mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
Merge branch 'bugfix/spp_improvement' into 'master'
fix(bt/bluedroid): fixed multiple high-severity issues from AI code review in SPP See merge request espressif/esp-idf!46803
This commit is contained in:
@@ -80,6 +80,7 @@ static tGOEPC_CCB *find_ccb_by_obex_handle(UINT16 obex_handle)
|
||||
for (int i = 0; i < GOEPC_MAX_CONNECTION; ++i) {
|
||||
if (goepc_cb.ccb[i].allocated && goepc_cb.ccb[i].obex_handle == obex_handle) {
|
||||
p_ccb = &goepc_cb.ccb[i];
|
||||
break;
|
||||
}
|
||||
}
|
||||
return p_ccb;
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2024 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -121,7 +121,7 @@ UINT16 OBEX_CreateConn(tOBEX_SVR_INFO *server, tOBEX_MSG_CBACK callback, UINT16
|
||||
tOBEX_CCB *p_ccb = NULL;
|
||||
|
||||
do {
|
||||
if (server->tl >= OBEX_NUM_TL) {
|
||||
if (!server || (server->tl >= OBEX_NUM_TL)) {
|
||||
ret = OBEX_INVALID_PARAM;
|
||||
break;
|
||||
}
|
||||
@@ -144,7 +144,9 @@ UINT16 OBEX_CreateConn(tOBEX_SVR_INFO *server, tOBEX_MSG_CBACK callback, UINT16
|
||||
p_ccb->callback = callback;
|
||||
p_ccb->role = OBEX_ROLE_CLIENT;
|
||||
p_ccb->state = OBEX_STATE_OPENING;
|
||||
*out_handle = p_ccb->allocated;
|
||||
if (out_handle) {
|
||||
*out_handle = p_ccb->allocated;
|
||||
}
|
||||
} while (0);
|
||||
|
||||
if (ret != OBEX_SUCCESS && p_ccb != NULL) {
|
||||
@@ -627,20 +629,35 @@ UINT16 OBEX_ParseRequest(BT_HDR *pkt, tOBEX_PARSE_INFO *info)
|
||||
}
|
||||
|
||||
UINT8 *p_data = (UINT8 *)(pkt + 1) + pkt->offset;
|
||||
UINT16 len = pkt->len;
|
||||
|
||||
if (len < 1) {
|
||||
return OBEX_FAILURE;
|
||||
}
|
||||
|
||||
info->opcode = *p_data;
|
||||
switch (info->opcode)
|
||||
{
|
||||
case OBEX_OPCODE_CONNECT:
|
||||
if (len < 7) {
|
||||
return OBEX_FAILURE;
|
||||
}
|
||||
info->obex_version_number = p_data[3];
|
||||
info->flags = p_data[4];
|
||||
info->max_packet_length = (p_data[5] << 8) + p_data[6];
|
||||
info->next_header_pos = 7;
|
||||
break;
|
||||
case OBEX_OPCODE_SETPATH:
|
||||
if (len < 5) {
|
||||
return OBEX_FAILURE;
|
||||
}
|
||||
info->flags = p_data[3];
|
||||
info->next_header_pos = 5;
|
||||
break;
|
||||
default:
|
||||
if (len < 3) {
|
||||
return OBEX_FAILURE;
|
||||
}
|
||||
info->next_header_pos = 3;
|
||||
break;
|
||||
}
|
||||
|
||||
@@ -62,13 +62,13 @@ static void rfc_set_port_state(tPORT_STATE *port_pars, MX_FRAME *p_frame);
|
||||
*******************************************************************************/
|
||||
void rfc_port_sm_execute (tPORT *p_port, UINT16 event, void *p_data)
|
||||
{
|
||||
RFCOMM_TRACE_DEBUG("%s st:%d, evt:%d\n", __func__, p_port->rfc.state, event);
|
||||
|
||||
if (!p_port) {
|
||||
RFCOMM_TRACE_WARNING ("NULL port event %d", event);
|
||||
return;
|
||||
}
|
||||
|
||||
RFCOMM_TRACE_DEBUG("%s st:%d, evt:%d\n", __func__, p_port->rfc.state, event);
|
||||
|
||||
switch (p_port->rfc.state) {
|
||||
case RFC_STATE_CLOSED:
|
||||
rfc_port_sm_state_closed (p_port, event, p_data);
|
||||
@@ -240,7 +240,7 @@ void rfc_port_sm_sabme_wait_ua (tPORT *p_port, UINT16 event, void *p_data)
|
||||
**
|
||||
** Description This function handles events for the port in the
|
||||
** WAIT_SEC_CHECK state. SABME has been received from the
|
||||
** peer and Security Manager verifes BD_ADDR, before we can
|
||||
** peer and Security Manager verifies BD_ADDR, before we can
|
||||
** send ESTABLISH_IND to the Port entity
|
||||
**
|
||||
** Returns void
|
||||
|
||||
@@ -179,8 +179,17 @@ void rfc_send_buf_uih (tRFC_MCB *p_mcb, UINT8 dlci, BT_HDR *p_buf)
|
||||
UINT8 cr = RFCOMM_CR(p_mcb->is_initiator, TRUE);
|
||||
UINT8 credits;
|
||||
|
||||
if (p_buf->offset < RFCOMM_CTRL_FRAME_LEN) {
|
||||
osi_free(p_buf);
|
||||
return;
|
||||
}
|
||||
|
||||
p_buf->offset -= RFCOMM_CTRL_FRAME_LEN;
|
||||
if (p_buf->len > 127) {
|
||||
if (p_buf->offset < 1) {
|
||||
osi_free(p_buf);
|
||||
return;
|
||||
}
|
||||
p_buf->offset--;
|
||||
}
|
||||
|
||||
@@ -191,6 +200,10 @@ void rfc_send_buf_uih (tRFC_MCB *p_mcb, UINT8 dlci, BT_HDR *p_buf)
|
||||
}
|
||||
|
||||
if (credits) {
|
||||
if (p_buf->offset < 1) {
|
||||
osi_free(p_buf);
|
||||
return;
|
||||
}
|
||||
p_buf->offset--;
|
||||
}
|
||||
|
||||
@@ -558,8 +571,26 @@ void rfc_send_test (tRFC_MCB *p_mcb, BOOLEAN is_command, BT_HDR *p_buf)
|
||||
UINT16 xx;
|
||||
UINT8 *p_src, *p_dest;
|
||||
|
||||
if (p_buf->offset + sizeof(BT_HDR) >= RFCOMM_CMD_BUF_SIZE) {
|
||||
osi_free(p_buf);
|
||||
return;
|
||||
}
|
||||
|
||||
UINT16 max_len = RFCOMM_CMD_BUF_SIZE - sizeof(BT_HDR) - p_buf->offset;
|
||||
if (p_buf->offset < (L2CAP_MIN_OFFSET + RFCOMM_MIN_OFFSET + 2)) {
|
||||
if (max_len < (L2CAP_MIN_OFFSET + RFCOMM_MIN_OFFSET + 2 - p_buf->offset)) {
|
||||
osi_free(p_buf);
|
||||
return;
|
||||
}
|
||||
max_len -= (L2CAP_MIN_OFFSET + RFCOMM_MIN_OFFSET + 2 - p_buf->offset);
|
||||
}
|
||||
if (p_buf->len > max_len) {
|
||||
p_buf->len = max_len;
|
||||
}
|
||||
|
||||
BT_HDR *p_buf_new;
|
||||
if ((p_buf_new = (BT_HDR *)osi_malloc(RFCOMM_CMD_BUF_SIZE)) == NULL) {
|
||||
osi_free(p_buf);
|
||||
return;
|
||||
}
|
||||
memcpy(p_buf_new, p_buf, sizeof(BT_HDR) + p_buf->offset + p_buf->len);
|
||||
|
||||
@@ -491,18 +491,21 @@ void rfc_check_send_cmd(tRFC_MCB *p_mcb, BT_HDR *p_buf)
|
||||
RFCOMM_TRACE_ERROR("%s: empty queue: p_mcb = %p p_mcb->lcid = %u cached p_mcb = %p",
|
||||
__func__, p_mcb, p_mcb->lcid,
|
||||
rfc_find_lcid_mcb(p_mcb->lcid));
|
||||
osi_free(p_buf);
|
||||
} else {
|
||||
fixed_queue_enqueue(p_mcb->cmd_q, p_buf, FIXED_QUEUE_MAX_TIMEOUT);
|
||||
}
|
||||
fixed_queue_enqueue(p_mcb->cmd_q, p_buf, FIXED_QUEUE_MAX_TIMEOUT);
|
||||
}
|
||||
|
||||
/* handle queue if L2CAP not congested */
|
||||
while (p_mcb->l2cap_congested == FALSE) {
|
||||
if ((p = (BT_HDR *)fixed_queue_dequeue(p_mcb->cmd_q, 0)) == NULL) {
|
||||
break;
|
||||
if (p_mcb->cmd_q) {
|
||||
while (p_mcb->l2cap_congested == FALSE) {
|
||||
if ((p = (BT_HDR *)fixed_queue_dequeue(p_mcb->cmd_q, 0)) == NULL) {
|
||||
break;
|
||||
}
|
||||
|
||||
L2CA_DataWrite (p_mcb->lcid, p);
|
||||
}
|
||||
|
||||
|
||||
L2CA_DataWrite (p_mcb->lcid, p);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user