From: Hitalo Souza <enghitalo@gmail.com>
To: linux-bluetooth@vger.kernel.org
Cc: marcel@holtmann.org, luiz.dentz@gmail.com,
linux-kernel@vger.kernel.org, Hitalo Souza <enghitalo@gmail.com>
Subject: [PATCH 1/3] Bluetooth: hci_event: Don't fail a connected SCO link on setup errors
Date: Wed, 7 Oct 2026 11:43:51 -0400 [thread overview]
Message-ID: <20261007154353.148223-2-enghitalo@gmail.com> (raw)
In-Reply-To: <20261007154353.148223-1-enghitalo@gmail.com>
When Add SCO Connection, Setup Synchronous Connection or Enhanced Setup
Synchronous Connection fails in Command Status, the error handlers fail
the first link on the ACL, whatever its state. If that link is already
up, it is deleted while the controller keeps it: its socket gets an
error and, as no Disconnect is sent, later setups to the device are
rejected until the ACL drops.
A link that is up can be the first one on the ACL since commit
a13f316e90fd ("Bluetooth: hci_conn: Consolidate code for aborting
connections"). Aborting a pending SCO/eSCO setup, e.g. because its
socket was closed, now deletes its hci_conn, so a socket that connects
right after gets a new one and sends its own setup. The abandoned setup
can still complete, and it is then matched to the new connection by
address. When the controller rejects the new setup because a link
already exists, the handler fails the connection that just came up.
This was reported with an HFP headset, where the rejection was Invalid
HCI Command Parameters and the microphone stayed silent.
Only fail a link that is still waiting for its setup to complete.
Link: https://github.com/bluez/bluez/issues/2562
Fixes: a13f316e90fd ("Bluetooth: hci_conn: Consolidate code for aborting connections")
Assisted-by: LLM
Signed-off-by: Hitalo Souza <enghitalo@gmail.com>
---
net/bluetooth/hci_event.c | 24 ++++++++++++++++++------
1 file changed, 18 insertions(+), 6 deletions(-)
diff --git a/net/bluetooth/hci_event.c b/net/bluetooth/hci_event.c
index c055d16cf..cbe53e19e 100644
--- a/net/bluetooth/hci_event.c
+++ b/net/bluetooth/hci_event.c
@@ -2400,13 +2400,19 @@ static void hci_cs_add_sco(struct hci_dev *hdev, __u8 status)
acl = hci_conn_hash_lookup_handle(hdev, handle);
if (acl) {
- link = list_first_entry_or_null(&acl->link_list,
- struct hci_link, list);
- if (link && link->conn) {
+ /* Only a link still waiting for its setup can be the one the
+ * failed command was for: one that is already up must be kept.
+ */
+ list_for_each_entry(link, &acl->link_list, list) {
+ if (link->conn->state != BT_CONNECT ||
+ !HCI_CONN_HANDLE_UNSET(link->conn->handle))
+ continue;
+
link->conn->state = BT_CLOSED;
hci_connect_cfm(link->conn, status);
hci_conn_del(link->conn);
+ break;
}
}
@@ -2683,13 +2689,19 @@ static void hci_setup_sync_conn_status(struct hci_dev *hdev, __u16 handle,
acl = hci_conn_hash_lookup_handle(hdev, handle);
if (acl) {
- link = list_first_entry_or_null(&acl->link_list,
- struct hci_link, list);
- if (link && link->conn) {
+ /* Only a link still waiting for its setup can be the one the
+ * failed command was for: one that is already up must be kept.
+ */
+ list_for_each_entry(link, &acl->link_list, list) {
+ if (link->conn->state != BT_CONNECT ||
+ !HCI_CONN_HANDLE_UNSET(link->conn->handle))
+ continue;
+
link->conn->state = BT_CLOSED;
hci_connect_cfm(link->conn, status);
hci_conn_del(link->conn);
+ break;
}
}
--
2.55.0
next prev parent reply other threads:[~2026-10-07 15:44 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 15:43 [PATCH 0/3] Bluetooth: Fix SCO setup failures after an abandoned setup Hitalo Souza
2026-10-07 15:43 ` Hitalo Souza [this message]
2026-10-07 15:43 ` [PATCH 2/3] Bluetooth: hci_conn: Don't set up a SCO link that is already up Hitalo Souza
2026-10-07 15:43 ` [PATCH 3/3] Bluetooth: Don't leave abandoned SCO links up in the controller Hitalo Souza
2026-10-07 18:15 ` Luiz Augusto von Dentz
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007154353.148223-2-enghitalo@gmail.com \
--to=enghitalo@gmail.com \
--cc=linux-bluetooth@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luiz.dentz@gmail.com \
--cc=marcel@holtmann.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®