* [PATCH] Bluetooth: hci_debugfs: Pin the module for open dut_mode files
@ 2026-10-08 4:01 Cen Zhang
0 siblings, 0 replies; only message in thread
From: Cen Zhang @ 2026-10-08 4:01 UTC (permalink / raw)
To: marcel, luiz.dentz
Cc: linux-bluetooth, linux-kernel, baijiaju1990, jjzuming, zzzccc427
An open dut_mode file retains dut_mode_fops in the debugfs proxy state.
The table must remain allocated until the final close has finished
accessing it. However, dut_mode_fops has no owner, so fops_get()
succeeds without taking a Bluetooth module reference.
With CONFIG_BT=m and Bluetooth debugfs enabled, a descriptor can remain
open across controller removal and module unload if all other module
references have been dropped. After hci_debugfs_create_basic() publishes
the file, the following order is possible:
File holder Controller/module teardown
----------- --------------------------
open dut_mode
full_proxy_open_regular()
fops_get(): owner == NULL
debugfs_file_put()
keep descriptor open hci_unregister_dev()
hci_release_dev()
debugfs_remove_recursive()
delete_module()
bt_exit()
free_module()
close descriptor after unload
full_proxy_release()
read real_fops->release
Debugfs removal drains active callbacks, but an idle open descriptor is
not an active user. Its dentry retains the saved table pointer until
close. full_proxy_release() then reads the release field, even though
it is NULL, and fops_put() reads the owner field from freed module
storage. The close can fault in full_proxy_release(), as shown below.
Set the owner of dut_mode_fops to THIS_MODULE, matching the tables
created by DEFINE_SHOW_ATTRIBUTE in the same file. The existing debugfs
fops_get()/fops_put() pair then keeps Bluetooth loaded until close has
finished using the table, preventing normal unload with the file open.
Oops report as below:
BUG: unable to handle page fault for address: fffffbfff8056f03
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 1a7ff6067 P4D 1a7ff6067 PUD 1a7ff2067 PMD 100ad6067 PTE 0
Oops: Oops: 0000 [#1] SMP KASAN NOPTI
Call Trace:
<TASK>
__fput+0x39f/0xa60
fput_close_sync+0xff/0x200
? __pfx_fput_close_sync+0x10/0x10
? dnotify_flush+0x22/0x4b0
__x64_sys_close+0x8c/0xf0
do_syscall_64+0x115/0x6a0
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Fixes: 4b4148e9acc1 ("Bluetooth: Add support for setting DUT mode")
Assisted-by: LLM
Signed-off-by: Cen Zhang <zzzccc427@gmail.com>
Assisted-by: LLM
---
diff --git a/net/bluetooth/hci_debugfs.c b/net/bluetooth/hci_debugfs.c
index 2559fb6324d63d5fc84d530d2a19f2602ac06d3d..f17b5c960522cb22140322e4781775e4e2f6b711 100644
--- a/net/bluetooth/hci_debugfs.c
+++ b/net/bluetooth/hci_debugfs.c
@@ -1315,6 +1315,7 @@ static ssize_t dut_mode_write(struct file *file, const char __user *user_buf,
}
static const struct file_operations dut_mode_fops = {
+ .owner = THIS_MODULE,
.open = simple_open,
.read = dut_mode_read,
.write = dut_mode_write,
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-10-08 4:01 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08 4:01 [PATCH] Bluetooth: hci_debugfs: Pin the module for open dut_mode files Cen Zhang
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®