fix(bt_stack): Fix some critical bugs in classic_bt stack

related: obex, smp, pbap, sdp, rfcomm, stack_dm

- Deinit function doesn't delete connection when OBEX_DYNAMIC_MEMORY is on
- Union tGOEPC_DATA sometimes is free by osi_free in some cases when it contains mtu_id
- Add correct free and return solution after fail
- Fix symbol mistake in mod calculation
- Fix pointer-related UAF problems and memory free problems
- Fix buffer overflows and out-of-bounds access
- Fix infinite loops triggered by integer overflow wraparound
- Fix double free
- Change layer_specific usage to avoid heap overflow
- Add some NULL check for pointers
- Fix sdp_db free function
- Fix state table mismatch
This commit is contained in:
hejiaxin
2026-07-23 15:46:38 +08:00
parent 4097b5e3ca
commit 54cd579d3b
27 changed files with 177 additions and 73 deletions
@@ -649,9 +649,9 @@ esp_err_t esp_hf_client_audio_data_send(esp_hf_sync_conn_hdl_t sync_conn_hdl, es
return ESP_OK;
}
void esp_hf_client_pcm_resample_init(uint32_t src_sps, uint32_t bits, uint32_t channels)
esp_err_t esp_hf_client_pcm_resample_init(uint32_t src_sps, uint32_t bits, uint32_t channels)
{
BTA_DmPcmInitSamples(src_sps, bits, channels);
return (BTA_DmPcmInitSamples(src_sps, bits, channels) == BTA_SUCCESS) ? ESP_OK : ESP_FAIL;
}
void esp_hf_client_pcm_resample_deinit(void)
@@ -46,6 +46,12 @@ static bool esp_sdp_record_integrity_check(esp_bluetooth_sdp_record_t *record)
}
break;
case ESP_SDP_TYPE_OPP_SERVER:
if (record->ops.supported_formats_list_len <= 0 || record->ops.supported_formats_list_len > SDP_OPP_SUPPORTED_FORMATS_MAX_LENGTH) {
LOG_ERROR("Invalid supported_formats_list_len in record ops!\n");
ret = false;
}
default:
break;
}
@@ -737,8 +737,10 @@ esp_err_t esp_hf_client_audio_data_send(esp_hf_sync_conn_hdl_t sync_conn_hdl, es
* @param[in] bits: number of bits per pcm sample (16)
*
* @param[in] channels: number of channels (i.e. mono(1), stereo(2)...)
*
* @return esp_err_t
*/
void esp_hf_client_pcm_resample_init(uint32_t src_sps, uint32_t bits, uint32_t channels);
esp_err_t esp_hf_client_pcm_resample_init(uint32_t src_sps, uint32_t bits, uint32_t channels);
/**
* @brief Deinitialize the down sampling converter.