From: Selvarasu Ganesan <selvarasu.g@samsung.com>
To: Thinh Nguyen <Thinh.Nguyen@synopsys.com>
Cc: "gregkh@linuxfoundation.org" <gregkh@linuxfoundation.org>,
"linux-usb@vger.kernel.org" <linux-usb@vger.kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"jh0801.jung@samsung.com" <jh0801.jung@samsung.com>,
"dh10.jung@samsung.com" <dh10.jung@samsung.com>,
"akash.m5@samsung.com" <akash.m5@samsung.com>,
"hongpooh.kim@samsung.com" <hongpooh.kim@samsung.com>,
"eomji.oh@samsung.com" <eomji.oh@samsung.com>,
"h10.kim@samsung.com" <h10.kim@samsung.com>,
"shijie.cai@samsung.com" <shijie.cai@samsung.com>,
"alim.akhtar@samsung.com" <alim.akhtar@samsung.com>,
"muhammed.ali@samsung.com" <muhammed.ali@samsung.com>,
"thiagu.r@samsung.com" <thiagu.r@samsung.com>,
"pritam.sutar@samsung.com" <pritam.sutar@samsung.com>,
"stable@vger.kernel.org" <stable@vger.kernel.org>
Subject: Re: [PATCH v3] usb: dwc3: gadget: Prevent EP resource conflicts during StartTransfer
Date: Wed, 7 Oct 2026 19:44:58 +0530 [thread overview]
Message-ID: <98f16da0-5e24-4dd1-8f9f-79a1a5e7656c@samsung.com> (raw)
In-Reply-To: <ff5d6900-374b-44d8-967f-0af16ae53437@samsung.com>
On 10/7/2026 7:27 PM, Selvarasu Ganesan wrote:
> On 10/7/2026 7:36 AM, Thinh Nguyen wrote:
>> On Tue, Oct 06, 2026, Selvarasu Ganesan wrote:
>>>> /* Clear out the ep descriptors for non-ep0 */
>>>> @@ -1792,9 +1815,9 @@ static int __dwc3_stop_active_transfer(struct dwc3_ep *dep, bool force, bool int
>>>>
>>>> dep->resource_index = 0;
>>>>
>>>> - if (!interrupt)
>>>> + if (!interrupt || ret)
>>> Hi Thinh,
>>>
>>> Thanks for your code changes. The given code changes look good to me and
>>> are working as expected.
>>>
>>> There is one more concern about an uncovered endpoint resource failure
>>> in some corner cases where END TRANSFER timeout is observed (ret = -110).
>>>
>>> The sequence is explained below,
>>>
>>> Step 1:
>>> __dwc3_gadget_ep_set_halt(dep, value=0)
>>> ->dwc3_stop_active_transfer(dep, true, true)
>> Looks like you still do ForceRM=true. Can you apply this patch:
>>
>> b58e6200450d ("usb: dwc3: clear forceRM when issuing EndTransfer")
> We have this fix in our dwc3 driver code. but still observing EP end
> transfer timeout.
>
>
>>> ->END(e.g, ep2out, resource_index=7) issued, but timeout occurs
>>> -> resource_index cleared to 0
>>> ->dwc3_send_clear_stall_ep_cmd(dep)
>>> -> failed to clear STALL on ep2out
>>>
>>>
>>> Step 2:
>>> __dwc3_gadget_ep_set_halt(dep, value=0) ->Re triggered clear stall for
>>> same EP
>>> -> dwc3_stop_active_transfer(dep, true, true)
>>> -> END(ep2out, resource_index=0) issued (wrong resource!)
>>> -> Command succeeds, DWC3_EP_TRANSFER_STARTED cleared in
>>> completion handler
>>>
>>> Step 3:
>>> usb_ep_queue()
>>> -> dwc3_gadget_ep_queue()
>>> -> __dwc3_gadget_kick_transfer()
>>> -> starting = !(dep->flags & DWC3_EP_TRANSFER_STARTED) -> starting=0
>>> -> Issues STARTTRANSFER (because DWC3_EP_TRANSFER_STARTED is not
>>> set)
>>> -> Hardware rejects with NO_RESOURCE (resource 7 still held)
>>>
>>>
>>> Could you please give your suggestions on this issue case?
>>>
>> Thanks for testing. Can you check whether the End Transfer command ever
>> completes with the endpoint completion event after the -ETIMEDOUT error?
>
> No, the endpoint completion event is not seen after the -ETIMEDOUT error.
>
> The proposed fix works well for the __dwc3_gadget_ep_set_halt sequence,
> where DWC3_EP_END_TRANSFER_PENDING must be set to prevent dwc3_ep_queue
> from starting a new transfer during a EP transfer timeout.
>
> But, this is unnecessary for __dwc3_gadget_ep_disable. Since there's no
> way to clear the pending flag if the interrupt is missed and no
> dwc3_ep_queue calls occur until the EP is re-enabled, preserving
> DWC3_EP_END_TRANSFER_PENDING here provides no benefit.
> So, the below changes is not necessary in ep disable,
>
> @@ -1096,6 +1110,15 @@ static int __dwc3_gadget_ep_disable(struct
> dwc3_ep *dep) */
> if (dep->flags & DWC3_EP_DELAY_STOP)
> mask |= (DWC3_EP_DELAY_STOP | DWC3_EP_TRANSFER_STARTED);
> + + /* + * The End Transfer command is still in progress. Do not clear
> the + * flags, so that the ep is only rearmed once the command
> completes. + */ + if (dep->flags & DWC3_EP_END_TRANSFER_PENDING) + mask
> |= (DWC3_EP_END_TRANSFER_PENDING | + DWC3_EP_TRANSFER_STARTED); +
>
> Instead, keep our suggestion changes that prevent the manipulation of
> dep->flags due to the race condition between dwc3_gadget_ep_disable()
> and dwc3_gadget_ep_queue(), since this race observing in long run rndis
> test.
>
> + + /* + * When dwc3_gadget_ep_disable() calls dwc3_gadget_giveback(), +
> * the dwc->lock is temporarily released. If dwc3_gadget_ep_queue() + *
> runs in that window it may set the DWC3_EP_TRANSFER_STARTED flag as + *
> part of dwc3_send_gadget_ep_cmd. The original code cleared the flag + *
> unconditionally in the mask operation, which could overwrite the + *
> concurrent modification. + * + * As a workaround for the interrupt
> context constraint where we cannot + * wait for endpoint flushing,
> preserve the DWC3_EP_TRANSFER_STARTED + * flag if it is set, avoiding
> resource conflicts until the framework + * is fixed to properly
> synchronize endpoint lifecycle management. + */ + if (dep->flags &
> DWC3_EP_TRANSFER_STARTED) + mask |= DWC3_EP_TRANSFER_STARTED; +
>
>
> Thanks,
> Selva
Sorry for the format issue. The updated answers as below,
No, the endpoint completion event is not seen after the -ETIMEDOUT error.
The proposed fix works well for the __dwc3_gadget_ep_set_halt sequence,
where DWC3_EP_END_TRANSFER_PENDING must be set to prevent dwc3_ep_queue
from starting a new transfer during a EP transfer timeout.
But, this is unnecessary for __dwc3_gadget_ep_disable. Since there's no
way to clear the pending flag if the interrupt is missed and no
dwc3_ep_queue calls occur until the EP is re-enabled, preserving
DWC3_EP_END_TRANSFER_PENDING here provides no benefit.
So, the below changes is not necessary in ep disable,
@@ -1096,6 +1144,15 @@ static int __dwc3_gadget_ep_disable(struct
dwc3_ep *dep)
*/
if (dep->flags & DWC3_EP_DELAY_STOP)
mask |= (DWC3_EP_DELAY_STOP | DWC3_EP_TRANSFER_STARTED);
+
+ /*
+ * The End Transfer command is still in progress. Do not clear the
+ * flags, so that the ep is only rearmed once the command completes.
+ */
+ if (dep->flags & DWC3_EP_END_TRANSFER_PENDING)
+ mask |= (DWC3_EP_END_TRANSFER_PENDING |
+ DWC3_EP_TRANSFER_STARTED);
+
Instead, keep our suggestion changes that prevent the manipulation of
dep->flags due to the race condition between dwc3_gadget_ep_disable()
and dwc3_gadget_ep_queue(), since this race observing in long run rndis
test.
+
+ /*
+ * When dwc3_gadget_ep_disable() calls dwc3_gadget_giveback(),
+ * the dwc->lock is temporarily released. If dwc3_gadget_ep_queue()
+ * runs in that window it may set the DWC3_EP_TRANSFER_STARTED
flag as
+ * part of dwc3_send_gadget_ep_cmd. The original code cleared
the flag
+ * unconditionally in the mask operation, which could overwrite the
+ * concurrent modification.
+ *
+ * As a workaround for the interrupt context constraint where we
cannot
+ * wait for endpoint flushing, preserve the DWC3_EP_TRANSFER_STARTED
+ * flag if it is set, avoiding resource conflicts until the
framework
+ * is fixed to properly synchronize endpoint lifecycle management.
+ */
+ if (dep->flags & DWC3_EP_TRANSFER_STARTED)
+ mask |= DWC3_EP_TRANSFER_STARTED;
+
Thanks,
Selva
>> Try with the below.
>>
>> Thanks,
>> Thinh
>>
>> diff --git a/drivers/usb/dwc3/gadget.c b/drivers/usb/dwc3/gadget.c
>> index 1f973e546219..bac0328423cd 100644
>> --- a/drivers/usb/dwc3/gadget.c
>> +++ b/drivers/usb/dwc3/gadget.c
>> @@ -1819,7 +1819,11 @@ static int __dwc3_stop_active_transfer(struct dwc3_ep *dep, bool force, bool int
>>
>> dep->resource_index = 0;
>>
>> - if (!interrupt || ret)
>> + if (!interrupt || (ret && ret != -ETIMEDOUT))
>> dep->flags &= ~DWC3_EP_TRANSFER_STARTED;
>> else
>> dep->flags |= DWC3_EP_END_TRANSFER_PENDING;
>> @@ -3895,6 +3899,8 @@ static void dwc3_gadget_endpoint_command_complete(struct dwc3_ep *dep,
>> if (dep->stream_capable)
>> dep->flags |= DWC3_EP_IGNORE_NEXT_NOSTREAM;
>>
>> + dep->flags &= ~DWC3_EP_DELAY_STOP;
>> dep->flags &= ~DWC3_EP_END_TRANSFER_PENDING;
>> dep->flags &= ~DWC3_EP_TRANSFER_STARTED;
>> dwc3_gadget_ep_cleanup_cancelled_requests(dep);
next prev parent reply other threads:[~2026-10-07 14:15 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <CGME20260227121338epcas5p4baebb406db37f07223545b2f85751bf2@epcas5p4.samsung.com>
2026-02-27 12:12 ` Selvarasu Ganesan
2026-02-28 0:27 ` Thinh Nguyen
2026-03-03 0:39 ` Thinh Nguyen
2026-03-06 13:06 ` Selvarasu Ganesan
2026-03-06 21:41 ` Thinh Nguyen
2026-09-24 12:05 ` Selvarasu Ganesan
2026-09-24 12:24 ` Selvarasu Ganesan
2026-09-29 3:08 ` Thinh Nguyen
2026-09-29 7:04 ` Selvarasu Ganesan
2026-10-03 1:59 ` Thinh Nguyen
2026-10-06 15:52 ` Selvarasu Ganesan
2026-10-07 2:06 ` Thinh Nguyen
2026-10-07 13:57 ` Selvarasu Ganesan
2026-10-07 14:14 ` Selvarasu Ganesan [this message]
2026-10-07 23:59 ` Thinh Nguyen
2026-10-08 4:37 ` Selvarasu Ganesan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=98f16da0-5e24-4dd1-8f9f-79a1a5e7656c@samsung.com \
--to=selvarasu.g@samsung.com \
--cc=Thinh.Nguyen@synopsys.com \
--cc=akash.m5@samsung.com \
--cc=alim.akhtar@samsung.com \
--cc=dh10.jung@samsung.com \
--cc=eomji.oh@samsung.com \
--cc=gregkh@linuxfoundation.org \
--cc=h10.kim@samsung.com \
--cc=hongpooh.kim@samsung.com \
--cc=jh0801.jung@samsung.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=muhammed.ali@samsung.com \
--cc=pritam.sutar@samsung.com \
--cc=shijie.cai@samsung.com \
--cc=stable@vger.kernel.org \
--cc=thiagu.r@samsung.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®