Kernel log, 6.8.0-139-generic with the attached patch applied: hci0
completes "Device setup in 159295 usecs", AOSP extensions initialise,
adapter reaches UP RUNNING with a valid BD address.

** Attachment added: "patched-6.8.0-139-generic.txt"
   
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2166509/+attachment/5997468/+files/patched-6.8.0-139-generic.txt

** Description changed:

  The following report is filled by AI upon my request. However, I had the
- issue, I read about the fix that AI proposed, I applied it and the fixed
- worked. So I can say that it was not an hallucination, at least for my
+ issue, I read about the fix that AI proposed, I applied it and the fix
+ worked. So I can say that it was not a hallucination, at least for my
  computer. Would it work on others computers? Is it a good patch? I have
  no idea...
  
  [Impact]
  
  MediaTek MT7925/MT7921 USB Bluetooth controllers are completely non-functional
  on linux-image-6.8.0-139-generic. The controller oopses during firmware setup,
  the hci0 kworker exits with irqs disabled, and the adapter is left DOWN INIT
  with BD_ADDR 00:00:00:00:00:00. bluetoothctl reports no controller at all, so
  the machine has no usable Bluetooth: no pairing, and every previously paired
  device stops working.
  
  This is a regression introduced by 6.8.0-139.139. 6.8.0-138.138 is unaffected
  on identical hardware.
  
  MediaTek MT7925/MT7921 is the Bluetooth companion of the mt7921e Wi-Fi chip 
and
  is very common on recent AMD desktop boards and laptops, so the affected
  population is not small.
  
  [Fix]
  
  Two consecutive upstream commits from the same July 2024 MediaTek series, both
  first released in v6.11:
  
-   d019930b0049 ("Bluetooth: btmtk: move btusb_mtk_hci_wmt_sync to btmtk.c")
-       Moves the WMT handshake into btmtk.c. struct btusb_data is out of scope
-       there, so the moved code reads the USB interface, device and control
-       anchor out of the btmtk private area of hci_dev instead:
+   d019930b0049 ("Bluetooth: btmtk: move btusb_mtk_hci_wmt_sync to btmtk.c")
+       Moves the WMT handshake into btmtk.c. struct btusb_data is out of scope
+       there, so the moved code reads the USB interface, device and control
+       anchor out of the btmtk private area of hci_dev instead:
  
-           struct btmtk_data *data = hci_get_priv(hdev);
-           ...
-           err = usb_autopm_get_interface(data->intf);
+           struct btmtk_data *data = hci_get_priv(hdev);
+           ...
+           err = usb_autopm_get_interface(data->intf);
  
-   5c5e8c52e3ca ("Bluetooth: btmtk: move btusb_mtk_[setup, shutdown] to 
btmtk.c")
-       Rewrites btusb_mtk_setup() to populate exactly those three fields before
-       delegating to btmtk_usb_setup().
+   5c5e8c52e3ca ("Bluetooth: btmtk: move btusb_mtk_[setup, shutdown] to 
btmtk.c")
+       Rewrites btusb_mtk_setup() to populate exactly those three fields before
+       delegating to btmtk_usb_setup().
  
  noble applied the first in 6.8.0-139.139, via LP: #2160250 ("Noble update:
  upstream stable patchset 2026-07-09"), but not the second. The consumer landed
  without its producer.
  
  btusb_mtk_setup() in noble therefore still has its pre-6.11 shape and sets 
only
  ->dev_id and ->reset_sync, leaving ->intf, ->udev and ->ctrl_anchor NULL.
  btmtk_usb_hci_wmt_sync() then calls usb_autopm_get_interface(NULL).
  
  Upstream is not affected: v6.11 and later carry both commits, v6.10 and 
earlier
  carry neither. Only a tree holding one without the other is broken.
  
  Backporting 5c5e8c52e3ca in full is not appropriate here: it moves
  btusb_mtk_setup()/btusb_mtk_shutdown() wholesale into btmtk.c and depends on 
the
  rest of the 6.11 MediaTek restructuring (btmtk_usb_setup(), 
btmtk_usb_shutdown(),
  the ISO data transmission series).
  
  The attached patch instead seeds the three fields the moved WMT code requires,
  which is what 5c5e8c52e3ca does for them upstream:
  
-       mediatek = hci_get_priv(hdev);
-       mediatek->dev_id = dev_id;
-       mediatek->reset_sync = btusb_mtk_reset;
+  mediatek = hci_get_priv(hdev);
+  mediatek->dev_id = dev_id;
+  mediatek->reset_sync = btusb_mtk_reset;
  +     mediatek->intf = data->intf;
  +     mediatek->udev = data->udev;
  +     mediatek->ctrl_anchor = &data->ctrl_anchor;
  
  [Test Case]
  
  On an MT7925 USB adapter (0e8d:0616) running 6.8.0-139-generic, no Bluetooth
  adapter is usable: hci0 never leaves DOWN INIT, it carries no BD address, and
  bluetoothctl lists no controller. The kernel log shows why, at boot:
  
-   BUG: kernel NULL pointer dereference, address: 0000000000000219
-   #PF: supervisor read access in kernel mode
-   Oops: 0000 [#1] PREEMPT SMP NOPTI
-   CPU: 6 PID: 225 Comm: kworker/u51:0 Tainted: P OE 6.8.0-139-generic 
#139-Ubuntu
-   Workqueue: hci0 hci_power_on [bluetooth]
-   RIP: 0010:__pm_runtime_resume+0x1b/0x80
-   Call Trace:
-    usb_autopm_get_interface+0x1d/0x60
-    btmtk_usb_hci_wmt_sync+0xa9/0x2e0     [btmtk]
-    btmtk_setup_firmware_79xx+0x1c7/0x360 [btmtk]
-    btusb_mtk_setup+0x453/0x610           [btusb]
-    hci_dev_setup_sync+0x6c/0x430         [bluetooth]
-    hci_dev_init_sync+0x3e/0x1c0          [bluetooth]
-    hci_dev_open_sync+0xb1/0x350          [bluetooth]
-    hci_dev_do_open+0x28/0x70             [bluetooth]
-    hci_power_on+0x50/0x210               [bluetooth]
-    process_one_work+0x181/0x3a0
-    worker_thread+0x18b/0x330
-    kthread+0xef/0x120
-   note: kworker/u51:0[225] exited with irqs disabled
+   BUG: kernel NULL pointer dereference, address: 0000000000000219
+   #PF: supervisor read access in kernel mode
+   Oops: 0000 [#1] PREEMPT SMP NOPTI
+   CPU: 6 PID: 225 Comm: kworker/u51:0 Tainted: P OE 6.8.0-139-generic 
#139-Ubuntu
+   Workqueue: hci0 hci_power_on [bluetooth]
+   RIP: 0010:__pm_runtime_resume+0x1b/0x80
+   Call Trace:
+    usb_autopm_get_interface+0x1d/0x60
+    btmtk_usb_hci_wmt_sync+0xa9/0x2e0     [btmtk]
+    btmtk_setup_firmware_79xx+0x1c7/0x360 [btmtk]
+    btusb_mtk_setup+0x453/0x610           [btusb]
+    hci_dev_setup_sync+0x6c/0x430         [bluetooth]
+    hci_dev_init_sync+0x3e/0x1c0          [bluetooth]
+    hci_dev_open_sync+0xb1/0x350          [bluetooth]
+    hci_dev_do_open+0x28/0x70             [bluetooth]
+    hci_power_on+0x50/0x210               [bluetooth]
+    process_one_work+0x181/0x3a0
+    worker_thread+0x18b/0x330
+    kthread+0xef/0x120
+   note: kworker/u51:0[225] exited with irqs disabled
  
  Booting 6.8.0-138-generic on the same machine: no oops, Bluetooth works.
  
  With btusb.ko rebuilt from 6.8.0-139 sources plus the attached patch, the same
  machine boots to:
  
-   Bluetooth: hci0: HW/SW Version: 0x008a008a, Build Time: 20250523103438
-   Bluetooth: hci0: Device setup in 159295 usecs
-   Bluetooth: hci0: AOSP extensions version v1.00
+   Bluetooth: hci0: HW/SW Version: 0x008a008a, Build Time: 20250523103438
+   Bluetooth: hci0: Device setup in 159295 usecs
+   Bluetooth: hci0: AOSP extensions version v1.00
  
-   $ hciconfig -a | head -3
-   hci0:   Type: Primary  Bus: USB
-           BD Address: A8:3B:76:XX:XX:XX  ACL MTU: 1021:6  SCO MTU: 240:8
-           UP RUNNING PSCAN
+   $ hciconfig -a | head -3
+   hci0:   Type: Primary  Bus: USB
+           BD Address: A8:3B:76:XX:XX:XX  ACL MTU: 1021:6  SCO MTU: 240:8
+           UP RUNNING PSCAN
  
  and audio devices pair and stream normally.
  
  [Regression Potential]
  
  Very low. Three assignments of already-available values, confined to the
  MediaTek USB setup path, restoring parity with upstream btusb_mtk_setup().
  
  Non-MediaTek controllers never execute this code. Without the assignments the
  fields are NULL and every consumer of them oopses, so there is no existing
  behaviour to preserve. Any risk would be confined to MediaTek USB Bluetooth,
  which is currently 100% broken on this kernel.
  
  [Other Info]
  
  Broken:    linux-image-6.8.0-139-generic  6.8.0-139.139
  Last good: linux-image-6.8.0-138-generic  6.8.0-138.138
  Release:   Ubuntu 24.04.4 LTS (noble)
  
  Adapter: MediaTek MT7925, USB 0e8d:0616 (companion to mt7921e Wi-Fi)
  Board:   Micro-Star MSI MAG X670E TOMAHAWK WIFI (MS-7E12), BIOS 1.80 
02/06/2024
  
  Any MT7921/MT7922/MT7925 USB controller going through btusb_mtk_setup() should
  reproduce this identically.
  
  Patch, build scripts and full kernel logs for the broken, good and patched
  boots: https://github.com/LouisJULIEN/btusb-mtk-fix
  
  ProblemType: Bug
  DistroRelease: Ubuntu 24.04
  Package: linux-image-6.8.0-139-generic 6.8.0-139.139
  ProcVersionSignature: Ubuntu 6.8.0-139.139-generic 6.8.12
  Uname: Linux 6.8.0-139-generic x86_64
  NonfreeKernelModules: nvidia_modeset nvidia zfs
  ApportVersion: 2.28.3-0ubuntu0.1
  Architecture: amd64
  CRDA: N/A
  CasperMD5CheckResult: pass
  CurrentDesktop: ubuntu:GNOME
  Date: Fri Sep  4 17:08:27 2026
  HibernationDevice: RESUME=none
  InstallationDate: Installed on 2024-03-20 (898 days ago)
  InstallationMedia: Ubuntu 22.04.4 LTS "Jammy Jellyfish" - Release amd64 
(20240220)
  MachineType: Micro-Star International Co., Ltd. MS-7E12
  ProcFB: 0 simpledrmdrmfb
  ProcKernelCmdLine: BOOT_IMAGE=/BOOT/ubuntu_hve01w@/vmlinuz-6.8.0-139-generic 
root=ZFS=rpool/ROOT/ubuntu_hve01w ro quiet splash vt.handoff=1
  RelatedPackageVersions:
-  linux-restricted-modules-6.8.0-139-generic N/A
-  linux-backports-modules-6.8.0-139-generic  N/A
-  linux-firmware                             20240318.git3b128b60-0ubuntu2.29
+  linux-restricted-modules-6.8.0-139-generic N/A
+  linux-backports-modules-6.8.0-139-generic  N/A
+  linux-firmware                             20240318.git3b128b60-0ubuntu2.29
  SourcePackage: linux
  UpgradeStatus: Upgraded to noble on 2024-11-30 (643 days ago)
  dmi.bios.date: 02/06/2024
  dmi.bios.release: 5.32
  dmi.bios.vendor: American Megatrends International, LLC.
  dmi.bios.version: 1.80
  dmi.board.asset.tag: To be filled by O.E.M.
  dmi.board.name: MAG X670E TOMAHAWK WIFI (MS-7E12)
  dmi.board.vendor: Micro-Star International Co., Ltd.
  dmi.board.version: 1.0
  dmi.chassis.asset.tag: To be filled by O.E.M.
  dmi.chassis.type: 3
  dmi.chassis.vendor: Micro-Star International Co., Ltd.
  dmi.chassis.version: 1.0
  dmi.modalias: 
dmi:bvnAmericanMegatrendsInternational,LLC.:bvr1.80:bd02/06/2024:br5.32:svnMicro-StarInternationalCo.,Ltd.:pnMS-7E12:pvr1.0:rvnMicro-StarInternationalCo.,Ltd.:rnMAGX670ETOMAHAWKWIFI(MS-7E12):rvr1.0:cvnMicro-StarInternationalCo.,Ltd.:ct3:cvr1.0:skuTobefilledbyO.E.M.:
  dmi.product.family: To be filled by O.E.M.
  dmi.product.name: MS-7E12
  dmi.product.sku: To be filled by O.E.M.
  dmi.product.version: 1.0
  dmi.sys.vendor: Micro-Star International Co., Ltd.

** Tags added: regression-update

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166509

Title:
   NULL pointer dereference in btmtk_usb_hci_wmt_sync kills MT7925
  Bluetooth in 6.8.0-139 (regression from 6.8.0-138)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2166509/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to