Linux bluetooth development
 help / color / mirror / Atom feed
From: Shuai Zhang <shuai.zhang@oss.qualcomm.com>
To: Luiz Augusto von Dentz <luiz.dentz@gmail.com>
Cc: Marcel Holtmann <marcel@holtmann.org>,
	linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org,
	linux-arm-msm@vger.kernel.org, chejiang@qti.qualcomm.com,
	quic_chezhou@quicinc.com, wei.deng@oss.qualcomm.com,
	jinwang.li@oss.qualcomm.com, mengshi.wu@oss.qualcomm.com
Subject: Re: [PATCH v2] Bluetooth: mgmt: reply to cancelled mgmt commands instead of silently dropping
Date: Tue, 18 Aug 2026 19:21:09 +0800	[thread overview]
Message-ID: <4c08029e-9404-4e79-bda1-b0414faad4f9@oss.qualcomm.com> (raw)
In-Reply-To: <CABBYNZK=Pk_5UpB5F9RkUvk8kTzXYVi_dzB-yr4_yCTumTBE+A@mail.gmail.com>

Hi Luiz

On 8/18/2026 2:05 AM, Luiz Augusto von Dentz wrote:
> Hi Shuai,
>
> On Mon, Aug 17, 2026 at 2:01 AM Shuai Zhang
> <shuai.zhang@oss.qualcomm.com> wrote:
>> The kernel sets HCI_AUTO_OFF when a controller is first registered and
>> starts a 2-second timer. On slower boots bluetoothd and the HCI_AUTO_OFF
>> timer can race: hci_power_off() is already queued while bluetoothd is
>> still in the middle of its adapter setup sequence. hci_cmd_sync_clear()
>> then cancels any pending mgmt commands with -ECANCELED, including the
>> MGMT_OP_REMOVE_ADV_MONITOR sent by reset_adv_monitors() early in the
>> setup sequence.
>>
>> When auto_off=1, hci_dev_close_sync() skips __mgmt_power_off() entirely,
>> so there is no fallback path to reply to the cancelled commands.
>> mgmt_remove_adv_monitor_complete() silently returns on -ECANCELED, leaving
>> the command with no reply. Since bluez's mgmt queue is strictly serialised,
>> this stalls all subsequent commands indefinitely, leaving bluetoothd unable
>> to register the adapter.
>>
>> Fix by mapping -ECANCELED to MGMT_STATUS_CANCELLED in mgmt_errno_status()
>> and removing the early return in mgmt_remove_adv_monitor_complete(), so
>> bluetoothd receives a reply and can continue normally.
>>
>> Signed-off-by: Shuai Zhang <shuai.zhang@oss.qualcomm.com>
>> ---
>>   net/bluetooth/mgmt.c | 5 ++---
>>   1 file changed, 2 insertions(+), 3 deletions(-)
>>
>> diff --git a/net/bluetooth/mgmt.c b/net/bluetooth/mgmt.c
>> index ac4864e56..c660bd3cd 100644
>> --- a/net/bluetooth/mgmt.c
>> +++ b/net/bluetooth/mgmt.c
>> @@ -301,6 +301,8 @@ static u8 mgmt_errno_status(int err)
>>                  return MGMT_STATUS_ALREADY_CONNECTED;
>>          case -ENOTCONN:
>>                  return MGMT_STATUS_DISCONNECTED;
>> +       case -ECANCELED:
>> +               return MGMT_STATUS_CANCELLED;
>>          }
>>
>>          return MGMT_STATUS_FAILED;
>> @@ -5675,9 +5677,6 @@ static void mgmt_remove_adv_monitor_complete(struct hci_dev *hdev,
>>          struct mgmt_pending_cmd *cmd = data;
>>          struct mgmt_cp_remove_adv_monitor *cp;
>>
>> -       if (status == -ECANCELED)
>> -               return;
>> -
>>          hci_dev_lock(hdev);
>>
>>          cp = cmd->param;
>> --
>> 2.34.1
>>
> Sashiko is flagging a couple of problems:
>
> https://sashiko.dev/#/patchset/20260817060134.3298439-1-shuai.zhang%40oss.qualcomm.com
This is indeed a valid issue. I'll address it in the next revision.

Thanks

shuai


>

      reply	other threads:[~2026-08-18 11:21 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-17  6:01 [PATCH v2] Bluetooth: mgmt: reply to cancelled mgmt commands instead of silently dropping Shuai Zhang
2026-08-17  6:38 ` [v2] " bluez.test.bot
2026-08-17 18:05 ` [PATCH v2] " Luiz Augusto von Dentz
2026-08-18 11:21   ` Shuai Zhang [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4c08029e-9404-4e79-bda1-b0414faad4f9@oss.qualcomm.com \
    --to=shuai.zhang@oss.qualcomm.com \
    --cc=chejiang@qti.qualcomm.com \
    --cc=jinwang.li@oss.qualcomm.com \
    --cc=linux-arm-msm@vger.kernel.org \
    --cc=linux-bluetooth@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=luiz.dentz@gmail.com \
    --cc=marcel@holtmann.org \
    --cc=mengshi.wu@oss.qualcomm.com \
    --cc=quic_chezhou@quicinc.com \
    --cc=wei.deng@oss.qualcomm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox