fix(bt): Fix the critical issues related to AVRCP from AI review report

- recalculate len_left per attribute in avrc_bld_app_setting_text_rsp
- abort fragmented message reassembly when reassembly buffer alloc fails
This commit is contained in:
yangfeng
2026-06-25 14:42:06 +08:00
parent a6928be465
commit 37b55f4ca5
2 changed files with 11 additions and 17 deletions
@@ -435,18 +435,17 @@ static UINT8 avrc_proc_far_msg(UINT8 handle, UINT8 label, UINT8 cr, BT_HDR **pp_
/* Free original START packet, replace with pointer to reassembly buffer */
osi_free(p_pkt);
*pp_pkt = p_rcb->p_rmsg;
} else {
/* Unable to allocate buffer for fragmented avrc message. Reuse START
buffer for reassembly (re-assembled message may fit into ACL buf) */
AVRC_TRACE_DEBUG ("Unable to allocate buffer for fragmented avrc message, \
reusing START buffer for reassembly");
p_rcb->rasm_offset = p_pkt->offset;
p_rcb->p_rmsg = p_pkt;
}
/* set offset to point to where to copy next - use the same re-asm logic as AVCT */
p_rcb->p_rmsg->offset += p_rcb->p_rmsg->len;
req_continue = TRUE;
/* set offset to point to where to copy next - use the same re-asm logic as AVCT */
p_rcb->p_rmsg->offset += p_rcb->p_rmsg->len;
req_continue = TRUE;
} else {
/* do not reuse START buffer; it is smaller than BT_DEFAULT_BUFFER_SIZE */
AVRC_TRACE_ERROR("Unable to allocate buffer for fragmented avrc message");
drop_code = 5;
osi_free(p_pkt);
*pp_pkt = NULL;
}
} else if (p_rcb->p_rmsg == NULL) {
/* Received a CONTINUE/END, but no corresponding START
(or previous fragmented response was dropped) */
@@ -314,12 +314,6 @@ static tAVRC_STS avrc_bld_app_setting_text_rsp (tAVRC_GET_APP_ATTR_TXT_RSP *p_rs
p_start = (UINT8 *)(p_pkt + 1) + p_pkt->offset;
p_data = p_len = p_start + 2; /* pdu + rsvd */
/*
* NOTE: The buffer is allocated within avrc_bld_init_rsp_buffer(), and is
* always of size BT_DEFAULT_BUFFER_SIZE.
*/
len_left = BT_DEFAULT_BUFFER_SIZE - BT_HDR_SIZE - p_pkt->offset - p_pkt->len;
BE_STREAM_TO_UINT16(len, p_data);
p_count = p_data;
@@ -331,6 +325,7 @@ static tAVRC_STS avrc_bld_app_setting_text_rsp (tAVRC_GET_APP_ATTR_TXT_RSP *p_rs
}
for (xx = 0; xx < p_rsp->num_attr; xx++) {
len_left = (UINT16)(((UINT8 *)p_pkt + BT_DEFAULT_BUFFER_SIZE) - p_data);
if (len_left < (p_rsp->p_attrs[xx].str_len + 4)) {
AVRC_TRACE_ERROR("avrc_bld_app_setting_text_rsp out of room %d(str_len:%d, left:%d)",
xx, p_rsp->p_attrs[xx].str_len, len_left);