Linux bluetooth development
 help / color / mirror / Atom feed
* [PATCH] Bluetooth: RFCOMM: Fix initial port reference race
@ 2026-09-26 17:27 Chengfeng Ye
  2026-09-27 23:23 ` bluez.test.bot
  2026-09-28 15:40 ` [PATCH] " patchwork-bot+bluetooth
  0 siblings, 2 replies; 3+ messages in thread
From: Chengfeng Ye @ 2026-09-26 17:27 UTC (permalink / raw)
  To: Marcel Holtmann, Luiz Augusto von Dentz, Jakub Kicinski,
	Mark Brown, Johan Hovold, Chengfeng Ye, Tim Bird, Kees Cook,
	Peter Hurley
  Cc: linux-bluetooth, linux-kernel, stable

For RFCOMM_RELEASE_ONHUP devices, rfcomm_tty_install() and
__rfcomm_release_dev() both use RFCOMM_TTY_OWNED to decide who drops the
initial tty_port reference. The release path tests the bit separately
from the install path setting it, so both can drop that reference.

The synchronous hangup does not prevent this race: port->tty is not
assigned until tty_port_open(), after installation. The following
interleaving is possible:

  1. Install and release each obtain a reference with rfcomm_dev_get().
  2. Release observes RFCOMM_TTY_OWNED clear.
  3. Install sets RFCOMM_TTY_OWNED and drops the initial reference.
  4. Release drops the same initial reference again.
  5. TTY cleanup drops its reference and frees the device.
  6. Release performs its final tty_port_put() on the freed port.

KASAN reported:

  BUG: KASAN: slab-use-after-free in tty_port_put+0x22/0x190
  Write of size 4 at addr ffff8881001d3d5c by task poc/92

  Call Trace:
   tty_port_put+0x22/0x190
   rfcomm_dev_ioctl+0x1d4/0x1930
   sock_do_ioctl+0x110/0x260
   sock_ioctl+0x380/0x590
   __x64_sys_ioctl+0x134/0x1c0

  Allocated by task 88:
   rfcomm_dev_ioctl+0x8f6/0x1930
   sock_do_ioctl+0x110/0x260
   sock_ioctl+0x380/0x590
   __x64_sys_ioctl+0x134/0x1c0

  Freed by task 65:
   kfree+0x131/0x3c0
   rfcomm_dev_destruct+0x23b/0x2f0
   release_one_tty+0xc1/0x370
   process_one_work+0x661/0x1090

Use test_and_set_bit() in both paths so that only the caller that changes
RFCOMM_TTY_OWNED from clear to set drops the initial reference. Each path
keeps its own lookup reference until release or TTY cleanup, preserving
the existing callback ordering and error handling.

Fixes: 80ea73378af4 ("Bluetooth: Fix unreleased rfcomm_dev reference")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
---
 net/bluetooth/rfcomm/tty.c | 7 +++----
 1 file changed, 3 insertions(+), 4 deletions(-)

diff --git a/net/bluetooth/rfcomm/tty.c b/net/bluetooth/rfcomm/tty.c
index b2c1060394e6..dc3cdf614def 100644
--- a/net/bluetooth/rfcomm/tty.c
+++ b/net/bluetooth/rfcomm/tty.c
@@ -462,7 +462,7 @@ static int __rfcomm_release_dev(void __user *arg)
 	/* Shut down TTY synchronously before freeing rfcomm_dev */
 	tty_port_tty_vhangup(&dev->port);
 
-	if (!test_bit(RFCOMM_TTY_OWNED, &dev->status))
+	if (!test_and_set_bit(RFCOMM_TTY_OWNED, &dev->status))
 		tty_port_put(&dev->port);
 
 	tty_port_put(&dev->port);
@@ -724,10 +724,9 @@ static int rfcomm_tty_install(struct tty_driver *driver, struct tty_struct *tty)
 	 * when the last process closes the tty. The behaviour is expected by
 	 * userspace.
 	 */
-	if (test_bit(RFCOMM_RELEASE_ONHUP, &dev->flags)) {
-		set_bit(RFCOMM_TTY_OWNED, &dev->status);
+	if (test_bit(RFCOMM_RELEASE_ONHUP, &dev->flags) &&
+	    !test_and_set_bit(RFCOMM_TTY_OWNED, &dev->status))
 		tty_port_put(&dev->port);
-	}
 
 	return 0;
 }
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* RE: Bluetooth: RFCOMM: Fix initial port reference race
  2026-09-26 17:27 [PATCH] Bluetooth: RFCOMM: Fix initial port reference race Chengfeng Ye
@ 2026-09-27 23:23 ` bluez.test.bot
  2026-09-28 15:40 ` [PATCH] " patchwork-bot+bluetooth
  1 sibling, 0 replies; 3+ messages in thread
From: bluez.test.bot @ 2026-09-27 23:23 UTC (permalink / raw)
  To: linux-bluetooth, nicoyip.dev

[-- Attachment #1: Type: text/plain, Size: 1072 bytes --]

This is automated email and please do not reply to this email!

Dear submitter,

Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/series/1174570/

---Test result---

Test Summary:
CheckPatch                    PASS      0.57 seconds
VerifyFixes                   PASS      0.11 seconds
VerifySignedoff               PASS      0.07 seconds
GitLint                       PASS      0.23 seconds
SubjectPrefix                 PASS      0.06 seconds
BuildKernel                   PASS      30.05 seconds
CheckAllWarning               PASS      33.65 seconds
CheckSparse                   PASS      36.17 seconds
BuildKernel32                 PASS      29.39 seconds
CheckKernelLLVM               PASS      34.21 seconds
TestRunnerSetup               PASS      792.17 seconds
TestRunner_rfcomm-tester      PASS      5.62 seconds
IncrementalBuild              PASS      27.68 seconds



https://github.com/bluez/bluetooth-next/pull/824

---
Regards,
Linux Bluetooth


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] Bluetooth: RFCOMM: Fix initial port reference race
  2026-09-26 17:27 [PATCH] Bluetooth: RFCOMM: Fix initial port reference race Chengfeng Ye
  2026-09-27 23:23 ` bluez.test.bot
@ 2026-09-28 15:40 ` patchwork-bot+bluetooth
  1 sibling, 0 replies; 3+ messages in thread
From: patchwork-bot+bluetooth @ 2026-09-28 15:40 UTC (permalink / raw)
  To: Chengfeng Ye
  Cc: marcel, luiz.dentz, kuba, broonie, johan, tim.bird, kees, peter,
	linux-bluetooth, linux-kernel, stable

Hello:

This patch was applied to bluetooth/bluetooth-next.git (master)
by Luiz Augusto von Dentz <luiz.von.dentz@intel.com>:

On Sun, 27 Sep 2026 01:27:23 +0800 you wrote:
> For RFCOMM_RELEASE_ONHUP devices, rfcomm_tty_install() and
> __rfcomm_release_dev() both use RFCOMM_TTY_OWNED to decide who drops the
> initial tty_port reference. The release path tests the bit separately
> from the install path setting it, so both can drop that reference.
> 
> The synchronous hangup does not prevent this race: port->tty is not
> assigned until tty_port_open(), after installation. The following
> interleaving is possible:
> 
> [...]

Here is the summary with links:
  - Bluetooth: RFCOMM: Fix initial port reference race
    https://git.kernel.org/bluetooth/bluetooth-next/c/2d696c1ed346

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-28 15:41 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 17:27 [PATCH] Bluetooth: RFCOMM: Fix initial port reference race Chengfeng Ye
2026-09-27 23:23 ` bluez.test.bot
2026-09-28 15:40 ` [PATCH] " patchwork-bot+bluetooth

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox