mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
	akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
	Alan Stern <stern@rowland.harvard.edu>,
	David Brownell <david-b@pacbell.net>
Subject: [15/23] ehci-hcd: Bug fix: dont set a QHs Halt bit
Date: Fri, 25 Mar 2011 16:55:52 -0700	[thread overview]
Message-ID: <20110325235638.009159575@clark.kroah.org> (raw)
In-Reply-To: <20110325235654.GA24416@kroah.com>

[-- Attachment #1: ehci-hcd-bug-fix-don-t-set-a-qh-s-halt-bit.patch --]
[-- Type: text/plain, Size: 2753 bytes --]

From: Alan Stern <stern@rowland.harvard.edu>

commit b5a3b3d985493c173925907adfebf3edab236fe7 upstream.

This patch (as1453) fixes a long-standing bug in the ehci-hcd driver.

There is no need to set the Halt bit in the overlay region for an
unlinked or blocked QH.  Contrary to what the comment says, setting
the Halt bit does not cause the QH to be patched later; that decision
(made in qh_refresh()) depends only on whether the QH is currently
pointing to a valid qTD.  Likewise, setting the Halt bit does not
prevent completions from activating the QH while it is "stopped"; they
are prevented by the fact that qh_completions() temporarily changes
qh->qh_state to QH_STATE_COMPLETING.

On the other hand, there are circumstances in which the QH will be
reactivated _without_ being patched; this happens after an URB beyond
the head of the queue is unlinked.  Setting the Halt bit will then
cause the hardware to see the QH with both the Active and Halt bits
set, an invalid combination that will prevent the queue from
advancing and may even crash some controllers.

Apparently the only reason this hasn't been reported before is that
unlinking URBs from the middle of a running queue is quite uncommon.
However Test 17, recently added to the usbtest driver, does exactly
this, and it confirms the presence of the bug.

In short, there is no reason to set the Halt bit for an unlinked or
blocked QH, and there is a very good reason not to set it.  Therefore
the code that sets it is removed.

Signed-off-by: Alan Stern <stern@rowland.harvard.edu>
Tested-by: Andiry Xu <andiry.xu@amd.com>
CC: David Brownell <david-b@pacbell.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 drivers/usb/host/ehci-q.c |   12 ------------
 1 file changed, 12 deletions(-)

--- a/drivers/usb/host/ehci-q.c
+++ b/drivers/usb/host/ehci-q.c
@@ -315,7 +315,6 @@ qh_completions (struct ehci_hcd *ehci, s
 	int			stopped;
 	unsigned		count = 0;
 	u8			state;
-	const __le32		halt = HALT_BIT(ehci);
 	struct ehci_qh_hw	*hw = qh->hw;
 
 	if (unlikely (list_empty (&qh->qtd_list)))
@@ -422,7 +421,6 @@ qh_completions (struct ehci_hcd *ehci, s
 					&& !(qtd->hw_alt_next
 						& EHCI_LIST_END(ehci))) {
 				stopped = 1;
-				goto halt;
 			}
 
 		/* stop scanning when we reach qtds the hc is using */
@@ -456,16 +454,6 @@ qh_completions (struct ehci_hcd *ehci, s
 				 */
 				ehci_clear_tt_buffer(ehci, qh, urb, token);
 			}
-
-			/* force halt for unlinked or blocked qh, so we'll
-			 * patch the qh later and so that completions can't
-			 * activate it while we "know" it's stopped.
-			 */
-			if ((halt & hw->hw_token) == 0) {
-halt:
-				hw->hw_token |= halt;
-				wmb ();
-			}
 		}
 
 		/* unless we already know the urb's status, collect qtd status



  parent reply	other threads:[~2011-03-25 23:58 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20110325235537.660072281@clark.kroah.org>
2011-03-25 23:56 ` [00/23] 2.6.32.36-longterm review Greg KH
2011-03-25 23:55   ` [01/23] aio: wake all waiters when destroying ctx Greg KH
2011-03-25 23:55   ` [02/23] shmem: let shared anonymous be nonlinear again Greg KH
2011-03-25 23:55   ` [03/23] PCI hotplug: acpiphp: set current_state to D0 in register_slot Greg KH
2011-03-25 23:55   ` [04/23] xen: set max_pfn_mapped to the last pfn mapped Greg KH
2011-03-25 23:55   ` [05/23] x86: Cleanup highmap after brk is concluded Greg KH
2011-03-25 23:55   ` [06/23] PCI: return correct value when writing to the "reset" attribute Greg KH
2011-03-25 23:55   ` [07/23] Prevent rt_sigqueueinfo and rt_tgsigqueueinfo from spoofing the signal code Greg KH
2011-03-25 23:55   ` [08/23] ext3: skip orphan cleanup on rocompat fs Greg KH
2011-03-25 23:55   ` [09/23] procfs: fix /proc/<pid>/maps heap check Greg KH
2011-03-25 23:55   ` [10/23] proc: protect mm start_code/end_code in /proc/pid/stat Greg KH
2011-03-25 23:55   ` [11/23] fbcon: Bugfix soft cursor detection in Tile Blitting Greg KH
2011-03-25 23:55   ` [12/23] nfsd41: modify the members value of nfsd4_op_flags Greg KH
2011-03-25 23:55   ` [13/23] nfsd: wrong index used in inner loop Greg KH
2011-03-25 23:55   ` [14/23] [media] uvcvideo: Fix uvc_fixup_video_ctrl() format search Greg KH
2011-03-25 23:55   ` Greg KH [this message]
2011-03-25 23:55   ` [16/23] USB: uss720 fixup refcount position Greg KH
2011-03-25 23:55   ` [17/23] USB: cdc-acm: fix memory corruption / panic Greg KH
2011-03-25 23:55   ` [18/23] USB: cdc-acm: fix potential null-pointer dereference Greg KH
2011-03-25 23:55   ` [19/23] USB: cdc-acm: fix potential null-pointer dereference on disconnect Greg KH
2011-03-25 23:55   ` [20/23] Input: xen-kbdfront - advertise either absolute or relative coordinates Greg KH
2011-03-25 23:55   ` [21/23] SUNRPC: Never reuse the socket port after an xs_close() Greg KH
2011-03-25 23:55   ` [22/23] fs: call security_d_instantiate in d_obtain_alias V2 Greg KH
2011-03-25 23:56   ` [23/23] dcdbas: force SMI to happen when expected Greg KH
2011-03-26  0:50   ` [00/23] 2.6.32.36-longterm review Teck Choon Giam
2011-03-26  4:51     ` Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20110325235638.009159575@clark.kroah.org \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=david-b@pacbell.net \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable-review@kernel.org \
    --cc=stable@kernel.org \
    --cc=stern@rowland.harvard.edu \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®