Luiz Augusto von Dentz
bef3334183
Bluetooth: hci_core: Fix sleeping function called from invalid context
[ Upstream commit 4d94f05558271654670d18c26c912da0c1c15549 ]
This reworks hci_cb_list to not use mutex hci_cb_list_lock to avoid bugs
like the bellow:
BUG: sleeping function called from invalid context at kernel/locking/mutex.c:585
in_atomic(): 0, irqs_disabled(): 0, non_block: 0, pid: 5070, name: kworker/u9:2
preempt_count: 0, expected: 0
RCU nest depth: 1, expected: 0
4 locks held by kworker/u9:2/5070:
#0: ffff888015be3948 ((wq_completion)hci0#2){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3229 [inline]
#0: ffff888015be3948 ((wq_completion)hci0#2){+.+.}-{0:0}, at: process_scheduled_works+0x8e0/0x1770 kernel/workqueue.c:3335
#1: ffffc90003b6fd00 ((work_completion)(&hdev->rx_work)){+.+.}-{0:0}, at: process_one_work kernel/workqueue.c:3230 [inline]
#1: ffffc90003b6fd00 ((work_completion)(&hdev->rx_work)){+.+.}-{0:0}, at: process_scheduled_works+0x91b/0x1770 kernel/workqueue.c:3335
#2: ffff8880665d0078 (&hdev->lock){+.+.}-{3:3}, at: hci_le_create_big_complete_evt+0xcf/0xae0 net/bluetooth/hci_event.c:6914
#3: ffffffff8e132020 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire include/linux/rcupdate.h:298 [inline]
#3: ffffffff8e132020 (rcu_read_lock){....}-{1:2}, at: rcu_read_lock include/linux/rcupdate.h:750 [inline]
#3: ffffffff8e132020 (rcu_read_lock){....}-{1:2}, at: hci_le_create_big_complete_evt+0xdb/0xae0 net/bluetooth/hci_event.c:6915
CPU: 0 PID: 5070 Comm: kworker/u9:2 Not tainted 6.8.0-syzkaller-08073-g480e035fc4c7 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024
Workqueue: hci0 hci_rx_work
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114
__might_resched+0x5d4/0x780 kernel/sched/core.c:10187
__mutex_lock_common kernel/locking/mutex.c:585 [inline]
__mutex_lock+0xc1/0xd70 kernel/locking/mutex.c:752
hci_connect_cfm include/net/bluetooth/hci_core.h:2004 [inline]
hci_le_create_big_complete_evt+0x3d9/0xae0 net/bluetooth/hci_event.c:6939
hci_event_func net/bluetooth/hci_event.c:7514 [inline]
hci_event_packet+0xa53/0x1540 net/bluetooth/hci_event.c:7569
hci_rx_work+0x3e8/0xca0 net/bluetooth/hci_core.c:4171
process_one_work kernel/workqueue.c:3254 [inline]
process_scheduled_works+0xa00/0x1770 kernel/workqueue.c:3335
worker_thread+0x86d/0xd70 kernel/workqueue.c:3416
kthread+0x2f0/0x390 kernel/kthread.c:388
ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:243
</TASK>
Reported-by: syzbot+2fb0835e0c9cefc34614@syzkaller.appspotmail.com
Tested-by: syzbot+2fb0835e0c9cefc34614@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=2fb0835e0c9cefc34614
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-01-09 13:32:05 +01:00
..
2024-12-09 10:32:57 +01:00
2024-12-19 18:11:27 +01:00
2025-01-09 13:32:05 +01:00
2024-11-08 16:28:19 +01:00
2024-10-17 15:24:29 +02:00
2024-12-14 20:00:04 +01:00
2025-01-02 10:32:00 +01:00
2025-01-09 13:32:02 +01:00
2024-12-14 19:59:36 +01:00
2024-10-10 11:58:07 +02:00
2024-12-14 19:59:39 +01:00
2024-12-14 19:59:34 +01:00
2024-12-14 20:00:04 +01:00
2025-01-09 13:32:00 +01:00
2025-01-09 13:32:03 +01:00
2024-12-09 10:32:33 +01:00
2024-08-29 17:33:46 +02:00
2024-12-14 19:59:35 +01:00
2025-01-09 13:32:01 +01:00
2025-01-09 13:32:03 +01:00
2024-10-10 11:57:59 +02:00
2025-01-09 13:31:54 +01:00
2024-12-14 19:59:35 +01:00
2024-12-09 10:31:42 +01:00
2024-12-27 13:58:49 +01:00
2024-12-09 10:32:09 +01:00
2025-01-09 13:32:00 +01:00
2024-08-19 06:04:28 +02:00
2024-08-29 17:33:50 +02:00
2025-01-09 13:32:02 +01:00
2024-10-17 15:24:30 +02:00
2024-10-04 16:29:41 +02:00
2024-08-19 06:04:27 +02:00
2024-12-09 10:32:11 +01:00
2024-12-09 10:32:35 +01:00
2024-12-27 13:58:41 +01:00
2024-12-14 19:59:35 +01:00
2024-12-27 13:58:47 +01:00
2024-12-09 10:33:00 +01:00
2024-12-19 18:11:27 +01:00
2024-12-19 18:11:21 +01:00
2024-12-14 19:59:47 +01:00
2024-12-19 18:11:27 +01:00
2024-12-14 19:59:57 +01:00
2024-12-14 19:59:35 +01:00
2024-10-17 15:24:35 +02:00
2024-08-11 12:47:13 +02:00