Re: [PATCH] usb: typec: thunderbolt: Disable work before freeing tbt on remove

Heikki Krogerus <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.linux-kernel,org.kernel.vger.linux-usb
Message-ID <[email protected]>
On Sun, Aug 02, 2026 at 01:49:59AM +0000, Fan Wu wrote:
> tbt_altmode_remove() drops the plug and cable references without
> draining tbt->work. The work function dereferences those references,
> and can also requeue itself in its error path. The VDM callbacks can
> queue the same work item.
> 
> Disable and drain tbt->work before dropping the references. This waits
> for an existing invocation and prevents subsequent schedule_work()
> calls from queueing it during teardown.
> 
> This issue was found by an in-house static analysis tool and confirmed
> by manual code review.
> 
> Fixes: 100e25738659 ("usb: typec: Add driver for Thunderbolt 3 Alternate Mode")
> Cc: [email protected]
> Assisted-by: Codex:gpt-5.6
> Signed-off-by: Fan Wu <[email protected]>

Acked-by: Heikki Krogerus <[email protected]>

> ---
>  drivers/usb/typec/altmodes/thunderbolt.c | 2 ++
>  1 file changed, 2 insertions(+)
> 
> diff --git a/drivers/usb/typec/altmodes/thunderbolt.c b/drivers/usb/typec/altmodes/thunderbolt.c
> index 32250b942..601d39ee1 100644
> --- a/drivers/usb/typec/altmodes/thunderbolt.c
> +++ b/drivers/usb/typec/altmodes/thunderbolt.c
> @@ -303,6 +303,8 @@ static void tbt_altmode_remove(struct typec_altmode *alt)
>  {
>  	struct tbt_altmode *tbt = typec_altmode_get_drvdata(alt);
>  
> +	disable_work_sync(&tbt->work);
> +
>  	for (int i = TYPEC_PLUG_SOP_PP; i >= 0; --i) {
>  		if (tbt->plug[i])
>  			typec_altmode_put_plug(tbt->plug[i]);
> -- 
> 2.34.1

-- 
heikki
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.