Merge branch 'bugfix/fix_bluedroid_static_random_conn_rpa_v5.5' into 'release/v5.5'

fix(ble/bluedroid): skip identity conversion for static random direct connect (5.5)

See merge request espressif/esp-idf!50084
This commit is contained in:
Island
2026-07-20 21:39:24 +08:00
41 changed files with 440 additions and 226 deletions
@@ -2393,7 +2393,7 @@ void btm_read_channel_map_complete(UINT8 *p)
memcpy(results.rem_bda, p_acl_cb->remote_addr, BD_ADDR_LEN);
}
} else {
results.status = BTM_ERR_PROCESSING;
results.status = BTM_HCI_ERROR | results.hci_status;
BTM_TRACE_ERROR("BTM Channel Map Read Failed: hci status 0x%02x", results.hci_status);
}
@@ -2990,26 +2990,47 @@ uint8_t btm_ble_scan_active_count(void)
return count;
}
#if (BLE_INCLUDED == TRUE)
#if (SMP_INCLUDED == TRUE)
extern bool btc_config_has_section(const char *section);
#endif
uint8_t btm_ble_sec_dev_record_count(void)
{
tBTM_SEC_DEV_REC *p_dev_rec = NULL;
list_node_t *p_node = NULL;
uint8_t count = 0;
/* First look for the non-paired devices for the oldest entry */
for (p_node = list_begin(btm_cb.p_sec_dev_rec_list); p_node; p_node = list_next(p_node)) {
p_dev_rec = list_node(p_node);
#if (SMP_INCLUDED == TRUE)
if (p_dev_rec && (p_dev_rec->sec_flags & BTM_SEC_IN_USE) && (p_dev_rec->ble.key_type != BTM_LE_KEY_NONE)) {
BTM_TRACE_DEBUG("%s BLE security device #%d: bd_addr=%02X:%02X:%02X:%02X:%02X:%02X",
#else
if (p_dev_rec && (p_dev_rec->sec_flags & BTM_SEC_IN_USE)) {
#endif
#if (SMP_INCLUDED == TRUE)
/* Check if device exists in NVS */
char bdstr[18] = {0};
bdaddr_to_string((bt_bdaddr_t *)p_dev_rec->bd_addr, bdstr, sizeof(bdstr));
BTM_TRACE_WARNING("%s device #%d: "MACSTR", key_type=0x%02x (PENC:%d PID:%d PCSRK:%d LENC:%d LID:%d LCSRK:%d), in_nvs=%d",
__func__,
count,
p_dev_rec->bd_addr[0],
p_dev_rec->bd_addr[1],
p_dev_rec->bd_addr[2],
p_dev_rec->bd_addr[3],
p_dev_rec->bd_addr[4],
p_dev_rec->bd_addr[5]);
MAC2STR(p_dev_rec->bd_addr),
p_dev_rec->ble.key_type,
(p_dev_rec->ble.key_type & BTM_LE_KEY_PENC) ? 1 : 0,
(p_dev_rec->ble.key_type & BTM_LE_KEY_PID) ? 1 : 0,
(p_dev_rec->ble.key_type & BTM_LE_KEY_PCSRK) ? 1 : 0,
(p_dev_rec->ble.key_type & BTM_LE_KEY_LENC) ? 1 : 0,
(p_dev_rec->ble.key_type & BTM_LE_KEY_LID) ? 1 : 0,
(p_dev_rec->ble.key_type & BTM_LE_KEY_LCSRK) ? 1 : 0,
btc_config_has_section(bdstr));
#else
BTM_TRACE_WARNING("%s device #%d: "MACSTR,
__func__,
count,
MAC2STR(p_dev_rec->bd_addr));
#endif
count++;
}
}
@@ -251,24 +251,6 @@ tBTM_STATUS BTM_BleSetExtendedAdvParams(UINT8 instance, tBTM_BLE_GAP_EXT_ADV_PAR
goto end;
}
if (params->type & BTM_BLE_GAP_SET_EXT_ADV_PROP_CONNECTABLE) {
extend_adv_cb.inst[instance].connetable = true;
} else {
extend_adv_cb.inst[instance].connetable = false;
}
if (params->type & BTM_BLE_GAP_SET_EXT_ADV_PROP_SCANNABLE) {
extend_adv_cb.inst[instance].scannable = true;
} else {
extend_adv_cb.inst[instance].scannable = false;
}
if (params->type & BTM_BLE_GAP_SET_EXT_ADV_PROP_LEGACY) {
extend_adv_cb.inst[instance].legacy_pdu = true;
} else {
extend_adv_cb.inst[instance].legacy_pdu = false;
}
#if (CONTROLLER_RPA_LIST_ENABLE == FALSE)
// if own_addr_type == BLE_ADDR_PUBLIC_ID or BLE_ADDR_RANDOM_ID,
if((params->own_addr_type == BLE_ADDR_PUBLIC_ID || params->own_addr_type == BLE_ADDR_RANDOM_ID) && BTM_GetLocalResolvablePrivateAddr(rand_addr)) {
@@ -305,6 +287,31 @@ tBTM_STATUS BTM_BleSetExtendedAdvParams(UINT8 instance, tBTM_BLE_GAP_EXT_ADV_PAR
}
#endif // (BT_BLE_FEAT_ADV_CODING_SELECTION == TRUE)
if (params->type & BTM_BLE_GAP_SET_EXT_ADV_PROP_CONNECTABLE) {
extend_adv_cb.inst[instance].connetable = true;
} else {
extend_adv_cb.inst[instance].connetable = false;
}
if (params->type & BTM_BLE_GAP_SET_EXT_ADV_PROP_SCANNABLE) {
extend_adv_cb.inst[instance].scannable = true;
} else {
extend_adv_cb.inst[instance].scannable = false;
}
if (params->type & BTM_BLE_GAP_SET_EXT_ADV_PROP_LEGACY) {
extend_adv_cb.inst[instance].legacy_pdu = true;
} else {
extend_adv_cb.inst[instance].legacy_pdu = false;
}
if (params->type & (BTM_BLE_GAP_SET_EXT_ADV_PROP_DIRECTED |
BTM_BLE_GAP_SET_EXT_ADV_PROP_HD_DIRECTED)) {
extend_adv_cb.inst[instance].directed = true;
} else {
extend_adv_cb.inst[instance].directed = false;
}
extend_adv_cb.inst[instance].configured = true;
/* Record the post-fallback on-air address type for per-set conn_addr fixup. */
extend_adv_cb.inst[instance].own_addr_type = params->own_addr_type;
@@ -1117,15 +1117,17 @@ tBTM_STATUS BTM_BleStartAdvWithParams(UINT16 adv_int_min, UINT16 adv_int_max, UI
tBTM_STATUS status = BTM_SUCCESS;
/* update adv params */
if (btsnd_hcic_ble_write_adv_params (adv_int_min,
UINT8 hci_status = btsnd_hcic_ble_write_adv_params (adv_int_min,
adv_int_max,
adv_type,
own_bda_type,
p_dir_bda->type,
p_dir_bda->bda,
chnl_map,
p_cb->afp) != HCI_SUCCESS) {
status = BTM_NO_RESOURCES;
p_cb->afp);
if (hci_status != HCI_SUCCESS) {
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
status = btm_ble_status_from_hci(hci_status);
}
osi_mutex_unlock(&btm_lock);
@@ -1175,13 +1177,13 @@ tBTM_STATUS BTM_BleSetScanFilterParams(tGATT_IF client_if, UINT32 scan_interval,
(scan_mode == BTM_BLE_SCAN_MODE_ACTI || scan_mode == BTM_BLE_SCAN_MODE_PASS) &&
(scan_duplicate_filter < BTM_BLE_SCAN_DUPLICATE_MAX) && (scan_window <= scan_interval)) {
if ((btsnd_hcic_ble_set_scan_params(scan_mode, (UINT16)scan_interval,
(UINT16)scan_window,
addr_type_own,
scan_filter_policy)) != HCI_SUCCESS) {
ret = BTM_ILLEGAL_VALUE;
BTM_TRACE_ERROR("Illegal params: scan_interval = %d scan_window = %d\n",
scan_interval, scan_window);
UINT8 hci_status = btsnd_hcic_ble_set_scan_params(scan_mode, (UINT16)scan_interval,
(UINT16)scan_window,
addr_type_own,
scan_filter_policy);
if (hci_status != HCI_SUCCESS) {
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
ret = btm_ble_status_from_hci(hci_status);
} else {
p_cb->scan_type = scan_mode;
p_cb->scan_interval = scan_interval;
@@ -1232,8 +1234,10 @@ tBTM_STATUS BTM_BleWriteScanRsp(tBTM_BLE_AD_MASK data_mask, tBTM_BLE_ADV_DATA *p
BTM_TRACE_WARNING("%s, Partial data write into ADV", __func__);
}
if (btsnd_hcic_ble_set_scan_rsp_data((UINT8)(p - rsp_data), rsp_data) != HCI_SUCCESS) {
ret = BTM_ILLEGAL_VALUE;
UINT8 hci_status = btsnd_hcic_ble_set_scan_rsp_data((UINT8)(p - rsp_data), rsp_data);
if (hci_status != HCI_SUCCESS) {
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
ret = btm_ble_status_from_hci(hci_status);
btm_cb.ble_ctr_cb.inq_var.scan_rsp = FALSE;
} else {
ret = BTM_SUCCESS;
@@ -1265,8 +1269,10 @@ tBTM_STATUS BTM_BleWriteScanRspRaw(UINT8 *p_raw_scan_rsp, UINT32 raw_scan_rsp_le
tBTM_STATUS ret = BTM_SUCCESS;
osi_mutex_lock(&btm_lock, OSI_MUTEX_MAX_TIMEOUT);
if (btsnd_hcic_ble_set_scan_rsp_data((UINT8)raw_scan_rsp_len, p_raw_scan_rsp) != HCI_SUCCESS) {
ret = BTM_NO_RESOURCES;
UINT8 hci_status = btsnd_hcic_ble_set_scan_rsp_data((UINT8)raw_scan_rsp_len, p_raw_scan_rsp);
if (hci_status != HCI_SUCCESS) {
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
ret = btm_ble_status_from_hci(hci_status);
}
osi_mutex_unlock(&btm_lock);
@@ -1377,9 +1383,11 @@ tBTM_STATUS BTM_BleWriteAdvData(tBTM_BLE_AD_MASK data_mask, tBTM_BLE_ADV_DATA *p
p_cb_data->data_mask &= ~mask;
if ((btsnd_hcic_ble_set_adv_data((UINT8)(p_cb_data->p_pad - p_cb_data->ad_data),
p_cb_data->ad_data)) != HCI_SUCCESS) {
ret = BTM_NO_RESOURCES;
UINT8 hci_status = btsnd_hcic_ble_set_adv_data((UINT8)(p_cb_data->p_pad - p_cb_data->ad_data),
p_cb_data->ad_data);
if (hci_status != HCI_SUCCESS) {
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
ret = btm_ble_status_from_hci(hci_status);
}
osi_mutex_unlock(&btm_lock);
return ret;
@@ -1400,8 +1408,10 @@ tBTM_STATUS BTM_BleWriteAdvDataRaw(UINT8 *p_raw_adv, UINT32 raw_adv_len)
{
tBTM_STATUS ret = BTM_SUCCESS;
osi_mutex_lock(&btm_lock, OSI_MUTEX_MAX_TIMEOUT);
if ((btsnd_hcic_ble_set_adv_data((UINT8)raw_adv_len, p_raw_adv)) != HCI_SUCCESS) {
ret = BTM_NO_RESOURCES;
UINT8 hci_status = btsnd_hcic_ble_set_adv_data((UINT8)raw_adv_len, p_raw_adv);
if (hci_status != HCI_SUCCESS) {
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
ret = btm_ble_status_from_hci(hci_status);
}
osi_mutex_unlock(&btm_lock);
@@ -2065,15 +2075,17 @@ tBTM_STATUS btm_ble_set_discoverability(UINT16 combined_mode)
#endif // #if (BLE_42_ADV_EN == TRUE)
/* update adv params */
if (btsnd_hcic_ble_write_adv_params (adv_int_min,
UINT8 hci_status = btsnd_hcic_ble_write_adv_params (adv_int_min,
adv_int_max,
evt_type,
own_addr_type,
init_addr_type,
p_addr_ptr,
p_cb->adv_chnl_map,
p_cb->afp) != HCI_SUCCESS) {
status = BTM_NO_RESOURCES;
p_cb->afp);
if (hci_status != HCI_SUCCESS) {
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
status = btm_ble_status_from_hci(hci_status);
} else {
p_cb->evt_type = evt_type;
p_cb->adv_addr_type = own_addr_type;
@@ -2163,15 +2175,17 @@ tBTM_STATUS btm_ble_set_connectability(UINT16 combined_mode)
btm_ble_stop_adv();
#endif // #if (BLE_42_ADV_EN == TRUE)
if (btsnd_hcic_ble_write_adv_params (adv_int_min,
UINT8 hci_status = btsnd_hcic_ble_write_adv_params (adv_int_min,
adv_int_max,
evt_type,
own_addr_type,
peer_addr_type,
p_addr_ptr,
p_cb->adv_chnl_map,
p_cb->afp) != HCI_SUCCESS) {
status = BTM_NO_RESOURCES;
p_cb->afp);
if (hci_status != HCI_SUCCESS) {
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
status = btm_ble_status_from_hci(hci_status);
} else {
p_cb->evt_type = evt_type;
p_cb->adv_addr_type = own_addr_type;
@@ -3241,8 +3255,10 @@ tBTM_STATUS btm_ble_start_scan(void)
p_inq->scan_duplicate_filter = BTM_BLE_DUPLICATE_DISABLE;
}
/* start scan, disable duplicate filtering */
if ((btsnd_hcic_ble_set_scan_enable (BTM_BLE_SCAN_ENABLE, p_inq->scan_duplicate_filter)) != HCI_SUCCESS) {
status = BTM_NO_RESOURCES;
UINT8 hci_status = btsnd_hcic_ble_set_scan_enable (BTM_BLE_SCAN_ENABLE, p_inq->scan_duplicate_filter);
if (hci_status != HCI_SUCCESS) {
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
status = btm_ble_status_from_hci(hci_status);
} else {
btm_cb.ble_ctr_cb.inq_var.state |= BTM_BLE_SCANNING;
#if (BLE_TOPOLOGY_CHECK == TRUE)
@@ -3312,8 +3328,10 @@ static tBTM_STATUS btm_ble_stop_discover(void)
/* Clear the inquiry callback if set */
btm_cb.ble_ctr_cb.inq_var.state &= ~BTM_BLE_SCANNING;
/* stop discovery now */
if (btsnd_hcic_ble_set_scan_enable (BTM_BLE_SCAN_DISABLE, BTM_BLE_DUPLICATE_ENABLE) != HCI_SUCCESS) {
status = BTM_NO_RESOURCES;
UINT8 hci_status = btsnd_hcic_ble_set_scan_enable (BTM_BLE_SCAN_DISABLE, BTM_BLE_DUPLICATE_ENABLE);
if (hci_status != HCI_SUCCESS) {
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
status = btm_ble_status_from_hci(hci_status);
}
#if (BLE_TOPOLOGY_CHECK == TRUE)
/* reset status */
@@ -3428,8 +3446,10 @@ tBTM_STATUS btm_ble_start_adv(void)
#if (BLE_TOPOLOGY_CHECK == TRUE)
btm_ble_adv_states_operation(btm_ble_set_topology_mask, p_cb->evt_type);
#endif // (BLE_TOPOLOGY_CHECK == TRUE)
if (btsnd_hcic_ble_set_adv_enable (BTM_BLE_ADV_ENABLE) != HCI_SUCCESS) {
rt = BTM_NO_RESOURCES;
UINT8 hci_status = btsnd_hcic_ble_set_adv_enable (BTM_BLE_ADV_ENABLE);
if (hci_status != HCI_SUCCESS) {
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
rt = btm_ble_status_from_hci(hci_status);
p_cb->state = temp_state;
p_cb->adv_mode = adv_mode;
#if (BLE_TOPOLOGY_CHECK == TRUE)
@@ -3472,7 +3492,8 @@ tBTM_STATUS btm_ble_stop_adv(void)
/* clear all adv states */
btm_ble_clear_topology_mask (BTM_BLE_STATE_ALL_ADV_MASK);
#endif // (BLE_TOPOLOGY_CHECK == TRUE)
if (btsnd_hcic_ble_set_adv_enable (BTM_BLE_ADV_DISABLE) != HCI_SUCCESS) {
UINT8 hci_status = btsnd_hcic_ble_set_adv_enable (BTM_BLE_ADV_DISABLE);
if (hci_status != HCI_SUCCESS) {
// reset state
p_cb->fast_adv_on = temp_fast_adv_on;
p_cb->adv_mode = temp_adv_mode;
@@ -3481,7 +3502,8 @@ tBTM_STATUS btm_ble_stop_adv(void)
#if (BLE_TOPOLOGY_CHECK == TRUE)
btm_ble_set_topology_mask (temp_mask);
#endif // (BLE_TOPOLOGY_CHECK == TRUE)
rt = BTM_NO_RESOURCES;
BTM_BLE_TRACE_HCI_CMD_FAIL(__func__, hci_status);
rt = btm_ble_status_from_hci(hci_status);
}
if(rt != HCI_SUCCESS) {
p_cb->adv_mode = temp_adv_mode;
@@ -1327,12 +1327,8 @@ void btm_ble_set_channels_complete (UINT8 *p)
case HCI_SUCCESS:
cb_params.set_channels.status = BTM_SUCCESS;
break;
case HCI_ERR_UNSUPPORTED_VALUE:
case HCI_ERR_ILLEGAL_PARAMETER_FMT:
cb_params.set_channels.status = BTM_ILLEGAL_VALUE;
break;
default:
cb_params.set_channels.status = BTM_ERR_PROCESSING;
cb_params.set_channels.status = BTM_HCI_ERROR | cb_params.set_channels.hci_status;
break;
}
BTM_LegacyBleCallbackTrigger(BTM_BLE_LEGACY_GAP_SET_CHANNELS_COMPLETE_EVT, &cb_params);
@@ -628,6 +628,14 @@ void btm_ble_cs_subevt_result_evt(tBTM_BLE_CS_SUBEVT_RESULT_CMPL_EVT *subevt_res
void btm_ble_cs_subevt_continue_result_evt(tBTM_BLE_CS_SUBEVT_RESULT_CONTINUE_EVT *subevt_continue_result);
#endif // (BT_BLE_FEAT_CHANNEL_SOUNDING == TRUE)
static inline tBTM_STATUS btm_ble_status_from_hci(UINT8 hci_status)
{
return (hci_status == HCI_SUCCESS) ? BTM_SUCCESS : (tBTM_STATUS)(BTM_HCI_ERROR | hci_status);
}
#define BTM_BLE_TRACE_HCI_CMD_FAIL(func, hci_status) \
BTM_TRACE_ERROR("%s, fail to send the hci command, the error code = 0x%x", (func), (hci_status))
/*
#ifdef __cplusplus
@@ -983,6 +983,20 @@ static void btu_hcif_disconnection_comp_evt (UINT8 *p)
handle = HCID_GET_HANDLE (handle);
#if BLE_INCLUDED == TRUE
/* Capture the disconnecting device's address before btm_acl_disconnected()
* clears the matched connection handle. The record itself is re-looked-up
* afterwards (by address) because callbacks fired during disconnection may
* have already freed it. */
BD_ADDR disc_bda;
BOOLEAN have_disc_bda = FALSE;
tBTM_SEC_DEV_REC *p_dev_rec = btm_find_dev_by_handle(handle);
if (p_dev_rec) {
memcpy(disc_bda, p_dev_rec->bd_addr, BD_ADDR_LEN);
have_disc_bda = TRUE;
}
#endif
dev_find = btm_acl_disconnected(handle, reason);
#if (BLE_FEAT_ISO_CIG_EN == TRUE)
@@ -995,6 +1009,48 @@ static void btu_hcif_disconnection_comp_evt (UINT8 *p)
HCI_TRACE_WARNING("hcif disc complete: hdl 0x%x, rsn 0x%x dev_find %d", handle, reason, dev_find);
UNUSED(dev_find);
#if BLE_INCLUDED == TRUE
/* Delete unpaired device records to free memory (~356B per device).
*
* Re-find the record by address: callbacks invoked during
* btm_acl_disconnected() may already have freed it, so the pointer captured
* before the call cannot be trusted.
*
* Only delete when the device is fully idle and unpaired:
* 1. No active BR/EDR connection (hci_handle invalid)
* 2. No active LE connection (ble_hci_handle invalid) - protects the still
* connected transport of a dual-mode device when the other one drops
* 3. No BLE security keys (unpaired) - when SMP is enabled
*
* BT_TRANSPORT_LE is used so that any retained BR/EDR link key keeps a
* BR/EDR-bonded record alive; an LE-unpaired record that has no BR/EDR key
* collapses to BTM_SEC_IN_USE only and is removed from the list.
*
* Skip deletion on HCI_ERR_CONN_FAILED_ESTABLISHMENT when connect
* retry is enabled.
*/
if (have_disc_bda
#if (GATTC_CONNECT_RETRY_EN == TRUE)
&& reason != HCI_ERR_CONN_FAILED_ESTABLISHMENT
#endif
) {
p_dev_rec = btm_find_dev(disc_bda);
if (p_dev_rec
&& p_dev_rec->hci_handle == BTM_SEC_INVALID_HANDLE /* No active BR/EDR connection */
&& p_dev_rec->ble_hci_handle == BTM_SEC_INVALID_HANDLE /* No active LE connection */
#if SMP_INCLUDED == TRUE
&& !p_dev_rec->ble.key_type /* No BLE security keys */
#endif
) {
BTM_TRACE_WARNING(
"Deleting unpaired device %02X:%02X:%02X:%02X:%02X:%02X",
p_dev_rec->bd_addr[0], p_dev_rec->bd_addr[1], p_dev_rec->bd_addr[2],
p_dev_rec->bd_addr[3], p_dev_rec->bd_addr[4], p_dev_rec->bd_addr[5]);
btm_sec_free_dev(p_dev_rec, BT_TRANSPORT_LE);
}
}
#endif // BLE_INCLUDED == TRUE
}
/*******************************************************************************
@@ -1913,6 +1969,11 @@ static void btu_hcif_command_status_evt(uint8_t status, BT_HDR *command, void *c
{
BT_HDR *event = osi_calloc(sizeof(BT_HDR) + sizeof(command_status_hack_t));
command_status_hack_t *hack = (command_status_hack_t *)&event->data[0];
#if ((BLE_50_FEATURE_SUPPORT == TRUE) || (BLE_42_FEATURE_SUPPORT == TRUE))
if (status != HCI_SUCCESS) {
btsnd_hci_ble_set_status(status);
}
#endif // #if ((BLE_50_FEATURE_SUPPORT == TRUE) || (BLE_42_FEATURE_SUPPORT == TRUE))
hack->callback = btu_hcif_command_status_evt_on_task;
hack->status = status;
@@ -571,6 +571,11 @@ void gatt_process_error_rsp(tGATT_TCB *p_tcb, tGATT_CLCB *p_clcb, UINT8 op_code,
STREAM_TO_UINT16(handle, p);
STREAM_TO_UINT8(reason, p);
/* 0x00 is not a valid ATT error code; treat as unknown error. */
if (reason == GATT_SUCCESS) {
reason = GATT_UNKNOWN_ERROR;
}
if (p_clcb->operation == GATTC_OPTYPE_DISCOVERY) {
gatt_proc_disc_error_rsp(p_tcb, p_clcb, opcode, handle, reason);
} else {
@@ -579,9 +584,6 @@ void gatt_process_error_rsp(tGATT_TCB *p_tcb, tGATT_CLCB *p_clcb, UINT8 op_code,
(opcode == GATT_REQ_PREPARE_WRITE) &&
(p_attr) &&
(handle == p_attr->handle) ) {
if (reason == GATT_SUCCESS){
reason = GATT_ERROR;
}
p_clcb->status = reason;
gatt_send_queue_write_cancel(p_tcb, p_clcb, GATT_PREP_WRITE_CANCEL);
} else if ((p_clcb->operation == GATTC_OPTYPE_READ) &&
@@ -891,7 +893,11 @@ void gatt_process_read_by_type_rsp (tGATT_TCB *p_tcb, tGATT_CLCB *p_clcb, UINT8
/* value_len is the length of current record's value; use it to avoid overread when multiple records present */
p_clcb->counter = value_len;
p_clcb->s_handle = handle;
if ( p_clcb->counter == (p_clcb->p_tcb->payload_size - 4)) {
UINT16 max_rbtype_val_len = (p_clcb->p_tcb->payload_size - 4);
if (max_rbtype_val_len > GATT_MAX_READ_BY_TYPE_VALUE_LEN) {
max_rbtype_val_len = GATT_MAX_READ_BY_TYPE_VALUE_LEN;
}
if (p_clcb->counter == max_rbtype_val_len) {
p_clcb->op_subtype = GATT_READ_BY_HANDLE;
if (!p_clcb->p_attr_buf) {
p_clcb->p_attr_buf = (UINT8 *)osi_malloc(GATT_MAX_ATTR_LEN);
@@ -370,7 +370,13 @@ tGATT_STATUS gatts_db_read_attr_value_by_type (tGATT_TCB *p_tcb,
UINT16_TO_STREAM (p, p_attr->handle);
status = read_attr_value ((void *)p_attr, 0, &p, FALSE, (UINT16)(*p_len - 2), &len, sec_flag, key_size);
{
UINT16 max_val_len = (UINT16)(*p_len - 2);
if (max_val_len > GATT_MAX_READ_BY_TYPE_VALUE_LEN) {
max_val_len = GATT_MAX_READ_BY_TYPE_VALUE_LEN;
}
status = read_attr_value ((void *)p_attr, 0, &p, FALSE, max_val_len, &len, sec_flag, key_size);
}
if (status == GATT_PENDING) {
+117 -58
View File
@@ -148,6 +148,66 @@ void gatt_dequeue_sr_cmd (tGATT_TCB *p_tcb)
memset( &p_tcb->sr_cmd, 0, sizeof(tGATT_SR_CMD));
}
/*******************************************************************************
**
** Function gatt_find_multi_rsp_by_handle
**
** Description Find a read-multiple response entry by attribute handle.
** occurrence selects the Nth matching entry (for duplicate
** handles in the same request).
**
** Returns Pointer to response, or NULL if not found
**
*******************************************************************************/
static tGATTS_RSP *gatt_find_multi_rsp_by_handle(tGATT_SR_CMD *p_cmd, UINT16 handle,
UINT16 occurrence)
{
list_t *list;
const list_node_t *node;
UINT16 match_count = 0;
if (p_cmd->multi_rsp_q == NULL || fixed_queue_is_empty(p_cmd->multi_rsp_q)) {
return NULL;
}
list = fixed_queue_get_list(p_cmd->multi_rsp_q);
for (node = list_begin(list); node != list_end(list); node = list_next(node)) {
tGATTS_RSP *p_rsp = (tGATTS_RSP *)list_node(node);
if (p_rsp->attr_value.handle == handle) {
if (match_count == occurrence) {
return p_rsp;
}
match_count++;
}
}
return NULL;
}
/*******************************************************************************
**
** Function gatt_get_multi_handle_occurrence
**
** Description Return occurrence index of handle at multi_req index.
**
** Returns occurrence count
**
*******************************************************************************/
static UINT16 gatt_get_multi_handle_occurrence(tGATT_SR_CMD *p_cmd, UINT16 index)
{
UINT16 ii;
UINT16 occurrence = 0;
for (ii = 0; ii < index; ii++) {
if (p_cmd->multi_req.handles[ii] == p_cmd->multi_req.handles[index]) {
occurrence++;
}
}
return occurrence;
}
/*******************************************************************************
**
** Function process_read_multi_rsp
@@ -206,24 +266,12 @@ static BOOLEAN process_read_multi_rsp (tGATT_SR_CMD *p_cmd, tGATT_STATUS status,
*p++ = GATT_RSP_READ_MULTI;
p_buf->len = 1;
/* Now walk through the buffers putting the data into the response in order */
list_t *list = NULL;
const list_node_t *node = NULL;
if (! fixed_queue_is_empty(p_cmd->multi_rsp_q)) {
list = fixed_queue_get_list(p_cmd->multi_rsp_q);
}
/* Walk request handles in order; match responses by handle because
* stack (sync) and app (async) replies may arrive out of order. */
for (ii = 0; ii < p_cmd->multi_req.num_handles; ii++) {
tGATTS_RSP *p_rsp = NULL;
if (list != NULL) {
if (ii == 0) {
node = list_begin(list);
} else {
node = list_next(node);
}
if (node != list_end(list)) {
p_rsp = (tGATTS_RSP *)list_node(node);
}
}
tGATTS_RSP *p_rsp = gatt_find_multi_rsp_by_handle(
p_cmd, p_cmd->multi_req.handles[ii],
gatt_get_multi_handle_occurrence(p_cmd, ii));
if (p_rsp != NULL) {
@@ -238,16 +286,11 @@ static BOOLEAN process_read_multi_rsp (tGATT_SR_CMD *p_cmd, tGATT_STATUS status,
len = p_rsp->attr_value.len;
}
if (p_rsp->attr_value.handle == p_cmd->multi_req.handles[ii]) {
memcpy (p, p_rsp->attr_value.value, len);
if (!is_overflow) {
p += len;
}
p_buf->len += len;
} else {
p_cmd->status = GATT_NOT_FOUND;
break;
memcpy (p, p_rsp->attr_value.value, len);
if (!is_overflow) {
p += len;
}
p_buf->len += len;
if (is_overflow) {
break;
@@ -262,7 +305,7 @@ static BOOLEAN process_read_multi_rsp (tGATT_SR_CMD *p_cmd, tGATT_STATUS status,
/* Sanity check on the buffer length */
if (p_buf->len == 0) {
if (p_buf->len <= 1) {
GATT_TRACE_ERROR("process_read_multi_rsp - nothing found!!");
p_cmd->status = GATT_NOT_FOUND;
osi_free (p_buf);
@@ -333,24 +376,11 @@ static BOOLEAN process_read_multi_var_rsp (tGATT_SR_CMD *p_cmd, tGATT_STATUS sta
*p++ = GATT_RSP_READ_MULTI_VAR;
p_buf->len = 1;
/* Now walk through the buffers putting the data into the response in order */
list_t *list = NULL;
const list_node_t *node = NULL;
if (! fixed_queue_is_empty(p_cmd->multi_rsp_q)) {
list = fixed_queue_get_list(p_cmd->multi_rsp_q);
}
/* Match responses by handle; replies may arrive out of order. */
for (ii = 0; ii < p_cmd->multi_req.num_handles; ii++) {
tGATTS_RSP *p_rsp = NULL;
if (list != NULL) {
if (ii == 0) {
node = list_begin(list);
} else {
node = list_next(node);
}
if (node != list_end(list)) {
p_rsp = (tGATTS_RSP *)list_node(node);
}
}
tGATTS_RSP *p_rsp = gatt_find_multi_rsp_by_handle(
p_cmd, p_cmd->multi_req.handles[ii],
gatt_get_multi_handle_occurrence(p_cmd, ii));
if (p_rsp != NULL) {
@@ -362,16 +392,11 @@ static BOOLEAN process_read_multi_var_rsp (tGATT_SR_CMD *p_cmd, tGATT_STATUS sta
}
len = MIN(p_rsp->attr_value.len, (mtu - total_len)); // attribute value length
if (p_rsp->attr_value.handle == p_cmd->multi_req.handles[ii]) {
GATT_TRACE_DEBUG("%s handle %x len %u", __func__, p_rsp->attr_value.handle, p_rsp->attr_value.len);
UINT16_TO_STREAM(p, p_rsp->attr_value.len);
memcpy (p, p_rsp->attr_value.value, len);
p += len;
p_buf->len += (2+len);
} else {
p_cmd->status = GATT_NOT_FOUND;
break;
}
GATT_TRACE_DEBUG("%s handle %x len %u", __func__, p_rsp->attr_value.handle, p_rsp->attr_value.len);
UINT16_TO_STREAM(p, p_rsp->attr_value.len);
memcpy (p, p_rsp->attr_value.value, len);
p += len;
p_buf->len += (2+len);
} else {
p_cmd->status = GATT_NOT_FOUND;
break;
@@ -380,7 +405,7 @@ static BOOLEAN process_read_multi_var_rsp (tGATT_SR_CMD *p_cmd, tGATT_STATUS sta
} /* loop through all handles*/
/* Sanity check on the buffer length */
if (p_buf->len == 0) {
if (p_buf->len <= 1) {
GATT_TRACE_ERROR("%s - nothing found!!", __func__);
p_cmd->status = GATT_NOT_FOUND;
osi_free (p_buf);
@@ -414,6 +439,27 @@ tGATT_STATUS gatt_sr_process_app_rsp (tGATT_TCB *p_tcb, tGATT_IF gatt_if,
UINT32 trans_id, UINT8 op_code,
tGATT_STATUS status, tGATTS_RSP *p_msg)
{
if ((p_tcb->exec_write_rsp_trans_id == trans_id) && (op_code == GATT_REQ_EXEC_WRITE)) {
/*
* Execute Write is a special case without a handle, so both stack and application
* may try to send a response.
* - Stack: may have already sent an automatic Execute Write Response.
* - App: may call esp_gatts_send_response() with the same trans_id.
*
* To prevent sending two responses for the same Execute Write request,
* we check if this trans_id has already been auto-responded by stack.
* If so, ignore the application response without sending another ATT packet.
* Still update cback_cnt/dequeue sr_cmd so state stays consistent when multiple
* apps are registered; only clear exec_write_rsp_trans_id after all apps respond.
*/
gatt_sr_update_cback_cnt(p_tcb, gatt_if, FALSE, FALSE);
if (gatt_sr_is_cback_cnt_zero(p_tcb)) {
gatt_dequeue_sr_cmd(p_tcb);
p_tcb->exec_write_rsp_trans_id = 0;
}
return GATT_SUCCESS;
}
tGATT_STATUS ret_code = GATT_SUCCESS;
UNUSED(trans_id);
@@ -455,10 +501,12 @@ tGATT_STATUS gatt_sr_process_app_rsp (tGATT_TCB *p_tcb, tGATT_IF gatt_if,
ret_code = attp_send_sr_msg (p_tcb, p_tcb->sr_cmd.p_rsp_msg);
p_tcb->sr_cmd.p_rsp_msg = NULL;
} else {
if (p_tcb->sr_cmd.status == GATT_SUCCESS){
status = GATT_UNKNOWN_ERROR;
tGATT_STATUS err_status = p_tcb->sr_cmd.status;
if (err_status == GATT_SUCCESS) {
err_status = GATT_UNKNOWN_ERROR;
}
ret_code = gatt_send_error_rsp (p_tcb, status, op_code, p_tcb->sr_cmd.handle, FALSE);
ret_code = gatt_send_error_rsp (p_tcb, err_status, op_code, p_tcb->sr_cmd.handle, FALSE);
}
gatt_dequeue_sr_cmd(p_tcb);
@@ -481,6 +529,7 @@ tGATT_STATUS gatt_sr_process_app_rsp (tGATT_TCB *p_tcb, tGATT_IF gatt_if,
*******************************************************************************/
void gatt_process_exec_write_req (tGATT_TCB *p_tcb, UINT8 op_code, UINT16 len, UINT8 *p_data)
{
BOOLEAN response_sent = false;
UINT8 *p = p_data, flag, i = 0;
UINT32 trans_id = 0;
tGATT_IF gatt_if;
@@ -536,6 +585,7 @@ void gatt_process_exec_write_req (tGATT_TCB *p_tcb, UINT8 op_code, UINT16 len, U
is_prepare_write_valid = TRUE;
}
GATT_TRACE_DEBUG("Send execute_write_rsp\n");
response_sent = TRUE;
} else if ((prepare_record->error_code_app == GATT_SUCCESS) &&
(prepare_record->total_num > queue_num)){
//No error for stack_rsp's handles and there exist some app_rsp's handles,
@@ -580,6 +630,10 @@ void gatt_process_exec_write_req (tGATT_TCB *p_tcb, UINT8 op_code, UINT16 len, U
trans_id = gatt_sr_enqueue_cmd(p_tcb, op_code, 0);
gatt_sr_copy_prep_cnt_to_cback_cnt(p_tcb);
}
/* Record trans_id if stack already sent response, to prevent app from sending duplicate */
if (response_sent) {
p_tcb->exec_write_rsp_trans_id = trans_id;
}
for (i = 0; i < GATT_MAX_APPS; i++) {
if (p_tcb->prep_cnt[i]) {
gatt_if = (tGATT_IF) (i + 1);
@@ -657,6 +711,11 @@ void gatt_process_exec_write_req (tGATT_TCB *p_tcb, UINT8 op_code, UINT16 len, U
gatt_sr_copy_prep_cnt_to_cback_cnt(p_tcb);
}
/* Record trans_id if stack already sent response, to prevent app from sending duplicate */
if (response_sent) {
p_tcb->exec_write_rsp_trans_id = trans_id;
}
for (i = 0; i < GATT_MAX_APPS; i++) {
if (p_tcb->prep_cnt[i]) {
gatt_if = (tGATT_IF) (i + 1);
@@ -76,6 +76,10 @@ typedef UINT8 tGATT_SEC_ACTION;
#define GATT_HDR_SIZE 3 /* 1B opcode + 2B handle */
/* ATT Read By Type Response: Length field is 1 octet (max 255). */
#define GATT_MAX_READ_BY_TYPE_PAIR_LEN 255
#define GATT_MAX_READ_BY_TYPE_VALUE_LEN (GATT_MAX_READ_BY_TYPE_PAIR_LEN - 2)
/**
* Wait for ATT cmd response timeout value (40 seconds).
* The max connection supervision timeout is 32 seconds,
@@ -421,6 +425,7 @@ typedef struct {
UINT8 tcb_idx;
#if (GATTS_INCLUDED == TRUE)
tGATT_PREPARE_WRITE_RECORD prepare_write_record; /* prepare write packets record */
UINT32 exec_write_rsp_trans_id; /* trans_id of auto-responded execute write */
#endif // (GATTS_INCLUDED == TRUE)
} tGATT_TCB;
@@ -147,40 +147,42 @@ BOOLEAN L2CA_UpdateBleConnParams (BD_ADDR rem_bda, UINT16 min_int, UINT16 max_in
/* See if we have a link control block for the remote device */
p_lcb = l2cu_find_lcb_by_bd_addr (rem_bda, BT_TRANSPORT_LE);
/* If we don't have one, create one and accept the connection. */
if (!p_lcb || !p_acl_cb) {
L2CAP_TRACE_WARNING ("L2CA_UpdateBleConnParams - unknown BD_ADDR "MACSTR"", MAC2STR(rem_bda));
return (FALSE);
}
if (p_lcb->transport != BT_TRANSPORT_LE) {
status = HCI_ERR_NO_CONNECTION;
need_cb = true;
} else if (p_lcb->transport != BT_TRANSPORT_LE) {
L2CAP_TRACE_WARNING ("L2CA_UpdateBleConnParams - BD_ADDR "MACSTR" not LE", MAC2STR(rem_bda));
return (FALSE);
}
/* Check whether the request conn params is already set */
if ((max_int == p_lcb->current_used_conn_interval) && (latency == p_lcb->current_used_conn_latency) &&
(timeout == p_lcb->current_used_conn_timeout)) {
status = HCI_SUCCESS;
status = HCI_ERR_NO_CONNECTION;
need_cb = true;
L2CAP_TRACE_WARNING("%s connection parameter already set", __func__);
}
} else {
/* Check whether the request conn params is already set */
if ((max_int == p_lcb->current_used_conn_interval) && (latency == p_lcb->current_used_conn_latency) &&
(timeout == p_lcb->current_used_conn_timeout)) {
status = HCI_SUCCESS;
need_cb = true;
L2CAP_TRACE_WARNING("%s connection parameter already set", __func__);
}
if (p_lcb->conn_update_mask & L2C_BLE_UPDATE_PARAM_FULL){
status = HCI_ERR_ILLEGAL_COMMAND;
need_cb = true;
L2CAP_TRACE_ERROR("%s connection parameter update in progress, please try later", __func__);
if (p_lcb->conn_update_mask & L2C_BLE_UPDATE_PARAM_FULL){
status = HCI_ERR_ILLEGAL_COMMAND;
need_cb = true;
L2CAP_TRACE_ERROR("%s connection parameter update in progress, please try later", __func__);
}
}
if (need_cb) {
tBTM_BLE_LEGACY_GAP_CB_PARAMS cb_params = {0};
cb_params.conn_params_update.status = status;
memcpy(cb_params.conn_params_update.remote_bd_addr, p_lcb->remote_bd_addr, BD_ADDR_LEN);
memcpy(cb_params.conn_params_update.remote_bd_addr,
p_lcb ? p_lcb->remote_bd_addr : rem_bda, BD_ADDR_LEN);
cb_params.conn_params_update.min_conn_int = min_int;
cb_params.conn_params_update.max_conn_int = max_int;
cb_params.conn_params_update.conn_int = p_lcb->current_used_conn_interval;
cb_params.conn_params_update.slave_latency = p_lcb->current_used_conn_latency;
cb_params.conn_params_update.supervision_tout = p_lcb->current_used_conn_timeout;
if (p_lcb) {
cb_params.conn_params_update.conn_int = p_lcb->current_used_conn_interval;
cb_params.conn_params_update.slave_latency = p_lcb->current_used_conn_latency;
cb_params.conn_params_update.supervision_tout = p_lcb->current_used_conn_timeout;
}
BTM_LegacyBleCallbackTrigger(BTM_BLE_LEGACY_GAP_CONNECTION_PARAMS_UPDATE_EVT, &cb_params);
@@ -993,12 +995,14 @@ BOOLEAN l2cble_init_direct_conn (tL2C_LCB *p_lcb)
#if (CONTROLLER_RPA_LIST_ENABLE)
if (p_dev_rec->ble.in_controller_list & BTM_RESOLVING_LIST_BIT) {
if (btm_cb.ble_ctr_cb.privacy_mode >= BTM_PRIVACY_1_2) {
own_addr_type |= BLE_ADDR_TYPE_ID_BIT;
}
if (!(peer_addr_type == BLE_ADDR_RANDOM && !BTM_BLE_IS_RESOLVE_BDA(peer_addr))) {
if (btm_cb.ble_ctr_cb.privacy_mode >= BTM_PRIVACY_1_2) {
own_addr_type |= BLE_ADDR_TYPE_ID_BIT;
}
//btm_ble_enable_resolving_list(BTM_BLE_RL_INIT);
btm_random_pseudo_to_identity_addr(peer_addr, &peer_addr_type);
//btm_ble_enable_resolving_list(BTM_BLE_RL_INIT);
btm_random_pseudo_to_identity_addr(peer_addr, &peer_addr_type);
}
} else {
btm_ble_disable_resolving_list(BTM_BLE_RL_INIT, TRUE);
}
@@ -1793,7 +1793,7 @@ UINT32 smp_calculate_g2(UINT8 *u, UINT8 *v, UINT8 *x, UINT8 *y)
smp_debug_print_nbyte_little_endian (p_prnt, (const UINT8 *)"cmac mod 2**32 mod 10**6", 4);
#endif
SMP_TRACE_ERROR("Value for numeric comparison = %d", vres);
SMP_TRACE_WARNING("Value for numeric comparison = %d", vres);
return vres;
}