[PATCH v2 0/2] Bluetooth: Fix data-races in SCO/ISO connect paths
SeungJu Cheon <[email protected]> Mon, 1 Jun 2026 20:19:06 +0900
| Newsgroups | dev.linux.lists.linux-kernel-mentees,org.kernel.vger.linux-bluetooth,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
The connect paths read socket address and config fields without lock_sock() and pass them to hci_get_route() and hci_connect_*(), while connect()/bind()/setsockopt() can update them concurrently. Patch 1 covers ISO (iso_connect_bis/cis, iso_listen_bis, iso_conn_big_sync), patch 2 covers SCO (sco_connect). The added lock_sock() sections are reached with the lock not held and released before hci_get_route()/hci_dev_lock(), so no recursive locking or new lock ordering is introduced. Tested on KCSAN + PROVE_LOCKING with VHCI reproducers on the SCO and ISO CIS connect paths; the hci_get_route() race no longer reproduces and no lockdep splat is seen. Changes in v2: - ISO: cache bc_sid too, and pass cached src/dst/bc_sid to __iso_get_sock_listen_by_sid() in iso_listen_bis() (missed in v1) - ISO: use cached bc_sid in BT_DBG() in iso_connect_bis() - SCO: also snapshot src, setting and codec; v1 only did dst - reword: the fix stops torn reads, it does not close the TOCTOU window - fix the SCO Fixes: tag title SeungJu Cheon (2): Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls Bluetooth: SCO: Fix data-race on sco_pi fields in sco_connect net/bluetooth/iso.c | 60 +++++++++++++++++++++++++++++++++------------ net/bluetooth/sco.c | 20 +++++++++++---- 2 files changed, 59 insertions(+), 21 deletions(-) -- 2.52.0