[PATCH 00/16] Bluetooth: L2CAP: fix and annotate l2cap_conn::chan_l locking
From: Pauli Virtanen
Date: Sat Aug 29 2026 - 10:21:09 EST
The intent in current code is that:
- l2cap_conn::chan_l read/write is guarded by l2cap_conn::lock
- l2cap_chan_del called with held l2cap_chan::lock (l2cap_sock.c uses
this)
This is currently not done right in several code paths.
This series fixes the locking vs. the above, and adds context analysis
annotations to make more sure it is systematic.
The last three patches fix some miscellaneous locking related issues.
Mostly straightforward, but two more complicated parts:
- race condition in acquiring l2cap_conn::lock & l2cap_chan::lock
- __l2cap_ecred_conn_rsp_defer(chan) may l2cap_chan_del other l2cap_chan
To deal with these, this series adds
- l2cap_chan_lock_conn / l2cap_chan_unlock_conn
- l2cap_chan_close_unlocked
- l2cap_chan_try_sibling_lock-
- new nesting rule for l2cap_conn::lock
The context analysis annotations for l2cap_chan_close() declare via
context_unsafe() that __must_hold(&chan->conn->lock) even if chan->conn
is NULL. This is OK for the current static locking analysis, doesn't
affect code generation. It could be cleaner by adding separate
l2cap_chan_del() variant assuming chan->conn == NULL, but playing loose
here avoids such duplication.
LLM tools were used for patch review, catching some some corner cases
before sending this series out. No code / commit messages are generated
by them.
Finding the bugs here is mostly based on adding the context analysis
annotations which make it obvious where appropriate locks are missing.
Assisted-by: gpt-5.6 deepseek-4-flash
Pauli Virtanen (16):
Bluetooth: L2CAP: take chan->lock for l2cap_chan_add/ready/del
Bluetooth: L2CAP: add l2cap_chan_close_unlocked() and locking helpers
Bluetooth: L2CAP: fix race condition in l2cap_sock_shutdown()
Bluetooth: 6lowpan: use l2cap_chan_close_unlocked()
Bluetooth: L2CAP: remove unused l2cap_chan_close()
Bluetooth: 6lowpan: avoid concurrent peer_del() in
bt_6lowpan_disconnect
Bluetooth: L2CAP: hold conn->lock for __l2cap_ecred_conn_rsp_defer
Bluetooth: L2CAP: hold l2cap_conn::lock in l2cap_connect_cfm()
Bluetooth: L2CAP: add annotations for l2cap_chan list locking
Bluetooth: L2CAP: take lock for l2cap_chan_del in
l2cap_ecred_rsp_defer
Bluetooth: L2CAP: hold chan in l2cap_ecred_conn_rsp()
Bluetooth: L2CAP: annotate locking for l2cap_chan_del()
Bluetooth: L2CAP: annotate locking for l2cap_ops callbacks
Bluetooth: L2CAP: make concurrent l2cap_set_timer() refcounting safe
Bluetooth: L2CAP: remove conditional locking from l2cap_connect()
Bluetooth: L2CAP: refuse __l2cap_chan_add if chan already has conn
include/net/bluetooth/l2cap.h | 100 ++++++++-----
net/bluetooth/6lowpan.c | 44 +++---
net/bluetooth/l2cap_core.c | 257 +++++++++++++++++++++++++++++++---
net/bluetooth/l2cap_sock.c | 95 +++++++------
4 files changed, 384 insertions(+), 112 deletions(-)
--
2.55.0