Linux USB
 help / color / mirror / Atom feed
From: Jeff Vanhoof <jdv1029@gmail.com>
To: Thinh Nguyen <Thinh.Nguyen@synopsys.com>
Cc: Felipe Balbi <balbi@kernel.org>,
	Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	linux-usb@vger.kernel.org, John Youn <John.Youn@synopsys.com>,
	stable@vger.kernel.org, Dan Vacura <w36195@motorola.com>
Subject: Re: [PATCH v2 1/2] usb: dwc3: gadget: Stop processing more requests on IMI
Date: Tue, 25 Oct 2022 13:22:09 -0500	[thread overview]
Message-ID: <20221025182207.GA8539@qjv001-XeonWs> (raw)
In-Reply-To: <20221025164235.GA5795@qjv001-XeonWs>

Hi Thinh,

On Tue, Oct 25, 2022 at 11:42:37AM -0500, Jeff Vanhoof wrote:
> Hi Thinh,
> 
> On Mon, Oct 24, 2022 at 11:45:48PM -0500, Jeff Vanhoof wrote:
> > On Mon, Oct 24, 2022 at 06:27:57PM -0700, Thinh Nguyen wrote:
> > > When servicing a transfer completion event, the dwc3 driver will reclaim
> > > TRBs of started requests up to the request associated with the interrupt
> > > event. Currently we don't check for interrupt due to missed isoc, and
> > > the driver may attempt to reclaim TRBs beyond the associated event. This
> > > causes invalid memory access when the hardware still owns the TRB. If
> > > there's a missed isoc TRB with IMI (interrupt on missed isoc), make sure
> > > to stop servicing further.
> > > 
> > > Note that only the last TRB of chained TRBs has its status updated with
> > > missed isoc.
> > > 
> > > Fixes: 72246da40f37 ("usb: Introduce DesignWare USB3 DRD Driver")
> > > Cc: stable@vger.kernel.org
> > > Reported-by: Jeff Vanhoof <jdv1029@gmail.com>
> > > Reported-by: Dan Vacura <w36195@motorola.com>
> > > Signed-off-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com>
> > > ---
> > >  Changes in v2:
> > >  - No need to check for CHN=0 since only the last TRB has its status
> > >    updated to missed isoc
> > > 
> > >  drivers/usb/dwc3/gadget.c | 4 ++++
> > >  1 file changed, 4 insertions(+)
> > > 
> > > diff --git a/drivers/usb/dwc3/gadget.c b/drivers/usb/dwc3/gadget.c
> > > index dd8ecbe61bec..230b3c660054 100644
> > > --- a/drivers/usb/dwc3/gadget.c
> > > +++ b/drivers/usb/dwc3/gadget.c
> > > @@ -3248,6 +3248,10 @@ static int dwc3_gadget_ep_reclaim_completed_trb(struct dwc3_ep *dep,
> > >  	if (event->status & DEPEVT_STATUS_SHORT && !chain)
> > >  		return 1;
> > >  
> > > +	if ((trb->ctrl & DWC3_TRB_CTRL_ISP_IMI) &&
> > > +	    DWC3_TRB_SIZE_TRBSTS(trb->size) == DWC3_TRBSTS_MISSED_ISOC)
> > > +		return 1;
> > > +
> > >  	if ((trb->ctrl & DWC3_TRB_CTRL_IOC) ||
> > >  	    (trb->ctrl & DWC3_TRB_CTRL_LST))
> > >  		return 1;
> > > -- 
> > > 2.28.0
> > >
> > 
> > Testing shows that the changes appear to work to prevent the arm-smmu panic I
> > was seeing after missed isoc errors. Also, changes to reclaim trbs only up to
> > the associated interrupt event make sense.
> > 
> > Reviewed-by: Jeff Vanhoof <jdv1029@gmail.com>
> > Tested-by: Jeff Vanhoof <jdv1029@gmail.com>
> > 
> > Regards,
> > Jeff
> > 
> 
> I just followed up with Dan and he mentioned that he was still seeing the arm-smmu panic on his baseline. I will work with him this afternoon to better understand what may be going on there. Let's hold off on merging these changes in until we figure out what is going on. He and I are testing off of different baselines (5.10 vs 5.15), different USB speeds (USB 3 vs 2), and are using different hardware, so I don't know yet why we are seeing a difference here.
> 
> Regards,
> Jeff
> 

Between the changes for PATCH v2 1/2 & PATCH v2 2/2, are there any extra
precautions required for when scatter gather is in use? Should the IMI bit be
set only for the last item in the sg list? I suspect something in this area but
I have no proof yet. Your thoughts?

Thanks,
Jeff




  reply	other threads:[~2022-10-25 18:22 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-10-25  1:27 [PATCH v2 0/2] usb: dwc3: gadget: Fix isoc interrupt check Thinh Nguyen
2022-10-25  1:27 ` [PATCH v2 1/2] usb: dwc3: gadget: Stop processing more requests on IMI Thinh Nguyen
2022-10-25  4:45   ` Jeff Vanhoof
2022-10-25 16:42     ` Jeff Vanhoof
2022-10-25 18:22       ` Jeff Vanhoof [this message]
2022-10-25  1:28 ` [PATCH v2 2/2] usb: dwc3: gadget: Don't set IMI for no_interrupt Thinh Nguyen
2022-10-25  4:51   ` Jeff Vanhoof
2022-10-25 20:05     ` Jeff Vanhoof
2022-10-25 20:53       ` Thinh Nguyen
2022-10-25 21:28         ` Thinh Nguyen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20221025182207.GA8539@qjv001-XeonWs \
    --to=jdv1029@gmail.com \
    --cc=John.Youn@synopsys.com \
    --cc=Thinh.Nguyen@synopsys.com \
    --cc=balbi@kernel.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=w36195@motorola.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox