Seeking help debugging a crash in hid-magicmouse
From: Andrew Rodland <hidden>
Date: 2025-09-05 18:17:22
Subsystem:
hid core layer, the rest · Maintainers:
Jiri Kosina, Benjamin Tissoires, Linus Torvalds
Hi, I use an Apple Magic Trackpad 2 (2024 USB-C model) on my Linux desktop. After upgrading from Linux 6.16.3 to 6.16.4 (6.16.4-arch1-1: https://github.com/archlinux/linux/releases/tag/v6.16.4-arch1 -- I don't think there's anything terrible in the patchset), I was suffering from periodic crashes. I rebuilt the kernel with debug symbols and enabled kdump and captured this dmesg: [32607.193629] [ C7] BUG: kernel NULL pointer dereference, address: 000000000000001c [32607.193636] [ C7] #PF: supervisor read access in kernel mode [32607.193637] [ C7] #PF: error_code(0x0000) - not-present page [32607.193638] [ C7] PGD 910ad3067 P4D 910ad3067 PUD 9a49a3067 PMD 6e1bc2067 PTE 0 [32607.193641] [ C7] Oops: Oops: 0000 [#1] SMP NOPTI [32607.193644] [ C7] CPU: 7 UID: 0 PID: 0 Comm: swapper/7 Kdump: loaded Tainted: P S OE 6.16.4-arch1-1-kdump #2 PREEMPT(lazy) a4265b7ab8b2a583c4532d85e7773a521cc6f594 [32607.193647] [ C7] Tainted: [P]=PROPRIETARY_MODULE, [S]=CPU_OUT_OF_SPEC, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE [32607.193648] [ C7] Hardware name: Micro-Star International Co., Ltd. MS-7E59/MAG X870E TOMAHAWK WIFI (MS-7E59), BIOS 2.A84 08/05/2025 [32607.193649] [ C7] RIP: 0010:magicmouse_event+0x13/0x40 [hid_magicmouse] [32607.193654] [ C7] Code: 0f 1f 80 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 48 8b 87 50 19 00 00 48 8b 00 <0f> b7 40 1c 66 3d 69 02 74 0f 31 d2 66 3d 23 03 74 07 89 d0 c3 cc [32607.193655] [ C7] RSP: 0018:ffffd26900454d50 EFLAGS: 00010246 [32607.193656] [ C7] RAX: 0000000000000000 RBX: 0000000000000001 RCX: 0000000000000001 [32607.193656] [ C7] RDX: ffff8ad502029e88 RSI: ffff8ad502029e00 RDI: ffff8ad50cb9a000 [32607.193657] [ C7] RBP: 0000000000000001 R08: ffffffffc0431950 R09: 0000000000000002 [32607.193657] [ C7] R10: ffff8ad50a101000 R11: 0000000000000064 R12: ffff8ad50cb9a000 [32607.193658] [ C7] R13: ffff8ad502029e88 R14: ffffffffc03fd080 R15: ffff8ad502029e00 [32607.193659] [ C7] FS: 0000000000000000(0000) GS:ffff8aebe30ea000(0000) knlGS:0000000000000000 [32607.193659] [ C7] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [32607.193660] [ C7] CR2: 000000000000001c CR3: 000000074f246000 CR4: 0000000000f50ef0 [32607.193661] [ C7] DR0: 0000000141952b70 DR1: 0000000000000000 DR2: 0000000000000000 [32607.193661] [ C7] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000600 [32607.193662] [ C7] PKRU: 55555554 [32607.193662] [ C7] Call Trace: [32607.193664] [ C7] <IRQ> [32607.193665] [ C7] hid_process_event+0xb4/0x130 [32607.193671] [ C7] hid_report_raw_event+0x323/0x4c0 [32607.193674] [ C7] __hid_input_report+0x14d/0x200 [32607.193676] [ C7] hid_input_report+0x15/0x20 [32607.193677] [ C7] hid_irq_in+0x1a1/0x1d0 [32607.193679] [ C7] __usb_hcd_giveback_urb+0x9d/0x120 [32607.193682] [ C7] usb_giveback_urb_bh+0xc3/0x150 [32607.193684] [ C7] process_one_work+0x190/0x350 [32607.193686] [ C7] bh_worker+0x1ac/0x210 [32607.193688] [ C7] ? sched_clock_cpu+0xf/0x200 [32607.193691] [ C7] tasklet_hi_action+0x13/0x30 [32607.193693] [ C7] handle_softirqs+0xe3/0x2a0 [32607.193694] [ C7] __irq_exit_rcu+0xcb/0xf0 [32607.193696] [ C7] common_interrupt+0x85/0xa0 [32607.193699] [ C7] </IRQ> [32607.193699] [ C7] <TASK> [32607.193699] [ C7] asm_common_interrupt+0x26/0x40 [32607.193701] [ C7] RIP: 0010:cpuidle_enter_state+0xbb/0x410 [32607.193703] [ C7] Code: 00 00 e8 d8 86 0b ff e8 e3 f2 ff ff 48 89 c5 0f 1f 44 00 00 31 ff e8 c4 ff 09 ff 45 84 ff 0f 85 33 02 00 00 fb 0f 1f 44 00 00 <45> 85 f6 0f 88 7c 01 00 00 49 63 ce 48 2b 2c 24 48 6b d1 68 48 89 [32607.193704] [ C7] RSP: 0018:ffffd2690025fe78 EFLAGS: 00000246 [32607.193704] [ C7] RAX: ffff8aebe30ea000 RBX: 0000000000000002 RCX: 0000000000000000 [32607.193705] [ C7] RDX: 00001da7f4314dff RSI: fffffff7ee2390e5 RDI: 0000000000000000 [32607.193705] [ C7] RBP: 00001da7f4314dff R08: 0000000000000002 R09: 000000000000adcb [32607.193705] [ C7] R10: 00000000000002dd R11: ffffffffffffffff R12: ffff8ad501313400 [32607.193706] [ C7] R13: ffffffff9bffc440 R14: 0000000000000002 R15: 0000000000000000 [32607.193708] [ C7] ? cpuidle_enter_state+0xac/0x410 [32607.193709] [ C7] cpuidle_enter+0x31/0x50 [32607.193711] [ C7] do_idle+0x1b1/0x210 [32607.193714] [ C7] cpu_startup_entry+0x29/0x30 [32607.193715] [ C7] start_secondary+0x119/0x140 [32607.193718] [ C7] common_startup_64+0x13e/0x141 [32607.193720] [ C7] </TASK> [32607.193721] [ C7] Modules linked in: xpad hid_playstation ff_memless led_class_multicolor uinput xt_MASQUERADE xt_tcpudp xt_mark snd_seq_dummy rfcomm snd_hrtimer snd_seq tun nf_tables ip6table_nat ip6table_filter ip6_tables iptable_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 iptable_filter uhid cmac algif_hash algif_skcipher af_alg bnep nct6683 amd_atl intel_rapl_msr intel_rapl_common btusb snd_usb_audio btrtl btintel snd_usbmidi_lib kvm_amd snd_ump btbcm snd_rawmidi btmtk apple_mfi_fastcharge kvm snd_seq_device bluetooth mousedev joydev mc irqbypass polyval_clmulni ghash_clmulni_intel rfkill snd_hda_codec_hdmi sha512_ssse3 snd_hda_intel sha1_ssse3 aesni_intel snd_intel_dspcfg spd5118 snd_intel_sdw_acpi wmi_bmof rapl pcspkr sp5100_tco snd_hda_codec zfs(POE) thunderbolt snd_hda_core i2c_piix4 k10temp ccp snd_hwdep r8169 i2c_smbus snd_pcm realtek mdio_devres snd_timer libphy snd soundcore spl(OE) mdio_bus gpio_amdpt gpio_generic mac_hid sg i2c_dev crypto_user dm_mod loop nfnetlink ip_tables x_tables amdgpu amdxcp [32607.193749] [ C7] i2c_algo_bit drm_ttm_helper ttm drm_exec gpu_sched drm_suballoc_helper drm_panel_backlight_quirks nvme uas drm_buddy nvme_core usb_storage hid_magicmouse drm_display_helper nvme_keyring cec nvme_auth video wmi [32607.193755] [ C7] CR2: 000000000000001c Unfortunately the core file itself was too large and was truncated, and can't be loaded. If I rebuild with the following patch applied:
diff --git a/drivers/hid/hid-magicmouse.c b/drivers/hid/hid-magicmouse.c
index 226682762db3..7be2daffc6fb 100644
--- a/drivers/hid/hid-magicmouse.c
+++ b/drivers/hid/hid-magicmouse.c@@ -522,6 +522,11 @@ static int magicmouse_event(struct hid_device *hdev, struct hid_field *field,
struct hid_usage *usage, __s32 value)
{
struct magicmouse_sc *msc = hid_get_drvdata(hdev);
+ if (!msc || !msc->input) {
+ hid_warn(hdev, "this would have crashed\n");
+ return 0;
+ }
+
if ((msc->input->id.product == USB_DEVICE_ID_APPLE_MAGICMOUSE2 ||
msc->input->id.product ==
USB_DEVICE_ID_APPLE_MAGICMOUSE2_USBC) &&
field->report->id == MOUSE2_REPORT_ID) {
then I receive
[45398.145218] magicmouse 0003:05AC:0324.0003: this would have crashed
and the system does, in fact, not crash.
I have no idea what the cause is; in this instance the message appeared
for the first time about 12 hours after system boot (but sometimes it's
much faster), it printed several times a second for 42 minutes (I guess
I should have used hid_warn_ratelimited), and then stopped again. The
trackpad remained usable throughout.
Please let me know if there's anything I can do to help debug further. I
know my way around the kernel tolerably well, but I don't have any
particular knowledge of the HID subsystem.
Thanks,
Andrew