From: Henry Tseng <henrytseng@qnap.com>
To: Michal Pecio <michal.pecio@gmail.com>
Cc: Henry Tseng <henrytseng@qnap.com>,
Mathias Nyman <mathias.nyman@intel.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
linux-usb@vger.kernel.org
Subject: Re: [PATCH 0/2] xhci: handshake timeout overrun and configure endpoint hang on device disconnect
Date: Thu, 8 Oct 2026 18:25:20 +0800 [thread overview]
Message-ID: <20261008102522.109308-1-henrytseng@qnap.com> (raw)
In-Reply-To: <20261008110642.56567a92.michal.pecio@gmail.com>
Hi Michal,
On Thu, 8 Oct 2026 11:06:42 +0200, Michal Pecio <michal.pecio@gmail.com> wrote:
> Can you identify the 2-1.3 device? Can it be separated or is all
> this stuff inside one physical box?
>
2-1.3 is a hub, 1c04:0018 "QNAP Systems, Inc. USB3.2 Hub". 2-1 and
2-1.4 have the same VID:PID. They are all inside the TL-D800C and
can't be separated.
/: Bus 001.Port 001: Dev 001, Class=root_hub, Driver=xhci_hcd/4p, 480M
ID 1d6b:0002 Linux Foundation 2.0 root hub
|__ Port 001: Dev 002, If 0, Class=Hub, Driver=hub/4p, 480M
ID 1c04:0018 QNAP System Inc.
|__ Port 001: Dev 003, If 0, Class=Communications, Driver=cdc_acm, 12M
ID 04d8:000a Microchip Technology, Inc. CDC RS-232 Emulation Demo
|__ Port 001: Dev 003, If 1, Class=CDC Data, Driver=cdc_acm, 12M
ID 04d8:000a Microchip Technology, Inc. CDC RS-232 Emulation Demo
|__ Port 003: Dev 004, If 0, Class=Hub, Driver=hub/4p, 480M
ID 1c04:0610 QNAP System Inc.
|__ Port 004: Dev 005, If 0, Class=Hub, Driver=hub/4p, 480M
ID 1c04:0610 QNAP System Inc.
/: Bus 002.Port 001: Dev 001, Class=root_hub, Driver=xhci_hcd/4p, 10000M
ID 1d6b:0003 Linux Foundation 3.0 root hub
|__ Port 001: Dev 002, If 0, Class=Hub, Driver=hub/4p, 10000M
ID 1c04:0018 QNAP System Inc.
|__ Port 003: Dev 003, If 0, Class=Hub, Driver=hub/4p, 10000M
ID 1c04:0018 QNAP System Inc.
|__ Port 004: Dev 004, If 0, Class=Hub, Driver=hub/4p, 10000M
ID 1c04:0018 QNAP System Inc.
|__ Port 004: Dev 005, If 0, Class=Mass Storage, Driver=uas, 10000M
ID 174c:55aa ASMedia Technology Inc. ASM1051E SATA 6Gb/s bridge, ASM1053E SATA 6Gb/s bridge, ASM1153 SATA 3Gb/s bridge, ASM1153E SATA 6Gb/s bridge
> Does it help to blacklist "uas" driver before connecting the whole
> tree? My guess at this point: probably not, it's not a streams bug.
>
No, the host still dies.
> What happens if deconfigure manually before disconnection:
>
> echo 0 > /sys/bus/usb/devices/4-6/bConfigurationValue
>
> Will it hang on deconfiguration, disconnection, or not at all?
>
I used 2-1.3 as in your follow-up. The whole tree enumerates the same
way in every run. The logs in patch 2 were taken with an extra USB
stick on 2-2 of the same host, which shifted slot IDs by one, so 2-1.3
was slot 5 there and slot 4 here.
Deconfiguring 2-1.3 completes fine:
[ 87.929570] xhci_hcd 0000:0c:00.3: Cancel URB 0000000064a1e51d, dev 1.3, ep 0x83, starting at offset 0xfff49000
[ 87.929675] xhci_hcd 0000:0c:00.3: Stopped on Transfer TRB for slot 4 ep 6
[ 87.929756] xhci_hcd 0000:0c:00.3: Successful Set TR Deq Ptr cmd, deq = @fff49010
[ 87.930564] xhci_hcd 0000:0c:00.3: drop ep 0x83, slot id 4, new drop flags = 0x80, new add flags = 0x0
[ 87.937756] xhci_hcd 0000:0c:00.3: Successful Endpoint Configure command
The host still dies on disconnection, but the stuck command is now the
configure endpoint dropping 0x83 of the 2-1.4 hub (slot 6):
[ 164.793408] usb 2-1: USB disconnect, device number 2
[ 164.793419] usb 2-1.3: USB disconnect, device number 3
...
[ 164.803390] usb 2-1.4: USB disconnect, device number 4
...
[ 164.834173] xhci_hcd 0000:0c:00.3: Cancel URB 000000009ac4b95a, dev 1.4, ep 0x83, starting at offset 0xfff15010
[ 164.834219] xhci_hcd 0000:0c:00.3: Stopped on Transfer TRB for slot 6 ep 6
[ 164.834819] xhci_hcd 0000:0c:00.3: drop ep 0x83, slot id 6, new drop flags = 0x80, new add flags = 0x0
[ 170.058142] xhci_hcd 0000:0c:00.3: Command timeout, USBSTS: 0x00000010 PCD
[ 185.909602] xhci_hcd 0000:0c:00.3: Abort failed to stop command ring: -110
[ 185.921446] xhci_hcd 0000:0c:00.3: xHCI host controller not responding, assume dead
If 2-1 is deconfigured instead, the same command completes for all
three hubs (2-1.3, 2-1.4 and 2-1 on slots 4, 6 and 2) while still
connected, and the host survives the unplug:
[ 165.209890] xhci_hcd 0000:0c:00.3: drop ep 0x83, slot id 4, new drop flags = 0x80, new add flags = 0x0
[ 165.210644] xhci_hcd 0000:0c:00.3: Successful Endpoint Configure command
...
[ 165.397383] xhci_hcd 0000:0c:00.3: drop ep 0x83, slot id 6, new drop flags = 0x80, new add flags = 0x0
[ 165.402651] xhci_hcd 0000:0c:00.3: Successful Endpoint Configure command
...
[ 165.404152] xhci_hcd 0000:0c:00.3: drop ep 0x83, slot id 2, new drop flags = 0x80, new add flags = 0x0
[ 165.418650] xhci_hcd 0000:0c:00.3: Successful Endpoint Configure command
...
[ 173.245013] usb 2-1: USB disconnect, device number 2
So far this command has only hung when issued after the disconnect.
Thanks,
Henry
next prev parent reply other threads:[~2026-10-08 10:25 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 10:17 [PATCH 0/2] xhci: handshake timeout overrun and configure endpoint hang on device disconnect Henry Tseng
2026-09-30 10:17 ` [PATCH 1/2] xhci: make xhci_handshake() timeout wall-clock based again Henry Tseng
2026-09-30 10:17 ` [PATCH 2/2] xhci: skip configure endpoint when dropping endpoints of a disconnected device Henry Tseng
2026-10-02 9:30 ` [PATCH 0/2] xhci: handshake timeout overrun and configure endpoint hang on device disconnect Michal Pecio
2026-10-07 9:52 ` Henry Tseng
2026-10-08 9:06 ` Michal Pecio
2026-10-08 9:13 ` Michal Pecio
2026-10-08 10:25 ` Henry Tseng [this message]
2026-10-09 15:35 ` Michal Pecio
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008102522.109308-1-henrytseng@qnap.com \
--to=henrytseng@qnap.com \
--cc=gregkh@linuxfoundation.org \
--cc=linux-usb@vger.kernel.org \
--cc=mathias.nyman@intel.com \
--cc=michal.pecio@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox