mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
fix(bt): fix A2DP stack component issues reported by AI review
This commit is contained in:
@@ -62,6 +62,9 @@ void AVCT_Register(UINT16 mtu, UINT16 mtu_br, UINT8 sec_mask)
|
||||
|
||||
AVCT_TRACE_API("AVCT_Register");
|
||||
|
||||
/* initialize AVCTP data structures */
|
||||
memset(&avct_cb, 0, sizeof(tAVCT_CB));
|
||||
|
||||
/* register PSM with L2CAP */
|
||||
L2CA_Register(AVCT_PSM, (tL2CAP_APPL_INFO *) &avct_l2c_appl);
|
||||
|
||||
@@ -69,9 +72,6 @@ void AVCT_Register(UINT16 mtu, UINT16 mtu_br, UINT8 sec_mask)
|
||||
BTM_SetSecurityLevel(TRUE, "", BTM_SEC_SERVICE_AVCTP, sec_mask, AVCT_PSM, 0, 0);
|
||||
BTM_SetSecurityLevel(FALSE, "", BTM_SEC_SERVICE_AVCTP, sec_mask, AVCT_PSM, 0, 0);
|
||||
|
||||
/* initialize AVCTP data structures */
|
||||
memset(&avct_cb, 0, sizeof(tAVCT_CB));
|
||||
|
||||
#if (AVCT_BROWSE_INCLUDED == TRUE)
|
||||
/* Include the browsing channel which uses eFCR */
|
||||
L2CA_Register(AVCT_BR_PSM, (tL2CAP_APPL_INFO *) &avct_l2c_br_appl);
|
||||
@@ -142,6 +142,10 @@ UINT16 AVCT_CreateConn(UINT8 *p_handle, tAVCT_CC *p_cc, BD_ADDR peer_addr)
|
||||
tAVCT_CCB *p_ccb;
|
||||
tAVCT_LCB *p_lcb;
|
||||
|
||||
if (p_cc == NULL || p_handle == NULL) {
|
||||
return AVCT_BAD_HANDLE;
|
||||
}
|
||||
|
||||
AVCT_TRACE_API("AVCT_CreateConn: %d, control:%d", p_cc->role, p_cc->control);
|
||||
|
||||
/* Allocate ccb; if no ccbs, return failure */
|
||||
@@ -234,7 +238,7 @@ UINT16 AVCT_CreateBrowse (UINT8 handle, UINT8 role)
|
||||
#if (AVCT_BROWSE_INCLUDED == TRUE)
|
||||
UINT16 result = AVCT_SUCCESS;
|
||||
tAVCT_CCB *p_ccb;
|
||||
tAVCT_BCB *p_bcb;
|
||||
tAVCT_BCB *p_bcb = NULL;
|
||||
int index;
|
||||
|
||||
AVCT_TRACE_API("AVCT_CreateBrowse: %d", role);
|
||||
@@ -428,7 +432,12 @@ UINT16 AVCT_MsgReq(UINT8 handle, UINT8 label, UINT8 cr, BT_HDR *p_msg)
|
||||
osi_free(p_msg);
|
||||
} else {
|
||||
p_ccb->p_bcb = avct_bcb_by_lcb(p_ccb->p_lcb);
|
||||
avct_bcb_event(p_ccb->p_bcb, AVCT_LCB_UL_MSG_EVT, (tAVCT_LCB_EVT *) &ul_msg);
|
||||
if (p_ccb->p_bcb == NULL) {
|
||||
result = AVCT_BAD_HANDLE;
|
||||
osi_free(p_msg);
|
||||
} else {
|
||||
avct_bcb_event(p_ccb->p_bcb, AVCT_LCB_UL_MSG_EVT, (tAVCT_LCB_EVT *) &ul_msg);
|
||||
}
|
||||
}
|
||||
}
|
||||
/* send msg event to lcb */
|
||||
|
||||
@@ -83,7 +83,7 @@ void avct_ccb_dealloc(tAVCT_CCB *p_ccb, UINT8 event, UINT16 result, BD_ADDR bd_a
|
||||
if (p_ccb->p_bcb == NULL) {
|
||||
memset(p_ccb, 0, sizeof(tAVCT_CCB));
|
||||
} else {
|
||||
/* control channel is down, but the browsing channel is still connected 0 disconnect it now */
|
||||
/* control channel is down, but the browsing channel is still connected - disconnect it now */
|
||||
avct_bcb_event(p_ccb->p_bcb, AVCT_LCB_UL_UNBIND_EVT, (tAVCT_LCB_EVT *) &p_ccb);
|
||||
p_ccb->p_lcb = NULL;
|
||||
}
|
||||
|
||||
@@ -124,6 +124,7 @@ void avct_l2c_connect_ind_cback(BD_ADDR bd_addr, UINT16 lcid, UINT16 psm, UINT8
|
||||
} else {
|
||||
/* TG role only - accept the connection from CT. move the channel ID to the conflict list */
|
||||
p_lcb->conflict_lcid = p_lcb->ch_lcid;
|
||||
p_lcb->ch_flags = 0;
|
||||
AVCT_TRACE_DEBUG("avct_l2c_connect_ind_cback conflict_lcid:0x%x", p_lcb->conflict_lcid);
|
||||
}
|
||||
}
|
||||
@@ -142,6 +143,7 @@ void avct_l2c_connect_ind_cback(BD_ADDR bd_addr, UINT16 lcid, UINT16 psm, UINT8
|
||||
|
||||
/* transition to configuration state */
|
||||
p_lcb->ch_state = AVCT_CH_CFG;
|
||||
p_lcb->ch_flags = 0;
|
||||
|
||||
/* Send L2CAP config req */
|
||||
memset(&cfg, 0, sizeof(tL2CAP_CFG_INFO));
|
||||
@@ -183,6 +185,7 @@ void avct_l2c_connect_cfm_cback(UINT16 lcid, UINT16 result)
|
||||
if (result == L2CAP_CONN_OK) {
|
||||
/* set channel state */
|
||||
p_lcb->ch_state = AVCT_CH_CFG;
|
||||
p_lcb->ch_flags = 0;
|
||||
|
||||
/* Send L2CAP config req */
|
||||
memset(&cfg, 0, sizeof(tL2CAP_CFG_INFO));
|
||||
@@ -275,6 +278,10 @@ void avct_l2c_config_ind_cback(UINT16 lcid, tL2CAP_CFG_INFO *p_cfg)
|
||||
/* look up lcb for this channel */
|
||||
if ((p_lcb = avct_lcb_by_lcid(lcid)) != NULL) {
|
||||
AVCT_TRACE_DEBUG("avct_l2c_config_ind_cback: 0x%x, ch_state: %d", lcid, p_lcb->ch_state);
|
||||
if (p_lcb->ch_state != AVCT_CH_CFG) {
|
||||
AVCT_TRACE_ERROR("avct_l2c_config_ind_cback: EINVAL state %d", p_lcb->ch_state);
|
||||
return;
|
||||
}
|
||||
/* store the mtu in tbl */
|
||||
if (p_cfg->mtu_present) {
|
||||
p_lcb->peer_mtu = p_cfg->mtu;
|
||||
|
||||
@@ -310,10 +310,16 @@ tAVCT_LCB *avct_lcb_alloc(BD_ADDR bd_addr)
|
||||
|
||||
for (i = 0; i < AVCT_NUM_LINKS; i++, p_lcb++) {
|
||||
if (!p_lcb->allocated) {
|
||||
memset(p_lcb, 0, sizeof(tAVCT_LCB));
|
||||
p_lcb->allocated = (UINT8)(i + 1);
|
||||
memcpy(p_lcb->peer_addr, bd_addr, BD_ADDR_LEN);
|
||||
AVCT_TRACE_DEBUG("avct_lcb_alloc %d", p_lcb->allocated);
|
||||
p_lcb->tx_q = fixed_queue_new(QUEUE_SIZE_MAX);
|
||||
if (p_lcb->tx_q == NULL) {
|
||||
AVCT_TRACE_ERROR("avct_lcb_alloc: failed to create tx_q");
|
||||
memset(p_lcb, 0, sizeof(tAVCT_LCB));
|
||||
p_lcb = NULL;
|
||||
}
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -63,6 +63,11 @@ static BT_HDR *avct_lcb_msg_asmbl(tAVCT_LCB *p_lcb, BT_HDR *p_buf)
|
||||
p = (UINT8 *)(p_buf + 1) + p_buf->offset;
|
||||
AVCT_PRS_PKT_TYPE(p, pkt_type);
|
||||
|
||||
if (pkt_type > AVCT_PKT_TYPE_END) {
|
||||
osi_free(p_buf);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/* quick sanity check on length */
|
||||
if (p_buf->len < avct_lcb_pkt_type_len[pkt_type]) {
|
||||
osi_free(p_buf);
|
||||
@@ -114,6 +119,11 @@ static BT_HDR *avct_lcb_msg_asmbl(tAVCT_LCB *p_lcb, BT_HDR *p_buf)
|
||||
/* set offset to point to where to copy next */
|
||||
p_lcb->p_rx_msg->offset += p_lcb->p_rx_msg->len;
|
||||
|
||||
if (p_lcb->p_rx_msg->len < 1) {
|
||||
osi_free(p_lcb->p_rx_msg);
|
||||
p_lcb->p_rx_msg = NULL;
|
||||
return NULL;
|
||||
}
|
||||
/* adjust length for packet header */
|
||||
p_lcb->p_rx_msg->len -= 1;
|
||||
}
|
||||
@@ -146,6 +156,11 @@ static BT_HDR *avct_lcb_msg_asmbl(tAVCT_LCB *p_lcb, BT_HDR *p_buf)
|
||||
p_lcb->p_rx_msg = NULL;
|
||||
osi_free(p_buf);
|
||||
p_ret = NULL;
|
||||
} else if ((UINT32)p_lcb->p_rx_msg->len + p_buf->len > 0xFFFF) {
|
||||
osi_free(p_lcb->p_rx_msg);
|
||||
p_lcb->p_rx_msg = NULL;
|
||||
osi_free(p_buf);
|
||||
p_ret = NULL;
|
||||
} else {
|
||||
/* copy contents of p_buf to p_rx_msg */
|
||||
memcpy((UINT8 *)(p_lcb->p_rx_msg + 1) + p_lcb->p_rx_msg->offset,
|
||||
@@ -541,6 +556,7 @@ void avct_lcb_send_msg(tAVCT_LCB *p_lcb, tAVCT_LCB_EVT *p_data)
|
||||
/* whoops; free original msg buf and bail */
|
||||
AVCT_TRACE_ERROR ("avct_lcb_send_msg cannot alloc buffer!!");
|
||||
osi_free(p_data->ul_msg.p_buf);
|
||||
p_data->ul_msg.p_buf = NULL;
|
||||
break;
|
||||
}
|
||||
|
||||
@@ -555,6 +571,7 @@ void avct_lcb_send_msg(tAVCT_LCB *p_lcb, tAVCT_LCB_EVT *p_data)
|
||||
p_data->ul_msg.p_buf->len -= p_buf->len;
|
||||
} else {
|
||||
p_buf = p_data->ul_msg.p_buf;
|
||||
p_data->ul_msg.p_buf = NULL;
|
||||
}
|
||||
|
||||
curr_msg_len -= p_buf->len;
|
||||
|
||||
Reference in New Issue
Block a user