Re: [PATCH v2] usb: xhci: bail out of setup if the controller is inaccessible

Mathias Nyman <[email protected]>
Newsgroups org.kernel.vger.linux-usb,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
On 7/24/26 12:38, Breno Leitao wrote:
> xhci_gen_setup() locates the operational registers using the capability
> length read from the very first register:
> 
> 	xhci->op_regs = hcd->regs +
> 		HC_LENGTH(readl(&xhci->cap_regs->hc_capbase));
> 
> If the controller is dead or has dropped off the bus, that read returns
> ~0, HC_LENGTH() truncates it to 0xff, and op_regs ends up 0xff bytes
> past the page-aligned MMIO base, i.e. unaligned. The first access
> through it, xhci_halt() -> xhci_handshake() reading op_regs->status, is
> then an unaligned readl() on device memory. arm64 faults on unaligned
> device accesses, so instead of xhci_handshake() catching the all-ones
> value and returning -ENODEV, setup oopses:
> 
>    xhci-pci-renesas 0005:08:00.0: Unable to change power state from D3cold to D0, device inaccessible
>    xhci-pci-renesas 0005:08:00.0: xHCI Host Controller
>    xhci-pci-renesas 0005:08:00.0: new USB bus registered, assigned bus number 1
>    Unable to handle kernel paging request at virtual address ffff80030a770103
>      ESR = 0x0000000096000021
>      FSC = 0x21: alignment fault
>    Internal error: Oops: 0000000096000021 [#1]  SMP
>    pc : xhci_halt [xhci_hcd]
>    Call trace:
>     xhci_halt
>     xhci_gen_setup
>     xhci_pci_setup
>     usb_add_hcd
>     usb_hcd_pci_probe
>     xhci_pci_common_probe
>     xhci_pci_renesas_probe
> 
> This was hit with a Renesas uPD720201 that failed to power up ("Unable
> to change power state from D3cold to D0, device inaccessible") yet still
> reached the HCD probe path.
> 
> Read the capability register once, and if it reads back the all-ones
> value (as xhci_handshake() and xhci_reset() already test for), abort
> setup with -ENODEV before op_regs is derived from it. Reading it once
> also avoids re-reading a register that may change under a concurrent
> hot-removal.
> 
> Fixes: 66d4eadd8d06 ("USB: xhci: BIOS handoff and HW initialization.")
> Cc: [email protected]
> Signed-off-by: Breno Leitao <[email protected]>
> ---

Thanks, added to queue

-Mathias
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.