Linux USB
 help / color / mirror / Atom feed
From: Henry Tseng <henrytseng@qnap.com>
To: Michal Pecio <michal.pecio@gmail.com>
Cc: Henry Tseng <henrytseng@qnap.com>,
	Mathias Nyman <mathias.nyman@intel.com>,
	Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	linux-usb@vger.kernel.org
Subject: Re: [PATCH 0/2] xhci: handshake timeout overrun and configure endpoint hang on device disconnect
Date: Thu,  8 Oct 2026 18:25:20 +0800	[thread overview]
Message-ID: <20261008102522.109308-1-henrytseng@qnap.com> (raw)
In-Reply-To: <20261008110642.56567a92.michal.pecio@gmail.com>

Hi Michal,

On Thu, 8 Oct 2026 11:06:42 +0200, Michal Pecio <michal.pecio@gmail.com> wrote:
> Can you identify the 2-1.3 device? Can it be separated or is all 
> this stuff inside one physical box?
> 

2-1.3 is a hub, 1c04:0018 "QNAP Systems, Inc. USB3.2 Hub". 2-1 and
2-1.4 have the same VID:PID. They are all inside the TL-D800C and
can't be separated.

/:  Bus 001.Port 001: Dev 001, Class=root_hub, Driver=xhci_hcd/4p, 480M
    ID 1d6b:0002 Linux Foundation 2.0 root hub
    |__ Port 001: Dev 002, If 0, Class=Hub, Driver=hub/4p, 480M
        ID 1c04:0018 QNAP System Inc.
        |__ Port 001: Dev 003, If 0, Class=Communications, Driver=cdc_acm, 12M
            ID 04d8:000a Microchip Technology, Inc. CDC RS-232 Emulation Demo
        |__ Port 001: Dev 003, If 1, Class=CDC Data, Driver=cdc_acm, 12M
            ID 04d8:000a Microchip Technology, Inc. CDC RS-232 Emulation Demo
        |__ Port 003: Dev 004, If 0, Class=Hub, Driver=hub/4p, 480M
            ID 1c04:0610 QNAP System Inc.
        |__ Port 004: Dev 005, If 0, Class=Hub, Driver=hub/4p, 480M
            ID 1c04:0610 QNAP System Inc.
/:  Bus 002.Port 001: Dev 001, Class=root_hub, Driver=xhci_hcd/4p, 10000M
    ID 1d6b:0003 Linux Foundation 3.0 root hub
    |__ Port 001: Dev 002, If 0, Class=Hub, Driver=hub/4p, 10000M
        ID 1c04:0018 QNAP System Inc.
        |__ Port 003: Dev 003, If 0, Class=Hub, Driver=hub/4p, 10000M
            ID 1c04:0018 QNAP System Inc.
        |__ Port 004: Dev 004, If 0, Class=Hub, Driver=hub/4p, 10000M
            ID 1c04:0018 QNAP System Inc.
            |__ Port 004: Dev 005, If 0, Class=Mass Storage, Driver=uas, 10000M
                ID 174c:55aa ASMedia Technology Inc. ASM1051E SATA 6Gb/s bridge, ASM1053E SATA 6Gb/s bridge, ASM1153 SATA 3Gb/s bridge, ASM1153E SATA 6Gb/s bridge

> Does it help to blacklist "uas" driver before connecting the whole
> tree? My guess at this point: probably not, it's not a streams bug.
> 

No, the host still dies.

> What happens if deconfigure manually before disconnection:
> 
>   echo 0 > /sys/bus/usb/devices/4-6/bConfigurationValue
> 
> Will it hang on deconfiguration, disconnection, or not at all?
> 

I used 2-1.3 as in your follow-up. The whole tree enumerates the same
way in every run. The logs in patch 2 were taken with an extra USB
stick on 2-2 of the same host, which shifted slot IDs by one, so 2-1.3
was slot 5 there and slot 4 here.

Deconfiguring 2-1.3 completes fine:

  [   87.929570] xhci_hcd 0000:0c:00.3: Cancel URB 0000000064a1e51d, dev 1.3, ep 0x83, starting at offset 0xfff49000
  [   87.929675] xhci_hcd 0000:0c:00.3: Stopped on Transfer TRB for slot 4 ep 6
  [   87.929756] xhci_hcd 0000:0c:00.3: Successful Set TR Deq Ptr cmd, deq = @fff49010
  [   87.930564] xhci_hcd 0000:0c:00.3: drop ep 0x83, slot id 4, new drop flags = 0x80, new add flags = 0x0
  [   87.937756] xhci_hcd 0000:0c:00.3: Successful Endpoint Configure command

The host still dies on disconnection, but the stuck command is now the
configure endpoint dropping 0x83 of the 2-1.4 hub (slot 6):

  [  164.793408] usb 2-1: USB disconnect, device number 2
  [  164.793419] usb 2-1.3: USB disconnect, device number 3
  ...
  [  164.803390] usb 2-1.4: USB disconnect, device number 4
  ...
  [  164.834173] xhci_hcd 0000:0c:00.3: Cancel URB 000000009ac4b95a, dev 1.4, ep 0x83, starting at offset 0xfff15010
  [  164.834219] xhci_hcd 0000:0c:00.3: Stopped on Transfer TRB for slot 6 ep 6
  [  164.834819] xhci_hcd 0000:0c:00.3: drop ep 0x83, slot id 6, new drop flags = 0x80, new add flags = 0x0
  [  170.058142] xhci_hcd 0000:0c:00.3: Command timeout, USBSTS: 0x00000010 PCD
  [  185.909602] xhci_hcd 0000:0c:00.3: Abort failed to stop command ring: -110
  [  185.921446] xhci_hcd 0000:0c:00.3: xHCI host controller not responding, assume dead

If 2-1 is deconfigured instead, the same command completes for all
three hubs (2-1.3, 2-1.4 and 2-1 on slots 4, 6 and 2) while still
connected, and the host survives the unplug:

  [  165.209890] xhci_hcd 0000:0c:00.3: drop ep 0x83, slot id 4, new drop flags = 0x80, new add flags = 0x0
  [  165.210644] xhci_hcd 0000:0c:00.3: Successful Endpoint Configure command
  ...
  [  165.397383] xhci_hcd 0000:0c:00.3: drop ep 0x83, slot id 6, new drop flags = 0x80, new add flags = 0x0
  [  165.402651] xhci_hcd 0000:0c:00.3: Successful Endpoint Configure command
  ...
  [  165.404152] xhci_hcd 0000:0c:00.3: drop ep 0x83, slot id 2, new drop flags = 0x80, new add flags = 0x0
  [  165.418650] xhci_hcd 0000:0c:00.3: Successful Endpoint Configure command
  ...
  [  173.245013] usb 2-1: USB disconnect, device number 2

So far this command has only hung when issued after the disconnect.

Thanks,
Henry

  parent reply	other threads:[~2026-10-08 10:25 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30 10:17 [PATCH 0/2] xhci: handshake timeout overrun and configure endpoint hang on device disconnect Henry Tseng
2026-09-30 10:17 ` [PATCH 1/2] xhci: make xhci_handshake() timeout wall-clock based again Henry Tseng
2026-09-30 10:17 ` [PATCH 2/2] xhci: skip configure endpoint when dropping endpoints of a disconnected device Henry Tseng
2026-10-02  9:30 ` [PATCH 0/2] xhci: handshake timeout overrun and configure endpoint hang on device disconnect Michal Pecio
2026-10-07  9:52   ` Henry Tseng
2026-10-08  9:06     ` Michal Pecio
2026-10-08  9:13       ` Michal Pecio
2026-10-08 10:25       ` Henry Tseng [this message]
2026-10-09 15:35         ` Michal Pecio

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261008102522.109308-1-henrytseng@qnap.com \
    --to=henrytseng@qnap.com \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=mathias.nyman@intel.com \
    --cc=michal.pecio@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox