]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
5.10-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 21 Jul 2026 15:03:05 +0000 (17:03 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 21 Jul 2026 15:03:05 +0000 (17:03 +0200)
added patches:
bluetooth-l2cap-fix-regressions-caused-by-reusing-ident.patch

queue-5.10/bluetooth-l2cap-fix-regressions-caused-by-reusing-ident.patch [new file with mode: 0644]
queue-5.10/series

diff --git a/queue-5.10/bluetooth-l2cap-fix-regressions-caused-by-reusing-ident.patch b/queue-5.10/bluetooth-l2cap-fix-regressions-caused-by-reusing-ident.patch
new file mode 100644 (file)
index 0000000..9b770a8
--- /dev/null
@@ -0,0 +1,81 @@
+From 761fb8ec8778f0caf2bba5a41e3cff1ea86974f3 Mon Sep 17 00:00:00 2001
+From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
+Date: Tue, 17 Mar 2026 11:54:01 -0400
+Subject: Bluetooth: L2CAP: Fix regressions caused by reusing ident
+
+From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
+
+commit 761fb8ec8778f0caf2bba5a41e3cff1ea86974f3 upstream.
+
+This attempt to fix regressions caused by reusing ident which apparently
+is not handled well on certain stacks causing the stack to not respond to
+requests, so instead of simple returning the first unallocated id this
+stores the last used tx_ident and then attempt to use the next until all
+available ids are exausted and then cycle starting over to 1.
+
+Link: https://bugzilla.kernel.org/show_bug.cgi?id=221120
+Link: https://bugzilla.kernel.org/show_bug.cgi?id=221177
+Fixes: 6c3ea155e5ee ("Bluetooth: L2CAP: Fix not tracking outstanding TX ident")
+Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
+Tested-by: Christian Eggers <ceggers@arri.de>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+---
+ include/net/bluetooth/l2cap.h |    1 +
+ net/bluetooth/l2cap_core.c    |   29 ++++++++++++++++++++++++++---
+ 2 files changed, 27 insertions(+), 3 deletions(-)
+
+--- a/include/net/bluetooth/l2cap.h
++++ b/include/net/bluetooth/l2cap.h
+@@ -691,6 +691,7 @@ struct l2cap_conn {
+       struct sk_buff          *rx_skb;
+       __u32                   rx_len;
+       struct ida              tx_ida;
++      __u8                    tx_ident;
+       struct sk_buff_head     pending_rx;
+       struct work_struct      pending_rx_work;
+--- a/net/bluetooth/l2cap_core.c
++++ b/net/bluetooth/l2cap_core.c
+@@ -941,16 +941,39 @@ int l2cap_chan_check_security(struct l2c
+ static int l2cap_get_ident(struct l2cap_conn *conn)
+ {
++      u8 max;
++      int ident;
++
+       /* LE link does not support tools like l2ping so use the full range */
+       if (conn->hcon->type == LE_LINK)
+-              return ida_alloc_range(&conn->tx_ida, 1, 255, GFP_ATOMIC);
+-
++              max = 255;
+       /* Get next available identificator.
+        *    1 - 128 are used by kernel.
+        *  129 - 199 are reserved.
+        *  200 - 254 are used by utilities like l2ping, etc.
+        */
+-      return ida_alloc_range(&conn->tx_ida, 1, 128, GFP_ATOMIC);
++      else
++              max = 128;
++
++      /* Allocate ident using min as last used + 1 (cyclic) */
++      ident = ida_alloc_range(&conn->tx_ida, READ_ONCE(conn->tx_ident) + 1,
++                              max, GFP_ATOMIC);
++      /* Force min 1 to start over */
++      if (ident <= 0) {
++              ident = ida_alloc_range(&conn->tx_ida, 1, max, GFP_ATOMIC);
++              if (ident <= 0) {
++                      /* If all idents are in use, log an error, this is
++                       * extremely unlikely to happen and would indicate a bug
++                       * in the code that idents are not being freed properly.
++                       */
++                      BT_ERR("Unable to allocate ident: %d", ident);
++                      return 0;
++              }
++      }
++
++      WRITE_ONCE(conn->tx_ident, ident);
++
++      return ident;
+ }
+ static void l2cap_send_cmd(struct l2cap_conn *conn, u8 ident, u8 code, u16 len,
index dcb480c5a4a724276bea4517858a6c5817a75595..5bce0e63824286cd46893b354ab9c70568d7c409 100644 (file)
@@ -684,3 +684,4 @@ audit-add-audit_log_nf_skb-helper-function.patch
 audit-fix-potential-integer-overflow-in-audit_log_n_hex.patch
 posix-cpu-timers-use-u64-multiplication-in-update_rlimit_cpu.patch
 kvm-move-kvm_io_bus_get_dev-locking-responsibilities-to-callers.patch
+bluetooth-l2cap-fix-regressions-caused-by-reusing-ident.patch