Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative
authorGuangshuo Li <lgs201920130244@gmail.com>
Sat, 8 Aug 2026 05:15:32 +0000 (13:15 +0800)
committerLuiz Augusto von Dentz <luiz.von.dentz@intel.com>
Mon, 24 Aug 2026 17:04:03 +0000 (13:04 -0400)
bcm_request_irq() calls pm_runtime_use_autosuspend(), but bcm_close()
does not call the matching pm_runtime_dont_use_autosuspend() when
tearing down runtime PM.

If the autosuspend delay is set to a negative value while autosuspend
is enabled, the runtime PM core increments usage_count to prevent
runtime suspend. Without calling pm_runtime_dont_use_autosuspend()
during driver teardown, this reference is not dropped and usage_count
remains unbalanced.

Add the missing pm_runtime_dont_use_autosuspend() call before disabling
runtime PM.

This issue was found by manual code inspection.

Fixes: e88ab30d3669 ("Bluetooth: hci_bcm: Add suspend/resume runtime PM functions")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
drivers/bluetooth/hci_bcm.c

index 01da3fe..9a103db 100644 (file)
@@ -547,6 +547,7 @@ static int bcm_close(struct hci_uart *hu)
                if (IS_ENABLED(CONFIG_PM) && bdev->irq_acquired) {
                        devm_free_irq(bdev->dev, bdev->irq, bdev);
                        device_init_wakeup(bdev->dev, false);
+                       pm_runtime_dont_use_autosuspend(bdev->dev);
                        pm_runtime_disable(bdev->dev);
                }