[regression] Kernel crash in bluetooth with Bose QC35

Bug #1729030 reported by Merlijn Sebrechts
18
This bug affects 3 people
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Confirmed
Medium
Konrad Zapałowicz

Bug Description

Bose QC35 with latest firmware
Ubuntu 17.10

This is a regression from 17.04 Ubuntu Gnome. In 17.04, you had to temporarily disable `le` mode to pair but after pairing, everything worked flawlessly. In 17.10, pairing works out of the box, but the following issue appears:

After a few hours of being connected, the connection between bose qc35 and Ubuntu seemingly breaks: the headphones don't play any sound anymore. re-pairing fails and restarting the headphones doesn't fix the issue. It seems bluetoothd crashed conmpletely since `bluetoothctl` doesn't work anymore.. Restarting Ubuntu fixes the issue.

syslog contains a bunch of kernel stacktraces including a nullpointer dereference..

Oct 31 16:41:06 travers dbus-daemon[3888]: Activating via systemd: service name='org.bluez.obex' unit='dbus-org.bluez.obex.service'
Oct 31 16:41:06 travers systemd[3874]: Starting Bluetooth OBEX service...
Oct 31 16:41:06 travers bluetoothd[1128]: Failed to set mode: Busy (0x0a)
Oct 31 16:41:06 travers obexd[29587]: OBEX daemon 5.46
Oct 31 16:41:06 travers dbus-daemon[3888]: Successfully activated service 'org.bluez.obex'
Oct 31 16:41:06 travers systemd[3874]: Started Bluetooth OBEX service.
Oct 31 16:41:06 travers bluetoothd[1128]: Failed to set mode: Busy (0x0a)
Oct 31 16:41:06 travers bluetoothd[1128]: Failed to set mode: Busy (0x0a)
Oct 31 16:41:12 travers kernel: Bluetooth: hci0 link tx timeout
Oct 31 16:41:12 travers kernel: Bluetooth: hci0 killing stalled connection 04:52:c7:60:d6:2c
Oct 31 16:41:12 travers acpid[1126]: input device has been disconnected, fd 24
Oct 31 16:41:12 travers kernel: Bluetooth: hci0 link tx timeout
Oct 31 16:41:12 travers kernel: Bluetooth: hci0 killing stalled connection 04:52:c7:60:d6:2c
Oct 31 16:41:14 travers bluetoothd[1128]: Disconnecting failed: already disconnected
Oct 31 16:41:18 travers bluetoothd[1128]: Close: Connection timed out (110)
Oct 31 16:41:18 travers kernel: Bluetooth: hci0 link tx timeout
Oct 31 16:41:18 travers kernel: Bluetooth: hci0 killing stalled connection 04:52:c7:60:d6:2c
Oct 31 16:41:20 travers bluetoothd[1128]: Abort: Connection timed out (110)
Oct 31 16:41:20 travers kernel: Bluetooth: hci0 link tx timeout
Oct 31 16:41:20 travers kernel: Bluetooth: hci0 killing stalled connection 04:52:c7:60:d6:2c
Oct 31 16:41:20 travers kernel: Bluetooth: hci0 link tx timeout
Oct 31 16:41:20 travers kernel: Bluetooth: hci0 killing stalled connection 04:52:c7:60:d6:2c
Oct 31 16:41:20 travers dbus[1074]: [system] Rejected send message, 3 matched rules; type="method_return", sender=":1.86" (uid=1000 pid=3997 comm="/usr/bin/pulseaudio --start --log-target=syslog ") interface="(unset)" member="(unset)" error name="(unset)" requested_reply="0" destination=":1.7" (uid=0 pid=1128 comm="/usr/lib/bluetooth/bluetoothd ")
Oct 31 16:41:20 travers gsd-media-keys[4157]: Unable to get default sink
Oct 31 16:41:32 travers kernel: sysfs: cannot create duplicate filename '/devices/pci0000:00/0000:00:14.0/usb1/1-6/1-6:1.0/bluetooth/hci0/hci0:256'
Oct 31 16:41:32 travers kernel: ------------[ cut here ]------------
Oct 31 16:41:32 travers kernel: WARNING: CPU: 2 PID: 19117 at /build/linux-XO_uEE/linux-4.13.0/fs/sysfs/dir.c:31 sysfs_warn_dup+0x56/0x70
Oct 31 16:41:32 travers kernel: Modules linked in: rfcomm ip6t_MASQUERADE nf_nat_masquerade_ipv6 ip6table_nat nf_conntrack_ipv6 nf_defrag_ipv6 nf_nat_ipv6 xt_comment zfs(PO) zunicode(PO) zavl(PO) zcommon(PO) znvpair(PO) spl(O) pci_stub vboxpci(OE) vboxnetadp(OE) vboxnetflt(OE) vboxdrv(OE) ccm cmac xt_CHECKSUM iptable_mangle ipt_MASQUERADE nf_nat_masquerade_ipv4 iptable_nat nf_nat_ipv4 nf_nat nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack nf_conntrack libcrc32c ipt_REJECT nf_reject_ipv4 xt_tcpudp bridge stp llc ebtable_filter ebtables ip6table_filter ip6_tables iptable_filter bnep nls_iso8859_1 arc4 hid_alps snd_hda_codec_hdmi intel_rapl x86_pkg_temp_thermal intel_powerclamp coretemp kvm_intel kvm dell_rbtn dell_laptop iwlmvm irqbypass dell_smm_hwmon mac80211 crct10dif_pclmul crc32_pclmul snd_hda_codec_realtek snd_hda_codec_generic
Oct 31 16:41:32 travers kernel: ghash_clmulni_intel pcbc iwlwifi rtsx_pci_ms uvcvideo cfg80211 memstick videobuf2_vmalloc videobuf2_memops videobuf2_v4l2 videobuf2_core videodev media aesni_intel aes_x86_64 crypto_simd glue_helper cryptd intel_cstate intel_rapl_perf snd_hda_intel snd_hda_codec joydev snd_hda_core snd_hwdep snd_pcm btusb btrtl snd_seq_midi snd_seq_midi_event snd_rawmidi snd_seq snd_seq_device input_leds snd_timer serio_raw snd dell_wmi dell_smbios dcdbas wmi_bmof soundcore mei_me shpchp idma64 hci_uart mei virt_dma processor_thermal_device intel_pch_thermal intel_soc_dts_iosf intel_lpss_pci btbcm serdev btqca btintel bluetooth ecdh_generic dell_smo8800 int3403_thermal tpm_crb intel_hid intel_lpss_acpi int340x_thermal_zone int3400_thermal acpi_als acpi_thermal_rel intel_lpss kfifo_buf sparse_keymap mac_hid
Oct 31 16:41:32 travers kernel: acpi_pad industrialio parport_pc ppdev lp parport ip_tables x_tables autofs4 hid_generic usbhid i915 i2c_algo_bit rtsx_pci_sdmmc drm_kms_helper e1000e syscopyarea sysfillrect sysimgblt ptp fb_sys_fops pps_core rtsx_pci drm ahci libahci wmi i2c_hid hid video pinctrl_sunrisepoint pinctrl_intel
Oct 31 16:41:32 travers kernel: CPU: 2 PID: 19117 Comm: kworker/u9:1 Tainted: P OE 4.13.0-16-generic #19-Ubuntu
Oct 31 16:41:32 travers kernel: Hardware name: Dell Inc. Latitude 5580/0DTP1F, BIOS 1.6.4 09/12/2017
Oct 31 16:41:32 travers kernel: Workqueue: hci0 hci_rx_work [bluetooth]
Oct 31 16:41:32 travers kernel: task: ffff93b3ef8017c0 task.stack: ffffb77091e8c000
Oct 31 16:41:32 travers kernel: RIP: 0010:sysfs_warn_dup+0x56/0x70
Oct 31 16:41:32 travers kernel: RSP: 0018:ffffb77091e8fb80 EFLAGS: 00010282
Oct 31 16:41:32 travers kernel: RAX: 0000000000000073 RBX: ffff93b46769a000 RCX: 0000000000000000
Oct 31 16:41:32 travers kernel: RDX: 0000000000000000 RSI: ffff93b5ee50dc78 RDI: ffff93b5ee50dc78
Oct 31 16:41:32 travers kernel: RBP: ffffb77091e8fb98 R08: 0000000000000001 R09: 0000000000000436
Oct 31 16:41:32 travers kernel: R10: 0000000000000001 R11: 0000000000000000 R12: ffff93b54df84e50
Oct 31 16:41:32 travers kernel: R13: ffff93b5d0581690 R14: ffff93b5d4d1c288 R15: ffff93b5d7bb4c50
Oct 31 16:41:32 travers kernel: FS: 0000000000000000(0000) GS:ffff93b5ee500000(0000) knlGS:0000000000000000
Oct 31 16:41:32 travers kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Oct 31 16:41:32 travers kernel: CR2: 000020563636d008 CR3: 00000003bed2c000 CR4: 00000000003406e0
Oct 31 16:41:32 travers kernel: DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
Oct 31 16:41:32 travers kernel: DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Oct 31 16:41:32 travers kernel: Call Trace:
Oct 31 16:41:32 travers kernel: sysfs_create_dir_ns+0x77/0x90
Oct 31 16:41:32 travers kernel: kobject_add_internal+0xac/0x2b0
Oct 31 16:41:32 travers kernel: kobject_add+0x71/0xd0
Oct 31 16:41:32 travers kernel: ? kfree_const+0x20/0x30
Oct 31 16:41:32 travers kernel: device_add+0x12c/0x680
Oct 31 16:41:32 travers kernel: hci_conn_add_sysfs+0x49/0xc0 [bluetooth]
Oct 31 16:41:32 travers kernel: hci_conn_complete_evt.isra.46+0xc6/0x3f0 [bluetooth]
Oct 31 16:41:32 travers kernel: hci_event_packet+0x1ac5/0x2a80 [bluetooth]
Oct 31 16:41:32 travers kernel: ? pick_next_task_fair+0x131/0x560
Oct 31 16:41:32 travers kernel: hci_rx_work+0x18d/0x380 [bluetooth]
Oct 31 16:41:32 travers kernel: ? hci_rx_work+0x18d/0x380 [bluetooth]
Oct 31 16:41:32 travers kernel: ? __schedule+0x293/0x890
Oct 31 16:41:32 travers kernel: process_one_work+0x1e7/0x410
Oct 31 16:41:32 travers kernel: worker_thread+0x4a/0x410
Oct 31 16:41:32 travers kernel: kthread+0x125/0x140
Oct 31 16:41:32 travers kernel: ? process_one_work+0x410/0x410
Oct 31 16:41:32 travers kernel: ? kthread_create_on_node+0x70/0x70
Oct 31 16:41:32 travers kernel: ret_from_fork+0x25/0x30
Oct 31 16:41:32 travers kernel: Code: 85 c0 48 89 c3 74 12 b9 00 10 00 00 48 89 c2 31 f6 4c 89 ef e8 0c c8 ff ff 4c 89 e2 48 89 de 48 c7 c7 d0 9f 4c b4 e8 cb 78 e0 ff <0f> ff 48 89 df e8 60 bd f4 ff 5b 41 5c 41 5d 5d c3 66 0f 1f 84
Oct 31 16:41:32 travers kernel: ---[ end trace d6a6ced6c41fcfc5 ]---
Oct 31 16:41:32 travers kernel: kobject_add_internal failed for hci0:256 with -EEXIST, don't try to register things with the same name in the same directory.
Oct 31 16:41:32 travers kernel: ------------[ cut here ]------------
Oct 31 16:41:32 travers kernel: WARNING: CPU: 2 PID: 19117 at /build/linux-XO_uEE/linux-4.13.0/lib/kobject.c:240 kobject_add_internal+0x26b/0x2b0
Oct 31 16:41:32 travers kernel: Modules linked in: rfcomm ip6t_MASQUERADE nf_nat_masquerade_ipv6 ip6table_nat nf_conntrack_ipv6 nf_defrag_ipv6 nf_nat_ipv6 xt_comment zfs(PO) zunicode(PO) zavl(PO) zcommon(PO) znvpair(PO) spl(O) pci_stub vboxpci(OE) vboxnetadp(OE) vboxnetflt(OE) vboxdrv(OE) ccm cmac xt_CHECKSUM iptable_mangle ipt_MASQUERADE nf_nat_masquerade_ipv4 iptable_nat nf_nat_ipv4 nf_nat nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack nf_conntrack libcrc32c ipt_REJECT nf_reject_ipv4 xt_tcpudp bridge stp llc ebtable_filter ebtables ip6table_filter ip6_tables iptable_filter bnep nls_iso8859_1 arc4 hid_alps snd_hda_codec_hdmi intel_rapl x86_pkg_temp_thermal intel_powerclamp coretemp kvm_intel kvm dell_rbtn dell_laptop iwlmvm irqbypass dell_smm_hwmon mac80211 crct10dif_pclmul crc32_pclmul snd_hda_codec_realtek snd_hda_codec_generic
Oct 31 16:41:32 travers kernel: ghash_clmulni_intel pcbc iwlwifi rtsx_pci_ms uvcvideo cfg80211 memstick videobuf2_vmalloc videobuf2_memops videobuf2_v4l2 videobuf2_core videodev media aesni_intel aes_x86_64 crypto_simd glue_helper cryptd intel_cstate intel_rapl_perf snd_hda_intel snd_hda_codec joydev snd_hda_core snd_hwdep snd_pcm btusb btrtl snd_seq_midi snd_seq_midi_event snd_rawmidi snd_seq snd_seq_device input_leds snd_timer serio_raw snd dell_wmi dell_smbios dcdbas wmi_bmof soundcore mei_me shpchp idma64 hci_uart mei virt_dma processor_thermal_device intel_pch_thermal intel_soc_dts_iosf intel_lpss_pci btbcm serdev btqca btintel bluetooth ecdh_generic dell_smo8800 int3403_thermal tpm_crb intel_hid intel_lpss_acpi int340x_thermal_zone int3400_thermal acpi_als acpi_thermal_rel intel_lpss kfifo_buf sparse_keymap mac_hid
Oct 31 16:41:32 travers kernel: acpi_pad industrialio parport_pc ppdev lp parport ip_tables x_tables autofs4 hid_generic usbhid i915 i2c_algo_bit rtsx_pci_sdmmc drm_kms_helper e1000e syscopyarea sysfillrect sysimgblt ptp fb_sys_fops pps_core rtsx_pci drm ahci libahci wmi i2c_hid hid video pinctrl_sunrisepoint pinctrl_intel
Oct 31 16:41:32 travers kernel: CPU: 2 PID: 19117 Comm: kworker/u9:1 Tainted: P W OE 4.13.0-16-generic #19-Ubuntu
Oct 31 16:41:32 travers kernel: Hardware name: Dell Inc. Latitude 5580/0DTP1F, BIOS 1.6.4 09/12/2017
Oct 31 16:41:32 travers kernel: Workqueue: hci0 hci_rx_work [bluetooth]
Oct 31 16:41:32 travers kernel: task: ffff93b3ef8017c0 task.stack: ffffb77091e8c000
Oct 31 16:41:32 travers kernel: RIP: 0010:kobject_add_internal+0x26b/0x2b0
Oct 31 16:41:32 travers kernel: RSP: 0018:ffffb77091e8fbd0 EFLAGS: 00010286
Oct 31 16:41:32 travers kernel: RAX: 000000000000007d RBX: ffff93b5d4d1c298 RCX: 0000000000000006
Oct 31 16:41:32 travers kernel: RDX: 0000000000000000 RSI: 0000000000000086 RDI: ffff93b5ee50dc70
Oct 31 16:41:32 travers kernel: RBP: ffffb77091e8fc00 R08: 0000000000000001 R09: 0000000000000461
Oct 31 16:41:32 travers kernel: R10: ffffe5630a9da600 R11: 0000000000000000 R12: ffff93b5d7bb4c50
Oct 31 16:41:32 travers kernel: R13: 00000000ffffffef R14: ffff93b5d4d1c288 R15: ffff93b5d7bb4c50
Oct 31 16:41:32 travers kernel: FS: 0000000000000000(0000) GS:ffff93b5ee500000(0000) knlGS:0000000000000000
Oct 31 16:41:32 travers kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Oct 31 16:41:32 travers kernel: CR2: 000020563636d008 CR3: 00000003bed2c000 CR4: 00000000003406e0
Oct 31 16:41:32 travers kernel: DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
Oct 31 16:41:32 travers kernel: DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Oct 31 16:41:32 travers kernel: Call Trace:
Oct 31 16:41:32 travers kernel: kobject_add+0x71/0xd0
Oct 31 16:41:32 travers kernel: ? kfree_const+0x20/0x30
Oct 31 16:41:32 travers kernel: device_add+0x12c/0x680
Oct 31 16:41:32 travers kernel: hci_conn_add_sysfs+0x49/0xc0 [bluetooth]
Oct 31 16:41:32 travers kernel: hci_conn_complete_evt.isra.46+0xc6/0x3f0 [bluetooth]
Oct 31 16:41:32 travers kernel: hci_event_packet+0x1ac5/0x2a80 [bluetooth]
Oct 31 16:41:32 travers kernel: ? pick_next_task_fair+0x131/0x560
Oct 31 16:41:32 travers kernel: hci_rx_work+0x18d/0x380 [bluetooth]
Oct 31 16:41:32 travers kernel: ? hci_rx_work+0x18d/0x380 [bluetooth]
Oct 31 16:41:32 travers kernel: ? __schedule+0x293/0x890
Oct 31 16:41:32 travers kernel: process_one_work+0x1e7/0x410
Oct 31 16:41:32 travers kernel: worker_thread+0x4a/0x410
Oct 31 16:41:32 travers kernel: kthread+0x125/0x140
Oct 31 16:41:32 travers kernel: ? process_one_work+0x410/0x410
Oct 31 16:41:32 travers kernel: ? kthread_create_on_node+0x70/0x70
Oct 31 16:41:32 travers kernel: ret_from_fork+0x25/0x30
Oct 31 16:41:32 travers kernel: Code: 49 89 c4 48 85 ff 0f 84 44 fe ff ff 48 83 c7 18 e9 ff fd ff ff 48 8b 13 48 c7 c6 d0 57 30 b4 48 c7 c7 b8 65 56 b4 e8 66 5f 7f ff <0f> ff e9 92 fe ff ff 0f ff eb a5 0f ff eb 98 41 bd fe ff ff ff
Oct 31 16:41:32 travers kernel: ---[ end trace d6a6ced6c41fcfc6 ]---
Oct 31 16:41:32 travers kernel: Bluetooth: Failed to register connection device
Oct 31 16:41:32 travers kernel: Bluetooth: hci0 link tx timeout
Oct 31 16:41:32 travers kernel: Bluetooth: hci0 killing stalled connection 04:52:c7:60:d6:2c
Oct 31 16:41:32 travers bluetoothd[1128]: No matching connection for device
Oct 31 16:41:32 travers kernel: BUG: unable to handle kernel NULL pointer dereference at 0000000000000020
Oct 31 16:41:32 travers kernel: IP: klist_next+0x16/0xb0
Oct 31 16:41:32 travers kernel: PGD 0
Oct 31 16:41:32 travers kernel: P4D 0
Oct 31 16:41:32 travers kernel:
Oct 31 16:41:32 travers kernel: Oops: 0000 [#1] SMP
Oct 31 16:41:32 travers kernel: Modules linked in: rfcomm ip6t_MASQUERADE nf_nat_masquerade_ipv6 ip6table_nat nf_conntrack_ipv6 nf_defrag_ipv6 nf_nat_ipv6 xt_comment zfs(PO) zunicode(PO) zavl(PO) zcommon(PO) znvpair(PO) spl(O) pci_stub vboxpci(OE) vboxnetadp(OE) vboxnetflt(OE) vboxdrv(OE) ccm cmac xt_CHECKSUM iptable_mangle ipt_MASQUERADE nf_nat_masquerade_ipv4 iptable_nat nf_nat_ipv4 nf_nat nf_conntrack_ipv4 nf_defrag_ipv4 xt_conntrack nf_conntrack libcrc32c ipt_REJECT nf_reject_ipv4 xt_tcpudp bridge stp llc ebtable_filter ebtables ip6table_filter ip6_tables iptable_filter bnep nls_iso8859_1 arc4 hid_alps snd_hda_codec_hdmi intel_rapl x86_pkg_temp_thermal intel_powerclamp coretemp kvm_intel kvm dell_rbtn dell_laptop iwlmvm irqbypass dell_smm_hwmon mac80211 crct10dif_pclmul crc32_pclmul snd_hda_codec_realtek snd_hda_codec_generic
Oct 31 16:41:32 travers kernel: ghash_clmulni_intel pcbc iwlwifi rtsx_pci_ms uvcvideo cfg80211 memstick videobuf2_vmalloc videobuf2_memops videobuf2_v4l2 videobuf2_core videodev media aesni_intel aes_x86_64 crypto_simd glue_helper cryptd intel_cstate intel_rapl_perf snd_hda_intel snd_hda_codec joydev snd_hda_core snd_hwdep snd_pcm btusb btrtl snd_seq_midi snd_seq_midi_event snd_rawmidi snd_seq snd_seq_device input_leds snd_timer serio_raw snd dell_wmi dell_smbios dcdbas wmi_bmof soundcore mei_me shpchp idma64 hci_uart mei virt_dma processor_thermal_device intel_pch_thermal intel_soc_dts_iosf intel_lpss_pci btbcm serdev btqca btintel bluetooth ecdh_generic dell_smo8800 int3403_thermal tpm_crb intel_hid intel_lpss_acpi int340x_thermal_zone int3400_thermal acpi_als acpi_thermal_rel intel_lpss kfifo_buf sparse_keymap mac_hid
Oct 31 16:41:32 travers kernel: acpi_pad industrialio parport_pc ppdev lp parport ip_tables x_tables autofs4 hid_generic usbhid i915 i2c_algo_bit rtsx_pci_sdmmc drm_kms_helper e1000e syscopyarea sysfillrect sysimgblt ptp fb_sys_fops pps_core rtsx_pci drm ahci libahci wmi i2c_hid hid video pinctrl_sunrisepoint pinctrl_intel

# HCICONFIG OUTPUT

hci0: Type: Primary Bus: USB
 BD Address: CC:2F:71:7D:95:00 ACL MTU: 1021:4 SCO MTU: 96:6
 UP RUNNING PSCAN ISCAN
 RX bytes:5571230 acl:176 sco:0 events:648741 errors:0
 TX bytes:385789321 acl:625464 sco:0 commands:2503 errors:0
 Features: 0xff 0xfe 0x0f 0xfe 0xdb 0xff 0x7b 0x87
 Packet type: DM1 DM3 DM5 DH1 DH3 DH5 HV1 HV2 HV3
 Link policy: RSWITCH HOLD SNIFF
 Link mode: SLAVE ACCEPT
Can't read local name on hci0: Connection timed out (110)

# BLUETOOTHCTL OUTPUT

bluetoothctl
[bluetooth]# nnect to bluetoothd...
[bluetooth]#
[bluetooth]# show
No default controller available
[bluetooth]# devices
No default controller available
[bluetooth]# info
Missing device address argument
[bluetooth]#

sudo wireless-tools.rfkill list
Can't open RFKILL control device: Permission denied
---
ApportVersion: 2.20.7-0ubuntu3.5
Architecture: amd64
AudioDevicesInUse:
 USER PID ACCESS COMMAND
 /dev/snd/controlC0: merlijn 3523 F.... pulseaudio
CurrentDesktop: ubuntu:GNOME
DistroRelease: Ubuntu 17.10
HibernationDevice: RESUME=UUID=de1d3c2e-7beb-4791-8294-9f6455b173e0
InstallationDate: Installed on 2017-09-22 (65 days ago)
InstallationMedia: Ubuntu 17.10 "Artful Aardvark" - Alpha amd64 (20170922)
Lsusb:
 Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub
 Bus 001 Device 005: ID 8087:0a2b Intel Corp.
 Bus 001 Device 002: ID 24ae:2003
 Bus 001 Device 004: ID 0bda:5650 Realtek Semiconductor Corp.
 Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
MachineType: Dell Inc. Latitude 5580
NonfreeKernelModules: zfs zunicode zavl zcommon znvpair
Package: linux (not installed)
ProcFB: 0 inteldrmfb
ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-4.13.0-17-generic.efi.signed root=/dev/mapper/ubuntu--vg-root ro quiet splash vt.handoff=7
ProcVersionSignature: Ubuntu 4.13.0-17.20-generic 4.13.8
RelatedPackageVersions:
 linux-restricted-modules-4.13.0-17-generic N/A
 linux-backports-modules-4.13.0-17-generic N/A
 linux-firmware 1.169
Tags: artful wayland-session
Uname: Linux 4.13.0-17-generic x86_64
UpgradeStatus: No upgrade log present (probably fresh install)
UserGroups: adm cdrom dip libvirt lpadmin lxd plugdev sambashare sudo vboxusers
_MarkForUpload: True
dmi.bios.date: 11/12/2017
dmi.bios.vendor: Dell Inc.
dmi.bios.version: 1.7.5
dmi.board.name: 0DTP1F
dmi.board.vendor: Dell Inc.
dmi.board.version: X02
dmi.chassis.type: 10
dmi.chassis.vendor: Dell Inc.
dmi.modalias: dmi:bvnDellInc.:bvr1.7.5:bd11/12/2017:svnDellInc.:pnLatitude5580:pvr:rvnDellInc.:rn0DTP1F:rvrX02:cvnDellInc.:ct10:cvr:
dmi.product.family: Latitude
dmi.product.name: Latitude 5580
dmi.sys.vendor: Dell Inc.

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote :
summary: - Bose QC35 loses connection, requiring restart
+ [bluez] regression: bluetoothd crash with Bose QC35
Jim Hodapp (jhodapp)
Changed in snappy-hwe-snaps:
importance: Undecided → Medium
assignee: nobody → Konrad Zapałowicz (kzapalowicz)
Revision history for this message
Konrad Zapałowicz (kzapalowicz) wrote : Re: [bluez] regression: bluetoothd crash with Bose QC35

@Merlijn

Hey, a few follow-up questions:

1. Are you using bluez as a snap on desktop?
2. What s the kernel version being used, you can check this with $ uname -a

Thanks,
KZ

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote :

I'm using stock Ubuntu 17.10, so that's bluez from the archive: bluez/artful,now 5.46-0ubuntu3 amd64 [installed]

Linux travers 4.13.0-16-generic #19-Ubuntu SMP Wed Oct 11 18:35:14 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux

affects: snappy-hwe-snaps → bluez (Ubuntu)
Revision history for this message
Daniel van Vugt (vanvugt) wrote : Re: [regression] Kernel crash with Bose QC35

It's not bluetoothd (BlueZ) crashing. The log information shows the kernel crashing in 'bluetooth' which is a kernel module. This will of course cause bluetoothd to stop working properly, but the bug is not in bluetoothd, it's in the kernel.

summary: - [bluez] regression: bluetoothd crash with Bose QC35
+ [regression] Kernel crash with Bose QC35
Revision history for this message
Daniel van Vugt (vanvugt) wrote :

Please try a slightly older kernel or two from here:

  http://kernel.ubuntu.com/~kernel-ppa/mainline/?C=N;O=D

Since you say Ubuntu 17.04 worked, try kernels down to v4.10 (which is where it was working).

affects: bluez (Ubuntu) → linux (Ubuntu)
Changed in linux (Ubuntu):
status: New → Incomplete
summary: - [regression] Kernel crash with Bose QC35
+ [regression] Kernel crash in bluetooth with Bose QC35
Revision history for this message
Joseph Salisbury (jsalisbury) wrote :

Would it be possible for you to test the latest upstream kernel? Refer to https://wiki.ubuntu.com/KernelMainlineBuilds . Please test the latest v4.14 kernel[0].

If this bug is fixed in the mainline kernel, please add the following tag 'kernel-fixed-upstream'.

If the mainline kernel does not fix this bug, please add the tag: 'kernel-bug-exists-upstream'.

Once testing of the upstream kernel is complete, please mark this bug as "Confirmed".

Thanks in advance.

[0] http://kernel.ubuntu.com/~kernel-ppa/mainline/v4.14

tags: added: kernel-da-key
Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote :

@joseph

I have not found a reliable way to replicate this bug so I cannot test if it is still present in the latest upstream kernel.

I have attached the full syslog of multiple days + multiple crashes in the second message in this thread. Does it give any hints as to how to replicate this issue?

Revision history for this message
Kai-Heng Feng (kaihengfeng) wrote :

Can you provide full dmesg?

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote :

This is the dmesg output before a crash. I'll add another dmesg output when I get the next crash.

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote :

dmesg output after a crash:

[ 8681.543399] Bluetooth: hci0: Waiting for firmware download to complete
[ 8681.544000] Bluetooth: hci0: Firmware loaded in 1653022 usecs
[ 8681.544085] Bluetooth: hci0: Waiting for device to boot
[ 8681.556011] Bluetooth: hci0: Device booted in 11725 usecs
[ 8681.556015] Bluetooth: hci0: Found Intel DDC parameters: intel/ibt-12-16.ddc
[ 8681.558066] Bluetooth: hci0: Applying Intel DDC parameters completed
[ 8685.153002] wlp1s0: authenticate with dc:53:7c:69:75:6f
[ 8685.161238] wlp1s0: send auth to dc:53:7c:69:75:6f (try 1/3)
[ 8685.167428] wlp1s0: authenticated
[ 8685.171558] wlp1s0: associate with dc:53:7c:69:75:6f (try 1/3)
[ 8685.172546] wlp1s0: RX AssocResp from dc:53:7c:69:75:6f (capab=0x411 status=0 aid=1)
[ 8685.175579] wlp1s0: associated
[ 8685.175614] IPv6: ADDRCONF(NETDEV_CHANGE): wlp1s0: link becomes ready
[ 8697.695935] input: 04:52:C7:60:D6:2C as /devices/virtual/input/input21
[ 9960.422408] wlp1s0: disconnect from AP dc:53:7c:69:75:6f for new auth to dc:53:7c:69:75:6e
[ 9960.434610] wlp1s0: authenticate with dc:53:7c:69:75:6e
[ 9960.444243] wlp1s0: send auth to dc:53:7c:69:75:6e (try 1/3)
[ 9960.456829] wlp1s0: authenticated
[ 9960.460915] wlp1s0: associate with dc:53:7c:69:75:6e (try 1/3)
[ 9960.568647] wlp1s0: associate with dc:53:7c:69:75:6e (try 2/3)
[ 9960.672650] wlp1s0: associate with dc:53:7c:69:75:6e (try 3/3)
[ 9960.784566] wlp1s0: association with dc:53:7c:69:75:6e timed out
[ 9960.928961] wlp1s0: authenticate with dc:53:7c:69:75:6f
[ 9960.939516] wlp1s0: send auth to dc:53:7c:69:75:6f (try 1/3)
[ 9961.037029] wlp1s0: authenticated
[ 9961.040633] wlp1s0: associate with dc:53:7c:69:75:6f (try 1/3)
[ 9961.041740] wlp1s0: RX AssocResp from dc:53:7c:69:75:6f (capab=0x411 status=0 aid=1)
[ 9961.044422] wlp1s0: associated
[10013.994612] Bluetooth: hci0 link tx timeout
[10013.994617] Bluetooth: hci0 killing stalled connection 04:52:c7:60:d6:2c
[10015.990917] Bluetooth: hci0 link tx timeout
[10015.990922] Bluetooth: hci0 killing stalled connection 04:52:c7:60:d6:2c
[10016.024585] Bluetooth: hci0 link tx timeout
[10016.024589] Bluetooth: hci0 killing stalled connection 04:52:c7:60:d6:2c
[10016.024924] Bluetooth: hci0 link tx timeout
[10016.024926] Bluetooth: hci0 killing stalled connection 04:52:c7:60:d6:2c
[11993.074880] usb 1-6: USB disconnect, device number 3

Changed in linux (Ubuntu):
status: Incomplete → New
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote : Missing required logs.

This bug is missing log files that will aid in diagnosing the problem. While running an Ubuntu kernel (not a mainline or third-party kernel) please enter the following command in a terminal window:

apport-collect 1729030

and then change the status of the bug to 'Confirmed'.

If, due to the nature of the issue you have encountered, you are unable to run this command, please add a comment stating that fact and change the bug status to 'Confirmed'.

This change has been made by an automated script, maintained by the Ubuntu Kernel Team.

Changed in linux (Ubuntu):
status: New → Incomplete
tags: added: artful
Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : AlsaInfo.txt

apport information

tags: added: apport-collected wayland-session
description: updated
Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : CRDA.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : CurrentDmesg.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : IwConfig.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : JournalErrors.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : Lspci.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : ProcCpuinfo.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : ProcCpuinfoMinimal.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : ProcEnviron.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : ProcInterrupts.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : ProcModules.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : PulseList.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : RfKill.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : UdevDb.txt

apport information

Revision history for this message
Merlijn Sebrechts (merlijn-sebrechts) wrote : WifiSyslog.txt

apport information

Changed in linux (Ubuntu):
status: Incomplete → Confirmed
Revision history for this message
Axel Meunier (axel-meunier) wrote :
Download full text (42.7 KiB)

My computer (Depp Precision 5510 with Ubuntu 17.10 - actually Pop!_OS - fresh install) is affected by the same kind of bug.

Connection to bluetooth speakers sometimes works, sometimes does not, sometimes works well at boot then stops. I am not able to reproduce the issue consistently. When bluetooth stops working, it can not be desactivated/reactivated from panel, system settings stalls, shutdown fails => hard reset.

What information should I provide ?
I have this :

axel@pop-os:~$ dmesg |grep -i bluetooth

[ 4.253605] Bluetooth: Core ver 2.22
[ 4.253617] Bluetooth: HCI device and connection manager initialized
[ 4.253618] Bluetooth: HCI socket layer initialized
[ 4.253619] Bluetooth: L2CAP socket layer initialized
[ 4.253622] Bluetooth: SCO socket layer initialized
[ 4.263362] Bluetooth: HCI UART driver ver 2.3
[ 4.263364] Bluetooth: HCI UART protocol H4 registered
[ 4.263364] Bluetooth: HCI UART protocol BCSP registered
[ 4.263378] Bluetooth: HCI UART protocol LL registered
[ 4.263379] Bluetooth: HCI UART protocol ATH3K registered
[ 4.263379] Bluetooth: HCI UART protocol Three-wire (H5) registered
[ 4.263401] Bluetooth: HCI UART protocol Intel registered
[ 4.263412] Bluetooth: HCI UART protocol Broadcom registered
[ 4.263413] Bluetooth: HCI UART protocol QCA registered
[ 4.263413] Bluetooth: HCI UART protocol AG6XX registered
[ 4.263414] Bluetooth: HCI UART protocol Marvell registered
[ 4.265026] Bluetooth: hci0: Bootloader revision 0.0 build 2 week 52 2014
[ 4.269822] Bluetooth: hci0: Device revision is 5
[ 4.269823] Bluetooth: hci0: Secure boot is enabled
[ 4.269823] Bluetooth: hci0: OTP lock is enabled
[ 4.269824] Bluetooth: hci0: API lock is enabled
[ 4.269824] Bluetooth: hci0: Debug lock is disabled
[ 4.269825] Bluetooth: hci0: Minimum firmware build 1 week 10 2014
[ 4.271430] Bluetooth: hci0: Found device firmware: intel/ibt-11-5.sfi
[ 4.442885] Bluetooth: hci0: Failed to send firmware data (-38)
[ 4.606250] Bluetooth: BNEP (Ethernet Emulation) ver 1.3
[ 4.606251] Bluetooth: BNEP filters: protocol multicast
[ 4.606253] Bluetooth: BNEP socket layer initialized
[ 11.766887] Bluetooth: hci0: Bootloader revision 0.0 build 2 week 52 2014
[ 11.771866] Bluetooth: hci0: Device revision is 5
[ 11.771868] Bluetooth: hci0: Secure boot is enabled
[ 11.771868] Bluetooth: hci0: OTP lock is enabled
[ 11.771869] Bluetooth: hci0: API lock is enabled
[ 11.771870] Bluetooth: hci0: Debug lock is disabled
[ 11.771871] Bluetooth: hci0: Minimum firmware build 1 week 10 2014
[ 11.772112] Bluetooth: hci0: Found device firmware: intel/ibt-11-5.sfi
[ 13.478350] Bluetooth: hci0: Waiting for firmware download to complete
[ 13.478830] Bluetooth: hci0: Firmware loaded in 1672625 usecs
[ 13.478898] Bluetooth: hci0: Waiting for device to boot
[ 13.489968] Bluetooth: hci0: Device booted in 10838 usecs
[ 13.490206] Bluetooth: hci0: Found Intel DDC parameters: intel/ibt-11-5.ddc
[ 13.494923] Bluetooth: hci0: Applying Intel DDC parameters completed
[ 18.880056] Bluetooth: RFCOMM TTY layer initialized
[ 18.880062] Bluetooth: RFCOMM socket layer initialized...

description: updated
Revision history for this message
Axel Meunier (axel-meunier) wrote :

Here is full dmesg.
In it there is this bug :

BUG: unable to handle kernel NULL pointer dereference at 0000000000000020

Revision history for this message
Axel Meunier (axel-meunier) wrote :

I also comment on this bug although it is tagged as "expired" :
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1718864

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.