[PATCH 0/5] usb: xhci: fix endpoint halt and stall recovery

Stephano Cetola <[email protected]>
Newsgroups org.infradead.lists.barebox
Message-ID <[email protected]>
Recovering from a halted or stalled USB endpoint is broken in the
XHCI driver in several independent ways. An interrupt endpoint
transfer never gets a real chance to complete. Its own timeout
always defeats the hardware's autonomous polling before it can
succeed. When that or any other transfer times out, the resulting
cleanup can hit a BUG_ON in the wrong completion state, corrupt a
pointer used in the recovery command, or leave the endpoint looking
halted even after recovery actually succeeded.

In practice this shows up two ways. Most keypresses still get
through by racing the cleanup against the hardware's real response,
so it looks like occasional dropped keystrokes rather than a dead
keyboard. When the rarer failure paths trigger instead, the keyboard
stops responding entirely until reboot.

This series fixes each of those problems in the order they are
actually hit during recovery. Patch order matters.

reset_ep()'s timeout_ms parameter was inherited from an unrelated
feature (b310b08f087e, "usb: xhci: Honor transfer timeouts") meant
to let data polls like network RX return quickly, not to describe
how long a hardware recovery command needs. Recovery should always
run to completion regardless of the original transfer's timeout, so
this series gives it a fixed one instead.

Found and fixed during USB bring-up on the MNT Pocket Reform
(RK3588S), which appears to be the first board in this tree to
combine an XHCI controller with a polled USB keyboard. Testers on
the official RCORE RK3588 module independently report the same
symptom. USB polling errors appear on screen, and only a reboot
recovers the keyboard.

Signed-off-by: Stephano Cetola <[email protected]>
---
Stephano Cetola (5):
      usb: xhci: tolerate COMP_CTX_STATE in abort_td's final completion check
      usb: xhci: reset_ep: wait for real completion, not the caller's timeout
      usb: xhci: reset_ep: fix misaligned pointer in Set TR Dequeue Pointer
      usb: xhci: xhci_bulk_tx: re-fetch ep_ctx after resetting a halted endpoint
      usb: xhci: wait a real interval for interrupt endpoint transfers

 drivers/usb/host/xhci-ring.c | 29 +++++++++++++++++++----------
 drivers/usb/host/xhci.c      |  2 +-
 2 files changed, 20 insertions(+), 11 deletions(-)
---
base-commit: 9bc1a26592a59919d2ee8c60c273d87d3d9f2e81
change-id: 20260822-send-xhci-fixes-bf1812c6c27e
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.