| From 526867c3ca0caa2e3e846cb993b0f961c33c2abb Mon Sep 17 00:00:00 2001 |
| From: Florian Wolter <wolly84@web.de> |
| Date: Wed, 14 Aug 2013 10:33:16 +0200 |
| Subject: xhci: Fix race between ep halt and URB cancellation |
| |
| From: Florian Wolter <wolly84@web.de> |
| |
| commit 526867c3ca0caa2e3e846cb993b0f961c33c2abb upstream. |
| |
| The halted state of a endpoint cannot be cleared over CLEAR_HALT from a |
| user process, because the stopped_td variable was overwritten in the |
| handle_stopped_endpoint() function. So the xhci_endpoint_reset() function will |
| refuse the reset and communication with device can not run over this endpoint. |
| https://bugzilla.kernel.org/show_bug.cgi?id=60699 |
| |
| Signed-off-by: Florian Wolter <wolly84@web.de> |
| Signed-off-by: Sarah Sharp <sarah.a.sharp@linux.intel.com> |
| Cc: Jonghwan Choi <jhbird.choi@samsung.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| |
| --- |
| drivers/usb/host/xhci-ring.c | 8 ++++++-- |
| 1 file changed, 6 insertions(+), 2 deletions(-) |
| |
| --- a/drivers/usb/host/xhci-ring.c |
| +++ b/drivers/usb/host/xhci-ring.c |
| @@ -857,8 +857,12 @@ remove_finished_td: |
| /* Otherwise ring the doorbell(s) to restart queued transfers */ |
| ring_doorbell_for_active_rings(xhci, slot_id, ep_index); |
| } |
| - ep->stopped_td = NULL; |
| - ep->stopped_trb = NULL; |
| + |
| + /* Clear stopped_td and stopped_trb if endpoint is not halted */ |
| + if (!(ep->ep_state & EP_HALTED)) { |
| + ep->stopped_td = NULL; |
| + ep->stopped_trb = NULL; |
| + } |
| |
| /* |
| * Drop the lock and complete the URBs in the cancelled TD list. |