Linux USB
 help / color / mirror / Atom feed
From: Michal Pecio <michal.pecio@gmail.com>
To: Ben <benstaples10@gmail.com>
Cc: Mathias Nyman <mathias.nyman@linux.intel.com>,
	Mika Westerberg <mika.westerberg@linux.intel.com>,
	linux-usb@vger.kernel.org, andreas.noever@gmail.com,
	westeri@kernel.org, YehezkelShB@gmail.com
Subject: Re: xhci_hcd 0000:0c:00.0 dies with "Abort failed to stop command ring: -110" exactly 24s post-init, tunneled USB4 xHCI behind Goshen Ridge (ASUS ThunderboltEX 4) + CalDigit TS4
Date: Sat, 26 Sep 2026 10:37:08 +0200	[thread overview]
Message-ID: <20260926103708.0025dad2.michal.pecio@gmail.com> (raw)
In-Reply-To: <CANcA1gCRveYso4ishW68P_2N3z0pRYevAwShS_VRNQLEMKJfQg@mail.gmail.com>

[-- Attachment #1: Type: text/plain, Size: 2460 bytes --]

On Fri, 25 Sep 2026 20:28:14 -0400, Ben wrote:
> Kernel Information:
> >   git remote -v
> > origin https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git (fetch)
> > origin https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git (push)
> > thunderbolt https://git.kernel.org/pub/scm/linux/kernel/git/westeri/thunderbolt.git/ (fetch)
> > thunderbolt https://git.kernel.org/pub/scm/linux/kernel/git/westeri/thunderbolt.git/ (push)
> >   git status
> > HEAD detached at thunderbolt/master
> > Changes not staged for commit:
> >  (use "git add <file>..." to update what will be committed)
> >  (use "git restore <file>..." to discard changes in working directory)
> > modified:   drivers/usb/host/xhci-mem.c
> > modified:   drivers/usb/host/xhci.c  
> 
> I've provided more snapshots. One with the quirks from console
> options, one without.

This looks right, but the debugfs dumps don't seem to have been taken
from the patched kernel. Not sure what are those slot_2xx directories,
but neither of them has the bogus IR0_ERSTBA_LOW value.

Was USB functional at all? The patch would break it. Maybe it wasn't
ideal, please try this revised patch which only touches the suspect
host controller. And don't use xhci_hcd.quirks=0x800000 anymore.

Please confirm that the string "beef cafe" appears in dmesg, this shows
that the patch is applied and it recognized the suspect controller.
Then check if there are any "AMD-Vi" errors logged, particularly at
addresses 0xbeef0000 and 0xcafe0000, and check this:

# grep ERSTBA_LOW /sys/kernel/debug/usb/xhci/0000\:0c\:00.0/reg-runtime
IR0_ERSTBA_LOW = 0xbeef0000
  
> usbmon.txt is the result of:
>   sudo cat /sys/kernel/debug/usb/usbmon/0u | tee usbmon.log
> 
> followed by:
>   echo 0000:0c:00.0 | sudo tee /sys/bus/pci/drivers/xhci_hcd/unbind
>   sleep 2
>   echo 0000:0c:00.0 | sudo tee /sys/bus/pci/drivers/xhci_hcd/bind

This confirms that USB core initializes the hub, detects connected
ports and tries to enable them without working Port Status Change
events. Hub interrupt endpoints only see submissions and unlinks.

I separately confirmed the same on my system. I completely patched
out the call to handle_port_status() and devices connected during
driver reload were still detected, only hotplug stopped working.

So it's not surprising that Enable Slot command is queued without
functional xHCI events.

Regards,
Michal

[-- Attachment #2: xhci-bogus-dma.patch --]
[-- Type: text/x-patch, Size: 1525 bytes --]

diff --git a/drivers/usb/host/xhci-mem.c b/drivers/usb/host/xhci-mem.c
index 83ed26c4f9e4..a8f6d50eaf03 100644
--- a/drivers/usb/host/xhci-mem.c
+++ b/drivers/usb/host/xhci-mem.c
@@ -2349,7 +2349,7 @@ void xhci_add_interrupter(struct xhci_hcd *xhci, unsigned int intr_num)
 
 	erst_base = xhci_read_64(xhci, &ir->ir_set->erst_base);
 	erst_base &= ~ERST_BASE_ADDRESS_MASK;
-	erst_base |= ir->erst.erst_dma_addr & ERST_BASE_ADDRESS_MASK;
+	erst_base |= xhci->quirks == 0x9810 ? 0xbeef0000 : ir->erst.erst_dma_addr & ERST_BASE_ADDRESS_MASK;
 	if (xhci->quirks & XHCI_WRITE_64_HI_LO)
 		hi_lo_writeq(erst_base, &ir->ir_set->erst_base);
 	else
diff --git a/drivers/usb/host/xhci.c b/drivers/usb/host/xhci.c
index e5c8b3a945a6..62c0690d4b55 100644
--- a/drivers/usb/host/xhci.c
+++ b/drivers/usb/host/xhci.c
@@ -497,7 +497,7 @@ static void xhci_set_cmd_ring_deq(struct xhci_hcd *xhci)
 
 	crcr = xhci_read_64(xhci, &xhci->op_regs->cmd_ring);
 	crcr &= ~(CMD_RING_PTR_MASK | CMD_RING_CYCLE);
-	crcr |= deq_dma;
+	crcr |= xhci->quirks == 0x9810 ? 0xcafe0000 : deq_dma;
 	crcr |= xhci->cmd_ring->cycle_state;
 
 	xhci_dbg_trace(xhci, trace_xhci_dbg_init, "Setting command ring address to 0x%llx", crcr);
@@ -533,6 +533,9 @@ static void xhci_init(struct usb_hcd *hcd)
 {
 	struct xhci_hcd *xhci = hcd_to_xhci(hcd);
 
+	if (xhci->quirks == 0x9810)
+		xhci_info(xhci, "beef cafe\n");
+
 	xhci_dbg_trace(xhci, trace_xhci_dbg_init, "Starting %s", __func__);
 
 	/* Set the Number of Device Slots Enabled to the maximum supported value */

  reply	other threads:[~2026-09-26  8:37 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-15  4:04 xhci_hcd 0000:0c:00.0 dies with "Abort failed to stop command ring: -110" exactly 24s post-init, tunneled USB4 xHCI behind Goshen Ridge (ASUS ThunderboltEX 4) + CalDigit TS4 Ben
2026-09-15  4:19 ` Mika Westerberg
2026-09-15  4:27   ` Ben
2026-09-15  4:38     ` Mika Westerberg
2026-09-15  4:46       ` Ben
2026-09-15  5:05         ` Mika Westerberg
2026-09-16  3:01           ` Ben
2026-09-16  7:51             ` Mika Westerberg
2026-09-17  2:18               ` Ben
2026-09-17  2:40                 ` Ben
2026-09-17  4:38                 ` Mika Westerberg
2026-09-19  0:28                   ` Ben
2026-09-21  4:44                     ` Mika Westerberg
2026-09-21 23:25                       ` Ben
2026-09-22  4:26                         ` Mika Westerberg
2026-09-22 11:28                           ` Mathias Nyman
2026-09-24  3:02                           ` Ben
2026-09-24 15:49                             ` [WARNING: UNSCANNABLE EXTRACTION FAILED]Re: " Mathias Nyman
2026-09-24 22:18                               ` Ben
2026-09-25  8:27                                 ` Michal Pecio
2026-09-25  8:40                                   ` Michal Pecio
2026-09-26  0:28                                     ` Ben
2026-09-26  8:37                                       ` Michal Pecio [this message]
2026-09-26 13:59                                         ` Ben
2026-09-26 17:41                                           ` Michal Pecio
2026-09-29 23:50                                             ` Ben

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260926103708.0025dad2.michal.pecio@gmail.com \
    --to=michal.pecio@gmail.com \
    --cc=YehezkelShB@gmail.com \
    --cc=andreas.noever@gmail.com \
    --cc=benstaples10@gmail.com \
    --cc=linux-usb@vger.kernel.org \
    --cc=mathias.nyman@linux.intel.com \
    --cc=mika.westerberg@linux.intel.com \
    --cc=westeri@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox