*** This bug is a duplicate of bug 2165873 *** https://bugs.launchpad.net/bugs/2165873 I confirm this bug! I loaded a previous kernel version before 139 and my bluetooth came back and became functional again. -- You received this bug notification because you are subscribed to linux in Ubuntu. Matching subscriptions: Bgg, Bmail, Nb https://bugs.launchpad.net/bugs/2166561 Title: 6.8.0-139: btmtk NULL deref kills MT7922 Bluetooth and hangs resume Status in linux package in Ubuntu: New Bug description: 6.8.0-139.139 oopses at every boot in the MediaTek Bluetooth setup path. hci0 never finishes setup, so Bluetooth stays down, and resume from suspend hangs the machine — only a hard reset recovers it. 6.8.0-137.137 and 6.8.0-138.138 are unaffected on the same hardware and userspace. Only the kernel changed; linux-firmware was upgraded the same day but that revision only splits the package into subpackages, same upstream snapshot. (This system runs Linux Mint 22.3 on the Ubuntu 24.04 base, where "ubuntu-bug linux" refuses to file because it does not treat an Ubuntu-origin package as a distro package. Environment data is therefore listed manually below.) --- OOPS --- Every boot, immediately after "Bluetooth: hci0: HW/SW Version: 0x008a008a": BUG: kernel NULL pointer dereference, address: 0000000000000219 Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 10 PID: 159 Comm: kworker/u33:0 Not tainted 6.8.0-139-generic #139-Ubuntu Hardware name: ASRock B650I Lightning WiFi, BIOS 3.30 06/16/2025 Workqueue: hci0 hci_power_on [bluetooth] RIP: 0010:__pm_runtime_resume+0x1b/0x80 RSI: 0000000000000000 RDI: 0000000000000050 CR2: 0000000000000219 Call Trace: usb_autopm_get_interface+0x1d/0x60 btmtk_usb_hci_wmt_sync+0xa9/0x2e0 [btmtk] btmtk_setup_firmware_79xx+0x1c7/0x360 [btmtk] btusb_mtk_setup+0x453/0x610 [btusb] hci_dev_setup_sync+0x6c/0x430 [bluetooth] hci_dev_init_sync+0x3e/0x1c0 [bluetooth] hci_dev_open_sync+0xb1/0x350 [bluetooth] hci_dev_do_open+0x28/0x70 [bluetooth] hci_power_on+0x50/0x210 [bluetooth] btmtk_usb_hci_wmt_sync appears to pass a NULL USB interface to usb_autopm_get_interface: RDI=0x50 and fault address 0x219 are offsets into a NULL-based struct. The oops kills the hci0 worker part-way through the MT7922 firmware download, leaving the device half-configured. --- RESUME HANG --- 2 of 2 real suspend attempts on 6.8.0-139 hung, against 57 consecutive successful cycles on 6.8.0-138. amdgpu resumes (the monitor lights up) but the machine is dead and the journal ends at "PM: suspend entry (deep)". Reproducer, no real S3 needed: echo 0 > /sys/power/pm_async # sequential device resume echo devices > /sys/power/pm_test # devices only, no S3 systemctl suspend Booted with "no_console_suspend pm_debug_messages initcall_debug ignore_loglevel" and without "quiet splash", the console ends at: usb 1-10: PM: usb_dev_resume+0x0/0x20 returned 0 after 639667 usecs usb 1-12: PM: calling usb_dev_resume+0x0/0x20 @ 312619, parent: usb1 usb 1-12: reset high-speed USB device number 6 using xhci_hcd <no "returned" line, machine hung> With pm_async=0 the resume is strictly sequential, so the unmatched "calling" line is unambiguous. usb 1-12 is the MT7922 Bluetooth interface (0e8d:0616); every other USB device resumes normally in the same run. --- WORKAROUND, CONFIRMED BY INTERVENTION --- Blacklisting btusb removes both symptoms: no oops at boot, and 2 of 2 real suspend cycles complete on 6.8.0-139, against 2 of 2 failures on the same kernel without it. Booting 6.8.0-138 also avoids both. --- ENVIRONMENT --- ProcVersionSignature: Ubuntu 6.8.0-139.139-generic 6.8.12 Uname: Linux 6.8.0-139-generic #139-Ubuntu SMP PREEMPT_DYNAMIC Sat Aug 1 03:52:05 UTC 2026 x86_64 Architecture: amd64 DistroRelease: Linux Mint 22.3 (Ubuntu 24.04 noble base) MachineType: ASRock B650I Lightning WiFi, BIOS 3.30 (06/16/2025) CPU: AMD Ryzen 7 8700G w/ Radeon 780M Graphics GPU: AMD Phoenix1 [1002:15bf], amdgpu Bluetooth: MediaTek MT7922, USB 0e8d:0616, btusb/btmtk, at usb 1-12 CurrentDesktop: X-Cinnamon ProcCmdline: root=/dev/mapper/... ro ipv6.disable=1 quiet splash Regression: 6.8.0-138.138 good, 6.8.0-139.139 bad. Both 6.8.12 based. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2166561/+subscriptions
Комментариев нет:
Отправить комментарий