Re: [PATCH v3] Bluetooth: virtio: Fix HCI device unregister on probe failure

From: Luiz Augusto von Dentz

Date: Tue Jul 07 2026 - 11:25:37 EST


Hi Haoxiang,

On Tue, Jul 7, 2026 at 3:30 AM Haoxiang Li <haoxiang_li2024@xxxxxxx> wrote:
>
> virtbt_probe() registers the HCI device before opening the virtio
> Bluetooth device. If virtbt_open_vdev() fails, the error path frees
> the HCI device without unregistering it first.
>
> The probe error paths also leak the virtio_bluetooth structure after it
> has been allocated.
>
> Rework the probe error handling into an unwind ladder so each failure
> path releases the resources acquired earlier. Also close the virtio
> device before unregistering the HCI device in virtbt_remove(), matching
> the cleanup order used by the probe failure path.
>
> Fixes: afd2daa26c7a ("Bluetooth: Add support for virtio transport driver")
> Fixes: dc65b4b0f90a ("Bluetooth: virtio_bt: fix device removal")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Haoxiang Li <haoxiang_li2024@xxxxxxx>
> ---
> Changes in v2:
> - Rework virtbt_probe() error paths into an unwind ladder.
> - Free vbt on probe failures.
> - Reset the virtio device and unregister the HCI device before freeing it
> when virtbt_open_vdev() fails.
> - Close the virtio device before unregistering the HCI device in remove().
>
> Thanks Dan for the suggestions. The blog is very helpful.
> Changes in v3:
> - Remove virtio_reset_device() from the virtbt_open_vdev() failure path.
> ---
> drivers/bluetooth/virtio_bt.c | 22 +++++++++++++---------
> 1 file changed, 13 insertions(+), 9 deletions(-)
>
> diff --git a/drivers/bluetooth/virtio_bt.c b/drivers/bluetooth/virtio_bt.c
> index 140ab55c9fc5..c063c2391c5c 100644
> --- a/drivers/bluetooth/virtio_bt.c
> +++ b/drivers/bluetooth/virtio_bt.c
> @@ -311,12 +311,12 @@ static int virtbt_probe(struct virtio_device *vdev)
>
> err = virtio_find_vqs(vdev, VIRTBT_NUM_VQS, vbt->vqs, vqs_info, NULL);
> if (err)
> - return err;
> + goto err_free_vbt;
>
> hdev = hci_alloc_dev();
> if (!hdev) {
> err = -ENOMEM;
> - goto failed;
> + goto err_del_vqs;
> }
>
> vbt->hdev = hdev;
> @@ -383,23 +383,27 @@ static int virtbt_probe(struct virtio_device *vdev)
> if (virtio_has_feature(vdev, VIRTIO_BT_F_AOSP_EXT))
> hci_set_aosp_capable(hdev);
>
> - if (hci_register_dev(hdev) < 0) {
> - hci_free_dev(hdev);
> + err = hci_register_dev(hdev);
> + if (err < 0) {
> err = -EBUSY;
> - goto failed;
> + goto err_free_hdev;
> }
>
> virtio_device_ready(vdev);
> err = virtbt_open_vdev(vbt);
> if (err)
> - goto open_failed;
> + goto err_unregister_hdev;
>
> return 0;
>
> -open_failed:
> +err_unregister_hdev:
> + hci_unregister_dev(hdev);
> +err_free_hdev:
> hci_free_dev(hdev);
> -failed:
> +err_del_vqs:
> vdev->config->del_vqs(vdev);
> +err_free_vbt:
> + kfree(vbt);

Sashiko flagged a new problem regarding the code above:

https://sashiko.dev/#/patchset/20260707072955.3093138-1-haoxiang_li2024%40163.com

> return err;
> }
>
> @@ -408,10 +412,10 @@ static void virtbt_remove(struct virtio_device *vdev)
> struct virtio_bluetooth *vbt = vdev->priv;
> struct hci_dev *hdev = vbt->hdev;
>
> - hci_unregister_dev(hdev);
> virtio_reset_device(vdev);
> virtbt_close_vdev(vbt);
>
> + hci_unregister_dev(hdev);
> hci_free_dev(hdev);
> vbt->hdev = NULL;
>
> --
> 2.25.1
>


--
Luiz Augusto von Dentz