Re: [PATCH] Bluetooth: hci_vhci: Pin module for debugfs file operations

From: patchwork-bot+bluetooth

Date: Fri Oct 09 2026 - 10:22:34 EST


Hello:

This patch was applied to bluetooth/bluetooth-next.git (master)
by Luiz Augusto von Dentz <luiz.von.dentz@xxxxxxxxx>:

On Thu, 8 Oct 2026 11:54:13 +0700 you wrote:
> An open debugfs file retains its file_operations pointer in the
> debugfs proxy state. However, force_suspend_fops, force_wakeup_fops,
> aosp_capable_fops, and force_devcoredump_fops have no .owner set to
> THIS_MODULE. As a result, full_proxy_open_regular() calls fops_get()
> which succeeds without taking a reference to the hci_vhci module.
>
> When userspace opens any of these debugfs files and later closes
> the /dev/vhci file descriptor (triggering vhci_release() and
> debugfs file removal), the open debugfs file descriptor remains valid
> in userspace. Because the module refcount was not incremented,
> the hci_vhci module can be unloaded via delete_module (rmmod hci_vhci).
>
> [...]

Here is the summary with links:
- Bluetooth: hci_vhci: Pin module for debugfs file operations
https://git.kernel.org/bluetooth/bluetooth-next/c/da8aab8ed08d

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html