Re: [PATCH] thunderbolt: Fix domain reference leak on DPRX work cancel
From: Mika Westerberg
Date: Wed Sep 30 2026 - 23:48:59 EST
Hi,
On Wed, Sep 30, 2026 at 10:16:35PM -0400, David Medina via B4 Relay wrote:
> From: David Medina <b2amedina@xxxxxxxxx>
>
> tb_dp_dprx_start() takes an additional reference to the domain with
> tb_domain_get() and passes it as callback_data to tb_tunnel_alloc_dp().
> That reference is only released by the callback, tb_dp_tunnel_active(),
> which tb_dp_dprx_work() invokes once the DPRX capabilities read completes
> or times out.
>
> If the tunnel is deactivated before the DPRX work runs to completion,
> tb_dp_dprx_stop() cancels the still pending work. The callback is then
> never called and the domain reference held in callback_data leaks. The
> domain's reference count never reaches zero, so tb_domain_release() never
> runs and a subsequent shutdown/reboot hangs waiting for the domain to be
> released.
>
> Release the callback_data domain reference in tb_dp_dprx_stop() when the
> DPRX work is canceled, mirroring the release done by the callback.
>
> Fixes: d6d458d42e1e ("thunderbolt: Handle DisplayPort tunnel activation asynchronously")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: David Medina <b2amedina@xxxxxxxxx>
This should be fixed already by the patches in my fixes branch, can you
try?
https://git.kernel.org/pub/scm/linux/kernel/git/westeri/thunderbolt.git/log/?h=fixes