mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
fix(bt/bluedroid): fixed multiple high-severity issues from AI code review in Bluedroid
This commit is contained in:
@@ -360,9 +360,7 @@ BOOLEAN SDP_DeleteRecord (UINT32 handle)
|
||||
if (handle == 0 || sdp_cb.server_db.num_records == 0) {
|
||||
/* Delete all records in the database */
|
||||
sdp_cb.server_db.num_records = 0;
|
||||
for (p_node = list_begin(sdp_cb.server_db.p_record_list); p_node; p_node = list_next(p_node)) {
|
||||
list_remove(sdp_cb.server_db.p_record_list, p_node);
|
||||
}
|
||||
list_clear(sdp_cb.server_db.p_record_list);
|
||||
/* require new DI record to be created in SDP_SetLocalDiRecord */
|
||||
sdp_cb.server_db.di_primary_handle = 0;
|
||||
|
||||
@@ -488,15 +486,13 @@ BOOLEAN SDP_AddAttribute (UINT32 handle, UINT16 attr_id, UINT8 attr_type,
|
||||
p_attr->type = attr_type;
|
||||
p_attr->len = attr_len;
|
||||
|
||||
if (p_rec->free_pad_ptr + attr_len >= SDP_MAX_PAD_LEN) {
|
||||
if (p_rec->free_pad_ptr + attr_len > SDP_MAX_PAD_LEN) {
|
||||
/* do truncate only for text string type descriptor */
|
||||
if (attr_type == TEXT_STR_DESC_TYPE) {
|
||||
SDP_TRACE_WARNING("SDP_AddAttribute: attr_len:%d too long. truncate to (%d)\n",
|
||||
attr_len, SDP_MAX_PAD_LEN - p_rec->free_pad_ptr );
|
||||
|
||||
attr_len = SDP_MAX_PAD_LEN - p_rec->free_pad_ptr;
|
||||
p_val[SDP_MAX_PAD_LEN - p_rec->free_pad_ptr] = '\0';
|
||||
p_val[SDP_MAX_PAD_LEN - p_rec->free_pad_ptr + 1] = '\0';
|
||||
} else {
|
||||
attr_len = 0;
|
||||
}
|
||||
|
||||
@@ -305,6 +305,9 @@ static void process_service_search_rsp (tCONN_CB *p_ccb, UINT8 *p_reply, UINT8 *
|
||||
if (p_ccb->num_handles > sdp_cb.max_recs_per_search) {
|
||||
p_ccb->num_handles = sdp_cb.max_recs_per_search;
|
||||
}
|
||||
if (p_ccb->num_handles > SDP_MAX_DISC_SERVER_RECS) {
|
||||
p_ccb->num_handles = SDP_MAX_DISC_SERVER_RECS;
|
||||
}
|
||||
|
||||
if (p_reply + ((p_ccb->num_handles - orig) * 4) + 1 > p_reply_end) {
|
||||
sdp_disconnect(p_ccb, SDP_GENERIC_ERROR);
|
||||
@@ -424,8 +427,10 @@ static void process_service_attr_rsp (tCONN_CB *p_ccb, UINT8 *p_reply, UINT8 *p_
|
||||
/* If p_reply is NULL, we were called after the records handles were read */
|
||||
if (p_reply) {
|
||||
#if (SDP_DEBUG_RAW == TRUE)
|
||||
SDP_TRACE_WARNING("ID & len: 0x%02x-%02x-%02x-%02x\n",
|
||||
p_reply[0], p_reply[1], p_reply[2], p_reply[3]);
|
||||
if (p_reply + 4 <= p_reply_end) {
|
||||
SDP_TRACE_WARNING("ID & len: 0x%02x-%02x-%02x-%02x\n",
|
||||
p_reply[0], p_reply[1], p_reply[2], p_reply[3]);
|
||||
}
|
||||
#endif
|
||||
/* Skip transaction ID and length */
|
||||
p_reply += 4;
|
||||
|
||||
@@ -226,7 +226,7 @@ static void process_service_search (tCONN_CB *p_ccb, UINT16 trans_num,
|
||||
return;
|
||||
}
|
||||
if (*p_req) {
|
||||
if (*p_req++ != SDP_CONTINUATION_LEN || (p_req >= p_req_end)) {
|
||||
if (*p_req++ != SDP_CONTINUATION_LEN || (p_req + 2 > p_req_end)) {
|
||||
sdpu_build_n_send_error (p_ccb, trans_num, SDP_INVALID_CONT_STATE,
|
||||
SDP_TEXT_BAD_CONT_LEN);
|
||||
return;
|
||||
|
||||
Reference in New Issue
Block a user