fix(ble/bluedroid): fix L2CAP, SMP and HCI command issues

- Fix active_count check in l2cu_ble_plcb_active_count
- Restore previous state if connection command fails
- Fix HCI cmd buffer size off-by-one errors
- Fix connect handle length errors
- Fix channel sounding event status handling
- Fix SMP param_len check in smp_rand_back
- Fix spelling: BROCASTER to BROADCASTER in definitions
This commit is contained in:
zhiweijian
2026-02-27 17:59:59 +08:00
parent e0ccc644a8
commit e118d053b3
13 changed files with 183 additions and 65 deletions
@@ -234,6 +234,7 @@ BOOLEAN L2CA_EnableUpdateBleConnParams (BD_ADDR rem_bda, BOOLEAN enable)
return (FALSE);
}
bool is_disable = (p_lcb->conn_update_mask & L2C_BLE_CONN_UPDATE_DISABLE);
// for multiple links, actively updating the parameters to 7.5ms may degrade multi-connection performance
if(l2cu_ble_plcb_active_count() >1 && !(enable && is_disable)) {
return FALSE;
}
@@ -875,10 +876,11 @@ void l2cble_process_sig_cmd (tL2C_LCB *p_lcb, UINT8 *p, UINT16 pkt_len)
p_ccb = l2cu_find_ccb_by_cid(p_lcb, lcid);
if (p_ccb) {
p_ccb->remote_id = id;
// TODO
l2cu_send_peer_disc_rsp(p_lcb, id, lcid, rcid);
} else {
L2CAP_TRACE_WARNING ("L2CAP - LE - disc req with invalid lcid, send cmd reject");
l2cu_send_peer_cmd_reject(p_lcb, L2CAP_CMD_REJ_INVALID_CID, id, rcid, lcid);
}
l2cu_send_peer_disc_rsp(p_lcb, id, lcid, rcid);
break;
}
default:
@@ -1073,19 +1075,29 @@ BOOLEAN l2cble_init_direct_conn (tL2C_LCB *p_lcb)
#if (BT_BLE_FEAT_PAWR_EN == TRUE)
if (p_lcb->is_pawr_synced) {
if(!btsnd_hcic_ble_create_ext_conn_v2(&aux_conn)) {
l2cb.is_ble_connecting = FALSE;
memset(l2cb.ble_connecting_bda, 0, BD_ADDR_LEN);
btm_ble_set_conn_st (BLE_CONN_IDLE);
l2cu_release_lcb (p_lcb);
L2CAP_TRACE_ERROR("initiate pawr sync connection failed, no resources");
return (FALSE);
}
} else
#endif // (BT_BLE_FEAT_PAWR_EN == TRUE)
{
if(!btsnd_hcic_ble_create_ext_conn(&aux_conn)) {
l2cb.is_ble_connecting = FALSE;
memset(l2cb.ble_connecting_bda, 0, BD_ADDR_LEN);
btm_ble_set_conn_st (BLE_CONN_IDLE);
l2cu_release_lcb (p_lcb);
L2CAP_TRACE_ERROR("initiate Aux connection failed, no resources");
return (FALSE);
}
}
#else
l2cu_release_lcb (p_lcb);
L2CAP_TRACE_ERROR("BLE 5.0 not support!\n");
return (FALSE);
#endif // #if (BLE_50_FEATURE_SUPPORT == TRUE)
return (TRUE);
}
@@ -1293,7 +1305,7 @@ void l2cble_process_rc_param_request_evt(UINT16 handle, UINT16 int_min, UINT16 i
btsnd_hcic_ble_rc_param_req_reply(handle, int_min, int_max, latency, timeout, BLE_CE_LEN_MIN, BLE_CE_LEN_MIN);
}else {
L2CAP_TRACE_EVENT ("L2CAP - LE - update currently disabled");
p_lcb->conn_update_mask |= L2C_BLE_NEW_CONN_PARAM;
// p_lcb->conn_update_mask |= L2C_BLE_NEW_CONN_PARAM;
btsnd_hcic_ble_rc_param_req_neg_reply (handle, HCI_ERR_UNACCEPT_CONN_INTERVAL);
}
}
@@ -43,7 +43,7 @@
static BOOLEAN l2c_link_send_to_lower (tL2C_LCB *p_lcb, BT_HDR *p_buf);
#if (BLE_50_FEATURE_SUPPORT == TRUE)
extern tBTM_STATUS BTM_BleStartExtAdvRestart(uint8_t handle);
extern tBTM_STATUS BTM_BleStartExtAdvRestart(uint16_t handle);
#endif// #if (BLE_50_FEATURE_SUPPORT == TRUE)
extern bool btm_ble_inter_get(void);
@@ -909,7 +909,7 @@ void l2c_init (void)
l2cb.l2c_ble_fixed_chnls_mask =
L2CAP_FIXED_CHNL_ATT_BIT | L2CAP_FIXED_CHNL_BLE_SIG_BIT | L2CAP_FIXED_CHNL_SMP_BIT;
#endif
// Free callback must be NULL
l2cb.rcv_pending_q = list_new(NULL);
if (l2cb.rcv_pending_q == NULL) {
L2CAP_TRACE_ERROR("%s unable to allocate memory for link layer control block", __func__);
@@ -948,6 +948,10 @@ void l2c_free_p_ccb_pool(void)
void l2c_free(void)
{
// check again
if (l2cb.rcv_pending_q && list_length(l2cb.rcv_pending_q) > 0) {
assert(0);
}
list_free(l2cb.rcv_pending_q);
l2cb.rcv_pending_q = NULL;
l2c_free_p_lcb_pool();
@@ -170,6 +170,10 @@ void l2cu_release_lcb (tL2C_LCB *p_lcb)
p_lcb->start_time_s = 0;
#endif // #if (BLE_INCLUDED == TRUE)
#if (BT_BLE_FEAT_PAWR_EN == TRUE)
p_lcb->is_pawr_synced = FALSE;
#endif
/* Stop and release timers */
btu_free_timer (&p_lcb->timer_entry);
memset(&p_lcb->timer_entry, 0, sizeof(TIMER_LIST_ENT));
@@ -364,10 +368,7 @@ uint8_t l2cu_ble_plcb_active_count(void)
active_count ++;
}
}
if (active_count >= MAX_L2CAP_CHANNELS) {
L2CAP_TRACE_ERROR("error active count");
active_count = 0;
}
L2CAP_TRACE_DEBUG("plcb active count %d", active_count);
return active_count;
@@ -3286,7 +3287,7 @@ tL2C_LCB *l2cu_find_lcb_by_handle (UINT16 handle)
bool l2cu_find_ccb_in_list(void *p_ccb_node, void *p_local_cid)
{
tL2C_CCB *p_ccb = (tL2C_CCB *)p_ccb_node;
uint8_t local_cid = *((uint8_t *)p_local_cid);
uint16_t local_cid = *((uint16_t *)p_local_cid);
if (p_ccb->local_cid == local_cid && p_ccb->in_use) {
return FALSE;