Seeking help debugging a crash in hid-magicmouse

From: Andrew Rodland <hidden>
Date: 2025-09-05 18:17:22
Subsystem: hid core layer, the rest · Maintainers: Jiri Kosina, Benjamin Tissoires, Linus Torvalds

Hi,

I use an Apple Magic Trackpad 2 (2024 USB-C model) on my Linux desktop.

After upgrading from Linux 6.16.3 to 6.16.4 (6.16.4-arch1-1: 
https://github.com/archlinux/linux/releases/tag/v6.16.4-arch1 -- I don't 
think there's anything terrible in the patchset), I was suffering from 
periodic crashes.

I rebuilt the kernel with debug symbols and enabled kdump and captured 
this dmesg:

[32607.193629] [      C7] BUG: kernel NULL pointer dereference, address: 
000000000000001c
[32607.193636] [      C7] #PF: supervisor read access in kernel mode
[32607.193637] [      C7] #PF: error_code(0x0000) - not-present page
[32607.193638] [      C7] PGD 910ad3067 P4D 910ad3067 PUD 9a49a3067 PMD 
6e1bc2067 PTE 0
[32607.193641] [      C7] Oops: Oops: 0000 [#1] SMP NOPTI
[32607.193644] [      C7] CPU: 7 UID: 0 PID: 0 Comm: swapper/7 Kdump: 
loaded Tainted: P S         OE       6.16.4-arch1-1-kdump #2 
PREEMPT(lazy)  a4265b7ab8b2a583c4532d85e7773a521cc6f594
[32607.193647] [      C7] Tainted: [P]=PROPRIETARY_MODULE, 
[S]=CPU_OUT_OF_SPEC, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE
[32607.193648] [      C7] Hardware name: Micro-Star International Co., 
Ltd. MS-7E59/MAG X870E TOMAHAWK WIFI (MS-7E59), BIOS 2.A84 08/05/2025
[32607.193649] [      C7] RIP: 0010:magicmouse_event+0x13/0x40 
[hid_magicmouse]
[32607.193654] [      C7] Code: 0f 1f 80 00 00 00 00 90 90 90 90 90 90 
90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 48 8b 87 50 19 
00 00 48 8b 00 <0f> b7 40 1c 66 3d 69 02 74 0f 31 d2 66 3d 23 03 74 07 
89 d0 c3 cc
[32607.193655] [      C7] RSP: 0018:ffffd26900454d50 EFLAGS: 00010246
[32607.193656] [      C7] RAX: 0000000000000000 RBX: 0000000000000001 
RCX: 0000000000000001
[32607.193656] [      C7] RDX: ffff8ad502029e88 RSI: ffff8ad502029e00 
RDI: ffff8ad50cb9a000
[32607.193657] [      C7] RBP: 0000000000000001 R08: ffffffffc0431950 
R09: 0000000000000002
[32607.193657] [      C7] R10: ffff8ad50a101000 R11: 0000000000000064 
R12: ffff8ad50cb9a000
[32607.193658] [      C7] R13: ffff8ad502029e88 R14: ffffffffc03fd080 
R15: ffff8ad502029e00
[32607.193659] [      C7] FS:  0000000000000000(0000) 
GS:ffff8aebe30ea000(0000) knlGS:0000000000000000
[32607.193659] [      C7] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[32607.193660] [      C7] CR2: 000000000000001c CR3: 000000074f246000 
CR4: 0000000000f50ef0
[32607.193661] [      C7] DR0: 0000000141952b70 DR1: 0000000000000000 
DR2: 0000000000000000
[32607.193661] [      C7] DR3: 0000000000000000 DR6: 00000000ffff0ff0 
DR7: 0000000000000600
[32607.193662] [      C7] PKRU: 55555554
[32607.193662] [      C7] Call Trace:
[32607.193664] [      C7]  <IRQ>
[32607.193665] [      C7]  hid_process_event+0xb4/0x130
[32607.193671] [      C7]  hid_report_raw_event+0x323/0x4c0
[32607.193674] [      C7]  __hid_input_report+0x14d/0x200
[32607.193676] [      C7]  hid_input_report+0x15/0x20
[32607.193677] [      C7]  hid_irq_in+0x1a1/0x1d0
[32607.193679] [      C7]  __usb_hcd_giveback_urb+0x9d/0x120
[32607.193682] [      C7]  usb_giveback_urb_bh+0xc3/0x150
[32607.193684] [      C7]  process_one_work+0x190/0x350
[32607.193686] [      C7]  bh_worker+0x1ac/0x210
[32607.193688] [      C7]  ? sched_clock_cpu+0xf/0x200
[32607.193691] [      C7]  tasklet_hi_action+0x13/0x30
[32607.193693] [      C7]  handle_softirqs+0xe3/0x2a0
[32607.193694] [      C7]  __irq_exit_rcu+0xcb/0xf0
[32607.193696] [      C7]  common_interrupt+0x85/0xa0
[32607.193699] [      C7]  </IRQ>
[32607.193699] [      C7]  <TASK>
[32607.193699] [      C7]  asm_common_interrupt+0x26/0x40
[32607.193701] [      C7] RIP: 0010:cpuidle_enter_state+0xbb/0x410
[32607.193703] [      C7] Code: 00 00 e8 d8 86 0b ff e8 e3 f2 ff ff 48 
89 c5 0f 1f 44 00 00 31 ff e8 c4 ff 09 ff 45 84 ff 0f 85 33 02 00 00 fb 
0f 1f 44 00 00 <45> 85 f6 0f 88 7c 01 00 00 49 63 ce 48 2b 2c 24 48 6b 
d1 68 48 89
[32607.193704] [      C7] RSP: 0018:ffffd2690025fe78 EFLAGS: 00000246
[32607.193704] [      C7] RAX: ffff8aebe30ea000 RBX: 0000000000000002 
RCX: 0000000000000000
[32607.193705] [      C7] RDX: 00001da7f4314dff RSI: fffffff7ee2390e5 
RDI: 0000000000000000
[32607.193705] [      C7] RBP: 00001da7f4314dff R08: 0000000000000002 
R09: 000000000000adcb
[32607.193705] [      C7] R10: 00000000000002dd R11: ffffffffffffffff 
R12: ffff8ad501313400
[32607.193706] [      C7] R13: ffffffff9bffc440 R14: 0000000000000002 
R15: 0000000000000000
[32607.193708] [      C7]  ? cpuidle_enter_state+0xac/0x410
[32607.193709] [      C7]  cpuidle_enter+0x31/0x50
[32607.193711] [      C7]  do_idle+0x1b1/0x210
[32607.193714] [      C7]  cpu_startup_entry+0x29/0x30
[32607.193715] [      C7]  start_secondary+0x119/0x140
[32607.193718] [      C7]  common_startup_64+0x13e/0x141
[32607.193720] [      C7]  </TASK>

[32607.193721] [      C7] Modules linked in: xpad hid_playstation 
ff_memless led_class_multicolor uinput xt_MASQUERADE xt_tcpudp xt_mark 
snd_seq_dummy rfcomm snd_hrtimer snd_seq tun nf_tables ip6table_nat 
ip6table_filter ip6_tables iptable_nat nf_nat nf_conntrack 
nf_defrag_ipv6 nf_defrag_ipv4 iptable_filter uhid cmac algif_hash 
algif_skcipher af_alg bnep nct6683 amd_atl intel_rapl_msr 
intel_rapl_common btusb snd_usb_audio btrtl btintel snd_usbmidi_lib 
kvm_amd snd_ump btbcm snd_rawmidi btmtk apple_mfi_fastcharge kvm 
snd_seq_device bluetooth mousedev joydev mc irqbypass polyval_clmulni 
ghash_clmulni_intel rfkill snd_hda_codec_hdmi sha512_ssse3 snd_hda_intel 
sha1_ssse3 aesni_intel snd_intel_dspcfg spd5118 snd_intel_sdw_acpi 
wmi_bmof rapl pcspkr sp5100_tco snd_hda_codec zfs(POE) thunderbolt 
snd_hda_core i2c_piix4 k10temp ccp snd_hwdep r8169 i2c_smbus snd_pcm 
realtek mdio_devres snd_timer libphy snd soundcore spl(OE) mdio_bus 
gpio_amdpt gpio_generic mac_hid sg i2c_dev crypto_user dm_mod loop 
nfnetlink ip_tables x_tables amdgpu amdxcp
[32607.193749] [      C7]  i2c_algo_bit drm_ttm_helper ttm drm_exec 
gpu_sched drm_suballoc_helper drm_panel_backlight_quirks nvme uas 
drm_buddy nvme_core usb_storage hid_magicmouse drm_display_helper 
nvme_keyring cec nvme_auth video wmi
[32607.193755] [      C7] CR2: 000000000000001c

Unfortunately the core file itself was too large and was truncated, and 
can't be loaded.

If I rebuild with the following patch applied:
diff --git a/drivers/hid/hid-magicmouse.c b/drivers/hid/hid-magicmouse.c
index 226682762db3..7be2daffc6fb 100644
--- a/drivers/hid/hid-magicmouse.c
+++ b/drivers/hid/hid-magicmouse.c
@@ -522,6 +522,11 @@ static int magicmouse_event(struct hid_device 
*hdev, struct hid_field *field,
                 struct hid_usage *usage, __s32 value)
  {
         struct magicmouse_sc *msc = hid_get_drvdata(hdev);
+       if (!msc || !msc->input) {
+               hid_warn(hdev, "this would have crashed\n");
+               return 0;
+       }
+
         if ((msc->input->id.product == USB_DEVICE_ID_APPLE_MAGICMOUSE2 ||
              msc->input->id.product == 
USB_DEVICE_ID_APPLE_MAGICMOUSE2_USBC) &&
             field->report->id == MOUSE2_REPORT_ID) {

then I receive

[45398.145218] magicmouse 0003:05AC:0324.0003: this would have crashed

and the system does, in fact, not crash.

I have no idea what the cause is; in this instance the message appeared 
for the first time about 12 hours after system boot (but sometimes it's 
much faster), it printed several times a second for 42 minutes (I guess 
I should have used hid_warn_ratelimited), and then stopped again. The 
trackpad remained usable throughout.

Please let me know if there's anything I can do to help debug further. I 
know my way around the kernel tolerably well, but I don't have any 
particular knowledge of the HID subsystem.

Thanks,

Andrew
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help