Skip to content

Commit fe1ccba

Browse files
Michal Peciogregkh
authored andcommitted
usb: xhci: Skip only one TD on Ring Underrun/Overrun
If skipping is deferred to events other than Missed Service Error itsef, it means we are running on an xHCI 1.0 host and don't know how many TDs were missed until we reach some ordinary transfer completion event. And in case of ring xrun, we can't know where the xrun happened either. If we skip all pending TDs, we may prematurely give back TDs added after the xrun had occurred, risking data loss or buffer UAF by the xHC. If we skip none, a driver may become confused and stop working when all its URBs are missed and appear to be "in flight" forever. Skip exactly one TD on each xrun event - the first one that was missed, as we can now be sure that the HC has finished processing it. Provided that one more TD is queued before any subsequent doorbell ring, it will become safe to skip another TD by the time we get an xrun again. Signed-off-by: Michal Pecio <[email protected]> Signed-off-by: Mathias Nyman <[email protected]> Link: https://lore.kernel.org/r/[email protected] Signed-off-by: Greg Kroah-Hartman <[email protected]>
1 parent d0b6195 commit fe1ccba

File tree

1 file changed

+14
-1
lines changed

1 file changed

+14
-1
lines changed

drivers/usb/host/xhci-ring.c

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2843,8 +2843,21 @@ static int handle_tx_event(struct xhci_hcd *xhci,
28432843
return 0;
28442844

28452845
skip_isoc_td(xhci, td, ep, status);
2846-
if (!list_empty(&ep_ring->td_list))
2846+
2847+
if (!list_empty(&ep_ring->td_list)) {
2848+
if (ring_xrun_event) {
2849+
/*
2850+
* If we are here, we are on xHCI 1.0 host with no
2851+
* idea how many TDs were missed or where the xrun
2852+
* occurred. New TDs may have been added after the
2853+
* xrun, so skip only one TD to be safe.
2854+
*/
2855+
xhci_dbg(xhci, "Skipped one TD for slot %u ep %u",
2856+
slot_id, ep_index);
2857+
return 0;
2858+
}
28472859
continue;
2860+
}
28482861

28492862
xhci_dbg(xhci, "All TDs skipped for slot %u ep %u. Clear skip flag.\n",
28502863
slot_id, ep_index);

0 commit comments

Comments
 (0)