Re: [PATCH] Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev
Bartosz Golaszewski <[email protected]>
| Newsgroups | org.kernel.vger.linux-bluetooth,org.kernel.vger.linux-arm-msm,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <CAMRc=McFRb8iZaDLY=DfLfDDA9WFJeNG94CaQeF3RJDgyqe8bg@mail.gmail.com> |
On Mon, 13 Jul 2026 09:25:43 +0200, raoxu <[email protected]> said: > From: Xu Rao <[email protected]> > > The command and ACL RPMsg endpoints store struct btqcomsmd as their > callback private data. The receive callbacks dereference btq->hdev > without taking an hci_dev reference. > > The current teardown order frees the hci_dev before destroying the RPMsg > endpoints in both the hci_register_dev() error path and the driver remove > path. If WCNSS delivers data in that window, the endpoint callback can > run with an already freed hci_dev and pass it to the Bluetooth core. > > For qcom_smd endpoints, rpmsg_destroy_ept() closes the channel and clears > the callback under the channel recv_lock. The receive path holds the same > lock while invoking the callback, so destroying the endpoints first both > prevents new callbacks and serializes with any callback already running. > > Destroy the command and ACL endpoints before hci_free_dev(). Keep > hci_unregister_dev() first during remove so the HCI core stops issuing > operations before the transport endpoints are shut down. In the full > registration-error cleanup path, return directly after freeing the hci_dev > to avoid falling through to the partial-construction labels and destroying > the endpoints twice. > > Fixes: 5052de8deff5 ("soc: qcom: smd: Transition client drivers from smd to rpmsg") > Fixes: 9a39a927be01 ("Bluetooth: btqcomsmd: Fix a resource leak in error handling paths in the probe function") > Cc: [email protected] > Signed-off-by: Xu Rao <[email protected]> > --- Acked-by: Bartosz Golaszewski <[email protected]>