From: Greg KH <greg@kroah.com>
To: Markus Rechberger <mrechberger@gmail.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>,
linux-usb@vger.kernel.org, werner@guyane.dyn-o-saur.com,
Marcus Meissner <meissner@suse.de>,
linux-kernel@vger.kernel.org
Subject: Re: 2.6.33 bugs (USBFS, Intel graphic)
Date: Fri, 26 Feb 2010 21:26:48 -0800 [thread overview]
Message-ID: <20100227052648.GA31418@kroah.com> (raw)
In-Reply-To: <20100227051737.GA14976@kroah.com>
On Fri, Feb 26, 2010 at 09:17:37PM -0800, Greg KH wrote:
> On Sat, Feb 27, 2010 at 05:34:27AM +0100, Markus Rechberger wrote:
> > On Sat, Feb 27, 2010 at 5:29 AM, Linus Torvalds
> > <torvalds@linux-foundation.org> wrote:
> > >
> > >
> > > On Fri, 26 Feb 2010, Greg KH wrote:
> > >>
> > >> Yes, and that patch didn't touch the iso frames. ?That happens later on
> > >> in the functions that were modified. ?The patch should not have had any
> > >> affect on iso transfers. ?Unless I'm missing something?
> > >
> > > Hmm. What seems to happen is that for an isochronous transfer, the buffer
> > > is split for each microframe. No?
> > >
> >
> > exactly. and each microframe has its own buffer length identifier.
> >
> > the current behaviour breaks VMware, QEMU and virtualbox .. probably
> > other things too.
> >
> >
> > > So the total length may be in 'urb->actual_length', but the actual data in
> > > the buffer may not be contiguous, because it's created from multiple
> > > smaller frames, some of which might not be full length?
> > >
> >
> > yes, it's only contiguous for BULK.
> >
> > > I dunno. That would explain the problem - actual_length is correct, but
> > > the 'copy_to_user()' still doesn't copy all the data, because it's
> > > fragmented.
> > >
> >
> > no you got it, but your patch does not work. The best way would be to
> > revert it if someone wants to speed up BULK it should go down another
> > path, leaving the old working implementation untouched.
>
> Hm, so it's back to the original idea of just doing a kzalloc of the
> initial buffer, that should solve the problem that Marcus found.
>
> I'll go dig that back up and if you could test it, that would be most
> appreciated.
Here, can you try this on top of everything?
thanks,
greg k-h
diff --git a/drivers/usb/core/devio.c b/drivers/usb/core/devio.c
index a678186..252d3b4 100644
--- a/drivers/usb/core/devio.c
+++ b/drivers/usb/core/devio.c
@@ -1168,7 +1168,7 @@ static int proc_do_submiturb(struct dev_state *ps, struct usbdevfs_urb *uurb,
return -ENOMEM;
}
if (uurb->buffer_length > 0) {
- as->urb->transfer_buffer = kmalloc(uurb->buffer_length,
+ as->urb->transfer_buffer = kzalloc(uurb->buffer_length,
GFP_KERNEL);
if (!as->urb->transfer_buffer) {
kfree(isopkt);
@@ -1312,9 +1312,9 @@ static int processcompl(struct async *as, void __user * __user *arg)
void __user *addr = as->userurb;
unsigned int i;
- if (as->userbuffer && urb->actual_length)
+ if (as->userbuffer)
if (copy_to_user(as->userbuffer, urb->transfer_buffer,
- urb->actual_length))
+ urb->transfer_buffer_length))
goto err_out;
if (put_user(as->status, &userurb->status))
goto err_out;
@@ -1480,9 +1480,9 @@ static int processcompl_compat(struct async *as, void __user * __user *arg)
void __user *addr = as->userurb;
unsigned int i;
- if (as->userbuffer && urb->actual_length)
+ if (as->userbuffer)
if (copy_to_user(as->userbuffer, urb->transfer_buffer,
- urb->actual_length))
+ urb->transfer_buffer_length))
return -EFAULT;
if (put_user(as->status, &userurb->status))
return -EFAULT;
next prev parent reply other threads:[~2010-02-27 5:26 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-02-27 3:42 2.6.33 bugs (USBFS, Intel graphic) Markus Rechberger
2010-02-27 3:56 ` Greg KH
2010-02-27 4:05 ` Markus Rechberger
2010-02-27 4:18 ` Greg KH
2010-02-27 4:29 ` Linus Torvalds
2010-02-27 4:34 ` Markus Rechberger
2010-02-27 5:17 ` Greg KH
2010-02-27 5:26 ` Greg KH [this message]
2010-02-27 5:38 ` Markus Rechberger
2010-02-27 5:48 ` Greg KH
2010-02-27 11:00 ` Markus Rechberger
2010-02-27 12:15 ` Pekka Enberg
2010-02-27 12:17 ` Pekka Enberg
2010-02-27 16:49 ` Jesse Barnes
2010-02-27 18:08 ` Markus Rechberger
2010-02-27 22:33 ` Markus Rechberger
2010-02-27 17:20 ` Alan Stern
2010-03-03 0:09 ` Greg KH
2010-03-05 21:37 ` Markus Rechberger
2010-03-06 16:30 ` Markus Rechberger
2010-03-06 17:06 ` Greg KH
2010-03-06 20:04 ` Alan Stern
2010-02-27 4:11 ` Linus Torvalds
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20100227052648.GA31418@kroah.com \
--to=greg@kroah.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=meissner@suse.de \
--cc=mrechberger@gmail.com \
--cc=torvalds@linux-foundation.org \
--cc=werner@guyane.dyn-o-saur.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox