mirror of
https://github.com/apache/nuttx.git
synced 2026-08-01 20:28:58 +00:00
arch/rp2040: clamp bulk OUT read length to the endpoint max packet size
rp2040_epread() armed the DPSRAM buffer-control register with the full usbdev request length. That length is only correct for requests no larger than the buffer-control LEN field, which is 10 bits wide (max 1023 bytes). Class drivers that post larger read requests -- e.g. cdcncm allocates a 16 KiB NTB read buffer -- overflow LEN: 16384 & 0x3ff is 0, and the high bits corrupt the neighbouring control flags. The controller then sees a zero-length available buffer and completes the transfer immediately with zero bytes, over and over, so no OUT data is ever received (cdcncm floods "Wrong NTH SIGN, skblen 0"). The receive path already accumulates a request across multiple packets: rp2040_rxcomplete() copies each packet, advances xfrd and re-arms via rp2040_rdrequest() until the request is satisfied or a short packet arrives. So the buffer only ever needs to be armed for a single maximum-size packet. Clamp nbytes accordingly. This matches the transmit path, which already chunks to ep.maxpacket in rp2040_wrrequest. Bulk classes with small reads (cdcacm, usbmsc) were unaffected because their request lengths already fit in LEN, which is why the defect only showed up on cdcncm. Validated on raspberrypi-pico (RP2040): a CONFIG_NET_CDCNCM device that previously received nothing now passes traffic in both directions with 0% packet loss. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AHJRvWeBMTHwzpwjaUg4HW Signed-off-by: Ricard Rosson <ricard@groundbits.com>
This commit is contained in:
parent
e593ba35a4
commit
cc77be145a
1 changed files with 14 additions and 0 deletions
|
|
@ -536,6 +536,20 @@ static int rp2040_epread(struct rp2040_ep_s *privep, uint16_t nbytes)
|
|||
uint32_t val;
|
||||
irqstate_t flags;
|
||||
|
||||
/* The hardware receives a single USB packet into the buffer, and the
|
||||
* buffer-control LEN field is only 10 bits wide. Arm the buffer for at
|
||||
* most one maximum-size packet; rp2040_rxcomplete accumulates the request
|
||||
* across multiple packets and re-arms until it is satisfied or a short
|
||||
* packet arrives. Passing the full (possibly multi-kByte) request length
|
||||
* would overflow LEN and corrupt the neighbouring control bits, making the
|
||||
* transfer complete immediately with zero bytes.
|
||||
*/
|
||||
|
||||
if (nbytes > privep->ep.maxpacket)
|
||||
{
|
||||
nbytes = privep->ep.maxpacket;
|
||||
}
|
||||
|
||||
val = nbytes |
|
||||
RP2040_USBCTRL_DPSRAM_EP_BUFF_CTRL_AVAIL |
|
||||
(privep->next_pid ?
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue