[PATCH v3 0/4] Bluetooth: fix hci_conn lookup RCU usage + holding refcounts

From: Pauli Virtanen

Date: Fri Jul 10 2026 - 04:25:53 EST


Resending parts of
https://lore.kernel.org/linux-bluetooth/cover.1762100290.git.pav@xxxxxx/
plus additional hci_conn_params usage fix.

v3
- Copy params->flags in hci_le_pa_create_sync() to reduce number of
unlocks in branches.

- Don't convert hci_conn_params to RCU here, as it appears to require
sorting out eg. data race vs MGMT_OP_LOAD_CONN_PARAM in field access,
and is more complex change than memory safety fix.

To my understanding it would be performance optimization and it's
unclear that it is significant: these are on Create LE Connection and
Create PA Sync code paths which take hdev->lock in several places eg.
in completion callback in any case.

v2:
- Take hdev->lock instead of RCU in hci_update_scan_sync() to
guard also the hdev->accept_list access.

- In unpair_device/disconnect_sync, take hdev->lock instead of RCU.
This avoids potential access to uninitialized struct device.

In __hci_conn_add() it looks like we should move
hci_conn_hash_add(hdev, conn); after hci_conn_init_sysfs(conn);
so that the pattern

conn = hci_conn_lookup(...)
if (conn)
hci_conn_get(conn)

can be done with RCU without needing hdev->lock.
But better done in separate patch series.

Pauli Virtanen (4):
Bluetooth: hci_sync: extend conn_hash lookup critical sections
Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups

net/bluetooth/hci_sync.c | 66 +++++++++++++++++++++++++++++++++++-----
net/bluetooth/mgmt.c | 42 ++++++++++++++++++++++---
2 files changed, 97 insertions(+), 11 deletions(-)

--
2.55.0