fix(ble/bluedroid): fix GATT server lifecycle and callbacks

This commit is contained in:
zhiweijian
2026-05-29 10:15:02 +08:00
parent 653477c3e9
commit 54a1e31916
10 changed files with 446 additions and 131 deletions
@@ -171,7 +171,7 @@ void gatt_sec_check_complete(BOOLEAN sec_check_ok, tGATT_CLCB *p_clcb, UINT8 s
void gatt_enc_cmpl_cback(BD_ADDR bd_addr, tBT_TRANSPORT transport, void *p_ref_data, tBTM_STATUS result)
{
tGATT_TCB *p_tcb;
UINT8 sec_flag;
UINT8 sec_flag = 0;
BOOLEAN status = FALSE;
UNUSED(p_ref_data);
@@ -185,9 +185,8 @@ void gatt_enc_cmpl_cback(BD_ADDR bd_addr, tBT_TRANSPORT transport, void *p_ref_d
if (p_buf != NULL) {
if (result == BTM_SUCCESS) {
if (gatt_get_sec_act(p_tcb) == GATT_SEC_ENCRYPT_MITM ) {
BTM_GetSecurityFlagsByTransport(bd_addr, &sec_flag, transport);
if (sec_flag & BTM_SEC_FLAG_LKEY_AUTHED) {
if (BTM_GetSecurityFlagsByTransport(bd_addr, &sec_flag, transport) &&
(sec_flag & BTM_SEC_FLAG_LKEY_AUTHED)) {
status = TRUE;
}
} else {
@@ -305,7 +304,7 @@ tGATT_SEC_ACTION gatt_get_sec_act(tGATT_TCB *p_tcb)
tGATT_SEC_ACTION gatt_determine_sec_act(tGATT_CLCB *p_clcb )
{
tGATT_SEC_ACTION act = GATT_SEC_OK;
UINT8 sec_flag;
UINT8 sec_flag = 0;
tGATT_TCB *p_tcb = p_clcb->p_tcb;
tGATT_AUTH_REQ auth_req = p_clcb->auth_req;
BOOLEAN is_link_encrypted = FALSE;
@@ -754,8 +754,7 @@ void gatt_process_read_multi_req (tGATT_TCB *p_tcb, UINT8 op_code, UINT16 len, U
for (ll = 0; ll < p_tcb->sr_cmd.multi_req.num_handles; ll ++) {
if ((p_msg = (tGATTS_RSP *)osi_malloc(sizeof(tGATTS_RSP))) != NULL) {
memset(p_msg, 0, sizeof(tGATTS_RSP))
;
memset(p_msg, 0, sizeof(tGATTS_RSP));
handle = p_tcb->sr_cmd.multi_req.handles[ll];
i_rcb = gatt_sr_find_i_rcb_by_handle(handle);
@@ -1496,10 +1495,17 @@ void gatt_attr_process_prepare_write (tGATT_TCB *p_tcb, UINT8 i_rcb, UINT16 hand
}
}
/* sr_cmd enqueued at handle but no attribute branch ran (null DB/list or no exact handle). */
if (trans_id != 0 && !is_need_prepare_write_rsp && !is_need_queue_data &&
status == GATT_SUCCESS) {
status = GATT_INVALID_HANDLE;
}
if (is_need_queue_data){
queue_data = (tGATT_PREPARE_WRITE_QUEUE_DATA *)osi_malloc(len + sizeof(tGATT_PREPARE_WRITE_QUEUE_DATA));
if (queue_data == NULL){
status = GATT_PREPARE_Q_FULL;
is_need_prepare_write_rsp = FALSE;
} else {
queue_data->p_attr = p_attr_temp;
queue_data->len = len;
@@ -1509,7 +1515,16 @@ void gatt_attr_process_prepare_write (tGATT_TCB *p_tcb, UINT8 i_rcb, UINT16 hand
if (prepare_record->queue == NULL) {
prepare_record->queue = fixed_queue_new(QUEUE_SIZE_MAX);
}
fixed_queue_enqueue(prepare_record->queue, queue_data, FIXED_QUEUE_MAX_TIMEOUT);
if (prepare_record->queue == NULL ||
fixed_queue_length(prepare_record->queue) >=
fixed_queue_capacity(prepare_record->queue)) {
osi_free(queue_data);
queue_data = NULL;
status = GATT_PREPARE_Q_FULL;
is_need_prepare_write_rsp = FALSE;
} else {
fixed_queue_enqueue(prepare_record->queue, queue_data, FIXED_QUEUE_MAX_TIMEOUT);
}
}
}
@@ -690,6 +690,9 @@ BOOLEAN gatt_add_an_item_to_list(tGATT_HDL_LIST_INFO *p_list, tGATT_HDL_LIST_ELE
p_new->p_prev = p_old->p_prev;
p_new->p_next = p_old;
if (p_old->p_prev != NULL) {
p_old->p_prev->p_next = p_new;
}
p_old->p_prev = p_new;
break;
@@ -1231,6 +1234,10 @@ BOOLEAN gatt_parse_uuid_from_cmd(tBT_UUID *p_uuid_rec, UINT16 uuid_size, UINT8 *
void gatt_start_rsp_timer(UINT16 clcb_idx)
{
tGATT_CLCB *p_clcb = gatt_clcb_find_by_idx(clcb_idx);
if (p_clcb == NULL) {
GATT_TRACE_ERROR("%s: no CLCB for clcb_idx=0x%x", __func__, clcb_idx);
return;
}
p_clcb->rsp_timer_ent.param = (TIMER_PARAM_TYPE)p_clcb;
btu_start_timer (&p_clcb->rsp_timer_ent, BTU_TTYPE_ATT_WAIT_FOR_RSP,
GATT_WAIT_FOR_RSP_TOUT);
@@ -2305,10 +2312,17 @@ void gatt_cleanup_upon_disc(BD_ADDR bda, UINT16 reason, tBT_TRANSPORT transport)
UINT8 i;
UINT16 conn_id;
tGATT_REG *p_reg = NULL;
#if (GATTS_INCLUDED == TRUE)
BD_ADDR bda_local;
#endif
GATT_TRACE_DEBUG ("gatt_cleanup_upon_disc ");
#if (GATTS_INCLUDED == TRUE)
/* Copy in case bda points into p_tcb->peer_bda, which is invalid after gatt_tcb_free. */
memcpy(bda_local, bda, BD_ADDR_LEN);
#endif
if ((p_tcb = gatt_find_tcb_by_addr(bda, transport)) != NULL) {
GATT_TRACE_DEBUG ("found p_tcb ");
gatt_set_ch_state(p_tcb, GATT_CH_CLOSE);
@@ -2357,7 +2371,7 @@ void gatt_cleanup_upon_disc(BD_ADDR bda, UINT16 reason, tBT_TRANSPORT transport)
BTM_Recovery_Pre_State();
}
#if (GATTS_INCLUDED == TRUE)
gatt_delete_dev_from_srv_chg_clt_list(bda);
gatt_delete_dev_from_srv_chg_clt_list(bda_local);
#endif // (GATTS_INCLUDED == TRUE)
}
/*******************************************************************************