fix(bt/bluedroid): fixed multiple high-severity issues from AI code review in Bluedroid

This commit is contained in:
Jin Cheng
2026-05-11 09:42:17 +08:00
committed by Jin Cheng
parent da54c7e4d8
commit cb05dc0b3f
13 changed files with 83 additions and 45 deletions
@@ -283,6 +283,7 @@ static void hci_sco_data_to_lower(BT_HDR *p_buf)
if (p_buf->offset == 0) {
BTM_TRACE_ERROR("offset cannot be 0");
osi_free(p_buf);
return;
}
bte_main_hci_send(p_buf, (UINT16)(BT_EVT_TO_LM_HCI_SCO | LOCAL_BLE_CONTROLLER_ID));
@@ -1166,11 +1167,15 @@ UINT16 btm_find_scb_by_handle (UINT16 handle)
tBTM_STATUS BTM_RemoveSco (UINT16 sco_inx)
{
#if (BTM_MAX_SCO_LINKS>0)
if (sco_inx >= BTM_MAX_SCO_LINKS) {
return (BTM_UNKNOWN_ADDR);
}
tSCO_CONN *p = &btm_cb.sco_cb.sco_db[sco_inx];
UINT16 tempstate;
/* Validity check */
if ((sco_inx >= BTM_MAX_SCO_LINKS) || (p->state == SCO_ST_UNUSED)) {
if (p->state == SCO_ST_UNUSED) {
return (BTM_UNKNOWN_ADDR);
}
@@ -130,7 +130,6 @@ UINT16 GAP_ConnOpen (const char *p_serv_name, UINT8 service_id, BOOLEAN is_serve
{
tGAP_CCB *p_ccb;
UINT16 cid;
//tBT_UUID bt_uuid = {2, {GAP_PROTOCOL_ID}};
GAP_TRACE_EVENT ("GAP_CONN - Open Request");
@@ -149,6 +148,7 @@ UINT16 GAP_ConnOpen (const char *p_serv_name, UINT8 service_id, BOOLEAN is_serve
memcpy (&p_ccb->rem_dev_address[0], p_rem_bda, BD_ADDR_LEN);
} else if (!is_server) {
/* remote addr is not specified and is not a server -> bad */
gap_release_ccb (p_ccb);
return (GAP_INVALID_HANDLE);
}
@@ -234,7 +234,7 @@ UINT16 GAP_ConnOpen (const char *p_serv_name, UINT8 service_id, BOOLEAN is_serve
}
/* Check if L2CAP started the connection process */
if (p_rem_bda && ((cid = L2CA_CONNECT_REQ (p_ccb->psm, p_rem_bda, &p_ccb->ertm_info, &bt_uuid)) != 0)) {
if (p_rem_bda && ((cid = L2CA_CONNECT_REQ (p_ccb->psm, p_rem_bda, &p_ccb->ertm_info, NULL)) != 0)) {
p_ccb->connection_id = cid;
return (p_ccb->gap_handle);
} else {
@@ -721,7 +721,6 @@ static void gap_connect_ind (BD_ADDR bd_addr, UINT16 l2cap_cid, UINT16 psm, UIN
{
UINT16 xx;
tGAP_CCB *p_ccb;
//tBT_UUID bt_uuid = {2, {GAP_PROTOCOL_ID}};
/* See if we have a CCB listening for the connection */
for (xx = 0, p_ccb = gap_cb.conn.ccb_pool; xx < GAP_MAX_CONNECTIONS; xx++, p_ccb++) {
@@ -751,7 +750,7 @@ static void gap_connect_ind (BD_ADDR bd_addr, UINT16 l2cap_cid, UINT16 psm, UIN
p_ccb->connection_id = l2cap_cid;
/* Send response to the L2CAP layer. */
L2CA_CONNECT_RSP (bd_addr, l2cap_id, l2cap_cid, L2CAP_CONN_OK, L2CAP_CONN_OK, &p_ccb->ertm_info, &bt_uuid);
L2CA_CONNECT_RSP (bd_addr, l2cap_id, l2cap_cid, L2CAP_CONN_OK, L2CAP_CONN_OK, &p_ccb->ertm_info, NULL);
GAP_TRACE_EVENT("GAP_CONN - Rcvd L2CAP conn ind, CID: 0x%x", p_ccb->connection_id);
@@ -185,7 +185,7 @@ static void l2c_ucd_config_cfm_cback (UINT16 cid, tL2CAP_CFG_INFO *p_cfg)
**
** Parameters: tL2CAP_UCD_CB_INFO
**
** Return value: TRUE if successs
** Return value: TRUE if success
**
*******************************************************************************/
BOOLEAN L2CA_UcdRegister ( UINT16 psm, tL2CAP_UCD_CB_INFO *p_cb_info )
@@ -242,12 +242,12 @@ BOOLEAN L2CA_UcdRegister ( UINT16 psm, tL2CAP_UCD_CB_INFO *p_cb_info )
**
** Parameters: PSM
**
** Return value: TRUE if successs
** Return value: TRUE if success
**
*******************************************************************************/
BOOLEAN L2CA_UcdDeregister_In_CCB_List (void *p_ccb_node, void * context)
{
p_ccb = (tL2C_CCB *)p_ccb_node;
tL2C_CCB *p_ccb = (tL2C_CCB *)p_ccb_node;
if (( p_ccb->in_use )
&& ( p_ccb->local_cid == L2CAP_CONNECTIONLESS_CID )) {
l2cu_release_ccb (p_ccb);
@@ -301,7 +301,7 @@ BOOLEAN L2CA_UcdDeregister ( UINT16 psm )
** L2CAP_UCD_INFO_TYPE_MTU
**
**
** Return value: TRUE if successs
** Return value: TRUE if success
**
*******************************************************************************/
BOOLEAN L2CA_UcdDiscover ( UINT16 psm, BD_ADDR rem_bda, UINT8 info_type )
@@ -450,7 +450,7 @@ UINT16 L2CA_UcdDataWrite (UINT16 psm, BD_ADDR rem_bda, BT_HDR *p_buf, UINT16 fla
** Parameters: BD Addr
** Timeout in second
**
** Return value: TRUE if successs
** Return value: TRUE if success
**
*******************************************************************************/
BOOLEAN L2CA_UcdSetIdleTimeout ( BD_ADDR rem_bda, UINT16 timeout )
@@ -517,7 +517,7 @@ BOOLEAN L2CA_UCDSetTxPriority ( BD_ADDR rem_bda, tL2CAP_CHNL_PRIORITY priority )
**
** Parameters: BD_ADDR of remote device
**
** Return value: TRUE if successs
** Return value: TRUE if success
**
*******************************************************************************/
static BOOLEAN l2c_ucd_connect ( BD_ADDR rem_bda )
@@ -597,7 +597,7 @@ static BOOLEAN l2c_ucd_connect ( BD_ADDR rem_bda )
void l2c_ucd_delete_sec_pending_q(tL2C_LCB *p_lcb)
{
/* clean up any security pending UCD */
while (p_lcb->ucd_out_sec_pending_q.p_first) {
while (!fixed_queue_is_empty(p_lcb->ucd_out_sec_pending_q)) {
osi_free(fixed_queue_dequeue(p_lcb->ucd_out_sec_pending_q, 0));
}
fixed_queue_free(p_lcb->ucd_out_sec_pending_q, NULL);
@@ -606,7 +606,7 @@ void l2c_ucd_delete_sec_pending_q(tL2C_LCB *p_lcb)
while (! fixed_queue_is_empty(p_lcb->ucd_in_sec_pending_q)) {
osi_free(fixed_queue_dequeue(p_lcb->ucd_in_sec_pending_q, 0));
}
fixed_queue_free(p_lcb->ucd_in_sec_pending_q);
fixed_queue_free(p_lcb->ucd_in_sec_pending_q, NULL);
p_lcb->ucd_in_sec_pending_q = NULL;
}
@@ -797,7 +797,7 @@ BOOLEAN l2c_ucd_check_pending_in_sec_q(tL2C_CCB *p_ccb)
*******************************************************************************/
void l2c_ucd_send_pending_in_sec_q(tL2C_CCB *p_ccb)
{
BT_HDR *p_buf = (BT_HDR*)fixed_queue_dequeue(p_ccb->p_lcb->ucd_in_sec_pending_q, 0)
BT_HDR *p_buf = (BT_HDR*)fixed_queue_dequeue(p_ccb->p_lcb->ucd_in_sec_pending_q, 0);
if (p_buf != NULL) {
p_ccb->p_rcb->ucd.cb_info.pL2CA_UCD_Data_Cb(p_ccb->p_lcb->remote_bd_addr, (BT_HDR *)p_buf);
@@ -107,7 +107,7 @@ l2cap_client_t *l2cap_client_new(const l2cap_client_callbacks_t *callbacks, void
ret->remote_mtu = L2CAP_MTU_DEFAULT;
ret->outbound_fragments = list_new(NULL);
if (!ret) {
if (!ret->outbound_fragments) {
L2CAP_TRACE_ERROR("%s unable to allocate outbound L2CAP fragment list.", __func__);
goto error;
}
@@ -393,7 +393,7 @@ static void fragment_packet(l2cap_client_t *client, buffer_t *packet)
assert(packet != NULL);
// TODO(sharvil): eliminate copy into BT_HDR.
BT_HDR *bt_packet = osi_malloc(buffer_length(packet) + L2CAP_MIN_OFFSET);
BT_HDR *bt_packet = osi_malloc(sizeof(BT_HDR) + buffer_length(packet) + L2CAP_MIN_OFFSET);
bt_packet->offset = L2CAP_MIN_OFFSET;
bt_packet->len = buffer_length(packet);
memcpy(bt_packet->data + bt_packet->offset, buffer_ptr(packet), buffer_length(packet));
@@ -408,7 +408,7 @@ static void fragment_packet(l2cap_client_t *client, buffer_t *packet)
break;
}
BT_HDR *fragment = osi_malloc(client->remote_mtu + L2CAP_MIN_OFFSET);
BT_HDR *fragment = osi_malloc(sizeof(BT_HDR) + client->remote_mtu + L2CAP_MIN_OFFSET);
fragment->offset = L2CAP_MIN_OFFSET;
fragment->len = client->remote_mtu;
memcpy(fragment->data + fragment->offset, bt_packet->data + bt_packet->offset, client->remote_mtu);
@@ -360,9 +360,7 @@ BOOLEAN SDP_DeleteRecord (UINT32 handle)
if (handle == 0 || sdp_cb.server_db.num_records == 0) {
/* Delete all records in the database */
sdp_cb.server_db.num_records = 0;
for (p_node = list_begin(sdp_cb.server_db.p_record_list); p_node; p_node = list_next(p_node)) {
list_remove(sdp_cb.server_db.p_record_list, p_node);
}
list_clear(sdp_cb.server_db.p_record_list);
/* require new DI record to be created in SDP_SetLocalDiRecord */
sdp_cb.server_db.di_primary_handle = 0;
@@ -488,15 +486,13 @@ BOOLEAN SDP_AddAttribute (UINT32 handle, UINT16 attr_id, UINT8 attr_type,
p_attr->type = attr_type;
p_attr->len = attr_len;
if (p_rec->free_pad_ptr + attr_len >= SDP_MAX_PAD_LEN) {
if (p_rec->free_pad_ptr + attr_len > SDP_MAX_PAD_LEN) {
/* do truncate only for text string type descriptor */
if (attr_type == TEXT_STR_DESC_TYPE) {
SDP_TRACE_WARNING("SDP_AddAttribute: attr_len:%d too long. truncate to (%d)\n",
attr_len, SDP_MAX_PAD_LEN - p_rec->free_pad_ptr );
attr_len = SDP_MAX_PAD_LEN - p_rec->free_pad_ptr;
p_val[SDP_MAX_PAD_LEN - p_rec->free_pad_ptr] = '\0';
p_val[SDP_MAX_PAD_LEN - p_rec->free_pad_ptr + 1] = '\0';
} else {
attr_len = 0;
}
@@ -305,6 +305,9 @@ static void process_service_search_rsp (tCONN_CB *p_ccb, UINT8 *p_reply, UINT8 *
if (p_ccb->num_handles > sdp_cb.max_recs_per_search) {
p_ccb->num_handles = sdp_cb.max_recs_per_search;
}
if (p_ccb->num_handles > SDP_MAX_DISC_SERVER_RECS) {
p_ccb->num_handles = SDP_MAX_DISC_SERVER_RECS;
}
if (p_reply + ((p_ccb->num_handles - orig) * 4) + 1 > p_reply_end) {
sdp_disconnect(p_ccb, SDP_GENERIC_ERROR);
@@ -424,8 +427,10 @@ static void process_service_attr_rsp (tCONN_CB *p_ccb, UINT8 *p_reply, UINT8 *p_
/* If p_reply is NULL, we were called after the records handles were read */
if (p_reply) {
#if (SDP_DEBUG_RAW == TRUE)
SDP_TRACE_WARNING("ID & len: 0x%02x-%02x-%02x-%02x\n",
p_reply[0], p_reply[1], p_reply[2], p_reply[3]);
if (p_reply + 4 <= p_reply_end) {
SDP_TRACE_WARNING("ID & len: 0x%02x-%02x-%02x-%02x\n",
p_reply[0], p_reply[1], p_reply[2], p_reply[3]);
}
#endif
/* Skip transaction ID and length */
p_reply += 4;
@@ -226,7 +226,7 @@ static void process_service_search (tCONN_CB *p_ccb, UINT16 trans_num,
return;
}
if (*p_req) {
if (*p_req++ != SDP_CONTINUATION_LEN || (p_req >= p_req_end)) {
if (*p_req++ != SDP_CONTINUATION_LEN || (p_req + 2 > p_req_end)) {
sdpu_build_n_send_error (p_ccb, trans_num, SDP_INVALID_CONT_STATE,
SDP_TEXT_BAD_CONT_LEN);
return;