fix(bt/bluedroid): fixed the vulerabilities from AI code review in SPP

This commit is contained in:
Jin Cheng
2026-03-30 17:38:46 +08:00
parent 2839dacbc2
commit ed270d71c8
17 changed files with 133 additions and 75 deletions
@@ -38,7 +38,7 @@ static inline void obex_server_to_tl_server(tOBEX_SVR_INFO *server, tOBEX_TL_SVR
}
}
static inline void obex_updata_packet_length(BT_HDR *p_buf, UINT16 len)
static inline void obex_update_packet_length(BT_HDR *p_buf, UINT16 len)
{
UINT8 *p_pkt_len = (UINT8 *)(p_buf + 1) + p_buf->offset + 1;
UINT16_TO_BE_FIELD(p_pkt_len, len);
@@ -66,12 +66,12 @@ UINT16 OBEX_Init(void)
#endif /* #if (OBEX_DYNAMIC_MEMORY) */
memset(&obex_cb, 0, sizeof(tOBEX_CB));
obex_cb.tl_ops[OBEX_OVER_L2CAP] = obex_tl_l2cap_ops_get();
if (obex_cb.tl_ops[OBEX_OVER_L2CAP]->init != NULL) {
if (obex_cb.tl_ops[OBEX_OVER_L2CAP] && obex_cb.tl_ops[OBEX_OVER_L2CAP]->init) {
obex_cb.tl_ops[OBEX_OVER_L2CAP]->init(obex_tl_l2cap_callback);
}
#if (RFCOMM_INCLUDED == TRUE)
obex_cb.tl_ops[OBEX_OVER_RFCOMM] = obex_tl_rfcomm_ops_get();
if (obex_cb.tl_ops[OBEX_OVER_RFCOMM]->init != NULL) {
if (obex_cb.tl_ops[OBEX_OVER_RFCOMM] && obex_cb.tl_ops[OBEX_OVER_RFCOMM]->init) {
obex_cb.tl_ops[OBEX_OVER_RFCOMM]->init(obex_tl_rfcomm_callback);
}
#endif
@@ -89,11 +89,11 @@ UINT16 OBEX_Init(void)
*******************************************************************************/
void OBEX_Deinit(void)
{
if (obex_cb.tl_ops[OBEX_OVER_L2CAP]->deinit != NULL) {
if (obex_cb.tl_ops[OBEX_OVER_L2CAP] && obex_cb.tl_ops[OBEX_OVER_L2CAP]->deinit) {
obex_cb.tl_ops[OBEX_OVER_L2CAP]->deinit();
}
#if (RFCOMM_INCLUDED == TRUE)
if (obex_cb.tl_ops[OBEX_OVER_RFCOMM]->deinit != NULL) {
if (obex_cb.tl_ops[OBEX_OVER_RFCOMM] && obex_cb.tl_ops[OBEX_OVER_RFCOMM]->deinit) {
obex_cb.tl_ops[OBEX_OVER_RFCOMM]->deinit();
}
#endif
@@ -327,7 +327,7 @@ UINT16 OBEX_BuildRequest(tOBEX_PARSE_INFO *info, UINT16 buff_size, BT_HDR **out_
}
buff_size += sizeof(BT_HDR) + OBEX_BT_HDR_MIN_OFFSET + OBEX_BT_HDR_RESERVE_LEN;
BT_HDR *p_buf= (BT_HDR *)osi_malloc(buff_size);
BT_HDR *p_buf = (BT_HDR *)osi_malloc(buff_size);
if (p_buf == NULL) {
return OBEX_NO_RESOURCES;
}
@@ -780,10 +780,10 @@ UINT8 *OBEX_GetNextHeader(BT_HDR *pkt, tOBEX_PARSE_INFO *info)
if (pkt == NULL || info == NULL) {
return NULL;
}
UINT8 *p_data = (UINT8 *)(pkt + 1) + pkt->offset;
if (info->next_header_pos == 0 || info->next_header_pos >= pkt->len) {
return NULL;
}
UINT8 *p_data = (UINT8 *)(pkt + 1) + pkt->offset;
UINT8 *header = p_data + info->next_header_pos;
UINT16 header_len = OBEX_GetHeaderLength(header);
info->next_header_pos += header_len;
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2024 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -554,7 +554,7 @@ void obex_tl_l2cap_congestion_status_ind(UINT16 lcid, BOOLEAN is_congested)
** other APIs
**
*******************************************************************************/
void obex_tl_l2cap_init(tOBEX_TL_CBACK callback)
void obex_tl_l2cap_init(tOBEX_TL_CBACK *callback)
{
assert(callback != NULL);
#if (OBEX_DYNAMIC_MEMORY)
@@ -587,7 +587,7 @@ void obex_tl_l2cap_init(tOBEX_TL_CBACK callback)
/*******************************************************************************
**
** Function obex_tl_l2cap_init
** Function obex_tl_l2cap_deinit
**
** Description Deinitialize OBEX over L2CAP transport layer
**
@@ -674,7 +674,7 @@ void obex_tl_l2cap_disconnect(UINT16 hdl)
**
** Function obex_tl_l2cap_send_data
**
** Description Start the process of establishing a L2CAP connection
** Description Send data on an established L2CAP connection
**
** Returns OBEX_TL_SUCCESS, if data accepted
** OBEX_TL_CONGESTED, if data accepted and the channel is congested
@@ -357,6 +357,8 @@ UINT16 obex_tl_rfcomm_send(UINT16 handle, BT_HDR *p_buf)
if (PORT_Write(p_ccb->rfc_handle, p_buf) == PORT_SUCCESS) {
ret = OBEX_TL_SUCCESS;
} else {
osi_free(p_buf);
}
} while (0);
return ret;