Linux thunderbolt driver: host_reset, CLx and bolt authorization

Parent: Thunderbolt eGPU on Linux for local LLM inference · Published reference · snapshot 2026-09-08 · skill devops-linux-internals/references/thunderbolt-usb4-pcie-tunnel-bolt-iommu-linux.md

Also known as: bolt authorization, bolt.service, boltctl, host_reset, iommu+user, kernel dma protection, pcie_aspm, razer core x v2 linux, software connection manager, thunderbolt security level, thunderbolt.clx, thunderbolt.host_reset, usb4 pcie tunnel bandwidth

↓ Facts as markdown↓ Download this reference fileall context files

How a Thunderbolt 4 or USB4 host builds the PCIe tunnel to an eGPU enclosure on Linux and what governs it — host router, connection manager, retimers and the enclosure switch; the 32 Gb/s tunnel ceili

These notes link each claim to its source. A source may be a research report hosted on this site rather than the primary document. A published reference means the content is available; it does not certify independent review or accuracy.Read the editorial policy and follow the sources before relying on a claim.

Linux thunderbolt driver: host_reset, CLx and bolt authorization

Thunderbolt/USB4 PCIe Tunnelling on Linux — eGPU Reference

Core Concepts

Text diagram — the anchor box

What each layer actually delivers

Kernel security levels (`/sys/bus/thunderbolt/devices/domainX/security`)

bolt / boltctl reference

What de-authorization actually does (the anchor's `echo 0 > authorized` case)

How Linux decides `iommu_dma_protection`

Kernel Module Parameters & host_reset

What `host_reset` does

Why the reset exists (commit 59a54c5f3dbd, "thunderbolt: Reset topology created by the boot firmware", authored by an AMD engineer, committed by the Thunderbolt maintainer)

Regression timeline

CLx

Retimers and firmware

Firmware/BIOS Options

Anti-patterns

Quick diagnostic checklist (anchor-tested order)

Sources

  • Regressions / threads: [source]
    • "[REGRESSION] Thunderbolt Host Reset Change Causes eGPU Disconnection from 6.8.7=>6.8.8" - https://ratatoskr.run/stable/2024/05/2595778/t ; https://lkml.iu.edu/2405.0/04964.html ; https://lkml.org/lkml/2024/5/20/216 [source]
    • Ubuntu bug 2078573 "I can no longer boot from my Thunderbolt disk" - https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2078573 [source]
    • "ReBAR over Thunderbolt" (linux-pci, 2026-03) - https://ratatoskr.run/linux-pci/2026/03/14618943/t [source]
    • AUTOSEL "thunderbolt: Disable CLx on Titan Ridge-based devices with old firmware" (2026-04) - https://ratatoskr.run/linux-usb/2026/04/3533651 [source]
    • "thunderbolt: PCIe tunnel creation fails for ..." (Titan Ridge host + USB4 dock, 2026-08) - https://ratatoskr.run/linux-usb/2026/08/17378667/t [source]
    • "[PATCH v2] thunderbolt: Assert downstream port ..." (DPR on tb_stop, 2026-06) - https://ratatoskr.run/linux-usb/2026/06/17108362/t [source]
    • Retimer nvm_version EAGAIN (6.11) - https://bugs.launchpad.net/ubuntu/+source/linux-oem-6.11/+bug/2085945 ; https://github.com/fwupd/fwupd/issues/8200 ; https://lists.openwall.net/linux-kernel/2024/12/09/1333 [source]
    • boltctl(1) - https://man.archlinux.org/man/boltctl.1 [source]
    • boltd(8) - https://man.archlinux.org/man/extra/bolt/boltd.8.en [source]
    • boltctl-domains.c ("iommu+%s" render) - https://raw.githubusercontent.com/gicmo/bolt/master/cli/boltctl-domains.c [source]
    • "bolt 0.8 with support for IOMMU protection" - https://christian.kellner.me/2019/07/09/bolt-0-8-with-support-for-iommu-protection/ [source]
  • Specs / bandwidth / vendor: [source]
    • Thunderbolt (interface) - https://en.wikipedia.org/wiki/Thunderbolt_(interface) [source]
    • Plugable "What Is Thunderbolt 5?" - https://plugable.com/blogs/news/what-is-thunderbolt-5-architecture-speed-and-whether-you-actually-need-it [source]
    • Plugable TB4 sneak peek (16→32 Gb/s PCIe minimum) - https://plugable.com/blogs/news/take-a-sneak-peek-at-intel-s-new-thunderbolt-4-specifications [source]
    • Intel TB4 certification requirements summary - https://serdes-validation-framework.readthedocs.io/en/stable/usb4/certification/intel-requirements.html [source]
    • Thunderspy 2 (Kernel DMA Protection) - https://thunderspy.io/ts2.html [source]
    • Phoronix: Linux 4.21 IOMMU DMA protection - https://www.phoronix.com/news/Linux-4.21-Thunderbolt-IOMMU [source]
    • Phoronix: Linux 5.12 USB4 SL5 "nopcie" - https://www.phoronix.com/news/Linux-5.12-USB4-SL5 [source]
    • Intel Community: NUC15CRK eGPU via TB4 PCIe tunnelling - https://community.intel.com/t5/Mobile-and-Desktop-Processors/NUC15CRK-eGPU-via-TB4-PCIe-tunneling-ASM2464PDX-RTX-5060-Ti/m-p/1756462 [source]
  • Community / eGPU practice: [source]
    • hvico/Razer-Core-v2-Linux-Fix (Core X V2 on Linux; clx=0, host_reset=0, BAR remove+rescan) - https://github.com/hvico/Razer-Core-v2-Linux-Fix [source]
    • eGPU.io: impact of eGPU connection speed on local LLM inference - https://egpu.io/forums/pro-applications/impact-of-egpu-connection-speed-on-local-llm-inference-in-multi-egpu-setups/ [source]
    • eGPU.io: Titan Ridge vs Alpine Ridge bandwidth - https://egpu.io/forums/thunderbolt-enclosures/any-egpu-improvements-expected-with-titan-ridge-tb3/ [source]
    • eGPU.io: Maple Ridge TB4 host 32 Gb/s - https://egpu.io/forums/pc-gaming/maple-ridge-host-controller-info/ [source]
    • localaimaster: eGPU for local AI (TB4 vs USB4 vs OCuLink) - https://localaimaster.com/blog/egpu-local-ai-benchmarks [source]
    • Arch Wiki External GPU / Thunderbolt (not fetchable on 2026-09-24 - Anubis challenge; cited for orientation only) - https://wiki.archlinux.org/title/External_GPU ; https://wiki.archlinux.org/title/Thunderbolt [source]
  • Children

    Frontier under this node: DMAR fault triage, Firmware CM (ICM) / Titan Ridge limitations, Intel VT-d untrusted-device domain policy, Resizable BAR over Thunderbolt, Thunderbolt NVM and retimer firmware updates (fwupd), USB4 router/adapter/path model, XDomain Thunderbolt networking and thunderbolt_dma_test, eGPU multi-GPU LLM topology: Thunderbolt vs OCuLink, initramfs Thunderbolt boot-device authorization, pciehp hotplug and Thunderbolt root-port removal

    ← the whole tree · 3D view· how to read this page