mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(bt): Fix the high issues related to AVRCP from AI review report
- SDP/registration: handle SDP record creation and discovery failures safely - AVRC stack: fix packet checks, fragment leaks, response build, and compile guards - BTC AVRCP: fix return codes, connection state, metadata parsing, and memory leaks - AVCTP: fix event passing, L2CAP conflicts, TX queue leaks, and disconnect handling - Example: remove TG RN capability setup before initialization
This commit is contained in:
@@ -118,6 +118,9 @@ void AVCT_Deregister(void)
|
||||
|
||||
/* deregister PSM with L2CAP */
|
||||
L2CA_Deregister(AVCT_PSM);
|
||||
#if (AVCT_BROWSE_INCLUDED == TRUE)
|
||||
L2CA_Deregister(AVCT_BR_PSM);
|
||||
#endif
|
||||
}
|
||||
|
||||
/*******************************************************************************
|
||||
@@ -173,9 +176,14 @@ UINT16 AVCT_CreateConn(UINT8 *p_handle, tAVCT_CC *p_cc, BD_ADDR peer_addr)
|
||||
|
||||
if (result == AVCT_SUCCESS) {
|
||||
/* bind lcb to ccb */
|
||||
tAVCT_LCB_EVT evt;
|
||||
p_ccb->p_lcb = p_lcb;
|
||||
AVCT_TRACE_DEBUG("ch_state: %d", p_lcb->ch_state);
|
||||
avct_lcb_event(p_lcb, AVCT_LCB_UL_BIND_EVT, (tAVCT_LCB_EVT *) &p_ccb);
|
||||
evt.p_ccb = p_ccb;
|
||||
avct_lcb_event(p_lcb, AVCT_LCB_UL_BIND_EVT, &evt);
|
||||
if (!p_ccb->allocated) {
|
||||
result = AVCT_NOT_OPEN;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -212,7 +220,9 @@ UINT16 AVCT_RemoveConn(UINT8 handle)
|
||||
}
|
||||
/* send unbind event to lcb */
|
||||
else {
|
||||
avct_lcb_event(p_ccb->p_lcb, AVCT_LCB_UL_UNBIND_EVT, (tAVCT_LCB_EVT *) &p_ccb);
|
||||
tAVCT_LCB_EVT evt;
|
||||
evt.p_ccb = p_ccb;
|
||||
avct_lcb_event(p_ccb->p_lcb, AVCT_LCB_UL_UNBIND_EVT, &evt);
|
||||
}
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -234,6 +234,9 @@ void avct_l2c_config_cfm_cback(UINT16 lcid, tL2CAP_CFG_INFO *p_cfg)
|
||||
if ((p_lcb = avct_lcb_by_lcid(lcid)) != NULL) {
|
||||
AVCT_TRACE_DEBUG("avct_l2c_config_cfm_cback: 0x%x, ch_state: %d, res: %d",
|
||||
lcid, p_lcb->ch_state, p_cfg->result);
|
||||
if (p_lcb->conflict_lcid == lcid) {
|
||||
return;
|
||||
}
|
||||
/* if in correct state */
|
||||
if (p_lcb->ch_state == AVCT_CH_CFG) {
|
||||
/* if result successful */
|
||||
@@ -294,6 +297,10 @@ void avct_l2c_config_ind_cback(UINT16 lcid, tL2CAP_CFG_INFO *p_cfg)
|
||||
p_cfg->result = L2CAP_CFG_OK;
|
||||
L2CA_ConfigRsp(lcid, p_cfg);
|
||||
|
||||
if (p_lcb->conflict_lcid == lcid) {
|
||||
return;
|
||||
}
|
||||
|
||||
/* if first config ind */
|
||||
if ((p_lcb->ch_flags & AVCT_L2C_CFG_IND_DONE) == 0) {
|
||||
/* update flags */
|
||||
@@ -322,7 +329,7 @@ void avct_l2c_config_ind_cback(UINT16 lcid, tL2CAP_CFG_INFO *p_cfg)
|
||||
void avct_l2c_disconnect_ind_cback(UINT16 lcid, BOOLEAN ack_needed)
|
||||
{
|
||||
tAVCT_LCB *p_lcb;
|
||||
UINT16 result = AVCT_RESULT_FAIL;
|
||||
tAVCT_LCB_EVT evt;
|
||||
|
||||
/* look up lcb for this channel */
|
||||
if ((p_lcb = avct_lcb_by_lcid(lcid)) != NULL) {
|
||||
@@ -332,7 +339,13 @@ void avct_l2c_disconnect_ind_cback(UINT16 lcid, BOOLEAN ack_needed)
|
||||
L2CA_DisconnectRsp(lcid);
|
||||
}
|
||||
|
||||
avct_lcb_event(p_lcb, AVCT_LCB_LL_CLOSE_EVT, (tAVCT_LCB_EVT *) &result);
|
||||
if (p_lcb->conflict_lcid == lcid) {
|
||||
p_lcb->conflict_lcid = 0;
|
||||
return;
|
||||
}
|
||||
|
||||
evt.result = AVCT_RESULT_FAIL;
|
||||
avct_lcb_event(p_lcb, AVCT_LCB_LL_CLOSE_EVT, &evt);
|
||||
AVCT_TRACE_DEBUG("ch_state di: %d ", p_lcb->ch_state);
|
||||
}
|
||||
}
|
||||
@@ -356,6 +369,10 @@ void avct_l2c_disconnect_cfm_cback(UINT16 lcid, UINT16 result)
|
||||
if ((p_lcb = avct_lcb_by_lcid(lcid)) != NULL) {
|
||||
AVCT_TRACE_DEBUG("avct_l2c_disconnect_cfm_cback: 0x%x, ch_state: %d, res: %d",
|
||||
lcid, p_lcb->ch_state, result);
|
||||
if (p_lcb->conflict_lcid == lcid) {
|
||||
p_lcb->conflict_lcid = 0;
|
||||
return;
|
||||
}
|
||||
/* result value may be previously stored */
|
||||
res = (p_lcb->ch_result != 0) ? p_lcb->ch_result : result;
|
||||
p_lcb->ch_result = 0;
|
||||
|
||||
@@ -364,7 +364,7 @@ void avct_lcb_dealloc(tAVCT_LCB *p_lcb, tAVCT_LCB_EVT *p_data)
|
||||
|
||||
AVCT_TRACE_DEBUG("%s Freeing LCB", __func__);
|
||||
osi_free(p_lcb->p_rx_msg);
|
||||
fixed_queue_free(p_lcb->tx_q, NULL);
|
||||
fixed_queue_free(p_lcb->tx_q, osi_free_func);
|
||||
memset(p_lcb, 0, sizeof(tAVCT_LCB));
|
||||
}
|
||||
|
||||
|
||||
@@ -425,7 +425,12 @@ void avct_lcb_chnl_disc(tAVCT_LCB *p_lcb, tAVCT_LCB_EVT *p_data)
|
||||
{
|
||||
UNUSED(p_data);
|
||||
|
||||
L2CA_DisconnectReq(p_lcb->ch_lcid);
|
||||
tAVCT_LCB_EVT evt;
|
||||
|
||||
if (!L2CA_DisconnectReq(p_lcb->ch_lcid)) {
|
||||
evt.result = AVCT_RESULT_FAIL;
|
||||
avct_lcb_event(p_lcb, AVCT_LCB_LL_CLOSE_EVT, &evt);
|
||||
}
|
||||
}
|
||||
|
||||
/*******************************************************************************
|
||||
@@ -474,6 +479,7 @@ void avct_lcb_cong_ind(tAVCT_LCB *p_lcb, tAVCT_LCB_EVT *p_data)
|
||||
if (L2CA_DataWrite(p_lcb->ch_lcid, p_buf) == L2CAP_DW_CONGESTED)
|
||||
{
|
||||
p_lcb->cong = TRUE;
|
||||
event = AVCT_CONG_IND_EVT;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user