Skip to content

fix[usb]: stop aliasing rt_ringbuffer as rt_serial_rx_fifo in VCOM - #11770

Open
Finder16 wants to merge 1 commit into
RT-Thread:masterfrom
Finder16:fix/vcom-serial-v2-rx-fifo
Open

fix[usb]: stop aliasing rt_ringbuffer as rt_serial_rx_fifo in VCOM#11770
Finder16 wants to merge 1 commit into
RT-Thread:masterfrom
Finder16:fix/vcom-serial-v2-rx-fifo

Conversation

@Finder16

@Finder16 Finder16 commented Aug 29, 2026

Copy link
Copy Markdown

拉取/合并请求描述:(PR description)

为什么提交这份PR (why to submit this PR)

Fixes #11739

With RT_USB_DEVICE_CDC and RT_USING_SERIAL_V2 both enabled, _function_enable() assigned the embedded rx_ringbuffer to serial.serial_rx:

data->serial.serial_rx = &data->rx_ringbuffer;

Serial V2 reads that pointer as a struct rt_serial_rx_fifo *. Because rt_ringbuffer is the first member of rt_serial_rx_fifo, ring-buffer access happened to work, while rx_cpt, rx_cpt_index and rx_timeout landed on the members that follow rx_ringbuffer inside struct vcom, corrupting tx_rbp. The layout shifts again when RT_SERIAL_USING_DMA is enabled, which inserts dma_ping_rb ahead of those fields.

Serial V2 already owns the receive FIFO: dev_serial_v2.c allocates it with rt_malloc() on open and releases it with rt_free() on close. The assignment therefore also overwrote the FIFO allocated at open time, and made the close path call rt_free() on memory inside struct vcom that was never dynamically allocated. The problem becomes reachable once the USB host configures the CDC device.

你的解决方案是什么 (what is your solution)

  • Remove the data->serial.serial_rx = &data->rx_ringbuffer; assignment from _function_enable(), so the RX FIFO that Serial V2 allocated on open stays intact.
  • In _ep_out_handler(), under RT_USING_SERIAL_V2, cast serial.serial_rx to struct rt_serial_rx_fifo * and push the received data into rx_fifo->rb, guarded against RT_NULL for the case where the serial device has not been opened yet. This matches rt_hw_serial_isr(), which reports RX_IND from serial_rx->rb.
  • In _vcom_getc(), drain the same FIFO under RT_USING_SERIAL_V2.
  • The Serial V1 path is left unchanged in the #else branches, so data->rx_ringbuffer is still used when RT_USING_SERIAL_V2 is not defined.

No API or Kconfig change is involved. The diff is limited to components/legacy/usb/usbdevice/class/cdc_vcom.c (+23 / -4).

请提供验证的bsp和config (provide the config and bsp)

  • BSP: Not board-specific. The change is in the common component
    components/legacy/usb/usbdevice/class/cdc_vcom.c, which is shared by every BSP that
    provides a USB device controller. It was not verified on physical hardware. Verification
    was done by code review, struct-layout analysis of struct vcom versus
    struct rt_serial_rx_fifo, and build checks. Testing on a board with a USB device
    controller and RT_USB_DEVICE_CDC + RT_USING_SERIAL_V2 enabled is very welcome.

  • .config: RT_USING_SERIAL_V2, RT_USB_DEVICE, RT_USB_DEVICE_CDC

  • action: https://github.com/Finder16/rt-thread/actions/runs/33252216932
    (qemu-vexpress-a9, sourcery-arm, branch fix/vcom-serial-v2-rx-fifo, result: success)

    Note: no BSP in the tree enables RT_USB_DEVICE_CDC together with RT_USING_SERIAL_V2 in
    its default .config, so cdc_vcom.c is not compiled by the BSP build CI. The linked run
    only confirms that the tree still builds with this change applied. Review of the USB CDC
    path itself, and testing on hardware with a USB device controller, would be appreciated.

贡献者 (Contributors)

This issue was analyzed and reported together with:

当前拉取/合并请求的状态 Intent for your PR

必须选择一项 Choose one (Mandatory):

  • 本拉取/合并请求是一个草稿版本 This PR is for a code-review and is intended to get feedback
  • 本拉取/合并请求是一个成熟版本 This PR is mature, and ready to be integrated into the repo

代码质量 Code Quality:

我在这个拉取/合并请求中已经考虑了 As part of this pull request, I've considered the following:

  • 已经仔细查看过代码改动的对比 Already check the difference between PR and old code
  • 代码风格正确,包括缩进空格,命名及其他风格 Style guide is adhered to, including spacing, naming and other styles
  • 没有垃圾代码,代码尽量精简,不包含#if 0代码,不包含已经被注释了的代码 All redundant code is removed and cleaned up
  • 所有变更均有原因及合理的,并且不会影响到其他软件组件代码或BSP All modifications are justified and not affect other components or BSP
  • 对难懂代码均提供对应的注释 I've commented appropriately where code is tricky
  • 代码是高质量的 Code in this PR is of high quality
  • 已经使用clang-format 源码格式化工具确保格式符合RT-Thread代码规范 This PR has been formatted with clang-format and complies with RT-Thread code specification
  • 如果是新增bsp, 已经添加ci检查到.github/ALL_BSP_COMPILE.json 详细请参考链接BSP自查

With RT_USB_DEVICE_CDC and RT_USING_SERIAL_V2 both enabled, _function_enable
assigned the embedded rx_ringbuffer to serial.serial_rx. Serial V2 reads that
pointer as a struct rt_serial_rx_fifo, whose first member is a rt_ringbuffer,
so ring-buffer access happened to work while rx_cpt, rx_cpt_index and
rx_timeout landed on the following members of struct vcom, corrupting tx_rbp.
The layout shifts again with RT_SERIAL_USING_DMA, which inserts dma_ping_rb
ahead of those fields.

Serial V2 already owns the receive FIFO: dev_serial_v2.c allocates it with
rt_malloc on open and releases it with rt_free on close, so the assignment
also made rt_free run on memory inside struct vcom.

Drop the assignment and read the FIFO Serial V2 owns. rt_hw_serial_isr
reports RX_IND from serial_rx->rb, so the endpoint handler now fills that
ring buffer and _vcom_getc drains it. The Serial V1 path is unchanged.

Fixes RT-Thread#11739

Signed-off-by: Jaeyeong Lee <lee@jaeyeong.cc>
@CLAassistant

CLAassistant commented Aug 29, 2026

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@github-actions

Copy link
Copy Markdown

👋 感谢您对 RT-Thread 的贡献!Thank you for your contribution to RT-Thread!

为确保代码符合 RT-Thread 的编码规范,请在你的仓库中执行以下步骤运行代码格式化工作流(如果格式化CI运行失败)。
To ensure your code complies with RT-Thread's coding style, please run the code formatting workflow by following the steps below (If the formatting of CI fails to run).


🛠 操作步骤 | Steps

  1. 前往 Actions 页面 | Go to the Actions page
    点击进入工作流 → | Click to open workflow →

  2. 点击 Run workflow | Click Run workflow

  • Use workflow from 保持默认分支(通常为 master
    Keep the default branch (usually master) in Use workflow from
  • branch 输入框填写 PR 分支 fix/vcom-serial-v2-rx-fifo
    Enter PR branch fix/vcom-serial-v2-rx-fifo in the branch field
  • 设置需排除的文件/目录(目录请以"/"结尾)
    Set files/directories to exclude (directories should end with "/")
  1. 等待工作流完成 | Wait for the workflow to complete
    格式化后的代码将作为独立提交推送至你的分支。
    The formatting changes will be pushed to your branch as a separate commit.

完成后,提交将自动更新至 fix/vcom-serial-v2-rx-fifo 分支,关联的 Pull Request 也会同步更新。
Once completed, commits will be pushed to the fix/vcom-serial-v2-rx-fifo branch automatically, and the related Pull Request will be updated.

如有问题欢迎联系我们,再次感谢您的贡献!💐
If you have any questions, feel free to reach out. Thanks again for your contribution!

@github-actions

Copy link
Copy Markdown

📌 Code Review Assignment

🏷️ Tag: components

Reviewers: @Maihuanyi

Changed Files (Click to expand)
  • components/legacy/usb/usbdevice/class/cdc_vcom.c

📊 Current Review Status (Last Updated: 2026-08-29 20:29 CST)


📝 Review Instructions

  1. 维护者可以通过单击此处来刷新审查状态: 🔄 刷新状态
    Maintainers can refresh the review status by clicking here: 🔄 Refresh Status

  2. 确认审核通过后评论 LGTM/lgtm
    Comment LGTM/lgtm after confirming approval

  3. PR合并前需至少一位维护者确认
    PR must be confirmed by at least one maintainer before merging

ℹ️ 刷新CI状态操作需要具备仓库写入权限。
ℹ️ Refresh CI status operation requires repository Write permission.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] Legacy USB CDC VCOM uses rt_ringbuffer as rt_serial_rx_fifo with Serial V2

2 participants