From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f52.google.com (mail-wr1-f52.google.com [209.85.221.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E0B473ACEFE for ; Fri, 14 Aug 2026 23:12:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786749178; cv=none; b=EjnVvoGMe2DN/K/Ti2QOQKv4myjFOVM4gBZrRLmYtb6XxM5GjZdSIF3gfMtamTabkQUBP/g3N+fskqKMGlyh2/n+LGf28ivR5q6eHgvOxE4rKD2YGR/Rzm0Yw2UXZGXi17YMx+lZ5SD6VKOTRzNZ6IEcnpjjYcTB8DMvHwVtSxE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786749178; c=relaxed/simple; bh=/2viJdQpryEE7rdr5VoupLH1jBOoJzjsw3SbX+zKLYU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=jLAaUNn1ivhWPjbLeZmmDtMthBUv7VBYDTZb/I1KZBD47+oXnEDIqoHvBeGzwt+dZHJcVv89Z16eiL+UWHJw1+rhnqapJGwX6mcVPH2UAYzNH/1Q1zQ+QZXjRF7Lyh8LJdC6VsdvHq6HL/H0MXpPYJq2/wmG8I1n73uQn1Hj+zE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=GxlkTAcF; arc=none smtp.client-ip=209.85.221.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="GxlkTAcF" Received: by mail-wr1-f52.google.com with SMTP id ffacd0b85a97d-47f7872abb6so869808f8f.3 for ; Fri, 14 Aug 2026 16:12:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786749174; x=1787353974; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=fKB+Iwkbk4H49tmH4QXa0HUCzoP7pEEfG4W0BPo05F8=; b=GxlkTAcF0DJmKRrKpT/NU+6m5+Q7IGVdXEk0qijln5ahXkqEI7/ilAOUJPl19k9HdA 5KsgFMCFRKuA3VWbcoyx+nKx2qxf5oJuqlGn7jMEZdqwqtkIDyYZx6VgfccDWAJR6fn6 8QvoL7OdlAyDbpW2wk7KHDn1X3n427mziNzWcuAt4k6Bctbv86fGFeJSbkbyEcu5/hJl CLUNOuW3biXwsSDnUjkFbGux1V4yzmiPw4oixVDEF3xXuq2u6tRYO5Js0HJk0bF2ZZ4+ 6hM4IYxo8xTHie6clHWTNAAUUhFxTLH0683gAl/Ie+Aj58BoOJVdZt5/e+L6BpQdpcRu swCA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786749174; x=1787353974; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=fKB+Iwkbk4H49tmH4QXa0HUCzoP7pEEfG4W0BPo05F8=; b=DRCr+yhxfJjHFd6T/0uBtFY1hnvhx1ESpc1iiUDAKbBxeIwoEk531liaQXcjzJf5jJ MS2dOsxTX8PYQHUAmUEXjuT/M7h32M6Z5u3YzYpvx6coSX+SVIsPGUjjgQSb4o6+lj7A G4yE/3vb6W9FOY8AqgoylZJrPqQlTAMahpKHwJm6QmctcKzw7sXJ/ki2pvvX6xcDeoP8 UZcRsdY4WprQ2VoM9qvsy+KEjy0KlBfaEnnud4gsvej/6/AwnNMnOVjZJpdpTb1ltpXR 9Ixq39bN1VO0z1AvyDoTwataC4sOxA/zWZGoO9t7+Z39/bkGb9kX8XtPbixk37WvKdgb NjTg== X-Forwarded-Encrypted: i=1; AHgh+RpKvEnWaepLDwBsjbMSM5xTtOgOV9vaXA4DR2rLXSSGYQt4+gNU+SV+A2qdbvgEMiftnhjLU9PyqEOSrlU=@vger.kernel.org X-Gm-Message-State: AOJu0YzTfDrTQgyb5mjUOVp7cru1pn5AWVGK5SN6RrlHpDv+wI8KnQ0v xmkQey/FgMIZCBI8WxLmOU7QjlOJrmUwl8xhDaJuKFFHkiFsg1l3I6k= X-Gm-Gg: AR+sD13FVdS4QhmkX8KLUy0OaGkPUpqPorJGrD9kNOkUjYY+XYZJNJnIfrIsS3VNp1o skGQDmTUjEXHeb5QWwed5nB8JY4qBFr25Ybgjui3m0dT15YOLvzmQfgAjvHh8hVbZUQ+p/g3QkD vtwELmN86qT9wxNbio6nJnhOeQ5EM2z7hiB7U1haOZwJeJIqnM47yszKinsvvIdo1T3yTReVkyw 16Qqd9PNdvShjtHie0Lz6XAG1A1pxIryyzCgCWN1JqrmBjQ6jPE9i0cBPOuI5UnTiEAcxpw+1M1 pYz3EkjFERF1PdLqD2fgYP+W7KFdd0lFQl/TuEmnK3sOE6MDZsjN4W5fDGb6BvoYdHs1e8tqgip SB8986q0ZoSSJIoF7UsvTvxtkXFCA5FwHmvPnQ/ne2JN5ZT9bxWCqLCklNXcMBbzPHTvVfCXbJe CCqaHMtx2YdbkOQXVIq4oekJ/5jad0Gw== X-Received: by 2002:a05:6000:470d:b0:481:5167:d526 with SMTP id ffacd0b85a97d-481606f4665mr13917452f8f.6.1786749174148; Fri, 14 Aug 2026 16:12:54 -0700 (PDT) Received: from debian.. ([2001:41d0:303:db6b::]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4815f219f7bsm11739429f8f.13.2026.08.14.16.12.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 16:12:51 -0700 (PDT) From: Tristan Madani To: Luiz Augusto von Dentz Cc: Marcel Holtmann , Abhishek Pandit-Subedi , Manish Mandlik , linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Tristan Madani Subject: [PATCH bluetooth] Bluetooth: cancel devcoredump work during device teardown Date: Fri, 14 Aug 2026 23:12:48 +0000 Message-ID: <20260814231248.3096377-1-tristmd@gmail.com> X-Mailer: git-send-email 2.47.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Tristan Madani hci_devcd_setup() initializes dump_timeout and dump_rx work items during device allocation, but hci_unregister_dev() does not cancel them before the device is freed. If a devcoredump is in progress when the device is unregistered, the dump_timeout delayed work timer remains active. When it fires after hci_release_dev() frees the hci_dev struct, it accesses freed memory. Add hci_devcd_destroy() to disable dump work items and purge the dump queue, called from hci_unregister_dev() alongside the existing disable_work_sync() calls. Fixes: 9695ef876fd1 ("Bluetooth: Add support for hci devcoredump") Cc: stable@vger.kernel.org Signed-off-by: Tristan Madani --- include/net/bluetooth/hci_core.h | 9 +++++++++ net/bluetooth/hci_core.c | 2 ++ 2 files changed, 11 insertions(+) diff --git a/include/net/bluetooth/hci_core.h b/include/net/bluetooth/hci_core.h index 3df59849dcbea..5a60c3f94a462 100644 --- a/include/net/bluetooth/hci_core.h +++ b/include/net/bluetooth/hci_core.h @@ -1800,6 +1800,15 @@ static inline void hci_devcd_setup(struct hci_dev *hdev) #endif } +static inline void hci_devcd_destroy(struct hci_dev *hdev) +{ +#ifdef CONFIG_DEV_COREDUMP + disable_delayed_work_sync(&hdev->dump.dump_timeout); + disable_work_sync(&hdev->dump.dump_rx); + skb_queue_purge(&hdev->dump.dump_q); +#endif +} + int hci_dev_open(__u16 dev); int hci_dev_close(__u16 dev); int hci_dev_do_close(struct hci_dev *hdev); diff --git a/net/bluetooth/hci_core.c b/net/bluetooth/hci_core.c index 5ba9fe8261ec8..d4d559dabf422 100644 --- a/net/bluetooth/hci_core.c +++ b/net/bluetooth/hci_core.c @@ -2671,6 +2671,8 @@ void hci_unregister_dev(struct hci_dev *hdev) disable_delayed_work_sync(&hdev->cmd_timer); disable_delayed_work_sync(&hdev->ncmd_timer); + hci_devcd_destroy(hdev); + hci_cmd_sync_clear(hdev); hci_unregister_suspend_notifier(hdev); -- 2.47.3