[PATCH v3 5/6] Bluetooth: hci_event: Disconnect an ACL link that completes after its abort
From: Hitalo Souza
Date: Thu Oct 08 2026 - 18:27:19 EST
Since commit a13f316e90fd ("Bluetooth: hci_conn: Consolidate code for
aborting connections"), aborting an ACL connection in BT_CONNECT sends
Create Connection Cancel and deletes the connection. For an incoming
connection that was accepted, e.g. one that MGMT_OP_DISCONNECT aborts
before it completes, the cancel fails at once as the device was never
paged, and the Connection Complete that follows finds no connection and
is ignored. The link then stays up in the controller with nothing to
disconnect it. The same happens with controllers older than 1.2, where
no cancel is sent at all.
Disconnect an ACL link that completes with no connection to take it,
unless an accept list entry makes it an auto-connection, which is
handled as before.
Fixes: a13f316e90fd ("Bluetooth: hci_conn: Consolidate code for aborting connections")
Assisted-by: LLM
Signed-off-by: Hitalo Souza <enghitalo@xxxxxxxxx>
---
net/bluetooth/hci_event.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/net/bluetooth/hci_event.c b/net/bluetooth/hci_event.c
index c825a99db..14270711c 100644
--- a/net/bluetooth/hci_event.c
+++ b/net/bluetooth/hci_event.c
@@ -3301,8 +3301,15 @@ static void hci_conn_complete_evt(struct hci_dev *hdev, void *data,
goto unlock;
}
} else {
- if (ev->link_type != SCO_LINK)
+ if (ev->link_type != SCO_LINK) {
+ /* No connection takes this link, e.g. an
+ * incoming one aborted after it was accepted
+ */
+ hci_disconnect_unused(hdev,
+ __le16_to_cpu(ev->handle),
+ HCI_ERROR_REMOTE_USER_TERM);
goto unlock;
+ }
conn = hci_conn_hash_lookup_ba(hdev, ESCO_LINK,
&ev->bdaddr);
--
2.55.0