Linux USB
 help / color / mirror / Atom feed
From: Michal Pecio <michal.pecio@gmail.com>
To: sashiko-bot@kernel.org
Cc: sashiko-reviews@lists.linux.dev,
	"Mathias Nyman" <mathias.nyman@linux.intel.com>,
	linux-usb@vger.kernel.org
Subject: Re: [PATCH v2 09/11] usb: xhci: Rework and improve the TD matching and skipping logic
Date: Sat, 10 Oct 2026 08:16:10 +0200	[thread overview]
Message-ID: <20261010081610.7e5b47e6.michal.pecio@gmail.com> (raw)
In-Reply-To: <sashiko-outbox-165778@kernel.org>

On Fri, 09 Oct 2026 15:34:20 +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] usb: xhci: handle_tx_event() halts >1.0 hosts on bogus MSE pointers
> --
> 
> commit cc3554d902e447131e844c7826abc9b1b4f75f82
> Author: Michal Pecio <michal.pecio@gmail.com>
> 
>     usb: xhci: Rework and improve the TD matching and skipping logic
>     
>     Matching events with TDs and giving back missed TDs is carried out
>     by a complicated loop. Replace it with a simpler linear logic:
>     
>     0. Having verified that 'td_list' isn't empty,
>     1. Scan it to find the matching TD and count missed TDs,
>     2. Perform necessary adjustments for corner cases,
>     3. Give back missed TDs, if applicable, using a short and tidy loop,
>     4. Check if the event refers to the expected TD and proceed as usual.
> 
> > diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c
> > index 7597ef8105c65..243b1fd2b2f68 100644
> > --- a/drivers/usb/host/xhci-ring.c
> > +++ b/drivers/usb/host/xhci-ring.c  
> [ ... ]
> > @@ -2858,66 +2861,50 @@ static int handle_tx_event(struct xhci_hcd *xhci,  
> [ ... ]
> > +	td = find_td_by_dma(ep_ring, &missed_tds, ep_trb_dma);
> >  
> > -			xhci_dbg(xhci,
> > -				 "Found td. Clear skip flag for slot %u ep %u.\n",
> > -				 slot_id, ep_index);
> > +	if (ep->skip) {
> > +		if (!td) {
> > +			/*
> > +			 * xHCI 1.0 allowed MSE events to have zero TRB pointers. Some old chips
> > +			 * also generate bogus non-zero pointers. We know, don't bother warning.
> > +			 * Missed TDs will be given back by the next event with a valid pointer.
> > +			 */
> > +			if (trb_comp_code == COMP_MISSED_SERVICE_ERROR &&
> > +			    xhci->hci_version <= 0x100)
> > +				return 0;  
> 
> [Severity: High]
> Does this code inadvertently halt hosts > 1.0 on bogus MSE pointers?
>
> By restricting the leniency for bogus Missed Service Error (MSE)
> pointers strictly to xHCI 1.0, controllers > 1.0 that generate a
> bogus pointer for MSE will fall through and hit the "HC is busted"
> block below.

Nothing actually gets halted, only warnings are logged, as for any
out-of-spec event that isn't known and dealt with. Specifically, MSE
are being logged since 2025, as we began to process them more.

One HW bug has been reported since then, in old Intel chipsets, not
sure how many PCI IDs are affected. Hence no warnings on xHCI 1.0.
Otherwise, I prefer to keep logging anomalies because it helps with
discovering SW bugs and properly attributing HW bugs to xHCI layer.

Regards,
Michal

  reply	other threads:[~2026-10-10  6:16 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-09 15:16 [PATCH v2 00/11] xhci features and fixes for usb-next Mathias Nyman
2026-10-09 15:16 ` [PATCH v2 01/11] usb: xhci: return an error if the host is not halted Mathias Nyman
2026-10-09 15:24   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 02/11] usb: xhci: Unlock for command abort polling Mathias Nyman
2026-10-09 15:27   ` sashiko-bot
2026-10-10  6:36     ` Michal Pecio
2026-10-09 15:16 ` [PATCH v2 03/11] usb: xhci: fix typos in comments Mathias Nyman
2026-10-09 15:18   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 04/11] xhci: check device notification type before forwarding wake event Mathias Nyman
2026-10-09 15:23   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 05/11] xhci: dbc: lock the minor IDR on registration failure Mathias Nyman
2026-10-09 15:25   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 06/11] usb: xhci: Guarantee URB giveback on Ring Underrun/Overrun Mathias Nyman
2026-10-09 15:25   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 07/11] usb: xhci: Don't set the skip flag on non-isoc endpoints Mathias Nyman
2026-10-09 15:23   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 08/11] usb: xhci: Shorten the TD skipping loop Mathias Nyman
2026-10-09 15:22   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 09/11] usb: xhci: Rework and improve the TD matching and skipping logic Mathias Nyman
2026-10-09 15:34   ` sashiko-bot
2026-10-10  6:16     ` Michal Pecio [this message]
2026-10-09 15:16 ` [PATCH v2 10/11] usb: xhci: Fix bounce buffer overflow Mathias Nyman
2026-10-09 15:28   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 11/11] xhci: Prevent invalid vdev dereference during sideband unregister Mathias Nyman
2026-10-09 15:30   ` sashiko-bot
2026-10-09 22:47     ` Mathias Nyman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261010081610.7e5b47e6.michal.pecio@gmail.com \
    --to=michal.pecio@gmail.com \
    --cc=linux-usb@vger.kernel.org \
    --cc=mathias.nyman@linux.intel.com \
    --cc=sashiko-bot@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox