* [PATCH v4 1/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset
@ 2026-08-24 1:08 Jiajia Liu
2026-08-24 1:09 ` [PATCH v4 2/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset Jiajia Liu
2026-08-24 2:40 ` [v4,1/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset bluez.test.bot
0 siblings, 2 replies; 3+ messages in thread
From: Jiajia Liu @ 2026-08-24 1:08 UTC (permalink / raw)
To: Marcel Holtmann, Luiz Augusto von Dentz, Ying Hsu, Archie Pusaka,
Abhishek Pandit-Subedi, Matthias Brugger,
AngeloGioacchino Del Regno, Jing Cai, Sean Wang, Chris Lu
Cc: linux-bluetooth, linux-kernel, linux-arm-kernel, linux-mediatek,
Jiajia Liu
MT7925 on HP Pro Mini 260 sometimes timed out during reloading driver
and reset usb device. btusb_suspend is not called again after closing
bluetooth interface.
usbcore: registered new interface driver btusb
Bluetooth: hci0: HW/SW Version: 0x00000000, Build Time: 20260605184935
Bluetooth: hci0: Execution of wmt command timed out
Bluetooth: hci0: Failed to send wmt patch dwnld (-110)
Bluetooth: hci0: Failed to set up firmware (-110)
usb 3-10: reset high-speed USB device number 4 using xhci_hcd
Bluetooth: hci0: HW/SW Version: 0x00000000, Build Time: 20260605184935
Bluetooth: hci0: Device setup in 1856545 usecs
Bluetooth: hci0: AOSP extensions version v1.00
Bluetooth: hci0: AOSP quality report is supported
Bluetooth: MGMT ver 1.23
btusb_mtk_reset calls usb_autopm_get_interface to resume the device
before driving the hardware reset, but never calls the matching
usb_autopm_put_interface. Every hardware reset therefore leaks a PM
usage reference of the interface, preventing the device from being
runtime suspended again until it is unbound.
Add the BTUSB_RESET flag. It is set before usb_queue_reset_device
and is cleared in btusb_disconnect, which drops the reference as well.
If the flag is already set when a new reset is requested, drop one
reference.
Also clear BTMTK_HW_RESET_ACTIVE if usb_autopm_get_interface fails,
otherwise no further reset could ever be attempted.
Fixes: 25b6d7593a3a ("Bluetooth: btmtk: introduce btmtk reset work")
Assisted-by: Claude:qwen3.8-max
Signed-off-by: Jiajia Liu <liujiajia@kylinos.cn>
---
Changes in v4:
- do not return if BTUSB_RESET is set in case the first reset failed.
move test_and_set_bit right before usb_queue_reset_device (sashiko)
Changes in v3:
- rename BTUSB_USB_RESET_ACTIVE to BTUSB_RESET (Luiz)
- test_and_clear_bit BTUSB_RESET in btusb_disconnect (Luiz)
- handle multiple reset requests int btusb_mtk_reset (sashiko)
set BTUSB_RESET if no reset_gpio after usb_autopm_get_interface.
If the flag is already set, add log and drop newly acquired reference
and return.
- clear BTMTK_HW_RESET_ACTIVE if usb_autopm_get_interface fails and add
error log. (sashiko)
---
drivers/bluetooth/btusb.c | 14 +++++++++++++-
1 file changed, 13 insertions(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 184e95c1625e5..c95f72484fc0f 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -957,6 +957,7 @@ struct qca_dump_info {
#define BTUSB_USE_ALT3_FOR_WBS 15
#define BTUSB_ALT6_CONTINUOUS_TX 16
#define BTUSB_HW_SSR_ACTIVE 17
+#define BTUSB_RESET 18
struct btusb_data {
struct hci_dev *hdev;
@@ -2891,8 +2892,11 @@ static int btusb_mtk_reset(struct hci_dev *hdev, void *rst_data)
}
err = usb_autopm_get_interface(data->intf);
- if (err < 0)
+ if (err < 0) {
+ bt_dev_err(hdev, "Failed usb_autopm_get_interface: %d", err);
+ clear_bit(BTMTK_HW_RESET_ACTIVE, &btmtk_data->flags);
return err;
+ }
/* Release MediaTek ISO data interface */
btusb_mtk_release_iso_intf(hdev);
@@ -2915,6 +2919,11 @@ static int btusb_mtk_reset(struct hci_dev *hdev, void *rst_data)
err = btmtk_usb_subsys_reset(hdev, btmtk_data->dev_id);
+ if (test_and_set_bit(BTUSB_RESET, &data->flags)) {
+ bt_dev_err(hdev, "last usb reset failed? Resetting again");
+ usb_autopm_put_interface_no_suspend(data->intf);
+ }
+
usb_queue_reset_device(data->intf);
clear_bit(BTMTK_HW_RESET_ACTIVE, &btmtk_data->flags);
@@ -4497,6 +4506,9 @@ static void btusb_disconnect(struct usb_interface *intf)
if (data->reset_gpio)
gpiod_put(data->reset_gpio);
+ if (test_and_clear_bit(BTUSB_RESET, &data->flags))
+ usb_autopm_put_interface_no_suspend(data->intf);
+
if (intf == data->intf) {
if (data->isoc)
usb_driver_release_interface(&btusb_driver, data->isoc);
--
2.53.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* [PATCH v4 2/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset
2026-08-24 1:08 [PATCH v4 1/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset Jiajia Liu
@ 2026-08-24 1:09 ` Jiajia Liu
2026-08-24 2:40 ` [v4,1/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset bluez.test.bot
1 sibling, 0 replies; 3+ messages in thread
From: Jiajia Liu @ 2026-08-24 1:09 UTC (permalink / raw)
To: Marcel Holtmann, Luiz Augusto von Dentz, Ying Hsu, Archie Pusaka,
Abhishek Pandit-Subedi, Matthias Brugger,
AngeloGioacchino Del Regno, Jing Cai, Sean Wang, Chris Lu
Cc: linux-bluetooth, linux-kernel, linux-arm-kernel, linux-mediatek,
Jiajia Liu
btusb_reset calls usb_autopm_get_interface to resume the device
before queuing a reset of it, but never calls the matching
usb_autopm_put_interface.
usb_queue_reset_device ends up in usb_reset_device(), and since
btusb provides no pre_reset/post_reset callbacks the interface is
merely unbound and rebound: the interface device object survives
this cycle, and so does its PM usage count, which is not cleared
when the driver is unbound.
As a result every reset permanently leaks a PM usage reference,
preventing the interface from being runtime suspended again until
it is unbound.
Set BTUSB_RESET flag before usb_queue_reset_device so that
btusb_disconnect drops the reference. If the flag is already set,
drop one reference.
Fixes: c9209b269afd ("Bluetooth: btusb: Introduce generic USB reset")
Assisted-by: Claude:qwen3.8-max
Signed-off-by: Jiajia Liu <liujiajia@kylinos.cn>
---
Changes in v4:
- do not return if BTUSB_RESET is set in case the first reset failed.
(sashiko)
Changes in v3:
- handle multiple reset requests int btusb_reset (sashiko)
set BTUSB_RESET after usb_autopm_get_interface. If the flag is
already set, drop newly acquired reference and return.
Changes in v2:
- Fix the race window (sashiko)
set BTUSB_USB_RESET_ACTIVE flag before usb_queue_reset_device.
Changes in v1:
- add usb_autopm_put_interface after usb_queue_reset_device
---
drivers/bluetooth/btusb.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index c95f72484fc0f..f92ea1178bc26 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -1033,13 +1033,15 @@ static void btusb_reset(struct hci_dev *hdev)
int err;
data = hci_get_drvdata(hdev);
- /* This is not an unbalanced PM reference since the device will reset */
err = usb_autopm_get_interface(data->intf);
if (err) {
bt_dev_err(hdev, "Failed usb_autopm_get_interface: %d", err);
return;
}
+ if (test_and_set_bit(BTUSB_RESET, &data->flags))
+ usb_autopm_put_interface_no_suspend(data->intf);
+
bt_dev_err(hdev, "Resetting usb device.");
usb_queue_reset_device(data->intf);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* RE: [v4,1/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset
2026-08-24 1:08 [PATCH v4 1/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset Jiajia Liu
2026-08-24 1:09 ` [PATCH v4 2/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset Jiajia Liu
@ 2026-08-24 2:40 ` bluez.test.bot
1 sibling, 0 replies; 3+ messages in thread
From: bluez.test.bot @ 2026-08-24 2:40 UTC (permalink / raw)
To: linux-bluetooth, liujiajia
[-- Attachment #1: Type: text/plain, Size: 1181 bytes --]
This is automated email and please do not reply to this email!
Dear submitter,
Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/project/bluetooth/list/?series=1150542
---Test result---
Test Summary:
CheckPatch PASS 1.01 seconds
VerifyFixes PASS 0.10 seconds
VerifySignedoff PASS 0.10 seconds
GitLint PASS 0.47 seconds
SubjectPrefix PASS 0.19 seconds
BuildKernel PASS 17.72 seconds
CheckAllWarning PASS 19.43 seconds
CheckSparse PASS 18.31 seconds
BuildKernel32 PASS 17.08 seconds
CheckKernelLLVM SKIP 0.00 seconds
TestRunnerSetup PASS 310.98 seconds
IncrementalBuild PASS 17.92 seconds
Details
##############################
Test: CheckKernelLLVM - SKIP
Desc: Build kernel with LLVM + context analysis
Output:
Clang not found
https://github.com/bluez/bluetooth-next/pull/639
---
Regards,
Linux Bluetooth
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-24 2:40 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-24 1:08 [PATCH v4 1/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset Jiajia Liu
2026-08-24 1:09 ` [PATCH v4 2/2] Bluetooth: btusb: Fix leaked runtime PM reference in btusb_reset Jiajia Liu
2026-08-24 2:40 ` [v4,1/2] Bluetooth: btusb: mediatek: Fix leaked runtime PM reference in reset bluez.test.bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox