Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset()
@ 2026-08-18  7:52 Jiajia Liu
  2026-08-18  7:52 ` [PATCH 2/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset Jiajia Liu
  2026-08-18  9:56 ` [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() Jiajia Liu
  0 siblings, 2 replies; 3+ messages in thread
From: Jiajia Liu @ 2026-08-18  7:52 UTC (permalink / raw)
  To: Marcel Holtmann, Luiz Augusto von Dentz, Ying Hsu, Archie Pusaka,
	Abhishek Pandit-Subedi, Matthias Brugger,
	AngeloGioacchino Del Regno, Jing Cai, Sean Wang, Chris Lu
  Cc: linux-bluetooth, linux-kernel, linux-arm-kernel, linux-mediatek,
	Jiajia Liu

btusb_reset() calls usb_autopm_get_interface() to resume the device
before queuing a reset of it, but never calls the matching
usb_autopm_put_interface().

usb_queue_reset_device() ends up in usb_reset_device(), and since
btusb provides no pre_reset/post_reset callbacks the interface is
merely unbound and rebound: the interface device object survives
this cycle, and so does its PM usage count, which is not cleared
when the driver is unbound.

As a result every reset permanently leaks a PM usage reference,
preventing the interface from being runtime suspended again until it
is unbound.

Calling usb_autopm_put_interface() right after queuing the reset: the
reset runs asynchronously in a workqueue and usb_reset_device()
resumes the device on its own.

Fixes: c9209b269afd ("Bluetooth: btusb: Introduce generic USB reset")
Assisted-by: Claude:qwen3.8-max
Signed-off-by: Jiajia Liu <liujiajia@kylinos.cn>
---
 drivers/bluetooth/btusb.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 2bae85b0016c..cc19828893c6 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -1051,7 +1051,6 @@ static void btusb_reset(struct hci_dev *hdev)
 	int err;
 
 	data = hci_get_drvdata(hdev);
-	/* This is not an unbalanced PM reference since the device will reset */
 	err = usb_autopm_get_interface(data->intf);
 	if (err) {
 		bt_dev_err(hdev, "Failed usb_autopm_get_interface: %d", err);
@@ -1060,6 +1059,7 @@ static void btusb_reset(struct hci_dev *hdev)
 
 	bt_dev_err(hdev, "Resetting usb device.");
 	usb_queue_reset_device(data->intf);
+	usb_autopm_put_interface(data->intf);
 }
 
 static void btusb_intel_reset(struct hci_dev *hdev)
-- 
2.55.0



^ permalink raw reply related	[flat|nested] 3+ messages in thread

* [PATCH 2/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset
  2026-08-18  7:52 [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() Jiajia Liu
@ 2026-08-18  7:52 ` Jiajia Liu
  2026-08-18  9:56 ` [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() Jiajia Liu
  1 sibling, 0 replies; 3+ messages in thread
From: Jiajia Liu @ 2026-08-18  7:52 UTC (permalink / raw)
  To: Marcel Holtmann, Luiz Augusto von Dentz, Ying Hsu, Archie Pusaka,
	Abhishek Pandit-Subedi, Matthias Brugger,
	AngeloGioacchino Del Regno, Jing Cai, Sean Wang, Chris Lu
  Cc: linux-bluetooth, linux-kernel, linux-arm-kernel, linux-mediatek,
	Jiajia Liu

MT7925 on HP Pro Mini 260 sometimes timed out during reloading driver
and reset usb device. btusb_suspend is not called again after closing
bluetooth interface.

 usbcore: registered new interface driver btusb
 Bluetooth: hci0: HW/SW Version: 0x00000000, Build Time: 20260605184935
 Bluetooth: hci0: Execution of wmt command timed out
 Bluetooth: hci0: Failed to send wmt patch dwnld (-110)
 Bluetooth: hci0: Failed to set up firmware (-110)
 usb 3-10: reset high-speed USB device number 4 using xhci_hcd
 Bluetooth: hci0: HW/SW Version: 0x00000000, Build Time: 20260605184935
 Bluetooth: hci0: Device setup in 1856545 usecs
 Bluetooth: hci0: AOSP extensions version v1.00
 Bluetooth: hci0: AOSP quality report is supported
 Bluetooth: MGMT ver 1.23

btusb_mtk_reset() calls usb_autopm_get_interface() to resume the
device before driving the hardware reset, but never calls the matching
usb_autopm_put_interface(). Every hardware reset therefore leaks a PM
usage reference of the interface, preventing the device from being
runtime suspended again until it is unbound.

Add the missing usb_autopm_put_interface() at the end of the function.
The reset_gpio path is left untouched on purpose: there the device
yanks itself off the USB and replugs, so the interface is destroyed
and its PM state goes away with it.

Fixes: 25b6d7593a3a ("Bluetooth: btmtk: introduce btmtk reset work")
Assisted-by: Claude:qwen3.8-max
Signed-off-by: Jiajia Liu <liujiajia@kylinos.cn>
---
 drivers/bluetooth/btusb.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index cc19828893c6..c3cc70ca28dc 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -2945,6 +2945,7 @@ static int btusb_mtk_reset(struct hci_dev *hdev, void *rst_data)
 
 	usb_queue_reset_device(data->intf);
 	clear_bit(BTMTK_HW_RESET_ACTIVE, &btmtk_data->flags);
+	usb_autopm_put_interface(data->intf);
 
 	return err;
 }
-- 
2.55.0



^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset()
  2026-08-18  7:52 [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() Jiajia Liu
  2026-08-18  7:52 ` [PATCH 2/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset Jiajia Liu
@ 2026-08-18  9:56 ` Jiajia Liu
  1 sibling, 0 replies; 3+ messages in thread
From: Jiajia Liu @ 2026-08-18  9:56 UTC (permalink / raw)
  To: Marcel Holtmann, Luiz Augusto von Dentz, Ying Hsu, Archie Pusaka,
	Abhishek Pandit-Subedi, Matthias Brugger,
	AngeloGioacchino Del Regno, Jing Cai, Sean Wang, Chris Lu
  Cc: linux-bluetooth, linux-kernel, linux-arm-kernel, linux-mediatek

Drop this series. There is a potential race window found by sashiko,
usb_lock_device_for_reset may abort the usb reset if the usb device
enters suspended before it.


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-08-18  9:56 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-18  7:52 [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() Jiajia Liu
2026-08-18  7:52 ` [PATCH 2/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset Jiajia Liu
2026-08-18  9:56 ` [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() Jiajia Liu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox