* [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset()
@ 2026-08-18 7:52 Jiajia Liu
2026-08-18 7:52 ` [PATCH 2/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset Jiajia Liu
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Jiajia Liu @ 2026-08-18 7:52 UTC (permalink / raw)
To: Marcel Holtmann, Luiz Augusto von Dentz, Ying Hsu, Archie Pusaka,
Abhishek Pandit-Subedi, Matthias Brugger,
AngeloGioacchino Del Regno, Jing Cai, Sean Wang, Chris Lu
Cc: linux-bluetooth, linux-kernel, linux-arm-kernel, linux-mediatek,
Jiajia Liu
btusb_reset() calls usb_autopm_get_interface() to resume the device
before queuing a reset of it, but never calls the matching
usb_autopm_put_interface().
usb_queue_reset_device() ends up in usb_reset_device(), and since
btusb provides no pre_reset/post_reset callbacks the interface is
merely unbound and rebound: the interface device object survives
this cycle, and so does its PM usage count, which is not cleared
when the driver is unbound.
As a result every reset permanently leaks a PM usage reference,
preventing the interface from being runtime suspended again until it
is unbound.
Calling usb_autopm_put_interface() right after queuing the reset: the
reset runs asynchronously in a workqueue and usb_reset_device()
resumes the device on its own.
Fixes: c9209b269afd ("Bluetooth: btusb: Introduce generic USB reset")
Assisted-by: Claude:qwen3.8-max
Signed-off-by: Jiajia Liu <liujiajia@kylinos.cn>
---
drivers/bluetooth/btusb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 2bae85b0016c..cc19828893c6 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -1051,7 +1051,6 @@ static void btusb_reset(struct hci_dev *hdev)
int err;
data = hci_get_drvdata(hdev);
- /* This is not an unbalanced PM reference since the device will reset */
err = usb_autopm_get_interface(data->intf);
if (err) {
bt_dev_err(hdev, "Failed usb_autopm_get_interface: %d", err);
@@ -1060,6 +1059,7 @@ static void btusb_reset(struct hci_dev *hdev)
bt_dev_err(hdev, "Resetting usb device.");
usb_queue_reset_device(data->intf);
+ usb_autopm_put_interface(data->intf);
}
static void btusb_intel_reset(struct hci_dev *hdev)
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread* [PATCH 2/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset
2026-08-18 7:52 [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() Jiajia Liu
@ 2026-08-18 7:52 ` Jiajia Liu
2026-08-18 8:32 ` [1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() bluez.test.bot
2026-08-18 9:56 ` [PATCH 1/2] " Jiajia Liu
2 siblings, 0 replies; 4+ messages in thread
From: Jiajia Liu @ 2026-08-18 7:52 UTC (permalink / raw)
To: Marcel Holtmann, Luiz Augusto von Dentz, Ying Hsu, Archie Pusaka,
Abhishek Pandit-Subedi, Matthias Brugger,
AngeloGioacchino Del Regno, Jing Cai, Sean Wang, Chris Lu
Cc: linux-bluetooth, linux-kernel, linux-arm-kernel, linux-mediatek,
Jiajia Liu
MT7925 on HP Pro Mini 260 sometimes timed out during reloading driver
and reset usb device. btusb_suspend is not called again after closing
bluetooth interface.
usbcore: registered new interface driver btusb
Bluetooth: hci0: HW/SW Version: 0x00000000, Build Time: 20260605184935
Bluetooth: hci0: Execution of wmt command timed out
Bluetooth: hci0: Failed to send wmt patch dwnld (-110)
Bluetooth: hci0: Failed to set up firmware (-110)
usb 3-10: reset high-speed USB device number 4 using xhci_hcd
Bluetooth: hci0: HW/SW Version: 0x00000000, Build Time: 20260605184935
Bluetooth: hci0: Device setup in 1856545 usecs
Bluetooth: hci0: AOSP extensions version v1.00
Bluetooth: hci0: AOSP quality report is supported
Bluetooth: MGMT ver 1.23
btusb_mtk_reset() calls usb_autopm_get_interface() to resume the
device before driving the hardware reset, but never calls the matching
usb_autopm_put_interface(). Every hardware reset therefore leaks a PM
usage reference of the interface, preventing the device from being
runtime suspended again until it is unbound.
Add the missing usb_autopm_put_interface() at the end of the function.
The reset_gpio path is left untouched on purpose: there the device
yanks itself off the USB and replugs, so the interface is destroyed
and its PM state goes away with it.
Fixes: 25b6d7593a3a ("Bluetooth: btmtk: introduce btmtk reset work")
Assisted-by: Claude:qwen3.8-max
Signed-off-by: Jiajia Liu <liujiajia@kylinos.cn>
---
drivers/bluetooth/btusb.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index cc19828893c6..c3cc70ca28dc 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -2945,6 +2945,7 @@ static int btusb_mtk_reset(struct hci_dev *hdev, void *rst_data)
usb_queue_reset_device(data->intf);
clear_bit(BTMTK_HW_RESET_ACTIVE, &btmtk_data->flags);
+ usb_autopm_put_interface(data->intf);
return err;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread* RE: [1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset()
2026-08-18 7:52 [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() Jiajia Liu
2026-08-18 7:52 ` [PATCH 2/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset Jiajia Liu
@ 2026-08-18 8:32 ` bluez.test.bot
2026-08-18 9:56 ` [PATCH 1/2] " Jiajia Liu
2 siblings, 0 replies; 4+ messages in thread
From: bluez.test.bot @ 2026-08-18 8:32 UTC (permalink / raw)
To: linux-bluetooth, liujiajia
[-- Attachment #1: Type: text/plain, Size: 1181 bytes --]
This is automated email and please do not reply to this email!
Dear submitter,
Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/project/bluetooth/list/?series=1147623
---Test result---
Test Summary:
CheckPatch PASS 1.10 seconds
VerifyFixes PASS 0.08 seconds
VerifySignedoff PASS 0.07 seconds
GitLint PASS 0.41 seconds
SubjectPrefix PASS 0.13 seconds
BuildKernel PASS 28.05 seconds
CheckAllWarning PASS 30.29 seconds
CheckSparse PASS 29.07 seconds
BuildKernel32 PASS 26.38 seconds
CheckKernelLLVM SKIP 0.00 seconds
TestRunnerSetup PASS 504.49 seconds
IncrementalBuild PASS 27.54 seconds
Details
##############################
Test: CheckKernelLLVM - SKIP
Desc: Build kernel with LLVM + context analysis
Output:
Clang not found
https://github.com/bluez/bluetooth-next/pull/605
---
Regards,
Linux Bluetooth
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset()
2026-08-18 7:52 [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() Jiajia Liu
2026-08-18 7:52 ` [PATCH 2/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset Jiajia Liu
2026-08-18 8:32 ` [1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() bluez.test.bot
@ 2026-08-18 9:56 ` Jiajia Liu
2 siblings, 0 replies; 4+ messages in thread
From: Jiajia Liu @ 2026-08-18 9:56 UTC (permalink / raw)
To: Marcel Holtmann, Luiz Augusto von Dentz, Ying Hsu, Archie Pusaka,
Abhishek Pandit-Subedi, Matthias Brugger,
AngeloGioacchino Del Regno, Jing Cai, Sean Wang, Chris Lu
Cc: linux-bluetooth, linux-kernel, linux-arm-kernel, linux-mediatek
Drop this series. There is a potential race window found by sashiko,
usb_lock_device_for_reset may abort the usb reset if the usb device
enters suspended before it.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-18 9:56 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-18 7:52 [PATCH 1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() Jiajia Liu
2026-08-18 7:52 ` [PATCH 2/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset Jiajia Liu
2026-08-18 8:32 ` [1/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset() bluez.test.bot
2026-08-18 9:56 ` [PATCH 1/2] " Jiajia Liu
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox