Re: [PATCH 6.12 528/602] thunderbolt: Prevent XDomain delayed work use-after-free on disconnect

Harshit Mogalapalli <[email protected]> Mon, 3 Aug 2026 10:38:20 +0530
Newsgroups dev.linux.lists.patches,org.kernel.vger.stable
Message-ID <[email protected]>
Hi Sasha,

On 02/08/26 8:45 am, Sasha Levin wrote:
> On Sat, Aug 01, 2026 at 08:56:42PM +0530, Harshit Mogalapalli wrote:
>> I have run an AI assisted backport review and it spotted an issue. I
>> have taken a look, and this backport does not contain the fix described
>> by upstream 2c5d2d3c3f70.
> 
> You're right, and thanks for the careful review.
> 
>> The 6.12.y commit still has:
>>
>>      if (xd)
>>              queue_delayed_work(xd->tb->wq,
>>                                 &xd->properties_changed_work, ...);
>>
>> and no removing field or guarded request-handler queue sites. Its diff
>> only relocates the unchanged update_xdomain() function, so work can
>> still be queued after cancellation and run after the xdomain is freed.
> 
> Yup :(
> 
> Dropped from the 7.1, 6.18, 6.12 and 6.6 queues, along with the full
> prerequisite chain that came with it:
> 
>    - thunderbolt: Keep XDomain reference during the lifetime of a service
>    - thunderbolt: Remove service debugfs entries during unregister
>    - thunderbolt: Remove XDomain from the bus without holding tb->lock
>    - thunderbolt: Handle lane bonding of Gen 4 XDomain links properly (6.6)
>    - thunderbolt: Remove usage of the deprecated ida_simple_xx() API (6.6)
>    - thunderbolt: Update property.c function documentation (6.6)
> 
> The actual upstream commit applies cleanly to all four branches, so I'll
> requeue it properly next cycle.

thanks a lot Sasha, as you know, it's very useful to get this fixed 
before they get merged :)

regards,
Harshit