All of lore.kernel.org
 help / color / mirror / Atom feed
From: devgianlu <noreply@github.com>
To: linux-bluetooth@vger.kernel.org
Subject: [bluez/bluez] 9af06c: shared/gatt-db: Always notify service removal
Date: Wed, 30 Sep 2026 07:10:22 -0700	[thread overview]
Message-ID: <bluez/bluez/push/refs/heads/1176731/000000-9da276@github.com> (raw)

  Branch: refs/heads/1176731
  Home:   https://github.com/bluez/bluez
  Commit: 9af06c7096caf1dd02209dc8f46ed980f0b096ee
      https://github.com/bluez/bluez/commit/9af06c7096caf1dd02209dc8f46ed980f0b096ee
  Author: Gianluca Altomani <altomanigianluca@gmail.com>
  Date:   2026-09-30 (Wed, 30 Sep 2026)

  Changed paths:
    M src/shared/gatt-db.c

  Log Message:
  -----------
  shared/gatt-db: Always notify service removal

gatt_db_service_destroy() only notified removal listeners about active
services. A gatt-client discovery keeps services that are not active
yet in its pending_svcs queue, and it only drops them from that queue
through this notification. When such a service is destroyed while the
discovery is in flight, for example through gatt_db_clear_range() after
the link drops mid-discovery, the queue is left pointing at freed
memory, and discovery_op_complete() then dereferences it:

  gatt_db_service_get_active (src/shared/gatt-db.c)
  discovery_op_complete (src/shared/gatt-client.c)

Notify removal whether or not the service was active. The other
removal listeners already ignore services they never saw added, since
services are only announced when they become active.

It is reproduced by connecting over LE, reading one characteristic and
disconnecting about once a second, so that the link repeatedly drops
while bluetoothd is still discovering the peer: on 5.72 bluetoothd
crashed on the 15th connection in 4 runs out of 4.

The same change was found independently in
https://github.com/ownback/airpods-bluez-fix.

Assisted-by: Claude:claude-opus-5-5


  Commit: 9da2762fc2d1ff895a45a2be4073c58d2af66f1e
      https://github.com/bluez/bluez/commit/9da2762fc2d1ff895a45a2be4073c58d2af66f1e
  Author: Gianluca Altomani <altomanigianluca@gmail.com>
  Date:   2026-09-30 (Wed, 30 Sep 2026)

  Changed paths:
    M src/shared/gatt-client.c

  Log Message:
  -----------
  shared/gatt-client: Fix double-queued service

discovery_op_create() loads every service already in the client
database into pending_svcs, active or not, and discovery_found_service()
then queues an inactive service again when it finds it. A service left
inactive by an earlier discovery that was cut short therefore ends up
in the queue twice.

If that discovery fails too, discovery_op_complete() walks pending_svcs
with its removal callback already unregistered: the first entry removes
and frees the service, and the second one dereferences it:

  gatt_db_service_get_active (src/shared/gatt-db.c)
  discovery_op_complete (src/shared/gatt-client.c)

Only queue an inactive service if it is not pending already.

Assisted-by: Claude:claude-opus-5-5


Compare: https://github.com/bluez/bluez/compare/9af06c7096ca%5E...9da2762fc2d1

To unsubscribe from these emails, change your notification settings at https://github.com/bluez/bluez/settings/notifications

                 reply	other threads:[~2026-09-30 14:10 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=bluez/bluez/push/refs/heads/1176731/000000-9da276@github.com \
    --to=noreply@github.com \
    --cc=linux-bluetooth@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.