From nobody Fri Oct 2 01:15:27 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2577E1A6811; Thu, 6 Aug 2026 13:00:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786021216; cv=none; b=pNJMVQEtdKWsRj5rYkP3ytN9lUeGy4gdvoYBX7rALoOXZcBvHyXxpR1LnY3lvvk9gtQ1QpI28G+vHGS1YpEPAnya0vLNau7vJQyjcCAWxquDxTOKICJ7nIp+Am36/I0szjoUF5XB60IqC4VSgkgQr9RYHS11Kh+9RghRXMSm83w= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786021216; c=relaxed/simple; bh=uytQJkFwbSJVR9WerDh6/MyYSJXxEMX+p4hPRyKr6mE=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Ln1Ixopgt1ZRXpeNf14GiJgxPsV8rg5ekAmqICXFWwdM7BT+PXPHvR+9muEG34iiCzP47TxYJdZs/LLwNy9/WzI+be20y7Q3MfG58qZEZdM1JvzwNEWTXLRSLau+F34eJ7CgdxzcaRnhVxh3rVODjoePO5hqWoFgjg3pSS4PYlE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: bee95f3c919611f1aa26b74ffac11d73-20260806 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:23f66040-8084-4fff-a208-d5a29117c92e,IP:0,U RL:0,TC:0,Content:0,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTION :release,TS:25 X-CID-META: VersionHash:e7bac3a,CLOUDID:5e12b33f8d537a1c9334a9c0520b16ae,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:5,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI: 0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: bee95f3c919611f1aa26b74ffac11d73-20260806 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 1083245973; Thu, 06 Aug 2026 21:00:05 +0800 From: Linmao Li To: Marcel Holtmann , Luiz Augusto von Dentz Cc: Brian Gix , linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH bluetooth 1/4] Bluetooth: hci_conn: fix the SCO setup context lifetime Date: Thu, 6 Aug 2026 20:59:54 +0800 Message-Id: <20260806125957.698760-2-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260806125957.698760-1-lilinmao@kylinos.cn> References: <20260806125957.698760-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" hci_setup_sync() queues a conn_handle_t with a NULL destroy callback, so the context is only freed if hci_enhanced_setup_sync() actually runs. An entry that is cancelled instead is leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when there is no destroy callback, and hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. The context also stores a bare hci_conn pointer, so the connection can be freed while the work is queued. The dequeue in hci_conn_del() does not cover it either, as it matches on entry->data =3D=3D conn and entry->data is the wrapper here. Same problem as commit 2f5d635ad590 ("Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks"). Hold the connection and release both from a destroy callback. The submission failure path drops both, since hci_cmd_sync_submit() does not call the destroy callback when it fails to queue. Fixes: e07a06b4eb41 ("Bluetooth: Convert SCO configure_datapath to hci_sync= ") Signed-off-by: Linmao Li --- net/bluetooth/hci_conn.c | 20 +++++++++++++++----- 1 file changed, 15 insertions(+), 5 deletions(-) diff --git a/net/bluetooth/hci_conn.c b/net/bluetooth/hci_conn.c index b1f911fd4ad6a..19b7629b1cc10 100644 --- a/net/bluetooth/hci_conn.c +++ b/net/bluetooth/hci_conn.c @@ -283,8 +283,6 @@ static int hci_enhanced_setup_sync(struct hci_dev *hdev= , void *data) struct hci_cp_enhanced_setup_sync_conn cp; const struct sco_param *param; =20 - kfree(conn_handle); - if (!hci_conn_valid(hdev, conn)) return -ECANCELED; =20 @@ -453,6 +451,15 @@ static bool hci_setup_sync_conn(struct hci_conn *conn,= __u16 handle) return true; } =20 +static void hci_enhanced_setup_sync_destroy(struct hci_dev *hdev, void *da= ta, + int err) +{ + struct conn_handle_t *conn_handle =3D data; + + hci_conn_put(conn_handle->conn); + kfree(conn_handle); +} + bool hci_setup_sync(struct hci_conn *conn, __u16 handle) { int result; @@ -464,12 +471,15 @@ bool hci_setup_sync(struct hci_conn *conn, __u16 hand= le) if (!conn_handle) return false; =20 - conn_handle->conn =3D conn; + conn_handle->conn =3D hci_conn_get(conn); conn_handle->handle =3D handle; result =3D hci_cmd_sync_queue(conn->hdev, hci_enhanced_setup_sync, - conn_handle, NULL); - if (result < 0) + conn_handle, + hci_enhanced_setup_sync_destroy); + if (result < 0) { + hci_conn_put(conn); kfree(conn_handle); + } =20 return result =3D=3D 0; } --=20 2.25.1 From nobody Fri Oct 2 01:15:27 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A44522F60CC; Thu, 6 Aug 2026 13:00:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786021218; cv=none; b=lq8/IaGzv7lfZCMTrbD+T60ZAmmls8MrKBsrGTEZbIJaS5VQsAN5EUzr5d/FoJBN5y12CtGqKcqPkEa5k8nV0LKfGaFnz2YuF5UDvYDFUW4a8gCswNz3NYStPa9WCpSubSPjX6EIYeo31o0I7CqEa/uhtyDl1t3VKlM5/KXykhs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786021218; c=relaxed/simple; bh=e5uV9dHRaRo243fgckkbVRZxLQBS8gyQ4A30hg254Ww=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=T++8GtH2JUPPIdtofhYkL/ZKL5cKqYkpfD+/Zw+21IsImwoWG/IATNJ0Aqn8uFnfbYIj0Xu4Mr7MvIwmdzvg6Ca1FCE6LOBvTRyKCF5JP1kcRlF7cDV+X5jvY1kFS3Ch2GkN/8GsTN6Hy4P4TjPOOAFA6moklxanLMyF1yfSG4g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: c35b143e919611f1aa26b74ffac11d73-20260806 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:f398380e-abf6-4f70-ba8c-9eced9308940,IP:0,U RL:0,TC:0,Content:0,EDM:0,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTION: release,TS:0 X-CID-META: VersionHash:e7bac3a,CLOUDID:87c56219d59855b6d1ba470f5d39a6b8,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:-3,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI :0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: c35b143e919611f1aa26b74ffac11d73-20260806 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 1091912076; Thu, 06 Aug 2026 21:00:13 +0800 From: Linmao Li To: Marcel Holtmann , Luiz Augusto von Dentz Cc: Brian Gix , linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH bluetooth 2/4] Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths Date: Thu, 6 Aug 2026 20:59:55 +0800 Message-Id: <20260806125957.698760-3-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260806125957.698760-1-lilinmao@kylinos.cn> References: <20260806125957.698760-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" adv_timeout_expire() hands a kmalloc()ed instance byte to hci_cmd_sync_queue() with a NULL destroy callback, and only adv_timeout_expire_sync() frees it. That leaks on two paths: - the return value is not checked, and hci_cmd_sync_queue() does not take ownership when it fails (-ENETDOWN, -ENODEV, -ENOMEM); - a cancelled entry is not released, as _hci_cmd_sync_cancel_entry() does not free entry->data when there is no destroy callback. hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. Free the buffer from a destroy callback, and in the caller when the entry could not be queued at all. Fixes: c249ea9b4309 ("Bluetooth: Move Adv Instance timer to hci_sync") Signed-off-by: Linmao Li --- net/bluetooth/hci_sync.c | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/net/bluetooth/hci_sync.c b/net/bluetooth/hci_sync.c index c8d14128c363d..d21b7c8877545 100644 --- a/net/bluetooth/hci_sync.c +++ b/net/bluetooth/hci_sync.c @@ -540,8 +540,6 @@ static int adv_timeout_expire_sync(struct hci_dev *hdev= , void *data) { u8 instance =3D *(u8 *)data; =20 - kfree(data); - hci_clear_adv_instance_sync(hdev, NULL, instance, false); =20 if (list_empty(&hdev->adv_instances)) @@ -550,6 +548,12 @@ static int adv_timeout_expire_sync(struct hci_dev *hde= v, void *data) return 0; } =20 +static void adv_timeout_expire_destroy(struct hci_dev *hdev, void *data, + int err) +{ + kfree(data); +} + static void adv_timeout_expire(struct work_struct *work) { u8 *inst_ptr; @@ -570,7 +574,9 @@ static void adv_timeout_expire(struct work_struct *work) goto unlock; =20 *inst_ptr =3D hdev->cur_adv_instance; - hci_cmd_sync_queue(hdev, adv_timeout_expire_sync, inst_ptr, NULL); + if (hci_cmd_sync_queue(hdev, adv_timeout_expire_sync, inst_ptr, + adv_timeout_expire_destroy) < 0) + kfree(inst_ptr); =20 unlock: hci_dev_unlock(hdev); --=20 2.25.1 From nobody Fri Oct 2 01:15:27 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 791E61A6811; Thu, 6 Aug 2026 13:00:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786021234; cv=none; b=Jyh3hd/8VkBlH2kn67Ejf8AEeMH4yFsgGp5VSLTtmo8Y9eqmQ6wVGTWjVz94LF4f2SclGws4NgBXWeMtzh0+sCSfATyzvNK/ButTA+rszJfl5EqhBfUGC3v0X9CFG7cau3LIXL8xfd7JuF9Oonh8WEV8KgZeu8yDTy/MOIj2Ha0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786021234; c=relaxed/simple; bh=wQYqSn39znyFeriEWAuyoOFvx7yAMdHlo1NkxOiJB2M=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=ppXnks6qMvHEc25s04FXqvfKcNEguinjmZGH2vvyGC+VcjxyEFUL879SAS3a3FHNvzXolQiu0gbtFb0GkF/0BmH6X8pywY/ePZuW/Jqai0F9/qxrn/obipWxieYawmkDo+VXa7RDiHbDYOQykb8srBpLXGV8mp2c+rJcjVlgq/E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: c69e3950919611f1aa26b74ffac11d73-20260806 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:c55b309e-4ecc-4b85-8e81-b16b60ff4187,IP:0,U RL:0,TC:0,Content:-5,EDM:0,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTION :release,TS:-5 X-CID-META: VersionHash:e7bac3a,CLOUDID:177bc3b9de8ed4259b580199e078719e,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:-3,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI :0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: c69e3950919611f1aa26b74ffac11d73-20260806 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 838548469; Thu, 06 Aug 2026 21:00:18 +0800 From: Linmao Li To: Marcel Holtmann , Luiz Augusto von Dentz Cc: Brian Gix , linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH bluetooth 3/4] Bluetooth: MGMT: free the mesh send cancel command when it is cancelled Date: Thu, 6 Aug 2026 20:59:56 +0800 Message-Id: <20260806125957.698760-4-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260806125957.698760-1-lilinmao@kylinos.cn> References: <20260806125957.698760-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" mesh_send_cancel() queues the pending command with a NULL destroy callback, so it is only freed if send_cancel() runs. A cancelled entry is leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when there is no destroy callback, and hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. Nothing else reclaims it either: mgmt_pending_new() does not put the command on hdev->mgmt_pending. The leak also pins the socket reference taken by mgmt_pending_new(), so the mgmt socket is never released. Free the command from a destroy callback. Fixes: b338d91703fa ("Bluetooth: Implement support for Mesh") Signed-off-by: Linmao Li --- net/bluetooth/mgmt.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/net/bluetooth/mgmt.c b/net/bluetooth/mgmt.c index 167d75e345266..a80653b5b875d 100644 --- a/net/bluetooth/mgmt.c +++ b/net/bluetooth/mgmt.c @@ -2431,11 +2431,15 @@ static int send_cancel(struct hci_dev *hdev, void *= data) =20 mgmt_cmd_complete(cmd->sk, hdev->id, MGMT_OP_MESH_SEND_CANCEL, 0, NULL, 0); - mgmt_pending_free(cmd); =20 return 0; } =20 +static void send_cancel_destroy(struct hci_dev *hdev, void *data, int err) +{ + mgmt_pending_free(data); +} + static int mesh_send_cancel(struct sock *sk, struct hci_dev *hdev, void *data, u16 len) { @@ -2456,7 +2460,8 @@ static int mesh_send_cancel(struct sock *sk, struct h= ci_dev *hdev, if (!cmd) err =3D -ENOMEM; else - err =3D hci_cmd_sync_queue(hdev, send_cancel, cmd, NULL); + err =3D hci_cmd_sync_queue(hdev, send_cancel, cmd, + send_cancel_destroy); =20 if (err < 0) { err =3D mgmt_cmd_status(sk, hdev->id, MGMT_OP_MESH_SEND_CANCEL, --=20 2.25.1 From nobody Fri Oct 2 01:15:27 2026 Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D54A51F0E29; Thu, 6 Aug 2026 13:00:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786021231; cv=none; b=IKBRf5Fmn8r4Y0cjxKxnO/keOjspV+NVYArd8SyxI74aQlD90xauWrgT9ozjwLN0Fq7fcHKgCyjvqowJABXZf5W24cqJgJIZmvaLys4c2ItsTKCKpoi/G7GMrI7u6L4djo30w1K74YFrrKiM1X1rqEqvxbqw5l8dcOkcrv1Idg8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786021231; c=relaxed/simple; bh=7vrqT986iwcbo5gUIILeFrHRFIiW6cKy5ohx231gdEA=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=cqFAwNum9LI6b8+rHnpO6qkTCvMfegcdlIaCUESgRbg0v1qQrmdwCCd788UXskPeNq71n2KNPrGdWLpthqP5HwUb/kT5ix0iKv5kEFr3vt8YwuYmyflg5g4sQKOVwyhdenVhdt9+Yocy27qJBJniI99w7NQYiiB0OTfNSdtlo+I= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn; spf=pass smtp.mailfrom=kylinos.cn; arc=none smtp.client-ip=124.126.103.232 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kylinos.cn X-UUID: c7d92a96919611f1aa26b74ffac11d73-20260806 X-CID-P-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:4073e5af-0cd4-4108-8585-7ceb0a29fb3f,IP:0,U RL:0,TC:0,Content:0,EDM:25,RT:0,SF:0,FILE:0,BULK:0,RULE:Release_Ham,ACTION :release,TS:25 X-CID-META: VersionHash:e7bac3a,CLOUDID:b5da540dc652c9efa0e4cb77c8e9bf48,BulkI D:nil,BulkQuantity:0,Recheck:0,SF:81|82|102|850|865|898,TC:nil,Content:0|1 5|50,EDM:5,IP:nil,URL:0,File:nil,RT:nil,Bulk:nil,QS:nil,BEC:nil,COL:0,OSI: 0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE:0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_SNR X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: c7d92a96919611f1aa26b74ffac11d73-20260806 X-User: lilinmao@kylinos.cn Received: from localhost.localdomain [(10.44.16.150)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 1533056951; Thu, 06 Aug 2026 21:00:20 +0800 From: Linmao Li To: Marcel Holtmann , Luiz Augusto von Dentz Cc: Brian Gix , linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org, Linmao Li Subject: [PATCH bluetooth 4/4] Bluetooth: MGMT: free the HCI command when it is cancelled Date: Thu, 6 Aug 2026 20:59:57 +0800 Message-Id: <20260806125957.698760-5-lilinmao@kylinos.cn> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20260806125957.698760-1-lilinmao@kylinos.cn> References: <20260806125957.698760-1-lilinmao@kylinos.cn> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" mgmt_hci_cmd_sync() queues the pending command with a NULL destroy callback, so it is only freed if send_hci_cmd_sync() runs. A cancelled entry is leaked, as _hci_cmd_sync_cancel_entry() does not release entry->data when there is no destroy callback, and hci_cmd_sync_clear() cancels every pending entry when the controller is unregistered. Nothing else reclaims it either: mgmt_pending_new() does not put the command on hdev->mgmt_pending. The leak also pins the socket reference taken by mgmt_pending_new(), so the mgmt socket is never released. Free the command from a destroy callback. The now-empty done label is replaced by a direct return. Fixes: 827af4787e74 ("Bluetooth: MGMT: Add initial implementation of MGMT_O= P_HCI_CMD_SYNC") Signed-off-by: Linmao Li --- net/bluetooth/mgmt.c | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/net/bluetooth/mgmt.c b/net/bluetooth/mgmt.c index a80653b5b875d..7e9d27eefb504 100644 --- a/net/bluetooth/mgmt.c +++ b/net/bluetooth/mgmt.c @@ -2647,7 +2647,7 @@ static int send_hci_cmd_sync(struct hci_dev *hdev, vo= id *data) if (IS_ERR(skb)) { mgmt_cmd_status(cmd->sk, hdev->id, MGMT_OP_HCI_CMD_SYNC, mgmt_status(PTR_ERR(skb))); - goto done; + return 0; } =20 mgmt_cmd_complete(cmd->sk, hdev->id, MGMT_OP_HCI_CMD_SYNC, 0, @@ -2655,12 +2655,14 @@ static int send_hci_cmd_sync(struct hci_dev *hdev, = void *data) =20 kfree_skb(skb); =20 -done: - mgmt_pending_free(cmd); - return 0; } =20 +static void send_hci_cmd_sync_destroy(struct hci_dev *hdev, void *data, in= t err) +{ + mgmt_pending_free(data); +} + static int mgmt_hci_cmd_sync(struct sock *sk, struct hci_dev *hdev, void *data, u16 len) { @@ -2678,7 +2680,8 @@ static int mgmt_hci_cmd_sync(struct sock *sk, struct = hci_dev *hdev, if (!cmd) err =3D -ENOMEM; else - err =3D hci_cmd_sync_queue(hdev, send_hci_cmd_sync, cmd, NULL); + err =3D hci_cmd_sync_queue(hdev, send_hci_cmd_sync, cmd, + send_hci_cmd_sync_destroy); =20 if (err < 0) { err =3D mgmt_cmd_status(sk, hdev->id, MGMT_OP_HCI_CMD_SYNC, --=20 2.25.1