Blame 0301-usb-controllers-do-not-need-to-check-for-babble-them.patch

c8dfc6
From d69c3f589874de55e2eae03110a0c696485b8fa7 Mon Sep 17 00:00:00 2001
c8dfc6
From: Hans de Goede <hdegoede@redhat.com>
c8dfc6
Date: Fri, 17 Aug 2012 11:39:16 +0200
c8dfc6
Subject: [PATCH 301/366] usb: controllers do not need to check for babble
c8dfc6
 themselves
c8dfc6
c8dfc6
If an (emulated) usb-device tries to write more data to a packet then
c8dfc6
its iov len, this will trigger an assert in usb_packet_copy(), and if
c8dfc6
a driver somehow circumvents that check and writes more data to the
c8dfc6
iov then there is space, we have a much bigger problem then not correctly
c8dfc6
reporting babble to the guest.
c8dfc6
c8dfc6
In practice babble will only happen with (real) redirected devices, and there
c8dfc6
both the usb-host os and the qemu usb-device code already check for it.
c8dfc6
c8dfc6
Signed-off-by: Hans de Goede <hdegoede@redhat.com>
c8dfc6
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
c8dfc6
---
c8dfc6
 hw/usb/hcd-ehci.c | 4 ----
c8dfc6
 hw/usb/hcd-uhci.c | 5 -----
c8dfc6
 2 files changed, 9 deletions(-)
c8dfc6
c8dfc6
diff --git a/hw/usb/hcd-ehci.c b/hw/usb/hcd-ehci.c
c8dfc6
index 017342b..9523247 100644
c8dfc6
--- a/hw/usb/hcd-ehci.c
c8dfc6
+++ b/hw/usb/hcd-ehci.c
c8dfc6
@@ -1481,10 +1481,6 @@ static void ehci_execute_complete(EHCIQueue *q)
c8dfc6
             assert(0);
c8dfc6
             break;
c8dfc6
         }
c8dfc6
-    } else if ((p->usb_status > p->tbytes) && (p->pid == USB_TOKEN_IN)) {
c8dfc6
-        p->usb_status = USB_RET_BABBLE;
c8dfc6
-        q->qh.token |= (QTD_TOKEN_HALT | QTD_TOKEN_BABBLE);
c8dfc6
-        ehci_raise_irq(q->ehci, USBSTS_ERRINT);
c8dfc6
     } else {
c8dfc6
         // TODO check 4.12 for splits
c8dfc6
 
c8dfc6
diff --git a/hw/usb/hcd-uhci.c b/hw/usb/hcd-uhci.c
c8dfc6
index b0db921..c7c8786 100644
c8dfc6
--- a/hw/usb/hcd-uhci.c
c8dfc6
+++ b/hw/usb/hcd-uhci.c
c8dfc6
@@ -729,11 +729,6 @@ static int uhci_complete_td(UHCIState *s, UHCI_TD *td, UHCIAsync *async, uint32_
c8dfc6
         *int_mask |= 0x01;
c8dfc6
 
c8dfc6
     if (pid == USB_TOKEN_IN) {
c8dfc6
-        if (len > max_len) {
c8dfc6
-            ret = USB_RET_BABBLE;
c8dfc6
-            goto out;
c8dfc6
-        }
c8dfc6
-
c8dfc6
         if ((td->ctrl & TD_CTRL_SPD) && len < max_len) {
c8dfc6
             *int_mask |= 0x02;
c8dfc6
             /* short packet: do not update QH */
c8dfc6
-- 
c8dfc6
1.7.12
c8dfc6