From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AAE0A28E0 for ; Fri, 7 Aug 2026 15:21:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786116107; cv=none; b=AollE4vzzTMBxZWkGAqwSwD2K1ivjqh5QnCqVcKEtyIcTftLyrT1mytbsoz/Lu0DADHEasepwlImiUcJml5JC9ogrK0M6pBxNKCwDsC6qAciL95LJm/iMH4DbYxRJFP4esFXFNGrKyeihiDMPFO11+Km8jVTXQEjLJMEtJxlIDI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786116107; c=relaxed/simple; bh=eXthG3pwF7AdjE6Zu2onIWo5e3+oLbrtMezp3Zvbm1g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=QsfKAqjx8XUQ62MDALjyET0yaiXrPeAbdL/44NFHuueD+8o8U6Fr/hbDpT7Tb9cZfMusIlc8LVYV4RirXaKtrIuNl40XBf9aQf9MpWgU3wFLICjuIKgHnjwG7siO1cPsSeM7u/yCwV1l0yo3g/nBxUVATL4egxndQFM9UxyZKZk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=Cus5LkxS; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=SjgATUL1; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="Cus5LkxS"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="SjgATUL1" Received: from pps.filterd (m0279866.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 677EvML9955148 for ; Fri, 7 Aug 2026 15:21:44 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=qcppdkim1; bh=fIN2n834rIS hCbSttoGPoLBBWFwgRPau6O7pYEVDiZ4=; b=Cus5LkxSQyoPITe4InwwZGjjQEu WTZbTdjdK/c9qnWkJE2zCIqmqK7LnFxDVclJkFQ8lO8SdfKIB5vPSmcVD6nBq30/ UkA7tlivEyfYpNst9mrXqceefX4Y3/t4Afm3W1nWrue64cwI0U4jzgExJdos/1Og O+0XszP33YAWQHXl9fueznbnQUogEYYCyUuZSF+NxoqjuGbV0ZJfOMM1sKBMmN/X Lz6o6sNfP27k4v8EXSad9pBEej/VM1X72O6QeLXqtH5Xyj1ih2hojYQzO3K/U24U /YyKzvsWjnNFGFNZGsfnmNlB6II0oOBWtC7X0zKGEKCD0GgYTBItMXlcKPw== Received: from mail-qt1-f197.google.com (mail-qt1-f197.google.com [209.85.160.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4fwhk3g3g0-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 07 Aug 2026 15:21:44 +0000 (GMT) Received: by mail-qt1-f197.google.com with SMTP id d75a77b69052e-51bff5c7035so63394561cf.2 for ; Fri, 07 Aug 2026 08:21:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1786116104; x=1786720904; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=fIN2n834rIShCbSttoGPoLBBWFwgRPau6O7pYEVDiZ4=; b=SjgATUL1Wrn4N+zXmWQ5Jg6ty4FX8SWqohQ7GOlJTJ2iqdpVDopxGgIFN2zzVAFYRX rpTzas3tCPMZbuiXX5rwMerpWhrGjR2GMwNoJeAq/bEJTroI+xi9gln3EOhWQ6/8B0PZ T+z+n3YNGXa+Tj0HIPZSUcNh3mbsRz0VUonzx5Mt091z/Jzq4V2QlP/hG8QBpfXMV/Ej 4MqLdslwf/lGRqbyTCd78dGInFQ4j2NKveYTPHzbbmrJ41EVzbqkkwIfYLKGsRZ7S3ot NNnBtwIjdCfw1X8wa4447m1h2HMQwdAXE0grgbxBN5KC+/pdUETOFeellfNni3L+53oN 8x2A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786116104; x=1786720904; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=fIN2n834rIShCbSttoGPoLBBWFwgRPau6O7pYEVDiZ4=; b=AMTZAFshc7YHdLhjeqzIb4Q2B9ZlWfXeifTxHHa9HNo6qz5zh7YSUIFQ8QJBJN9Hni MxHm7lAslI/k9QrcQEE/fyu3NGKaxD/g12eLvat37awN5JjIll/rk5ZJadz172CXmnOA WQ/nUZKIiO6aj0cATYfyEPWum/zFNS77Qt5b/VvI42k8UTDghyAnJlYovz2v/Sgf3g8n i2H67G72oDCUJwI7/L/hHkm7eSZVkzktn6En0ThldK55d+ARW/QFPS2xWh5pQljd+et3 G8UGJSnXPPBxZKwdxwBoqjR/VKfWFstxWuF9gaO6/6hyJRCHiO1/GFUYe3BdjPcl6atM JrOQ== X-Forwarded-Encrypted: i=1; AHgh+RpQI0X5x6MSLd0iAcTM1MnA02z35gC1mqkd8zZWVQQNjWnlphXn2TG+E/7BQxZOE41RUzk8prqXvfLpL54=@vger.kernel.org X-Gm-Message-State: AOJu0Yw46pbKWbTVnghjXZ/zOzRK+6sYbFuUD9J1ZkbZ3dOdqaDVJe1e SBN81284R4R6XRY75mdpjyccDNfMCEmvqtaofi51wMo9ZqaAeTmHYaEgyX2jQ+eL0/2e1dbc6cw m/Sce/X3srgLkNTFPH227+nlaYIyXo2D+eqz+9PlkEf8BG0u6gOK+H2NlU5dvWRUZvL4= X-Gm-Gg: AR+sD125G00dsb2hMtElNuSPawUX0Fpk93Alw/+q4ofBCWR9oXTKvpMigji1ibNF3q6 0JcOyqWBgNiBCNwUyzbVG+haQAZ4ubxxUU4FsLDTKBYzE5gr7moJWPdIOx5n9YRs+/NVTi0LAh7 /WY/GD4eZD4X9/atc6RL6J8C0W8nyuflsOt2hDwbSRS8u6EYOrYtGXpIw0RMz8TdT6Dm1b4OXjS ySLx9x6P4Rf3WWXAVOOPwEyyeIpcXm2O5mWAyXWgal7n5zNDBvVrgVnE2PknrLFQsItqxI2+HIm XfHdnjk2UalSa1B3XDzpTrPA5lTJaTymBOIK73lUYH6RFaVOycyTi1cZA7522Lq50yyqzhHLI+G 9y2ywsl1lcmuXeP2TPgH/zCyEFe3k0Og= X-Received: by 2002:a05:622a:480a:b0:51b:ee11:e71e with SMTP id d75a77b69052e-52ce5f7e829mr259021001cf.1.1786116103649; Fri, 07 Aug 2026 08:21:43 -0700 (PDT) X-Received: by 2002:a05:622a:480a:b0:51b:ee11:e71e with SMTP id d75a77b69052e-52ce5f7e829mr259020311cf.1.1786116103200; Fri, 07 Aug 2026 08:21:43 -0700 (PDT) Received: from QCOM-WFsSr66Fqw.qualcomm.com ([212.136.9.4]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a1e7c9d78asm774026a12.3.2026.08.07.08.21.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 07 Aug 2026 08:21:42 -0700 (PDT) From: Igor Skalkin To: haoxiang_li2024@163.com Cc: error27@gmail.com, mst@redhat.com, marcel@holtmann.org, luiz.dentz@gmail.com, linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, Trilok Soni , Igor Skalkin Subject: Re: [PATCH v4] Bluetooth: virtio: Fix virtbt_probe() init and cleanup Date: Fri, 7 Aug 2026 17:21:34 +0200 Message-ID: <20260807152134.1525-1-igor.skalkin@oss.qualcomm.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260709114745.4030794-1-haoxiang_li2024@163.com> References: <20260709114745.4030794-1-haoxiang_li2024@163.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Authority-Analysis: v=2.4 cv=RKaD2Yi+ c=1 sm=1 tr=0 ts=6a75f808 cx=c_pps a=EVbN6Ke/fEF3bsl7X48z0g==:117 a=dNlqnMcrdpbb+gQrTujlOQ==:17 a=Sv0fKeRqtYgA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=YMgV9FUhrdKAYTUUvYB2:22 a=EUspDBNiAAAA:8 a=6wz9AUWKJ1XHrY9wszAA:9 a=a_PwQJl-kcHnX1M80qC6:22 X-Proofpoint-Spam-Info: AW1haW4tMjYwODA3MDExOSBTYWx0ZWRfX5oDtveQd84YD EYqcd6cfUffEjZBpCYoNn9lVRzZOcQpACt0TZYZBUKPHRqEa/MGN+djeeF3AvJk6/w4a9c6F2Fv f+cQpZx5rW1YD9qJcxKl/d03MRPLFv8= X-Proofpoint-ORIG-GUID: pcRpiuQTWhReiH9-MJ5vL95IcthNDOr0 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODA3MDExOSBTYWx0ZWRfXzgkv99Q4EU6o MXOEjRkiai7N0bAMVyJjUDBQBRzbKIBkJhp3OPKDqtf/HoFGuOfdlacJNt71tf+a2XLpxQ8x3L0 mdur9QF9APQwaXC2mznPNy47Fkf+6IPPD7HOVg9JwspCqKiKfUIY7WPmbXoWBQvWAAMkqeGMdUU mnAj1uHp/PBATU0qVcXLomC40aNlJ4hCgqTHwxvPHcBBOX4MaW00gqv1cK5VlMue1wEVKjNWiN7 A0yl2MJqqy5ikiLAeOM1FXx+Gb1U9XAt/Pn7aBNbCaEdQzBHINLe9HczNWpHCSYMWu4Dz4KdW1w pfkjcF9fIucZhie3WIhcbiwlTBawQRhdxPxP4+E5TrFSqIDuumxhiDWRhkbIsJAIxowvTPWD3n6 Rhp+SwNrtwJqvg0IpjgLX7S45iLxvAn1xl8nYDG4nrCWwToFfobZTqsAQ1IenpLGGnp6/4fYaWM 7MByHim8vDpIRie9C0A== X-Proofpoint-GUID: pcRpiuQTWhReiH9-MJ5vL95IcthNDOr0 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-07_02,2026-08-06_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 lowpriorityscore=0 malwarescore=0 suspectscore=0 phishscore=0 impostorscore=0 adultscore=0 spamscore=0 clxscore=1015 priorityscore=1501 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608070119 I tested this against real hardware (not just QEMU-internal loopback): a MediaTek USB Bluetooth controller on the host, exposed to a guest kernel through QEMU's virtio-bt-pci device via HCI_CHANNEL_USER. This exercises the actual virtio transport and the real HCI core, not a mock. No other local changes to drivers/bluetooth/virtio_bt.c were present; this v4 patch was applied alone on top of plain v7.2-rc4. Test setup: - Host: Linux with a MediaTek USB BT controller (hci0), bluetooth.service stopped/masked and the adapter taken down for the duration of the test so QEMU could bind HCI_CHANNEL_USER exclusively. - Guest: v7.2-rc4 kernel with CONFIG_DEBUG_KMEMLEAK=y, booted via QEMU's virtio-bt-pci device pointed at the host adapter. - This patch (v4) applied alone, on top of plain v7.2-rc4, nothing else changed in virtio_bt.c; built as a loadable module for repeated bind/unbind testing. - A module parameter (test-only, not part of this patch) let me force a failure at each of the four points virtbt_probe() can now fail at, to drive every branch of the new unwind ladder without needing to fault-inject the real kernel functions. Cases run, each followed by an explicit kmemleak scan: 1. Happy path: probe succeeds, hci0 appears under /sys/class/bluetooth, remove() runs cleanly. 2. Five back-to-back insmod/rmmod cycles on the happy path, to catch leaks or use-after-free that only show up cumulatively. 3. Forced failure at virtio_find_vqs() -> err_free_vbt path. 4. Forced failure at hci_alloc_dev() -> err_del_vqs path. 5. Forced failure at virtbt_open_vdev(), i.e. after virtio_device_ready() (post-DRIVER_OK) -> err_close_vdev path. 6. Forced failure at hci_register_dev(), also post-DRIVER_OK and post-open -> err_close_vdev path. Results for all six: no Oops/BUG, no lockdep or RCU-stall warnings, rmmod always succeeded, hci0 was present under /sys/class/bluetooth only when probe actually succeeded (cases 1-2), and kmemleak reported zero unreferenced objects after every case and in a final aggregate scan at the end of the run. This covers the ordering fix Sashiko flagged (hci_register_dev() moved after virtio_device_ready()/virtbt_open_vdev(), so no buffers are kicked before DRIVER_OK) and the vbt-leak/priv-cleanup fix on the virtio_find_vqs() failure path, both under a real transport rather than a stub. Tested-by: Igor Skalkin Happy to share the QEMU/kernel config and the fault-injection harness if useful for other reviewers.