mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] Bluetooth: hci_debugfs: Pin the module for open dut_mode files
@ 2026-10-08  4:01 Cen Zhang
  0 siblings, 0 replies; only message in thread
From: Cen Zhang @ 2026-10-08  4:01 UTC (permalink / raw)
  To: marcel, luiz.dentz
  Cc: linux-bluetooth, linux-kernel, baijiaju1990, jjzuming, zzzccc427

An open dut_mode file retains dut_mode_fops in the debugfs proxy state.
The table must remain allocated until the final close has finished
accessing it. However, dut_mode_fops has no owner, so fops_get()
succeeds without taking a Bluetooth module reference.

With CONFIG_BT=m and Bluetooth debugfs enabled, a descriptor can remain
open across controller removal and module unload if all other module
references have been dropped. After hci_debugfs_create_basic() publishes
the file, the following order is possible:

    File holder                     Controller/module teardown
    -----------                     --------------------------
    open dut_mode
      full_proxy_open_regular()
      fops_get(): owner == NULL
      debugfs_file_put()
    keep descriptor open            hci_unregister_dev()
                                    hci_release_dev()
                                      debugfs_remove_recursive()
                                    delete_module()
                                      bt_exit()
                                      free_module()
    close descriptor after unload
      full_proxy_release()
        read real_fops->release

Debugfs removal drains active callbacks, but an idle open descriptor is
not an active user. Its dentry retains the saved table pointer until
close. full_proxy_release() then reads the release field, even though
it is NULL, and fops_put() reads the owner field from freed module
storage. The close can fault in full_proxy_release(), as shown below.

Set the owner of dut_mode_fops to THIS_MODULE, matching the tables
created by DEFINE_SHOW_ATTRIBUTE in the same file. The existing debugfs
fops_get()/fops_put() pair then keeps Bluetooth loaded until close has
finished using the table, preventing normal unload with the file open.

Oops report as below:
    BUG: unable to handle page fault for address: fffffbfff8056f03
    #PF: supervisor read access in kernel mode
    #PF: error_code(0x0000) - not-present page
    PGD 1a7ff6067 P4D 1a7ff6067 PUD 1a7ff2067 PMD 100ad6067 PTE 0
    Oops: Oops: 0000 [#1] SMP KASAN NOPTI
    Call Trace:
     <TASK>
     __fput+0x39f/0xa60
     fput_close_sync+0xff/0x200
     ? __pfx_fput_close_sync+0x10/0x10
     ? dnotify_flush+0x22/0x4b0
     __x64_sys_close+0x8c/0xf0
     do_syscall_64+0x115/0x6a0
     entry_SYSCALL_64_after_hwframe+0x77/0x7f
Fixes: 4b4148e9acc1 ("Bluetooth: Add support for setting DUT mode")
Assisted-by: LLM
Signed-off-by: Cen Zhang <zzzccc427@gmail.com>

Assisted-by: LLM
---

diff --git a/net/bluetooth/hci_debugfs.c b/net/bluetooth/hci_debugfs.c
index 2559fb6324d63d5fc84d530d2a19f2602ac06d3d..f17b5c960522cb22140322e4781775e4e2f6b711 100644
--- a/net/bluetooth/hci_debugfs.c
+++ b/net/bluetooth/hci_debugfs.c
@@ -1315,6 +1315,7 @@ static ssize_t dut_mode_write(struct file *file, const char __user *user_buf,
 }
 
 static const struct file_operations dut_mode_fops = {
+	.owner		= THIS_MODULE,
 	.open		= simple_open,
 	.read		= dut_mode_read,
 	.write		= dut_mode_write,

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-10-08  4:01 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08  4:01 [PATCH] Bluetooth: hci_debugfs: Pin the module for open dut_mode files Cen Zhang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®