]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
thunderbolt: Initialize ->domain_released completion before it is being used
authorMika Westerberg <mika.westerberg@linux.intel.com>
Tue, 28 Jul 2026 06:15:39 +0000 (09:15 +0300)
committerMika Westerberg <mika.westerberg@linux.intel.com>
Thu, 30 Jul 2026 04:47:32 +0000 (06:47 +0200)
Both Woody and Marek reported following crash:

 BUG: unable to handle page fault for address: fffffffffffffff8
 Call Trace:
  <TASK>
  device_release+0x43/0x90
  kobject_cleanup+0x3c/0x180
  icm_probe+0x19c/0x550 [thunderbolt]
  nhi_probe+0x1a4/0x370 [thunderbolt]
  local_pci_probe+0x41/0x90
  pci_call_probe+0x5b/0x1a0
  ...

This only triggers on the error path when icm_probe() fails and the
domain structure is released, it tries to complete() uninitialized
completion.

Fix this by initializing the completion earlier.

Reported-by: Marek Marczykowski-Górecki <marmarek@invisiblethingslab.com>
Closes: https://lore.kernel.org/linux-usb/amdezCBiW4fd_DuB@mail-itl/
Reported-by: Woody Suwalski <terraluna977@gmail.com>
Tested_by: Woody Suwalski <terraluna977@gmail.com>
Closes: https://lore.kernel.org/linux-usb/62caf7f8-b403-d0dd-15bc-b31b56f71c28@gmail.com/
Fixes: f5cc545f5969 ("thunderbolt: Wait for tb_domain_release() to complete when driver is removed")
Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
drivers/thunderbolt/nhi.c

index 0f795ea58756d6d3c73bb22f2d427e218e6e1ac8..35e3c119d5ee8474ca46dc6b42cabe739f8c2859 100644 (file)
@@ -1226,6 +1226,8 @@ int nhi_probe(struct tb_nhi *nhi)
                        return dev_err_probe(dev, res, "NHI specific init failed\n");
        }
 
+       init_completion(&nhi->domain_released);
+
        tb = nhi_select_cm(nhi);
        if (!tb)
                return dev_err_probe(dev, -ENODEV,
@@ -1233,8 +1235,6 @@ int nhi_probe(struct tb_nhi *nhi)
 
        dev_dbg(dev, "NHI initialized, starting thunderbolt\n");
 
-       init_completion(&nhi->domain_released);
-
        res = tb_domain_add(tb, host_reset);
        if (res) {
                /*