From 85a3cebb7a49de2f46f85d999976ce1813767517 Mon Sep 17 00:00:00 2001 From: yangfeng Date: Mon, 8 Jun 2026 11:25:07 +0800 Subject: [PATCH] fix(bt): Fix the critical issues related to AVRCP from AI review report - recalculate len_left per attribute in avrc_bld_app_setting_text_rsp - abort fragmented message reassembly when reassembly buffer alloc fails --- .../bt/host/bluedroid/stack/avrc/avrc_api.c | 21 +++++++++---------- .../host/bluedroid/stack/avrc/avrc_bld_tg.c | 7 +------ 2 files changed, 11 insertions(+), 17 deletions(-) diff --git a/components/bt/host/bluedroid/stack/avrc/avrc_api.c b/components/bt/host/bluedroid/stack/avrc/avrc_api.c index 004613b3508..7894ce567eb 100644 --- a/components/bt/host/bluedroid/stack/avrc/avrc_api.c +++ b/components/bt/host/bluedroid/stack/avrc/avrc_api.c @@ -435,18 +435,17 @@ static UINT8 avrc_proc_far_msg(UINT8 handle, UINT8 label, UINT8 cr, BT_HDR **pp_ /* Free original START packet, replace with pointer to reassembly buffer */ osi_free(p_pkt); *pp_pkt = p_rcb->p_rmsg; - } else { - /* Unable to allocate buffer for fragmented avrc message. Reuse START - buffer for reassembly (re-assembled message may fit into ACL buf) */ - AVRC_TRACE_DEBUG ("Unable to allocate buffer for fragmented avrc message, \ - reusing START buffer for reassembly"); - p_rcb->rasm_offset = p_pkt->offset; - p_rcb->p_rmsg = p_pkt; - } - /* set offset to point to where to copy next - use the same re-asm logic as AVCT */ - p_rcb->p_rmsg->offset += p_rcb->p_rmsg->len; - req_continue = TRUE; + /* set offset to point to where to copy next - use the same re-asm logic as AVCT */ + p_rcb->p_rmsg->offset += p_rcb->p_rmsg->len; + req_continue = TRUE; + } else { + /* do not reuse START buffer; it is smaller than BT_DEFAULT_BUFFER_SIZE */ + AVRC_TRACE_ERROR("Unable to allocate buffer for fragmented avrc message"); + drop_code = 5; + osi_free(p_pkt); + *pp_pkt = NULL; + } } else if (p_rcb->p_rmsg == NULL) { /* Received a CONTINUE/END, but no corresponding START (or previous fragmented response was dropped) */ diff --git a/components/bt/host/bluedroid/stack/avrc/avrc_bld_tg.c b/components/bt/host/bluedroid/stack/avrc/avrc_bld_tg.c index e82a0512723..8ec668391d5 100644 --- a/components/bt/host/bluedroid/stack/avrc/avrc_bld_tg.c +++ b/components/bt/host/bluedroid/stack/avrc/avrc_bld_tg.c @@ -314,12 +314,6 @@ static tAVRC_STS avrc_bld_app_setting_text_rsp (tAVRC_GET_APP_ATTR_TXT_RSP *p_rs p_start = (UINT8 *)(p_pkt + 1) + p_pkt->offset; p_data = p_len = p_start + 2; /* pdu + rsvd */ - /* - * NOTE: The buffer is allocated within avrc_bld_init_rsp_buffer(), and is - * always of size BT_DEFAULT_BUFFER_SIZE. - */ - len_left = BT_DEFAULT_BUFFER_SIZE - BT_HDR_SIZE - p_pkt->offset - p_pkt->len; - BE_STREAM_TO_UINT16(len, p_data); p_count = p_data; @@ -331,6 +325,7 @@ static tAVRC_STS avrc_bld_app_setting_text_rsp (tAVRC_GET_APP_ATTR_TXT_RSP *p_rs } for (xx = 0; xx < p_rsp->num_attr; xx++) { + len_left = (UINT16)(((UINT8 *)p_pkt + BT_DEFAULT_BUFFER_SIZE) - p_data); if (len_left < (p_rsp->p_attrs[xx].str_len + 4)) { AVRC_TRACE_ERROR("avrc_bld_app_setting_text_rsp out of room %d(str_len:%d, left:%d)", xx, p_rsp->p_attrs[xx].str_len, len_left);