[3.13.y.z extended stable] Patch "Bluetooth: Fix HCI H5 corrupted ack value" has been added to staging queue
kamal at canonical.com
Tue Oct 21 20:09:08 UTC 2014
This is a note to let you know that I have just added a patch titled
Bluetooth: Fix HCI H5 corrupted ack value
to the linux-3.13.y-queue branch of the 3.13.y.z extended stable tree
which can be found at:
This patch is scheduled to be released in version 220.127.116.11.
If you, or anyone else, feels it should not be added to this tree, please
reply to this email.
For more information about the 3.13.y.z tree, see
>From f0012881e0d0fd7b2eae7bc7ba5556aeba795d93 Mon Sep 17 00:00:00 2001
From: Loic Poulain <loic.poulain at intel.com>
Date: Fri, 8 Aug 2014 19:07:16 +0200
Subject: Bluetooth: Fix HCI H5 corrupted ack value
commit 4807b51895dce8aa650ebebc51fa4a795ed6b8b8 upstream.
In this expression: seq = (seq - 1) % 8
seq (u8) is implicitly converted to an int in the arithmetic operation.
So if seq value is 0, operation is ((0 - 1) % 8) => (-1 % 8) => -1.
The new seq value is 0xff which is an invalid ACK value, we expect 0x07.
It leads to frequent dropped ACK and retransmission.
Fix this by using '&' binary operator instead of '%'.
Signed-off-by: Loic Poulain <loic.poulain at intel.com>
Signed-off-by: Marcel Holtmann <marcel at holtmann.org>
Signed-off-by: Kamal Mostafa <kamal at canonical.com>
drivers/bluetooth/hci_h5.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/bluetooth/hci_h5.c b/drivers/bluetooth/hci_h5.c
index e36a024..5651992 100644
@@ -237,7 +237,7 @@ static void h5_pkt_cull(struct h5 *h5)
- seq = (seq - 1) % 8;
+ seq = (seq - 1) & 0x07;
if (seq != h5->rx_ack)
More information about the kernel-team