U-Boot Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Mattijs Korpershoek <mkorpershoek@kernel.org>
To: Ye Li <ye.li@nxp.com>,
	lukma@denx.de, mkorpershoek@kernel.org, u-boot@lists.denx.de
Cc: festevam@gmail.com, peng.fan@nxp.com, uboot-imx@nxp.com,
	ye.li@oss.nxp.com, xu.yang_2@nxp.com, jason.he_1@nxp.com
Subject: Re: [PATCH 3/3] usb: ci_udc: verify all dtds are inactive before completing request
Date: Tue, 16 Jun 2026 11:30:21 +0200	[thread overview]
Message-ID: <87fr2mhlxu.fsf@kernel.org> (raw)
In-Reply-To: <20260522075512.1291485-3-ye.li@nxp.com>

Hi Ye,

Thank you for the patch.

On Fri, May 22, 2026 at 15:55, Ye Li <ye.li@nxp.com> wrote:

> From: Jason He <jason.he_1@nxp.com>
>
> According to device mode spec, the ACTIVE status field of dtds should
> be check to determine whether the transfers completed successfully.
> However, this is not implemented in handle_ep_complete.
> When two EPs are enabled and transferring, EPa requests with multiple dtds
> and EPb request with one dtd. Irq is triggred on EPb. The udc_irq handler
> finds both EPb's and EPa's ENDPTCOMPLETE=1 while not all of EPa's dtds
> have been completed. Because ACTIVE status is not checked, this case
> causes crash in ci_udc driver.
>
> Signed-off-by: Jason He <jason.he_1@nxp.com>
> Signed-off-by: Ye Li <ye.li@nxp.com>
> ---
>  drivers/usb/gadget/ci_udc.c | 11 +++++++++++
>  1 file changed, 11 insertions(+)
>
> diff --git a/drivers/usb/gadget/ci_udc.c b/drivers/usb/gadget/ci_udc.c
> index 0baad83ef90..53796887dac 100644
> --- a/drivers/usb/gadget/ci_udc.c
> +++ b/drivers/usb/gadget/ci_udc.c
> @@ -733,6 +733,17 @@ static void handle_ep_complete(struct ci_ep *ci_ep)
>  	ci_invalidate_qtd(num);
>  	ci_req = list_first_entry(&ci_ep->queue, struct ci_req, queue);
>  
> +	/* Check all dtd are completed, otherwise return for next irq process */
> +	next_td = item;
> +	for (j = 0; j < ci_req->dtd_count; j++) {
> +		ci_invalidate_td(next_td);
> +		if (next_td->info & INFO_ACTIVE)
> +			return;
> +		if (j != ci_req->dtd_count - 1)
> +			next_td = (struct ept_queue_item *)(unsigned long)
> +				next_td->next;
> +	}

A very similar loop (that walks all the dtds) is just below:

> +
>  	next_td = item;
>  	len = 0;
>  	for (j = 0; j < ci_req->dtd_count; j++) {

Can't we merge both loops together?

> -- 
> 2.37.1

  reply	other threads:[~2026-06-16  9:30 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-22  7:55 [PATCH 1/3] usb: ci_udc: set correct ep type in ep_enable() Ye Li
2026-05-22  7:55 ` [PATCH 2/3] usb: ci_udc: Update usb request status Ye Li
2026-06-16  9:15   ` Mattijs Korpershoek
2026-05-22  7:55 ` [PATCH 3/3] usb: ci_udc: verify all dtds are inactive before completing request Ye Li
2026-06-16  9:30   ` Mattijs Korpershoek [this message]
2026-06-16  9:05 ` [PATCH 1/3] usb: ci_udc: set correct ep type in ep_enable() Mattijs Korpershoek

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87fr2mhlxu.fsf@kernel.org \
    --to=mkorpershoek@kernel.org \
    --cc=festevam@gmail.com \
    --cc=jason.he_1@nxp.com \
    --cc=lukma@denx.de \
    --cc=peng.fan@nxp.com \
    --cc=u-boot@lists.denx.de \
    --cc=uboot-imx@nxp.com \
    --cc=xu.yang_2@nxp.com \
    --cc=ye.li@nxp.com \
    --cc=ye.li@oss.nxp.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox