Commit 526867c3 authored by Florian Wolter's avatar Florian Wolter Committed by Sarah Sharp
Browse files

xhci: Fix race between ep halt and URB cancellation

The halted state of a endpoint cannot be cleared over CLEAR_HALT from a
user process, because the stopped_td variable was overwritten in the
handle_stopped_endpoint() function. So the xhci_endpoint_reset() function will
refuse the reset and communication with device can not run over this endpoint.
https://bugzilla.kernel.org/show_bug.cgi?id=60699



Signed-off-by: default avatarFlorian Wolter <wolly84@web.de>
Signed-off-by: default avatarSarah Sharp <sarah.a.sharp@linux.intel.com>
parent 8b3d4570
Loading
Loading
Loading
Loading
+6 −2
Original line number Diff line number Diff line
@@ -869,8 +869,12 @@ remove_finished_td:
		/* Otherwise ring the doorbell(s) to restart queued transfers */
		ring_doorbell_for_active_rings(xhci, slot_id, ep_index);
	}

	/* Clear stopped_td and stopped_trb if endpoint is not halted */
	if (!(ep->ep_state & EP_HALTED)) {
		ep->stopped_td = NULL;
		ep->stopped_trb = NULL;
	}

	/*
	 * Drop the lock and complete the URBs in the cancelled TD list.