mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
fix(bt): Fix the critical issues related to AVRCP from AI review report
- recalculate len_left per attribute in avrc_bld_app_setting_text_rsp - abort fragmented message reassembly when reassembly buffer alloc fails
This commit is contained in:
@@ -435,18 +435,17 @@ static UINT8 avrc_proc_far_msg(UINT8 handle, UINT8 label, UINT8 cr, BT_HDR **pp_
|
|||||||
/* Free original START packet, replace with pointer to reassembly buffer */
|
/* Free original START packet, replace with pointer to reassembly buffer */
|
||||||
osi_free(p_pkt);
|
osi_free(p_pkt);
|
||||||
*pp_pkt = p_rcb->p_rmsg;
|
*pp_pkt = p_rcb->p_rmsg;
|
||||||
} else {
|
|
||||||
/* Unable to allocate buffer for fragmented avrc message. Reuse START
|
|
||||||
buffer for reassembly (re-assembled message may fit into ACL buf) */
|
|
||||||
AVRC_TRACE_DEBUG ("Unable to allocate buffer for fragmented avrc message, \
|
|
||||||
reusing START buffer for reassembly");
|
|
||||||
p_rcb->rasm_offset = p_pkt->offset;
|
|
||||||
p_rcb->p_rmsg = p_pkt;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* set offset to point to where to copy next - use the same re-asm logic as AVCT */
|
/* set offset to point to where to copy next - use the same re-asm logic as AVCT */
|
||||||
p_rcb->p_rmsg->offset += p_rcb->p_rmsg->len;
|
p_rcb->p_rmsg->offset += p_rcb->p_rmsg->len;
|
||||||
req_continue = TRUE;
|
req_continue = TRUE;
|
||||||
|
} else {
|
||||||
|
/* do not reuse START buffer; it is smaller than BT_DEFAULT_BUFFER_SIZE */
|
||||||
|
AVRC_TRACE_ERROR("Unable to allocate buffer for fragmented avrc message");
|
||||||
|
drop_code = 5;
|
||||||
|
osi_free(p_pkt);
|
||||||
|
*pp_pkt = NULL;
|
||||||
|
}
|
||||||
} else if (p_rcb->p_rmsg == NULL) {
|
} else if (p_rcb->p_rmsg == NULL) {
|
||||||
/* Received a CONTINUE/END, but no corresponding START
|
/* Received a CONTINUE/END, but no corresponding START
|
||||||
(or previous fragmented response was dropped) */
|
(or previous fragmented response was dropped) */
|
||||||
|
|||||||
@@ -314,12 +314,6 @@ static tAVRC_STS avrc_bld_app_setting_text_rsp (tAVRC_GET_APP_ATTR_TXT_RSP *p_rs
|
|||||||
p_start = (UINT8 *)(p_pkt + 1) + p_pkt->offset;
|
p_start = (UINT8 *)(p_pkt + 1) + p_pkt->offset;
|
||||||
p_data = p_len = p_start + 2; /* pdu + rsvd */
|
p_data = p_len = p_start + 2; /* pdu + rsvd */
|
||||||
|
|
||||||
/*
|
|
||||||
* NOTE: The buffer is allocated within avrc_bld_init_rsp_buffer(), and is
|
|
||||||
* always of size BT_DEFAULT_BUFFER_SIZE.
|
|
||||||
*/
|
|
||||||
len_left = BT_DEFAULT_BUFFER_SIZE - BT_HDR_SIZE - p_pkt->offset - p_pkt->len;
|
|
||||||
|
|
||||||
BE_STREAM_TO_UINT16(len, p_data);
|
BE_STREAM_TO_UINT16(len, p_data);
|
||||||
p_count = p_data;
|
p_count = p_data;
|
||||||
|
|
||||||
@@ -331,6 +325,7 @@ static tAVRC_STS avrc_bld_app_setting_text_rsp (tAVRC_GET_APP_ATTR_TXT_RSP *p_rs
|
|||||||
}
|
}
|
||||||
|
|
||||||
for (xx = 0; xx < p_rsp->num_attr; xx++) {
|
for (xx = 0; xx < p_rsp->num_attr; xx++) {
|
||||||
|
len_left = (UINT16)(((UINT8 *)p_pkt + BT_DEFAULT_BUFFER_SIZE) - p_data);
|
||||||
if (len_left < (p_rsp->p_attrs[xx].str_len + 4)) {
|
if (len_left < (p_rsp->p_attrs[xx].str_len + 4)) {
|
||||||
AVRC_TRACE_ERROR("avrc_bld_app_setting_text_rsp out of room %d(str_len:%d, left:%d)",
|
AVRC_TRACE_ERROR("avrc_bld_app_setting_text_rsp out of room %d(str_len:%d, left:%d)",
|
||||||
xx, p_rsp->p_attrs[xx].str_len, len_left);
|
xx, p_rsp->p_attrs[xx].str_len, len_left);
|
||||||
|
|||||||
Reference in New Issue
Block a user