On 21/09/2026 07.46, Junjie Cao wrote:
The endpoint type in the xHCI endpoint context comes from the guest and
is not checked against the device. A guest can configure the interrupt
IN endpoint of usb-kbd as Isoch IN. The idle HID endpoint NAKs, and as
soon as the transfer goes through the retry path in xhci_kick_epctx()
it hits

   assert(xfer->packet.status != USB_RET_NAK);

No device model NAKs on an isoch endpoint, so this only triggers with a
mismatched endpoint type.

The two retry branches differ only in what they do on NAK: the isoch one
asserts, the other keeps the transfer pending. Merge them.

Fixes: 3d1396842d ("xhci: iso xfer support")
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3886
Reported-by: Feifan Qian <[email protected]>
Cc: [email protected]
Signed-off-by: Junjie Cao <[email protected]>
---
  hw/usb/hcd-xhci.c | 27 ++++++++-------------------
  1 file changed, 8 insertions(+), 19 deletions(-)
Reviewed-by: Thomas Huth <[email protected]>


Reply via email to