Re: [PATCH] thunderbolt: Fix domain reference leak on DPRX work cancel
From: David Medina
Date: Thu Oct 01 2026 - 19:58:35 EST
Hi Mika,
Had issues with your mail servers kicking back my message - so
resending just in case.
------
Thanks — I tested your fixes branch and can confirm it already
resolves the shutdown/reboot hang.
Please disregard my patch.
Thanks,
David
On Wed, Sep 30, 2026 at 11:48 PM Mika Westerberg
<mika.westerberg@xxxxxxxxxxxxxxx> wrote:
>
> Hi,
>
> On Wed, Sep 30, 2026 at 10:16:35PM -0400, David Medina via B4 Relay wrote:
> > From: David Medina <b2amedina@xxxxxxxxx>
> >
> > tb_dp_dprx_start() takes an additional reference to the domain with
> > tb_domain_get() and passes it as callback_data to tb_tunnel_alloc_dp().
> > That reference is only released by the callback, tb_dp_tunnel_active(),
> > which tb_dp_dprx_work() invokes once the DPRX capabilities read completes
> > or times out.
> >
> > If the tunnel is deactivated before the DPRX work runs to completion,
> > tb_dp_dprx_stop() cancels the still pending work. The callback is then
> > never called and the domain reference held in callback_data leaks. The
> > domain's reference count never reaches zero, so tb_domain_release() never
> > runs and a subsequent shutdown/reboot hangs waiting for the domain to be
> > released.
> >
> > Release the callback_data domain reference in tb_dp_dprx_stop() when the
> > DPRX work is canceled, mirroring the release done by the callback.
> >
> > Fixes: d6d458d42e1e ("thunderbolt: Handle DisplayPort tunnel activation asynchronously")
> > Cc: stable@xxxxxxxxxxxxxxx
> > Signed-off-by: David Medina <b2amedina@xxxxxxxxx>
>
> This should be fixed already by the patches in my fixes branch, can you
> try?
>
> https://git.kernel.org/pub/scm/linux/kernel/git/westeri/thunderbolt.git/log/?h=fixes
--
David Medina
14901 SW 87th Ave
Palmetto Bay, FL 33176
786-280-0880