Bluetooth: Fix deadlock and crash when SMP pairing times out
authorJohan Hedberg <johan.hedberg@intel.com>
Wed, 6 Jun 2012 10:44:11 +0000 (18:44 +0800)
committerGustavo Padovan <gustavo.padovan@collabora.co.uk>
Fri, 8 Jun 2012 06:23:56 +0000 (03:23 -0300)
commitd06cc416f517a25713dedd9e2a9ccf4f3086c09a
tree4faf0f0e7f32bc66705f75d3f82d8db503e93741
parent4c47d7396420160d27209f578680141874c0110b
Bluetooth: Fix deadlock and crash when SMP pairing times out

The l2cap_conn_del function tries to cancel_sync the security timer, but
when it's called from the timeout function itself a deadlock occurs.
Subsequently the "hcon->l2cap_data = NULL" that's supposed to protect
multiple calls to l2cap_conn_del never gets cleared and when the
connection finally drops we double free's etc which will crash the
kernel.

This patch fixes the issue by using the HCI_CONN_LE_SMP_PEND for
protecting against this. The same flag is also used for the same purpose
in other places in the SMP code.

Signed-off-by: Johan Hedberg <johan.hedberg@intel.com>
Signed-off-by: Gustavo Padovan <gustavo.padovan@collabora.co.uk>
net/bluetooth/l2cap_core.c