Hi Dean, >>> If this is an issue in 4.10, then lets get this fixed / hardened. >>> >> >> If I manage to produce some more useful results then I will post them. >> > > I have now managed to crash the h4 Data Link protocol layer via hci_uart_tty_close(). > > This confirms that there is a design flaw in hci_uart_tty_close() which is independent of the Bluetooth Data Link protocol layers. > > I don't have a Bluetooth Radio Module that uses h4 protocol so I used my BCSP enabled Bluetooth Radio Module that has a USB to serial interface. I realise that this is a weird setup but it is OK for this testcase because we need the h4 protocol to be timing out for transmissions. Also the BCSP Bluetooth Radio Module may send BCSP frames which will exercise the h4 receive path although rejection of the frames should occur which is as expected. can you send me a patch set with my minor comments addressed. Then I have another look at it. Regards Marcel -- To unsubscribe from this list: send the line "unsubscribe linux-bluetooth" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html