Skip to content

hci_bcm4377: Repeated HCI command tx timeouts and transfer ring failures during A2DP streaming (BCM4378, M1 MacBook Air) #604

Description

@areofyl

The BCM4378 Bluetooth chip randomly becomes unresponsive during A2DP audio streaming, causing audio static/crackling. HCI commands time out, all transfer and completion rings fail to destroy, and the driver has to reset the chip. This happens multiple times per session during normal use (no suspend involved).

Hardware

  • Apple MacBook Air (M1, 2020): J313
  • Bluetooth chip: BCM4378 (PCIe 0000:01:00.1, shared with WiFi on 0000:01:00.0)
  • Firmware: brcmbt4378b1-apple,shikoku-m

Software

  • Kernel: 7.1.6-asahi-fairydust+ (driver source identical to 7.1.8-asahi)
  • BlueZ 5.87
  • PipeWire 1.6.8 + WirePlumber
  • Audio profile: A2DP Sink (SBC codec)
  • Connected device: AirPods Pro

Symptoms

  1. After ~20-60 minutes of A2DP audio streaming, audio becomes static/crackly
  2. bluetoothctl power off often fails to communicate with the chip
  3. Only modprobe -r hci_bcm4377 && modprobe hci_bcm4377 recovers it
  4. Pausing and resuming playback sometimes temporarily recovers audio
  5. Occurs during normal streaming meaning it isn't triggered by suspend/resume

dmesg

The pattern repeats multiple times per boot. HCI_Reset (0x0c01) times out, followed by all transfer and completion rings failing to destroy, then the driver resets the chip:

First occurrence (~56 min after boot):

[ 3394.089521] Bluetooth: hci0: command 0x0c01 tx timeout
[ 3394.089540] Bluetooth: hci0: Opcode 0x0c01 failed: -110
[ 3396.105546] Bluetooth: hci0: command 0x0c01 tx timeout
[ 3396.105551] Bluetooth: hci0: Opcode 0x0c1a failed: -110
[ 3397.289573] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 6
[ 3398.313574] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 5
[ 3399.337558] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 4
[ 3400.361569] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 3
[ 3401.389594] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 2
[ 3402.409599] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 1
[ 3403.433640] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 4
[ 3404.461646] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 3
[ 3405.481667] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 2
[ 3406.509643] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 1
[ 3408.547573] hci_bcm4377 0000:01:00.1: resetting
[ 3408.653781] hci_bcm4377 0000:01:00.1: reset done

Second occurrence (~3.5 hr after boot):

[12612.235989] Bluetooth: hci0: command 0x0c01 tx timeout
[12612.235996] Bluetooth: hci0: Opcode 0x0c01 failed: -110
[12614.252059] Bluetooth: hci0: Opcode 0x0c1a failed: -110
[12614.252066] Bluetooth: hci0: command 0x0c01 tx timeout
[12615.440098] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 6
[12616.460125] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 5
[12617.484161] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 4
[12618.508194] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 3
[12619.532205] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 2
[12620.556240] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 1
[12621.580275] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 4
[12622.604317] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 3
[12623.628351] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 2
[12624.652390] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 1
[12626.698742] hci_bcm4377 0000:01:00.1: resetting
[12626.804524] hci_bcm4377 0000:01:00.1: reset done

Third occurrence (~4.2 hr after boot):

[15150.748563] Bluetooth: hci0: Opcode 0x0c01 failed: -110
[15150.748573] Bluetooth: hci0: command 0x0c01 tx timeout
[15150.748588] Bluetooth: hci0: Opcode 0x0c1a failed: -110
[15151.932572] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 6
[15152.960579] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 5
[15153.980594] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 4
[15155.004606] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 3
[15156.028640] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 2
[15157.052638] hci_bcm4377 0000:01:00.1: failed to destroy transfer ring 1
[15158.076683] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 4
[15159.101060] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 3
[15160.124734] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 2
[15161.148738] hci_bcm4377 0000:01:00.1: failed to destroy completion ring 1
[15163.190843] hci_bcm4377 0000:01:00.1: resetting
[15163.296899] hci_bcm4377 0000:01:00.1: reset done

All three occurred during active A2DP streaming without any suspend/resume.

WiFi crash precedes every Bluetooth crash

Every Bluetooth timeout is preceded by WiFi (brcmfmac) errors 2-3 seconds earlier. The WiFi side of the shared BCM4378 chip crashes first, taking Bluetooth down with it:

[12608.909950] ieee80211 phy0: brcmf_notify_escan_complete: Scan abort failed
[12608.974359] ieee80211 phy0: brcmf_cfg80211_escan_handler: scan not ready, bsscfgidx=0
[12608.974367] ieee80211 phy0: brcmf_fweh_event_worker: event handler failed (69)
[12609.342967] ieee80211 phy0: brcmf_cfg80211_escan_handler: scan not ready, bsscfgidx=0
[12609.342978] ieee80211 phy0: brcmf_fweh_event_worker: event handler failed (69)
[12610.119852] apple-pmgr-pwrstate 23b700000.power-management:power-controller@1e0: PS fpwm1: Failed to reach power state 0xf (now: 0x80f)
[12612.235989] Bluetooth: hci0: command 0x0c01 tx timeout

This pattern repeats for all three occurrences. The Bluetooth timeout appears to be a side effect of the WiFi firmware crashing on the shared PCIe device, not an independent Bluetooth driver issue.

Mitigations tried (none fully resolve it)

  • Disabled PCIe D3cold (d3cold_allowed=0) via udev which had no effect on this issue
  • PCIe runtime PM already set to on
  • WiFi on 5GHz (channel 48) to avoid 2.4GHz coexistence
  • Disabled HFP/HSP profiles in WirePlumber
  • Driver source is identical between 7.1.6-fairydust and 7.1.8-asahi

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions