From eec9afd56cbbfd385d3b608a3bf38504353bcd68 Mon Sep 17 00:00:00 2001 From: Pratham Pratap Date: Thu, 25 Feb 2021 21:04:05 +0530 Subject: [PATCH] usb: gadget: Give back request from ep_dequeue Consider a case where DWC3_DEPCMD_ENDTRANSFER command times out, then controller will not receive DWC3_DEPEVT_EPCMDCMPLT event and request queued will not be given back to the function driver from remove_requests. Now, if a function driver(e.g mass storage) tries to dequeue the request, gadget driver will move the request from started_list to cancelled_list but will not giveback the request to function driver causing it to wait forever for the transfer to be completed. This can lead the tasks to be in hung state causing a crash. Fix this by giving back the request from ep_dequeue by cleaning up the cancelled requests. Change-Id: I08b7a766d34992808260788a907054c835402c45 Signed-off-by: Pratham Pratap --- drivers/usb/dwc3/gadget.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/usb/dwc3/gadget.c b/drivers/usb/dwc3/gadget.c index b02dadcbab1f..cf630970a3c3 100644 --- a/drivers/usb/dwc3/gadget.c +++ b/drivers/usb/dwc3/gadget.c @@ -1779,6 +1779,12 @@ static int dwc3_gadget_ep_dequeue(struct usb_ep *ep, list_for_each_entry_safe(r, t, &dep->started_list, list) dwc3_gadget_move_cancelled_request(r); + /* If ep isn't started, then there's no end transfer + * pending + */ + if (!(dep->flags & DWC3_EP_END_TRANSFER_PENDING)) + dwc3_gadget_ep_cleanup_cancelled_requests(dep); + goto out; } }