Linux USB
 help / color / mirror / Atom feed
* [BUG] thunderbolt: NULL pointer dereference in tb_dp_dprx_work after device disconnect (7.2.6)
@ 2026-09-22 14:48 Paweł Frelek
  2026-09-24 16:28 ` Paweł Frelek
  0 siblings, 1 reply; 3+ messages in thread
From: Paweł Frelek @ 2026-09-22 14:48 UTC (permalink / raw)
  To: andreas.noever; +Cc: linux-usb, YehezkelShB

Hi,

I hit a NULL pointer dereference in tb_dp_dprx_work during reboot,
right after the dock was disconnected from the Thunderbolt bus.

Hardware:
- Lenovo ThinkPad X13 Gen 3 AMD (21CNS15T00), BIOS R22ET81W (1.51)
- Lenovo ThinkPad Thunderbolt 4 Dock (40B0), external monitor over DP

Kernel: 7.2.6-hardened1 (Arch linux-hardened), not tainted
Cmdline includes: thunderbolt.dprx_timeout=-1

What happened:
The external DP monitor behind the dock did not come up at boot. I
unplugged and replugged the monitor's DP cable at the dock, without
success, then rebooted (the dock itself stayed connected). During
shutdown the dock was reported as disconnected and ~50 ms later the
pending DPRX work crashed:

[  140.825070] thunderbolt 0-2: device disconnected
[  140.875648] BUG: kernel NULL pointer dereference, address: 000000000000032b
[  140.877281] CPU: 8 UID: 0 PID: 125 Comm: kworker/u48:4 Not tainted
7.2.6-hardened1-1-hardened #1 PREEMPT(full)
[  140.877513] Hardware name: LENOVO 21CNS15T00/21CNS15T00, BIOS
R22ET81W (1.51 ) 04/10/2026
[  140.877748] Workqueue: thunderbolt0 tb_dp_dprx_work [thunderbolt]
[  140.878003] RIP: 0010:tb_dp_dprx_work+0x82/0x160 [thunderbolt]
[  140.880927] Call Trace:
[  140.881164]  <TASK>
[  140.881652]  process_one_work+0x198/0x370
[  140.881896]  worker_thread+0x1a6/0x310
[  140.882380]  kthread+0xf3/0x130
[  140.882863]  ret_from_fork+0x2dc/0x3a0
[  140.883818]  ret_from_fork_asm+0x1a/0x30
[  140.884065]  </TASK>
[  141.399331] Code: 24 20 48 8b 87 58 ff ff ff 48 8d b8 18 03 00 00
49 89 c4 4c 8d b8 18 03 00 00 e8 39 ff db d3 48 8b 8b 60 ff ff ff 48
8b 41 20 <0f> b6 90 2b 03 00 00 c0 ea 05 75 5d 66 81 b8 18 03 00 00 86
80 74
[  141.399974] RAX: 0000000000000000 RBX: ffff88ae1389c4b0 RCX: ffff88b040d53578
[  141.400298] RDX: ffff88b0916f0000 RSI: ffff88ae1389c4b8 RDI: ffff88ae011a6318
[  141.402844] Kernel panic - not syncing: Fatal exception

It looks like the DPRX work is not cancelled when the device behind the
tunnel goes away. With dprx_timeout=-1 the work never expires, which
makes the window large, but I assume the race exists with the default
timeout too.

I set dprx_timeout=-1 because the external monitors sometimes did not
come up at boot (DP tunnel torn down as "not active").

Full pstore dmesg available on request.

Thanks,
Paweł

-- 
Paweł Frelek   ( ͡° ͜ʖ ͡°)
pawel.frelek@gmail.com

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-25  5:29 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-22 14:48 [BUG] thunderbolt: NULL pointer dereference in tb_dp_dprx_work after device disconnect (7.2.6) Paweł Frelek
2026-09-24 16:28 ` Paweł Frelek
2026-09-25  5:29   ` Mika Westerberg

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox