Re: [PATCH] Bluetooth: ISO: Serialize concurrent connect calls
From: Chengfeng Ye
Date: Mon Oct 05 2026 - 03:57:24 EST
On Mon, Oct 5, 2026 at 1:16 AM Pauli Virtanen <pav@xxxxxx> wrote:
>
> Hi,
>
> ma, 2026-10-05 kello 00:24 +0800, Chengfeng Ye kirjoitti:
> > iso_sock_connect() checks the socket state before taking the socket lock
> > and drops the lock again before setting up a connection. Two callers can
> > both pass the admission check while the socket is open or bound.
> >
> > Caller A can copy its destination for route selection, then caller B can
> > replace the socket destination before A binds or connects the CIS. A
> > then uses B's destination with the route selected for its own request.
> > B can also proceed after A attaches a connection and sets BT_CONNECT.
> > For deferred BIS setup, B can bind a second BIS and overwrite
> > iso_pi(sk)->conn, leaving the first connection's reference and conn->sk
> > back-pointer stranded. Concurrent CIS connects can likewise replace the
>
> Memory safety probably should be enforced somewhat down the calls,
> likely __iso_chan_add() should reject adding a different iso_conn to sk
> if it already has one, since that looks like it leaks the
> iso_conn_hold() reference and the back pointer association.
Hi Pauli,
Thanks for the review. I have just sent v2 with the check in __iso_chan_add().
I also adjusted the outgoing BIS and CIS callers to handle conflicting
attachments early. The BIS check prevents modifying a reusable
connection before attachment is rejected. The CIS check releases the
HCI hold acquired by the current attempt on rejection, while
preserving same-connection reuse for deferred setup.
Best regards,
Chengfeng