Page MenuHomeFreeBSD

libusb: dequeue next transfer on completion to prevent stalls
ClosedPublic

Authored by bapt on Feb 15 2026, 6:20 PM.
Tags
None
Referenced Files
F167809960: D55289.id.diff
Mon, Aug 24, 5:29 PM
Unknown Object (File)
Sun, Aug 9, 4:20 AM
Unknown Object (File)
Sat, Aug 8, 7:53 PM
Unknown Object (File)
Sat, Aug 8, 5:22 PM
Unknown Object (File)
Thu, Aug 6, 2:31 PM
Unknown Object (File)
Thu, Aug 6, 9:25 AM
Unknown Object (File)
Thu, Aug 6, 9:25 AM
Unknown Object (File)
Thu, Aug 6, 7:15 AM
Subscribers

Details

Summary

The transfer proxy callbacks (bulk/interrupt, control, isochronous)
only called libusb10_submit_transfer_sub() in the START path to
pipeline the second kernel transfer slot. On completion or error,
no attempt was made to dequeue the next pending transfer from
tr_head onto the now-free slot.

When more than two async transfers were submitted on the same
endpoint, the third (and subsequent) transfers would remain stuck
on tr_head indefinitely, since no completion ever triggered their
submission. This caused a protocol-level deadlock in applications
like adb that submit header + payload + zero-length terminator as
three separate bulk transfers in sequence.

Fix by calling libusb10_submit_transfer_sub() after every
libusb10_complete_transfer() in all three proxy callbacks.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable