mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 10:40:47 +03:00
fix(bt/bluedroid): fixed potential OOB in Bluedroid
This commit is contained in:
@@ -214,6 +214,55 @@
|
||||
#define AVRC_PDU_ADD_TO_NOW_PLAYING 0x90
|
||||
#define AVRC_PDU_GENERAL_REJECT 0xA0
|
||||
|
||||
/* Define the length of vendor dependent PDUs
|
||||
*/
|
||||
#define AVRC_CMD_PARAM_LENGTH_OFFSET 2
|
||||
#define AVRC_CMD_PARAM_VALUE_OFFSET 4
|
||||
#define AVRC_CMD_FIXED_SIZE 4
|
||||
|
||||
#define AVRC_GET_CAPABILITIES_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 1)
|
||||
#define AVRC_LIST_PLAYER_APP_ATTR_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 0)
|
||||
#define AVRC_LIST_PLAYER_APP_VALUES_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 1)
|
||||
#define AVRC_GET_CUR_PLAYER_APP_VALUE_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 2)
|
||||
#define AVRC_SET_PLAYER_APP_VALUE_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 3)
|
||||
#define AVRC_GET_PLAYER_APP_ATTR_TEXT_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 2)
|
||||
#define AVRC_GET_PLAYER_APP_VALUE_TEXT_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 3)
|
||||
#define AVRC_INFORM_DISPLAY_CHARSET_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 3)
|
||||
#define AVRC_INFORM_BATTERY_STAT_OF_CT_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 1)
|
||||
#define AVRC_GET_ELEMENT_ATTR_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 13)
|
||||
#define AVRC_GET_PLAY_STATUS_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 0)
|
||||
#define AVRC_REGISTER_NOTIFICATION_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 5)
|
||||
#define AVRC_REQUEST_CONTINUATION_RSP_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 1)
|
||||
#define AVRC_ABORT_CONTINUATION_RSP_CMD_SIZE (AVRC_CMD_FIXED_SIZE + 1)
|
||||
|
||||
/* Define the length of response of vendor dependent PDUs
|
||||
*/
|
||||
#define AVRC_RSP_OPCODE_OFFSET 0
|
||||
#define AVRC_RSP_PARAM_LENGTH_OFFSET 2
|
||||
#define AVRC_RSP_PARAM_VALUE_OFFSET 4
|
||||
#define AVRC_RSP_FIXED_SIZE 4
|
||||
|
||||
#define AVRC_GET_CAPABILITIES_RSP_SIZE_MIN (AVRC_RSP_FIXED_SIZE + 1)
|
||||
#define AVRC_LIST_PLAYER_APP_ATTR_RSP_SIZE (AVRC_RSP_FIXED_SIZE + 2)
|
||||
#define AVRC_LIST_PLAYER_APP_VALUES_RSP_SIZE (AVRC_RSP_FIXED_SIZE + 2)
|
||||
#define AVRC_GET_CUR_PLAYER_APP_VALUE_RSP_SIZE (AVRC_RSP_FIXED_SIZE + 3)
|
||||
#define AVRC_SET_PLAYER_APP_VALUE_RSP_SIZE (AVRC_RSP_FIXED_SIZE + 2)
|
||||
#define AVRC_GET_PLAYER_APP_ATTR_TEXT_RSP_SIZE_MIN (AVRC_RSP_FIXED_SIZE + 6)
|
||||
#define AVRC_GET_PLAYER_APP_VALUE_TEXT_RSP_SIZE_MIN (AVRC_RSP_FIXED_SIZE + 6)
|
||||
#define AVRC_INFORM_DISPLAY_CHARSET_RSP_SIZE (AVRC_RSP_FIXED_SIZE + 0)
|
||||
#define AVRC_INFORM_BATTERY_STAT_OF_CT_RSP_SIZE (AVRC_RSP_FIXED_SIZE + 0)
|
||||
#define AVRC_GET_ELEMENT_ATTR_RSP_SIZE_MIN (AVRC_RSP_FIXED_SIZE + 1)
|
||||
#define AVRC_GET_PLAY_STATUS_RSP_SIZE (AVRC_RSP_FIXED_SIZE + 9)
|
||||
#define AVRC_REGISTER_NOTIFICATION_RSP_SIZE_MIN (AVRC_RSP_FIXED_SIZE + 2)
|
||||
#define AVRC_RN_PLAY_STATUS_CHANGE_EVT_SIZE (AVRC_REGISTER_NOTIFICATION_RSP_SIZE_MIN)
|
||||
#define AVRC_RN_TRACK_CHANGE_EVT_SIZE (AVRC_REGISTER_NOTIFICATION_RSP_SIZE_MIN + 7)
|
||||
#define AVRC_RN_PLAY_POS_CHANGED_EVT_SIZE (AVRC_REGISTER_NOTIFICATION_RSP_SIZE_MIN + 3)
|
||||
#define AVRC_RN_BATTERY_STATUS_CHANGE_EVT_SIZE (AVRC_REGISTER_NOTIFICATION_RSP_SIZE_MIN)
|
||||
#define AVRC_RN_SYSTEM_STATUS_CHANGE_EVT_SIZE (AVRC_REGISTER_NOTIFICATION_RSP_SIZE_MIN)
|
||||
#define AVRC_RN_APP_SETTING_CHANGE_EVT_SIZE (AVRC_REGISTER_NOTIFICATION_RSP_SIZE_MIN + 2)
|
||||
#define AVRC_RN_VOLUME_CHANGE_EVT_SIZE (AVRC_REGISTER_NOTIFICATION_RSP_SIZE_MIN)
|
||||
#define AVRC_ABORT_CONTINUATION_RSP_RSP_SIZE (AVRC_RSP_FIXED_SIZE + 0)
|
||||
|
||||
/* Define the vendor unique id carried in the pass through data
|
||||
*/
|
||||
#define AVRC_PDU_NEXT_GROUP 0x00
|
||||
|
||||
@@ -42,7 +42,7 @@
|
||||
#define RFCOMM_UIH 0xEF
|
||||
|
||||
/*
|
||||
** Defenitions for the TS control frames
|
||||
** Definitions for the TS control frames
|
||||
*/
|
||||
#define RFCOMM_CTRL_FRAME_LEN 3
|
||||
#define RFCOMM_MIN_OFFSET 5 /* ctrl 2 , len 1 or 2 bytes, credit 1 byte */
|
||||
@@ -90,13 +90,6 @@
|
||||
pf = (*p_data++ & RFCOMM_PF_MASK) >> RFCOMM_PF_OFFSET;\
|
||||
}
|
||||
|
||||
#define RFCOMM_PARSE_LEN_FIELD(ea, length, p_data) \
|
||||
{ \
|
||||
ea = (*p_data & RFCOMM_EA); \
|
||||
length = (*p_data++ >> RFCOMM_SHIFT_LENGTH1); \
|
||||
if (!ea) length += (*p_data++ << RFCOMM_SHIFT_LENGTH2); \
|
||||
}
|
||||
|
||||
#define RFCOMM_FRAME_IS_CMD(initiator, cr) \
|
||||
(( (initiator) && !(cr)) || (!(initiator) && (cr)))
|
||||
|
||||
@@ -139,7 +132,7 @@
|
||||
#define RFCOMM_MSC_FC 0x02 /* Flow control*/
|
||||
#define RFCOMM_MSC_RTC 0x04 /* Ready to communicate*/
|
||||
#define RFCOMM_MSC_RTR 0x08 /* Ready to receive*/
|
||||
#define RFCOMM_MSC_IC 0x40 /* Incomming call indicator*/
|
||||
#define RFCOMM_MSC_IC 0x40 /* Incoming call indicator*/
|
||||
#define RFCOMM_MSC_DV 0x80 /* Data Valid*/
|
||||
|
||||
#define RFCOMM_MSC_SHIFT_BREAK 4
|
||||
|
||||
@@ -96,8 +96,8 @@ typedef struct {
|
||||
UINT8 u8; /* 8-bit integer */
|
||||
UINT16 u16; /* 16-bit integer */
|
||||
UINT32 u32; /* 32-bit integer */
|
||||
UINT8 array[4]; /* Variable length field */
|
||||
struct t_sdp_disc_attr *p_sub_attr; /* Addr of first sub-attr (list)*/
|
||||
UINT8 array[]; /* Variable length field */
|
||||
} v;
|
||||
|
||||
} tSDP_DISC_ATVAL;
|
||||
|
||||
Reference in New Issue
Block a user