Re: [PATCH] Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev
From: Dmitry Baryshkov
Date: Mon Jul 20 2026 - 11:16:02 EST
On Mon, Jul 13, 2026 at 03:25:43PM +0800, raoxu wrote:
> From: Xu Rao <raoxu@xxxxxxxxxxxxx>
>
> The command and ACL RPMsg endpoints store struct btqcomsmd as their
> callback private data. The receive callbacks dereference btq->hdev
> without taking an hci_dev reference.
>
> The current teardown order frees the hci_dev before destroying the RPMsg
> endpoints in both the hci_register_dev() error path and the driver remove
> path. If WCNSS delivers data in that window, the endpoint callback can
> run with an already freed hci_dev and pass it to the Bluetooth core.
>
> For qcom_smd endpoints, rpmsg_destroy_ept() closes the channel and clears
> the callback under the channel recv_lock. The receive path holds the same
> lock while invoking the callback, so destroying the endpoints first both
> prevents new callbacks and serializes with any callback already running.
>
> Destroy the command and ACL endpoints before hci_free_dev(). Keep
> hci_unregister_dev() first during remove so the HCI core stops issuing
> operations before the transport endpoints are shut down. In the full
> registration-error cleanup path, return directly after freeing the hci_dev
> to avoid falling through to the partial-construction labels and destroying
> the endpoints twice.
>
> Fixes: 5052de8deff5 ("soc: qcom: smd: Transition client drivers from smd to rpmsg")
> Fixes: 9a39a927be01 ("Bluetooth: btqcomsmd: Fix a resource leak in error handling paths in the probe function")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Xu Rao <raoxu@xxxxxxxxxxxxx>
> ---
> drivers/bluetooth/btqcomsmd.c | 6 +++++-
> 1 file changed, 5 insertions(+), 1 deletion(-)
>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@xxxxxxxxxxxxxxxx>
--
With best wishes
Dmitry