Skip to content

Commit 9b66008

Browse files
Thinh Nguyengregkh
authored andcommitted
usb: dwc3: gadget: Fix dwc3_calc_trbs_left()
commit 51f1954ad853d01ba4dc2b35dee14d8490ee05a1 upstream. We can't depend on the TRB's HWO bit to determine if the TRB ring is "full". A TRB is only available when the driver had processed it, not when the controller consumed and relinquished the TRB's ownership to the driver. Otherwise, the driver may overwrite unprocessed TRBs. This can happen when many transfer events accumulate and the system is slow to process them and/or when there are too many small requests. If a request is in the started_list, that means there is one or more unprocessed TRBs remained. Check this instead of the TRB's HWO bit whether the TRB ring is full. Fixes: c423357 ("usb: dwc3: gadget: prepare TRBs on update transfers too") Cc: <stable@vger.kernel.org> Acked-by: Felipe Balbi <balbi@kernel.org> Signed-off-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com> Link: https://lore.kernel.org/r/e91e975affb0d0d02770686afc3a5b9eb84409f6.1629335416.git.Thinh.Nguyen@synopsys.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 015936d commit 9b66008

1 file changed

Lines changed: 8 additions & 8 deletions

File tree

drivers/usb/dwc3/gadget.c

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -928,19 +928,19 @@ static struct dwc3_trb *dwc3_ep_prev_trb(struct dwc3_ep *dep, u8 index)
928928

929929
static u32 dwc3_calc_trbs_left(struct dwc3_ep *dep)
930930
{
931-
struct dwc3_trb *tmp;
932931
u8 trbs_left;
933932

934933
/*
935-
* If enqueue & dequeue are equal than it is either full or empty.
936-
*
937-
* One way to know for sure is if the TRB right before us has HWO bit
938-
* set or not. If it has, then we're definitely full and can't fit any
939-
* more transfers in our ring.
934+
* If the enqueue & dequeue are equal then the TRB ring is either full
935+
* or empty. It's considered full when there are DWC3_TRB_NUM-1 of TRBs
936+
* pending to be processed by the driver.
940937
*/
941938
if (dep->trb_enqueue == dep->trb_dequeue) {
942-
tmp = dwc3_ep_prev_trb(dep, dep->trb_enqueue);
943-
if (tmp->ctrl & DWC3_TRB_CTRL_HWO)
939+
/*
940+
* If there is any request remained in the started_list at
941+
* this point, that means there is no TRB available.
942+
*/
943+
if (!list_empty(&dep->started_list))
944944
return 0;
945945

946946
return DWC3_TRB_NUM - 1;

0 commit comments

Comments
 (0)