[PATCH 0/5] xhci: Sort out the TD skipping business

Michal Pecio <[email protected]> Tue, 4 Aug 2026 12:01:10 +0200
Newsgroups org.kernel.vger.linux-usb,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Hi,

This series is motivated by a recently found rare regression due to
my commit from last year and the solution suggested by Mathias Nyman.

https://lore.kernel.org/linux-usb/al_hchyOdPoPWKEo@spiral/

I think it's a good solution not only for this specific case, but also
in general, because the next event after Missed Service Error almost
always references some TD - exceptions are Ring Underrun, which we
have special handling for, and Stopped - Length Invalid, which would
be a rare occurrence, not currently supported anyway, and possible
to support within the proposed framework by making find_td_by_dma()
calculate accurate 'missed_tds' value while still returning NULL.

The first two patches fix bugs, because I found another obscure one.
The next two patches prepare for the last one by simplifying things.

The last patch implements the big change, the whole matching/skipping
loop is replaced with a more straightforward and robust version. New
functionality is paid for with a net increase of 4 LOC, not too bad.

I gave this a bit of testing and it seems to be working, including
weird cases like: Missed Service Error retires a waiting TD with
error_mid_td, then skipping is triggered by another Transaction Error
immediately afterwards, and it turns out that two TDs were missed.

[ 1665.224921] xhci_hcd 0000:0a:00.0: Transfer error for slot 1 ep 2 on endpoint
[ 1665.225151] xhci_hcd 0000:0a:00.0: Missed Service Error for slot 1 ep 2, skip 1, try now 0
[ 1665.225156] xhci_hcd 0000:0a:00.0: Missing TD completion event after mid TD error
[ 1665.225305] xhci_hcd 0000:0a:00.0: Transfer error for slot 1 ep 2 on endpoint
[ 1665.225308] xhci_hcd 0000:0a:00.0: Skipped 2 TDs on slot 1 ep 2 comp_code 4, TD found 1, skip flag 0

Additional testing of patch 1 in isolation would be appreciated from
the reporter of the regression (Cc). That patch would go to v6.18.

Regards,
Michal

Michal Pecio (5):
  usb: xhci: Handle bogus TRB pointers in Missed Service Error events
  usb: xhci: Guarantee URB giveback on Ring Underrun/Overrun
  usb: xhci: Don't set the skip flag on non-isoc endpoints
  usb: xhci: Shorten the TD skipping loop
  usb: xhci: Rework and improve the TD matching and skipping logic

 drivers/usb/host/xhci-ring.c | 200 ++++++++++++++++++-----------------
 1 file changed, 102 insertions(+), 98 deletions(-)

-- 
2.48.1