Linux USB
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Mathias Nyman" <mathias.nyman@linux.intel.com>
Cc: linux-usb@vger.kernel.org
Subject: Re: [PATCH 13/14] usb: xhci: Fix bounce buffer overflow
Date: Fri, 09 Oct 2026 10:15:37 +0000	[thread overview]
Message-ID: <sashiko-outbox-165213@kernel.org> (raw)
In-Reply-To: <20261009095834.561578-14-mathias.nyman@linux.intel.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] usb: xhci: inconsistent TD Size calculation for out-of-spec bulk devices
--

commit f7283e43a6da5355da08e764e6aa96a4a118927d
Author: Michal Pecio <michal.pecio@gmail.com>
Subject: usb: xhci: Fix bounce buffer overflow

High-speed devices with out of spec 1024 byte bulk endpoints exist and
are allowed by USB core, but xhci-hcd always sets packet size to 512.
This commit fixes a bounce buffer overflow for these devices by allocating
a 512 byte bounce buffer and using the correctly clamped packet size
in xhci_align_td().

Link: https://lore.kernel.org/linux-usb/D4tcSGerkYkIV1DmaUo1t8TaR5qQElDLkidn@bugs.sh/

> diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c
> index 243b1fd2b2f68..c23434001e9cb 100644
> --- a/drivers/usb/host/xhci-ring.c
> +++ b/drivers/usb/host/xhci-ring.c
[ ... ]
> @@ -3699,9 +3697,8 @@ int xhci_queue_bulk_tx(struct xhci_hcd *xhci, gfp_t mem_flags,
>  		if (enqd_len + trb_buff_len < full_len) {
>  			field |= TRB_CHAIN;
>  			if (trb_is_link(ring->enqueue + 1)) {
> -				if (xhci_align_td(xhci, urb, enqd_len,
> -						  &trb_buff_len,
> -						  ring->enq_seg)) {
> +				if (xhci_align_td(xhci, urb, enqd_len, &trb_buff_len,
> +						ring->enq_seg, ring->bounce_buf_len)) {

[Severity: Medium]
While xhci_align_td() is correctly updated here to use the clamped
ring->bounce_buf_len, does the xhci_td_remainder() call further down in
xhci_queue_bulk_tx() also need to be updated?

xhci_td_remainder() still relies on the raw 1024-byte max packet size from the
descriptor:

drivers/usb/host/xhci-ring.c:xhci_td_remainder() {
	...
	maxp = xhci_usb_endpoint_maxp(urb->dev, urb->ep);
	total_packet_count = DIV_ROUND_UP(td_total_len, maxp);

	/* Queueing functions don't count the current TRB into transferred */
	return (total_packet_count - ((transferred + trb_buff_len) / maxp));
}

Since the endpoint context and bounce buffer use a clamped 512-byte size, could
this mismatch cause the driver to write an incorrectly small TD Size into the
TRB? If the xHC hardware is using 512 bytes, might this mismatch lead to a
Transfer Ring Expansion Error, babble, or endpoint halt when queueing a bulk
transfer greater than 1024 bytes for a high-speed device with an out-of-spec
1024-byte max packet size?

>  					send_addr = ring->enq_seg->bounce_dma;
>  					/* TD bounced at least, and last on this seg */
>  					td->bounce_seg = ring->enq_seg;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261009095834.561578-1-mathias.nyman@linux.intel.com?part=13

  reply	other threads:[~2026-10-09 10:15 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-09  9:58 [PATCH 00/14] xhci features and fixes for usb-next Mathias Nyman
2026-10-09  9:58 ` [PATCH 01/14] early: usb: xhci-dbc: Handle out of bounds xhci-xdbc capability Mathias Nyman
2026-10-09 10:11   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 02/14] usb: xhci: return an error if the host is not halted Mathias Nyman
2026-10-09 10:13   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 03/14] usb: xhci: Unlock for command abort polling Mathias Nyman
2026-10-09 10:10   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 04/14] usb: xhci: fix typos in comments Mathias Nyman
2026-10-09 10:02   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 05/14] xhci: check device notification type before forwarding wake event Mathias Nyman
2026-10-09 10:10   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 06/14] xhci: dbc: lock the minor IDR on registration failure Mathias Nyman
2026-10-09 10:13   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 07/14] usb: xhci: sideband: fix ring sg table for sub-page TRB segments Mathias Nyman
2026-10-09 10:15   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 08/14] usb: xhci-pci: Add TUSB73x0 definitions Mathias Nyman
2026-10-09 10:07   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 09/14] usb: xhci: Guarantee URB giveback on Ring Underrun/Overrun Mathias Nyman
2026-10-09 10:11   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 10/14] usb: xhci: Don't set the skip flag on non-isoc endpoints Mathias Nyman
2026-10-09 10:16   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 11/14] usb: xhci: Shorten the TD skipping loop Mathias Nyman
2026-10-09 10:06   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 12/14] usb: xhci: Rework and improve the TD matching and skipping logic Mathias Nyman
2026-10-09 10:15   ` sashiko-bot
2026-10-09  9:58 ` [PATCH 13/14] usb: xhci: Fix bounce buffer overflow Mathias Nyman
2026-10-09 10:15   ` sashiko-bot [this message]
2026-10-09  9:58 ` [PATCH 14/14] xhci: Prevent invalid vdev dereference during sideband unregister Mathias Nyman
2026-10-09 10:12   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-165213@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=mathias.nyman@linux.intel.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox