[PATCH v2 1/6] Bluetooth: hci_event: Don't fail a connected SCO link on setup errors
From: Hitalo Souza
Date: Thu Oct 08 2026 - 11:13:52 EST
When Add SCO Connection, Setup Synchronous Connection or Enhanced Setup
Synchronous Connection fails in Command Status, the error handlers fail
the first link on the ACL, whatever its state. If that link is already
up, it is deleted while the controller keeps it: its socket gets an
error and, as no Disconnect is sent, later setups to the device are
rejected until the ACL drops.
A link that is up can be the first one on the ACL since commit
a13f316e90fd ("Bluetooth: hci_conn: Consolidate code for aborting
connections"). Aborting a pending SCO/eSCO setup, e.g. because its
socket was closed, now deletes its hci_conn, so a socket that connects
right after gets a new one and sends its own setup. The abandoned setup
can still complete, and it is then matched to the new connection by
address. When the controller rejects the new setup because a link
already exists, the handler fails the connection that just came up.
This was reported with an HFP headset, where the rejection was Invalid
HCI Command Parameters and the microphone stayed silent.
Only fail a link that is still waiting for its setup to complete.
Link: https://github.com/bluez/bluez/issues/2562
Fixes: a13f316e90fd ("Bluetooth: hci_conn: Consolidate code for aborting connections")
Assisted-by: LLM
Signed-off-by: Hitalo Souza <enghitalo@xxxxxxxxx>
---
net/bluetooth/hci_event.c | 24 ++++++++++++++++++------
1 file changed, 18 insertions(+), 6 deletions(-)
diff --git a/net/bluetooth/hci_event.c b/net/bluetooth/hci_event.c
index c055d16cf..cbe53e19e 100644
--- a/net/bluetooth/hci_event.c
+++ b/net/bluetooth/hci_event.c
@@ -2400,13 +2400,19 @@ static void hci_cs_add_sco(struct hci_dev *hdev, __u8 status)
acl = hci_conn_hash_lookup_handle(hdev, handle);
if (acl) {
- link = list_first_entry_or_null(&acl->link_list,
- struct hci_link, list);
- if (link && link->conn) {
+ /* Only a link still waiting for its setup can be the one the
+ * failed command was for: one that is already up must be kept.
+ */
+ list_for_each_entry(link, &acl->link_list, list) {
+ if (link->conn->state != BT_CONNECT ||
+ !HCI_CONN_HANDLE_UNSET(link->conn->handle))
+ continue;
+
link->conn->state = BT_CLOSED;
hci_connect_cfm(link->conn, status);
hci_conn_del(link->conn);
+ break;
}
}
@@ -2683,13 +2689,19 @@ static void hci_setup_sync_conn_status(struct hci_dev *hdev, __u16 handle,
acl = hci_conn_hash_lookup_handle(hdev, handle);
if (acl) {
- link = list_first_entry_or_null(&acl->link_list,
- struct hci_link, list);
- if (link && link->conn) {
+ /* Only a link still waiting for its setup can be the one the
+ * failed command was for: one that is already up must be kept.
+ */
+ list_for_each_entry(link, &acl->link_list, list) {
+ if (link->conn->state != BT_CONNECT ||
+ !HCI_CONN_HANDLE_UNSET(link->conn->handle))
+ continue;
+
link->conn->state = BT_CLOSED;
hci_connect_cfm(link->conn, status);
hci_conn_del(link->conn);
+ break;
}
}
--
2.55.0