From: Stephano Cetola <stephano@cetola.net>
To: Sascha Hauer <s.hauer@pengutronix.de>,
"open list:BAREBOX" <barebox@lists.infradead.org>
Subject: [PATCH 0/5] usb: xhci: fix endpoint halt and stall recovery
Date: Sat, 22 Aug 2026 15:33:59 -0700 [thread overview]
Message-ID: <20260822-send-xhci-fixes-v1-0-22e1de3be715@cetola.net> (raw)
Recovering from a halted or stalled USB endpoint is broken in the
XHCI driver in several independent ways. An interrupt endpoint
transfer never gets a real chance to complete. Its own timeout
always defeats the hardware's autonomous polling before it can
succeed. When that or any other transfer times out, the resulting
cleanup can hit a BUG_ON in the wrong completion state, corrupt a
pointer used in the recovery command, or leave the endpoint looking
halted even after recovery actually succeeded.
In practice this shows up two ways. Most keypresses still get
through by racing the cleanup against the hardware's real response,
so it looks like occasional dropped keystrokes rather than a dead
keyboard. When the rarer failure paths trigger instead, the keyboard
stops responding entirely until reboot.
This series fixes each of those problems in the order they are
actually hit during recovery. Patch order matters.
reset_ep()'s timeout_ms parameter was inherited from an unrelated
feature (b310b08f087e, "usb: xhci: Honor transfer timeouts") meant
to let data polls like network RX return quickly, not to describe
how long a hardware recovery command needs. Recovery should always
run to completion regardless of the original transfer's timeout, so
this series gives it a fixed one instead.
Found and fixed during USB bring-up on the MNT Pocket Reform
(RK3588S), which appears to be the first board in this tree to
combine an XHCI controller with a polled USB keyboard. Testers on
the official RCORE RK3588 module independently report the same
symptom. USB polling errors appear on screen, and only a reboot
recovers the keyboard.
Signed-off-by: Stephano Cetola <stephano@cetola.net>
---
Stephano Cetola (5):
usb: xhci: tolerate COMP_CTX_STATE in abort_td's final completion check
usb: xhci: reset_ep: wait for real completion, not the caller's timeout
usb: xhci: reset_ep: fix misaligned pointer in Set TR Dequeue Pointer
usb: xhci: xhci_bulk_tx: re-fetch ep_ctx after resetting a halted endpoint
usb: xhci: wait a real interval for interrupt endpoint transfers
drivers/usb/host/xhci-ring.c | 29 +++++++++++++++++++----------
drivers/usb/host/xhci.c | 2 +-
2 files changed, 20 insertions(+), 11 deletions(-)
---
base-commit: 9bc1a26592a59919d2ee8c60c273d87d3d9f2e81
change-id: 20260822-send-xhci-fixes-bf1812c6c27e
next reply other threads:[~2026-08-22 22:36 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-22 22:33 Stephano Cetola [this message]
2026-08-22 22:34 ` [PATCH 1/5] usb: xhci: tolerate COMP_CTX_STATE in abort_td's final completion check Stephano Cetola
2026-08-22 22:34 ` [PATCH 2/5] usb: xhci: reset_ep: wait for real completion, not the caller's timeout Stephano Cetola
2026-08-22 22:34 ` [PATCH 3/5] usb: xhci: reset_ep: fix misaligned pointer in Set TR Dequeue Pointer Stephano Cetola
2026-08-22 22:34 ` [PATCH 4/5] usb: xhci: xhci_bulk_tx: re-fetch ep_ctx after resetting a halted endpoint Stephano Cetola
2026-08-22 22:34 ` [PATCH 5/5] usb: xhci: wait a real interval for interrupt endpoint transfers Stephano Cetola
2026-08-24 10:14 ` [PATCH 0/5] usb: xhci: fix endpoint halt and stall recovery Sascha Hauer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260822-send-xhci-fixes-v1-0-22e1de3be715@cetola.net \
--to=stephano@cetola.net \
--cc=barebox@lists.infradead.org \
--cc=s.hauer@pengutronix.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox