From ceaa55822a16cae69a894f5743581e72db93162c Mon Sep 17 00:00:00 2001 From: luoxu Date: Mon, 9 Mar 2026 12:12:29 +0800 Subject: [PATCH] fix(ble_mesh): Miscellaneous bugfixes according to our internal bug report (v2) --- .../api/core/esp_ble_mesh_ble_api.c | 9 +- .../esp_ble_mesh_local_data_operation_api.c | 8 +- .../api/core/esp_ble_mesh_networking_api.c | 71 ++- .../api/core/esp_ble_mesh_provisioning_api.c | 11 +- .../api/core/esp_ble_mesh_proxy_api.c | 2 +- .../api/core/include/esp_ble_mesh_proxy_api.h | 2 +- .../models/esp_ble_mesh_config_model_api.c | 4 + .../models/esp_ble_mesh_generic_model_api.c | 4 + .../models/esp_ble_mesh_health_model_api.c | 10 +- .../models/esp_ble_mesh_lighting_model_api.c | 4 + .../models/esp_ble_mesh_sensor_model_api.c | 4 + .../include/esp_ble_mesh_generic_model_api.h | 3 +- .../include/esp_ble_mesh_lighting_model_api.h | 3 +- .../bt/esp_ble_mesh/btc/btc_ble_mesh_ble.c | 1 + .../btc/btc_ble_mesh_config_model.c | 2 + .../btc/btc_ble_mesh_generic_model.c | 11 +- .../btc/btc_ble_mesh_health_model.c | 4 +- .../btc/btc_ble_mesh_lighting_model.c | 8 +- .../bt/esp_ble_mesh/btc/btc_ble_mesh_prov.c | 108 ++-- .../btc/btc_ble_mesh_sensor_model.c | 13 +- .../btc/btc_ble_mesh_time_scene_model.c | 2 + components/bt/esp_ble_mesh/common/atomic.c | 34 +- components/bt/esp_ble_mesh/common/buf.c | 48 +- .../bt/esp_ble_mesh/common/crypto_mbedtls.c | 30 +- .../bt/esp_ble_mesh/common/crypto_psa.c | 46 +- components/bt/esp_ble_mesh/common/crypto_tc.c | 4 +- .../esp_ble_mesh/common/include/mesh/atomic.h | 2 +- .../esp_ble_mesh/common/include/mesh/mutex.h | 2 + .../esp_ble_mesh/common/include/mesh/utils.h | 7 + components/bt/esp_ble_mesh/common/kernel.c | 8 +- components/bt/esp_ble_mesh/common/mutex.c | 55 +- components/bt/esp_ble_mesh/common/queue.c | 2 +- components/bt/esp_ble_mesh/common/timer.c | 2 +- components/bt/esp_ble_mesh/common/utils.c | 14 +- components/bt/esp_ble_mesh/core/access.c | 90 ++- components/bt/esp_ble_mesh/core/access.h | 2 + components/bt/esp_ble_mesh/core/adv.c | 4 +- components/bt/esp_ble_mesh/core/adv_common.c | 3 +- components/bt/esp_ble_mesh/core/beacon.c | 24 +- .../core/bluedroid_host/adapter.c | 16 +- components/bt/esp_ble_mesh/core/cfg_cli.c | 8 +- components/bt/esp_ble_mesh/core/cfg_srv.c | 9 +- components/bt/esp_ble_mesh/core/crypto.c | 11 +- components/bt/esp_ble_mesh/core/crypto.h | 2 +- components/bt/esp_ble_mesh/core/ext_adv.c | 35 +- components/bt/esp_ble_mesh/core/fast_prov.c | 16 +- components/bt/esp_ble_mesh/core/friend.c | 2 +- components/bt/esp_ble_mesh/core/health_cli.c | 2 +- components/bt/esp_ble_mesh/core/health_srv.c | 13 +- components/bt/esp_ble_mesh/core/heartbeat.c | 52 +- components/bt/esp_ble_mesh/core/local.h | 4 +- components/bt/esp_ble_mesh/core/lpn.c | 17 +- components/bt/esp_ble_mesh/core/net.c | 15 +- .../esp_ble_mesh/core/nimble_host/adapter.c | 117 ++-- components/bt/esp_ble_mesh/core/prov_common.c | 40 +- components/bt/esp_ble_mesh/core/prov_node.c | 19 +- components/bt/esp_ble_mesh/core/prov_pvnr.c | 13 +- .../bt/esp_ble_mesh/core/proxy_client.c | 30 +- .../bt/esp_ble_mesh/core/proxy_server.c | 32 +- components/bt/esp_ble_mesh/core/pvnr_mgmt.c | 11 +- components/bt/esp_ble_mesh/core/rpl.c | 2 +- components/bt/esp_ble_mesh/core/scan.c | 47 +- .../bt/esp_ble_mesh/core/storage/settings.c | 13 +- .../esp_ble_mesh/core/storage/settings_nvs.c | 4 +- .../esp_ble_mesh/core/storage/settings_uid.c | 15 +- components/bt/esp_ble_mesh/core/test.h | 10 +- components/bt/esp_ble_mesh/core/transport.c | 17 +- .../bt/esp_ble_mesh/core/transport.enh.c | 36 +- components/bt/esp_ble_mesh/lib/ext.c | 57 +- .../models/client/client_common.c | 38 +- .../v1.1/btc/btc_ble_mesh_agg_model.c | 16 +- .../v1.1/btc/btc_ble_mesh_brc_model.c | 10 +- .../v1.1/btc/btc_ble_mesh_df_model.c | 22 +- .../v1.1/btc/btc_ble_mesh_dfu_model.c | 602 +++++++++--------- .../v1.1/btc/btc_ble_mesh_lcd_model.c | 10 +- .../v1.1/btc/btc_ble_mesh_mbt_model.c | 12 +- .../v1.1/btc/btc_ble_mesh_odp_model.c | 12 +- .../v1.1/btc/btc_ble_mesh_prb_model.c | 12 +- .../v1.1/btc/btc_ble_mesh_rpr_model.c | 20 +- .../v1.1/btc/btc_ble_mesh_sar_model.c | 2 +- .../v1.1/btc/btc_ble_mesh_srpl_model.c | 8 +- 81 files changed, 1297 insertions(+), 793 deletions(-) diff --git a/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_ble_api.c b/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_ble_api.c index 935918e7b17..f783b23f04e 100644 --- a/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_ble_api.c +++ b/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_ble_api.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2024 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -75,6 +75,13 @@ esp_err_t esp_ble_mesh_start_ble_scanning(esp_ble_mesh_ble_scan_param_t *param) btc_ble_mesh_ble_args_t arg = {0}; btc_msg_t msg = {0}; + /* Note: + * Currently the function is only used to enable reporting + * non-mesh advertising packets to the application layer, + * and the input parameter will not be used for now. + */ + ARG_UNUSED(param); + ESP_BLE_HOST_STATUS_CHECK(ESP_BLE_HOST_STATUS_ENABLED); msg.sig = BTC_SIG_API_CALL; diff --git a/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_local_data_operation_api.c b/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_local_data_operation_api.c index e4f2e67b678..ef9b079c898 100644 --- a/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_local_data_operation_api.c +++ b/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_local_data_operation_api.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -131,8 +131,10 @@ esp_err_t esp_ble_mesh_model_unsubscribe_group_addr(uint16_t element_addr, uint1 esp_err_t esp_ble_mesh_enable_directed_forwarding(uint16_t net_idx, bool directed_forwarding, bool directed_forwarding_relay) { - return btc_ble_mesh_enable_directed_forwarding(net_idx, directed_forwarding, - directed_forwarding_relay); + ESP_BLE_HOST_STATUS_CHECK(ESP_BLE_HOST_STATUS_ENABLED); + + return (btc_ble_mesh_enable_directed_forwarding(net_idx, directed_forwarding, + directed_forwarding_relay) == 0 ? ESP_OK : ESP_FAIL); } #endif /* CONFIG_BLE_MESH_DF_SRV */ diff --git a/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_networking_api.c b/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_networking_api.c index ac8ecece65d..d1f9230b339 100644 --- a/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_networking_api.c +++ b/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_networking_api.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -30,6 +30,35 @@ static esp_err_t ble_mesh_model_send_msg(esp_ble_mesh_model_t *model, ESP_BLE_HOST_STATUS_CHECK(ESP_BLE_HOST_STATUS_ENABLED); + /* When data is NULL, it is mandatory to set length to 0 to prevent users from misinterpreting parameters. */ + if (data == NULL) { + length = 0; + } + + /* Compute op_len from opcode before length validation */ + if (opcode < 0x100) { + op_len = 1; + } else if (opcode < 0x10000) { + op_len = 2; + } else { + op_len = 3; + } + + if (act == BTC_BLE_MESH_ACT_MODEL_PUBLISH) { + /* When "send_rel" is true and "send_szmic" is 1, 8-octets TransMIC will + * be used, otherwise 4-octets TransMIC will be used. + */ + mic_len = (model->pub->send_rel && model->pub->send_szmic) ? + ESP_BLE_MESH_MIC_LONG : ESP_BLE_MESH_MIC_SHORT; + } else { + /* When the message is tagged with the send-segmented tag and "send_szmic" + * is 1, 8-octets TransMIC will be used, otherwise 4-octets TransMIC will + * be used. + */ + mic_len = ((ctx->send_tag & ESP_BLE_MESH_TAG_SEND_SEGMENTED) && ctx->send_szmic) ? + ESP_BLE_MESH_MIC_LONG : ESP_BLE_MESH_MIC_SHORT; + } + if (ctx) { if (ctx->addr == ESP_BLE_MESH_ADDR_UNASSIGNED) { BT_ERR("Invalid destination address 0x0000"); @@ -63,6 +92,7 @@ static esp_err_t ble_mesh_model_send_msg(esp_ble_mesh_model_t *model, ctx->enh.long_pkt_cfg != ESP_BLE_MESH_LONG_PACKET_PREFER)) { BT_ERR("Invalid long packet configuration %d (expected FORCE=1 or PREFER=2)", ctx->enh.long_pkt_cfg); + return ESP_ERR_INVALID_ARG; } if (ctx->enh.long_pkt_cfg_used && (op_len + length + mic_len > ESP_BLE_MESH_EXT_SDU_MAX_LEN)) { @@ -82,19 +112,6 @@ static esp_err_t ble_mesh_model_send_msg(esp_ble_mesh_model_t *model, return ESP_ERR_INVALID_ARG; } - /* When data is NULL, it is mandatory to set length to 0 to prevent users from misinterpreting parameters. */ - if (data == NULL) { - length = 0; - } - - if (opcode < 0x100) { - op_len = 1; - } else if (opcode < 0x10000) { - op_len = 2; - } else { - op_len = 3; - } - if (act == BTC_BLE_MESH_ACT_MODEL_PUBLISH) { if (op_len + length > model->pub->msg->size) { BT_ERR("Too small publication msg size %d", model->pub->msg->size); @@ -102,31 +119,20 @@ static esp_err_t ble_mesh_model_send_msg(esp_ble_mesh_model_t *model, } } - if (act == BTC_BLE_MESH_ACT_MODEL_PUBLISH) { - /* When "send_rel" is true and "send_szmic" is 1, 8-octets TransMIC will - * be used, otherwise 4-octets TransMIC will be used. - */ - mic_len = (model->pub->send_rel && model->pub->send_szmic) ? - ESP_BLE_MESH_MIC_LONG : ESP_BLE_MESH_MIC_SHORT; - } else { - /* When the message is tagged with the send-segmented tag and "send_szmic" - * is 1, 8-octets TransMIC will be used, otherwise 4-octets TransMIC will - * be used. - */ - mic_len = ((ctx->send_tag & ESP_BLE_MESH_TAG_SEND_SEGMENTED) && ctx->send_szmic) ? - ESP_BLE_MESH_MIC_LONG : ESP_BLE_MESH_MIC_SHORT; - } - if (act == BTC_BLE_MESH_ACT_MODEL_PUBLISH) { bt_mesh_model_msg_init(model->pub->msg, opcode); - net_buf_simple_add_mem(model->pub->msg, data, length); + if (length > 0) { + net_buf_simple_add_mem(model->pub->msg, data, length); + } } else { msg_data = (uint8_t *)bt_mesh_calloc(op_len + length); if (msg_data == NULL) { return ESP_ERR_NO_MEM; } esp_ble_mesh_model_msg_opcode_init(msg_data, opcode); - memcpy(msg_data + op_len, data, length); + if (length > 0) { + memcpy(msg_data + op_len, data, length); + } } msg.sig = BTC_SIG_API_CALL; @@ -693,6 +699,7 @@ esp_err_t esp_ble_mesh_provisioner_open_settings_with_uid(const char *uid) msg.pid = BTC_PID_PROV; msg.act = BTC_BLE_MESH_ACT_PROVISIONER_OPEN_SETTINGS_WITH_UID; + memset(arg.open_settings_with_uid.uid, 0, sizeof(arg.open_settings_with_uid.uid)); strncpy(arg.open_settings_with_uid.uid, uid, ESP_BLE_MESH_SETTINGS_UID_SIZE); return (btc_transfer_context(&msg, &arg, sizeof(btc_ble_mesh_prov_args_t), NULL, NULL) @@ -736,6 +743,7 @@ esp_err_t esp_ble_mesh_provisioner_close_settings_with_uid(const char *uid, bool msg.pid = BTC_PID_PROV; msg.act = BTC_BLE_MESH_ACT_PROVISIONER_CLOSE_SETTINGS_WITH_UID; + memset(arg.close_settings_with_uid.uid, 0, sizeof(arg.close_settings_with_uid.uid)); strncpy(arg.close_settings_with_uid.uid, uid, ESP_BLE_MESH_SETTINGS_UID_SIZE); arg.close_settings_with_uid.erase = erase; @@ -779,6 +787,7 @@ esp_err_t esp_ble_mesh_provisioner_delete_settings_with_uid(const char *uid) msg.pid = BTC_PID_PROV; msg.act = BTC_BLE_MESH_ACT_PROVISIONER_DELETE_SETTINGS_WITH_UID; + memset(arg.delete_settings_with_uid.uid, 0, sizeof(arg.delete_settings_with_uid.uid)); strncpy(arg.delete_settings_with_uid.uid, uid, ESP_BLE_MESH_SETTINGS_UID_SIZE); return (btc_transfer_context(&msg, &arg, sizeof(btc_ble_mesh_prov_args_t), NULL, NULL) diff --git a/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_provisioning_api.c b/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_provisioning_api.c index c89903a1d83..6ad928f5f7b 100644 --- a/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_provisioning_api.c +++ b/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_provisioning_api.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2023 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -44,7 +44,7 @@ static bool prov_bearers_valid(esp_ble_mesh_prov_bearer_t bearers) esp_err_t esp_ble_mesh_node_prov_enable(esp_ble_mesh_prov_bearer_t bearers) { - btc_ble_mesh_prov_args_t arg = {0}; + btc_ble_mesh_prov_args_t arg; btc_msg_t msg = {0}; if (prov_bearers_valid(bearers) == false) { @@ -200,7 +200,7 @@ esp_err_t esp_ble_mesh_provisioner_input_string(const char *string, uint8_t link btc_ble_mesh_prov_args_t arg = {0}; btc_msg_t msg = {0}; - if (!string || strlen(string) > ESP_BLE_MESH_PROV_OUTPUT_OOB_MAX_LEN || + if (!string || strlen(string) > ESP_BLE_MESH_PROV_INPUT_OOB_MAX_LEN || link_idx >= MAX_PROV_LINK_IDX) { return ESP_ERR_INVALID_ARG; } @@ -482,7 +482,10 @@ esp_err_t esp_ble_mesh_set_fast_prov_info(esp_ble_mesh_fast_prov_info_t *fast_pr btc_msg_t msg = {0}; if (fast_prov_info == NULL || (fast_prov_info->offset + - fast_prov_info->match_len > ESP_BLE_MESH_OCTET16_LEN)) { + fast_prov_info->match_len > ESP_BLE_MESH_OCTET16_LEN) || + !ESP_BLE_MESH_ADDR_IS_UNICAST(fast_prov_info->unicast_min) || + !ESP_BLE_MESH_ADDR_IS_UNICAST(fast_prov_info->unicast_max) || + fast_prov_info->unicast_min > fast_prov_info->unicast_max) { return ESP_ERR_INVALID_ARG; } diff --git a/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_proxy_api.c b/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_proxy_api.c index 0365711d868..fe053930c3f 100644 --- a/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_proxy_api.c +++ b/components/bt/esp_ble_mesh/api/core/esp_ble_mesh_proxy_api.c @@ -224,7 +224,7 @@ esp_err_t esp_ble_mesh_proxy_client_directed_proxy_set(uint8_t conn_handle, uint #endif /* CONFIG_BLE_MESH_DF_CLI */ #if CONFIG_BLE_MESH_PROXY_SOLIC_PDU_TX -esp_err_t esp_ble_mesh_proxy_client_send_solic_pdu(uint8_t net_idx, uint16_t ssrc, uint16_t dst) +esp_err_t esp_ble_mesh_proxy_client_send_solic_pdu(uint16_t net_idx, uint16_t ssrc, uint16_t dst) { btc_ble_mesh_prov_args_t arg = {0}; btc_msg_t msg = {0}; diff --git a/components/bt/esp_ble_mesh/api/core/include/esp_ble_mesh_proxy_api.h b/components/bt/esp_ble_mesh/api/core/include/esp_ble_mesh_proxy_api.h index 66b1e1d4be0..092e8c8d758 100644 --- a/components/bt/esp_ble_mesh/api/core/include/esp_ble_mesh_proxy_api.h +++ b/components/bt/esp_ble_mesh/api/core/include/esp_ble_mesh_proxy_api.h @@ -161,7 +161,7 @@ esp_err_t esp_ble_mesh_proxy_client_directed_proxy_set(uint8_t conn_handle, uint * @return ESP_OK on success or error code otherwise. * */ -esp_err_t esp_ble_mesh_proxy_client_send_solic_pdu(uint8_t net_idx, uint16_t ssrc, uint16_t dst); +esp_err_t esp_ble_mesh_proxy_client_send_solic_pdu(uint16_t net_idx, uint16_t ssrc, uint16_t dst); #ifdef __cplusplus } diff --git a/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_config_model_api.c b/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_config_model_api.c index 98155caf174..bbf3a27a35f 100644 --- a/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_config_model_api.c +++ b/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_config_model_api.c @@ -14,6 +14,10 @@ #if CONFIG_BLE_MESH_CFG_CLI esp_err_t esp_ble_mesh_register_config_client_callback(esp_ble_mesh_cfg_client_cb_t callback) { + if (callback == NULL) { + return ESP_ERR_INVALID_ARG; + } + ESP_BLE_HOST_STATUS_CHECK(ESP_BLE_HOST_STATUS_ENABLED); return (btc_profile_cb_set(BTC_PID_CONFIG_CLIENT, callback) == 0 ? ESP_OK : ESP_FAIL); diff --git a/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_generic_model_api.c b/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_generic_model_api.c index e404c6a5bda..928a9005eaf 100644 --- a/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_generic_model_api.c +++ b/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_generic_model_api.c @@ -14,6 +14,10 @@ #if CONFIG_BLE_MESH_GENERIC_CLIENT esp_err_t esp_ble_mesh_register_generic_client_callback(esp_ble_mesh_generic_client_cb_t callback) { + if (callback == NULL) { + return ESP_ERR_INVALID_ARG; + } + ESP_BLE_HOST_STATUS_CHECK(ESP_BLE_HOST_STATUS_ENABLED); return (btc_profile_cb_set(BTC_PID_GENERIC_CLIENT, callback) == 0 ? ESP_OK : ESP_FAIL); diff --git a/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_health_model_api.c b/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_health_model_api.c index 2bdb35a30ae..225537886c6 100644 --- a/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_health_model_api.c +++ b/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_health_model_api.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -14,6 +14,10 @@ #if CONFIG_BLE_MESH_HEALTH_CLI esp_err_t esp_ble_mesh_register_health_client_callback(esp_ble_mesh_health_client_cb_t callback) { + if (callback == NULL) { + return ESP_ERR_INVALID_ARG; + } + ESP_BLE_HOST_STATUS_CHECK(ESP_BLE_HOST_STATUS_ENABLED); return (btc_profile_cb_set(BTC_PID_HEALTH_CLIENT, callback) == 0 ? ESP_OK : ESP_FAIL); @@ -29,7 +33,9 @@ esp_err_t esp_ble_mesh_health_client_get_state(esp_ble_mesh_client_common_param_ params->ctx.net_idx == ESP_BLE_MESH_KEY_UNUSED || params->ctx.app_idx == ESP_BLE_MESH_KEY_UNUSED || params->ctx.addr == ESP_BLE_MESH_ADDR_UNASSIGNED || - (params->opcode == ESP_BLE_MESH_MODEL_OP_HEALTH_FAULT_GET && get_state == NULL)) { + ((params->opcode == ESP_BLE_MESH_MODEL_OP_HEALTH_FAULT_GET || + params->opcode == ESP_BLE_MESH_MODEL_OP_ATTENTION_GET || + params->opcode == ESP_BLE_MESH_MODEL_OP_HEALTH_PERIOD_GET) && get_state == NULL)) { return ESP_ERR_INVALID_ARG; } diff --git a/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_lighting_model_api.c b/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_lighting_model_api.c index 80bc62f82d0..c5e148e825c 100644 --- a/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_lighting_model_api.c +++ b/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_lighting_model_api.c @@ -14,6 +14,10 @@ #if CONFIG_BLE_MESH_LIGHTING_CLIENT esp_err_t esp_ble_mesh_register_light_client_callback(esp_ble_mesh_light_client_cb_t callback) { + if (callback == NULL) { + return ESP_ERR_INVALID_ARG; + } + ESP_BLE_HOST_STATUS_CHECK(ESP_BLE_HOST_STATUS_ENABLED); return (btc_profile_cb_set(BTC_PID_LIGHTING_CLIENT, callback) == 0 ? ESP_OK : ESP_FAIL); diff --git a/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_sensor_model_api.c b/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_sensor_model_api.c index c3c047f12b6..8d49677ff6c 100644 --- a/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_sensor_model_api.c +++ b/components/bt/esp_ble_mesh/api/models/esp_ble_mesh_sensor_model_api.c @@ -14,6 +14,10 @@ #if CONFIG_BLE_MESH_SENSOR_CLI esp_err_t esp_ble_mesh_register_sensor_client_callback(esp_ble_mesh_sensor_client_cb_t callback) { + if (callback == NULL) { + return ESP_ERR_INVALID_ARG; + } + ESP_BLE_HOST_STATUS_CHECK(ESP_BLE_HOST_STATUS_ENABLED); return (btc_profile_cb_set(BTC_PID_SENSOR_CLIENT, callback) == 0 ? ESP_OK : ESP_FAIL); diff --git a/components/bt/esp_ble_mesh/api/models/include/esp_ble_mesh_generic_model_api.h b/components/bt/esp_ble_mesh/api/models/include/esp_ble_mesh_generic_model_api.h index fc4808af411..111e326b441 100644 --- a/components/bt/esp_ble_mesh/api/models/include/esp_ble_mesh_generic_model_api.h +++ b/components/bt/esp_ble_mesh/api/models/include/esp_ble_mesh_generic_model_api.h @@ -495,7 +495,8 @@ esp_err_t esp_ble_mesh_register_generic_client_callback(esp_ble_mesh_generic_cli * * @param[in] params: Pointer to BLE Mesh common client parameters. * @param[in] get_state: Pointer to generic get message value. - * Shall not be set to NULL. + * Shall not be set to NULL when the opcode requires + * parameters (property-related GET operations). * * @return ESP_OK on success or error code otherwise. * diff --git a/components/bt/esp_ble_mesh/api/models/include/esp_ble_mesh_lighting_model_api.h b/components/bt/esp_ble_mesh/api/models/include/esp_ble_mesh_lighting_model_api.h index c610c77a96e..e4fa684b01a 100644 --- a/components/bt/esp_ble_mesh/api/models/include/esp_ble_mesh_lighting_model_api.h +++ b/components/bt/esp_ble_mesh/api/models/include/esp_ble_mesh_lighting_model_api.h @@ -551,7 +551,8 @@ esp_err_t esp_ble_mesh_register_light_client_callback(esp_ble_mesh_light_client_ * * @param[in] params: Pointer to BLE Mesh common client parameters. * @param[in] get_state: Pointer of light get message value. - * Shall not be set to NULL. + * Shall not be set to NULL when the opcode requires + * parameters (e.g., ESP_BLE_MESH_MODEL_OP_LIGHT_LC_PROPERTY_GET). * * @return ESP_OK on success or error code otherwise. * diff --git a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_ble.c b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_ble.c index ac397aeb18d..3471b8814f2 100644 --- a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_ble.c +++ b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_ble.c @@ -38,6 +38,7 @@ static void btc_ble_mesh_ble_copy_req_data(btc_msg_t *msg, void *p_dst, void *p_ p_src_data->scan_ble_adv_pkt.length); } else { BT_ERR("%s, Out of memory, act %d", __func__, msg->act); + p_dst_data->scan_ble_adv_pkt.length = 0; } } break; diff --git a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_config_model.c b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_config_model.c index 3d6f53f5565..c39cf566c2d 100644 --- a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_config_model.c +++ b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_config_model.c @@ -248,6 +248,7 @@ static void btc_ble_mesh_config_client_copy_req_data(btc_msg_t *msg, void *p_des break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_CFG_CLIENT_TIMEOUT_EVT: break; default: @@ -300,6 +301,7 @@ static void btc_ble_mesh_config_client_free_req_data(btc_msg_t *msg) break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_CFG_CLIENT_TIMEOUT_EVT: if (arg->params) { bt_mesh_free(arg->params); diff --git a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_generic_model.c b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_generic_model.c index 3826eba0122..008ada9020a 100644 --- a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_generic_model.c +++ b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_generic_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -54,7 +54,7 @@ void btc_ble_mesh_generic_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, voi dst->generic_client_get_state.get_state = (esp_ble_mesh_generic_client_get_state_t *)bt_mesh_calloc(sizeof(esp_ble_mesh_generic_client_get_state_t)); if (dst->generic_client_get_state.get_state) { memcpy(dst->generic_client_get_state.get_state, src->generic_client_get_state.get_state, - sizeof(esp_ble_mesh_generic_client_get_state_t)); + sizeof(esp_ble_mesh_generic_client_get_state_t)); } else { BT_ERR("%s, Out of memory, act %d", __func__, msg->act); /* Free the previously allocated resources */ @@ -146,6 +146,11 @@ void btc_ble_mesh_generic_client_arg_deep_free(btc_msg_t *msg) } arg = (btc_ble_mesh_generic_client_args_t *)(msg->arg); + /** + * msg->arg is guaranteed to be non-NULL by btc_transfer_context + */ + ESP_ASSUME_NONNULL(arg); + switch (msg->act) { case BTC_BLE_MESH_ACT_GENERIC_CLIENT_GET_STATE: @@ -334,6 +339,7 @@ static void btc_ble_mesh_generic_client_copy_req_data(btc_msg_t *msg, void *p_de break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_GENERIC_CLIENT_TIMEOUT_EVT: break; default: @@ -393,6 +399,7 @@ static void btc_ble_mesh_generic_client_free_req_data(btc_msg_t *msg) break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_GENERIC_CLIENT_TIMEOUT_EVT: if (arg->params) { bt_mesh_free(arg->params); diff --git a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_health_model.c b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_health_model.c index f23ac1e2808..1a63686787b 100644 --- a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_health_model.c +++ b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_health_model.c @@ -53,7 +53,7 @@ void btc_ble_mesh_health_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void dst->health_client_get_state.get_state = (esp_ble_mesh_health_client_get_state_t *)bt_mesh_calloc(sizeof(esp_ble_mesh_health_client_get_state_t)); if (dst->health_client_get_state.get_state) { memcpy(dst->health_client_get_state.get_state, src->health_client_get_state.get_state, - sizeof(esp_ble_mesh_health_client_get_state_t)); + sizeof(esp_ble_mesh_health_client_get_state_t)); } else { BT_ERR("%s, Out of memory, act %d", __func__, msg->act); /* Free the previously allocated resources */ @@ -192,6 +192,7 @@ static void btc_ble_mesh_health_client_copy_req_data(btc_msg_t *msg, void *p_des break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_HEALTH_CLIENT_TIMEOUT_EVT: break; default: @@ -229,6 +230,7 @@ static void btc_ble_mesh_health_client_free_req_data(btc_msg_t *msg) break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_HEALTH_CLIENT_TIMEOUT_EVT: if (arg->params) { bt_mesh_free(arg->params); diff --git a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_lighting_model.c b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_lighting_model.c index d82b5f12047..731161c5ada 100644 --- a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_lighting_model.c +++ b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_lighting_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -176,6 +176,7 @@ static void btc_ble_mesh_lighting_client_copy_req_data(btc_msg_t *msg, void *p_d break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_LIGHT_CLIENT_TIMEOUT_EVT: break; default: @@ -209,6 +210,7 @@ static void btc_ble_mesh_lighting_client_free_req_data(btc_msg_t *msg) break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_LIGHT_CLIENT_TIMEOUT_EVT: if (arg->params) { bt_mesh_free(arg->params); @@ -458,13 +460,13 @@ static void btc_ble_mesh_lighting_server_free_req_data(btc_msg_t *msg) switch (msg->act) { case ESP_BLE_MESH_LIGHTING_SERVER_STATE_CHANGE_EVT: if (arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_LIGHT_LC_PROPERTY_SET || - arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_LIGHT_LC_PROPERTY_SET_UNACK) { + arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_LIGHT_LC_PROPERTY_SET_UNACK) { bt_mesh_free_buf(arg->value.state_change.lc_property_set.property_value); } break; case ESP_BLE_MESH_LIGHTING_SERVER_RECV_SET_MSG_EVT: if (arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_LIGHT_LC_PROPERTY_SET || - arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_LIGHT_LC_PROPERTY_SET_UNACK) { + arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_LIGHT_LC_PROPERTY_SET_UNACK) { bt_mesh_free_buf(arg->value.set.lc_property.property_value); } break; diff --git a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_prov.c b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_prov.c index 5e5bbe30c39..e82c61cd188 100644 --- a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_prov.c +++ b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_prov.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -208,7 +208,7 @@ static void btc_ble_mesh_prov_copy_req_data(btc_msg_t *msg, void *p_dest, void * #if CONFIG_BLE_MESH_CERT_BASED_PROV case ESP_BLE_MESH_PROVISIONER_RECV_PROV_RECORDS_LIST_EVT: if (p_src_data->recv_provisioner_records_list.msg && - p_src_data->recv_provisioner_records_list.len) { + p_src_data->recv_provisioner_records_list.len) { p_dest_data->recv_provisioner_records_list.msg = (uint8_t *)bt_mesh_calloc(p_src_data->recv_provisioner_records_list.len); if (!p_dest_data->recv_provisioner_records_list.msg) { BT_ERR("%s, Out of memory, act %d", __func__, msg->act); @@ -222,7 +222,7 @@ static void btc_ble_mesh_prov_copy_req_data(btc_msg_t *msg, void *p_dest, void * break; case ESP_BLE_MESH_PROVISIONER_PROV_RECORD_RECV_COMP_EVT: if (p_src_data->provisioner_prov_record_recv_comp.record && - p_src_data->provisioner_prov_record_recv_comp.total_len) { + p_src_data->provisioner_prov_record_recv_comp.total_len) { p_dest_data->provisioner_prov_record_recv_comp.record = bt_mesh_calloc(p_src_data->provisioner_prov_record_recv_comp.total_len); if (!p_dest_data->provisioner_prov_record_recv_comp.record) { BT_ERR("%s, Out of memory, act %d", __func__, msg->act); @@ -263,10 +263,11 @@ static void btc_ble_mesh_prov_free_req_data(btc_msg_t *msg) bt_mesh_free(arg->provisioner_prov_record_recv_comp.record); } break; -#else /* CONFIG_BLE_MESH_CERT_BASED_PROV */ - ARG_UNUSED(arg); #endif /* CONFIG_BLE_MESH_CERT_BASED_PROV */ default: +#if !CONFIG_BLE_MESH_CERT_BASED_PROV + ARG_UNUSED(arg); +#endif /* !CONFIG_BLE_MESH_CERT_BASED_PROV */ break; } } @@ -381,7 +382,7 @@ static void btc_ble_mesh_model_copy_req_data(btc_msg_t *msg, void *p_dest, void } if (p_src_data->model_operation.msg && - p_src_data->model_operation.length) { + p_src_data->model_operation.length) { p_dest_data->model_operation.msg = (uint8_t *)bt_mesh_calloc(p_src_data->model_operation.length); if (!p_dest_data->model_operation.msg) { BT_ERR("%s, Out of memory, act %d", __func__, msg->act); @@ -412,7 +413,7 @@ static void btc_ble_mesh_model_copy_req_data(btc_msg_t *msg, void *p_dest, void } if (p_src_data->client_recv_publish_msg.msg && - p_src_data->client_recv_publish_msg.length) { + p_src_data->client_recv_publish_msg.length) { p_dest_data->client_recv_publish_msg.msg = (uint8_t *)bt_mesh_calloc(p_src_data->client_recv_publish_msg.length); if (!p_dest_data->client_recv_publish_msg.msg) { BT_ERR("%s, Out of memory, act %d", __func__, msg->act); @@ -530,6 +531,14 @@ static void btc_ble_mesh_server_model_op_cb(struct bt_mesh_model *model, { esp_ble_mesh_model_cb_param_t mesh_param = {0}; + /** + * model,ctx and buf is guaranteed to be non-NULL + * by bt_mesh_model_recv in access.c + */ + ESP_ASSUME_NONNULL(model); + ESP_ASSUME_NONNULL(ctx); + ESP_ASSUME_NONNULL(buf); + mesh_param.model_operation.opcode = ctx->recv_op; mesh_param.model_operation.model = (esp_ble_mesh_model_t *)model; mesh_param.model_operation.ctx = (esp_ble_mesh_msg_ctx_t *)ctx; @@ -707,7 +716,7 @@ static int btc_ble_mesh_output_string_cb(const char *str) memset(mesh_param.node_prov_output_str.string, 0, sizeof(mesh_param.node_prov_output_str.string)); strncpy(mesh_param.node_prov_output_str.string, str, - MIN(strlen(str), sizeof(mesh_param.node_prov_output_str.string))); + MIN(strlen(str), sizeof(mesh_param.node_prov_output_str.string) - 1)); ret = btc_ble_mesh_prov_callback(&mesh_param, ESP_BLE_MESH_NODE_PROV_OUTPUT_STRING_EVT); return (ret == BT_STATUS_SUCCESS) ? 0 : -1; @@ -797,7 +806,7 @@ static void btc_ble_mesh_provisioner_recv_unprov_adv_pkt_cb(const uint8_t addr[6 esp_ble_mesh_prov_cb_param_t mesh_param = {0}; if (addr == NULL || dev_uuid == NULL || - (bearer != BLE_MESH_PROV_ADV && bearer != BLE_MESH_PROV_GATT)) { + (bearer != BLE_MESH_PROV_ADV && bearer != BLE_MESH_PROV_GATT)) { BT_ERR("%s, Invalid parameter", __func__); return; } @@ -850,6 +859,17 @@ static int btc_ble_mesh_provisioner_prov_output_cb(uint8_t method, bt_mesh_input mesh_param.provisioner_prov_output.size = size; mesh_param.provisioner_prov_output.link_idx = link_idx; if (act == BLE_MESH_ENTER_STRING) { + /** + * data is guaranteed to be non-NULL by `prov_auth` in `prov_pvnr.c` + */ + ESP_ASSUME_NONNULL(data); + /** + * The size of the string should be less than or equal to 8 bytes, + * which is defined in the Bluetooth Mesh Profile Specification 5.4.1.3. + * Moreover, the size used here has been verified by the protocol stack + * and is legitimate, so it will definitely not cause a string out-of-bounds + * issue. + */ strncpy(mesh_param.provisioner_prov_output.string, (char *)data, size); } else { mesh_param.provisioner_prov_output.number = sys_get_le32((uint8_t *)data); @@ -1160,7 +1180,10 @@ int btc_ble_mesh_client_model_init(esp_ble_mesh_model_t *model) return -EINVAL; } - __ASSERT(model && model->op, "Invalid parameter"); + if (!model || !model->op) { + BT_ERR("%s, Invalid parameter", __func__); + return -EINVAL; + } esp_ble_mesh_model_op_t *op = model->op; while (op && op->opcode != 0) { op->param_cb = (esp_ble_mesh_cb_t)btc_ble_mesh_client_model_op_cb; @@ -2351,7 +2374,7 @@ static void btc_ble_mesh_model_op_set(esp_ble_mesh_model_t *model) model->pub->update = (esp_ble_mesh_cb_t)btc_ble_mesh_model_publish_update; } break; -#endif /* CONFIG_BLE_MESH_DFD_SRV */ +#endif /* CONFIG_BLE_MESH_DFD_CLI */ default: goto set_vnd_op; } @@ -2390,6 +2413,7 @@ void btc_ble_mesh_prov_call_handler(btc_msg_t *msg) esp_ble_mesh_model_t *sig_model = &elem->sig_models[j]; if (sig_model->op && BLE_MESH_MODEL_OP_LEN(sig_model->op->opcode) == 3) { /* Opcode of SIG model must be 1 or 2 bytes. */ + xSemaphoreGive(arg->mesh_init.semaphore); btc_ble_mesh_prov_register_complete_cb(-EINVAL); return; } @@ -2400,6 +2424,7 @@ void btc_ble_mesh_prov_call_handler(btc_msg_t *msg) esp_ble_mesh_model_t *vnd_model = &elem->vnd_models[k]; if (vnd_model->op && BLE_MESH_MODEL_OP_LEN(vnd_model->op->opcode) < 3) { /* Opcode of vendor model must be 3 bytes. */ + xSemaphoreGive(arg->mesh_init.semaphore); btc_ble_mesh_prov_register_complete_cb(-EINVAL); return; } @@ -2588,9 +2613,9 @@ void btc_ble_mesh_prov_call_handler(btc_msg_t *msg) act = ESP_BLE_MESH_PROVISIONER_PROV_DEV_WITH_ADDR_COMP_EVT; param.provisioner_prov_dev_with_addr_comp.err_code = bt_mesh_provisioner_prov_device_with_addr(arg->provisioner_prov_dev_with_addr.uuid, - arg->provisioner_prov_dev_with_addr.addr, arg->provisioner_prov_dev_with_addr.addr_type, - arg->provisioner_prov_dev_with_addr.bearer, arg->provisioner_prov_dev_with_addr.oob_info, - arg->provisioner_prov_dev_with_addr.unicast_addr); + arg->provisioner_prov_dev_with_addr.addr, arg->provisioner_prov_dev_with_addr.addr_type, + arg->provisioner_prov_dev_with_addr.bearer, arg->provisioner_prov_dev_with_addr.oob_info, + arg->provisioner_prov_dev_with_addr.unicast_addr); break; case BTC_BLE_MESH_ACT_PROVISIONER_DEV_DEL: { struct bt_mesh_device_delete del_dev = {0}; @@ -2608,9 +2633,9 @@ void btc_ble_mesh_prov_call_handler(btc_msg_t *msg) act = ESP_BLE_MESH_PROVISIONER_SET_DEV_UUID_MATCH_COMP_EVT; param.provisioner_set_dev_uuid_match_comp.err_code = bt_mesh_provisioner_set_dev_uuid_match(arg->set_dev_uuid_match.offset, - arg->set_dev_uuid_match.match_len, - arg->set_dev_uuid_match.match_val, - arg->set_dev_uuid_match.prov_after_match); + arg->set_dev_uuid_match.match_len, + arg->set_dev_uuid_match.match_val, + arg->set_dev_uuid_match.prov_after_match); break; case BTC_BLE_MESH_ACT_PROVISIONER_SET_PROV_DATA_INFO: { struct bt_mesh_prov_data_info info = {0}; @@ -2653,7 +2678,7 @@ void btc_ble_mesh_prov_call_handler(btc_msg_t *msg) act = ESP_BLE_MESH_PROVISIONER_ADD_LOCAL_APP_KEY_COMP_EVT; param.provisioner_add_app_key_comp.err_code = bt_mesh_provisioner_local_app_key_add(app_key, arg->add_local_app_key.net_idx, - &arg->add_local_app_key.app_idx); + &arg->add_local_app_key.app_idx); param.provisioner_add_app_key_comp.net_idx = arg->add_local_app_key.net_idx; param.provisioner_add_app_key_comp.app_idx = arg->add_local_app_key.app_idx; break; @@ -2664,7 +2689,7 @@ void btc_ble_mesh_prov_call_handler(btc_msg_t *msg) param.provisioner_update_app_key_comp.app_idx = arg->update_local_app_key.app_idx; param.provisioner_update_app_key_comp.err_code = bt_mesh_provisioner_local_app_key_update(arg->update_local_app_key.app_key, - arg->update_local_app_key.net_idx, arg->update_local_app_key.app_idx); + arg->update_local_app_key.net_idx, arg->update_local_app_key.app_idx); break; case BTC_BLE_MESH_ACT_PROVISIONER_BIND_LOCAL_MOD_APP: act = ESP_BLE_MESH_PROVISIONER_BIND_APP_KEY_TO_MODEL_COMP_EVT; @@ -2674,9 +2699,9 @@ void btc_ble_mesh_prov_call_handler(btc_msg_t *msg) param.provisioner_bind_app_key_to_model_comp.model_id = arg->local_mod_app_bind.model_id; param.provisioner_bind_app_key_to_model_comp.err_code = bt_mesh_provisioner_bind_local_model_app_idx(arg->local_mod_app_bind.elem_addr, - arg->local_mod_app_bind.model_id, - arg->local_mod_app_bind.cid, - arg->local_mod_app_bind.app_idx); + arg->local_mod_app_bind.model_id, + arg->local_mod_app_bind.cid, + arg->local_mod_app_bind.app_idx); break; case BTC_BLE_MESH_ACT_PROVISIONER_ADD_LOCAL_NET_KEY: { const uint8_t *net_key = NULL; @@ -2695,14 +2720,14 @@ void btc_ble_mesh_prov_call_handler(btc_msg_t *msg) param.provisioner_update_net_key_comp.net_idx = arg->update_local_net_key.net_idx; param.provisioner_update_net_key_comp.err_code = bt_mesh_provisioner_local_net_key_update(arg->update_local_net_key.net_key, - arg->update_local_net_key.net_idx); + arg->update_local_net_key.net_idx); break; case BTC_BLE_MESH_ACT_PROVISIONER_STORE_NODE_COMP_DATA: act = ESP_BLE_MESH_PROVISIONER_STORE_NODE_COMP_DATA_COMP_EVT; param.provisioner_store_node_comp_data_comp.addr = arg->store_node_comp_data.unicast_addr; param.provisioner_store_node_comp_data_comp.err_code = bt_mesh_provisioner_store_node_comp_data(arg->store_node_comp_data.unicast_addr, - arg->store_node_comp_data.data, arg->store_node_comp_data.length); + arg->store_node_comp_data.data, arg->store_node_comp_data.length); break; case BTC_BLE_MESH_ACT_PROVISIONER_DELETE_NODE_WITH_UUID: act = ESP_BLE_MESH_PROVISIONER_DELETE_NODE_WITH_UUID_COMP_EVT; @@ -2794,11 +2819,11 @@ void btc_ble_mesh_prov_call_handler(btc_msg_t *msg) break; #endif /* CONFIG_BLE_MESH_USE_MULTIPLE_NAMESPACE */ #if CONFIG_BLE_MESH_CERT_BASED_PROV - extern int bt_mesh_provisioner_send_prov_records_get(uint16_t link_idx); - extern int bt_mesh_provisioner_send_prov_record_req(uint16_t link_idx, uint16_t record_id, - uint16_t frag_offset, uint16_t max_size); - extern int bt_mesh_provisioner_send_prov_invite(uint16_t link_idx); - extern int bt_mesh_provisioner_send_link_close(uint16_t link_idx); + extern int bt_mesh_provisioner_send_prov_records_get(uint16_t link_idx); + extern int bt_mesh_provisioner_send_prov_record_req(uint16_t link_idx, uint16_t record_id, + uint16_t frag_offset, uint16_t max_size); + extern int bt_mesh_provisioner_send_prov_invite(uint16_t link_idx); + extern int bt_mesh_provisioner_send_link_close(uint16_t link_idx); case BTC_BLE_MESH_ACT_PROVISIONER_SEND_PROV_RECORDS_GET: act = ESP_BLE_MESH_PROVISIONER_SEND_PROV_RECORDS_GET_EVT; @@ -2837,13 +2862,13 @@ void btc_ble_mesh_prov_call_handler(btc_msg_t *msg) act = ESP_BLE_MESH_SET_FAST_PROV_INFO_COMP_EVT; param.set_fast_prov_info_comp.status_unicast = bt_mesh_set_fast_prov_unicast_addr_range(arg->set_fast_prov_info.unicast_min, - arg->set_fast_prov_info.unicast_max); + arg->set_fast_prov_info.unicast_max); param.set_fast_prov_info_comp.status_net_idx = bt_mesh_set_fast_prov_net_idx(arg->set_fast_prov_info.net_idx); param.set_fast_prov_info_comp.status_match = bt_mesh_provisioner_set_dev_uuid_match(arg->set_fast_prov_info.offset, - arg->set_fast_prov_info.match_len, - arg->set_fast_prov_info.match_val, false); + arg->set_fast_prov_info.match_len, + arg->set_fast_prov_info.match_val, false); break; case BTC_BLE_MESH_ACT_SET_FAST_PROV_ACTION: act = ESP_BLE_MESH_SET_FAST_PROV_ACTION_COMP_EVT; @@ -3039,11 +3064,18 @@ void btc_ble_mesh_model_call_handler(btc_msg_t *msg) break; } case BTC_BLE_MESH_ACT_SERVER_MODEL_SEND: { - assert(arg->model_send.model); - assert(arg->model_send.ctx); - if (arg->model_send.length) { - assert(arg->model_send.data); - } + /** + * model,ctx and data is guaranteed to be non-NULL + * by esp_ble_mesh_server_model_send_msg in esp_ble_mesh_networking_api.c + */ + ESP_ASSUME_NONNULL(arg->model_send.model); + ESP_ASSUME_NONNULL(arg->model_send.ctx); + ESP_ASSUME_NONNULL(arg->model_send.data); + /** + * length is guaranteed to be greater than 0 (opcode length + payload length) + * by ble_mesh_model_send_msg in esp_ble_mesh_networking_api.c + */ + ESP_ASSUME_NONNULL(arg->model_send.length); /* arg->model_send.length contains opcode & payload, plus extra 4-bytes TransMIC */ struct net_buf_simple *buf = bt_mesh_alloc_buf(arg->model_send.length + BLE_MESH_MIC_SHORT); @@ -3109,7 +3141,7 @@ void btc_ble_mesh_model_call_handler(btc_msg_t *msg) (struct bt_mesh_model *)arg->model_update_state.model, arg->model_update_state.type, (bt_mesh_server_state_value_t *)arg->model_update_state.value); btc_ble_mesh_server_model_update_state_comp_cb(arg->model_update_state.model, - arg->model_update_state.type, err); + arg->model_update_state.type, err); break; #endif /* CONFIG_BLE_MESH_SERVER_MODEL */ default: diff --git a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_sensor_model.c b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_sensor_model.c index 015e108c38c..90d0ce0d744 100644 --- a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_sensor_model.c +++ b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_sensor_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -86,7 +86,6 @@ void btc_ble_mesh_sensor_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void length = src->sensor_client_get_state.get_state->series_get.raw_value_x1->len; dst->sensor_client_get_state.get_state->series_get.raw_value_x1 = bt_mesh_alloc_buf(length); if (!dst->sensor_client_get_state.get_state->series_get.raw_value_x1) { - BT_ERR("%s, Out of memory, act %d", __func__, msg->act); BT_ERR("%s, Out of memory, act %d", __func__, msg->act); /* Free the previously allocated resources */ bt_mesh_free(dst->sensor_client_get_state.params); @@ -103,7 +102,6 @@ void btc_ble_mesh_sensor_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void length = src->sensor_client_get_state.get_state->series_get.raw_value_x2->len; dst->sensor_client_get_state.get_state->series_get.raw_value_x2 = bt_mesh_alloc_buf(length); if (!dst->sensor_client_get_state.get_state->series_get.raw_value_x2) { - BT_ERR("%s, Out of memory, act %d", __func__, msg->act); BT_ERR("%s, Out of memory, act %d", __func__, msg->act); /* Free the previously allocated resources */ if (dst->sensor_client_get_state.get_state->series_get.raw_value_x1) { @@ -499,6 +497,7 @@ static void btc_ble_mesh_sensor_client_copy_req_data(btc_msg_t *msg, void *p_des break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_SENSOR_CLIENT_TIMEOUT_EVT: break; default: @@ -557,6 +556,7 @@ static void btc_ble_mesh_sensor_client_free_req_data(btc_msg_t *msg) break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_SENSOR_CLIENT_TIMEOUT_EVT: if (arg->params) { bt_mesh_free(arg->params); @@ -759,6 +759,7 @@ static void btc_ble_mesh_sensor_server_copy_req_data(btc_msg_t *msg, void *p_des p_dest_data->value.state_change.sensor_cadence_set.trigger_delta_up = bt_mesh_alloc_buf(length); if (p_dest_data->value.state_change.sensor_cadence_set.trigger_delta_up == NULL) { BT_ERR("%s, Out of memory, act %d", __func__, msg->act); + /* The allocated memory will be released by btc_ble_mesh_sensor_server_free_req_data */ return; } net_buf_simple_add_mem(p_dest_data->value.state_change.sensor_cadence_set.trigger_delta_up, @@ -770,6 +771,7 @@ static void btc_ble_mesh_sensor_server_copy_req_data(btc_msg_t *msg, void *p_des p_dest_data->value.state_change.sensor_cadence_set.fast_cadence_low = bt_mesh_alloc_buf(length); if (p_dest_data->value.state_change.sensor_cadence_set.fast_cadence_low == NULL) { BT_ERR("%s, Out of memory, act %d", __func__, msg->act); + /* The allocated memory will be released by btc_ble_mesh_sensor_server_free_req_data */ return; } net_buf_simple_add_mem(p_dest_data->value.state_change.sensor_cadence_set.fast_cadence_low, @@ -781,6 +783,7 @@ static void btc_ble_mesh_sensor_server_copy_req_data(btc_msg_t *msg, void *p_des p_dest_data->value.state_change.sensor_cadence_set.fast_cadence_high = bt_mesh_alloc_buf(length); if (p_dest_data->value.state_change.sensor_cadence_set.fast_cadence_high == NULL) { BT_ERR("%s, Out of memory, act %d", __func__, msg->act); + /* The allocated memory will be released by btc_ble_mesh_sensor_server_free_req_data */ return; } net_buf_simple_add_mem(p_dest_data->value.state_change.sensor_cadence_set.fast_cadence_high, @@ -877,7 +880,7 @@ static void btc_ble_mesh_sensor_server_free_req_data(btc_msg_t *msg) switch (msg->act) { case ESP_BLE_MESH_SENSOR_SERVER_STATE_CHANGE_EVT: if (arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_SENSOR_CADENCE_SET || - arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_SENSOR_CADENCE_SET_UNACK) { + arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_SENSOR_CADENCE_SET_UNACK) { bt_mesh_free_buf(arg->value.state_change.sensor_cadence_set.trigger_delta_down); bt_mesh_free_buf(arg->value.state_change.sensor_cadence_set.trigger_delta_up); bt_mesh_free_buf(arg->value.state_change.sensor_cadence_set.fast_cadence_low); @@ -896,7 +899,7 @@ static void btc_ble_mesh_sensor_server_free_req_data(btc_msg_t *msg) break; case ESP_BLE_MESH_SENSOR_SERVER_RECV_SET_MSG_EVT: if (arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_SENSOR_CADENCE_SET || - arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_SENSOR_CADENCE_SET_UNACK) { + arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_SENSOR_CADENCE_SET_UNACK) { bt_mesh_free_buf(arg->value.set.sensor_cadence.cadence); } else if (arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_SENSOR_SETTING_SET || arg->ctx.recv_op == ESP_BLE_MESH_MODEL_OP_SENSOR_SETTING_SET_UNACK) { diff --git a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_time_scene_model.c b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_time_scene_model.c index 234dd8edff7..2a71ac24d13 100644 --- a/components/bt/esp_ble_mesh/btc/btc_ble_mesh_time_scene_model.c +++ b/components/bt/esp_ble_mesh/btc/btc_ble_mesh_time_scene_model.c @@ -176,6 +176,7 @@ static void btc_ble_mesh_time_scene_client_copy_req_data(btc_msg_t *msg, void *p break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_TIME_SCENE_CLIENT_TIMEOUT_EVT: break; default: @@ -210,6 +211,7 @@ static void btc_ble_mesh_time_scene_client_free_req_data(btc_msg_t *msg) break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_TIME_SCENE_CLIENT_TIMEOUT_EVT: if (arg->params) { bt_mesh_free(arg->params); diff --git a/components/bt/esp_ble_mesh/common/atomic.c b/components/bt/esp_ble_mesh/common/atomic.c index 9c856cc3372..5f4f0fe4a98 100644 --- a/components/bt/esp_ble_mesh/common/atomic.c +++ b/components/bt/esp_ble_mesh/common/atomic.c @@ -13,7 +13,7 @@ /* * SPDX-FileCopyrightText: 2016 Intel Corporation * SPDX-FileCopyrightText: 2011-2014 Wind River Systems, Inc. - * SPDX-FileContributor: 2018-2024 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -24,20 +24,28 @@ #ifndef CONFIG_ATOMIC_OPERATIONS_BUILTIN /** -* -* @brief Atomic get primitive -* -* @param target memory location to read from -* -* This routine provides the atomic get primitive to atomically read -* a value from . It simply does an ordinary load. Note that -* is expected to be aligned to a 4-byte boundary. -* -* @return The value read from -*/ + * + * @brief Atomic get primitive + * + * @param target memory location to read from + * + * This routine provides the atomic get primitive to atomically read + * a value from . It simply does an ordinary load. Note that + * is expected to be aligned to a 4-byte boundary. + * + * @return The value read from + */ bt_mesh_atomic_val_t bt_mesh_atomic_get(const bt_mesh_atomic_t *target) { - return *target; + bt_mesh_atomic_val_t ret; + + bt_mesh_atomic_lock(); + + ret = *target; + + bt_mesh_atomic_unlock(); + + return ret; } /** diff --git a/components/bt/esp_ble_mesh/common/buf.c b/components/bt/esp_ble_mesh/common/buf.c index f988c4e8bdc..3b439436890 100644 --- a/components/bt/esp_ble_mesh/common/buf.c +++ b/components/bt/esp_ble_mesh/common/buf.c @@ -1,6 +1,6 @@ /* * SPDX-FileCopyrightText: 2015 Intel Corporation - * SPDX-FileContributor: 2018-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -378,6 +378,8 @@ void net_buf_reset(struct net_buf *buf) void net_buf_simple_init_with_data(struct net_buf_simple *buf, void *data, size_t size) { + NET_BUF_ASSERT(size <= UINT16_MAX); + buf->__buf = data; buf->data = data; buf->size = size; @@ -388,6 +390,7 @@ void net_buf_simple_reserve(struct net_buf_simple *buf, size_t reserve) { NET_BUF_ASSERT(buf); NET_BUF_ASSERT(buf->len == 0U); + NET_BUF_ASSERT(reserve <= buf->size); NET_BUF_DBG("buf %p reserve %zu", buf, reserve); buf->data = buf->__buf + reserve; @@ -416,18 +419,16 @@ struct net_buf *net_buf_slist_get(sys_slist_t *list) NET_BUF_ASSERT(list); bt_mesh_list_lock(); - buf = (void *)sys_slist_get(list); - bt_mesh_list_unlock(); + buf = (void *)sys_slist_get(list); if (!buf) { + bt_mesh_list_unlock(); return NULL; } /* Get any fragments belonging to this buffer */ for (frag = buf; (frag->flags & NET_BUF_FRAGS); frag = frag->frags) { - bt_mesh_list_lock(); frag->frags = (void *)sys_slist_get(list); - bt_mesh_list_unlock(); NET_BUF_ASSERT(frag->frags); @@ -435,6 +436,8 @@ struct net_buf *net_buf_slist_get(sys_slist_t *list) frag->flags &= ~NET_BUF_FRAGS; } + bt_mesh_list_unlock(); + /* Mark the end of the fragment list */ frag->frags = NULL; @@ -447,7 +450,10 @@ struct net_buf *net_buf_ref(struct net_buf *buf) NET_BUF_DBG("buf %p (old) ref %u pool %p", buf, buf->ref, buf->pool); + bt_mesh_buf_lock(); buf->ref++; + bt_mesh_buf_unlock(); + return buf; } @@ -459,6 +465,8 @@ void net_buf_unref(struct net_buf *buf) { NET_BUF_ASSERT(buf); + bt_mesh_buf_lock(); + while (buf) { struct net_buf *frags = buf->frags; struct net_buf_pool *pool = NULL; @@ -467,6 +475,7 @@ void net_buf_unref(struct net_buf *buf) if (!buf->ref) { NET_BUF_ERR("%s():%d: buf %p double free", func, line, buf); + bt_mesh_buf_unlock(); return; } #endif @@ -475,6 +484,7 @@ void net_buf_unref(struct net_buf *buf) /* Changed by Espressif. Add !buf->ref to avoid minus 0 */ if (!buf->ref || --buf->ref > 0) { + bt_mesh_buf_unlock(); return; } @@ -496,6 +506,8 @@ void net_buf_unref(struct net_buf *buf) buf = frags; } + + bt_mesh_buf_unlock(); } static uint8_t *fixed_data_alloc(struct net_buf *buf, size_t *size, int32_t timeout) @@ -525,6 +537,10 @@ static uint8_t *data_alloc(struct net_buf *buf, size_t *size, int32_t timeout) return pool->alloc->cb->alloc(buf, size, timeout); } +/** + * When using this function, Must ensure that the lock for + * buf->pool has been acquired; otherwise, race conditions may occur. + */ #if CONFIG_BLE_MESH_NET_BUF_LOG struct net_buf *net_buf_alloc_len_debug(struct net_buf_pool *pool, size_t size, int32_t timeout, const char *func, int line) @@ -541,11 +557,6 @@ struct net_buf *net_buf_alloc_len(struct net_buf_pool *pool, size_t size, NET_BUF_DBG("Alloc, pool %p, uninit_count %d, buf_count %d", pool, pool->uninit_count, pool->buf_count); - /* We need to lock interrupts temporarily to prevent race conditions - * when accessing pool->uninit_count. - */ - bt_mesh_buf_lock(); - /* If there are uninitialized buffers we're guaranteed to succeed * with the allocation one way or another. */ @@ -554,14 +565,11 @@ struct net_buf *net_buf_alloc_len(struct net_buf_pool *pool, size_t size, for (i = pool->buf_count; i > 0; i--) { buf = pool_get_uninit(pool, i); if (!buf->ref) { - bt_mesh_buf_unlock(); goto success; } } } - bt_mesh_buf_unlock(); - NET_BUF_ERR("Out of free buffer, pool %p", pool); return NULL; @@ -600,15 +608,25 @@ struct net_buf *net_buf_alloc_fixed_debug(struct net_buf_pool *pool, int line) { const struct net_buf_pool_fixed *fixed = pool->alloc->alloc_data; + struct net_buf *buf = NULL; - return net_buf_alloc_len_debug(pool, fixed->data_size, timeout, func, line); + bt_mesh_buf_lock(); + buf = net_buf_alloc_len_debug(pool, fixed->data_size, timeout, func, line); + bt_mesh_buf_unlock(); + + return buf; } #else struct net_buf *net_buf_alloc_fixed(struct net_buf_pool *pool, int32_t timeout) { const struct net_buf_pool_fixed *fixed = pool->alloc->alloc_data; + struct net_buf *buf = NULL; - return net_buf_alloc_len(pool, fixed->data_size, timeout); + bt_mesh_buf_lock(); + buf = net_buf_alloc_len(pool, fixed->data_size, timeout); + bt_mesh_buf_unlock(); + + return buf; } #endif diff --git a/components/bt/esp_ble_mesh/common/crypto_mbedtls.c b/components/bt/esp_ble_mesh/common/crypto_mbedtls.c index 4491fe779a9..bfafe70d4a2 100644 --- a/components/bt/esp_ble_mesh/common/crypto_mbedtls.c +++ b/components/bt/esp_ble_mesh/common/crypto_mbedtls.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -112,10 +112,14 @@ int bt_mesh_ccm_encrypt_raw_key(const uint8_t key[16], uint8_t nonce[13], uint8_t *enc_data, size_t mic_size) { struct bt_mesh_key mesh_key; + int ret; memcpy(mesh_key.key, key, 16); - return bt_mesh_ccm_encrypt(&mesh_key, nonce, plaintext, len, aad, aad_len, - enc_data, mic_size); + ret = bt_mesh_ccm_encrypt(&mesh_key, nonce, plaintext, len, aad, aad_len, + enc_data, mic_size); + + mbedtls_platform_zeroize(&mesh_key, sizeof(mesh_key)); + return ret; } int bt_mesh_ccm_decrypt_raw_key(const uint8_t key[16], uint8_t nonce[13], @@ -124,10 +128,14 @@ int bt_mesh_ccm_decrypt_raw_key(const uint8_t key[16], uint8_t nonce[13], uint8_t *plaintext, size_t mic_size) { struct bt_mesh_key mesh_key; + int ret; memcpy(mesh_key.key, key, 16); - return bt_mesh_ccm_decrypt(&mesh_key, nonce, enc_data, len, aad, aad_len, - plaintext, mic_size); + ret = bt_mesh_ccm_decrypt(&mesh_key, nonce, enc_data, len, aad, aad_len, + plaintext, mic_size); + + mbedtls_platform_zeroize(&mesh_key, sizeof(mesh_key)); + return ret; } int bt_mesh_aes_cmac_mesh_key(const struct bt_mesh_key *key, @@ -230,6 +238,10 @@ int bt_mesh_pub_key_gen(void) dh_pair.is_ready = false; do { + /** + * For now, there is no need to consider the security + * of the private key generated by the random function. + */ err = bt_mesh_rand(dh_pair.private_key, sizeof(dh_pair.private_key)); if (err) { BT_ERR("Failed to generate random private key"); @@ -360,12 +372,12 @@ bool bt_mesh_check_public_key_raw(const uint8_t key[64]) goto cleanup; } - ret = mbedtls_mpi_read_binary(&Q.MBEDTLS_PRIVATE(X), dh_pair.public_key, 32); + ret = mbedtls_mpi_read_binary(&Q.MBEDTLS_PRIVATE(X), key, 32); if (ret != 0) { goto cleanup; } - ret = mbedtls_mpi_read_binary(&Q.MBEDTLS_PRIVATE(Y), dh_pair.public_key + 32, 32); + ret = mbedtls_mpi_read_binary(&Q.MBEDTLS_PRIVATE(Y), key + 32, 32); if (ret != 0) { goto cleanup; } @@ -409,12 +421,12 @@ int bt_mesh_dhkey_gen_raw(const uint8_t *pub_key, const uint8_t *priv_key, } /* Load public key point */ - ret = mbedtls_mpi_read_binary(&Q.MBEDTLS_PRIVATE(X), dh_pair.public_key, 32); + ret = mbedtls_mpi_read_binary(&Q.MBEDTLS_PRIVATE(X), pub_key, 32); if (ret != 0) { goto cleanup; } - ret = mbedtls_mpi_read_binary(&Q.MBEDTLS_PRIVATE(Y), dh_pair.public_key + 32, 32); + ret = mbedtls_mpi_read_binary(&Q.MBEDTLS_PRIVATE(Y), pub_key + 32, 32); if (ret != 0) { goto cleanup; } diff --git a/components/bt/esp_ble_mesh/common/crypto_psa.c b/components/bt/esp_ble_mesh/common/crypto_psa.c index 340c027c390..ebb090b567d 100644 --- a/components/bt/esp_ble_mesh/common/crypto_psa.c +++ b/components/bt/esp_ble_mesh/common/crypto_psa.c @@ -1,6 +1,6 @@ /* * SPDX-FileCopyrightText: 2023 Nordic Semiconductor ASA - * SPDX-FileContributor: 2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2025-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -292,6 +292,7 @@ int bt_mesh_pub_key_gen(void) uint8_t private_key[PRIV_KEY_SIZE]; size_t key_len; int err; + int ret = 0; /* Destroy any existing key */ if (dh_pair.priv_key_id != PSA_KEY_ID_NULL) { @@ -300,15 +301,26 @@ int bt_mesh_pub_key_gen(void) } dh_pair.is_ready = false; - /* Generate a random private key (in little-endian format for storage) */ + /* Generate a random private key and let PSA validate the range. + * For NIST P-256, the private key scalar d must satisfy: 1 <= d < n. + * PSA will return PSA_ERROR_INVALID_ARGUMENT if the key is out of range. + */ + #define MAX_KEY_GEN_RETRIES 10 + int retries = 0; do { err = bt_mesh_rand(private_key, sizeof(private_key)); if (err) { BT_ERR("Failed to generate random private key"); - return err; + ret = err; + goto cleanup; } - /* Ensure the private key is valid (non-zero first bytes in BE) */ - } while (private_key[0] == 0 && private_key[1] == 0); + if (++retries > MAX_KEY_GEN_RETRIES) { + BT_ERR("Exceeded maximum key generation retries"); + ret = -EIO; + goto cleanup; + } + /* Minimal check for obviously invalid keys (all zeros in MSB region) */ + } while (private_key[0] == 0 && private_key[1] == 0 && private_key[2] == 0 && private_key[3] == 0); /* Configure key attributes for ECDH with P-256 */ psa_set_key_usage_flags(&key_attributes, PSA_KEY_USAGE_DERIVE); @@ -323,7 +335,8 @@ int bt_mesh_pub_key_gen(void) if (status != PSA_SUCCESS) { BT_ERR("PSA import private key failed: %d", status); psa_reset_key_attributes(&key_attributes); - return -EIO; + ret = -EIO; + goto cleanup; } /* Export public key (PSA computes it from the private key) */ @@ -334,13 +347,20 @@ int bt_mesh_pub_key_gen(void) psa_destroy_key(dh_pair.priv_key_id); dh_pair.priv_key_id = PSA_KEY_ID_NULL; psa_reset_key_attributes(&key_attributes); - return -EIO; + ret = -EIO; + goto cleanup; } dh_pair.is_ready = true; psa_reset_key_attributes(&key_attributes); - return 0; +cleanup: + /* Securely clear private key from stack to prevent key leakage */ + memset(private_key, 0, sizeof(private_key)); + /* Memory barrier to prevent compiler from optimizing out the memset */ + __asm__ __volatile__("" : : "r"(private_key) : "memory"); + + return ret; } const uint8_t *bt_mesh_pub_key_get_raw(void) @@ -360,6 +380,8 @@ void bt_mesh_set_private_key_raw(const uint8_t pri_key[32]) psa_status_t status; size_t key_len; + BT_DBG("Privkey:%s", bt_hex(pri_key, PRIV_KEY_SIZE)); + /* Destroy any existing key */ if (dh_pair.priv_key_id != PSA_KEY_ID_NULL) { psa_destroy_key(dh_pair.priv_key_id); @@ -393,7 +415,6 @@ void bt_mesh_set_private_key_raw(const uint8_t pri_key[32]) } BT_DBG("Pubkey:%s", bt_hex(&dh_pair.public_key[1], PUB_KEY_SIZE)); - BT_DBG("Privkey:%s", bt_hex(pri_key, PRIV_KEY_SIZE)); dh_pair.is_ready = true; psa_reset_key_attributes(&attributes); } @@ -407,7 +428,7 @@ bool bt_mesh_check_public_key_raw(const uint8_t key[64]) /* PSA requires 0x04 prefix for uncompressed point */ pub_be[0] = 0x04; - /* Convert from little-endian to big-endian */ + /* Copy X and Y coordinates (already in big-endian format) */ memcpy(&pub_be[1], key, 32); memcpy(&pub_be[33], key + 32, 32); @@ -587,15 +608,16 @@ void bt_mesh_key_assign(struct bt_mesh_key *dst, const struct bt_mesh_key *src) int bt_mesh_key_destroy(const struct bt_mesh_key *key) { psa_status_t status; + psa_key_id_t key_id = key->key; - status = psa_destroy_key(key->key); + status = psa_destroy_key(key_id); if (status != PSA_SUCCESS) { BT_ERR("PSA destroy key failed: %d", status); return -EIO; } #if CONFIG_BT_SETTINGS - return keyid_free(key->key); + return keyid_free(key_id); #else return 0; #endif diff --git a/components/bt/esp_ble_mesh/common/crypto_tc.c b/components/bt/esp_ble_mesh/common/crypto_tc.c index 24c8752c2a6..11979484e43 100644 --- a/components/bt/esp_ble_mesh/common/crypto_tc.c +++ b/components/bt/esp_ble_mesh/common/crypto_tc.c @@ -72,8 +72,8 @@ int bt_mesh_ccm_encrypt(const struct bt_mesh_key *key, uint8_t nonce[13], return -EIO; } - if (tc_ccm_generation_encryption(enc_data, len + mic_size, aad, aad_len, - plaintext, len, &ccm) == TC_CRYPTO_FAIL) { + if (tc_ccm_generation_encryption(enc_data, (unsigned int)(len + mic_size), aad, (unsigned int)aad_len, + plaintext, (unsigned int)len, &ccm) == TC_CRYPTO_FAIL) { return -EIO; } diff --git a/components/bt/esp_ble_mesh/common/include/mesh/atomic.h b/components/bt/esp_ble_mesh/common/include/mesh/atomic.h index b284974363a..16975d4a4d5 100644 --- a/components/bt/esp_ble_mesh/common/include/mesh/atomic.h +++ b/components/bt/esp_ble_mesh/common/include/mesh/atomic.h @@ -168,7 +168,7 @@ extern bt_mesh_atomic_val_t bt_mesh_atomic_and(bt_mesh_atomic_t *target, bt_mesh #ifdef CONFIG_ATOMIC_OPERATIONS_BUILTIN static inline bool bt_mesh_atomic_cas(bt_mesh_atomic_t *target, bt_mesh_atomic_val_t excepted, bt_mesh_atomic_val_t new_val) { - return __atomic_compare_exchange_n(target, &excepted, &new_val, false, __ATOMIC_SEQ_CST, __ATOMIC_SEQ_CST); + return __atomic_compare_exchange_n(target, &excepted, new_val, false, __ATOMIC_SEQ_CST, __ATOMIC_SEQ_CST); } #else extern bool bt_mesh_atomic_cas(bt_mesh_atomic_t *target, bt_mesh_atomic_val_t excepted, bt_mesh_atomic_val_t new_val); diff --git a/components/bt/esp_ble_mesh/common/include/mesh/mutex.h b/components/bt/esp_ble_mesh/common/include/mesh/mutex.h index 0cc47eb01a0..b32f0dcd722 100644 --- a/components/bt/esp_ble_mesh/common/include/mesh/mutex.h +++ b/components/bt/esp_ble_mesh/common/include/mesh/mutex.h @@ -50,7 +50,9 @@ void bt_mesh_atomic_lock(void); void bt_mesh_atomic_unlock(void); void bt_mesh_mutex_init(void); +#if CONFIG_BLE_MESH_DEINIT void bt_mesh_mutex_deinit(void); +#endif /* CONFIG_BLE_MESH_DEINIT */ #ifdef __cplusplus } diff --git a/components/bt/esp_ble_mesh/common/include/mesh/utils.h b/components/bt/esp_ble_mesh/common/include/mesh/utils.h index 4ef522ee322..4bcbe8df2da 100644 --- a/components/bt/esp_ble_mesh/common/include/mesh/utils.h +++ b/components/bt/esp_ble_mesh/common/include/mesh/utils.h @@ -41,6 +41,13 @@ extern "C" { #define INT_TO_POINTER(x) ((void *) (x)) #endif +#ifndef ESP_ASSUME_NONNULL +/** + * @brief Assume pointer parameters are non-null unless explicitly marked otherwise. +*/ +#define ESP_ASSUME_NONNULL(ptr) +#endif + /* Evaluates to 0 if cond is true-ish; compile error otherwise */ #ifndef ZERO_OR_COMPILE_ERROR #define ZERO_OR_COMPILE_ERROR(cond) ((int) sizeof(char[1 - 2 * !(cond)]) - 1) diff --git a/components/bt/esp_ble_mesh/common/kernel.c b/components/bt/esp_ble_mesh/common/kernel.c index 3db4ed45e12..e555bd42eef 100644 --- a/components/bt/esp_ble_mesh/common/kernel.c +++ b/components/bt/esp_ble_mesh/common/kernel.c @@ -1,14 +1,18 @@ /* * SPDX-FileCopyrightText: 2016 Intel Corporation * SPDX-FileCopyrightText: 2016 Wind River Systems, Inc. - * SPDX-FileContributor: 2020-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ +#include "mesh/timer.h" #include "mesh/kernel.h" void k_sleep(int32_t duration) { - vTaskDelay(duration / portTICK_PERIOD_MS); + if (duration < 0 && duration != K_FOREVER) { + duration = 0; + } + vTaskDelay((duration == K_FOREVER) ? portMAX_DELAY : (duration / portTICK_PERIOD_MS)); } diff --git a/components/bt/esp_ble_mesh/common/mutex.c b/components/bt/esp_ble_mesh/common/mutex.c index d3d280c87b5..2cbd849d1aa 100644 --- a/components/bt/esp_ble_mesh/common/mutex.c +++ b/components/bt/esp_ble_mesh/common/mutex.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2024 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -64,6 +64,8 @@ void bt_mesh_mutex_lock(bt_mesh_mutex_t *mutex) if (mutex->mutex) { xSemaphoreTake(mutex->mutex, portMAX_DELAY); + } else { + BT_ERR("Lock, no mutex"); } } @@ -76,6 +78,8 @@ void bt_mesh_mutex_unlock(bt_mesh_mutex_t *mutex) if (mutex->mutex) { xSemaphoreGive(mutex->mutex); + } else { + BT_ERR("Unlock, no mutex"); } } @@ -120,6 +124,8 @@ void bt_mesh_r_mutex_lock(bt_mesh_mutex_t *mutex) if (mutex->mutex) { xSemaphoreTakeRecursive(mutex->mutex, portMAX_DELAY); + } else { + BT_ERR("Lock, no recursive mutex"); } } @@ -132,6 +138,8 @@ void bt_mesh_r_mutex_unlock(bt_mesh_mutex_t *mutex) if (mutex->mutex) { xSemaphoreGiveRecursive(mutex->mutex); + } else { + BT_ERR("Unlock, no recursive mutex"); } } @@ -152,6 +160,11 @@ void bt_mesh_c_semaphore_create(bt_mesh_mutex_t *mutex, int max, int init) return; } + if (max <= 0 || init < 0 || init > max) { + BT_ERR("Create, invalid semaphore parameters (max=%d, init=%d)", max, init); + return; + } + #if CONFIG_BLE_MESH_FREERTOS_STATIC_ALLOC #if CONFIG_BLE_MESH_FREERTOS_STATIC_ALLOC_EXTERNAL mutex->buffer = heap_caps_calloc_prefer(1, sizeof(StaticQueue_t), 2, MALLOC_CAP_SPIRAM|MALLOC_CAP_8BIT, MALLOC_CAP_INTERNAL|MALLOC_CAP_8BIT); @@ -175,7 +188,11 @@ void bt_mesh_c_semaphore_take(bt_mesh_mutex_t *mutex, uint32_t timeout) } if (mutex->mutex) { - xSemaphoreTake(mutex->mutex, timeout / portTICK_PERIOD_MS); + if (xSemaphoreTake(mutex->mutex, timeout / portTICK_PERIOD_MS) != pdTRUE) { + BT_ERR("Failed to take semaphore"); + } + } else { + BT_ERR("Lock, no semaphore"); } } @@ -188,63 +205,65 @@ void bt_mesh_c_semaphore_give(bt_mesh_mutex_t *mutex) if (mutex->mutex) { xSemaphoreGive(mutex->mutex); + } else { + BT_ERR("Unlock, no semaphore"); } } void bt_mesh_alarm_lock(void) { - bt_mesh_mutex_lock(&alarm_lock); + bt_mesh_r_mutex_lock(&alarm_lock); } void bt_mesh_alarm_unlock(void) { - bt_mesh_mutex_unlock(&alarm_lock); + bt_mesh_r_mutex_unlock(&alarm_lock); } void bt_mesh_list_lock(void) { - bt_mesh_mutex_lock(&list_lock); + bt_mesh_r_mutex_lock(&list_lock); } void bt_mesh_list_unlock(void) { - bt_mesh_mutex_unlock(&list_lock); + bt_mesh_r_mutex_unlock(&list_lock); } void bt_mesh_buf_lock(void) { - bt_mesh_mutex_lock(&buf_lock); + bt_mesh_r_mutex_lock(&buf_lock); } void bt_mesh_buf_unlock(void) { - bt_mesh_mutex_unlock(&buf_lock); + bt_mesh_r_mutex_unlock(&buf_lock); } void bt_mesh_atomic_lock(void) { - bt_mesh_mutex_lock(&atomic_lock); + bt_mesh_r_mutex_lock(&atomic_lock); } void bt_mesh_atomic_unlock(void) { - bt_mesh_mutex_unlock(&atomic_lock); + bt_mesh_r_mutex_unlock(&atomic_lock); } void bt_mesh_mutex_init(void) { - bt_mesh_mutex_create(&alarm_lock); - bt_mesh_mutex_create(&list_lock); - bt_mesh_mutex_create(&buf_lock); - bt_mesh_mutex_create(&atomic_lock); + bt_mesh_r_mutex_create(&alarm_lock); + bt_mesh_r_mutex_create(&list_lock); + bt_mesh_r_mutex_create(&buf_lock); + bt_mesh_r_mutex_create(&atomic_lock); } #if CONFIG_BLE_MESH_DEINIT void bt_mesh_mutex_deinit(void) { - bt_mesh_mutex_free(&alarm_lock); - bt_mesh_mutex_free(&list_lock); - bt_mesh_mutex_free(&buf_lock); - bt_mesh_mutex_free(&atomic_lock); + bt_mesh_r_mutex_free(&alarm_lock); + bt_mesh_r_mutex_free(&list_lock); + bt_mesh_r_mutex_free(&buf_lock); + bt_mesh_r_mutex_free(&atomic_lock); } #endif /* CONFIG_BLE_MESH_DEINIT */ diff --git a/components/bt/esp_ble_mesh/common/queue.c b/components/bt/esp_ble_mesh/common/queue.c index 1fc3d66a618..3e19dca4d89 100644 --- a/components/bt/esp_ble_mesh/common/queue.c +++ b/components/bt/esp_ble_mesh/common/queue.c @@ -35,7 +35,7 @@ int bt_mesh_queue_init(bt_mesh_queue_t *queue, uint16_t queue_size, uint8_t item int bt_mesh_queue_deinit(bt_mesh_queue_t *queue) { - __ASSERT(queue, "Invalid queue init parameters"); + __ASSERT(queue && queue->handle, "Invalid queue deinit parameters"); vQueueDelete(queue->handle); queue->handle = NULL; #if CONFIG_BLE_MESH_FREERTOS_STATIC_ALLOC diff --git a/components/bt/esp_ble_mesh/common/timer.c b/components/bt/esp_ble_mesh/common/timer.c index 7547eecdbb6..95b6b73911d 100644 --- a/components/bt/esp_ble_mesh/common/timer.c +++ b/components/bt/esp_ble_mesh/common/timer.c @@ -135,7 +135,7 @@ int k_delayed_work_submit(struct k_delayed_work *work, int32_t delay) } /* If delay is 0, call the corresponding timeout handler. */ - if (delay == 0) { + if (delay <= 0) { k_work_submit(&work->work); return 0; } diff --git a/components/bt/esp_ble_mesh/common/utils.c b/components/bt/esp_ble_mesh/common/utils.c index 799035e4b30..05ef7436948 100644 --- a/components/bt/esp_ble_mesh/common/utils.c +++ b/components/bt/esp_ble_mesh/common/utils.c @@ -16,7 +16,10 @@ const char *bt_hex(const void *buf, size_t len) { static const char hex[] = "0123456789abcdef"; - static char hexbufs[2][129]; + /* WARNING: Buffer count limits concurrent bt_hex() calls in a single + * expression or across threads. Increase if more simultaneous calls needed. + */ + static char hexbufs[4][129]; static uint8_t curbuf; const uint8_t *b = buf; char *str = NULL; @@ -25,6 +28,11 @@ const char *bt_hex(const void *buf, size_t len) str = hexbufs[curbuf++]; curbuf %= ARRAY_SIZE(hexbufs); + if (buf == NULL) { + str[0] = '\0'; + return str; + } + len = MIN(len, (sizeof(hexbufs[0]) - 1) / 2); for (i = 0; i < len; i++) { @@ -39,6 +47,10 @@ const char *bt_hex(const void *buf, size_t len) void mem_rcopy(uint8_t *dst, uint8_t const *src, uint16_t len) { + if (dst == NULL || src == NULL || len == 0) { + return; + } + src += len; while (len--) { *dst++ = *--src; diff --git a/components/bt/esp_ble_mesh/core/access.c b/components/bt/esp_ble_mesh/core/access.c index 2f70e64eeae..584765fb6f7 100644 --- a/components/bt/esp_ble_mesh/core/access.c +++ b/components/bt/esp_ble_mesh/core/access.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -141,6 +141,11 @@ static int32_t next_period(struct bt_mesh_model *mod) return 0; } + if (pub->period_start == 0) { + BT_ERR("PubFailed,TryPubInNxtPeriod"); + return period; + } + elapsed = k_uptime_get_32() - pub->period_start; BT_INFO("Elapsed %u Period %u", elapsed, period); @@ -244,6 +249,13 @@ static int publish_retransmit(struct bt_mesh_model *mod) /* Tag with send-segmented */ ctx.send_tag |= BLE_MESH_TAG_SEND_SEGMENTED; } +#if CONFIG_BLE_MESH_LONG_PACKET + if ((pub->msg->len <= MIN(BLE_MESH_EXT_TX_SDU_MAX, BLE_MESH_EXT_SDU_MAX_LEN) - BLE_MESH_MIC_SHORT) && + (pub->msg->len > MIN(BLE_MESH_TX_SDU_MAX, BLE_MESH_SDU_MAX_LEN) - BLE_MESH_MIC_SHORT)) { + ctx.enh.long_pkt_cfg_used = true; + ctx.enh.long_pkt_cfg = BLE_MESH_LONG_PACKET_PREFER; + } +#endif /* CONFIG_BLE_MESH_LONG_PACKET */ BT_DBG("NetIdx 0x%04x AppIdx 0x%04x Dst 0x%04x", ctx.net_idx, ctx.app_idx, ctx.addr); @@ -316,13 +328,16 @@ static void mod_publish(struct k_work *work) * In the event, users can update the context of the publish message * which will be published in the next period. */ - if (pub->update && pub->update(pub->mod)) { - /* Cancel this publish attempt. */ - BT_ERR("Update failed, skipping publish (err %d)", err); + if (pub->update) { + err = pub->update(pub->mod); + if (err) { + /* Cancel this publish attempt. */ + BT_ERR("Update failed, skipping publish (err %d)", err); - pub->period_start = k_uptime_get_32(); - publish_retransmit_end(err, pub); - return; + pub->period_start = k_uptime_get_32(); + publish_retransmit_end(err, pub); + return; + } } err = bt_mesh_model_publish(pub->mod); @@ -335,6 +350,16 @@ struct bt_mesh_elem *bt_mesh_model_elem(const struct bt_mesh_model *mod) { BT_DBG("ModelElem, ElemIdx %u", mod->elem_idx); + if (!comp_0) { + BT_ERR("comp_0 not initialized"); + return NULL; + } + + if (mod->elem_idx >= comp_0->elem_count) { + BT_ERR("Invalid element index %u", mod->elem_idx); + return NULL; + } + return &comp_0->elem[mod->elem_idx]; } @@ -428,7 +453,7 @@ int bt_mesh_comp_register(const struct bt_mesh_comp *comp) BT_DBG("CompRegister, ElemCount %u", comp->elem_count); /* There must be at least one element */ - if (!comp->elem_count) { + if (!comp->elem_count || comp->elem_count > BLE_MESH_MODEL_MAX_ELEM_COUNT) { return -EINVAL; } @@ -504,6 +529,20 @@ void bt_mesh_comp_provision(uint16_t addr) { int i; + if (!comp_0) { + BT_ERR("comp_0 not initialized"); + return; + } + + /* Validate unicast address range: addr must be valid (0x0001-0x7FFF) and + * addr + elem_count - 1 must not exceed 0x7FFF (unicast address upper bound). + */ + if (!BLE_MESH_ADDR_IS_UNICAST(addr) || + (uint32_t)addr + comp_0->elem_count - 1 > 0x7FFF) { + BT_ERR("Address range overflow: addr 0x%04x, elem_count %u", addr, comp_0->elem_count); + return; + } + dev_primary_addr = addr; BT_INFO("CompProvision, PrimaryAddr 0x%04x ElemCount %u", addr, comp_0->elem_count); @@ -585,6 +624,11 @@ struct bt_mesh_elem *bt_mesh_elem_find(uint16_t addr) BT_DBG("ElemFind, Addr 0x%04x", addr); + if (!comp_0) { + BT_ERR("comp_0 not initialized"); + return NULL; + } + if (BLE_MESH_ADDR_IS_UNICAST(addr)) { index = (addr - comp_0->elem[0].addr); if (index < comp_0->elem_count) { @@ -609,6 +653,11 @@ bool bt_mesh_has_addr(uint16_t addr) { uint16_t index; + if (!comp_0) { + BT_ERR("comp_0 not initialized"); + return false; + } + if (BLE_MESH_ADDR_IS_UNICAST(addr)) { return bt_mesh_elem_find(addr) != NULL; } @@ -626,6 +675,11 @@ bool bt_mesh_has_addr(uint16_t addr) uint8_t bt_mesh_elem_count(void) { + if (!comp_0) { + BT_ERR("comp_0 not initialized"); + return 0; + } + BT_DBG("ElemCount %u", comp_0->elem_count); return comp_0->elem_count; @@ -797,6 +851,11 @@ void bt_mesh_model_recv(struct bt_mesh_net_rx *rx, struct net_buf_simple *buf) rx->ctx.app_idx, rx->ctx.addr, rx->ctx.recv_dst); BT_INFO("Len %u: %s", buf->len, bt_hex(buf->data, buf->len)); + if (!comp_0) { + BT_ERR("comp_0 not initialized"); + return; + } + if (get_opcode(buf, &opcode, true) < 0) { BT_WARN("Unable to decode OpCode"); return; @@ -911,7 +970,7 @@ static bool ready_to_send(uint16_t dst) if (IS_ENABLED(CONFIG_BLE_MESH_PROVISIONER) && bt_mesh_is_provisioner_en()) { if (bt_mesh_provisioner_check_msg_dst(dst) == false && - bt_mesh_elem_find(dst) == false) { + bt_mesh_elem_find(dst) == NULL) { BT_ERR("Failed to find Dst 0x%04x", dst); return false; } @@ -1205,10 +1264,22 @@ int bt_mesh_model_publish(struct bt_mesh_model *model) return -EADDRNOTAVAIL; } +#if CONFIG_BLE_MESH_LONG_PACKET + if (pub->msg->len + BLE_MESH_MIC_SHORT > MIN(BLE_MESH_EXT_TX_SDU_MAX, BLE_MESH_EXT_SDU_MAX_LEN)) { + BT_ERR("Message does not fit extended maximum SDU size"); + return -EMSGSIZE; + } + if ((pub->msg->len <= MIN(BLE_MESH_EXT_TX_SDU_MAX, BLE_MESH_EXT_SDU_MAX_LEN) - BLE_MESH_MIC_SHORT) && + (pub->msg->len > MIN(BLE_MESH_TX_SDU_MAX, BLE_MESH_SDU_MAX_LEN) - BLE_MESH_MIC_SHORT)) { + tx.ctx->enh.long_pkt_cfg_used = true; + tx.ctx->enh.long_pkt_cfg = BLE_MESH_LONG_PACKET_PREFER; + } +#else if (pub->msg->len + BLE_MESH_MIC_SHORT > MIN(BLE_MESH_TX_SDU_MAX, BLE_MESH_SDU_MAX_LEN)) { BT_ERR("Message does not fit maximum SDU size"); return -EMSGSIZE; } +#endif if (pub->count) { BT_WARN("Clearing publish retransmit timer"); @@ -1245,6 +1316,7 @@ int bt_mesh_model_publish(struct bt_mesh_model *model) bt_mesh_model_pub_use_directed(&tx, pub->directed_pub_policy); #endif /* CONFIG_BLE_MESH_DF_SRV */ + pub->period_start = 0; pub->count = BLE_MESH_PUB_TRANSMIT_COUNT(pub->retransmit); BT_INFO("PubCount %u PubInterval %u", diff --git a/components/bt/esp_ble_mesh/core/access.h b/components/bt/esp_ble_mesh/core/access.h index 669cff788c2..f98a2187900 100644 --- a/components/bt/esp_ble_mesh/core/access.h +++ b/components/bt/esp_ble_mesh/core/access.h @@ -15,6 +15,8 @@ extern "C" { #endif +#define BLE_MESH_MODEL_MAX_ELEM_COUNT 255 + /* bt_mesh_model.flags */ enum { BLE_MESH_MOD_BIND_PENDING = BIT(0), diff --git a/components/bt/esp_ble_mesh/core/adv.c b/components/bt/esp_ble_mesh/core/adv.c index e35d34c993c..e6de7c9d1b7 100644 --- a/components/bt/esp_ble_mesh/core/adv.c +++ b/components/bt/esp_ble_mesh/core/adv.c @@ -144,7 +144,7 @@ static int adv_send(struct net_buf *buf) struct bt_mesh_ble_adv_data data = {0}; struct bt_mesh_ble_adv_tx *tx = cb_data; - if (tx == NULL) { + if (tx == NULL || tx->buf == NULL) { BT_ERR("Invalid adv user data"); net_buf_unref(buf); return -EINVAL; @@ -217,7 +217,7 @@ static QueueHandle_t relay_adv_handle_get(void) adv_type = bt_mesh_adv_types_mgmt_get(BLE_MESH_ADV_RELAY_DATA); - if (adv_type->adv_q == NULL) { + if (adv_type == NULL || adv_type->adv_q == NULL) { BT_DBG("HandleNotFound"); return NULL; } diff --git a/components/bt/esp_ble_mesh/core/adv_common.c b/components/bt/esp_ble_mesh/core/adv_common.c index bf8e33e506b..37790fe10c3 100644 --- a/components/bt/esp_ble_mesh/core/adv_common.c +++ b/components/bt/esp_ble_mesh/core/adv_common.c @@ -216,6 +216,7 @@ int bt_mesh_adv_inst_deinit(enum bt_mesh_adv_inst_type inst_type) static struct bt_mesh_adv *adv_alloc(int id, enum bt_mesh_adv_type type) { BT_DBG("AdvAlloc, ID %d", id); + assert(id >= 0 && id < CONFIG_BLE_MESH_ADV_BUF_COUNT); init_adv_with_defaults(&adv_pool[id], type); return &adv_pool[id]; } @@ -700,7 +701,7 @@ void bt_mesh_relay_adv_init(void) &relay_adv_buf_pool, &relay_adv_alloc); #if CONFIG_BLE_MESH_EXT_ADV bt_mesh_adv_type_init(BLE_MESH_ADV_EXT_RELAY_DATA, &relay_adv_queue, - &ext_adv_buf_pool, &ext_relay_adv_alloc); + &ext_relay_adv_buf_pool, &ext_relay_adv_alloc); #if CONFIG_BLE_MESH_LONG_PACKET && CONFIG_BLE_MESH_LONG_PACKET_RELAY_ADV_BUF_COUNT bt_mesh_adv_type_init(BLE_MESH_ADV_EXT_LONG_RELAY_DATA, &relay_adv_queue, &ext_long_relay_adv_buf_pool, ext_long_relay_adv_alloc); diff --git a/components/bt/esp_ble_mesh/core/beacon.c b/components/bt/esp_ble_mesh/core/beacon.c index 4f030ec99d6..39c0188cc89 100644 --- a/components/bt/esp_ble_mesh/core/beacon.c +++ b/components/bt/esp_ble_mesh/core/beacon.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2024 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -225,13 +225,14 @@ static int secure_beacon_send(void) #if (CONFIG_BLE_MESH_NODE && CONFIG_BLE_MESH_PB_ADV) static int unprovisioned_beacon_send(void) { + const struct bt_mesh_prov *prov = bt_mesh_prov_get(); uint8_t uri_hash[16] = {0}; struct net_buf *buf = NULL; uint16_t oob_info = 0U; BT_DBG("UnprovisionedBeaconSend"); - if (bt_mesh_prov_get() == NULL) { + if (prov == NULL) { BT_ERR("No provisioning context provided"); return -EINVAL; } @@ -243,13 +244,13 @@ static int unprovisioned_beacon_send(void) } net_buf_add_u8(buf, BEACON_TYPE_UNPROVISIONED); - net_buf_add_mem(buf, bt_mesh_prov_get()->uuid, 16); + net_buf_add_mem(buf, prov->uuid, 16); - if (bt_mesh_prov_get()->uri && - bt_mesh_s1(bt_mesh_prov_get()->uri, uri_hash) == 0) { - oob_info = bt_mesh_prov_get()->oob_info | BLE_MESH_PROV_OOB_URI; + if (prov->uri && + bt_mesh_s1(prov->uri, uri_hash) == 0) { + oob_info = prov->oob_info | BLE_MESH_PROV_OOB_URI; } else { - oob_info = bt_mesh_prov_get()->oob_info; + oob_info = prov->oob_info; } net_buf_add_be16(buf, oob_info); @@ -258,7 +259,7 @@ static int unprovisioned_beacon_send(void) bt_mesh_adv_send(buf, UNPROV_XMIT, NULL, NULL); net_buf_unref(buf); - if (bt_mesh_prov_get()->uri) { + if (prov->uri) { size_t len = 0; buf = bt_mesh_adv_create(BLE_MESH_ADV_URI, K_NO_WAIT); @@ -267,14 +268,14 @@ static int unprovisioned_beacon_send(void) return -ENOBUFS; } - len = strlen(bt_mesh_prov_get()->uri); + len = strlen(prov->uri); - BT_DBG("URI %u: %s", len, bt_mesh_prov_get()->uri); + BT_DBG("URI %u: %s", len, prov->uri); if (net_buf_tailroom(buf) < len) { BT_WARN("Too long URI to fit advertising data"); } else { - net_buf_add_mem(buf, bt_mesh_prov_get()->uri, len); + net_buf_add_mem(buf, prov->uri, len); bt_mesh_adv_send(buf, UNPROV_XMIT, NULL, NULL); } @@ -561,6 +562,7 @@ void bt_mesh_beacon_init(void) /* private beacon init */ if (bt_mesh_private_beacon_timer_init()) { BT_ERR("Failed to create a mpb_timer"); + k_delayed_work_free(&snb_timer); return; } #endif /* CONFIG_BLE_MESH_PRB_SRV */ diff --git a/components/bt/esp_ble_mesh/core/bluedroid_host/adapter.c b/components/bt/esp_ble_mesh/core/bluedroid_host/adapter.c index a3bd5491c1e..0f406f36e30 100644 --- a/components/bt/esp_ble_mesh/core/bluedroid_host/adapter.c +++ b/components/bt/esp_ble_mesh/core/bluedroid_host/adapter.c @@ -455,7 +455,7 @@ void ble_mesh_5_gap_callback(tBTA_DM_BLE_5_GAP_EVENT event, break; case BTA_DM_BLE_5_GAP_EXT_SCAN_STOP_COMPLETE_EVT: if (params->scan_stop.status != BTM_SUCCESS) { - BT_ERR("BTM_BLE_5_GAP_EXT_SCAN_START_COMPLETE_EVT Failed"); + BT_ERR("BTA_DM_BLE_5_GAP_EXT_SCAN_STOP_COMPLETE_EVT Failed"); } break; default: @@ -571,7 +571,7 @@ static int start_le_scan(uint8_t scan_type, uint16_t interval, uint16_t window, if (interval == 0 || interval < window) { BT_ERR("invalid scan param itvl %d win %d", interval, window); - return EINVAL; + return -EINVAL; } ext_scan_params.own_addr_type = BLE_MESH_ADDR_PUBLIC; @@ -970,11 +970,19 @@ int bt_mesh_ble_ext_adv_start(const uint8_t inst_id, if (data && param->adv_type != BLE_MESH_ADV_DIRECT_IND && param->adv_type != BLE_MESH_ADV_DIRECT_IND_LOW_DUTY) { if (data->adv_data_len) { + if (data->adv_data_len > sizeof(set.data)) { + BT_ERR("adv_data_len %u exceeds buffer size %zu", data->adv_data_len, sizeof(set.data)); + return -EINVAL; + } set.len = data->adv_data_len; memcpy(set.data, data->adv_data, data->adv_data_len); BTA_DmBleGapConfigExtAdvDataRaw(false, inst_id, set.len, set.data); } if (data->scan_rsp_data_len && param->adv_type != BLE_MESH_ADV_NONCONN_IND) { + if (data->scan_rsp_data_len > sizeof(set.data)) { + BT_ERR("scan_rsp_data_len %u exceeds buffer size %zu", data->scan_rsp_data_len, sizeof(set.data)); + return -EINVAL; + } set.len = data->scan_rsp_data_len; memcpy(set.data, data->scan_rsp_data, data->scan_rsp_data_len); BTA_DmBleGapConfigExtAdvDataRaw(true, inst_id, set.len, set.data); @@ -1608,6 +1616,10 @@ int bt_mesh_gatts_service_register(struct bt_mesh_gatt_service *svc) break; } case BLE_MESH_UUID_GATT_CHRC_VAL: { + if (i + 1 >= svc->attr_count) { + BT_ERR("Characteristic declaration at index %d missing value attribute", i); + goto cleanup; + } gatts_future_mesh = future_new(); struct bt_mesh_gatt_char *gatts_chrc = (struct bt_mesh_gatt_char *)svc->attrs[i].user_data; bta_uuid_to_bt_mesh_uuid(&bta_uuid, gatts_chrc->uuid); diff --git a/components/bt/esp_ble_mesh/core/cfg_cli.c b/components/bt/esp_ble_mesh/core/cfg_cli.c index 6daae86afed..8946e45a558 100644 --- a/components/bt/esp_ble_mesh/core/cfg_cli.c +++ b/components/bt/esp_ble_mesh/core/cfg_cli.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -759,6 +759,12 @@ int bt_mesh_cfg_ttl_set(bt_mesh_client_common_param_t *param, uint8_t val) { BT_DBG("TTLSet, Val 0x%02x", val); + /* Per BLE Mesh spec, TTL 0x01 is prohibited and 0x80-0xFF are reserved */ + if (val == 0x01 || val > 0x7F) { + BT_ERR("Invalid TTL value 0x%02x", val); + return -EINVAL; + } + return send_msg_with_u8(param, OP_DEFAULT_TTL_SET, val); } diff --git a/components/bt/esp_ble_mesh/core/cfg_srv.c b/components/bt/esp_ble_mesh/core/cfg_srv.c index 6f7396bc6ba..a0155398468 100644 --- a/components/bt/esp_ble_mesh/core/cfg_srv.c +++ b/components/bt/esp_ble_mesh/core/cfg_srv.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2024 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -911,6 +911,7 @@ static void default_ttl_set(struct bt_mesh_model *model, } } else { BT_WARN("Prohibited Default TTL value 0x%02x", buf->data[0]); + return; } bt_mesh_model_msg_init(&msg, OP_DEFAULT_TTL_STATUS); @@ -1348,7 +1349,7 @@ static struct label *va_find(const uint8_t *label_uuid, for (i = 0; i < ARRAY_SIZE(labels); i++) { if (labels[i].ref == 0) { - if (free_slot != NULL) { + if (free_slot != NULL && *free_slot == NULL) { *free_slot = &labels[i]; } continue; @@ -1370,6 +1371,9 @@ uint8_t va_add(uint8_t *label_uuid, uint16_t *addr) update = va_find(label_uuid, &free_slot); if (update) { + if (update->ref == UINT16_MAX) { + return STATUS_INSUFF_RESOURCES; + } update->ref++; va_store(update); @@ -2590,6 +2594,7 @@ static void net_key_update(struct bt_mesh_model *model, switch (sub->kr_phase) { case BLE_MESH_KR_NORMAL: if (!memcmp(buf->data, sub->keys[0].net, 16)) { + send_net_key_status(model, ctx, idx, STATUS_SUCCESS); return; } break; diff --git a/components/bt/esp_ble_mesh/core/crypto.c b/components/bt/esp_ble_mesh/core/crypto.c index 8e85c8f4361..6c83c281ab0 100644 --- a/components/bt/esp_ble_mesh/core/crypto.c +++ b/components/bt/esp_ble_mesh/core/crypto.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -28,14 +28,19 @@ int bt_mesh_k1(const uint8_t *ikm, size_t ikm_len, const uint8_t salt[16], const char *info, uint8_t okm[16]) { + uint8_t t[16] = {0}; int err = 0; - err = bt_mesh_aes_cmac_one(salt, ikm, ikm_len, okm); + err = bt_mesh_aes_cmac_one(salt, ikm, ikm_len, t); if (err < 0) { + memset(t, 0, sizeof(t)); return err; } - return bt_mesh_aes_cmac_one(okm, info, strlen(info), okm); + err = bt_mesh_aes_cmac_one(t, info, strlen(info), okm); + + memset(t, 0, sizeof(t)); + return err; } int bt_mesh_k2(const uint8_t n[16], const uint8_t *p, size_t p_len, diff --git a/components/bt/esp_ble_mesh/core/crypto.h b/components/bt/esp_ble_mesh/core/crypto.h index ac6924c4f17..14a97f5f0d3 100644 --- a/components/bt/esp_ble_mesh/core/crypto.h +++ b/components/bt/esp_ble_mesh/core/crypto.h @@ -24,7 +24,7 @@ extern "C" { /* bt_mesh_aes_cmac_one is defined as inline in mesh/crypto.h */ -static inline bool bt_mesh_s1(const char *m, uint8_t salt[16]) +static inline int bt_mesh_s1(const char *m, uint8_t salt[16]) { const uint8_t zero[16] = { 0 }; diff --git a/components/bt/esp_ble_mesh/core/ext_adv.c b/components/bt/esp_ble_mesh/core/ext_adv.c index a7279b6c2e4..2ba48d0ac20 100644 --- a/components/bt/esp_ble_mesh/core/ext_adv.c +++ b/components/bt/esp_ble_mesh/core/ext_adv.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -30,7 +30,7 @@ static struct bt_mesh_adv_inst *adv_insts; -static int adv_send(struct bt_mesh_adv_inst *inst, uint16_t *adv_duration) +static int adv_send(struct bt_mesh_adv_inst *inst, int32_t *adv_duration) { struct net_buf *buf = inst->sending_buf; const struct bt_mesh_send_cb *cb = BLE_MESH_ADV(buf)->cb; @@ -57,9 +57,10 @@ static int adv_send(struct bt_mesh_adv_inst *inst, uint16_t *adv_duration) case BLE_MESH_ADV_EXT_LONG_DATA: case BLE_MESH_ADV_EXT_LONG_RELAY_DATA: #endif /* CONFIG_BLE_MESH_LONG_PACKET */ - { - is_ext_adv = true; - } + { + is_ext_adv = true; + } + __attribute__((fallthrough)); #endif /* CONFIG_BLE_MESH_EXT_ADV */ case BLE_MESH_ADV_PROV: case BLE_MESH_ADV_DATA: @@ -195,7 +196,7 @@ static int adv_send(struct bt_mesh_adv_inst *inst, uint16_t *adv_duration) return err; } - *adv_duration = duration; + *adv_duration = (int32_t)duration; BT_DBG("Advertising started. %u ms", duration); return 0; @@ -264,12 +265,12 @@ static int find_valid_msg_from_queue(bt_mesh_queue_t *msg_queue, bt_mesh_msg_t * return 0; } -static int activate_idle_adv_instance(uint32_t *update_evts, uint16_t *min_duration) +static int activate_idle_adv_instance(uint32_t *update_evts, int32_t *min_duration) { - uint16_t cur_min_duration = K_FOREVER; + int32_t cur_min_duration = K_FOREVER; enum bt_mesh_adv_type adv_type = 0; bt_mesh_queue_t *msg_queue = NULL; - uint16_t duration = K_FOREVER; + int32_t duration = K_FOREVER; bt_mesh_msg_t msg = {0}; uint32_t spt_mask = 0; uint32_t evts = 0; @@ -389,13 +390,17 @@ static uint32_t received_adv_evts_handle(uint32_t recv_evts) } else #endif { - BLE_MESH_SEND_END_CB(0, BLE_MESH_ADV(adv_insts[i].sending_buf)->cb, - BLE_MESH_ADV(adv_insts[i].sending_buf)->cb_data); + if (adv_insts[i].sending_buf == NULL) { + BT_WARN("sending_buf is NULL for inst %d, skipping", i); + } else { + BLE_MESH_SEND_END_CB(0, BLE_MESH_ADV(adv_insts[i].sending_buf)->cb, + BLE_MESH_ADV(adv_insts[i].sending_buf)->cb_data); - bt_mesh_adv_buf_ref_debug(__func__, adv_insts[i].sending_buf, 4U, BLE_MESH_BUF_REF_SMALL); + bt_mesh_adv_buf_ref_debug(__func__, adv_insts[i].sending_buf, 4U, BLE_MESH_BUF_REF_SMALL); - net_buf_unref(adv_insts[i].sending_buf); - adv_insts[i].sending_buf = NULL; + net_buf_unref(adv_insts[i].sending_buf); + adv_insts[i].sending_buf = NULL; + } } adv_insts[i].busy = false; @@ -407,7 +412,7 @@ static uint32_t received_adv_evts_handle(uint32_t recv_evts) static void adv_thread(void *p) { - uint16_t adv_duration = K_FOREVER; + int32_t adv_duration = K_FOREVER; uint32_t recv_evts = 0; uint32_t wait_evts = 0; diff --git a/components/bt/esp_ble_mesh/core/fast_prov.c b/components/bt/esp_ble_mesh/core/fast_prov.c index 6a256fb3bb3..a7b059eaae1 100644 --- a/components/bt/esp_ble_mesh/core/fast_prov.c +++ b/components/bt/esp_ble_mesh/core/fast_prov.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -62,7 +62,8 @@ struct bt_mesh_subnet *bt_mesh_fast_prov_subnet_get(uint16_t net_idx) for (i = 0; i < ARRAY_SIZE(bt_mesh.sub); i++) { sub = &bt_mesh.sub[i]; - if (sub->net_idx == net_idx) { + if (sub->net_idx != BLE_MESH_KEY_UNUSED && + sub->net_idx == net_idx) { BT_DBG("NodeSub"); return sub; } @@ -194,6 +195,12 @@ uint8_t bt_mesh_set_fast_prov_action(uint8_t action) } if (action == ACTION_ENTER) { + /* Perform validation before state mutation */ + if (bt_mesh_provisioner_set_primary_elem_addr(bt_mesh_primary_addr()) < 0) { + BT_ERR("SetPrimaryElemAddrFail"); + return 0x01; + } + if (bt_mesh_secure_beacon_get() == BLE_MESH_SECURE_BEACON_ENABLED) { bt_mesh_secure_beacon_disable(); } @@ -201,11 +208,6 @@ uint8_t bt_mesh_set_fast_prov_action(uint8_t action) if (IS_ENABLED(CONFIG_BLE_MESH_PB_GATT)) { bt_mesh_proxy_client_prov_enable(); } - - if (bt_mesh_provisioner_set_primary_elem_addr(bt_mesh_primary_addr()) < 0) { - BT_ERR("SetPrimaryElemAddrFail"); - return 0x01; - } bt_mesh_provisioner_set_prov_bearer(BLE_MESH_PROV_ADV, false); bt_mesh_provisioner_fast_prov_enable(true); bt_mesh_atomic_or(bt_mesh.flags, BIT(BLE_MESH_PROVISIONER) | BIT(BLE_MESH_VALID_PROV)); diff --git a/components/bt/esp_ble_mesh/core/friend.c b/components/bt/esp_ble_mesh/core/friend.c index ed02cd3129e..6800eb68f0f 100644 --- a/components/bt/esp_ble_mesh/core/friend.c +++ b/components/bt/esp_ble_mesh/core/friend.c @@ -994,7 +994,7 @@ int bt_mesh_friend_clear_cfm(struct bt_mesh_net_rx *rx, frnd = find_clear(rx->ctx.addr); if (!frnd) { - BT_WARN("No pending clear procedure for 0x%02x", rx->ctx.addr); + BT_WARN("No pending clear procedure for 0x%04x", rx->ctx.addr); return 0; } diff --git a/components/bt/esp_ble_mesh/core/health_cli.c b/components/bt/esp_ble_mesh/core/health_cli.c index c458710db12..b2883220216 100644 --- a/components/bt/esp_ble_mesh/core/health_cli.c +++ b/components/bt/esp_ble_mesh/core/health_cli.c @@ -270,7 +270,7 @@ int bt_mesh_health_fault_test(bt_mesh_client_common_param_t *param, { BLE_MESH_MODEL_BUF_DEFINE(msg, OP_HEALTH_FAULT_TEST, 3); - BT_DBG("HealthFaultTest, CID 0x%04x TestID 0x%04x NeedAck %u", cid, test_id, need_ack); + BT_DBG("HealthFaultTest, CID 0x%04x TestID 0x%02x NeedAck %u", cid, test_id, need_ack); bt_mesh_model_msg_init(&msg, need_ack ? OP_HEALTH_FAULT_TEST : OP_HEALTH_FAULT_TEST_UNREL); net_buf_simple_add_u8(&msg, test_id); diff --git a/components/bt/esp_ble_mesh/core/health_srv.c b/components/bt/esp_ble_mesh/core/health_srv.c index f7db34babb3..c5e849ce051 100644 --- a/components/bt/esp_ble_mesh/core/health_srv.c +++ b/components/bt/esp_ble_mesh/core/health_srv.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -418,6 +418,7 @@ static int health_pub_update(struct bt_mesh_model *model) int bt_mesh_fault_update(struct bt_mesh_elem *elem) { struct bt_mesh_model *model = NULL; + int err = 0; BT_DBG("FaultUpdate"); @@ -439,7 +440,10 @@ int bt_mesh_fault_update(struct bt_mesh_elem *elem) return 0; } - health_pub_update(model); + err = health_pub_update(model); + if (err) { + return err; + } return bt_mesh_model_publish(model); } @@ -449,10 +453,6 @@ static void attention_off(struct k_work *work) struct bt_mesh_health_srv *srv = CONTAINER_OF(work, struct bt_mesh_health_srv, attn_timer.work); - if (!srv) { - BT_ERR("No Health Server context provided"); - return; - } BT_DBG("AttentionOff"); @@ -532,6 +532,7 @@ static int health_srv_deinit(struct bt_mesh_model *model) model->pub->update = NULL; k_delayed_work_free(&srv->attn_timer); + srv->attn_timer_start = false; if (bt_mesh_model_in_primary(model)) { health_srv = NULL; diff --git a/components/bt/esp_ble_mesh/core/heartbeat.c b/components/bt/esp_ble_mesh/core/heartbeat.c index 4324da32234..a2cb153c607 100644 --- a/components/bt/esp_ble_mesh/core/heartbeat.c +++ b/components/bt/esp_ble_mesh/core/heartbeat.c @@ -1,6 +1,6 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2023 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -77,28 +77,50 @@ void bt_mesh_heartbeat_send(void) uint8_t init_ttl; uint16_t feat; } hb; - struct bt_mesh_msg_ctx ctx = { - .net_idx = cfg->hb_pub.net_idx, - .app_idx = BLE_MESH_KEY_UNUSED, - .addr = cfg->hb_pub.dst, - .send_ttl = cfg->hb_pub.ttl, - .send_cred = BLE_MESH_FLOODING_CRED, - }; - struct bt_mesh_net_tx tx = { - .sub = bt_mesh_subnet_get(cfg->hb_pub.net_idx), - .ctx = &ctx, - .src = bt_mesh_model_elem(cfg->model)->addr, - .xmit = bt_mesh_net_transmit_get(), - }; + struct bt_mesh_msg_ctx ctx = {0}; + struct bt_mesh_net_tx tx = {0}; + struct bt_mesh_elem *elem = NULL; uint16_t feat = 0U; - BT_DBG("HeartbeatSend, Dst 0x%04x", cfg->hb_pub.dst); + if (cfg == NULL) { + BT_WARN("No configuration server context available"); + return; + } + + if (cfg->model == NULL) { + BT_ERR("Configuration server model is NULL"); + return; + } /* Do nothing if heartbeat publication is not enabled */ if (cfg->hb_pub.dst == BLE_MESH_ADDR_UNASSIGNED) { return; } + elem = bt_mesh_model_elem(cfg->model); + if (elem == NULL) { + BT_ERR("Failed to get element for heartbeat"); + return; + } + + ctx.net_idx = cfg->hb_pub.net_idx; + ctx.app_idx = BLE_MESH_KEY_UNUSED; + ctx.addr = cfg->hb_pub.dst; + ctx.send_ttl = cfg->hb_pub.ttl; + ctx.send_cred = BLE_MESH_FLOODING_CRED; + + tx.sub = bt_mesh_subnet_get(cfg->hb_pub.net_idx); + if (tx.sub == NULL) { + BT_ERR("No subnet found for heartbeat publication (net_idx 0x%04x)", cfg->hb_pub.net_idx); + return; + } + + tx.ctx = &ctx; + tx.src = elem->addr; + tx.xmit = bt_mesh_net_transmit_get(); + + BT_DBG("HeartbeatSend, Dst 0x%04x", cfg->hb_pub.dst); + hb.init_ttl = cfg->hb_pub.ttl; if (bt_mesh_relay_get() == BLE_MESH_RELAY_ENABLED) { diff --git a/components/bt/esp_ble_mesh/core/local.h b/components/bt/esp_ble_mesh/core/local.h index 3172d58e170..67688e7a554 100644 --- a/components/bt/esp_ble_mesh/core/local.h +++ b/components/bt/esp_ble_mesh/core/local.h @@ -16,8 +16,8 @@ extern "C" { #endif -int bt_mesh_model_subscribe_group_addr(uint16_t elem_addr, uint16_t mod_id, - uint16_t cid, uint16_t group_addr); +int bt_mesh_model_subscribe_group_addr(uint16_t elem_addr, uint16_t cid, + uint16_t mod_id, uint16_t group_addr); int bt_mesh_model_unsubscribe_group_addr(uint16_t elem_addr, uint16_t cid, uint16_t mod_id, uint16_t group_addr); diff --git a/components/bt/esp_ble_mesh/core/lpn.c b/components/bt/esp_ble_mesh/core/lpn.c index 79d97887c74..fbb168c3709 100644 --- a/components/bt/esp_ble_mesh/core/lpn.c +++ b/components/bt/esp_ble_mesh/core/lpn.c @@ -283,7 +283,7 @@ static void clear_friendship(bool force, bool disable) */ lpn->groups_changed = 1U; - if (cfg->hb_pub.feat & BLE_MESH_FEAT_LOW_POWER) { + if (cfg && (cfg->hb_pub.feat & BLE_MESH_FEAT_LOW_POWER)) { bt_mesh_heartbeat_send(); } @@ -335,6 +335,11 @@ static const struct bt_mesh_send_cb friend_req_sent_cb = { static int send_friend_req(struct bt_mesh_lpn *lpn) { const struct bt_mesh_comp *comp = bt_mesh_comp_get(); + if (!comp) { + BT_ERR("Invalid composition data"); + return -EINVAL; + } + struct bt_mesh_msg_ctx ctx = { .net_idx = bt_mesh.sub[0].net_idx, .app_idx = BLE_MESH_KEY_UNUSED, @@ -710,6 +715,8 @@ static inline int group_popcount(bt_mesh_atomic_t *target) for (i = 0; i < ARRAY_SIZE(bt_mesh.lpn.added); i++) { count += popcount(bt_mesh_atomic_get(&target[i])); } + + return count; #else /* CONFIG_BLE_MESH_LPN_GROUPS > 32 */ return popcount(bt_mesh_atomic_get(target)); #endif /* CONFIG_BLE_MESH_LPN_GROUPS > 32 */ @@ -1086,7 +1093,7 @@ int bt_mesh_lpn_friend_update(struct bt_mesh_net_rx *rx, BT_INFO("Friendship established with 0x%04x", lpn->frnd); - if (cfg->hb_pub.feat & BLE_MESH_FEAT_LOW_POWER) { + if (cfg && (cfg->hb_pub.feat & BLE_MESH_FEAT_LOW_POWER)) { bt_mesh_heartbeat_send(); } @@ -1122,10 +1129,10 @@ int bt_mesh_lpn_friend_update(struct bt_mesh_net_rx *rx, bt_mesh_net_iv_update(iv_index, BLE_MESH_IV_UPDATE(msg->flags)); if (lpn->groups_changed) { - sub_update(TRANS_CTL_OP_FRIEND_SUB_ADD); - sub_update(TRANS_CTL_OP_FRIEND_SUB_REM); + bool sent = sub_update(TRANS_CTL_OP_FRIEND_SUB_ADD); + sent = (sent || sub_update(TRANS_CTL_OP_FRIEND_SUB_REM)); - if (!lpn->sent_req) { + if (!lpn->sent_req && !sent) { lpn->groups_changed = 0U; } } diff --git a/components/bt/esp_ble_mesh/core/net.c b/components/bt/esp_ble_mesh/core/net.c index b436ce5d6b4..919d248da9d 100644 --- a/components/bt/esp_ble_mesh/core/net.c +++ b/components/bt/esp_ble_mesh/core/net.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -641,13 +641,12 @@ bool bt_mesh_kr_update(struct bt_mesh_subnet *sub, uint8_t new_kr, bool new_key) /* Ignore */ break; } - /* Upon receiving a Secure Network beacon with the KR flag set - * to 0 using the new NetKey in Phase 1, the node shall - * immediately transition to Phase 3, which effectively skips - * Phase 2. - * - * Intentional fall-through. - */ + /* Upon receiving a Secure Network beacon with the KR flag set + * to 0 using the new NetKey in Phase 1, the node shall + * immediately transition to Phase 3, which effectively skips + * Phase 2. + */ + __attribute__((fallthrough)); case BLE_MESH_KR_PHASE_2: BT_INFO("KrPhase 0x%02x -> Normal", sub->kr_phase); diff --git a/components/bt/esp_ble_mesh/core/nimble_host/adapter.c b/components/bt/esp_ble_mesh/core/nimble_host/adapter.c index e2e22ad594d..9608762a417 100644 --- a/components/bt/esp_ble_mesh/core/nimble_host/adapter.c +++ b/components/bt/esp_ble_mesh/core/nimble_host/adapter.c @@ -1,7 +1,7 @@ /* * SPDX-FileCopyrightText: 2017 Nordic Semiconductor ASA * SPDX-FileCopyrightText: 2015-2016 Intel Corporation - * SPDX-FileContributor: 2018-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -88,7 +88,7 @@ static inline bool bt_mesh_is_ble_adv_running(); static bool g_host_init = false; -#if CONFIG_BLE_MESH_NODE && CONFIG_BLE_MESH_USE_BLE_50 +#if CONFIG_BLE_MESH_NODE static void bt_mesh_gatts_conn_init(void) { int i; @@ -118,7 +118,7 @@ static int bt_mesh_find_conn_idx(uint16_t conn_handle) } return -ENODEV; } -#endif /* CONFIG_BLE_MESH_NODE && CONFIG_BLE_MESH_USE_BLE_50 */ +#endif /* CONFIG_BLE_MESH_NODE */ int bt_mesh_host_init(void) { @@ -322,9 +322,10 @@ static int chr_disced(uint16_t conn_handle, const struct ble_gatt_error *error, uint16_t uuid16 = 0; int i = (int)arg; /* service index */ struct bt_mesh_conn *conn = &bt_mesh_gattc_info[i].conn; - const ble_uuid_any_t *uuid = &chr->uuid; + const ble_uuid_any_t *uuid = NULL; if (chr) { + uuid = &chr->uuid; uuid16 = (uint16_t) BLE_UUID16(uuid)->value; } @@ -698,10 +699,9 @@ report_to_user: bt_mesh_gattc_info[i].wr_desc_done = false; break; } - - if (i == ARRAY_SIZE(bt_mesh_gattc_info)) { - goto transfer_to_user; - } + } + if (i == ARRAY_SIZE(bt_mesh_gattc_info)) { + goto transfer_to_user; } } else { goto transfer_to_user; @@ -748,7 +748,10 @@ report_to_user: } conn = &bt_mesh_gattc_info[i].conn; - ble_gap_conn_find(event->notify_rx.conn_handle, &conn_desc); + if (ble_gap_conn_find(event->notify_rx.conn_handle, &conn_desc) != 0) { + BT_ERR("Failed to find connection for notify handler"); + return 0; + } if (bt_mesh_gattc_info[i].data_out_handle != event->notify_rx.attr_handle) { /* Data isn't populated yet */ @@ -829,6 +832,8 @@ void *bt_mesh_nimble_gap_cb_get(void) static int start_le_scan(uint8_t scan_type, uint16_t interval, uint16_t window, uint8_t filter_dup) { + int rc; + #if CONFIG_BLE_MESH_USE_BLE_50 uncoded_disc_params.itvl = (window ? interval : 0); uncoded_disc_params.window = window; @@ -839,9 +844,13 @@ static int start_le_scan(uint8_t scan_type, uint16_t interval, uint16_t window, coded_disc_params.passive = (scan_type == BLE_MESH_SCAN_PASSIVE); uncoded_disc_params.passive = (scan_type == BLE_MESH_SCAN_PASSIVE); - ble_gap_ext_disc(BLE_OWN_ADDR_PUBLIC, 0, 0, filter_dup, 0, 0, - uncoded_disc_params.itvl ? &uncoded_disc_params : NULL, - coded_disc_params.itvl ? &coded_disc_params : NULL, disc_cb, NULL); + rc = ble_gap_ext_disc(BLE_OWN_ADDR_PUBLIC, 0, 0, filter_dup, 0, 0, + uncoded_disc_params.itvl ? &uncoded_disc_params : NULL, + coded_disc_params.itvl ? &coded_disc_params : NULL, disc_cb, NULL); + if (rc != 0) { + BT_ERR("Failed to start extended discovery (err %d)", rc); + return rc; + } #else /* CONFIG_BLE_MESH_USE_BLE_50 */ scan_param.filter_duplicates = filter_dup; scan_param.itvl = interval; @@ -852,7 +861,11 @@ static int start_le_scan(uint8_t scan_type, uint16_t interval, uint16_t window, } else { scan_param.passive = 0; } - ble_gap_disc(BLE_OWN_ADDR_PUBLIC, BLE_HS_FOREVER, &scan_param, disc_cb, NULL); + rc = ble_gap_disc(BLE_OWN_ADDR_PUBLIC, BLE_HS_FOREVER, &scan_param, disc_cb, NULL); + if (rc != 0) { + BT_ERR("Failed to start discovery (err %d)", rc); + return rc; + } #endif /* CONFIG_BLE_MESH_USE_BLE_50 */ #if BLE_MESH_DEV @@ -880,10 +893,14 @@ static int gap_event_cb(struct ble_gap_event *event, void *arg) MODLOG_DFLT(INFO, "connection %s; status=%d ", event->connect.status == 0 ? "established" : "failed", event->connect.status); - if (event->connect.status == 0) { - rc = ble_gap_conn_find(event->connect.conn_handle, &desc); - assert(rc == 0); + + if (event->connect.status != 0) { + return 0; } + + rc = ble_gap_conn_find(event->connect.conn_handle, &desc); + assert(rc == 0); + MODLOG_DFLT(INFO, "\n"); #if BLE_MESH_DEV /* When connection is created, advertising will be stopped automatically. */ @@ -904,9 +921,7 @@ static int gap_event_cb(struct ble_gap_event *event, void *arg) #endif if (bt_mesh_gatts_conn_cb != NULL && bt_mesh_gatts_conn_cb->connected != NULL) { - int index = 0; -#if CONFIG_BLE_MESH_USE_BLE_50 - index = bt_mesh_find_free_conn_idx(); + int index = bt_mesh_find_free_conn_idx(); if (index != -ENOMEM) { bt_mesh_gatts_conn[index].handle = BLE_MESH_GATT_GET_CONN_ID(event->connect.conn_handle); (bt_mesh_gatts_conn_cb->connected)(&bt_mesh_gatts_conn[index], 0); @@ -914,13 +929,6 @@ static int gap_event_cb(struct ble_gap_event *event, void *arg) BT_ERR("No space for new connection"); ble_gap_terminate(event->connect.conn_handle, BLE_ERR_CONN_LIMIT); } -#else /* CONFIG_BLE_MESH_USE_BLE_50 */ - index = BLE_MESH_GATT_GET_CONN_ID(event->connect.conn_handle); - if (index < BLE_MESH_MAX_CONN) { - bt_mesh_gatts_conn[index].handle = BLE_MESH_GATT_GET_CONN_ID(event->connect.conn_handle); - (bt_mesh_gatts_conn_cb->connected)(&bt_mesh_gatts_conn[index], 0); - } -#endif /* CONFIG_BLE_MESH_USE_BLE_50 */ memcpy(bt_mesh_gatts_addr, desc.peer_id_addr.val, BLE_MESH_ADDR_LEN); /* This is for EspBleMesh Android app. When it tries to connect with the * device at the first time and it fails due to some reason. And after @@ -940,22 +948,13 @@ static int gap_event_cb(struct ble_gap_event *event, void *arg) bt_mesh_atomic_test_and_clear_bit(bt_mesh_dev.flags, BLE_MESH_DEV_ADVERTISING); #endif if (bt_mesh_gatts_conn_cb != NULL && bt_mesh_gatts_conn_cb->disconnected != NULL) { - int index = 0; -#if CONFIG_BLE_MESH_USE_BLE_50 - index = bt_mesh_find_conn_idx(BLE_MESH_GATT_GET_CONN_ID(event->disconnect.conn.conn_handle)); + int index = bt_mesh_find_conn_idx(BLE_MESH_GATT_GET_CONN_ID(event->disconnect.conn.conn_handle)); if (index != -ENODEV) { bt_mesh_gatts_conn[index].handle = BLE_MESH_GATT_GET_CONN_ID(event->disconnect.conn.conn_handle); (bt_mesh_gatts_conn_cb->disconnected)(&bt_mesh_gatts_conn[index], event->disconnect.reason); } else { BT_ERR("No device"); } -#else /* CONFIG_BLE_MESH_USE_BLE_50 */ - index = BLE_MESH_GATT_GET_CONN_ID(event->disconnect.conn.conn_handle); - if (index < BLE_MESH_MAX_CONN) { - bt_mesh_gatts_conn[index].handle = BLE_MESH_GATT_GET_CONN_ID(event->disconnect.conn.conn_handle); - (bt_mesh_gatts_conn_cb->disconnected)(&bt_mesh_gatts_conn[index], event->disconnect.reason); - } -#endif /* CONFIG_BLE_MESH_USE_BLE_50 */ bt_mesh_gatts_conn[index].handle = BT_MESH_GATTS_CONN_UNUSED; memset(bt_mesh_gatts_addr, 0x0, BLE_MESH_ADDR_LEN); } @@ -1035,19 +1034,11 @@ static int gap_event_cb(struct ble_gap_event *event, void *arg) uint16_t len = 0; uint16_t ccc_val = 0; -#if CONFIG_BLE_MESH_USE_BLE_50 index = bt_mesh_find_conn_idx(BLE_MESH_GATT_GET_CONN_ID(event->subscribe.conn_handle)); if (index == -ENODEV) { BT_ERR("Couldn't find conn %d", event->subscribe.conn_handle); return 0; } -#else /* CONFIG_BLE_MESH_USE_BLE_50 */ - index = BLE_MESH_GATT_GET_CONN_ID(event->subscribe.conn_handle); - if (index >= BLE_MESH_MAX_CONN) { - BT_ERR("InvConnIdx[%d]", index); - return 0; - } -#endif /* CONFIG_BLE_MESH_USE_BLE_50 */ if (event->subscribe.prev_notify != event->subscribe.cur_notify) { ccc_val = event->subscribe.cur_notify; @@ -1224,6 +1215,7 @@ int bt_le_ext_adv_start(const uint8_t inst_id, err = os_mbuf_append(data, buf, buf_len); if (err) { bt_mesh_free(buf); + os_mbuf_free_chain(data); BT_ERR("Append ad data to os buf failed %d", err); return -EINVAL; } @@ -1236,19 +1228,22 @@ int bt_le_ext_adv_start(const uint8_t inst_id, buf = bt_mesh_calloc(sd_len * BLE_HS_ADV_MAX_SZ); if (!buf) { BT_ERR("ad buffer alloc failed"); + os_mbuf_free_chain(data); return -ENOMEM; } err = set_ad(sd, sd_len, buf, &buf_len); if (err) { bt_mesh_free(buf); + os_mbuf_free_chain(data); BT_ERR("SetScanRspDataFail[%d]", err); return err; } scan_rsp = os_msys_get_pkthdr(buf_len, 0); - if (!data) { + if (!scan_rsp) { bt_mesh_free(buf); + os_mbuf_free_chain(data); BT_ERR("os buf get failed"); return -ENOBUFS; } @@ -1256,6 +1251,8 @@ int bt_le_ext_adv_start(const uint8_t inst_id, err = os_mbuf_append(scan_rsp, buf, buf_len); if (err) { bt_mesh_free(buf); + os_mbuf_free_chain(data); + os_mbuf_free_chain(scan_rsp); BT_ERR("Append ad data to os buf failed %d", err); return -EINVAL; } @@ -1315,6 +1312,10 @@ int bt_le_ext_adv_start(const uint8_t inst_id, err = ble_gap_ext_adv_remove(inst_id); if (err != 0 && err != BLE_HS_EALREADY) { BT_ERR("Advertising rm failed: err %d", err); + os_mbuf_free_chain(data); + if (scan_rsp) { + os_mbuf_free_chain(scan_rsp); + } return err; } } @@ -1322,6 +1323,10 @@ int bt_le_ext_adv_start(const uint8_t inst_id, err = ble_gap_ext_adv_configure(inst_id, &adv_params, NULL, gap_event_cb, NULL); if (err != 0) { BT_ERR("Advertising config failed: err %d", err); + os_mbuf_free_chain(data); + if (scan_rsp) { + os_mbuf_free_chain(scan_rsp); + } return err; } @@ -1331,6 +1336,9 @@ int bt_le_ext_adv_start(const uint8_t inst_id, err = ble_gap_ext_adv_set_data(inst_id, data); if (err != 0) { BT_ERR("Advertising set failed: err %d", err); + if (scan_rsp) { + os_mbuf_free_chain(scan_rsp); + } return err; } @@ -1604,6 +1612,7 @@ int bt_mesh_ble_ext_adv_start(const uint8_t inst_id, if (os_mbuf_append(data, adv_data->adv_data, adv_data->adv_data_len)) { BT_ERR("Append data failed"); + os_mbuf_free_chain(data); return -EINVAL; } @@ -1622,6 +1631,7 @@ int bt_mesh_ble_ext_adv_start(const uint8_t inst_id, if (os_mbuf_append(data, adv_data->scan_rsp_data, adv_data->scan_rsp_data_len)) { BT_ERR("Append data failed"); + os_mbuf_free_chain(data); return -EINVAL; } err = ble_gap_ext_adv_rsp_set_data(inst_id, data); @@ -2420,23 +2430,25 @@ static int proxy_char_access_cb(uint16_t conn_handle, uint16_t attr_handle, if (ctxt->op == BLE_GATT_ACCESS_OP_WRITE_CHR || ctxt->op == BLE_GATT_ACCESS_OP_WRITE_DSC) { struct bt_mesh_gatt_attr *attr = bt_mesh_gatts_find_attr_by_handle(attr_handle); int index = 0; - uint16_t len = 0; + ssize_t len = 0; -#if CONFIG_BLE_MESH_USE_BLE_50 - index = bt_mesh_find_conn_idx(BLE_MESH_GATT_GET_CONN_ID(conn_handle)); + index = bt_mesh_find_conn_idx(BLE_MESH_GATT_GET_CONN_ID(conn_handle)); if (index == -ENODEV) { BT_ERR("Unknown conn handle"); return 0; } -#else - index = BLE_MESH_GATT_GET_CONN_ID(conn_handle); -#endif BT_DBG("write, handle %d, len %d, data %s", attr_handle, ctxt->om->om_len, bt_hex(ctxt->om->om_data, ctxt->om->om_len)); if (attr != NULL && attr->write != NULL) { + if (OS_MBUF_IS_PKTHDR(ctxt->om) && OS_MBUF_PKTLEN(ctxt->om) > ctxt->om->om_len) { + /* Handle fragmented mbuf chain: either linearize or return error */ + BT_ERR("Fragmented mbuf not supported"); + return BLE_ATT_ERR_UNLIKELY; + } + if ((len = attr->write(&bt_mesh_gatts_conn[index], attr, ctxt->om->om_data, ctxt->om->om_len, @@ -2554,9 +2566,7 @@ void bt_mesh_gatt_init(void) ble_gatts_svc_set_visibility(prov_svc_start_handle, 1); ble_gatts_svc_set_visibility(proxy_svc_start_handle, 0); -#if CONFIG_BLE_MESH_USE_BLE_50 bt_mesh_gatts_conn_init(); -#endif /* CONFIG_BLE_MESH_USE_BLE_50 */ init = true; } #endif /* CONFIG_BLE_MESH_NODE */ @@ -2596,6 +2606,7 @@ void bt_mesh_gatt_init(void) ble_gatts_svc_set_visibility(prov_svc_start_handle, 1); ble_gatts_svc_set_visibility(proxy_svc_start_handle, 0); + bt_mesh_gatts_conn_init(); init = true; } #endif /* CONFIG_BLE_MESH_NODE */ diff --git a/components/bt/esp_ble_mesh/core/prov_common.c b/components/bt/esp_ble_mesh/core/prov_common.c index 8f14b67efa5..58bbf7bce5c 100644 --- a/components/bt/esp_ble_mesh/core/prov_common.c +++ b/components/bt/esp_ble_mesh/core/prov_common.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -103,6 +103,14 @@ static const struct { bool bt_mesh_prov_pdu_check(uint8_t type, uint16_t length, uint8_t *reason) { + if (type >= ARRAY_SIZE(prov_pdu)) { + BT_ERR("Invalid PDU type 0x%02x", type); + if (reason) { + *reason = PROV_ERR_NVAL_PDU; + } + return false; + } + if (prov_pdu[type].length != length) { #if CONFIG_BLE_MESH_CERT_BASED_PROV if ((type == PROV_REC_LIST || type == PROV_REC_RSP) && @@ -224,12 +232,21 @@ bool bt_mesh_gen_prov_start(struct bt_mesh_prov_link *link, return false; } - if (START_LAST_SEG(rx->gpc) > 0 && link->rx.buf->len <= 20) { - BT_ERR("Too small total length for multi-segment PDU"); - if (close) { - *close = true; + if (START_LAST_SEG(rx->gpc) > 0) { + /* For multi-segment PDUs, validate that total length is consistent + * with the claimed segment count to prevent underflow in + * bt_mesh_gen_prov_cont() when computing expect_len. + * Minimum length = first segment (20) + (last_seg - 1) * full continuation (23) + 1 + */ + uint16_t min_len = 20 + 23 * (START_LAST_SEG(rx->gpc) - 1) + 1; + if (link->rx.buf->len < min_len) { + BT_ERR("Total length %u too small for %u segments (min %u)", + link->rx.buf->len, START_LAST_SEG(rx->gpc) + 1, min_len); + if (close) { + *close = true; + } + return false; } - return false; } link->rx.seg = (1 << (START_LAST_SEG(rx->gpc) + 1)) - 1; @@ -375,7 +392,7 @@ static void free_segments(struct bt_mesh_prov_link *link) struct net_buf *buf = link->tx.buf[i]; if (!buf) { - break; + continue; } link->tx.buf[i] = NULL; @@ -536,6 +553,8 @@ static void send_reliable(struct bt_mesh_prov_link *link, uint8_t xmit) { link->tx.start = k_uptime_get(); + bt_mesh_mutex_lock(&link->buf_lock); + for (size_t i = 0; i < ARRAY_SIZE(link->tx.buf); i++) { struct net_buf *buf = link->tx.buf[i]; @@ -549,6 +568,8 @@ static void send_reliable(struct bt_mesh_prov_link *link, uint8_t xmit) bt_mesh_adv_send(buf, xmit, &buf_sent_cb, link); } } + + bt_mesh_mutex_unlock(&link->buf_lock); } int bt_mesh_prov_bearer_ctl_send(struct bt_mesh_prov_link *link, uint8_t op, @@ -737,6 +758,7 @@ int bt_mesh_prov_send(struct bt_mesh_prov_link *link, struct net_buf_simple *buf return bt_mesh_prov_send_adv(link, buf); #endif /* CONFIG_BLE_MESH_PB_ADV */ - /* Shall not reach here. */ - return 0; + /* Shall not reach here - no provisioning bearer is enabled */ + BT_ERR("No provisioning bearer available"); + return -ENOTSUP; } diff --git a/components/bt/esp_ble_mesh/core/prov_node.c b/components/bt/esp_ble_mesh/core/prov_node.c index 721f8feb729..67d0a2e8078 100644 --- a/components/bt/esp_ble_mesh/core/prov_node.c +++ b/components/bt/esp_ble_mesh/core/prov_node.c @@ -124,7 +124,7 @@ static void reset_adv_link(struct bt_mesh_prov_link *link, uint8_t reason) { ARG_UNUSED(link); - BT_INFO("ResetAdvLink:%08x", link->link_id); + BT_INFO("ResetAdvLink:%08x", prov_link.link_id); bt_mesh_prov_clear_tx(&prov_link, true); if (bt_mesh_prov_get()->link_close) { @@ -285,6 +285,11 @@ static int prov_auth(uint8_t method, uint8_t action, uint8_t size) return -EINVAL; } + if (bt_mesh_prov_get()->static_val == NULL) { + BT_ERR("Static OOB value not set"); + return -EINVAL; + } + if (bt_mesh_prov_get()->static_val_len > auth_size) { memcpy(prov_link.auth, bt_mesh_prov_get()->static_val, auth_size); } else { @@ -306,7 +311,7 @@ static int prov_auth(uint8_t method, uint8_t action, uint8_t size) return -EINVAL; } - if (size > bt_mesh_prov_get()->output_size) { + if (size == 0 || size > bt_mesh_prov_get()->output_size) { return -EINVAL; } @@ -599,7 +604,7 @@ int bt_mesh_input_string(const char *str) } (void)memset(prov_link.auth, 0, sizeof(prov_link.auth)); - (void)memcpy(prov_link.auth, str, bt_mesh_prov_get()->input_size); + (void)memcpy(prov_link.auth, str, MIN(strlen(str), bt_mesh_prov_get()->input_size)); send_input_complete(); @@ -631,11 +636,13 @@ static void send_pub_key(void) if (bt_mesh_dh_key_gen(buf.data, dhkey)) { BT_ERR("Unable to generate DHKey"); + (void)memset(dhkey, 0, sizeof(dhkey)); close_link(PROV_ERR_UNEXP_ERR); return; } memcpy(prov_link.dhkey, dhkey, 32); + (void)memset(dhkey, 0, sizeof(dhkey)); BT_DBG("DHkey: %s", bt_hex(prov_link.dhkey, 32)); @@ -643,6 +650,7 @@ static void send_pub_key(void) if (bt_mesh_pub_key_copy(pub_key)) { BT_ERR("No public key available"); + (void)memset(pub_key, 0, sizeof(pub_key)); close_link(PROV_ERR_UNEXP_ERR); return; } @@ -654,6 +662,7 @@ static void send_pub_key(void) /* Public key is already in big-endian format from bt_mesh_pub_key_copy() */ memcpy(net_buf_simple_add(&buf, 32), pub_key, 32); memcpy(net_buf_simple_add(&buf, 32), &pub_key[32], 32); + (void)memset(pub_key, 0, sizeof(pub_key)); memcpy(&prov_link.conf_inputs[81], &buf.data[1], 64); @@ -1187,7 +1196,7 @@ static void prov_msg_recv(void) uint8_t type = 0; if (bt_mesh_atomic_test_bit(prov_link.flags, LINK_INVALID)) { - BT_WARN("Unexpected msg 0x%02x on invalidated link", type); + BT_WARN("Unexpected msg on invalidated link"); close_link(PROV_ERR_UNEXP_PDU); return; } @@ -1196,7 +1205,7 @@ static void prov_msg_recv(void) * should be ignored. */ if (bt_mesh_atomic_test_bit(prov_link.flags, LINK_CLOSING)) { - BT_WARN("Link is closing, unexpected msg 0x%02x", type); + BT_WARN("Link is closing, unexpected msg received"); return; } diff --git a/components/bt/esp_ble_mesh/core/prov_pvnr.c b/components/bt/esp_ble_mesh/core/prov_pvnr.c index 88ce691464e..a1dde3b5002 100644 --- a/components/bt/esp_ble_mesh/core/prov_pvnr.c +++ b/components/bt/esp_ble_mesh/core/prov_pvnr.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -655,7 +655,7 @@ start: #endif /* CONFIG_BLE_MESH_PB_GATT */ /* Shall not reach here. */ - return 0; + return -EINVAL; } int bt_mesh_provisioner_prov_device_with_addr(const uint8_t uuid[16], const uint8_t addr[6], @@ -754,7 +754,7 @@ int bt_mesh_provisioner_prov_device_with_addr(const uint8_t uuid[16], const uint #endif /* CONFIG_BLE_MESH_PB_GATT */ /* Shall not reach here. */ - return 0; + return -EINVAL; } int bt_mesh_provisioner_delete_device(struct bt_mesh_device_delete *del_dev) @@ -2487,7 +2487,7 @@ static void prov_msg_recv(struct bt_mesh_prov_link *link) * should be ignored. */ if (bt_mesh_atomic_test_bit(link->flags, LINK_CLOSING)) { - BT_WARN("Link is closing, unexpected msg 0x%02x", type); + BT_WARN("Link is closing, ignoring received PDU"); return; } @@ -3165,7 +3165,7 @@ int bt_mesh_rpr_cli_pdu_recv(struct bt_mesh_prov_link *link, uint8_t type, return -EINVAL; } - if (type != link->expect) { + if (type != PROV_FAILED && type != link->expect) { BT_ERR("PB-Remote, unexpected msg 0x%02x != 0x%02x", type, link->expect); return -EINVAL; } @@ -3188,7 +3188,8 @@ int bt_mesh_rpr_cli_pdu_send(struct bt_mesh_prov_link *link, uint8_t type) send_confirm(link); break; default: - break; + BT_WARN("Unsupported RPR CLI PDU type 0x%02x", type); + return -EINVAL; } return 0; diff --git a/components/bt/esp_ble_mesh/core/proxy_client.c b/components/bt/esp_ble_mesh/core/proxy_client.c index 125a902ebe1..9d2400b890e 100644 --- a/components/bt/esp_ble_mesh/core/proxy_client.c +++ b/components/bt/esp_ble_mesh/core/proxy_client.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -80,7 +80,7 @@ static void proxy_sar_timeout(struct k_work *work) BT_WARN("ProxySARTimeout"); server = CONTAINER_OF(work, struct bt_mesh_proxy_server, sar_timer.work); - if (!server || !server->conn) { + if (!server->conn) { BT_ERR("InvalidProxyServerParam"); return; } @@ -429,6 +429,10 @@ int bt_mesh_proxy_client_segment_send(struct bt_mesh_conn *conn, uint8_t type, net_buf_simple_push_u8(msg, BLE_MESH_PROXY_PDU_HDR(BLE_MESH_PROXY_SAR_FIRST, type)); err = proxy_send(conn, msg->data, mtu); + /* Note: + * Even if proxy_send() failed, do not return early here in order to + * keep the msg in a consistent final state. + */ net_buf_simple_pull(msg, mtu); while (msg->len) { @@ -440,6 +444,10 @@ int bt_mesh_proxy_client_segment_send(struct bt_mesh_conn *conn, uint8_t type, net_buf_simple_push_u8(msg, BLE_MESH_PROXY_PDU_HDR(BLE_MESH_PROXY_SAR_CONT, type)); err = proxy_send(conn, msg->data, mtu); + /* Note: + * Even if proxy_send() failed, do not return early here in order to + * keep the msg in a consistent final state. + */ net_buf_simple_pull(msg, mtu); } @@ -449,10 +457,16 @@ int bt_mesh_proxy_client_segment_send(struct bt_mesh_conn *conn, uint8_t type, int bt_mesh_proxy_client_send(struct bt_mesh_conn *conn, uint8_t type, struct net_buf_simple *msg) { - struct bt_mesh_proxy_server *server = find_server(conn); + struct bt_mesh_proxy_server *server = NULL; + + if (conn == NULL) { + BT_ERR("%s, Invalid parameter", __func__); + return -EINVAL; + } BT_DBG("ProxyClientSend, ConnHandle 0x%04x Type %u", conn->handle, type); + server = find_server(conn); if (!server) { BT_ERR("No Proxy Server object found"); return -ENOTCONN; @@ -645,8 +659,8 @@ int bt_mesh_proxy_client_prov_disable(void) struct bt_mesh_proxy_server *server = &servers[i]; if (server->conn && server->conn_type == CLI_PROV) { - bt_mesh_gattc_disconnect(server->conn); server->conn_type = CLI_NONE; + bt_mesh_gattc_disconnect(server->conn); } } @@ -728,7 +742,7 @@ int bt_mesh_proxy_client_gatt_enable(void) BT_DBG("ProxyClientGattEnable"); for (i = 0; i < ARRAY_SIZE(servers); i++) { - if (servers[i].conn) { + if (servers[i].conn && servers[i].conn_type == CLI_NONE) { servers[i].conn_type = CLI_PROXY; } } @@ -758,8 +772,8 @@ int bt_mesh_proxy_client_gatt_disable(void) struct bt_mesh_proxy_server *server = &servers[i]; if (server->conn && server->conn_type == CLI_PROXY) { - bt_mesh_gattc_disconnect(server->conn); server->conn_type = CLI_NONE; + bt_mesh_gattc_disconnect(server->conn); } } @@ -1127,13 +1141,13 @@ static int send_proxy_cfg(struct bt_mesh_conn *conn, uint16_t net_idx, struct bt case BLE_MESH_PROXY_CFG_FILTER_ADD: for (uint16_t i = 0U; i < cfg->add.addr_num; i++) { - net_buf_simple_add_le16(buf, cfg->add.addr[i]); + net_buf_simple_add_be16(buf, cfg->add.addr[i]); } break; case BLE_MESH_PROXY_CFG_FILTER_REMOVE: for (uint16_t i = 0U; i < cfg->remove.addr_num; i++) { - net_buf_simple_add_le16(buf, cfg->remove.addr[i]); + net_buf_simple_add_be16(buf, cfg->remove.addr[i]); } break; diff --git a/components/bt/esp_ble_mesh/core/proxy_server.c b/components/bt/esp_ble_mesh/core/proxy_server.c index 2dcc54f58d8..33f2169a04a 100644 --- a/components/bt/esp_ble_mesh/core/proxy_server.c +++ b/components/bt/esp_ble_mesh/core/proxy_server.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -182,7 +182,7 @@ static void proxy_sar_timeout(struct k_work *work) BT_WARN("ProxySARTimeout"); client = CONTAINER_OF(work, struct bt_mesh_proxy_client, sar_timer.work); - if (!client || !client->conn) { + if (!client->conn) { BT_ERR("Invalid proxy client parameter"); return; } @@ -312,15 +312,12 @@ static void filter_add(struct bt_mesh_proxy_client *client, for (i = 0; i < ARRAY_SIZE(client->filter); i++) { if (client->filter[i].addr == addr) { + BT_INFO("client addr 0x%04x already added", addr); return; } } for (i = 0; i < ARRAY_SIZE(client->filter); i++) { - if (client->filter[i].addr == addr) { - BT_INFO("client addr 0x%04x already added", addr); - return; - } if (client->filter[i].addr == BLE_MESH_ADDR_UNASSIGNED) { BT_INFO("Add client or filter addr 0x%04x", addr); client->filter[i].addr = addr; @@ -514,7 +511,7 @@ static void proxy_send_beacons(struct k_work *work) { struct bt_mesh_proxy_client *client = CONTAINER_OF(work, struct bt_mesh_proxy_client, - send_beacons);; + send_beacons); int i; BT_DBG("ProxySendBeacons"); @@ -1484,10 +1481,10 @@ int bt_mesh_proxy_server_segment_send(struct bt_mesh_conn *conn, uint8_t type, net_buf_simple_push_u8(msg, BLE_MESH_PROXY_PDU_HDR(BLE_MESH_PROXY_SAR_FIRST, type)); err = proxy_send(conn, msg->data, mtu); - if (err) { - BT_ERR("ProxyServerSendFail %d", err); - return err; - } + /* Note: + * Even if proxy_send() failed, do not return early here in order to + * keep the msg in a consistent final state. + */ net_buf_simple_pull(msg, mtu); while (msg->len) { @@ -1498,14 +1495,14 @@ int bt_mesh_proxy_server_segment_send(struct bt_mesh_conn *conn, uint8_t type, net_buf_simple_push_u8(msg, BLE_MESH_PROXY_PDU_HDR(BLE_MESH_PROXY_SAR_CONT, type)); err = proxy_send(conn, msg->data, mtu); - if (err) { - BT_ERR("ProxyServerSendFail %d", err); - return err; - } + /* Note: + * Even if proxy_send() failed, do not return early here in order to + * keep the msg in a consistent final state. + */ net_buf_simple_pull(msg, mtu); } - return 0; + return err; } int bt_mesh_proxy_server_send(struct bt_mesh_conn *conn, uint8_t type, @@ -2241,6 +2238,9 @@ int bt_mesh_proxy_server_deinit(void) k_delayed_work_free(&client->sar_timer); memset(client, 0, sizeof(struct bt_mesh_proxy_client)); +#if CONFIG_BLE_MESH_PROXY_PRIVACY + client->proxy_privacy = BLE_MESH_PROXY_PRIVACY_DISABLED; +#endif /* CONFIG_BLE_MESH_PROXY_PRIVACY */ } #if CONFIG_BLE_MESH_GATT_PROXY_SERVER && CONFIG_BLE_MESH_PRB_SRV diff --git a/components/bt/esp_ble_mesh/core/pvnr_mgmt.c b/components/bt/esp_ble_mesh/core/pvnr_mgmt.c index 8fc5915d31e..1c2270f88d0 100644 --- a/components/bt/esp_ble_mesh/core/pvnr_mgmt.c +++ b/components/bt/esp_ble_mesh/core/pvnr_mgmt.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -378,11 +378,7 @@ static int provisioner_remove_node(uint16_t index, bool erase) /* Reset corresponding transport info when removing the node */ for (i = 0; i < node->element_num; i++) { bt_mesh_rx_reset_single(node->unicast_addr + i); - } - for (i = 0; i < node->element_num; i++) { bt_mesh_tx_reset_single(node->unicast_addr + i); - } - for (i = 0; i < node->element_num; i++) { bt_mesh_rpl_reset_single(node->unicast_addr + i, erase); } @@ -544,6 +540,11 @@ int bt_mesh_provisioner_delete_node_with_dev_addr(const bt_mesh_addr_t *addr) { int i; + if (addr == NULL) { + BT_ERR("Invalid device address"); + return -EINVAL; + } + bt_mesh_provisioner_lock(); for (i = 0; i < ARRAY_SIZE(mesh_nodes); i++) { diff --git a/components/bt/esp_ble_mesh/core/rpl.c b/components/bt/esp_ble_mesh/core/rpl.c index 43f4a4afdaa..f2035b9cd1b 100644 --- a/components/bt/esp_ble_mesh/core/rpl.c +++ b/components/bt/esp_ble_mesh/core/rpl.c @@ -36,7 +36,7 @@ void bt_mesh_update_rpl(struct bt_mesh_rpl *rpl, struct bt_mesh_net_rx *rx) */ static bool rpl_check_and_store(struct bt_mesh_net_rx *rx, struct bt_mesh_rpl **match) { - BT_DBG("%s, Src 0x%04x Seq %lu OldIV %u", + BT_DBG("%s, Src 0x%04x Seq 0x%06x OldIV %u", match ? "RPLOnlyCheck" : "RPLCheckAndStore", rx->ctx.addr, rx->seq, rx->old_iv); diff --git a/components/bt/esp_ble_mesh/core/scan.c b/components/bt/esp_ble_mesh/core/scan.c index 96b77e8a7f2..739f94200df 100644 --- a/components/bt/esp_ble_mesh/core/scan.c +++ b/components/bt/esp_ble_mesh/core/scan.c @@ -137,8 +137,12 @@ int bt_mesh_unprov_dev_info_query(uint8_t uuid[16], uint8_t addr[6], return 0; } - memcpy(addr, unprov_dev_info_fifo.info[idx].addr, 6); - *adv_type = unprov_dev_info_fifo.info[idx].adv_type; + if (addr) { + memcpy(addr, unprov_dev_info_fifo.info[idx].addr, 6); + } + if (adv_type) { + *adv_type = unprov_dev_info_fifo.info[idx].adv_type; + } break; } } @@ -324,19 +328,19 @@ static void handle_adv_service_data(struct net_buf_simple *buf, #if CONFIG_BLE_MESH_RPR_SRV if (bt_mesh_is_provisioned()) { - const bt_mesh_addr_t *addr = NULL; + const bt_mesh_addr_t *unprov_addr = NULL; if (buf->len != PROV_SVC_DATA_LEN) { BT_WARN("Invalid Mesh Prov Service Data length %d", buf->len); return; } - addr = bt_mesh_get_unprov_dev_addr(); - assert(addr); + unprov_addr = bt_mesh_get_unprov_dev_addr(); + assert(unprov_addr); - bt_mesh_unprov_dev_fifo_enqueue(buf->data, addr->val, bt_mesh_get_adv_type()); + bt_mesh_unprov_dev_fifo_enqueue(buf->data, unprov_addr->val, bt_mesh_get_adv_type()); - bt_mesh_rpr_srv_unprov_beacon_recv(buf, bt_mesh_get_adv_type(), addr, rssi); + bt_mesh_rpr_srv_unprov_beacon_recv(buf, bt_mesh_get_adv_type(), unprov_addr, rssi); } #endif /* CONFIG_BLE_MESH_RPR_SRV */ @@ -391,6 +395,14 @@ static bool ble_scan_en; int bt_mesh_start_ble_scan(struct bt_mesh_ble_scan_param *param) { BT_DBG("StartBLEScan"); + ARG_UNUSED(param); + + /* Note: + * Currently the function is only used to enable reporting + * non-mesh advertising packets to the application layer, + * and the input parameter will not be used for now. + */ + ARG_UNUSED(param); if (ble_scan_en == true) { BT_WARN("%s, Already", __func__); @@ -423,7 +435,7 @@ bool bt_mesh_ble_scan_state_get(void) return ble_scan_en; } -static void inline callback_ble_adv_pkt(const bt_mesh_addr_t *addr, +static inline void callback_ble_adv_pkt(const bt_mesh_addr_t *addr, uint8_t adv_type, uint8_t data[], uint16_t length, int8_t rssi) { @@ -570,6 +582,7 @@ static void bt_mesh_scan_cb(struct bt_mesh_adv_report *adv_rpt) #endif )) { BT_DBG("IgnorePkt, Type 0x%02x AdvType 0x%02x", type, adv_rpt->adv_type); + net_buf_simple_restore(buf, &buf_state); return; } @@ -724,18 +737,18 @@ int bt_mesh_scan_param_update(struct bt_mesh_scan_param *param) BT_DBG("ScanParamUpdate, Type %u Interval %u Window %u", param->type, param->interval, param->window); + err = bt_le_scan_stop(); + if (err && err != -EALREADY) { + BT_ERR("StopScanFailed, Err %d", err); + return err; + } + scan_param.interval = param->interval; scan_param.window = param->window; - err = bt_le_scan_stop(); - if (err) { - if (err == -EALREADY) { - BT_INFO("New scan parameters will take effect after scan starts"); - return 0; - } - - BT_ERR("StopScanFailed, Err %d", err); - return err; + if (err == -EALREADY) { + BT_INFO("New scan parameters will take effect after scan starts"); + return 0; } /* Since the user only needs to set the scan interval and scan window, diff --git a/components/bt/esp_ble_mesh/core/storage/settings.c b/components/bt/esp_ble_mesh/core/storage/settings.c index 8d783893d61..e2a935ac4ee 100644 --- a/components/bt/esp_ble_mesh/core/storage/settings.c +++ b/components/bt/esp_ble_mesh/core/storage/settings.c @@ -1,6 +1,6 @@ /* * SPDX-FileCopyrightText: 2018 Intel Corporation - * SPDX-FileContributor: 2018-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -244,7 +244,7 @@ static int net_set(const char *name) BT_ERR("Failed to load node net info"); memset(bt_mesh.dev_key, 0, sizeof(bt_mesh.dev_key)); bt_mesh_comp_unprovision(); - return 0; + return err; } if (exist == false) { @@ -2353,6 +2353,7 @@ static struct key_update *key_update_find(bool app_key, uint16_t key_idx, if (update->key_idx == key_idx) { match = update; + break; } } @@ -2949,12 +2950,12 @@ int bt_mesh_model_data_store(const struct bt_mesh_model *mod, bool vnd, char path[30] = {'\0'}; uint16_t model_key = 0U; + int len = 0; model_key = BLE_MESH_GET_MODEL_KEY(mod->elem_idx, mod->model_idx); - sprintf(path, "mesh/%s/%04x/d", vnd ? "v" : "s", model_key); - if (name) { - strcat(path, "/"); - strncat(path, name, SETTINGS_MAX_DIR_DEPTH); + len = snprintf(path, sizeof(path), "mesh/%s/%04x/d", vnd ? "v" : "s", model_key); + if (name && len > 0 && len < sizeof(path)) { + snprintf(path + len, sizeof(path) - len, "/%.*s", SETTINGS_MAX_DIR_DEPTH, name); } if (data_len) { diff --git a/components/bt/esp_ble_mesh/core/storage/settings_nvs.c b/components/bt/esp_ble_mesh/core/storage/settings_nvs.c index 6ca00833379..df108d4e089 100644 --- a/components/bt/esp_ble_mesh/core/storage/settings_nvs.c +++ b/components/bt/esp_ble_mesh/core/storage/settings_nvs.c @@ -600,9 +600,9 @@ static int settings_remove_item(bt_mesh_nvs_handle_t handle, const char *key, co length = buf->len - sizeof(val); if (!length) { - settings_save(handle, key, NULL, 0); + err = settings_save(handle, key, NULL, 0); bt_mesh_free_buf(buf); - return 0; + return err; } store = bt_mesh_alloc_buf(length); diff --git a/components/bt/esp_ble_mesh/core/storage/settings_uid.c b/components/bt/esp_ble_mesh/core/storage/settings_uid.c index fae4b89f5f4..8a6ecfc66a9 100644 --- a/components/bt/esp_ble_mesh/core/storage/settings_uid.c +++ b/components/bt/esp_ble_mesh/core/storage/settings_uid.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -101,6 +101,11 @@ int settings_uid_load(void) for (i = 0; i < length / SETTINGS_ITEM_SIZE; i++) { uint16_t index = net_buf_simple_pull_le16(buf); + if (index >= ARRAY_SIZE(user_ids)) { + BT_WARN("Invalid index %u in NVS, skipping", index); + continue; + } + sprintf(name, "mesh/id/%04x", index); err = bt_mesh_load_uid_settings(name, (uint8_t *)user_ids[index].id, @@ -117,7 +122,13 @@ int settings_uid_load(void) } bt_mesh_free_buf(buf); - return err; + + /* Return 0 since partial loads are acceptable by design. + * Individual load failures are logged via BT_WARN/BT_ERR + * in bt_mesh_load_uid_settings() and do not prevent + * successful restoration of other settings. + */ + return 0; } #if CONFIG_BLE_MESH_DEINIT diff --git a/components/bt/esp_ble_mesh/core/test.h b/components/bt/esp_ble_mesh/core/test.h index 23ef6a84278..94ed36ea0cc 100644 --- a/components/bt/esp_ble_mesh/core/test.h +++ b/components/bt/esp_ble_mesh/core/test.h @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2021 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -18,6 +18,9 @@ extern "C" { #endif +#if CONFIG_BLE_MESH_SELF_TEST + +#if CONFIG_BLE_MESH_NODE && CONFIG_BLE_MESH_TEST_AUTO_ENTER_NETWORK struct bt_mesh_device_network_info { uint8_t net_key[16]; uint16_t net_idx; @@ -31,7 +34,9 @@ struct bt_mesh_device_network_info { }; int bt_mesh_device_auto_enter_network(struct bt_mesh_device_network_info *info); +#endif /* CONFIG_BLE_MESH_NODE && CONFIG_BLE_MESH_TEST_AUTO_ENTER_NETWORK */ +#if CONFIG_BLE_MESH_TEST_USE_WHITE_LIST /* Before trying to update the white list, users need to make sure that * one of the following conditions is satisfied: * 1. BLE scanning is disabled; @@ -44,6 +49,7 @@ int bt_mesh_test_update_white_list(struct bt_mesh_white_list *wl); int bt_mesh_test_start_scanning(bool wl_en); int bt_mesh_test_stop_scanning(void); +#endif /* CONFIG_BLE_MESH_TEST_USE_WHITE_LIST */ typedef void (* bt_mesh_test_net_pdu_cb_t)(const uint8_t *data, uint16_t length); @@ -53,6 +59,8 @@ void bt_mesh_test_register_net_pdu_cb(bt_mesh_test_net_pdu_cb_t cb); void bt_mesh_test_set_seq(uint32_t seq); +#endif /* CONFIG_BLE_MESH_SELF_TEST */ + #ifdef __cplusplus } #endif diff --git a/components/bt/esp_ble_mesh/core/transport.c b/components/bt/esp_ble_mesh/core/transport.c index 0c33dce5ef0..eaf1cfd2317 100644 --- a/components/bt/esp_ble_mesh/core/transport.c +++ b/components/bt/esp_ble_mesh/core/transport.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2018-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -48,10 +48,10 @@ _Static_assert(CONFIG_BLE_MESH_ADV_BUF_COUNT >= (CONFIG_BLE_MESH_TX_SEG_MAX + 3) #define APP_MIC_LEN(aszmic) ((aszmic) ? BLE_MESH_MIC_LONG : BLE_MESH_MIC_SHORT) -#define UNSEG_HDR(akf, aid) ((akf << 6) | (aid & AID_MASK)) +#define UNSEG_HDR(akf, aid) (((akf) << 6) | ((aid) & AID_MASK)) #define SEG_HDR(akf, aid) (UNSEG_HDR(akf, aid) | 0x80) -#define BLOCK_COMPLETE(seg_n) (uint32_t)(((uint64_t)1 << (seg_n + 1)) - 1) +#define BLOCK_COMPLETE(seg_n) (uint32_t)(((uint64_t)1 << ((seg_n) + 1)) - 1) #define SEQ_AUTH(iv_index, seq) (((uint64_t)iv_index) << 24 | (uint64_t)seq) @@ -795,7 +795,7 @@ int bt_mesh_trans_send(struct bt_mesh_net_tx *tx, struct net_buf_simple *msg, uint8_t aid = 0U; int err = 0; - BT_DBG("transcend"); + BT_DBG("TransLegSend"); if (msg->len < 1) { BT_ERR("Zero-length SDU not allowed"); @@ -1499,7 +1499,7 @@ static void seg_ack(struct k_work *work) bt_mesh_seg_rx_unlock(); } -static inline uint16_t sdu_len_max(uint8_t seg_n,uint16_t seg_len) +static inline uint16_t sdu_len_max(uint8_t seg_n, uint16_t seg_len) { BT_DBG("IsSduLenOK,Len:%u,SegN:%u", seg_len, seg_n); @@ -1515,7 +1515,12 @@ static inline bool sdu_len_is_ok(bool ctl, uint8_t seg_n, uint16_t buf_len) BT_DBG("IsSduLenOK, CTL %u SegN %u", ctl, seg_n); #if CONFIG_BLE_MESH_LONG_PACKET - if ((sdu_len_max(seg_n, buf_len) > CONFIG_BLE_MESH_RX_SDU_MAX)) { + /* Use maximum possible segment length based on CTL flag, not actual buf_len, + * to correctly detect long packets. The last segment can be shorter than + * regular segments, so using buf_len could underestimate the SDU size. + */ + uint8_t max_seg_len = ctl ? BLE_MESH_EXT_CTL_SEG_SDU_MAX : BLE_MESH_EXT_APP_SEG_SDU_MAX; + if ((sdu_len_max(seg_n, max_seg_len) > BLE_MESH_EXT_RX_SDU_MAX)) { si.long_pkt = 1; return ((seg_n + 1) * seg_len(&si) <= BLE_MESH_EXT_RX_SDU_MAX); } diff --git a/components/bt/esp_ble_mesh/core/transport.enh.c b/components/bt/esp_ble_mesh/core/transport.enh.c index 4a962a6ba33..543e3fc9bb0 100644 --- a/components/bt/esp_ble_mesh/core/transport.enh.c +++ b/components/bt/esp_ble_mesh/core/transport.enh.c @@ -2,7 +2,7 @@ /* * SPDX-FileCopyrightText: 2017 Intel Corporation - * SPDX-FileContributor: 2023-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileContributor: 2023-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -45,12 +45,12 @@ _Static_assert(CONFIG_BLE_MESH_ADV_BUF_COUNT >= (CONFIG_BLE_MESH_TX_SEG_MAX + 3) #define APP_MIC_LEN(aszmic) ((aszmic) ? BLE_MESH_MIC_LONG : BLE_MESH_MIC_SHORT) -#define UNSEG_HDR(akf, aid) ((akf << 6) | (aid & AID_MASK)) -#define SEG_HDR(akf, aid) (UNSEG_HDR(akf, aid) | 0x80) +#define UNSEG_HDR(akf, aid) (((akf) << 6) | ((aid) & AID_MASK)) +#define SEG_HDR(akf, aid) (UNSEG_HDR((akf), (aid)) | 0x80) -#define BLOCK_COMPLETE(seg_n) (uint32_t)(((uint64_t)1 << (seg_n + 1)) - 1) +#define BLOCK_COMPLETE(seg_n) (uint32_t)(((uint64_t)1 << ((seg_n) + 1)) - 1) -#define SEQ_AUTH(iv_index, seq) (((uint64_t)iv_index) << 24 | (uint64_t)seq) +#define SEQ_AUTH(iv_index, seq) (((uint64_t)(iv_index)) << 24 | (uint64_t)(seq)) /* How long to wait for available buffers before giving up */ #define BUF_TIMEOUT K_NO_WAIT @@ -226,12 +226,13 @@ uint32_t bt_mesh_seg_rx_interval(void) uint32_t bt_mesh_seg_ack_timeout(uint8_t seg_n) { uint32_t timeout = 0U; - float min = 0.0; + uint32_t min_x2 = 0U; - min = MIN((float)seg_n + 0.5, (float)bt_mesh_get_sar_adi() + 1.5); - timeout = (uint32_t)(min * bt_mesh_seg_rx_interval()); + /* Use fixed-point arithmetic (x2 scale) to avoid float on FPU-less chips */ + min_x2 = MIN((uint32_t)seg_n * 2U + 1U, (uint32_t)bt_mesh_get_sar_adi() * 2U + 3U); + timeout = (min_x2 * bt_mesh_seg_rx_interval()) / 2U; - BT_DBG("SegAckTimeout %lu, Min %f", timeout, min); + BT_DBG("SegAckTimeout %lu, Min %lu", timeout, min_x2); return timeout; } @@ -1196,7 +1197,7 @@ int bt_mesh_trans_send(struct bt_mesh_net_tx *tx, struct net_buf_simple *msg, uint8_t aid = 0U; int err = 0; - BT_DBG("transcend"); + BT_DBG("TransEnhSend"); if (msg->len < 1) { BT_ERR("Zero-length SDU not allowed"); @@ -1679,6 +1680,12 @@ static int trans_heartbeat(struct bt_mesh_net_rx *rx, init_ttl = (net_buf_simple_pull_u8(buf) & 0x7f); feat = net_buf_simple_pull_be16(buf); + if (rx->ctx.recv_ttl > init_ttl) { + BT_WARN("Malformed heartbeat: recv_ttl (%u) > init_ttl (%u)", + rx->ctx.recv_ttl, init_ttl); + return -EINVAL; + } + hops = (init_ttl - rx->ctx.recv_ttl + 1); BT_INFO("Src 0x%04x TTL %u InitTTL %u Hops %u Feat 0x%04x", @@ -2064,7 +2071,7 @@ static void discard_msg(struct k_work *work) seg_rx_reset(rx, false); } -static inline uint16_t sdu_len_max(uint8_t seg_n,uint16_t seg_len) +static inline uint16_t sdu_len_max(uint8_t seg_n, uint16_t seg_len) { BT_DBG("IsSduLenOK,Len:%u,SegN:%u", seg_len, seg_n); @@ -2080,7 +2087,12 @@ static inline bool sdu_len_is_ok(bool ctl, uint8_t seg_n, uint16_t buf_len) BT_DBG("IsSduLenOK, CTL %u SegN %u", ctl, seg_n); #if CONFIG_BLE_MESH_LONG_PACKET - if ((sdu_len_max(seg_n, buf_len) > CONFIG_BLE_MESH_RX_SDU_MAX)) { + /* Use maximum possible segment length based on CTL flag, not actual buf_len, + * to correctly detect long packets. The last segment can be shorter than + * regular segments, so using buf_len could underestimate the SDU size. + */ + uint8_t max_seg_len = ctl ? BLE_MESH_EXT_CTL_SEG_SDU_MAX : BLE_MESH_EXT_APP_SEG_SDU_MAX; + if ((sdu_len_max(seg_n, max_seg_len) > BLE_MESH_EXT_RX_SDU_MAX)) { si.long_pkt = 1; return ((seg_n + 1) * seg_len(&si) <= BLE_MESH_EXT_RX_SDU_MAX); } diff --git a/components/bt/esp_ble_mesh/lib/ext.c b/components/bt/esp_ble_mesh/lib/ext.c index 9f7b61d548e..923d6f7db0b 100644 --- a/components/bt/esp_ble_mesh/lib/ext.c +++ b/components/bt/esp_ble_mesh/lib/ext.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2023-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2023-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -527,7 +527,7 @@ const char *bt_mesh_ext_hex(const void *buf, size_t len) } /* Crypto */ -bool bt_mesh_ext_s1(const char *m, uint8_t salt[16]) +int bt_mesh_ext_s1(const char *m, uint8_t salt[16]) { return bt_mesh_s1(m, salt); } @@ -866,18 +866,21 @@ void *bt_mesh_ext_model_get_pub(void *model) uint16_t bt_mesh_ext_model_get_pub_addr(void *model) { - return MODEL(model)->pub->addr; + struct bt_mesh_model_pub *pub = MODEL(model)->pub; + return pub ? pub->addr : BLE_MESH_ADDR_UNASSIGNED; } uint16_t bt_mesh_ext_model_get_pub_key(void *model) { - return MODEL(model)->pub->key; + struct bt_mesh_model_pub *pub = MODEL(model)->pub; + return pub ? pub->key : 0; } uint8_t bt_mesh_ext_model_get_pub_directed_pub_policy(void *model) { #if CONFIG_BLE_MESH_DF_SRV - return MODEL(model)->pub->directed_pub_policy; + struct bt_mesh_model_pub *pub = MODEL(model)->pub; + return pub ? pub->directed_pub_policy : 0; #else assert(0); return 0; @@ -887,7 +890,10 @@ uint8_t bt_mesh_ext_model_get_pub_directed_pub_policy(void *model) void bt_mesh_ext_model_set_pub_directed_pub_policy(void *model, uint8_t directed_pub_policy) { #if CONFIG_BLE_MESH_DF_SRV - MODEL(model)->pub->directed_pub_policy = directed_pub_policy; + struct bt_mesh_model_pub *pub = MODEL(model)->pub; + if (pub) { + pub->directed_pub_policy = directed_pub_policy; + } #else assert(0); #endif /* CONFIG_BLE_MESH_DF_SRV */ @@ -895,7 +901,8 @@ void bt_mesh_ext_model_set_pub_directed_pub_policy(void *model, uint8_t directed void *bt_mesh_ext_model_get_pub_msg(void *model) { - return MODEL(model)->pub->msg; + struct bt_mesh_model_pub *pub = MODEL(model)->pub; + return pub ? pub->msg : NULL; } uint8_t bt_mesh_ext_model_get_keys_count(void *model) @@ -1037,7 +1044,7 @@ bool bt_mesh_ext_model_is_opcode_belongs(void *models, uint8_t model_count, uint struct bt_mesh_model *model = NULL; for (size_t i = 0; i < model_count; i++) { - model = models + i; + model = &((struct bt_mesh_model *)models)[i]; for (op = model->op; op->func; op++) { if (op->opcode == opcode) { return true; @@ -1127,6 +1134,9 @@ int bt_mesh_ext_net_pdu_decrypt(void *sub, const uint8_t *enc, uint16_t bt_mesh_ext_net_get_sub_net_idx(uint8_t index) { + if (index >= ARRAY_SIZE(bt_mesh.sub)) { + return BLE_MESH_KEY_UNUSED; + } return bt_mesh.sub[index].net_idx; } @@ -1137,6 +1147,9 @@ uint8_t bt_mesh_ext_net_get_sub_count(void) void *bt_mesh_ext_net_get_sub(uint8_t index) { + if (index >= ARRAY_SIZE(bt_mesh.sub)) { + return NULL; + } return &bt_mesh.sub[index]; } @@ -1167,11 +1180,17 @@ uint16_t bt_mesh_ext_net_get_rpl_count(void) uint16_t bt_mesh_ext_net_get_rpl_src(uint16_t index) { + if (index >= ARRAY_SIZE(bt_mesh.rpl)) { + return BLE_MESH_ADDR_UNASSIGNED; + } return bt_mesh.rpl[index].src; } void bt_mesh_ext_net_reset_rpl(uint16_t index) { + if (index >= ARRAY_SIZE(bt_mesh.rpl)) { + return; + } memset(&bt_mesh.rpl[index], 0, sizeof(bt_mesh.rpl[index])); } @@ -1271,13 +1290,13 @@ uint8_t bt_mesh_ext_default_ttl_get(void) void bt_mesh_ext_key_idx_pack(struct net_buf_simple *buf, uint16_t idx1, uint16_t idx2) { - return key_idx_pack(buf, idx1, idx2); + key_idx_pack(buf, idx1, idx2); } void bt_mesh_ext_key_idx_unpack(struct net_buf_simple *buf, uint16_t *idx1, uint16_t *idx2) { - return key_idx_unpack(buf, idx1, idx2); + key_idx_unpack(buf, idx1, idx2); } /* Provisioning */ @@ -1729,6 +1748,9 @@ void bt_mesh_ext_prov_link_free_pb_remote_data(void *link) uint8_t *bt_mesh_ext_prov_link_get_record(void *link, uint16_t id) { #if (CONFIG_BLE_MESH_PROVISIONER && CONFIG_BLE_MESH_CERT_BASED_PROV) + if (id >= BLE_MESH_REC_MAX_ID) { + return NULL; + } return LINK(link)->records[id]; #else assert(0); @@ -1742,6 +1764,9 @@ uint8_t *bt_mesh_ext_prov_link_alloc_record(void *link, uint16_t id, uint16_t le if (id >= BLE_MESH_REC_MAX_ID) { return NULL; } + if (LINK(link)->records[id] != NULL) { + return NULL; /* Slot already allocated, caller should free first */ + } LINK(link)->records[id] = bt_mesh_calloc(len * sizeof(uint8_t)); return LINK(link)->records[id]; #else @@ -1930,6 +1955,9 @@ uint16_t bt_mesh_ext_proxy_server_get_filter_size(void *client) uint16_t bt_mesh_ext_proxy_server_get_filter_addr(void *client, uint8_t index) { #if CONFIG_BLE_MESH_GATT_PROXY_SERVER + if (index >= ARRAY_SIZE(PROXY_CLI(client)->filter)) { + return 0; + } return PROXY_CLI(client)->filter[index].addr; #else assert(0); @@ -1940,6 +1968,9 @@ uint16_t bt_mesh_ext_proxy_server_get_filter_addr(void *client, uint8_t index) bool bt_mesh_ext_proxy_server_filter_is_client(void *client, uint8_t index) { #if CONFIG_BLE_MESH_GATT_PROXY_SERVER + if (index >= ARRAY_SIZE(PROXY_CLI(client)->filter)) { + return false; + } return PROXY_CLI(client)->filter[index].proxy_client; #else assert(0); @@ -2117,7 +2148,7 @@ int bt_mesh_ext_rpr_srv_set_waiting_prov_link(void* link, bt_mesh_addr_t *addr) #else assert(0); return 0; -#endif /* CONFIG_BLE_MESH_PB_GATT && CONFIG_BLE_MESH_RPR_SRV) */ +#endif /* (CONFIG_BLE_MESH_PB_GATT && CONFIG_BLE_MESH_RPR_SRV) */ } /* Friend */ @@ -4192,7 +4223,7 @@ static const bt_mesh_ext_config_t bt_mesh_ext_cfg = { .config_ble_mesh_prb_cli = IS_ENABLED(CONFIG_BLE_MESH_PRB_CLI), .config_ble_mesh_prb_srv = IS_ENABLED(CONFIG_BLE_MESH_PRB_SRV), .config_ble_mesh_private_beacon = (IS_ENABLED(CONFIG_BLE_MESH_PRB_SRV) | \ - IS_ENABLED(CONFIG_BLE_MESH_PRB_SRV)), + IS_ENABLED(CONFIG_BLE_MESH_PRB_CLI)), .config_ble_mesh_rpr_cli = IS_ENABLED(CONFIG_BLE_MESH_RPR_CLI), .config_ble_mesh_rpr_srv = IS_ENABLED(CONFIG_BLE_MESH_RPR_SRV), .config_ble_mesh_rpr_srv_active_scan = IS_ENABLED(CONFIG_BLE_MESH_RPR_SRV_ACTIVE_SCAN), @@ -5060,7 +5091,7 @@ void ble_mesh_lib_compressed_buf_out(uint8_t log_level, uint32_t log_index, uint */ void bt_mesh_lib_ext_func_dummy_call(void) { - (void *)bt_hex(NULL, 0); + (void)bt_hex(NULL, 0); } int bt_mesh_v11_ext_init(void) diff --git a/components/bt/esp_ble_mesh/models/client/client_common.c b/components/bt/esp_ble_mesh/models/client/client_common.c index 1c177c3cf9d..2647a2c7dfd 100644 --- a/components/bt/esp_ble_mesh/models/client/client_common.c +++ b/components/bt/esp_ble_mesh/models/client/client_common.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2017-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2017-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -20,17 +20,14 @@ #define HCI_TIME_FOR_START_ADV K_MSEC(5) /* Three adv related hci commands may take 4 ~ 5ms */ -static bt_mesh_client_node_t *client_pick_node(sys_slist_t *list, uint16_t tx_dst) +static bt_mesh_client_node_t *client_pick_node_unsafe(sys_slist_t *list, uint16_t tx_dst) { bt_mesh_client_node_t *node = NULL; sys_snode_t *cur = NULL; BT_DBG("ClientPickNode, Dst 0x%04x", tx_dst); - bt_mesh_list_lock(); - if (sys_slist_is_empty(list)) { - bt_mesh_list_unlock(); BT_DBG("ListEmpty"); return NULL; } @@ -39,18 +36,26 @@ static bt_mesh_client_node_t *client_pick_node(sys_slist_t *list, uint16_t tx_ds cur != NULL; cur = sys_slist_peek_next(cur)) { node = (bt_mesh_client_node_t *)cur; if (node->ctx.addr == tx_dst) { - bt_mesh_list_unlock(); BT_DBG("ListNodeFound"); return node; } } - bt_mesh_list_unlock(); - BT_DBG("ListNodeNotFound"); return NULL; } +static bt_mesh_client_node_t *client_pick_node(sys_slist_t *list, uint16_t tx_dst) +{ + bt_mesh_client_node_t *node = NULL; + + bt_mesh_list_lock(); + node = client_pick_node_unsafe(list, tx_dst); + bt_mesh_list_unlock(); + + return node; +} + bt_mesh_client_node_t *bt_mesh_is_client_recv_publish_msg(struct bt_mesh_model *model, struct bt_mesh_msg_ctx *ctx, struct net_buf_simple *buf, @@ -99,7 +104,11 @@ bt_mesh_client_node_t *bt_mesh_is_client_recv_publish_msg(struct bt_mesh_model * return NULL; } - if ((node = client_pick_node(&data->queue, ctx->addr)) == NULL) { + bt_mesh_list_lock(); + + node = client_pick_node_unsafe(&data->queue, ctx->addr); + if (node == NULL) { + bt_mesh_list_unlock(); BT_DBG("MsgFromUnknownSrc"); if (cli->publish_status && need_pub) { cli->publish_status(ctx->recv_op, model, ctx, buf); @@ -108,6 +117,7 @@ bt_mesh_client_node_t *bt_mesh_is_client_recv_publish_msg(struct bt_mesh_model * } if (node->op_pending != ctx->recv_op) { + bt_mesh_list_unlock(); BT_DBG("MsgWithUnknownOp"); if (cli->publish_status && need_pub) { cli->publish_status(ctx->recv_op, model, ctx, buf); @@ -116,6 +126,7 @@ bt_mesh_client_node_t *bt_mesh_is_client_recv_publish_msg(struct bt_mesh_model * } if (k_delayed_work_remaining_get(&node->timer) == 0) { + bt_mesh_list_unlock(); BT_DBG("MsgWithTimerExpired"); if (cli->publish_status && need_pub) { cli->publish_status(ctx->recv_op, model, ctx, buf); @@ -123,6 +134,8 @@ bt_mesh_client_node_t *bt_mesh_is_client_recv_publish_msg(struct bt_mesh_model * return NULL; } + bt_mesh_list_unlock(); + return node; } @@ -152,7 +165,8 @@ static uint32_t client_get_status_op(const bt_mesh_client_op_pair_t *op_pair, static int32_t client_get_adv_duration(struct bt_mesh_msg_ctx *ctx) { - uint16_t duration = 0, adv_int = 0; + int32_t duration = 0; + uint16_t adv_int = 0; uint8_t xmit = 0; /* Initialize with network transmission */ @@ -172,9 +186,9 @@ static int32_t client_get_adv_duration(struct bt_mesh_msg_ctx *ctx) adv_int = BLE_MESH_TRANSMIT_INT(xmit); duration = (BLE_MESH_TRANSMIT_COUNT(xmit) + 1) * (adv_int + 10); - BT_DBG("Duration %ld", (int32_t)duration); + BT_DBG("Duration %ld", duration); - return (int32_t)duration; + return duration; } static int32_t client_calc_timeout(struct bt_mesh_msg_ctx *ctx, diff --git a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_agg_model.c b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_agg_model.c index ad087c33eb4..4b2a66ed955 100644 --- a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_agg_model.c +++ b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_agg_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2023 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -76,8 +76,8 @@ void btc_ble_mesh_agg_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void *p } net_buf_simple_add_mem(dst->agg_send.msg->agg_sequence.items, - src->agg_send.msg->agg_sequence.items->data, - src->agg_send.msg->agg_sequence.items->len); + src->agg_send.msg->agg_sequence.items->data, + src->agg_send.msg->agg_sequence.items->len); } } break; @@ -165,6 +165,7 @@ static void btc_ble_mesh_agg_client_copy_req_data(btc_msg_t *msg, void *p_dest, break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_AGG_CLIENT_SEND_COMP_EVT: case ESP_BLE_MESH_AGG_CLIENT_SEND_TIMEOUT_EVT: break; @@ -197,6 +198,7 @@ static void btc_ble_mesh_agg_client_free_req_data(btc_msg_t *msg) break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_AGG_CLIENT_SEND_COMP_EVT: case ESP_BLE_MESH_AGG_CLIENT_SEND_TIMEOUT_EVT: if (arg->params) { @@ -286,8 +288,8 @@ void btc_ble_mesh_agg_client_recv_pub_cb(uint32_t opcode, } bt_mesh_agg_client_cb_evt_to_btc(opcode, - BTC_BLE_MESH_EVT_AGG_CLIENT_RECV_PUB, - model, ctx, buf->data, buf->len); + BTC_BLE_MESH_EVT_AGG_CLIENT_RECV_PUB, + model, ctx, buf->data, buf->len); } static int btc_ble_mesh_agg_client_send(esp_ble_mesh_client_common_param_t *params, @@ -329,7 +331,7 @@ void btc_ble_mesh_agg_client_call_handler(btc_msg_t *msg) cb.send.err_code = btc_ble_mesh_agg_client_send(arg->agg_send.params, arg->agg_send.msg); btc_ble_mesh_agg_client_cb(&cb, - ESP_BLE_MESH_AGG_CLIENT_SEND_COMP_EVT); + ESP_BLE_MESH_AGG_CLIENT_SEND_COMP_EVT); break; default: break; @@ -430,7 +432,7 @@ static void btc_ble_mesh_agg_server_free_req_data(btc_msg_t *msg) } static void btc_ble_mesh_agg_server_cb( - esp_ble_mesh_agg_server_cb_param_t *cb_params, uint8_t act) + esp_ble_mesh_agg_server_cb_param_t *cb_params, uint8_t act) { btc_msg_t msg = {0}; diff --git a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_brc_model.c b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_brc_model.c index 6b607eab185..156d53b9ec4 100644 --- a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_brc_model.c +++ b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_brc_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2023 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -166,6 +166,7 @@ static void btc_ble_mesh_brc_client_copy_req_data(btc_msg_t *msg, void *p_dest, break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_BRC_CLIENT_SEND_COMP_EVT: case ESP_BLE_MESH_BRC_CLIENT_SEND_TIMEOUT_EVT: break; @@ -202,6 +203,7 @@ static void btc_ble_mesh_brc_client_free_req_data(btc_msg_t *msg) break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_BRC_CLIENT_SEND_COMP_EVT: case ESP_BLE_MESH_BRC_CLIENT_SEND_TIMEOUT_EVT: if (arg->params) { @@ -291,8 +293,8 @@ void btc_ble_mesh_brc_client_recv_pub_cb(uint32_t opcode, } bt_mesh_brc_client_cb_evt_to_btc(opcode, - ESP_BLE_MESH_BRC_CLIENT_RECV_PUB_EVT, - model, ctx, buf->data, buf->len); + ESP_BLE_MESH_BRC_CLIENT_RECV_PUB_EVT, + model, ctx, buf->data, buf->len); } static int btc_ble_mesh_brc_client_send(esp_ble_mesh_client_common_param_t *params, @@ -360,7 +362,7 @@ void btc_ble_mesh_brc_client_call_handler(btc_msg_t *msg) cb.send.err_code = btc_ble_mesh_brc_client_send(arg->brc_send.params, arg->brc_send.msg); btc_ble_mesh_brc_client_cb(&cb, - ESP_BLE_MESH_BRC_CLIENT_SEND_COMP_EVT); + ESP_BLE_MESH_BRC_CLIENT_SEND_COMP_EVT); break; default: break; diff --git a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_df_model.c b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_df_model.c index 92dc75e4908..0ee8484b3fc 100644 --- a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_df_model.c +++ b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_df_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2023 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -125,7 +125,7 @@ void btc_ble_mesh_df_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void *p_ switch (src->df_set.params->opcode) { case ESP_BLE_MESH_MODEL_OP_FORWARDING_TABLE_DEPS_ADD: if (src->df_set.set->forwarding_table_deps_add.dep_origin_uar_list && - src->df_set.set->forwarding_table_deps_add.dep_origin_uar_list_size) { + src->df_set.set->forwarding_table_deps_add.dep_origin_uar_list_size) { length = src->df_set.set->forwarding_table_deps_add.dep_origin_uar_list_size * sizeof(esp_ble_mesh_uar_t); dst->df_set.set->forwarding_table_deps_add.dep_origin_uar_list = bt_mesh_calloc(length); if (!dst->df_set.set->forwarding_table_deps_add.dep_origin_uar_list) { @@ -143,7 +143,7 @@ void btc_ble_mesh_df_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void *p_ length); } if (src->df_set.set->forwarding_table_deps_add.dep_target_uar_list && - src->df_set.set->forwarding_table_deps_add.dep_target_uar_list_size) { + src->df_set.set->forwarding_table_deps_add.dep_target_uar_list_size) { length = src->df_set.set->forwarding_table_deps_add.dep_target_uar_list_size * sizeof(esp_ble_mesh_uar_t); dst->df_set.set->forwarding_table_deps_add.dep_target_uar_list = bt_mesh_calloc(length); if (!dst->df_set.set->forwarding_table_deps_add.dep_target_uar_list) { @@ -167,7 +167,7 @@ void btc_ble_mesh_df_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void *p_ break; case ESP_BLE_MESH_MODEL_OP_FORWARDING_TABLE_DEPS_DEL: if (src->df_set.set->forwarding_table_deps_del.dep_origin_list && - src->df_set.set->forwarding_table_deps_del.dep_origin_list_size) { + src->df_set.set->forwarding_table_deps_del.dep_origin_list_size) { length = src->df_set.set->forwarding_table_deps_del.dep_origin_list_size * 2; dst->df_set.set->forwarding_table_deps_del.dep_origin_list = bt_mesh_calloc(length); if (!dst->df_set.set->forwarding_table_deps_del.dep_origin_list) { @@ -185,7 +185,7 @@ void btc_ble_mesh_df_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void *p_ length); } if (src->df_set.set->forwarding_table_deps_del.dep_target_list && - src->df_set.set->forwarding_table_deps_del.dep_target_list_size) { + src->df_set.set->forwarding_table_deps_del.dep_target_list_size) { length = src->df_set.set->forwarding_table_deps_del.dep_target_list_size * 2; dst->df_set.set->forwarding_table_deps_del.dep_target_list = bt_mesh_calloc(length); if (!dst->df_set.set->forwarding_table_deps_del.dep_target_list) { @@ -351,6 +351,7 @@ static void btc_ble_mesh_df_client_copy_req_data(btc_msg_t *msg, void *p_dest, v break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_DF_CLIENT_SEND_COMP_EVT: case ESP_BLE_MESH_DF_CLIENT_SEND_TIMEOUT_EVT: break; @@ -389,6 +390,7 @@ static void btc_ble_mesh_df_client_free_req_data(btc_msg_t *msg) break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_DF_CLIENT_SEND_COMP_EVT: case ESP_BLE_MESH_DF_CLIENT_SEND_TIMEOUT_EVT: if (arg->params) { @@ -481,8 +483,8 @@ void btc_ble_mesh_df_client_recv_pub_cb(uint32_t opcode, } bt_mesh_df_client_cb_evt_to_btc(opcode, - BTC_BLE_MESH_EVT_DF_CLIENT_RECV_PUB, - model, ctx, buf->data, buf->len); + BTC_BLE_MESH_EVT_DF_CLIENT_RECV_PUB, + model, ctx, buf->data, buf->len); } static int btc_ble_mesh_df_client_get_state(esp_ble_mesh_client_common_param_t *params, @@ -633,14 +635,14 @@ void btc_ble_mesh_df_client_call_handler(btc_msg_t *msg) cb.send.err_code = btc_ble_mesh_df_client_get_state(arg->df_get.params, arg->df_get.get); btc_ble_mesh_df_client_cb(&cb, - ESP_BLE_MESH_DF_CLIENT_SEND_COMP_EVT); + ESP_BLE_MESH_DF_CLIENT_SEND_COMP_EVT); break; case BTC_BLE_MESH_ACT_DF_CLIENT_SET_STATE: cb.params = arg->df_set.params; cb.send.err_code = btc_ble_mesh_df_client_set_state(arg->df_set.params, arg->df_set.set); btc_ble_mesh_df_client_cb(&cb, - ESP_BLE_MESH_DF_CLIENT_SEND_COMP_EVT); + ESP_BLE_MESH_DF_CLIENT_SEND_COMP_EVT); break; default: break; @@ -685,7 +687,7 @@ static inline void btc_ble_mesh_df_server_cb_to_app(esp_ble_mesh_df_server_cb_ev } static void btc_ble_mesh_df_server_cb( - esp_ble_mesh_df_server_cb_param_t *cb_params, uint8_t act) + esp_ble_mesh_df_server_cb_param_t *cb_params, uint8_t act) { btc_msg_t msg = {0}; diff --git a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_dfu_model.c b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_dfu_model.c index f316486c0c8..53e036512a5 100644 --- a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_dfu_model.c +++ b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_dfu_model.c @@ -94,8 +94,8 @@ void btc_ble_mesh_dfu_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void *p } case BTC_BLE_MESH_ACT_DFU_CLIENT_IMG_SEND: /* That will be freed when dfu completed or failed not on btc deep free */ - dst->send_arg.inputs =(struct esp_ble_mesh_blob_cli_inputs *) - dfu_targets_alloc((struct bt_mesh_blob_cli_inputs *)src->send_arg.inputs); + dst->send_arg.inputs = (struct esp_ble_mesh_blob_cli_inputs *) + dfu_targets_alloc((struct bt_mesh_blob_cli_inputs *)src->send_arg.inputs); break; default: BT_DBG("%s, Unknown act %d", __func__, msg->act); @@ -119,13 +119,13 @@ void btc_ble_mesh_dfu_client_arg_deep_free(btc_msg_t *msg) if (arg->dfu_get.params) { if (arg->dfu_get.get) { switch (arg->dfu_get.params->opcode) { - case ESP_BLE_MESH_DFU_OP_UPDATE_METADATA_CHECK: - if (arg->dfu_get.get->dfu_metadata_check.metadata) { - bt_mesh_free_buf(arg->dfu_get.get->dfu_metadata_check.metadata); - } - break; - default: - break; + case ESP_BLE_MESH_DFU_OP_UPDATE_METADATA_CHECK: + if (arg->dfu_get.get->dfu_metadata_check.metadata) { + bt_mesh_free_buf(arg->dfu_get.get->dfu_metadata_check.metadata); + } + break; + default: + break; } bt_mesh_free(arg->dfu_get.get); } @@ -185,6 +185,7 @@ static void btc_ble_mesh_dfu_client_copy_req_data(btc_msg_t *msg, void *p_dest, break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_DFU_CLIENT_SEND_COMP_EVT: case ESP_BLE_MESH_DFU_CLIENT_TIMEOUT_EVT: case ESP_BLE_MESH_DFU_CLIENT_IMG_SEND_CMP_EVT: @@ -221,6 +222,7 @@ static void btc_ble_mesh_dfu_client_free_req_data(btc_msg_t *msg) break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_DFU_CLIENT_SEND_COMP_EVT: case ESP_BLE_MESH_DFU_CLIENT_TIMEOUT_EVT: case ESP_BLE_MESH_DFU_CLIENT_IMG_SEND_CMP_EVT: @@ -457,7 +459,7 @@ static inline void btc_ble_mesh_dfd_client_cb_to_app(btc_ble_mesh_dfd_client_cb_ esp_ble_mesh_dfd_client_cb_param_t *param) { esp_ble_mesh_dfd_client_cb_t btc_ble_mesh_cb = - (esp_ble_mesh_dfd_client_cb_t)btc_profile_cb_get(BTC_PID_DFD_CLIENT); + (esp_ble_mesh_dfd_client_cb_t)btc_profile_cb_get(BTC_PID_DFD_CLIENT); if (btc_ble_mesh_cb) { btc_ble_mesh_cb(event, param); } @@ -476,7 +478,7 @@ static inline bool dfd_client_param_need(uint32_t opcode) case ESP_BLE_MESH_DFD_OP_FW_DELETE: return true; default: - break; + break; } return false; } @@ -496,38 +498,38 @@ static int btc_ble_mesh_dfd_client_get(esp_ble_mesh_client_common_param_t *param return -EINVAL; } - switch(params->opcode) { - case ESP_BLE_MESH_DFD_OP_RECEIVERS_GET: - case ESP_BLE_MESH_DFD_OP_FW_GET: - case ESP_BLE_MESH_DFD_OP_FW_GET_BY_INDEX: - if (get == NULL) { - BT_ERR("%s:InvParam", __func__); - return -EINVAL; - } + switch (params->opcode) { + case ESP_BLE_MESH_DFD_OP_RECEIVERS_GET: + case ESP_BLE_MESH_DFD_OP_FW_GET: + case ESP_BLE_MESH_DFD_OP_FW_GET_BY_INDEX: + if (get == NULL) { + BT_ERR("%s:InvParam", __func__); + return -EINVAL; + } break; - default: + default: break; } btc_ble_mesh_set_client_common_param(params, ¶m, false); switch (params->opcode) { - case ESP_BLE_MESH_DFD_OP_RECEIVERS_GET: - return bt_mesh_dfd_cli_receivers_get(¶m, get->receivers_get.first_index, - get->receivers_get.entries_limit); - case ESP_BLE_MESH_DFD_OP_CAPABILITIES_GET: - return bt_mesh_dfd_cli_distribution_capabilities_get(¶m); - case ESP_BLE_MESH_DFD_OP_GET: - return bt_mesh_dfd_cli_distribution_get(¶m); - case ESP_BLE_MESH_DFD_OP_UPLOAD_GET: - return bt_mesh_dfd_cli_distribution_upload_get(¶m); - case ESP_BLE_MESH_DFD_OP_FW_GET: - return bt_mesh_dfd_cli_firmware_get(¶m, get->dist_fw_get.fwid); - case ESP_BLE_MESH_DFD_OP_FW_GET_BY_INDEX: - return bt_mesh_dfd_cli_firmware_get_by_index(¶m, get->dist_fw_get_by_idx.dist_fw_idx); - default: - BT_ERR("UknOpc:%04x", params->opcode); - return -EINVAL; + case ESP_BLE_MESH_DFD_OP_RECEIVERS_GET: + return bt_mesh_dfd_cli_receivers_get(¶m, get->receivers_get.first_index, + get->receivers_get.entries_limit); + case ESP_BLE_MESH_DFD_OP_CAPABILITIES_GET: + return bt_mesh_dfd_cli_distribution_capabilities_get(¶m); + case ESP_BLE_MESH_DFD_OP_GET: + return bt_mesh_dfd_cli_distribution_get(¶m); + case ESP_BLE_MESH_DFD_OP_UPLOAD_GET: + return bt_mesh_dfd_cli_distribution_upload_get(¶m); + case ESP_BLE_MESH_DFD_OP_FW_GET: + return bt_mesh_dfd_cli_firmware_get(¶m, get->dist_fw_get.fwid); + case ESP_BLE_MESH_DFD_OP_FW_GET_BY_INDEX: + return bt_mesh_dfd_cli_firmware_get_by_index(¶m, get->dist_fw_get_by_idx.dist_fw_idx); + default: + BT_ERR("UknOpc:%04x", params->opcode); + return -EINVAL; } } @@ -549,31 +551,31 @@ static int btc_ble_mesh_dfd_client_set(esp_ble_mesh_client_common_param_t *param btc_ble_mesh_set_client_common_param(params, ¶m, false); switch (params->opcode) { - case ESP_BLE_MESH_DFD_OP_RECEIVERS_ADD: - return bt_mesh_dfd_cli_receivers_add(¶m, (dfd_cli_receiver_entry_t *)set->receivers_add.receivers, set->receivers_add.receivers_cnt); - case ESP_BLE_MESH_DFD_OP_RECEIVERS_DELETE_ALL: - return bt_mesh_dfd_cli_receivers_delete_all(¶m); - case ESP_BLE_MESH_DFD_OP_START: - return bt_mesh_dfd_cli_distribution_start(¶m, (dfd_cli_dist_start_t *)&set->dist_start); - case ESP_BLE_MESH_DFD_OP_SUSPEND: - return bt_mesh_dfd_cli_distribution_suspend(¶m); - case ESP_BLE_MESH_DFD_OP_CANCEL: - return bt_mesh_dfd_cli_distribution_cancel(¶m); - case ESP_BLE_MESH_DFD_OP_APPLY: - return bt_mesh_dfd_cli_distribution_apply(¶m); - case ESP_BLE_MESH_DFD_OP_UPLOAD_START: - return bt_mesh_dfd_cli_distribution_upload_start(¶m, (dfd_cli_dist_upload_start_t *)&set->dist_upload_start); - case ESP_BLE_MESH_DFD_OP_UPLOAD_START_OOB: - return bt_mesh_dfd_cli_distribution_upload_oob_start(¶m, (dfd_cli_dist_upload_oob_start_t *)&set->dist_upload_oob_start); - case ESP_BLE_MESH_DFD_OP_UPLOAD_CANCEL: - return bt_mesh_dfd_cli_distribution_upload_oob_cancel(¶m); - case ESP_BLE_MESH_DFD_OP_FW_DELETE: - return bt_mesh_dfd_cli_firmware_get_delete(¶m, set->dist_fw_del.fwid); - case ESP_BLE_MESH_DFD_OP_FW_DELETE_ALL: - return bt_mesh_dfd_cli_firmware_delete_all(¶m); - default: - BT_ERR("UknOpc:%04x", params->opcode); - return -EINVAL; + case ESP_BLE_MESH_DFD_OP_RECEIVERS_ADD: + return bt_mesh_dfd_cli_receivers_add(¶m, (dfd_cli_receiver_entry_t *)set->receivers_add.receivers, set->receivers_add.receivers_cnt); + case ESP_BLE_MESH_DFD_OP_RECEIVERS_DELETE_ALL: + return bt_mesh_dfd_cli_receivers_delete_all(¶m); + case ESP_BLE_MESH_DFD_OP_START: + return bt_mesh_dfd_cli_distribution_start(¶m, (dfd_cli_dist_start_t *)&set->dist_start); + case ESP_BLE_MESH_DFD_OP_SUSPEND: + return bt_mesh_dfd_cli_distribution_suspend(¶m); + case ESP_BLE_MESH_DFD_OP_CANCEL: + return bt_mesh_dfd_cli_distribution_cancel(¶m); + case ESP_BLE_MESH_DFD_OP_APPLY: + return bt_mesh_dfd_cli_distribution_apply(¶m); + case ESP_BLE_MESH_DFD_OP_UPLOAD_START: + return bt_mesh_dfd_cli_distribution_upload_start(¶m, (dfd_cli_dist_upload_start_t *)&set->dist_upload_start); + case ESP_BLE_MESH_DFD_OP_UPLOAD_START_OOB: + return bt_mesh_dfd_cli_distribution_upload_oob_start(¶m, (dfd_cli_dist_upload_oob_start_t *)&set->dist_upload_oob_start); + case ESP_BLE_MESH_DFD_OP_UPLOAD_CANCEL: + return bt_mesh_dfd_cli_distribution_upload_oob_cancel(¶m); + case ESP_BLE_MESH_DFD_OP_FW_DELETE: + return bt_mesh_dfd_cli_firmware_get_delete(¶m, set->dist_fw_del.fwid); + case ESP_BLE_MESH_DFD_OP_FW_DELETE_ALL: + return bt_mesh_dfd_cli_firmware_delete_all(¶m); + default: + BT_ERR("UknOpc:%04x", params->opcode); + return -EINVAL; } } @@ -633,34 +635,34 @@ void btc_ble_mesh_dfd_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void *p } switch (dst->dfd_client_get.params->opcode) { - case ESP_BLE_MESH_DFD_OP_FW_GET: - if (src->dfd_client_get.get->dist_fw_get.fwid == NULL) { - BT_ERR("%s:%d,InvParam", __func__, __LINE__); - /* Free the previously allocated resources */ - bt_mesh_free(dst->dfd_client_get.params); - dst->dfd_client_get.params = NULL; - bt_mesh_free(dst->dfd_client_get.get); - dst->dfd_client_get.get = NULL; - break; - } + case ESP_BLE_MESH_DFD_OP_FW_GET: + if (src->dfd_client_get.get->dist_fw_get.fwid == NULL) { + BT_ERR("%s:%d,InvParam", __func__, __LINE__); + /* Free the previously allocated resources */ + bt_mesh_free(dst->dfd_client_get.params); + dst->dfd_client_get.params = NULL; + bt_mesh_free(dst->dfd_client_get.get); + dst->dfd_client_get.get = NULL; + break; + } - dst->dfd_client_get.get->dist_fw_get.fwid = - bt_mesh_alloc_buf(src->dfd_client_get.get->dist_fw_get.fwid->len); - if (dst->dfd_client_get.get->dist_fw_get.fwid == NULL) { - BT_ERR("%s:%d,OutMem", __func__, __LINE__); - /* Free the previously allocated resources */ - bt_mesh_free(dst->dfd_client_get.params); - dst->dfd_client_get.params = NULL; - bt_mesh_free(dst->dfd_client_get.get); - dst->dfd_client_get.get = NULL; - break; - } - net_buf_simple_add_mem(dst->dfd_client_get.get->dist_fw_get.fwid, - src->dfd_client_get.get->dist_fw_get.fwid->data, - src->dfd_client_get.get->dist_fw_get.fwid->len); - break; - default: + dst->dfd_client_get.get->dist_fw_get.fwid = + bt_mesh_alloc_buf(src->dfd_client_get.get->dist_fw_get.fwid->len); + if (dst->dfd_client_get.get->dist_fw_get.fwid == NULL) { + BT_ERR("%s:%d,OutMem", __func__, __LINE__); + /* Free the previously allocated resources */ + bt_mesh_free(dst->dfd_client_get.params); + dst->dfd_client_get.params = NULL; + bt_mesh_free(dst->dfd_client_get.get); + dst->dfd_client_get.get = NULL; break; + } + net_buf_simple_add_mem(dst->dfd_client_get.get->dist_fw_get.fwid, + src->dfd_client_get.get->dist_fw_get.fwid->data, + src->dfd_client_get.get->dist_fw_get.fwid->len); + break; + default: + break; } break; case BTC_BLE_MESH_ACT_DFD_CLIENT_SET: @@ -687,150 +689,150 @@ void btc_ble_mesh_dfd_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void *p memcpy(dst->dfd_client_set.set, src->dfd_client_set.set, sizeof(esp_ble_mesh_dfd_client_set_param_t)); } switch (dst->dfd_client_set.params->opcode) { - case ESP_BLE_MESH_DFD_OP_RECEIVERS_ADD: - if (src->dfd_client_set.set->receivers_add.receivers_cnt == 0) { - dst->dfd_client_set.set->receivers_add.receivers = NULL; - BT_ERR("%s:%d,InvParam", __func__, __LINE__); - /* Free the previously allocated resources */ - bt_mesh_free(dst->dfd_client_set.params); - dst->dfd_client_set.params = NULL; - bt_mesh_free(dst->dfd_client_set.set); - dst->dfd_client_set.set = NULL; - break; - } - dst->dfd_client_set.set->receivers_add.receivers = - (esp_ble_mesh_dfd_cli_receiver_entry_t *)bt_mesh_calloc(dst->dfd_client_set.set->receivers_add.receivers_cnt * - sizeof(esp_ble_mesh_dfd_cli_receiver_entry_t)); - if (dst->dfd_client_set.set->receivers_add.receivers == NULL) { + case ESP_BLE_MESH_DFD_OP_RECEIVERS_ADD: + if (src->dfd_client_set.set->receivers_add.receivers_cnt == 0) { + dst->dfd_client_set.set->receivers_add.receivers = NULL; + BT_ERR("%s:%d,InvParam", __func__, __LINE__); + /* Free the previously allocated resources */ + bt_mesh_free(dst->dfd_client_set.params); + dst->dfd_client_set.params = NULL; + bt_mesh_free(dst->dfd_client_set.set); + dst->dfd_client_set.set = NULL; + break; + } + dst->dfd_client_set.set->receivers_add.receivers = + (esp_ble_mesh_dfd_cli_receiver_entry_t *)bt_mesh_calloc(dst->dfd_client_set.set->receivers_add.receivers_cnt * + sizeof(esp_ble_mesh_dfd_cli_receiver_entry_t)); + if (dst->dfd_client_set.set->receivers_add.receivers == NULL) { + BT_ERR("%s:%d,OutMem", __func__, __LINE__); + /* Free the previously allocated resources */ + bt_mesh_free(dst->dfd_client_set.params); + dst->dfd_client_set.params = NULL; + bt_mesh_free(dst->dfd_client_set.set); + dst->dfd_client_set.set = NULL; + break; + } + memcpy(dst->dfd_client_set.set->receivers_add.receivers, src->dfd_client_set.set->receivers_add.receivers, + dst->dfd_client_set.set->receivers_add.receivers_cnt * sizeof(esp_ble_mesh_dfd_cli_receiver_entry_t)); + break; + case ESP_BLE_MESH_DFD_OP_UPLOAD_START: + if (src->dfd_client_set.set->dist_upload_start.fwid == NULL) { + dst->dfd_client_set.set->dist_upload_start.fwid = NULL; + BT_ERR("%s:%d,InvParam", __func__, __LINE__); + /* Free the previously allocated resources */ + bt_mesh_free(dst->dfd_client_set.params); + dst->dfd_client_set.params = NULL; + bt_mesh_free(dst->dfd_client_set.set); + dst->dfd_client_set.set = NULL; + break; + } + + dst->dfd_client_set.set->dist_upload_start.fwid = + bt_mesh_alloc_buf(src->dfd_client_set.set->dist_upload_start.fwid->len); + if (dst->dfd_client_set.set->dist_upload_start.fwid == NULL) { + BT_ERR("%s:%d,OutMem", __func__, __LINE__); + /* Free the previously allocated resources */ + bt_mesh_free(dst->dfd_client_set.params); + dst->dfd_client_set.params = NULL; + bt_mesh_free(dst->dfd_client_set.set); + dst->dfd_client_set.set = NULL; + break; + } + net_buf_simple_add_mem(dst->dfd_client_set.set->dist_upload_start.fwid, + src->dfd_client_set.set->dist_upload_start.fwid->data, + src->dfd_client_set.set->dist_upload_start.fwid->len); + + if (src->dfd_client_set.set->dist_upload_start.fw_metadata->len == 0) { + dst->dfd_client_set.set->dist_upload_start.fw_metadata = NULL; + break; + } else { + dst->dfd_client_set.set->dist_upload_start.fw_metadata = + bt_mesh_alloc_buf(src->dfd_client_set.set->dist_upload_start.fw_metadata->len); + if (dst->dfd_client_set.set->dist_upload_start.fw_metadata == NULL) { BT_ERR("%s:%d,OutMem", __func__, __LINE__); /* Free the previously allocated resources */ - bt_mesh_free(dst->dfd_client_set.params); - dst->dfd_client_set.params = NULL; - bt_mesh_free(dst->dfd_client_set.set); - dst->dfd_client_set.set = NULL; - break; - } - memcpy(dst->dfd_client_set.set->receivers_add.receivers, src->dfd_client_set.set->receivers_add.receivers, - dst->dfd_client_set.set->receivers_add.receivers_cnt * sizeof(esp_ble_mesh_dfd_cli_receiver_entry_t)); - break; - case ESP_BLE_MESH_DFD_OP_UPLOAD_START: - if (src->dfd_client_set.set->dist_upload_start.fwid == NULL) { + bt_mesh_free_buf(dst->dfd_client_set.set->dist_upload_start.fwid); dst->dfd_client_set.set->dist_upload_start.fwid = NULL; - BT_ERR("%s:%d,InvParam", __func__, __LINE__); - /* Free the previously allocated resources */ bt_mesh_free(dst->dfd_client_set.params); dst->dfd_client_set.params = NULL; bt_mesh_free(dst->dfd_client_set.set); dst->dfd_client_set.set = NULL; break; } - - dst->dfd_client_set.set->dist_upload_start.fwid = - bt_mesh_alloc_buf(src->dfd_client_set.set->dist_upload_start.fwid->len); - if (dst->dfd_client_set.set->dist_upload_start.fwid == NULL) { - BT_ERR("%s:%d,OutMem", __func__, __LINE__); - /* Free the previously allocated resources */ - bt_mesh_free(dst->dfd_client_set.params); - dst->dfd_client_set.params = NULL; - bt_mesh_free(dst->dfd_client_set.set); - dst->dfd_client_set.set = NULL; - break; - } - net_buf_simple_add_mem(dst->dfd_client_set.set->dist_upload_start.fwid, - src->dfd_client_set.set->dist_upload_start.fwid->data, - src->dfd_client_set.set->dist_upload_start.fwid->len); - - if (src->dfd_client_set.set->dist_upload_start.fw_metadata->len == 0) { - dst->dfd_client_set.set->dist_upload_start.fw_metadata = NULL; - break; - } else { - dst->dfd_client_set.set->dist_upload_start.fw_metadata = - bt_mesh_alloc_buf(src->dfd_client_set.set->dist_upload_start.fw_metadata->len); - if (dst->dfd_client_set.set->dist_upload_start.fw_metadata == NULL) { - BT_ERR("%s:%d,OutMem", __func__, __LINE__); - /* Free the previously allocated resources */ - bt_mesh_free_buf(dst->dfd_client_set.set->dist_upload_start.fwid); - dst->dfd_client_set.set->dist_upload_start.fwid = NULL; - bt_mesh_free(dst->dfd_client_set.params); - dst->dfd_client_set.params = NULL; - bt_mesh_free(dst->dfd_client_set.set); - dst->dfd_client_set.set = NULL; - break; - } - net_buf_simple_add_mem(dst->dfd_client_set.set->dist_upload_start.fw_metadata, - src->dfd_client_set.set->dist_upload_start.fw_metadata->data, - src->dfd_client_set.set->dist_upload_start.fw_metadata->len); - } - break; - case ESP_BLE_MESH_DFD_OP_UPLOAD_START_OOB: - if (src->dfd_client_set.set->dist_upload_oob_start.url == NULL || + net_buf_simple_add_mem(dst->dfd_client_set.set->dist_upload_start.fw_metadata, + src->dfd_client_set.set->dist_upload_start.fw_metadata->data, + src->dfd_client_set.set->dist_upload_start.fw_metadata->len); + } + break; + case ESP_BLE_MESH_DFD_OP_UPLOAD_START_OOB: + if (src->dfd_client_set.set->dist_upload_oob_start.url == NULL || src->dfd_client_set.set->dist_upload_oob_start.fwid == NULL) { - BT_ERR("%s:%d,InvParam", __func__, __LINE__); - /* Free the previously allocated resources */ - bt_mesh_free(dst->dfd_client_set.params); - dst->dfd_client_set.params = NULL; - bt_mesh_free(dst->dfd_client_set.set); - dst->dfd_client_set.set = NULL; - break; - } - dst->dfd_client_set.set->dist_upload_oob_start.url = - bt_mesh_alloc_buf(src->dfd_client_set.set->dist_upload_oob_start.url->len); - if (dst->dfd_client_set.set->dist_upload_oob_start.url == NULL) { - BT_ERR("%s:%d,OutMem", __func__, __LINE__); - /* Free the previously allocated resources */ - bt_mesh_free(dst->dfd_client_set.params); - dst->dfd_client_set.params = NULL; - bt_mesh_free(dst->dfd_client_set.set); - dst->dfd_client_set.set = NULL; - break; - } - dst->dfd_client_set.set->dist_upload_oob_start.fwid = - bt_mesh_alloc_buf(src->dfd_client_set.set->dist_upload_oob_start.fwid->len); - if (dst->dfd_client_set.set->dist_upload_oob_start.fwid == NULL) { - BT_ERR("%s:%d,OutMem", __func__, __LINE__); - /* Free the previously allocated resources */ - bt_mesh_free_buf(dst->dfd_client_set.set->dist_upload_oob_start.url); - dst->dfd_client_set.set->dist_upload_oob_start.url = NULL; - bt_mesh_free(dst->dfd_client_set.params); - dst->dfd_client_set.params = NULL; - bt_mesh_free(dst->dfd_client_set.set); - dst->dfd_client_set.set = NULL; - break; - } - net_buf_simple_add_mem(dst->dfd_client_set.set->dist_upload_oob_start.url, - src->dfd_client_set.set->dist_upload_oob_start.url->data, - src->dfd_client_set.set->dist_upload_oob_start.url->len); - net_buf_simple_add_mem(dst->dfd_client_set.set->dist_upload_oob_start.fwid, - src->dfd_client_set.set->dist_upload_oob_start.fwid->data, - src->dfd_client_set.set->dist_upload_oob_start.fwid->len); + BT_ERR("%s:%d,InvParam", __func__, __LINE__); + /* Free the previously allocated resources */ + bt_mesh_free(dst->dfd_client_set.params); + dst->dfd_client_set.params = NULL; + bt_mesh_free(dst->dfd_client_set.set); + dst->dfd_client_set.set = NULL; break; - case ESP_BLE_MESH_DFD_OP_FW_DELETE: - if (src->dfd_client_set.set->dist_fw_del.fwid == NULL) { - BT_ERR("%s:%d,InvParam", __func__, __LINE__); - /* Free the previously allocated resources */ - bt_mesh_free(dst->dfd_client_set.params); - dst->dfd_client_set.params = NULL; - bt_mesh_free(dst->dfd_client_set.set); - dst->dfd_client_set.set = NULL; - break; - } - dst->dfd_client_set.set->dist_fw_del.fwid = - bt_mesh_alloc_buf(src->dfd_client_set.set->dist_fw_del.fwid->len); - if (dst->dfd_client_set.set->dist_fw_del.fwid == NULL) { - BT_ERR("%s:%d,OutMem", __func__, __LINE__); - /* Free the previously allocated resources */ - bt_mesh_free(dst->dfd_client_set.params); - dst->dfd_client_set.params = NULL; - bt_mesh_free(dst->dfd_client_set.set); - dst->dfd_client_set.set = NULL; - break; - } - net_buf_simple_add_mem(dst->dfd_client_set.set->dist_fw_del.fwid, - src->dfd_client_set.set->dist_fw_del.fwid->data, - src->dfd_client_set.set->dist_fw_del.fwid->len); + } + dst->dfd_client_set.set->dist_upload_oob_start.url = + bt_mesh_alloc_buf(src->dfd_client_set.set->dist_upload_oob_start.url->len); + if (dst->dfd_client_set.set->dist_upload_oob_start.url == NULL) { + BT_ERR("%s:%d,OutMem", __func__, __LINE__); + /* Free the previously allocated resources */ + bt_mesh_free(dst->dfd_client_set.params); + dst->dfd_client_set.params = NULL; + bt_mesh_free(dst->dfd_client_set.set); + dst->dfd_client_set.set = NULL; break; - default: + } + dst->dfd_client_set.set->dist_upload_oob_start.fwid = + bt_mesh_alloc_buf(src->dfd_client_set.set->dist_upload_oob_start.fwid->len); + if (dst->dfd_client_set.set->dist_upload_oob_start.fwid == NULL) { + BT_ERR("%s:%d,OutMem", __func__, __LINE__); + /* Free the previously allocated resources */ + bt_mesh_free_buf(dst->dfd_client_set.set->dist_upload_oob_start.url); + dst->dfd_client_set.set->dist_upload_oob_start.url = NULL; + bt_mesh_free(dst->dfd_client_set.params); + dst->dfd_client_set.params = NULL; + bt_mesh_free(dst->dfd_client_set.set); + dst->dfd_client_set.set = NULL; break; + } + net_buf_simple_add_mem(dst->dfd_client_set.set->dist_upload_oob_start.url, + src->dfd_client_set.set->dist_upload_oob_start.url->data, + src->dfd_client_set.set->dist_upload_oob_start.url->len); + net_buf_simple_add_mem(dst->dfd_client_set.set->dist_upload_oob_start.fwid, + src->dfd_client_set.set->dist_upload_oob_start.fwid->data, + src->dfd_client_set.set->dist_upload_oob_start.fwid->len); + break; + case ESP_BLE_MESH_DFD_OP_FW_DELETE: + if (src->dfd_client_set.set->dist_fw_del.fwid == NULL) { + BT_ERR("%s:%d,InvParam", __func__, __LINE__); + /* Free the previously allocated resources */ + bt_mesh_free(dst->dfd_client_set.params); + dst->dfd_client_set.params = NULL; + bt_mesh_free(dst->dfd_client_set.set); + dst->dfd_client_set.set = NULL; + break; + } + dst->dfd_client_set.set->dist_fw_del.fwid = + bt_mesh_alloc_buf(src->dfd_client_set.set->dist_fw_del.fwid->len); + if (dst->dfd_client_set.set->dist_fw_del.fwid == NULL) { + BT_ERR("%s:%d,OutMem", __func__, __LINE__); + /* Free the previously allocated resources */ + bt_mesh_free(dst->dfd_client_set.params); + dst->dfd_client_set.params = NULL; + bt_mesh_free(dst->dfd_client_set.set); + dst->dfd_client_set.set = NULL; + break; + } + net_buf_simple_add_mem(dst->dfd_client_set.set->dist_fw_del.fwid, + src->dfd_client_set.set->dist_fw_del.fwid->data, + src->dfd_client_set.set->dist_fw_del.fwid->len); + break; + default: + break; } default: BT_DBG("%s, Unknown act %d", __func__, msg->act); @@ -861,66 +863,66 @@ void btc_ble_mesh_dfd_client_arg_deep_free(btc_msg_t *msg) break; } switch (arg->dfd_client_get.params->opcode) { - case ESP_BLE_MESH_DFD_OP_FW_GET: - if (arg->dfd_client_get.get->dist_fw_get.fwid == NULL) { - BT_ERR("%s:%d,InvParam", __func__, __LINE__); - break; - } - bt_mesh_free_buf(arg->dfd_client_get.get->dist_fw_get.fwid); + case ESP_BLE_MESH_DFD_OP_FW_GET: + if (arg->dfd_client_get.get->dist_fw_get.fwid == NULL) { + BT_ERR("%s:%d,InvParam", __func__, __LINE__); + break; + } + bt_mesh_free_buf(arg->dfd_client_get.get->dist_fw_get.fwid); break; - default: + default: break; } if (arg->dfd_client_get.get) { bt_mesh_free(arg->dfd_client_get.get); } bt_mesh_free(arg->dfd_client_get.params); - break; + break; case ESP_BLE_MESH_ACT_DFD_CLIENT_SET: if (arg->dfd_client_set.params == NULL) { BT_ERR("%s:%d,InvParam", __func__, __LINE__); break; } switch (arg->dfd_client_set.params->opcode) { - case ESP_BLE_MESH_DFD_OP_RECEIVERS_ADD: - if (arg->dfd_client_set.set->receivers_add.receivers == NULL) { - BT_ERR("%s:%d,InvParam", __func__, __LINE__); - break; - } - bt_mesh_free(arg->dfd_client_set.set->receivers_add.receivers); + case ESP_BLE_MESH_DFD_OP_RECEIVERS_ADD: + if (arg->dfd_client_set.set->receivers_add.receivers == NULL) { + BT_ERR("%s:%d,InvParam", __func__, __LINE__); + break; + } + bt_mesh_free(arg->dfd_client_set.set->receivers_add.receivers); break; - case ESP_BLE_MESH_DFD_OP_UPLOAD_START: - if (arg->dfd_client_set.set->dist_upload_start.fwid == NULL) { - BT_ERR("%s:%d,InvParam", __func__, __LINE__); - break; - } - bt_mesh_free_buf(arg->dfd_client_set.set->dist_upload_start.fwid); - if (arg->dfd_client_set.set->dist_upload_start.fw_metadata) { - bt_mesh_free_buf(arg->dfd_client_set.set->dist_upload_start.fw_metadata); - } + case ESP_BLE_MESH_DFD_OP_UPLOAD_START: + if (arg->dfd_client_set.set->dist_upload_start.fwid == NULL) { + BT_ERR("%s:%d,InvParam", __func__, __LINE__); + break; + } + bt_mesh_free_buf(arg->dfd_client_set.set->dist_upload_start.fwid); + if (arg->dfd_client_set.set->dist_upload_start.fw_metadata) { + bt_mesh_free_buf(arg->dfd_client_set.set->dist_upload_start.fw_metadata); + } break; - case ESP_BLE_MESH_DFD_OP_UPLOAD_START_OOB: - if (arg->dfd_client_set.set->dist_upload_oob_start.url == NULL || + case ESP_BLE_MESH_DFD_OP_UPLOAD_START_OOB: + if (arg->dfd_client_set.set->dist_upload_oob_start.url == NULL || arg->dfd_client_set.set->dist_upload_oob_start.fwid == NULL) { - BT_ERR("%s:%d,InvParam", __func__, __LINE__); - break; - } - bt_mesh_free_buf(arg->dfd_client_set.set->dist_upload_oob_start.url); - bt_mesh_free_buf(arg->dfd_client_set.set->dist_upload_oob_start.fwid); + BT_ERR("%s:%d,InvParam", __func__, __LINE__); + break; + } + bt_mesh_free_buf(arg->dfd_client_set.set->dist_upload_oob_start.url); + bt_mesh_free_buf(arg->dfd_client_set.set->dist_upload_oob_start.fwid); break; - case ESP_BLE_MESH_DFD_OP_FW_DELETE: - if (arg->dfd_client_set.set->dist_fw_del.fwid == NULL) { - BT_ERR("%s:%d,InvParam", __func__, __LINE__); - break; - } - bt_mesh_free_buf(arg->dfd_client_set.set->dist_fw_del.fwid); + case ESP_BLE_MESH_DFD_OP_FW_DELETE: + if (arg->dfd_client_set.set->dist_fw_del.fwid == NULL) { + BT_ERR("%s:%d,InvParam", __func__, __LINE__); + break; + } + bt_mesh_free_buf(arg->dfd_client_set.set->dist_fw_del.fwid); break; } if (arg->dfd_client_set.set) { bt_mesh_free(arg->dfd_client_set.set); } bt_mesh_free(arg->dfd_client_set.params); - break; + break; default: BT_WARN("Unprocessed event %d", msg->act); break; @@ -931,8 +933,8 @@ void btc_ble_mesh_dfd_client_arg_deep_free(btc_msg_t *msg) void btc_ble_mesh_dfd_client_rsp_deep_copy(btc_msg_t *msg, void *p_dest, void *p_src) { - esp_ble_mesh_dfd_client_cb_param_t *dst =(esp_ble_mesh_dfd_client_cb_param_t *) p_dest; - esp_ble_mesh_dfd_client_cb_param_t *src =(esp_ble_mesh_dfd_client_cb_param_t *) p_src; + esp_ble_mesh_dfd_client_cb_param_t *dst = (esp_ble_mesh_dfd_client_cb_param_t *) p_dest; + esp_ble_mesh_dfd_client_cb_param_t *src = (esp_ble_mesh_dfd_client_cb_param_t *) p_src; if (!msg || !dst || !src) { BT_ERR("%s, Invalid parameter", __func__); @@ -953,7 +955,7 @@ void btc_ble_mesh_dfd_client_rsp_deep_copy(btc_msg_t *msg, void *p_dest, void *p switch (msg->act) { case ESP_BLE_MESH_EVT_DFD_CLIENT_RECV_RSP: if (src->params) { - switch(src->params->opcode) { + switch (src->params->opcode) { case BLE_MESH_DFD_OP_RECEIVERS_LIST: dst->status_cb.receiver_list.first_index = src->status_cb.receiver_list.first_index; dst->status_cb.receiver_list.entries_cnt = src->status_cb.receiver_list.entries_cnt; @@ -981,7 +983,7 @@ void btc_ble_mesh_dfd_client_rsp_deep_copy(btc_msg_t *msg, void *p_dest, void *p dst->status_cb.dist_caps.oob_retrieval_supported = src->status_cb.dist_caps.oob_retrieval_supported; if (src->status_cb.dist_caps.supported_url_scheme_names) { dst->status_cb.dist_caps.supported_url_scheme_names = - bt_mesh_alloc_buf(src->status_cb.dist_caps.supported_url_scheme_names->len); + bt_mesh_alloc_buf(src->status_cb.dist_caps.supported_url_scheme_names->len); if (dst->status_cb.dist_caps.supported_url_scheme_names == NULL) { BT_ERR("%s:%d,OutOfMem", __func__, __LINE__); /* Free the previously allocated resources */ @@ -1024,7 +1026,7 @@ void btc_ble_mesh_dfd_client_rsp_deep_copy(btc_msg_t *msg, void *p_dest, void *p BT_ERR("%s:%d,InvParam", __func__, __LINE__); } } else { - if(src->status_cb.upload_status.oob_fwid) { + if (src->status_cb.upload_status.oob_fwid) { dst->status_cb.upload_status.oob_fwid = bt_mesh_alloc_buf(src->status_cb.upload_status.oob_fwid->len); if (dst->status_cb.upload_status.oob_fwid == NULL) { BT_ERR("%s:%d,OutOfMem", __func__, __LINE__); @@ -1104,45 +1106,45 @@ void btc_ble_mesh_dfd_client_rsp_deep_free(btc_msg_t *msg) arg = (esp_ble_mesh_dfd_client_cb_param_t *)(msg->arg); if (arg->params == NULL && - msg->act != ESP_BLE_MESH_ACT_DFD_CLIEND_SEND_COMP) { + msg->act != ESP_BLE_MESH_ACT_DFD_CLIEND_SEND_COMP) { BT_ERR("%s:%d,InvParam", __func__, __LINE__); return; } switch (msg->act) { - case ESP_BLE_MESH_EVT_DFD_CLIENT_RECV_RSP: - switch (arg->params->opcode) { - case BLE_MESH_DFD_OP_RECEIVERS_LIST: - if (arg->status_cb.receiver_list.entries) { - bt_mesh_free(arg->status_cb.receiver_list.entries); - arg->status_cb.receiver_list.entries = NULL; - } - break; - case BLE_MESH_DFD_OP_CAPABILITIES_STATUS: - if (arg->status_cb.dist_caps.supported_url_scheme_names) { - bt_mesh_free_buf(arg->status_cb.dist_caps.supported_url_scheme_names); - arg->status_cb.dist_caps.supported_url_scheme_names = NULL; - } - break; - case BLE_MESH_DFD_OP_UPLOAD_STATUS: - /** - * firmware_id and upload_oob_firmware_id are a union - * structure, so only one pointer needs to be released - */ - if (arg->status_cb.upload_status.fwid) { - bt_mesh_free_buf(arg->status_cb.upload_status.fwid); - arg->status_cb.upload_status.fwid = NULL; - } - break; - case BLE_MESH_DFD_OP_FW_STATUS: - if (arg->status_cb.firmware_status.fwid) { - bt_mesh_free_buf(arg->status_cb.firmware_status.fwid); - arg->status_cb.firmware_status.fwid = NULL; - } - break; + case ESP_BLE_MESH_EVT_DFD_CLIENT_RECV_RSP: + switch (arg->params->opcode) { + case BLE_MESH_DFD_OP_RECEIVERS_LIST: + if (arg->status_cb.receiver_list.entries) { + bt_mesh_free(arg->status_cb.receiver_list.entries); + arg->status_cb.receiver_list.entries = NULL; } + break; + case BLE_MESH_DFD_OP_CAPABILITIES_STATUS: + if (arg->status_cb.dist_caps.supported_url_scheme_names) { + bt_mesh_free_buf(arg->status_cb.dist_caps.supported_url_scheme_names); + arg->status_cb.dist_caps.supported_url_scheme_names = NULL; + } + break; + case BLE_MESH_DFD_OP_UPLOAD_STATUS: + /** + * firmware_id and upload_oob_firmware_id are a union + * structure, so only one pointer needs to be released + */ + if (arg->status_cb.upload_status.fwid) { + bt_mesh_free_buf(arg->status_cb.upload_status.fwid); + arg->status_cb.upload_status.fwid = NULL; + } + break; + case BLE_MESH_DFD_OP_FW_STATUS: + if (arg->status_cb.firmware_status.fwid) { + bt_mesh_free_buf(arg->status_cb.firmware_status.fwid); + arg->status_cb.firmware_status.fwid = NULL; + } + break; + } break; - default: + default: break; } @@ -1184,14 +1186,14 @@ void bt_mesh_dfd_client_cb_evt_to_btc(btc_ble_mesh_dfd_client_cb_evt_t event, } switch (event) { - case BTC_BLE_MESH_EVT_DFD_CLIENT_RECV_RSP: - act = ESP_BLE_MESH_EVT_DFD_CLIENT_RECV_RSP; + case BTC_BLE_MESH_EVT_DFD_CLIENT_RECV_RSP: + act = ESP_BLE_MESH_EVT_DFD_CLIENT_RECV_RSP; break; - case BTC_BLE_MESH_EVT_DFD_CLIENT_TIMEOUT: - act = ESP_BLE_MESH_EVT_DFD_CLIENT_TIMEOUT; + case BTC_BLE_MESH_EVT_DFD_CLIENT_TIMEOUT: + act = ESP_BLE_MESH_EVT_DFD_CLIENT_TIMEOUT; break; - default: - BT_ERR("Unknown event %d", event); + default: + BT_ERR("Unknown event %d", event); break; } @@ -1251,8 +1253,8 @@ int btc_ble_mesh_dfd_srv_oob_check_complete(struct esp_ble_mesh_dfd_srv *srv, return 0; } int btc_ble_mesh_dfd_srv_oob_store_complete(struct esp_ble_mesh_dfd_srv *srv, - const struct esp_ble_mesh_dfu_slot *slot, bool success, - size_t size, const uint8_t *metadata, size_t metadata_len) + const struct esp_ble_mesh_dfu_slot *slot, bool success, + size_t size, const uint8_t *metadata, size_t metadata_len) { bt_mesh_dfd_srv_oob_store_complete((struct bt_mesh_dfd_srv *)srv, (struct bt_mesh_dfu_slot *)slot, success, size, metadata, metadata_len); return 0; diff --git a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_lcd_model.c b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_lcd_model.c index 600ed023174..feae6f27594 100644 --- a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_lcd_model.c +++ b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_lcd_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2023 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -157,6 +157,7 @@ static void btc_ble_mesh_lcd_client_copy_req_data(btc_msg_t *msg, void *p_dest, break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_LCD_CLIENT_SEND_COMP_EVT: case ESP_BLE_MESH_LCD_CLIENT_SEND_TIMEOUT_EVT: break; @@ -193,6 +194,7 @@ static void btc_ble_mesh_lcd_client_free_req_data(btc_msg_t *msg) break; } } + __attribute__((fallthrough)); case ESP_BLE_MESH_LCD_CLIENT_SEND_COMP_EVT: case ESP_BLE_MESH_LCD_CLIENT_SEND_TIMEOUT_EVT: if (arg->params) { @@ -282,8 +284,8 @@ void btc_ble_mesh_lcd_client_recv_pub_cb(uint32_t opcode, } bt_mesh_lcd_client_cb_evt_to_btc(opcode, - BTC_BLE_MESH_EVT_LCD_CLIENT_RECV_PUB, - model, ctx, buf->data, buf->len); + BTC_BLE_MESH_EVT_LCD_CLIENT_RECV_PUB, + model, ctx, buf->data, buf->len); } static int btc_ble_mesh_lcd_client_send(esp_ble_mesh_client_common_param_t *params, @@ -374,7 +376,7 @@ static inline void btc_ble_mesh_lcd_server_cb_to_app(esp_ble_mesh_lcd_server_cb_ } static void btc_ble_mesh_lcd_server_cb( - esp_ble_mesh_lcd_server_cb_param_t *cb_params, uint8_t act) + esp_ble_mesh_lcd_server_cb_param_t *cb_params, uint8_t act) { btc_msg_t msg = {0}; diff --git a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_mbt_model.c b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_mbt_model.c index 430bd31eeee..ed5ced368e3 100644 --- a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_mbt_model.c +++ b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_mbt_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2023 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -146,7 +146,7 @@ static void btc_ble_mesh_blob_trans_client_copy_req_data(btc_msg_t *msg, void *p switch (msg->act) { case BTC_BLE_MESH_ACT_MBT_CLIENT_RETRIEVE_CAPABILITIES: if (src->value.retrieve_capabilities_status.input.unicast_addr_count && - src->value.retrieve_capabilities_status.input.unicast_addr) { + src->value.retrieve_capabilities_status.input.unicast_addr) { dst->value.retrieve_capabilities_status.input.unicast_addr = bt_mesh_calloc(src->value.retrieve_capabilities_status.input.unicast_addr_count * 2); if (dst->value.retrieve_capabilities_status.input.unicast_addr) { memcpy(dst->value.retrieve_capabilities_status.input.unicast_addr, src->value.retrieve_capabilities_status.input.unicast_addr, @@ -159,7 +159,7 @@ static void btc_ble_mesh_blob_trans_client_copy_req_data(btc_msg_t *msg, void *p break; case BTC_BLE_MESH_ACT_MBT_CLIENT_TRANSFER_BLOB: if (src->value.transfer_blob_status.input.unicast_addr_count && - src->value.transfer_blob_status.input.unicast_addr) { + src->value.transfer_blob_status.input.unicast_addr) { dst->value.transfer_blob_status.input.unicast_addr = bt_mesh_calloc(src->value.transfer_blob_status.input.unicast_addr_count * 2); if (dst->value.transfer_blob_status.input.unicast_addr) { memcpy(dst->value.transfer_blob_status.input.unicast_addr, src->value.transfer_blob_status.input.unicast_addr, @@ -172,7 +172,7 @@ static void btc_ble_mesh_blob_trans_client_copy_req_data(btc_msg_t *msg, void *p break; case BTC_BLE_MESH_ACT_MBT_CLIENT_DETERMINE_TRANSFER_STATUS: if (src->value.determine_transfer_status_status.input.unicast_addr_count && - src->value.determine_transfer_status_status.input.unicast_addr) { + src->value.determine_transfer_status_status.input.unicast_addr) { dst->value.determine_transfer_status_status.input.unicast_addr = bt_mesh_calloc(src->value.determine_transfer_status_status.input.unicast_addr_count * 2); if (dst->value.determine_transfer_status_status.input.unicast_addr) { memcpy(dst->value.determine_transfer_status_status.input.unicast_addr, src->value.determine_transfer_status_status.input.unicast_addr, @@ -185,7 +185,7 @@ static void btc_ble_mesh_blob_trans_client_copy_req_data(btc_msg_t *msg, void *p break; case BTC_BLE_MESH_ACT_MBT_CLIENT_CANCEL_TRANSFER: if (src->value.cancel_transfer_status.input.unicast_addr_count && - src->value.cancel_transfer_status.input.unicast_addr) { + src->value.cancel_transfer_status.input.unicast_addr) { dst->value.cancel_transfer_status.input.unicast_addr = bt_mesh_calloc(src->value.cancel_transfer_status.input.unicast_addr_count * 2); if (dst->value.cancel_transfer_status.input.unicast_addr) { memcpy(dst->value.cancel_transfer_status.input.unicast_addr, src->value.cancel_transfer_status.input.unicast_addr, @@ -482,7 +482,7 @@ void bt_mesh_mbt_server_cb_evt_to_btc(uint8_t event, uint8_t cb_event = 0; if (model == NULL || (ctx == NULL && - event != BTC_BLE_MESH_EVT_MBT_SERVER_BLOB_RECEIVE_TIMEOUT)) { + event != BTC_BLE_MESH_EVT_MBT_SERVER_BLOB_RECEIVE_TIMEOUT)) { BT_ERR("%s, Invalid parameter", __func__); return; } diff --git a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_odp_model.c b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_odp_model.c index 4f455926775..693b929227b 100644 --- a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_odp_model.c +++ b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_odp_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2023 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -40,8 +40,8 @@ void btc_ble_mesh_odp_client_arg_deep_copy(btc_msg_t *msg, void *p_dest, void *p switch (msg->act) { case BTC_BLE_MESH_ACT_ODP_CLIENT_SEND: - dst->odp_send.params= NULL; - dst->odp_send.msg= NULL; + dst->odp_send.params = NULL; + dst->odp_send.msg = NULL; dst->odp_send.params = bt_mesh_calloc(sizeof(esp_ble_mesh_client_common_param_t)); if (!dst->odp_send.params) { @@ -217,8 +217,8 @@ void btc_ble_mesh_odp_client_recv_pub_cb(uint32_t opcode, } bt_mesh_odp_client_cb_evt_to_btc(opcode, - BTC_BLE_MESH_EVT_ODP_CLIENT_RECV_PUB, - model, ctx, buf->data, buf->len); + BTC_BLE_MESH_EVT_ODP_CLIENT_RECV_PUB, + model, ctx, buf->data, buf->len); } static int btc_ble_mesh_odp_client_send(esp_ble_mesh_client_common_param_t *params, @@ -266,7 +266,7 @@ void btc_ble_mesh_odp_client_call_handler(btc_msg_t *msg) cb.send.err_code = btc_ble_mesh_odp_client_send(arg->odp_send.params, arg->odp_send.msg); btc_ble_mesh_odp_client_cb(&cb, - ESP_BLE_MESH_ODP_CLIENT_SEND_COMP_EVT); + ESP_BLE_MESH_ODP_CLIENT_SEND_COMP_EVT); } btc_ble_mesh_odp_client_arg_deep_free(msg); diff --git a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_prb_model.c b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_prb_model.c index 48ce1cc606e..6598717bec9 100644 --- a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_prb_model.c +++ b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_prb_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2023 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -222,8 +222,8 @@ void btc_ble_mesh_prb_client_recv_pub_cb(uint32_t opcode, } bt_mesh_prb_client_cb_evt_to_btc(opcode, - BTC_BLE_MESH_EVT_PRB_CLIENT_RECV_PUB, - model, ctx, buf->data, buf->len); + BTC_BLE_MESH_EVT_PRB_CLIENT_RECV_PUB, + model, ctx, buf->data, buf->len); } static int btc_ble_mesh_prb_client_send(esp_ble_mesh_client_common_param_t *params, @@ -264,7 +264,7 @@ static int btc_ble_mesh_prb_client_send(esp_ble_mesh_client_common_param_t *para case ESP_BLE_MESH_MODEL_OP_PRIV_NODE_IDENTITY_GET: return bt_mesh_private_node_identity_get(¶m, msg->priv_node_id_get.net_idx); case ESP_BLE_MESH_MODEL_OP_PRIV_NODE_IDENTITY_SET: - return bt_mesh_private_node_identity_set(¶m, msg->priv_node_id_set.net_idx , msg->priv_node_id_set.private_node_id); + return bt_mesh_private_node_identity_set(¶m, msg->priv_node_id_set.net_idx, msg->priv_node_id_set.private_node_id); default: BT_ERR("Invalid Private Beacon opcode 0x%04x", param.opcode); return -EINVAL; @@ -289,7 +289,7 @@ void btc_ble_mesh_prb_client_call_handler(btc_msg_t *msg) cb.send.err_code = btc_ble_mesh_prb_client_send(arg->prb_send.params, arg->prb_send.msg); btc_ble_mesh_prb_client_cb(&cb, - ESP_BLE_MESH_PRB_CLIENT_SEND_COMP_EVT); + ESP_BLE_MESH_PRB_CLIENT_SEND_COMP_EVT); break; default: break; @@ -333,7 +333,7 @@ static inline void btc_ble_mesh_prb_server_cb_to_app(esp_ble_mesh_prb_server_cb_ } static void btc_ble_mesh_prb_server_cb( - esp_ble_mesh_prb_server_cb_param_t *cb_params, uint8_t act) + esp_ble_mesh_prb_server_cb_param_t *cb_params, uint8_t act) { btc_msg_t msg = {0}; diff --git a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_rpr_model.c b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_rpr_model.c index 34e6929af74..7dea145b313 100644 --- a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_rpr_model.c +++ b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_rpr_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2024 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -154,7 +154,7 @@ static void btc_ble_mesh_rpr_client_copy_req_data(btc_msg_t *msg, void *p_dest, * publish event. */ if (msg->act == ESP_BLE_MESH_RPR_CLIENT_RECV_PUB_EVT && - p_src_data->recv.params->opcode == ESP_BLE_MESH_MODEL_OP_RPR_EXT_SCAN_REPORT) { + p_src_data->recv.params->opcode == ESP_BLE_MESH_MODEL_OP_RPR_EXT_SCAN_REPORT) { if (p_src_data->recv.val.ext_scan_report.adv_structures) { length = p_src_data->recv.val.ext_scan_report.adv_structures->len; p_dest_data->recv.val.ext_scan_report.adv_structures = bt_mesh_alloc_buf(length); @@ -201,8 +201,8 @@ static void btc_ble_mesh_rpr_client_free_req_data(btc_msg_t *msg) case ESP_BLE_MESH_RPR_CLIENT_RECV_RSP_EVT: case ESP_BLE_MESH_RPR_CLIENT_RECV_PUB_EVT: if (arg->recv.params && - msg->act == ESP_BLE_MESH_RPR_CLIENT_RECV_PUB_EVT && - arg->recv.params->opcode == ESP_BLE_MESH_MODEL_OP_RPR_EXT_SCAN_REPORT) { + msg->act == ESP_BLE_MESH_RPR_CLIENT_RECV_PUB_EVT && + arg->recv.params->opcode == ESP_BLE_MESH_MODEL_OP_RPR_EXT_SCAN_REPORT) { bt_mesh_free_buf(arg->recv.val.ext_scan_report.adv_structures); } if (arg->recv.params) { @@ -242,9 +242,9 @@ void bt_mesh_rpr_client_cb_evt_to_btc(uint32_t opcode, uint8_t event, uint8_t act = 0; if (model == NULL || ctx == NULL || - ((event == BTC_BLE_MESH_EVT_RPR_CLIENT_RECV_RSP || - event == BTC_BLE_MESH_EVT_RPR_CLIENT_RECV_PUB) && - (len > sizeof(cb_params.recv.val)))) { + ((event == BTC_BLE_MESH_EVT_RPR_CLIENT_RECV_RSP || + event == BTC_BLE_MESH_EVT_RPR_CLIENT_RECV_PUB) && + (len > sizeof(cb_params.recv.val)))) { BT_ERR("%s, Invalid parameter", __func__); return; } @@ -467,7 +467,7 @@ void btc_ble_mesh_rpr_client_cb_handler(btc_msg_t *msg) #if CONFIG_BLE_MESH_RPR_SRV /* Remote Provisioning Server model related functions */ -extern int bt_mesh_rpr_srv_scan_set_dev_uuid_match(uint8_t offset, uint8_t length,const uint8_t *match); +extern int bt_mesh_rpr_srv_scan_set_dev_uuid_match(uint8_t offset, uint8_t length, const uint8_t *match); void btc_ble_mesh_rpr_server_arg_deep_copy(btc_msg_t *msg, void *p_dest, void *p_src) { @@ -479,7 +479,7 @@ void btc_ble_mesh_rpr_server_arg_deep_copy(btc_msg_t *msg, void *p_dest, void *p return; } - switch(msg->act) { + switch (msg->act) { case BTC_BLE_MESH_ACT_RPR_SRV_SET_UUID_MATCH: dst->set_uuid_match.match_val = bt_mesh_calloc(src->set_uuid_match.match_len); if (dst->set_uuid_match.match_val) { @@ -509,7 +509,7 @@ void btc_ble_mesh_rpr_server_arg_deep_free(btc_msg_t *msg) arg = (btc_ble_mesh_rpr_server_args_t *)msg->arg; - switch(msg->act) { + switch (msg->act) { case BTC_BLE_MESH_ACT_RPR_SRV_SET_UUID_MATCH: if (arg->set_uuid_match.match_val) { bt_mesh_free(arg->set_uuid_match.match_val); diff --git a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_sar_model.c b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_sar_model.c index 06cdbd311f5..065b34bc962 100644 --- a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_sar_model.c +++ b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_sar_model.c @@ -235,7 +235,7 @@ static int btc_ble_mesh_sar_client_send(esp_ble_mesh_client_common_param_t *para } if ((params->opcode == ESP_BLE_MESH_MODEL_OP_SAR_TRANSMITTER_SET || - params->opcode == ESP_BLE_MESH_MODEL_OP_SAR_RECEIVER_SET) && msg == NULL) { + params->opcode == ESP_BLE_MESH_MODEL_OP_SAR_RECEIVER_SET) && msg == NULL) { BT_ERR("Invalid SAR Config message, opcode 0x%04x", params->opcode); return -EINVAL; } diff --git a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_srpl_model.c b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_srpl_model.c index 11813110160..1ee349d6f1a 100644 --- a/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_srpl_model.c +++ b/components/bt/esp_ble_mesh/v1.1/btc/btc_ble_mesh_srpl_model.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2023 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -214,8 +214,8 @@ void btc_ble_mesh_srpl_client_recv_pub_cb(uint32_t opcode, } bt_mesh_srpl_client_cb_evt_to_btc(opcode, - BTC_BLE_MESH_EVT_SRPL_CLIENT_RECV_PUB, - model, ctx, buf->data, buf->len); + BTC_BLE_MESH_EVT_SRPL_CLIENT_RECV_PUB, + model, ctx, buf->data, buf->len); } static int btc_ble_mesh_srpl_client_send(esp_ble_mesh_client_common_param_t *params, @@ -258,7 +258,7 @@ void btc_ble_mesh_srpl_client_call_handler(btc_msg_t *msg) cb.send.err_code = btc_ble_mesh_srpl_client_send(arg->srpl_send.params, arg->srpl_send.msg); btc_ble_mesh_srpl_client_cb(&cb, - ESP_BLE_MESH_SRPL_CLIENT_SEND_COMP_EVT); + ESP_BLE_MESH_SRPL_CLIENT_SEND_COMP_EVT); break; default: break;