From: Luiz Augusto von Dentz <luiz.dentz@gmail.com>
To: linux-bluetooth@vger.kernel.org
Subject: [PATCH BlueZ v3 1/9] shared/gatt-client: Fix calling destroy after unregistering notify
Date: Thu, 24 Sep 2026 11:46:23 -0400 [thread overview]
Message-ID: <20260924154631.369299-2-luiz.dentz@gmail.com> (raw)
In-Reply-To: <20260924154631.369299-1-luiz.dentz@gmail.com>
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
bt_gatt_client_unregister_notify resets the callbacks of the
notification but not its destroy callback, which is called once the
notify_data is freed. If a procedure is still pending at that point,
e.g. the write of the CCC to disable the notifications, it holds a
reference to notify_data so destroy is called later, once the user data
may have been freed, e.g. the reports of HoG:
ERROR: AddressSanitizer: heap-use-after-free
#11 report_notify_destroy profiles/input/hog-lib.c:359
#12 attrib_callbacks_destroy attrib/gattrib.c:130
#13 notify_data_unref src/shared/gatt-client.c:256
#15 destroy_write_op src/shared/gatt-client.c:3189
#16 request_unref src/shared/gatt-client.c:201
#17 destroy_att_send_op src/shared/att.c:215
#18 bt_att_cancel src/shared/att.c:1925
#19 cancel_request src/shared/gatt-client.c:2783
...
#21 bt_gatt_client_cancel_all src/shared/gatt-client.c:2811
#22 bt_gatt_client_free src/shared/gatt-client.c:2290
Call destroy when unregistering instead.
---
src/shared/gatt-client.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/src/shared/gatt-client.c b/src/shared/gatt-client.c
index 92ad7c39c115..cd4270291827 100644
--- a/src/shared/gatt-client.c
+++ b/src/shared/gatt-client.c
@@ -3858,6 +3858,15 @@ bool bt_gatt_client_unregister_notify(struct bt_gatt_client *client,
notify_data->callback = NULL;
notify_data->notify = NULL;
+ /* Call destroy now as the user data may be freed once unregistered,
+ * while notify_data may still be referenced by a pending procedure,
+ * e.g. the write of the CCC.
+ */
+ if (notify_data->destroy) {
+ notify_data->destroy(notify_data->user_data);
+ notify_data->destroy = NULL;
+ }
+
complete_unregister_notify(notify_data);
return true;
}
--
2.55.0
next prev parent reply other threads:[~2026-09-24 15:46 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 15:46 [PATCH BlueZ v3 0/9] Add HID over GATT functional tests Luiz Augusto von Dentz
2026-09-24 15:46 ` Luiz Augusto von Dentz [this message]
2026-09-24 19:16 ` bluez.test.bot
2026-10-09 19:52 ` bluez.test.bot
2026-09-24 15:46 ` [PATCH BlueZ v3 2/9] attrib: Fix unregistering notifications registered with bt_gatt_client Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 3/9] client/gatt: Fix setting descriptor value from scripts Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 4/9] client/mgmt: Print Connection Subrate event Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 5/9] emulator: Default to the latest BR/EDR+LE version Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 6/9] client/scripts: Add HoG device scripts Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 7/9] doc: Add functional-hog documentation Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 8/9] test: functional: add HoG tests Luiz Augusto von Dentz
2026-09-24 15:46 ` [PATCH BlueZ v3 9/9] test: functional: limit the workers by the memory available Luiz Augusto von Dentz
2026-09-29 20:50 ` [PATCH BlueZ v3 0/9] Add HID over GATT functional tests patchwork-bot+bluetooth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924154631.369299-2-luiz.dentz@gmail.com \
--to=luiz.dentz@gmail.com \
--cc=linux-bluetooth@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.