From: Mathias Nyman <mathias.nyman@linux.intel.com>
To: Ben <benstaples10@gmail.com>,
Mika Westerberg <mika.westerberg@linux.intel.com>
Cc: linux-usb@vger.kernel.org, andreas.noever@gmail.com,
westeri@kernel.org, YehezkelShB@gmail.com
Subject: Re: [WARNING: UNSCANNABLE EXTRACTION FAILED]Re: xhci_hcd 0000:0c:00.0 dies with "Abort failed to stop command ring: -110" exactly 24s post-init, tunneled USB4 xHCI behind Goshen Ridge (ASUS ThunderboltEX 4) + CalDigit TS4
Date: Thu, 24 Sep 2026 18:49:22 +0300 [thread overview]
Message-ID: <2a4026e7-f5d3-4301-bc60-0570cbd7fa09@linux.intel.com> (raw)
In-Reply-To: <CANcA1gAijg6Ftmw9+aeuG+SjKKwKo-HyXb+kfBiGFGj=ZzNvaQ@mail.gmail.com>
On 9/24/26 06:02, Ben wrote:
> Hello,
>
>> It could be that it went into runtime suspend before that. One thing you
>> could try is to connect USB3 device to the dock, like memory stick or so.
>> That would prevent xHCI from entering runtime suspend.
>
> I have had a usb drive plugged into the dock just for quickly checking
> whether the usb ports on the dock are working properly each boot via
> lsusb. I believe that was the case during the boot that I shared.
>
>> Can you see the 0c:00.0 xHCI in the device manager? I would expect yes and
>> then this ends up just being Linux specific issue with the xHCI on GR. I'm
>> adding Mathias in case he has any ideas.
>
> I was truly having a hard time figuring out how to get this
> information on Windows and it really was not cooperating when I booted
> it up.
> If it's still useful, the next time around (or within the next couple
> days when I can find some time) I can confirm this with certainty.
>
>> Can you take snapshot copy of some xHC rings and registers a couple seconds before
>> the crash? following directories would be interesting, (including all files,
>> especially the 'trbs' ones):
>
> I've attached logs that should contain the relevant information around
> the time of this event:
> command-ring msi-irqs.txt pci-irq.txt proc-interrupts.txt
> reg-op uptime.txt
> event-ring pci-enable.txt power-state.txt reg-cap
> reg-runtime
>
>> [ 24.975645] xhci_hcd 0000:0c:00.0: Abort failed to stop command ring: -110
>
> I am providing these and I will hold onto additional ones from 2.48
> seconds into the boot.
> 24.57 /run/xhci-initrd/slot_200
> 24.68 /run/xhci-initrd/slot_201
> 24.79 /run/xhci-initrd/slot_202
> 24.90 /run/xhci-initrd/slot_203
> 25.01 /run/xhci-initrd/slot_204
> 25.12 /run/xhci-initrd/slot_205
>
Thanks for the logs.
Registers show xHC and the command ring are running, but it still didn't process the
'enable slot' command. There are no command completion events on the event ring.
No interrupts either, but that is expected as there are no events.
Odd thing is that event ring is completely empty.
There's usually a port change event when host detects a device, this event triggers
hub driver to start the usb device enumeration process, queuing the 'enable slot'
command as one of the first steps.
Either xHC isn't really running, or fails to write to the event ring.
I noticed that both event and command rings DMA addresses are above 32 bit.
Maybe dmesg log with usb core and xhci dynamic debug enabled could show something.
Can you add the following to the kernel cmd line:
xhci_hcd.dyndbg=+p usbcore.dyndbg=+p
Could also be worth testing with with 32bit DMA mask:
xhci_hcd.quirks=0x800000
Details from slot_200 logs;
reg-op
USBCMD = 0x00000005 xHC is Running with interrupts enabled,
USBSTS = 0x00000010 port change detect active, EINT==0 so no unhandled interrupt pending.
CRCR = 0x00000008 command ring is running
reg-runtime
MFINDEX = 0x00003252
IR0_IMAN = 0x00000002 primary interrupter enabled
IR0_ERDP_LOW = 0x026d3000 event ring dma address has both high and low 32 bit values
IR0_ERDP_HIGH = 0x00000001
command-ring/trbs
0 0x00000001026d1000: Enable Slot Command: flags C
0 0x00000001026d1010: type 'UNKNOWN' -> raw 00000000 00000000 00000000 00000000
event-ring/trbs
0 0x00000001026d3000: type 'UNKNOWN' -> raw 00000000 00000000 00000000 00000000
0 0x00000001026d3010: type 'UNKNOWN' -> raw 00000000 00000000 00000000 00000000
Event ring is empty, command ring shows the Enable Slot command that times out.
Thanks
Mathias
next prev parent reply other threads:[~2026-09-24 15:49 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 4:04 xhci_hcd 0000:0c:00.0 dies with "Abort failed to stop command ring: -110" exactly 24s post-init, tunneled USB4 xHCI behind Goshen Ridge (ASUS ThunderboltEX 4) + CalDigit TS4 Ben
2026-09-15 4:19 ` Mika Westerberg
2026-09-15 4:27 ` Ben
2026-09-15 4:38 ` Mika Westerberg
2026-09-15 4:46 ` Ben
2026-09-15 5:05 ` Mika Westerberg
2026-09-16 3:01 ` Ben
2026-09-16 7:51 ` Mika Westerberg
2026-09-17 2:18 ` Ben
2026-09-17 2:40 ` Ben
2026-09-17 4:38 ` Mika Westerberg
2026-09-19 0:28 ` Ben
2026-09-21 4:44 ` Mika Westerberg
2026-09-21 23:25 ` Ben
2026-09-22 4:26 ` Mika Westerberg
2026-09-22 11:28 ` Mathias Nyman
2026-09-24 3:02 ` Ben
2026-09-24 15:49 ` Mathias Nyman [this message]
2026-09-24 22:18 ` [WARNING: UNSCANNABLE EXTRACTION FAILED]Re: " Ben
2026-09-25 8:27 ` Michal Pecio
2026-09-25 8:40 ` Michal Pecio
2026-09-26 0:28 ` Ben
2026-09-26 8:37 ` Michal Pecio
2026-09-26 13:59 ` Ben
2026-09-26 17:41 ` Michal Pecio
2026-09-29 23:50 ` Ben
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2a4026e7-f5d3-4301-bc60-0570cbd7fa09@linux.intel.com \
--to=mathias.nyman@linux.intel.com \
--cc=YehezkelShB@gmail.com \
--cc=andreas.noever@gmail.com \
--cc=benstaples10@gmail.com \
--cc=linux-usb@vger.kernel.org \
--cc=mika.westerberg@linux.intel.com \
--cc=westeri@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox