int mgmt_pin_code_request(u16 index, bdaddr_t *bdaddr, u8 secure);
 int mgmt_pin_code_reply_complete(u16 index, bdaddr_t *bdaddr, u8 status);
 int mgmt_pin_code_neg_reply_complete(u16 index, bdaddr_t *bdaddr, u8 status);
-int mgmt_user_confirm_request(u16 index, bdaddr_t *bdaddr, __le32 value);
+int mgmt_user_confirm_request(u16 index, bdaddr_t *bdaddr, __le32 value,
+                                                       u8 confirm_hint);
 int mgmt_user_confirm_reply_complete(u16 index, bdaddr_t *bdaddr, u8 status);
 int mgmt_user_confirm_neg_reply_complete(u16 index, bdaddr_t *bdaddr,
                                                                u8 status);
 
 #define MGMT_EV_USER_CONFIRM_REQUEST   0x000F
 struct mgmt_ev_user_confirm_request {
        bdaddr_t bdaddr;
+       __u8 confirm_hint;
        __le32 value;
 } __packed;
 
 
                                                        struct sk_buff *skb)
 {
        struct hci_ev_user_confirm_req *ev = (void *) skb->data;
-       int loc_mitm, rem_mitm;
+       int loc_mitm, rem_mitm, confirm_hint = 0;
        struct hci_conn *conn;
 
        BT_DBG("%s", hdev->name);
        /* If no side requires MITM protection; auto-accept */
        if ((!loc_mitm || conn->remote_cap == 0x03) &&
                                (!rem_mitm || conn->io_capability == 0x03)) {
+
+               /* If we're not the initiators request authorization to
+                * proceed from user space (mgmt_user_confirm with
+                * confirm_hint set to 1). */
+               if (!test_bit(HCI_CONN_AUTH_PEND, &conn->pend)) {
+                       BT_DBG("Confirming auto-accept as acceptor");
+                       confirm_hint = 1;
+                       goto confirm;
+               }
+
                BT_DBG("Auto-accept of user confirmation with %ums delay",
                                                hdev->auto_accept_delay);
 
                goto unlock;
        }
 
-       mgmt_user_confirm_request(hdev->id, &ev->bdaddr, ev->passkey);
+confirm:
+       mgmt_user_confirm_request(hdev->id, &ev->bdaddr, ev->passkey,
+                                                               confirm_hint);
 
 unlock:
        hci_dev_unlock(hdev);
 
        return err;
 }
 
-int mgmt_user_confirm_request(u16 index, bdaddr_t *bdaddr, __le32 value)
+int mgmt_user_confirm_request(u16 index, bdaddr_t *bdaddr, __le32 value,
+                                                       u8 confirm_hint)
 {
        struct mgmt_ev_user_confirm_request ev;
 
        BT_DBG("hci%u", index);
 
        bacpy(&ev.bdaddr, bdaddr);
+       ev.confirm_hint = confirm_hint;
        put_unaligned_le32(value, &ev.value);
 
        return mgmt_event(MGMT_EV_USER_CONFIRM_REQUEST, index, &ev, sizeof(ev),