Merge branch 'bugfix/fix_bt_coverity_v5.3' into 'release/v5.3'

bugfix: Fix array compared against 0 in btc_manage.c and the issue of uninitialized pointer reading in coexist_printf (v5.3)

See merge request espressif/esp-idf!42068
This commit is contained in:
Jiang Jiang Jian
2025-10-20 19:24:03 +08:00
2 changed files with 19 additions and 14 deletions
+15 -12
View File
@@ -8,19 +8,20 @@
#include "btc/btc_task.h"
#include "osi/thread.h"
#if BTC_DYNAMIC_MEMORY == FALSE
void *btc_profile_cb_tab[BTC_PID_NUM] = {};
#else
#if BTC_DYNAMIC_MEMORY == TRUE
void **btc_profile_cb_tab;
#else
void *btc_profile_cb_tab[BTC_PID_NUM] = {};
#endif
void esp_profile_cb_reset(void)
{
#if BTC_DYNAMIC_MEMORY == TRUE
if (btc_profile_cb_tab == NULL) {
#if BTC_DYNAMIC_MEMORY == TRUE
void *p = btc_profile_cb_tab;
if (p == NULL) {
return;
}
#endif
#endif
int i;
@@ -31,11 +32,12 @@ void esp_profile_cb_reset(void)
int btc_profile_cb_set(btc_pid_t profile_id, void *cb)
{
#if BTC_DYNAMIC_MEMORY == TRUE
if (btc_profile_cb_tab == NULL) {
#if BTC_DYNAMIC_MEMORY == TRUE
void *p = btc_profile_cb_tab;
if (p == NULL) {
return -1;
}
#endif
#endif
if (profile_id < 0 || profile_id >= BTC_PID_NUM) {
return -1;
@@ -48,11 +50,12 @@ int btc_profile_cb_set(btc_pid_t profile_id, void *cb)
void *btc_profile_cb_get(btc_pid_t profile_id)
{
#if BTC_DYNAMIC_MEMORY == TRUE
if (btc_profile_cb_tab == NULL) {
#if BTC_DYNAMIC_MEMORY == TRUE
void *p = btc_profile_cb_tab;
if (p == NULL) {
return NULL;
}
#endif
#endif
if (profile_id < 0 || profile_id >= BTC_PID_NUM) {
return NULL;
+4 -2
View File
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2016-2024 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2016-2025 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -38,13 +38,15 @@ static int lib_printf(const char* tag, const char* format, va_list arg)
if (i > 0) {
ESP_LOGI(tag, "%s", temp);
}
va_end(arg);
return len;
}
int coexist_printf(const char* format, ...)
{
va_list arg;
/* coverity[uninit_use_in_call]
Event uninit_use_in_call: Using uninitialized value arg when calling __builtin_c23_va_start.
False-positive: arg will be initialized in the function va_start() */
va_start(arg, format);
int res = lib_printf("coexist", format, arg);
va_end(arg);