[PATCH] Bluetooth: mgmt: handle mesh send completion queue failure
From: Jiale Yao
Date: Sat Oct 03 2026 - 04:12:42 EST
mesh_send_done() relies on the queued command and its destroy callback
to clear HCI_MESH_SENDING, complete the current transmission, and start
the next one. If hci_cmd_sync_queue() fails, neither callback runs and
mesh transmission remains permanently marked busy.
Run the completion and continuation callbacks directly when the command
cannot be queued.
Fixes: b338d91703fa ("Bluetooth: Implement support for Mesh")
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
net/bluetooth/mgmt.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/net/bluetooth/mgmt.c b/net/bluetooth/mgmt.c
index ac4864e56ec7..690af594ddf4 100644
--- a/net/bluetooth/mgmt.c
+++ b/net/bluetooth/mgmt.c
@@ -1131,11 +1131,16 @@ static void mesh_send_done(struct work_struct *work)
{
struct hci_dev *hdev = container_of(work, struct hci_dev,
mesh_send_done.work);
+ int err;
if (!hci_dev_test_flag(hdev, HCI_MESH_SENDING))
return;
- hci_cmd_sync_queue(hdev, mesh_send_done_sync, NULL, mesh_next);
+ err = hci_cmd_sync_queue(hdev, mesh_send_done_sync, NULL, mesh_next);
+ if (err < 0) {
+ mesh_send_done_sync(hdev, NULL);
+ mesh_next(hdev, NULL, err);
+ }
}
static void mgmt_init_hdev(struct sock *sk, struct hci_dev *hdev)
--
2.34.1