[PATCH v3] Bluetooth: l2cap: Create temporary hcon for inbound LE connections

Amir Abudubai <[email protected]>
Newsgroups org.kernel.vger.linux-bluetooth
Message-ID <[email protected]>
On some adapters, ACL data for an inbound LE connection can arrive
before the Connection Complete event registers its handle with the host
stack, causing the packet to be dropped as an unrecognized handle.

To resolve this, create a temporary hcon for ACL traffic arriving with an
unrecognized handle while advertising. If a matching LE peripheral
connection event arrives within the grace period, the temporary connection
is adopted. Otherwise, a timeout armed at creation removes the temporary
connection and emits an unknown handle error.

This issue was observed and the fix verified on:
  - 8087:0025 Intel Corp. Wireless-AC 9260 Bluetooth Adapter
  - 7392:c611 Edimax Technology Co., Ltd Edimax Bluetooth Adapter

Assisted-by: OpenCode:openai/gpt-5.6-sol
Signed-off-by: Amir Abudubai <[email protected]>
---
I limited it to only inbound LE connections. I think it can
happen to any connection creation event in theory, so I started
there. However when I tried testing it, no other connections
came close. The nearest was classic inbound, but it was still
20ms away. If it does ever need to be expanded to other types,
just remove the advertising check and let other creation events
check for the temp hcon and copy over its pending rx.

 include/net/bluetooth/hci.h      |  1 +
 include/net/bluetooth/hci_core.h |  1 +
 net/bluetooth/hci_conn.c         |  9 ++++++
 net/bluetooth/hci_event.c        | 49 +++++++++++++++++++++++++++++++-
 net/bluetooth/l2cap_core.c       | 20 +++++++++++--
 5 files changed, 76 insertions(+), 4 deletions(-)

diff --git a/include/net/bluetooth/hci.h b/include/net/bluetooth/hci.h
index 1641d879dbda..27757588c115 100644
--- a/include/net/bluetooth/hci.h
+++ b/include/net/bluetooth/hci.h
@@ -486,6 +486,7 @@ enum {
 #define HCI_AUTO_OFF_TIMEOUT	msecs_to_jiffies(2000)	/* 2 seconds */
 #define HCI_ACL_CONN_TIMEOUT	msecs_to_jiffies(20000)	/* 20 seconds */
 #define HCI_LE_CONN_TIMEOUT	msecs_to_jiffies(20000)	/* 20 seconds */
+#define HCI_EARLY_ACL_TIMEOUT	msecs_to_jiffies(4)
 #define HCI_ISO_TX_TIMEOUT	usecs_to_jiffies(0x7fffff) /* 8388607 usecs */
 
 /* HCI data types */
diff --git a/include/net/bluetooth/hci_core.h b/include/net/bluetooth/hci_core.h
index e07418a5adce..834bf0586ab4 100644
--- a/include/net/bluetooth/hci_core.h
+++ b/include/net/bluetooth/hci_core.h
@@ -1009,6 +1009,7 @@ enum {
 	HCI_CONN_BIG_SYNC,
 	HCI_CONN_BIG_SYNC_FAILED,
 	HCI_CONN_CREATE_PA_SYNC,
+	HCI_CONN_EARLY_ACL,
 	HCI_CONN_PA_SYNC,
 	HCI_CONN_PA_SYNC_FAILED,
 };
diff --git a/net/bluetooth/hci_conn.c b/net/bluetooth/hci_conn.c
index 19b7629b1cc1..b7d4a8db4eb4 100644
--- a/net/bluetooth/hci_conn.c
+++ b/net/bluetooth/hci_conn.c
@@ -638,6 +638,15 @@ static void hci_conn_timeout(struct work_struct *work)
 
 	BT_DBG("hcon %p state %s", conn, state_to_string(conn->state));
 
+	if (test_bit(HCI_CONN_EARLY_ACL, &conn->flags)) {
+		bt_dev_err(conn->hdev,
+			   "ACL packet for unknown connection handle %d",
+			   conn->handle);
+		conn->state = BT_CLOSED;
+		hci_abort_conn(conn, HCI_ERROR_UNKNOWN_CONN_ID);
+		return;
+	}
+
 	WARN_ON(refcnt < 0);
 
 	/* FIXME: It was observed that in pairing failed scenario, refcnt
diff --git a/net/bluetooth/hci_event.c b/net/bluetooth/hci_event.c
index 371ca8236bc5..e277df667ff1 100644
--- a/net/bluetooth/hci_event.c
+++ b/net/bluetooth/hci_event.c
@@ -5695,6 +5695,44 @@ static void hci_remote_oob_data_request_evt(struct hci_dev *hdev, void *edata,
 	hci_dev_unlock(hdev);
 }
 
+static struct hci_conn *hci_early_acl_lookup(struct hci_dev *hdev, u16 handle)
+{
+	struct hci_conn *conn;
+
+	conn = hci_conn_hash_lookup_handle(hdev, handle);
+	if (!conn || !test_bit(HCI_CONN_EARLY_ACL, &conn->flags))
+		return NULL;
+
+	return conn;
+}
+
+static void hci_early_acl_discard(struct hci_conn *conn)
+{
+	cancel_delayed_work(&conn->disc_work);
+	if (conn->state == BT_OPEN)
+		bt_dev_err(conn->hdev,
+			   "ACL packet for unknown connection handle %d",
+			   conn->handle);
+
+	clear_bit(HCI_CONN_EARLY_ACL, &conn->flags);
+	hci_disconn_cfm(conn, HCI_ERROR_LOCAL_HOST_TERM);
+	hci_conn_del(conn);
+}
+
+static struct hci_conn *hci_early_acl_adopt(struct hci_conn *conn, u8 role,
+					    bdaddr_t *bdaddr, u8 bdaddr_type)
+{
+	if (conn->state != BT_OPEN || role != HCI_ROLE_SLAVE)
+		return NULL;
+
+	cancel_delayed_work(&conn->disc_work);
+	clear_bit(HCI_CONN_EARLY_ACL, &conn->flags);
+	bacpy(&conn->dst, bdaddr);
+	conn->dst_type = bdaddr_type;
+
+	return conn;
+}
+
 static void le_conn_update_addr(struct hci_conn *conn, bdaddr_t *bdaddr,
 				u8 bdaddr_type, bdaddr_t *local_rpa)
 {
@@ -5755,6 +5793,7 @@ static void le_conn_complete_evt(struct hci_dev *hdev, u8 status,
 				 u16 supervision_timeout)
 {
 	struct hci_conn_params *params;
+	struct hci_conn *early = NULL;
 	struct hci_conn *conn;
 	struct smp_irk *irk;
 	u8 addr_type;
@@ -5762,6 +5801,8 @@ static void le_conn_complete_evt(struct hci_dev *hdev, u8 status,
 
 	hci_dev_lock(hdev);
 	hci_store_wake_reason(hdev, bdaddr, bdaddr_type);
+	if (!status)
+		early = hci_early_acl_lookup(hdev, handle);
 
 	/* All controllers implicitly stop advertising in the event of a
 	 * connection, so ensure that the state bit is cleared.
@@ -5778,6 +5819,9 @@ static void le_conn_complete_evt(struct hci_dev *hdev, u8 status,
 	 *    it even attempts to connect (e.g. hcon->state == BT_OPEN).
 	 */
 	conn = hci_conn_hash_lookup_role(hdev, LE_LINK, role, bdaddr);
+	if (early && (!conn || conn == early))
+		conn = hci_early_acl_adopt(early, role, bdaddr, bdaddr_type);
+
 	if (!conn ||
 	    (conn->role == HCI_ROLE_MASTER && conn->state != BT_CONNECT)) {
 		/* In case of error status and there is no connection pending
@@ -5823,11 +5867,14 @@ static void le_conn_complete_evt(struct hci_dev *hdev, u8 status,
 	 * As the connection handle is set here for the first time, it indicates
 	 * whether the connection is already set up.
 	 */
-	if (!HCI_CONN_HANDLE_UNSET(conn->handle)) {
+	if (conn != early && !HCI_CONN_HANDLE_UNSET(conn->handle)) {
 		bt_dev_err(hdev, "Ignoring HCI_Connection_Complete for existing connection");
 		goto unlock;
 	}
 
+	if (early && conn != early)
+		hci_early_acl_discard(early);
+
 	le_conn_update_addr(conn, bdaddr, bdaddr_type, local_rpa);
 
 	/* Lookup the identity address from the stored connection
diff --git a/net/bluetooth/l2cap_core.c b/net/bluetooth/l2cap_core.c
index ee459dd411f5..600cc0bf31b6 100644
--- a/net/bluetooth/l2cap_core.c
+++ b/net/bluetooth/l2cap_core.c
@@ -7816,9 +7816,23 @@ int l2cap_recv_acldata(struct hci_dev *hdev, u16 handle,
 
 	hcon = hci_conn_hash_lookup_handle(hdev, handle);
 	if (!hcon) {
-		hci_dev_unlock(hdev);
-		kfree_skb(skb);
-		return -ENOENT;
+		if (!hci_dev_test_flag(hdev, HCI_LE_ADV)) {
+			hci_dev_unlock(hdev);
+			kfree_skb(skb);
+			return -ENOENT;
+		}
+
+		hcon = hci_conn_add(hdev, LE_LINK, BDADDR_ANY, 0,
+				    HCI_ROLE_SLAVE, handle);
+		if (IS_ERR(hcon)) {
+			hci_dev_unlock(hdev);
+			kfree_skb(skb);
+			return PTR_ERR(hcon);
+		}
+
+		set_bit(HCI_CONN_EARLY_ACL, &hcon->flags);
+		queue_delayed_work(hdev->workqueue, &hcon->disc_work,
+				   HCI_EARLY_ACL_TIMEOUT);
 	}
 
 	lockdep_assert_held(&hcon->hdev->lock);
-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.