJJfW3WASll9YeYaJmbcX4Xtm+ujTy8TlhDsXUWOkVeAXrS5WnCoh9/RnYawV5AWvRwB xdordAwQEs20I9Z0NyWEFtegqfNClWGdFZR/7f4kndJLTG04zKR6i9CbTgyXQ7svKE8Q EvCGc1/biRIRJPb039FoyUo+fhLeTl3UMupQ3mJjm3dssKiLhwgm3cOKGjr8oYSm+LMe SbVA== X-Forwarded-Encrypted: i=1; AKwUvBwIywwysp7IBVA6p8U2rtFvOD9Pj4IPHiM1KtQWXRxDhtCsFomA9ehmu0jQr8ad95johOsqeqBXsG+UQJU=@vger.kernel.org X-Gm-Message-State: AFuF++mAzvqKwYFYOaVaqPK/Nw10IuRCuG09+V0RlwYWmM3Er+ioPfl9 BPjlAyzVTb8G03kqQ4WZ9yS9yo1HwXSzWkbxkoFFuBk6sPIynUsU5SOBBI/bF118DXTrE4CdBRA IrtY36y5/+77NfgB1RaVYgBlxRPxzCUDBOqHHHkf+r2qNiRw+VgrNPBf7sCW5VujYN60= X-Gm-Gg: AYBFou2Y4Y8q2AWr7zbcifYyGCySa3Q/f8uZiqOxR0r3pZfFzyiw9yw06vJc2ywpMZL 1JYcxkDVRyv0Fihznn03jaIEhDi0JyLkwigz22JLSQ4UqNcLlnJ0XyUDbfn/HWEMLvc99vJPFUE fz6MdGRpbIM8tIdX/h2ODu7WOOtHGHjQtctx+xnBI/ZNdnBQmhI87pn6DolnaqU2YuFBLfOPqYJ vtw40Be7rn7yCoWmtkY8BmraxJhaLUU4Ocr2hGYzaXoT1DlMRlPuthB576oRcD+v+jnOD25O7Cw 3Eyf1yIk6vIp7NM8yKFRuJ9D57EAYdHUos7zS8Ezb2d40I95BmA9DbV6eptSOIO8cOarhoeKuRN 2rebT0GqEuUzKYjOdGDXn4GOS2cbMOPAFUGOaoRKw/3QB4FW3rKR2 X-Received: by 2002:a17:90a:fc4f:b0:396:669c:b5f6 with SMTP id 98e67ed59e1d1-39d7796cf16mr2864267a91.12.1789005068366; Wed, 09 Sep 2026 18:51:08 -0700 (PDT) X-Received: by 2002:a17:90a:fc4f:b0:396:669c:b5f6 with SMTP id 98e67ed59e1d1-39d7796cf16mr2864217a91.12.1789005067781; Wed, 09 Sep 2026 18:51:07 -0700 (PDT) Received: from hu-wcheng-lv.qualcomm.com (Global_NAT1.qualcomm.com. [129.46.96.20]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3339aa33e96sm47446234eec.12.2026.09.09.18.51.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 18:51:07 -0700 (PDT) From: Wesley Cheng Date: Wed, 09 Sep 2026 18:50:59 -0700 Subject: [PATCH v4 3/5] usb: xhci: sideband: allocate sideband ring segments from a dedicated pool Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260909-16k_offload_v1_b4-v4-3-f24a86617597@oss.qualcomm.com> References: <20260909-16k_offload_v1_b4-v4-0-f24a86617597@oss.qualcomm.com> In-Reply-To: <20260909-16k_offload_v1_b4-v4-0-f24a86617597@oss.qualcomm.com> To: Mathias Nyman , Greg Kroah-Hartman , Jaroslav Kysela , Takashi Iwai , Michal Pecio Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, linux-sound@vger.kernel.org, Wesley Cheng X-Mailer: b4 0.15.2 X-Proofpoint-Spam-Info: AW1haW4tMjYwOTEwMDAxOCBTYWx0ZWRfXw/EcGHbT6EnA Z/Nlbm6406pKOycSH1F3VuNVNUWd645u1kWH7DIwXEeO2jucJIf9DoHpYYBcV79Gmg7aYOxuapx 7GpQ+n2MxndpqqDxEEPePW30Wcx8oU0= X-Proofpoint-GUID: p40H5Pux7vBJIDUm3JVo5qoKzzrA1dMV X-Proofpoint-ORIG-GUID: p40H5Pux7vBJIDUm3JVo5qoKzzrA1dMV X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTEwMDAxOCBTYWx0ZWRfX7sdPTwLhUkE9 y7snTgrGMlzYLc7M0qnPTIWMNPzNMpreajs3Xr9fzBrQhl/+ycOTgLFf6WUbo1RPFRdIFE5RsGy bz3CRTv8w326/dhuIqblFVfdwNYgBpHruIffmfdkqDyPBKuYsexkHx5zzMhIJR9tnPMK76ivCf4 l7LLkj3Dz+Dy6fgukBqTJ+M3maON0qi+HasItI5q80eksDG4QWIbOLhwLyeD21gMqqevAcxkADu zULknEpfUuwKuggrOzo4lNq2m9wxRpC+HyHH8TI2OO8+HPGo5nnw/B5rBzGlMYurtceJnlas55m oA4cHrBbXb0yyTg4Ii8dWdm5+W+UdI1RHq1Y+14uCEnPtVgct7Q8gRtdkGxoURdDmzaAquf0fhT RGQvYhGf3CHvcFbja6RW/7cJ/uK8UPZbWZfFzw8UTJCi7FvnJsxSq+S94T0OvSO2Rn+frTJcBQ8 hBWpwIx2EwOJF1NTcdA== X-Authority-Analysis: v=2.4 cv=Go/XaU1C c=1 sm=1 tr=0 ts=6aa20d0d cx=c_pps a=vVfyC5vLCtgYJKYeQD43oA==:117 a=ouPCqIW2jiPt+lZRy3xVPw==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=YMgV9FUhrdKAYTUUvYB2:22 a=EUspDBNiAAAA:8 a=4UCl4-NCj7P3W_cXDs0A:9 a=QEXdDO2ut3YA:10 a=rl5im9kqc5Lf4LNbBjHf:22 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-10_01,2026-09-09_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 priorityscore=1501 lowpriorityscore=0 suspectscore=0 clxscore=1015 spamscore=0 bulkscore=0 malwarescore=0 impostorscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2609040000 definitions=main-2609100018 A sideband client that maps a ring buffer directly via the IOMMU (which operates at page granularity) needs to know exactly which page(s) back the ring, and only pages that are actually intended to be exposed to that client should ever be mapped this way. Allow each xhci_sideband endpoint to pass its own segment_pool, allocated separately from the core xhci->segment_pool, so every segment backing a sideband-tagged endpoint always comes from a page that is meant to be visible by the entity handling the offloaded endpoints. Normal (non-offloaded) endpoints are unaffected, as they keep allocating from xhci->segment_pool. The offload client owns the pool's full lifetime, and since that lifetime is no longer tied to the sideband instance itself, xhci_sideband_unregister() must free any ring still backed by a client-supplied pool before returning, rather than leaving it for xhci to free later when the client and its pool may already be gone. Assisted-by: Claude:claude-sonnet-5 Signed-off-by: Wesley Cheng --- drivers/usb/host/xhci-sideband.c | 38 +++++++++++++++++++++++++++++++++++= --- drivers/usb/host/xhci.h | 10 +++------- include/linux/usb/xhci-sideband.h | 20 +++++++++++++++++--- sound/usb/qcom/qc_audio_offload.c | 32 ++++++++++++++++++++++++++++---- 4 files changed, 83 insertions(+), 17 deletions(-) diff --git a/drivers/usb/host/xhci-sideband.c b/drivers/usb/host/xhci-sideb= and.c index 274da38f333d..1bb6e5034b58 100644 --- a/drivers/usb/host/xhci-sideband.c +++ b/drivers/usb/host/xhci-sideband.c @@ -9,6 +9,7 @@ */ =20 #include +#include =20 #include "xhci.h" =20 @@ -67,6 +68,7 @@ __xhci_sideband_remove_endpoint(struct xhci_sideband *sb,= struct xhci_virt_ep *e xhci_stop_endpoint_sync(sb->xhci, ep, 0, GFP_KERNEL); =20 ep->sideband =3D NULL; + ep->priv_seg_pool =3D NULL; sb->eps[ep->ep_index] =3D NULL; } =20 @@ -113,6 +115,8 @@ EXPORT_SYMBOL_GPL(xhci_sideband_notify_ep_ring_free); * xhci_sideband_add_endpoint - add endpoint to sideband access list * @sb: sideband instance for this usb device * @host_ep: usb host endpoint + * @pool: dma pool to allocate this endpoint's ring segments from, or NULL + * to leave the endpoint's current pool selection untouched * * Adds an endpoint to the list of sideband accessed endpoints for this usb * device. @@ -123,7 +127,8 @@ EXPORT_SYMBOL_GPL(xhci_sideband_notify_ep_ring_free); */ int xhci_sideband_add_endpoint(struct xhci_sideband *sb, - struct usb_host_endpoint *host_ep) + struct usb_host_endpoint *host_ep, + struct dma_pool *pool) { struct xhci_virt_ep *ep; unsigned int ep_index; @@ -153,6 +158,9 @@ xhci_sideband_add_endpoint(struct xhci_sideband *sb, ep->sideband =3D sb; sb->eps[ep_index] =3D ep; =20 + if (pool) + ep->priv_seg_pool =3D pool; + return 0; } EXPORT_SYMBOL_GPL(xhci_sideband_add_endpoint); @@ -288,6 +296,7 @@ EXPORT_SYMBOL_GPL(xhci_sideband_check); * xhci_sideband_create_interrupter - creates a new interrupter for this s= ideband * @sb: sideband instance for this usb device * @num_seg: number of event ring segments to allocate + * @pool: dma pool to allocate the interrupter's event ring segments from * @ip_autoclear: IP autoclearing support such as MSI implemented * * Sets up a xhci interrupter that can be used for this sideband accessed = usb @@ -301,7 +310,8 @@ EXPORT_SYMBOL_GPL(xhci_sideband_check); */ int xhci_sideband_create_interrupter(struct xhci_sideband *sb, int num_seg, - bool ip_autoclear, u32 imod_interval, int intr_num) + struct dma_pool *pool, bool ip_autoclear, + u32 imod_interval, int intr_num) { if (!sb || !sb->xhci) return -ENODEV; @@ -315,7 +325,7 @@ xhci_sideband_create_interrupter(struct xhci_sideband *= sb, int num_seg, return -EBUSY; =20 sb->ir =3D xhci_create_secondary_interrupter(xhci_to_hcd(sb->xhci), - num_seg, NULL, + num_seg, pool, imod_interval, intr_num); if (!sb->ir) return -ENOMEM; @@ -370,6 +380,8 @@ EXPORT_SYMBOL_GPL(xhci_sideband_interrupter_id); /** * xhci_sideband_register - register a sideband for a usb device * @intf: usb interface associated with the sideband device + * @type: xHCI sideband type + * @notify_client: callback for xHCI sideband sequences * * Allows for clients to utilize XHCI interrupters and fetch transfer and = event * ring parameters for executing data transfers. @@ -436,6 +448,15 @@ EXPORT_SYMBOL_GPL(xhci_sideband_register); * After this the endpoint and interrupter event buffers should no longer * be accessed via sideband. The xhci driver can now take over handling * the buffers. + * Any transfer ring allocated from a client supplied dma pool is freed he= re + * as well, as the client is not expected to keep that pool alive any long= er + * than this call. This includes rings of endpoints already removed with + * xhci_sideband_remove_endpoint(), which xhci would otherwise only free o= nce + * the device is reconfigured or torn down, i.e. after the client is gone. + * + * The caller must ensure the usb device is no longer streaming through the + * normal, non-sideband path when calling this, as the freed rings are sti= ll + * referenced by the endpoint contexts until xhci reconfigures the device. */ void xhci_sideband_unregister(struct xhci_sideband *sb) @@ -458,6 +479,17 @@ xhci_sideband_unregister(struct xhci_sideband *sb) if (sb->eps[i]) __xhci_sideband_remove_endpoint(sb, sb->eps[i]); =20 + spin_lock_irq(&xhci->lock); + for (i =3D 0; i < EP_CTX_PER_DEV; i++) { + struct xhci_ring *ring =3D vdev->eps[i].ring; + + if (ring && ring->segment_pool !=3D xhci->segment_pool) { + xhci_ring_free(xhci, ring); + vdev->eps[i].ring =3D NULL; + } + } + spin_unlock_irq(&xhci->lock); + __xhci_sideband_remove_interrupter(sb); =20 sb->vdev =3D NULL; diff --git a/drivers/usb/host/xhci.h b/drivers/usb/host/xhci.h index 15ce0bb7aa3f..1353d6fa2776 100644 --- a/drivers/usb/host/xhci.h +++ b/drivers/usb/host/xhci.h @@ -19,6 +19,7 @@ #include #include #include +#include =20 /* Code sharing between pci-quirks and xhci hcd */ #include "xhci-ext-caps.h" @@ -740,8 +741,6 @@ struct xhci_interval_bw_table { unsigned int ss_bw_out; }; =20 -#define EP_CTX_PER_DEV 31 - struct xhci_virt_device { int slot_id; struct usb_device *udev; @@ -1255,14 +1254,11 @@ static inline const char *xhci_trb_type_string(u8 t= ype) #define NEC_FW_MAJOR(p) (((p) >> 8) & 0xff) =20 /* - * TRBS_PER_SEGMENT must be a multiple of 4, - * since the command ring is 64-byte aligned. - * It must also be greater than 16. + * TRBS_PER_SEGMENT and TRB_SEGMENT_SIZE are defined in + * , shared with sideband client drivers. */ -#define TRBS_PER_SEGMENT 256 /* Allow two commands + a link TRB, along with any reserved command TRBs */ #define MAX_RSVD_CMD_TRBS (TRBS_PER_SEGMENT - 3) -#define TRB_SEGMENT_SIZE (TRBS_PER_SEGMENT*16) #define TRB_SEGMENT_SHIFT (ilog2(TRB_SEGMENT_SIZE)) /* TRB buffer pointers can't cross 64KB boundaries */ #define TRB_MAX_BUFF_SHIFT 16 diff --git a/include/linux/usb/xhci-sideband.h b/include/linux/usb/xhci-sid= eband.h index 005257085dcb..6d318e6a3bf6 100644 --- a/include/linux/usb/xhci-sideband.h +++ b/include/linux/usb/xhci-sideband.h @@ -13,7 +13,19 @@ #include #include =20 -#define EP_CTX_PER_DEV 31 /* FIXME defined twice, from xhci.h */ +/* + * Constants shared with the xHCI host driver (drivers/usb/host/xhci.h), + * which includes this header for its canonical definitions. + */ +#define EP_CTX_PER_DEV 31 + +/* + * TRBS_PER_SEGMENT must be a multiple of 4, + * since the command ring is 64-byte aligned. + * It must also be greater than 16. + */ +#define TRBS_PER_SEGMENT 256 +#define TRB_SEGMENT_SIZE (TRBS_PER_SEGMENT * 16) =20 struct xhci_sideband; =20 @@ -72,7 +84,8 @@ void xhci_sideband_unregister(struct xhci_sideband *sb); int xhci_sideband_add_endpoint(struct xhci_sideband *sb, - struct usb_host_endpoint *host_ep); + struct usb_host_endpoint *host_ep, + struct dma_pool *pool); int xhci_sideband_remove_endpoint(struct xhci_sideband *sb, struct usb_host_endpoint *host_ep); @@ -94,7 +107,8 @@ static inline bool xhci_sideband_check(struct usb_hcd *h= cd) =20 int xhci_sideband_create_interrupter(struct xhci_sideband *sb, int num_seg, - bool ip_autoclear, u32 imod_interval, int intr_num); + struct dma_pool *pool, bool ip_autoclear, + u32 imod_interval, int intr_num); void xhci_sideband_remove_interrupter(struct xhci_sideband *sb); int diff --git a/sound/usb/qcom/qc_audio_offload.c b/sound/usb/qcom/qc_audio_of= fload.c index e4bfd43a2488..c94b15423a9a 100644 --- a/sound/usb/qcom/qc_audio_offload.c +++ b/sound/usb/qcom/qc_audio_offload.c @@ -7,6 +7,7 @@ #include #include #include +#include #include #include #include @@ -131,6 +132,7 @@ struct uaudio_dev { =20 /* xhci sideband */ struct xhci_sideband *sb; + struct dma_pool *segment_pool; =20 /* SoC USB device */ struct snd_soc_usb_device *sdev; @@ -1140,7 +1142,8 @@ uaudio_endpoint_setup(struct snd_usb_substream *subs, =20 memcpy(ep_desc, &ep->desc, sizeof(ep->desc)); =20 - ret =3D xhci_sideband_add_endpoint(uadev[card_num].sb, ep); + ret =3D xhci_sideband_add_endpoint(uadev[card_num].sb, ep, + uadev[card_num].segment_pool); if (ret < 0) { dev_err(&subs->dev->dev, "failed to add data ep to sec intr: %d\n", ret); @@ -1211,8 +1214,9 @@ static int uaudio_event_ring_setup(struct snd_usb_sub= stream *subs, goto exit; =20 /* event ring */ - ret =3D xhci_sideband_create_interrupter(uadev[card_num].sb, 1, false, - 0, uaudio_qdev->data->intr_num); + ret =3D xhci_sideband_create_interrupter(uadev[card_num].sb, 1, + uadev[card_num].segment_pool, + false, 0, uaudio_qdev->data->intr_num); if (ret < 0) { dev_err(&subs->dev->dev, "failed to fetch interrupter\n"); goto put_offload; @@ -1786,6 +1790,7 @@ static void qc_usb_audio_offload_probe(struct snd_usb= _audio *chip) struct usb_interface_descriptor *altsd; struct usb_host_interface *alts; struct snd_soc_usb_device *sdev; + struct dma_pool *segment_pool; struct xhci_sideband *sb; =20 /* @@ -1804,10 +1809,21 @@ static void qc_usb_audio_offload_probe(struct snd_u= sb_audio *chip) if (!sdev) return; =20 + segment_pool =3D dma_pool_create("xHCI sideband ring segments", + interface_to_usbdev(intf)->bus->sysdev, + TRB_SEGMENT_SIZE, TRB_SEGMENT_SIZE, + TRB_SEGMENT_SIZE); + if (!segment_pool) + goto free_sdev; + sb =3D xhci_sideband_register(intf, XHCI_SIDEBAND_VENDOR, uaudio_sideband_notifier); - if (!sb) + if (!sb) { + dma_pool_destroy(segment_pool); goto free_sdev; + } + + uadev[chip->card->number].segment_pool =3D segment_pool; } else { sb =3D uadev[chip->card->number].sb; sdev =3D uadev[chip->card->number].sdev; @@ -1844,8 +1860,11 @@ static void qc_usb_audio_offload_probe(struct snd_us= b_audio *chip) return; =20 unreg_xhci: + segment_pool =3D uadev[chip->card->number].segment_pool; xhci_sideband_unregister(sb); + dma_pool_destroy(segment_pool); uadev[chip->card->number].sb =3D NULL; + uadev[chip->card->number].segment_pool =3D NULL; free_sdev: kfree(sdev); uadev[chip->card->number].sdev =3D NULL; @@ -1905,8 +1924,13 @@ static void qc_usb_audio_offload_disconnect(struct s= nd_usb_audio *chip) * This is to accommodate for devices w/ multiple UAC functions. */ if (chip->num_interfaces =3D=3D 1) { + struct dma_pool *segment_pool =3D dev->segment_pool; + snd_soc_usb_disconnect(uaudio_qdev->auxdev->dev.parent, dev->sdev); xhci_sideband_unregister(dev->sb); + dma_pool_destroy(segment_pool); + dev->sb =3D NULL; + dev->segment_pool =3D NULL; dev->chip =3D NULL; kfree(dev->sdev->ppcm_idx); kfree(dev->sdev); --=20 2.34.1 From nobody Fri Sep 25 17:49:58 2026 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D32B4376A12 for ; Thu, 10 Sep 2026 01:51:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789005074; cv=none; b=VE5tkdeCCQOBp3u4u4Yjv/IBDucVwZ0j2ckrMOkzDDqtkIW+YG++btYv59FYWGPUW975hcm0savEM/tyg7rejXwPsWNVCseDuhbH4Ratj4AVQFzAhu8joOzqwRgNe7Q7oSDEEHhB4gxr3q2WnmFbGPnqAoNZpcmsav0PmSlf+Wk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789005074; c=relaxed/simple; bh=QiWwIdap7asM25atMCh4cE80kDP0AIHyDVgphgNTl8o=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Vd8a06d0qXG/C9PVeFmvcDhNpbd25eb+7YD8R2XcsxW38anzysJXN3SO9KzwPp2Qko4wCNPa6oN52DUQNX4/rLjrDY35PoKFT1ppQGn6fqRCeXkJWvb/jIYmHrbVn10Ps5p7spzIibrtqjdxLzXRvP1/PF0udcfztl98BkQOWlw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=kdThvFpO; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=NlmxhEsK; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="kdThvFpO"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="NlmxhEsK" Received: from pps.filterd (m0279872.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 68A1lFNt3063455 for ; Thu, 10 Sep 2026 01:51:10 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= VdLMLU0lIE2FaCyPNgoMNNA59jScOU92wfwmF9t9O/A=; b=kdThvFpOM3fx/Fb0 5Qe7+3TD5LES9iEl+rPlTDXpqKLwp3lUGaDaZHs387YF1ANoEkRLKR6/zQATOClb TWL76mwc6fhKYQrjju41TXVPEUlX+YrWt3Mmoun66nJev4c8FoklXYfPuExca+RZ A2lE1tY/wjRdee61R/TC5BU5jBGDLrD7qc6bTop1bx1U5flID41jq0LmU3U8MN0y rLLewRM9sEbSN5dHBqimCdX7wqckfJtjLxjAhTHtgAaunkwqYNZKR2mkmFbMP99k edmCqwoLE6rA0dpKFcsFcj7v7t+S3DXI2eto+WYYP3UEX1oYYMZu97GDoC/66Gh7 oGqDnA== Received: from mail-pg1-f198.google.com (mail-pg1-f198.google.com [209.85.215.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4gkcyfhmd9-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Thu, 10 Sep 2026 01:51:10 +0000 (GMT) Received: by mail-pg1-f198.google.com with SMTP id 41be03b00d2f7-cc1b8088203so7155986a12.3 for ; Wed, 09 Sep 2026 18:51:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1789005070; x=1789609870; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VdLMLU0lIE2FaCyPNgoMNNA59jScOU92wfwmF9t9O/A=; b=NlmxhEsKHZcMm/yBF2D78p0lVZ9DX0vIl8HAYcPKjuLErUA7ucwneF9oRAHQzUbmEe l34S3IxfrSO3g8EB3007YvDkBkAl/T84ahHMvSg2BdQcUMqsg3gUHLbDmt0rfJth++2v TckMMr/WjPMzEvrDlI6PzXbQQcLP5Ue6cFFWL10yXTS0boIKYzestHhfqR9lDML5SdKf XxEjZa+ivapyyKeKGgW5gZSi5wYUYKuqNaQ4pIUtpmOUhrXOQfA0fGO6hU9tJIwXVW7R RGHqe/hr/WH4+rPJ56rNOUbk9jlR4F1JOJUIyH4hkzcZQubeP0acn5zLnolfv4wM7SYE zz1A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789005070; x=1789609870; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=VdLMLU0lIE2FaCyPNgoMNNA59jScOU92wfwmF9t9O/A=; b=ZtBBGYLoEDmXlEwGzyFVk+1iJ/2VOvBgLaXRQq71q7ZIzJKrcrMZWciNOUb4Uzy2F0 G4KQw12CFX3dQndKy9nTwkMAxP0Ux8wx+9cIU4Tv8P6rE1+lUMflhggYN9RsHdWJJ8uF K1CJ22p3XC7qu6sieap/kkH0AD8ZXWPsBHYGV8Rnv5qxKoYYZZTS+qMPZwSQN/zI8dLv v2SCDz4XTdqtAhoIc6pXRMWgf9K5hVN7SOOh0Jz12EzFY1RUnuaUq9cDGGmWBt/QHaQ6 rW/zErcdpad4G0aK+cj0x8wTlBL7VS+kBqDChVkbqcTq9p2f597ggsOkwdfg5FR9Vrz9 SYJw== X-Forwarded-Encrypted: i=1; AKwUvBwJrsdqK3GnM0JfSV3YO5yOcZ7jDVwpoCb9plqJtWE+FJC4gXm6KEstKbhHImAkN6UUugLgvH3dTd1bsd0=@vger.kernel.org X-Gm-Message-State: AFuF++kV5dKPmSkNlJdzCF/9ywDq+JTJrqQunR+E24yrEsCb+jm44gfr ZaTlfdC6p6APNRZ/HpMn+vQ/BuFYYqDAz5ozveyDYj/YFBWIHqUuA4IrpscNNOnRVx3IgJReHQM /s2VXJQemggQPHvX8hLvhim53z/E8kAKm91hYm9RZpV+PhxshxE/QiOXRuZxz5EkCBiM= X-Gm-Gg: AYBFou2YnnLNmAQS4yQAZRngN+cI84BZyrUQYmZ3P9NxP9ySu4P5hZeo2p69QZYF+W9 KFM27Ck3erWLTRVtDIqzYE2kVrIch+Z9Ba5pQa6DQBy6Tdi8OzFttYDcxOVcuLL1xOODin1t+dR a1hpqIbrgB3AWUu9lRtPsEtDqdIWhgAYveswnsRslhlRmMeGKt0UAlsyG8mIRBn4MtUEjRXQSE/ aUiSWAw1HuZsPE/fAANacoKPl14W4nEMS+nrEjzygipoGd+xnATC83PGEkwl9mSpHBuwQ0GFI2N MdFUpPpEAFV1DpJFTS82odk/mOuFy/BeolyE1UMOKYvUNPRDcrT4N9p9cMrAxE2Qhu3JAwuxex8 T1XXo9cfWRwSkA/pK7kKRHXx98RRameMuED7cEITGz1KsLh7+almf X-Received: by 2002:a17:90b:534e:b0:398:ba0e:96f6 with SMTP id 98e67ed59e1d1-39b2624f0f4mr55626610a91.23.1789005069614; Wed, 09 Sep 2026 18:51:09 -0700 (PDT) X-Received: by 2002:a17:90b:534e:b0:398:ba0e:96f6 with SMTP id 98e67ed59e1d1-39b2624f0f4mr55626527a91.23.1789005069086; Wed, 09 Sep 2026 18:51:09 -0700 (PDT) Received: from hu-wcheng-lv.qualcomm.com (Global_NAT1.qualcomm.com. [129.46.96.20]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3339aa33e96sm47446234eec.12.2026.09.09.18.51.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 18:51:08 -0700 (PDT) From: Wesley Cheng Date: Wed, 09 Sep 2026 18:51:00 -0700 Subject: [PATCH v4 4/5] ALSA: usb-audio: qcom: tag sideband endpoints before ring allocation Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260909-16k_offload_v1_b4-v4-4-f24a86617597@oss.qualcomm.com> References: <20260909-16k_offload_v1_b4-v4-0-f24a86617597@oss.qualcomm.com> In-Reply-To: <20260909-16k_offload_v1_b4-v4-0-f24a86617597@oss.qualcomm.com> To: Mathias Nyman , Greg Kroah-Hartman , Jaroslav Kysela , Takashi Iwai , Michal Pecio Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, linux-sound@vger.kernel.org, Wesley Cheng X-Mailer: b4 0.15.2 X-Proofpoint-Spam-Info: AW1haW4tMjYwOTEwMDAxOCBTYWx0ZWRfXygrpZAcGykhV jU+eIkM30P0Dd0f4K5zPYyhABTPwrnfhWNp5OxLnDR7fT7XrGqh+SniI/oEhtNyMclUs7mp8lkD rc2PUXIMHRZurzNk9emzedoOJ9KaFF4= X-Proofpoint-ORIG-GUID: q3b9WlaUP8biS2f-izAURs8EZEO2l6d3 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTEwMDAxOCBTYWx0ZWRfXwOsFN8jNlq4q tOvjCotN+DybTzoE7NLZBFQHLd6LfMlq4kiklp5+i6+cdJSOMVSNZirXe4Aunfow6BNqFK8MXaH LuUPlWcwktc8Wr9TA+Og8HbFkYgd45yfmCgNs8PfihejDX5XqnCwB0b6EQ4z7jfT7KtrC0asoyU jK/AgAhIvuOoZ/+tN/xrrzVbY2GXWUNmd196+HZMweIXdANCyoVfp/H6wfsdzbW8GYVfrVFmwfi OOUNOK+eGYkws1IpcK1A7/pWa9uVdkWLG4ZFYRBNfHol2+a2eQtMo8smDWc4tZvr56zU+ew2kFn Pbm5A/WimomqBCaTDlddaqXYVVO0JRVYjhbKfEEsloPFciaHSSVxLkwiTzNVAvfXuLhcGqoZW90 BV9Yh/DMSVEcshic0J6xXZEyG62txwcDfktB4t0zRQPAuLQsC3/c3p+Z3PWjRMUUBvj/RGhhqEh boleRGWebRCSjhXKrdg== X-Authority-Analysis: v=2.4 cv=H5pOUOYi c=1 sm=1 tr=0 ts=6aa20d0e cx=c_pps a=Qgeoaf8Lrialg5Z894R3/Q==:117 a=ouPCqIW2jiPt+lZRy3xVPw==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=yx91gb_oNiZeI1HMLzn7:22 a=EUspDBNiAAAA:8 a=CbMfP9IJxQ5wjS32uxIA:9 a=QEXdDO2ut3YA:10 a=x9snwWr2DeNwDh03kgHS:22 X-Proofpoint-GUID: q3b9WlaUP8biS2f-izAURs8EZEO2l6d3 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-10_01,2026-09-09_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 suspectscore=0 spamscore=0 priorityscore=1501 impostorscore=0 malwarescore=0 bulkscore=0 adultscore=0 lowpriorityscore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2609040000 definitions=main-2609100018 xhci_endpoint_init() picks the ring's segment pool based on whether the endpoint has already been tagged via xhci_sideband_add_endpoint(): sideband-tagged endpoints get their ring allocated from the offload client's own segment_pool instead of the shared xhci->segment_pool, so the buffer reported to the ADSP over QMI is guaranteed to come from a page meant to be ADSP-visible. xhci_sideband_add_endpoint() must therefore run before the endpoint's transfer ring is first allocated (i.e. before snd_usb_endpoint_prepare() triggers xhci_endpoint_init()) for that pool selection to apply to the first allocation. Move the xhci_sideband_add_endpoint() calls out of uaudio_endpoint_setup() and into enable_audio_stream(), before snd_usb_endpoint_prepare() is called for the data and sync endpoints, and unwind them on the new error paths. At that point in the setup sequence dev->ep_in[]/ep_out[] are not yet populated, since the endpoint's altsetting has not been activated, so usb_pipe_endpoint() cannot be used to find the usb_host_endpoint. Add uaudio_find_host_endpoint(), which resolves it directly from the interface's altsetting descriptor table instead. Assisted-by: Claude:claude-sonnet-5 Signed-off-by: Wesley Cheng --- sound/usb/qcom/qc_audio_offload.c | 96 +++++++++++++++++++++++++++++++++--= ---- 1 file changed, 82 insertions(+), 14 deletions(-) diff --git a/sound/usb/qcom/qc_audio_offload.c b/sound/usb/qcom/qc_audio_of= fload.c index c94b15423a9a..bb5a0d54cd72 100644 --- a/sound/usb/qcom/qc_audio_offload.c +++ b/sound/usb/qcom/qc_audio_offload.c @@ -943,6 +943,45 @@ static void uaudio_dev_release(struct kref *kref) wake_up(&dev->disconnect_wq); } =20 +/** + * uaudio_find_host_endpoint() - look up usb_host_endpoint for a snd_usb_e= ndpoint + * @subs: usb substream owning the target snd_usb_endpoint + * @endpoint: sync or data snd_usb_endpoint to resolve + * + * usb_pipe_endpoint() resolves via dev->ep_in[]/ep_out[], which are only + * populated once usb_set_interface() has activated the endpoint's altsett= ing + * (i.e. after snd_usb_endpoint_prepare() has run for it). Looking that up + * beforehand returns NULL. + * + * Instead, look the endpoint up directly in the interface's altsetting + * descriptor table, which is populated once at enumeration time and stays + * valid regardless of which altsetting is currently active. + * + * Return: matching usb_host_endpoint, or NULL if not found. + */ +static struct usb_host_endpoint * +uaudio_find_host_endpoint(struct snd_usb_substream *subs, + struct snd_usb_endpoint *endpoint) +{ + struct usb_host_interface *alt; + struct usb_interface *iface; + int i; + + iface =3D usb_ifnum_to_if(subs->dev, endpoint->iface); + if (!iface) + return NULL; + + alt =3D usb_altnum_to_altsetting(iface, endpoint->altsetting); + if (!alt) + return NULL; + + for (i =3D 0; i < alt->desc.bNumEndpoints; i++) + if (alt->endpoint[i].desc.bEndpointAddress =3D=3D endpoint->ep_num) + return &alt->endpoint[i]; + + return NULL; +} + /** * enable_audio_stream() - enable usb snd endpoints * @subs: usb substream @@ -960,8 +999,9 @@ static void uaudio_dev_release(struct kref *kref) static int enable_audio_stream(struct snd_usb_substream *subs, snd_pcm_format_t pcm_format, unsigned int channels, unsigned int cur_rate, - int datainterval) + int datainterval, unsigned int card_num) { + struct usb_host_endpoint *data_ep =3D NULL, *sync_ep =3D NULL; struct snd_pcm_hw_params params; struct snd_usb_audio *chip; struct snd_interval *i; @@ -999,17 +1039,49 @@ static int enable_audio_stream(struct snd_usb_substr= eam *subs, goto detach_ep; } =20 + data_ep =3D uaudio_find_host_endpoint(subs, subs->data_endpoint); + if (!data_ep) { + dev_err(&subs->dev->dev, "data ep # %d not found\n", + subs->data_endpoint->ep_num); + ret =3D -ENODEV; + goto detach_ep; + } + + ret =3D xhci_sideband_add_endpoint(uadev[card_num].sb, data_ep, + uadev[card_num].segment_pool); + if (ret < 0) { + dev_err(&subs->dev->dev, + "failed to add data ep to sec intr: %d\n", ret); + goto detach_ep; + } + if (subs->sync_endpoint) { + sync_ep =3D uaudio_find_host_endpoint(subs, subs->sync_endpoint); + if (!sync_ep) { + dev_err(&subs->dev->dev, "sync ep # %d not found\n", + subs->sync_endpoint->ep_num); + ret =3D -ENODEV; + goto remove_data_ep; + } + + ret =3D xhci_sideband_add_endpoint(uadev[card_num].sb, sync_ep, + uadev[card_num].segment_pool); + if (ret < 0) { + dev_err(&subs->dev->dev, + "failed to add sync ep to sec intr: %d\n", ret); + goto remove_data_ep; + } + ret =3D snd_usb_endpoint_prepare(chip, subs->sync_endpoint); if (ret < 0) - goto detach_ep; + goto remove_sync_ep; } =20 ret =3D snd_usb_endpoint_prepare(chip, subs->data_endpoint); if (ret < 0) - goto detach_ep; + goto remove_sync_ep; =20 - dev_dbg(uaudio_qdev->data->dev, + dev_dbg(&subs->dev->dev, "selected %s iface:%d altsetting:%d datainterval:%dus\n", subs->direction ? "capture" : "playback", subs->cur_audiofmt->iface, subs->cur_audiofmt->altsetting, @@ -1021,6 +1093,11 @@ static int enable_audio_stream(struct snd_usb_substr= eam *subs, =20 return 0; =20 +remove_sync_ep: + if (sync_ep) + xhci_sideband_remove_endpoint(uadev[card_num].sb, sync_ep); +remove_data_ep: + xhci_sideband_remove_endpoint(uadev[card_num].sb, data_ep); detach_ep: snd_usb_hw_free(subs); =20 @@ -1142,15 +1219,6 @@ uaudio_endpoint_setup(struct snd_usb_substream *subs, =20 memcpy(ep_desc, &ep->desc, sizeof(ep->desc)); =20 - ret =3D xhci_sideband_add_endpoint(uadev[card_num].sb, ep, - uadev[card_num].segment_pool); - if (ret < 0) { - dev_err(&subs->dev->dev, - "failed to add data ep to sec intr: %d\n", ret); - ret =3D -ENODEV; - goto exit; - } - sgt =3D xhci_sideband_get_endpoint_buffer(uadev[card_num].sb, ep); if (!sgt) { dev_err(&subs->dev->dev, @@ -1641,7 +1709,7 @@ static void handle_uaudio_stream_req(struct qmi_handl= e *handle, ret =3D enable_audio_stream(subs, map_pcm_format(req_msg->audio_format), req_msg->number_of_ch, req_msg->bit_rate, - datainterval); + datainterval, pcm_card_num); =20 if (!ret) ret =3D prepare_qmi_response(subs, req_msg, &resp, --=20 2.34.1 From nobody Fri Sep 25 17:49:58 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 884303749E1 for ; Thu, 10 Sep 2026 01:51:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789005075; cv=none; b=mfZk2Zk6b7TGsy316L13GhPQF5/gHP6NFbcymooVqPRKOZbkdi9glIs51Lkznibm2vH6nU2g2FFbMYvpfBg0eHxpLyVqvWaEWzU8XM+D+jwta+AU0Mf326UVYSCEXsAI2lNFiIpy4s5WSpl4xHYAzt/JCFDp2k5anHRVrEJirx8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789005075; c=relaxed/simple; bh=ynT43ZlYjgcPbqe8Z2Sitet6cthgPvBbmZ1TJ8jAs90=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=tI+oZD01J9Pmoa2iQCKMEB8ixn7eJr3izAe5bMLCsodRHDFz31z3H40h0gTqm1Sv+7XYBhHVhq6LZFI0jiWgbrmbaNklWhQDbIcuYh+jlNB29gMXsVxs6+j1UwyL70VOVEhiaeVih9OuXeg6goYtgGvPGAcGcq3zNBgbr5pqdpQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=Z+uxZgmM; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=fdFwU8tk; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="Z+uxZgmM"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="fdFwU8tk" Received: from pps.filterd (m0279862.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 68A1lc1X3199108 for ; Thu, 10 Sep 2026 01:51:11 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= 6p/ZNsYDwIyedUSRxVruTRQWYBLvpIq5hDQ1FGef1BM=; b=Z+uxZgmMztw7TZch MH/m1oP9vKWT2fWldgHsAt1dzxYUc01Pb4ol+aCd1EHwckuzSiAR2UYA6UF+nDeE qdwhOwHCFL12DvloklDWgSRTZlZCDyTuD6rG9RUENoJlkwnbdcbvk6XCny930uQv z2eTcuF/a8Z/1lsTic/WX3w5jbbCHd5S0dR15iwUYjaAiXsnAlg5cD7NJCnxxZ/u dBC5WhmBXkkm+8WMOo/hamq2tUPg5JH6PEDRBqalPN0xyHyK7WlFxx7rwhepT0bD HpG5651KRLoQtFWC+2TZEihXHwJc3FEPLqfh48YnjVG5m01FG5LAvk75cGdl+Pnn UXYjCg== Received: from mail-pj1-f71.google.com (mail-pj1-f71.google.com [209.85.216.71]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4gkcydshkw-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Thu, 10 Sep 2026 01:51:11 +0000 (GMT) Received: by mail-pj1-f71.google.com with SMTP id 98e67ed59e1d1-396901263b6so11929592a91.2 for ; Wed, 09 Sep 2026 18:51:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1789005071; x=1789609871; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6p/ZNsYDwIyedUSRxVruTRQWYBLvpIq5hDQ1FGef1BM=; b=fdFwU8tkaVlfkwXlwZryzWhu67PicCDrG6kzrbzlTsnz2YNyhTCn8KUo8YMgr2Ge+J IM90jttQDMY1P8zZkco2WGmyDlyxIN5gjRDoNoL5bHF5Q/80BwmBL+0MNArjZH8/doyB GXHpftejuHp1yUWQKyzFU3GvlOkRtLWdY4M6y6uEHd6AWCPQ2ZLBqV100ROV56reSnz2 7lgogbD2ddkuJOTbAUZp37SC+xAGEluLmrbYzMm6DAjVS2068hHFwBHrzeu+pLeUiGZL O49kw9zwNQmqj8XELOUK+Nv94M9bupunDMK3ZAiGh1E99kGy64hClNsMO+AvjwGNTmFD 90zQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789005071; x=1789609871; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=6p/ZNsYDwIyedUSRxVruTRQWYBLvpIq5hDQ1FGef1BM=; b=lPQmyS1p5ebfTqjILWwlxL56Lc9dRUC2T5lyWPE1j4IDjeUW8lAwNAy+BLHhHdbrTC fqoAI8c46D45qhZ7F6qobl2EGDRM8WaGdocEqB5JEWKYqZUt0yuKJgD+Tupn/ACnZm39 75QXfR+e26kg1JD9O14mYOtSJKTun/aINXgc/Q2pd8SX25RR9guqjjaNwR2zriAzGliI OWCw8nWfoMqTfhKA7IH0Frl5n5u+hv6L8g50T21FvzXzStCk4+tjYMFV38nqliqn3YEr YPShWfTRpXblxvZCcdzf7f7LaR/q9PugS5KXF2v/SgRxOV03xF2HFkPQYtFlXhd9wgS/ af0w== X-Forwarded-Encrypted: i=1; AKwUvByyRfRdt98K0ZrBsYvHBpL0OVV3/8FDjVSqVUkQ/XQIX+4ge1wXBCv7YWi2IJHMOILDHOi/KlH/vqY1128=@vger.kernel.org X-Gm-Message-State: AFuF++nCmmUJuRSwf8SePlBajmQl10hF9Ks5YkCFp7qLD5/voYjXPqfZ 9gxhUtT5MpIPCruE425BSBcAASobHfu4Rwnq6VzqFUbpgGb19LDTv145da+rhBGdbXNyon+I7km ANYFBFWtI4dgWN7n0kf4Nmhikl+av3z3mgeNBtMdFFKF0tSYP05Q0BbirSGyGufXtcUY= X-Gm-Gg: AYBFou24NKwoSzl9GSz2UH4I/ZaPlSy7vnv3QWmsh+D3p1Q9dULIIkbyj+CIj/tH/9s WpjcE1ta2xR3PCN53qAwToI1TDZbt+43cfSSK+s+fjV/XU47rWRXIeqDUn9GzHwVADuMQPgflQX 8GPKAZG/VeytXdt0opw6WKyy+pBbDifhmS/EhZQXaFY1ZDDV3eXxcdFIhus9qPLFBL7AkNahJFe 4ZEHtbmfL2FiYHIiQ4Z8n3tnPf+c1Gng+raUagCzOkJ0lrH6ZnGxJifbGMXQzubNZOTN0Nb154W QbG2Ak4YKpqr/Wv+ygufPryNMh6KjeIuwBIUt6ZqwB9Mm6qJjsvMYuFlxWhfFdmQ/rkWf2Yhq/D sbE5JGqLxyct/itmzeAreShC5xVT+MAnGHXdvfxqFNyMII+ayVbZe X-Received: by 2002:a17:90b:4d84:b0:398:e73e:5a0c with SMTP id 98e67ed59e1d1-39bac138257mr13113620a91.1.1789005070531; Wed, 09 Sep 2026 18:51:10 -0700 (PDT) X-Received: by 2002:a17:90b:4d84:b0:398:e73e:5a0c with SMTP id 98e67ed59e1d1-39bac138257mr13113546a91.1.1789005070066; Wed, 09 Sep 2026 18:51:10 -0700 (PDT) Received: from hu-wcheng-lv.qualcomm.com (Global_NAT1.qualcomm.com. [129.46.96.20]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3339aa33e96sm47446234eec.12.2026.09.09.18.51.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 09 Sep 2026 18:51:09 -0700 (PDT) From: Wesley Cheng Date: Wed, 09 Sep 2026 18:51:01 -0700 Subject: [PATCH v4 5/5] ALSA: usb-audio: qcom: fix xfer ring IOMMU unmap on 16K+ page kernels Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260909-16k_offload_v1_b4-v4-5-f24a86617597@oss.qualcomm.com> References: <20260909-16k_offload_v1_b4-v4-0-f24a86617597@oss.qualcomm.com> In-Reply-To: <20260909-16k_offload_v1_b4-v4-0-f24a86617597@oss.qualcomm.com> To: Mathias Nyman , Greg Kroah-Hartman , Jaroslav Kysela , Takashi Iwai , Michal Pecio Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, linux-sound@vger.kernel.org, Wesley Cheng X-Mailer: b4 0.15.2 X-Authority-Analysis: v=2.4 cv=IfsSymqa c=1 sm=1 tr=0 ts=6aa20d0f cx=c_pps a=UNFcQwm+pnOIJct1K4W+Mw==:117 a=ouPCqIW2jiPt+lZRy3xVPw==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_K5XuSEh1TEqbUxoQ0s3:22 a=EUspDBNiAAAA:8 a=LmYBifCbusCXSjBzSPcA:9 a=QEXdDO2ut3YA:10 a=uKXjsCUrEbL0IQVhDsJ9:22 X-Proofpoint-GUID: GJnacwIieDFRlLGWvULl2W4Y66KJ17qU X-Proofpoint-ORIG-GUID: GJnacwIieDFRlLGWvULl2W4Y66KJ17qU X-Proofpoint-Spam-Info: AW1haW4tMjYwOTEwMDAxOCBTYWx0ZWRfX+7KE1k6xvL4C OMBn9ry9YqZhRN8JOxGRd2YXn6bEHr0gi2SfwV/VvBBfhj3//ZqZ6I3WRTJhQhnNY7Up2yUgrjO XyQjUi3P1Elsg5f+EE7WhkZFtul/ovI= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTEwMDAxOCBTYWx0ZWRfX4ULqOnepWuyt 4bg5EM8Of3jOjINisy4/Ejp+a6ATFL7WSVPlVihKze4fz2Q2ssfN1PASl7xvU8U+6lS9hgroma7 gABe1XzngniCOKU3Lhz281/oo1DsZy9dq+rCHo+FCjU5vCGSbRdKoAW/8yK+0H+LTxLWfo/5hS4 aD8FAyovUtxed/CC8RMxEsFYomXrezF/uO7YI2GZoMK5ocmqDNqHpf9EBAW+AO+tTqK6QDgGXvb d5Q0y1jFRlJV0DB0k2TeNYjwmx02f3RAfifyhkEGbGwt0uFbMZAxbB6ikep9HOH8pxInTHB+Uzs IWsxHabMWY9/CDQLUxqPc6J5UT+mKHSOFlylIVx5EqbUXSzJJHHik62YOQ8O236paNo94oPfov3 rGBaATFaVZnDLjr+QTpELFdJ5V2IsytOtEhl0UDmX4gnYE0y4b4LDK59fy4AIt2sCnDGK9HOMiA g7qpnF8Ay30j+I7qsog== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-10_01,2026-09-09_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 malwarescore=0 priorityscore=1501 lowpriorityscore=0 impostorscore=0 spamscore=0 adultscore=0 suspectscore=0 bulkscore=0 clxscore=1015 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2609040000 definitions=main-2609100018 TRB_SEGMENT_SIZE is hardcoded to 4096 bytes, but on kernels built with a larger PAGE_SIZE (e.g. 16K or 64K page arches) the IOMMU still maps and unmaps in units of PAGE_SIZE. A ring segment's physical page can therefore start at a non-page-aligned offset relative to the segment itself, and the DMA address handed back for the ring (sg_dma_address()) carries that same intra-page offset. Add that offset back onto the mapped iova before sending it to the ADSP over QMI, so the reported address resolves to the start of the segment rather than the start of its containing page, and report the true TRB_SEGMENT_SIZE instead of PAGE_SIZE as the ring size. This broke the reverse direction: recovering the raw, page-aligned iova for iommu_unmap() by masking off the low PAGE_SIZE bits of the QMI-reported iova only works if that iova happens to already be page-aligned before the offset was added, which is not guaranteed. Add RING_IOVA_BASE(), which instead subtracts the exact offset that was added at setup time, and use it for both the cached data/sync_xfer_ring_va and the drop_sync_ep/drop_data_ep unmap error paths. Assisted-by: Claude:claude-sonnet-5 Signed-off-by: Wesley Cheng --- sound/usb/qcom/qc_audio_offload.c | 27 +++++++++++++++++++-------- 1 file changed, 19 insertions(+), 8 deletions(-) diff --git a/sound/usb/qcom/qc_audio_offload.c b/sound/usb/qcom/qc_audio_of= fload.c index bb5a0d54cd72..2e6397f9cab6 100644 --- a/sound/usb/qcom/qc_audio_offload.c +++ b/sound/usb/qcom/qc_audio_offload.c @@ -66,6 +66,12 @@ =20 #define MAX_XFER_BUFF_LEN (24 * PAGE_SIZE) =20 +/* recover the raw xfer ring iova by subtracting the intra-page offset add= ed at setup */ +static inline u64 ring_iova_base(struct mem_info_v01 mem) +{ + return IOVA_MASK(mem.iova) - (mem.dma & ~PAGE_MASK); +} + struct iova_info { struct list_head list; unsigned long start_iova; @@ -1241,8 +1247,10 @@ uaudio_endpoint_setup(struct snd_usb_substream *subs, goto clear_pa; } =20 - mem_info->iova =3D PREPEND_SID_TO_IOVA(iova, uaudio_qdev->data->sid); - mem_info->size =3D PAGE_SIZE; + /* add intra-page offset so DSP IOVA resolves to the correct 4K slot */ + mem_info->iova =3D PREPEND_SID_TO_IOVA(iova + (mem_info->dma & ~PAGE_MASK= ), + uaudio_qdev->data->sid); + mem_info->size =3D TRB_SEGMENT_SIZE; =20 return 0; =20 @@ -1311,8 +1319,10 @@ static int uaudio_event_ring_setup(struct snd_usb_su= bstream *subs, goto clear_pa; } =20 - mem_info->iova =3D PREPEND_SID_TO_IOVA(iova, uaudio_qdev->data->sid); - mem_info->size =3D PAGE_SIZE; + /* add intra-page offset so DSP IOVA resolves to the correct 4K slot */ + mem_info->iova =3D PREPEND_SID_TO_IOVA(iova + (mem_info->dma & ~PAGE_MASK= ), + uaudio_qdev->data->sid); + mem_info->size =3D TRB_SEGMENT_SIZE; =20 return 0; =20 @@ -1551,10 +1561,10 @@ static int prepare_qmi_response(struct snd_usb_subs= tream *subs, =20 /* cache intf specific info to use it for unmap and free xfer buf */ uadev[card_num].info[info_idx].data_xfer_ring_va =3D - IOVA_MASK(resp->xhci_mem_info.tr_data.iova); + ring_iova_base(resp->xhci_mem_info.tr_data); uadev[card_num].info[info_idx].data_xfer_ring_size =3D PAGE_SIZE; uadev[card_num].info[info_idx].sync_xfer_ring_va =3D - IOVA_MASK(resp->xhci_mem_info.tr_sync.iova); + ring_iova_base(resp->xhci_mem_info.tr_sync); uadev[card_num].info[info_idx].sync_xfer_ring_size =3D PAGE_SIZE; uadev[card_num].info[info_idx].xfer_buf_iova =3D IOVA_MASK(resp->xhci_mem_info.xfer_buff.iova); @@ -1589,13 +1599,14 @@ static int prepare_qmi_response(struct snd_usb_subs= tream *subs, drop_sync_ep: if (subs->sync_endpoint) { uaudio_iommu_unmap(MEM_XFER_RING, - IOVA_MASK(resp->xhci_mem_info.tr_sync.iova), + ring_iova_base(resp->xhci_mem_info.tr_sync), PAGE_SIZE, PAGE_SIZE); xhci_sideband_remove_endpoint(uadev[card_num].sb, usb_pipe_endpoint(subs->dev, subs->sync_endpoint->pipe)); } drop_data_ep: - uaudio_iommu_unmap(MEM_XFER_RING, IOVA_MASK(resp->xhci_mem_info.tr_data.i= ova), + uaudio_iommu_unmap(MEM_XFER_RING, + ring_iova_base(resp->xhci_mem_info.tr_data), PAGE_SIZE, PAGE_SIZE); xhci_sideband_remove_endpoint(uadev[card_num].sb, usb_pipe_endpoint(subs->dev, subs->data_endpoint->pipe)); --=20 2.34.1