From: sashiko-bot@kernel.org
To: "Mathias Nyman" <mathias.nyman@linux.intel.com>
Cc: linux-usb@vger.kernel.org
Subject: Re: [PATCH 10/14] usb: xhci: Don't set the skip flag on non-isoc endpoints
Date: Fri, 09 Oct 2026 10:16:14 +0000 [thread overview]
Message-ID: <sashiko-outbox-165215@kernel.org> (raw)
In-Reply-To: <20261009095834.561578-11-mathias.nyman@linux.intel.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] usb: xhci: invalid completion of URB with -EINPROGRESS on COMP_MISSED_SERVICE_ERROR
--
commit dfab6709cb637a348bd004519bdfe39df717cdc4
Author: Michal Pecio <michal.pecio@gmail.com>
usb: xhci: Don't set the skip flag on non-isoc endpoints
These events are unique to isochronous endpoints, ignore them otherwise.
Update debug messages to reflect new policies. We could also log invalid
events as errors, but it seems nobody has ever had problems with that,
so don't bother.
> diff --git a/drivers/usb/host/xhci-ring.c b/drivers/usb/host/xhci-ring.c
> index 8b915a1d5b256..2dd11732bb87c 100644
> --- a/drivers/usb/host/xhci-ring.c
> +++ b/drivers/usb/host/xhci-ring.c
> @@ -2778,16 +2778,18 @@ static int handle_tx_event(struct xhci_hcd *xhci,
> * Set skip flag of the ep_ring; Complete the missed tds as
> * short transfer when process the ep_ring next time.
> */
> - ep->skip = true;
> + if (ep_ring->type == TYPE_ISOC)
> + ep->skip = true;
> xhci_dbg(xhci,
> - "Miss service interval error for slot %u ep %u, set skip flag%s\n",
> - slot_id, ep_index, ep_trb_dma ? ", skip now" : "");
> + "Missed Service Error for slot %u ep %u, skip %d, try now %d\n",
> + slot_id, ep_index, ep->skip, !!ep_trb_dma);
> break;
[Severity: High]
In handle_tx_event() in drivers/usb/host/xhci-ring.c, for non-isochronous
endpoints, does using break instead of return 0 here cause the event to
improperly fall through into the rest of the handler?
If the event's DMA matches the current TD, it appears it is passed to
process_bulk_intr_td() or process_ctrl_td(). Since those functions do not
handle this completion code, does the URB's status remain initialized to
-EINPROGRESS, completing the URB with an illegal status code?
Additionally, if the event DMA does not match the current TD, does the code
fall back to the debug_finding_td error path, fatally shutting down the host
controller with -ESHUTDOWN?
> case COMP_NO_PING_RESPONSE_ERROR:
> - ep->skip = true;
> + if (ep_ring->type == TYPE_ISOC)
> + ep->skip = true;
> xhci_dbg(xhci,
> - "No Ping response error for slot %u ep %u, Skip one Isoc TD\n",
> - slot_id, ep_index);
> + "No Ping response error for slot %u ep %u, skip %d\n",
> + slot_id, ep_index, ep->skip);
> return 0;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261009095834.561578-1-mathias.nyman@linux.intel.com?part=10
next prev parent reply other threads:[~2026-10-09 10:16 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 9:58 [PATCH 00/14] xhci features and fixes for usb-next Mathias Nyman
2026-10-09 9:58 ` [PATCH 01/14] early: usb: xhci-dbc: Handle out of bounds xhci-xdbc capability Mathias Nyman
2026-10-09 10:11 ` sashiko-bot
2026-10-09 14:52 ` Mathias Nyman
2026-10-09 9:58 ` [PATCH 02/14] usb: xhci: return an error if the host is not halted Mathias Nyman
2026-10-09 10:13 ` sashiko-bot
2026-10-09 9:58 ` [PATCH 03/14] usb: xhci: Unlock for command abort polling Mathias Nyman
2026-10-09 10:10 ` sashiko-bot
2026-10-09 9:58 ` [PATCH 04/14] usb: xhci: fix typos in comments Mathias Nyman
2026-10-09 10:02 ` sashiko-bot
2026-10-09 9:58 ` [PATCH 05/14] xhci: check device notification type before forwarding wake event Mathias Nyman
2026-10-09 10:10 ` sashiko-bot
2026-10-09 9:58 ` [PATCH 06/14] xhci: dbc: lock the minor IDR on registration failure Mathias Nyman
2026-10-09 10:13 ` sashiko-bot
2026-10-09 10:51 ` Greg KH
2026-10-09 10:52 ` Greg KH
2026-10-09 11:16 ` Mathias Nyman
2026-10-09 11:23 ` Greg KH
2026-10-09 9:58 ` [PATCH 07/14] usb: xhci: sideband: fix ring sg table for sub-page TRB segments Mathias Nyman
2026-10-09 10:15 ` sashiko-bot
2026-10-09 13:35 ` Mathias Nyman
2026-10-09 9:58 ` [PATCH 08/14] usb: xhci-pci: Add TUSB73x0 definitions Mathias Nyman
2026-10-09 10:07 ` sashiko-bot
2026-10-09 12:15 ` Mathias Nyman
2026-10-09 9:58 ` [PATCH 09/14] usb: xhci: Guarantee URB giveback on Ring Underrun/Overrun Mathias Nyman
2026-10-09 10:11 ` sashiko-bot
2026-10-09 9:58 ` [PATCH 10/14] usb: xhci: Don't set the skip flag on non-isoc endpoints Mathias Nyman
2026-10-09 10:16 ` sashiko-bot [this message]
2026-10-09 12:06 ` Mathias Nyman
2026-10-09 9:58 ` [PATCH 11/14] usb: xhci: Shorten the TD skipping loop Mathias Nyman
2026-10-09 10:06 ` sashiko-bot
2026-10-09 9:58 ` [PATCH 12/14] usb: xhci: Rework and improve the TD matching and skipping logic Mathias Nyman
2026-10-09 10:15 ` sashiko-bot
2026-10-09 9:58 ` [PATCH 13/14] usb: xhci: Fix bounce buffer overflow Mathias Nyman
2026-10-09 10:15 ` sashiko-bot
2026-10-09 9:58 ` [PATCH 14/14] xhci: Prevent invalid vdev dereference during sideband unregister Mathias Nyman
2026-10-09 10:12 ` sashiko-bot
2026-10-09 10:50 ` [PATCH 00/14] xhci features and fixes for usb-next Greg KH
2026-10-09 11:00 ` Mathias Nyman
2026-10-09 12:23 ` Michal Pecio
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-165215@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=mathias.nyman@linux.intel.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox