IMX95 Kernel crash after connecting USB3.0 device Hi there, I am bringing up the USB 3.0 interface on our custom design based on the i.MX95 15x15 SoC. In our design, a USB hub is connected to the native USB 3.0 port. The hub enumerates successfully, but when I connect any USB 3.0 device (for example, a USB pendrive) to the hub, I get a kernel crash (logs below). This is odd, because USB 2.0 devices on the same port work without any issues. When I limit the port to high-speed only by setting maximum-speed = "high-speed"; in the device tree, the same USB 3.0 pendrive enumerates as a USB 2.0 device and works well. I also tried adding iommu.passthrough=1 to the kernel command line to rule out an SMMU issue, but the behavior did not change. Could you please help us identify the root cause? We are on Linux Kernel Version 6.18 NXP BSP. Here are the crash logs: root@imx95-15x15-lpddr4x-evk:~# lsusb Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub Bus 001 Device 002: ID 05e3:0610 Genesys Logic, Inc. Hub Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub Bus 002 Device 002: ID 05e3:0620 Genesys Logic, Inc. GL3523 Hub Bus 003 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub root@imx95-15x15-lpddr4x-evk:~# [ 527.354709] usb 2-1.1: new SuperSpeed USB device number 3 using xhci-hcd [ 527.379284] usb-storage 2-1.1:1.0: USB Mass Storage device detected [ 527.387024] scsi host0: usb-storage 2-1.1:1.0 [ 528.405103] scsi 0:0:0:0: Direct-Access USB SanDisk 3.2Gen1 1.00 PQ: 0 ANSI: 6 [ 528.423345] sd 0:0:0:0: [sda] 60125184 512-byte logical blocks: (30.8 GB/28.7 GiB) [ 528.431953] sd 0:0:0:0: [sda] Write Protect is off [ 528.437387] sd 0:0:0:0: [sda] Write cache: disabled, read cache: enabled, doesn't support DPO or FUA [ 528.492698] sda: sda1 [ 528.495895] sd 0:0:0:0: [sda] Attached SCSI removable disk [ 529.708851] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008 [ 529.717662] Mem abort info: [ 529.720448] ESR = 0x0000000096000004 [ 529.724184] EC = 0x25: DABT (current EL), IL = 32 bits [ 529.729478] SET = 0, FnV = 0 [ 529.732521] EA = 0, S1PTW = 0 [ 529.735649] FSC = 0x04: level 0 translation fault [ 529.740511] Data abort info: [ 529.743380] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 529.748848] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 529.753884] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 529.759179] user pgtable: 4k pages, 48-bit VAs, pgdp=00000001049be000 [ 529.765601] [0000000000000008] pgd=0000000000000000, p4d=0000000000000000 [ 529.772381] Internal error: Oops: 0000000096000004 [#1] SMP [ 529.778031] Modules linked in: polyval_ce mxc_jpeg_encdec v4l2_jpeg snd_soc_imx_card snd_soc_fsl_sai snd_soc_fsl_xcvr snd_soc_fsl_micfil imx_pcm_dma overlay snd_soc_fsl_utils pwm_fan fuse [ 529.794728] CPU: 1 UID: 0 PID: 217 Comm: kworker/1:2H Not tainted 6.18.2-g81bb96fa4952-dirty #15 PREEMPT [ 529.804281] Hardware name: NXP i.MX95 15X15 Mecha Comet (DT) [ 529.809929] Workqueue: blk_mq_run_work_fn (kblockd) [ 529.814899] pstate: 604000c9 (nZCv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 529.821847] pc : process_one_work+0xc8/0x284 [ 529.826112] lr : worker_thread+0x2c4/0x3e0 [ 529.830205] sp : ffff800081ff3db0 [ 529.833504] x29: ffff800081ff3dc0 x28: 0000000000000000 x27: 0000000000000000 [ 529.840628] x26: 0000000000000000 x25: ffff00008459e4c0 x24: ffff0000fbb90480 [ 529.847752] x23: ffff000081f1f248 x22: ffff0000fbb90458 x21: 0000000000000000 [ 529.854876] x20: ffff000081f1f240 x19: ffff00008459e480 x18: 0000000000000001 [ 529.862000] x17: 000000040044ffff x16: 005000f2b5503510 x15: 00000027f3567fb3 [ 529.869124] x14: 00000000000000d2 x13: ffff00008495d800 x12: 0000000000000000 [ 529.876248] x11: 00000000000000c0 x10: 0000000000000ab0 x9 : ffff800081ff3d30 [ 529.883372] x8 : ffff00008495e290 x7 : 0000000000000001 x6 : 0000000000000000 [ 529.890496] x5 : 000000050a0a3e6a x4 : ffff000081f1f240 x3 : ffff0000fbb90478 [ 529.897620] x2 : 0000000000000020 x1 : 0000000000000008 x0 : ffff00008459e500 [ 529.904746] Call trace: [ 529.907181] process_one_work+0xc8/0x284 (P) [ 529.911444] worker_thread+0x2c4/0x3e0 [ 529.915188] kthread+0x12c/0x204 [ 529.918412] ret_from_fork+0x10/0x20 [ 529.921987] Code: d2800402 f84086f8 53041f01 b9003261 (f94006a1) [ 529.928068] ---[ end trace 0000000000000000 ]--- [ 529.932679] note: kworker/1:2H[217] exited with irqs disabled [ 529.938512] note: kworker/1:2H[217] exited with preempt_count 1 [ 529.938795] Internal error: Oops - Undefined instruction: 0000000002000000 [#2] SMP [ 529.952155] Modules linked in: polyval_ce mxc_jpeg_encdec v4l2_jpeg snd_soc_imx_card snd_soc_fsl_sai snd_soc_fsl_xcvr snd_soc_fsl_micfil imx_pcm_dma overlay snd_soc_fsl_utils pwm_fan fuse [ 529.968852] CPU: 3 UID: 0 PID: 648 Comm: syslogd Tainted: G D 6.18.2-g81bb96fa4952-dirty #15 PREEMPT [ 529.979530] Tainted: [D]=DIE [ 529.982398] Hardware name: NXP i.MX95 15X15 Mecha Comet (DT) [ 529.988041] pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 529.994990] pc : copy_folio_from_iter_atomic+0x260/0x89c [ 530.000303] lr : copy_folio_from_iter_atomic+0x250/0x89c [ 530.005607] sp : ffff800088073ac0 [ 530.008909] x29: ffff800088073b30 x28: 000000000000000f x27: 0001000000000000 [ 530.016033] x26: ffff00008e3236c0 x25: 0000000000000000 x24: 0000000000000462 [ 530.023157] x23: 0000000000000000 x22: ffff000081ba9180 x21: ffff800088073cd0 [ 530.030281] x20: 000000000000000f x19: 0000000000000085 x18: 0000000000000000 [ 530.037405] x17: 0000000000000000 x16: 0000000000000000 x15: 0000ffffcef03a40 [ 530.044529] x14: 0000000000000000 x13: 0000000000000000 x12: ffff000081ba9180 [ 530.051653] x11: ffff00008e3236c0 x10: 0000fffffffffff1 x9 : ffff000081ba9180 [ 530.058777] x8 : 000000000000000f x7 : ffff000091bff462 x6 : ffff000091bff471 [ 530.065901] x5 : 0000000000000085 x4 : ffff000081ba9180 x3 : ffff000091bff000 [ 530.073025] x2 : 000000000000000f x1 : 000000000000000f x0 : 0000000000000000 [ 530.080153] Call trace: [ 530.082595] copy_folio_from_iter_atomic+0x260/0x89c (P) [ 530.087898] generic_perform_write+0x14c/0x25c [ 530.092335] shmem_file_write_iter+0xa0/0xa8 [ 530.096598] do_iter_readv_writev+0xfc/0x1e0 [ 530.100863] vfs_writev+0x134/0x2c0 [ 530.104346] do_writev+0x7c/0x148 [ 530.107657] __arm64_sys_writev+0x20/0x34 [ 530.111661] invoke_syscall+0x48/0x104 [ 530.115405] el0_svc_common.constprop.0+0x40/0xe0 [ 530.120103] do_el0_svc+0x1c/0x28 [ 530.123413] el0_svc+0x34/0xec [ 530.126464] el0t_64_sync_handler+0xa0/0xf0 [ 530.130641] el0t_64_sync+0x198/0x19c [ 530.134302] Code: cb000281 a9408fe7 8b01039c a941a7e5 (8f010339) [ 530.140385] ---[ end trace 0000000000000000 ]--- Same way when we connect USB 2.0 Device on same port. root@imx95-15x15-lpddr4x-evk:~# lsusb Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub Bus 001 Device 002: ID 05e3:0610 Genesys Logic, Inc. Hub Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub Bus 002 Device 002: ID 05e3:0620 Genesys Logic, Inc. GL3523 Hub Bus 003 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub root@imx95-15x15-lpddr4x-evk:~# [ 106.150901] extcon-tusb320 2-0047: TUSB Device Detected [ 111.942409] usb 1-1.1: new full-speed USB device number 3 using xhci-hcd [ 112.166092] hid-generic 0003:3151:1020.0001: device has no listeners, quitting [ 112.191037] input: YICHIP 2.4G Receiver Mouse as /devices/platform/soc/4c010010.usb/4c100000.usb/xhci-hcd.2.auto/usb1/1-1/1-1.1/1-1.1:1.1/0003:3151:1020.0002/input/input1 [ 112.207047] input: YICHIP 2.4G Receiver System Control as /devices/platform/soc/4c010010.usb/4c100000.usb/xhci-hcd.2.auto/usb1/1-1/1-1.1/1-1.1:1.1/0003:3151:1020.0002/input/input2 [ 112.279679] input: YICHIP 2.4G Receiver Consumer Control as /devices/platform/soc/4c010010.usb/4c100000.usb/xhci-hcd.2.auto/usb1/1-1/1-1.1/1-1.1:1.1/0003:3151:1020.0002/input/input3 [ 112.296313] hid-generic 0003:3151:1020.0002: input: USB HID v2.00 Mouse [YICHIP 2.4G Receiver] on usb-xhci-hcd.2.auto-1.1/input1 root@imx95-15x15-lpddr4x-evk:~# lsusb Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub Bus 001 Device 002: ID 05e3:0610 Genesys Logic, Inc. Hub Bus 001 Device 003: ID 3151:1020 YICHIP 2.4G Receiver Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub Bus 002 Device 002: ID 05e3:0620 Genesys Logic, Inc. GL3523 Hub Bus 003 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub Linux Multimedia Suspected Software Defect Re: IMX95 Kernel crash after connecting USB3.0 device Hello,
Could you please share your device tree configuration?
Best regards.
View full article