From nobody Mon Oct  5 21:33:30 2026
X-Original-To: usb@mlmmj.nyi.freebsd.org
Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1])
	by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hzCLL2GbJz6vRrb
	for <usb@mlmmj.nyi.freebsd.org>; Mon, 05 Oct 2026 21:33:30 +0000 (UTC)
	(envelope-from bugzilla-noreply@freebsd.org)
Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256
	 client-signature RSA-PSS (4096 bits) client-digest SHA256)
	(Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified))
	by mx1.freebsd.org (Postfix) with ESMTPS id 4hzCLL1nkVz58kF
	for <usb@FreeBSD.org>; Mon, 05 Oct 2026 21:33:30 +0000 (UTC)
	(envelope-from bugzilla-noreply@freebsd.org)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim;
	t=1791236010;
	h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
	 to:to:cc:mime-version:mime-version:content-type:content-type:
	 content-transfer-encoding:content-transfer-encoding;
	bh=6v4Ff0zPJjxsIvGxoKLULsf8/NqVhenkR6c2XgkB2Lw=;
	b=UnBmP48nzGBWMyjdlu7zEl7FAK377IKVRwULd7jCPgDCuvypmmPjujGm2pCwzKyG0LQiwa
	8gJBKcEmMxNQ+kkjbauB07cxgxDIo6p2/za0r+y0fzXzYKj53ucqZWJjz5bR0li8RbeaGy
	yRIWyWZFigLh4PNOb3zBVqP+Bi+DjgImpyUBP8qencjAfkXyH8UlqSFhjO461FxgmuqRcC
	rLNKDrTwEblpygTwmdB4wjgOj9Tj/W8c/ziYSqlsbYwpnNrh7LbatGuVvGWph2guRpZA6X
	BJQ/47Z1H16PSZIG/pepqPS9GATa0Q87HtUBIWSFvWS4I6cYanX7krUeed5zCQ==
ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1791236010;
	b=H9XAGKCnJB6lil6qfXuHFhZfxIbeFgJ5Qv7LcsLpsZISquudM+szSBCIZ4GYg1tt+qoUG+
	cteDvDWdHgfFdYYdthx3cVPykmV2DMA4HE7JBw4R6VTMi+vNhlXYCwk485fUrjPfzjpf9K
	the/sSSaCy+ulNHwJHJKRiO5ETdlQ8PWDaj/pJjN5jGkXnMje7QbAbZR0mmnLic+DZY6nf
	U7z3G7zkKppxrz/YxHTtNg6dj5fyGcRlc0DlngHNXQ/0E1o62xc6P9FzKjrZvl7wZV2sOn
	jzrlCo7MHv5AU4pLI4p7LXewJ8FqjMn05mZiRC5FFGIxT85HzK/6trXrhxwrRA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org;
	s=dkim; t=1791236010;
	h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
	 to:to:cc:mime-version:mime-version:content-type:content-type:
	 content-transfer-encoding:content-transfer-encoding;
	bh=6v4Ff0zPJjxsIvGxoKLULsf8/NqVhenkR6c2XgkB2Lw=;
	b=CFpHnH8sWf8RqepQF52hAaoVPpHBnHcc38BK2mDJxlFbcKZ7nM9JyKdfvdqvZ1Ije0/S8M
	og21m6GVSPIFwKlpO5yEXtIl5EJmc4vQFIlYdOSfd/uuTbrszerjeazfE0Rxvzpr4Rr0Zi
	6Bznl3SSu5TJszbYkzImUWyx9JxIVnNA/NQc0NE4eu+0NrjOdBWgUraaU4cQpDeSZQ4M8S
	XJ/9JudBWX0NnOtX0Q0D9FPHPkaNf7D3dWNl8bFO1x7BFtaowTnkvDjglNbBtHrm/F4ogs
	ajqBk1rpp0SFxY4kyGQrsVfBGwxXNssgyYTREI0mc3BPhmNRUQyASQM5wYLpjg==
ARC-Authentication-Results: i=1;
	mx1.freebsd.org;
	none
Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256)
	(Client did not present a certificate)
	by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4hzCLL0sB5zfMh
	for <usb@FreeBSD.org>; Mon, 05 Oct 2026 21:33:30 +0000 (UTC)
	(envelope-from bugzilla-noreply@freebsd.org)
Received: from kenobi.freebsd.org ([127.0.1.5])
	by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 695LXUN9052939
	for <usb@FreeBSD.org>; Mon, 5 Oct 2026 21:33:30 GMT
	(envelope-from bugzilla-noreply@freebsd.org)
Received: (from www@localhost)
	by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 695LXU21052938
	for usb@FreeBSD.org; Mon, 5 Oct 2026 21:33:30 GMT
	(envelope-from bugzilla-noreply@freebsd.org)
X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f
From: bugzilla-noreply@freebsd.org
To: usb@FreeBSD.org
Subject: [Bug 299163] xhci: Etron EJ168 requires IOC disabled on Link TRBs
Date: Mon, 05 Oct 2026 21:33:30 +0000
X-Bugzilla-Reason: AssignedTo
X-Bugzilla-Type: new
X-Bugzilla-Watch-Reason: None
X-Bugzilla-Product: Base System
X-Bugzilla-Component: usb
X-Bugzilla-Version: 15.1-RELEASE
X-Bugzilla-Keywords: 
X-Bugzilla-Severity: Affects Some People
X-Bugzilla-Who: guy.wyers@gmail.com
X-Bugzilla-Status: New
X-Bugzilla-Resolution: 
X-Bugzilla-Priority: ---
X-Bugzilla-Assigned-To: usb@FreeBSD.org
X-Bugzilla-Flags: 
X-Bugzilla-Changed-Fields: bug_id short_desc product version rep_platform
 op_sys bug_status bug_severity priority component assigned_to reporter
 attachments.created
Message-ID: <bug-299163-19105@https.bugs.freebsd.org/bugzilla/>
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="UTF-8"
X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/
Auto-Submitted: auto-generated
List-Id: FreeBSD <freebsd-usb.freebsd.org>
List-Archive: https://lists.freebsd.org/archives/freebsd-usb
List-Help: <mailto:usb+help@freebsd.org>
List-Post: <mailto:usb@freebsd.org>
List-Subscribe: <mailto:usb+subscribe@freebsd.org>
List-Unsubscribe: <mailto:usb+unsubscribe@freebsd.org>
X-BeenThere: freebsd-usb@freebsd.org
Sender: owner-freebsd-usb@FreeBSD.org
List-Id: <freebsd-usb.FreeBSD.org>
List-Post: <mailto:freebsd-usb@FreeBSD.org>
List-Help: <mailto:freebsd-usb+help@FreeBSD.org>
List-Subscribe: <mailto:freebsd-usb+subscribe@FreeBSD.org>
List-Unsubscribe: <mailto:freebsd-usb+unsubscribe@FreeBSD.org>
List-Owner: <mailto:postmaster@FreeBSD.org>
Precedence: list
MIME-Version: 1.0

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D299163

            Bug ID: 299163
           Summary: xhci: Etron EJ168 requires IOC disabled on Link TRBs
           Product: Base System
           Version: 15.1-RELEASE
          Hardware: amd64
                OS: Any
            Status: New
          Severity: Affects Some People
          Priority: ---
         Component: usb
          Assignee: usb@FreeBSD.org
          Reporter: guy.wyers@gmail.com

Created attachment 275428
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=3D275428&action=
=3Dedit
Patch file implementing the fix.

The Etron EJ168 USB 3.0 xHCI controller (PCI ID 1b6f:7023) does not
reliably operate SuperSpeed devices with the stock FreeBSD 15.1-RELEASE-p3
xhci driver.

Test system:
- Synology DS412+ R2
- Intel Atom D2701
- Etron EJ168 USB 3.0 controller (1b6f:7023)
- FreeBSD 15.1-RELEASE-p3 amd64
- releng/15.1 source at 88e7371d9dc26f85dfc1b008cbe59ebc7e4a33da

The EJ168 controller and its root hub initialize at SuperSpeed, but USB 3.0
devices fail during enumeration. Typical errors include:

    usbd_setup_device_desc: getting device descriptor at addr 1 failed,
    USB_ERR_IOERROR

and:

    usbd_req_re_enumerate: addr=3D1, set address failed!
    (USB_ERR_IOERROR, ignored)

Devices may subsequently fall back to their USB 2.0 interface and enumerate
at HIGH (480Mbps).

I instrumented the xHCI driver to trace control transfers, TRBs, Link TRBs,
completion events and TD activation.

The investigation identified IOC on Link TRBs as the trigger on this
controller.

First, removing XHCI_TRB_3_IOC_BIT from the Link TRB constructed by
xhci_setup_generic_chain_sub() substantially improved operation: an 18-byte
Device Descriptor request that previously stalled at the Setup -> Link ->
Data boundary completed successfully at SuperSpeed. However, some USB
requests still stalled.

A second Link TRB is constructed by xhci_transfer_insert() when the TD chain
is linked back into the endpoint scheduling ring. Removing IOC from this
Link TRB as well eliminated the remaining observed stalls.

The attached patch implements this as an EJ168-specific quirk,
XHCI_QUIRK_NO_LINK_IOC. The quirk is enabled only for PCI ID 1b6f:7023.
Existing Link-TRB IOC behaviour is preserved for all other xHCI controllers.

The existing sc_ctlstep workaround was also tested but was not required and
is not included in the patch.

The fix was tested with two independent USB 3.0 devices:

1. Realtek RTL8156 2.5GbE adapter
   - enumerates at SUPER (5.0Gbps)
   - cfg=3D0
   - ue0 attaches successfully

2. Samsung Portable SSD T5
   - enumerates at SUPER (5.0Gbps)
   - sustained approximately 165 MB/s during a non-destructive 4 GiB raw
     read, confirming actual SuperSpeed bulk transfer

Both devices were also successfully configured simultaneously on the EJ168.

This is an empirically verified workaround. I have not established the exact
underlying EJ168 silicon error(s).

--=20
You are receiving this mail because:
You are the assignee for the bug.=

