From: bugzilla-daemon@kernel.org
To: linux-usb@vger.kernel.org
Subject: [Bug 222091] New: Regression 7.1.10→7.2.x: poweroff hangs after Lenovo USB4 dock (40BF) connected during session; state persists after unplug
Date: Sat, 03 Oct 2026 16:33:53 +0000 [thread overview]
Message-ID: <bug-222091-208809@https.bugzilla.kernel.org/> (raw)
https://bugzilla.kernel.org/show_bug.cgi?id=222091
Bug ID: 222091
Summary: Regression 7.1.10→7.2.x: poweroff hangs after Lenovo
USB4 dock (40BF) connected during session; state
persists after unplug
Product: Drivers
Version: 2.5
Hardware: Intel
OS: Linux
Status: NEW
Severity: normal
Priority: P3
Component: USB
Assignee: drivers_usb@kernel-bugs.kernel.org
Reporter: abadragan@gmail.com
Regression: No
[Filed under Drivers/USB because there is no Thunderbolt component; this is a
drivers/thunderbolt (NHI) regression. Downstream report: see Red Hat Bugzilla,
Fedora component "kernel" -- URL to be added in a follow-up comment.]
REGRESSION: System fails to power off once a Lenovo ThinkPad USB4 Dock 5000
(40BF) has been connected during the session. Userspace shutdown completes
cleanly (journal shows poweroff.target reached, filesystems synced, journald
stopped), then the machine hangs at the firmware splash screen and requires a
hard power-off. The state is LATCHED: unplugging the dock afterwards does not
help; only sessions where the dock was never connected power off normally.
BISECTION (all verified on this machine):
6.19.10-300.fc44 GOOD (install-era kernel)
6.19.12-300.fc44 GOOD
7.1.10-200.fc44 GOOD (also verified on a parallel Bluefin install with
identical kernel config and cmdline)
7.2.5-200.fc44 BAD (first 7.x kernel this machine booted; install
jumped 6.19.10 -> 7.2.5)
7.2.7-200.fc44 BAD
7.2.8-200.fc44 BAD
ADDITIONAL FINDING: "modprobe -r thunderbolt" while docked deadlocks
permanently (process in D state). The dock router (thunderbolt 0-3) and
retimer (0-0:3.1) disconnect, then the NHI teardown blocks:
[<0>] nhi_pci_remove+0x53/0x60 [thunderbolt]
[<0>] pci_device_remove+0x4a/0xb0
[<0>] device_release_driver_internal+0x19e/0x200
[<0>] driver_detach+0x48/0x90
[<0>] bus_remove_driver+0x78/0x110
[<0>] pci_unregister_driver+0x36/0xe0
[<0>] nhi_unload+0x10/0x540 [thunderbolt]
However, blacklisting the thunderbolt module entirely does NOT fix the
poweroff hang, and neither does blacklisting ucsi_acpi -- suggesting the
latched state is below these drivers (ACPI power resources / EC interaction).
The BIOS exposes \_SB_.PC00.TBT0/TBT1 power resources and hands USB4 _OSC
control to the OS at boot; ACPI tables also show pre-existing
AE_ALREADY_EXISTS errors (\_SB.BGNV, \_SB.PC00.PTMA, ...).
HARDWARE:
Laptop: PC Specialist FusionVI 14 (Clevo/Kapok 1558:2680), Insyde BIOS
1.07.03dTPCS (2024-10-24), Intel Core Ultra 200V (Lunar Lake)
TB4 controller: Intel [8086:a833], driver thunderbolt
Dock: Lenovo ThinkPad USB4 Dock 5000 (40BF), "Lenovo Dock - USB4 Router"
(17ef:118d), Intel retimer (8086:0d9c), dock DMC fw 1.2.04 (latest)
REPRODUCER: boot 7.2.x on this hardware, attach dock at any point, then
poweroff (or "modprobe -r thunderbolt" for the unload deadlock).
WORKAROUND: pin kernel to 7.1.10-200.fc44.
--
You may reply to this email to add a comment.
You are receiving this mail because:
You are watching the assignee of the bug.
next reply other threads:[~2026-10-03 16:33 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 16:33 bugzilla-daemon [this message]
2026-10-05 11:28 ` [Bug 222091] Regression 7.1.10→7.2.x: poweroff hangs after Lenovo USB4 dock (40BF) connected during session; state persists after unplug bugzilla-daemon
2026-10-06 18:47 ` bugzilla-daemon
2026-10-07 7:47 ` bugzilla-daemon
2026-10-08 17:23 ` bugzilla-daemon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bug-222091-208809@https.bugzilla.kernel.org/ \
--to=bugzilla-daemon@kernel.org \
--cc=linux-usb@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox