mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
fix(ble_log): fix unaligned access and buffer safety in log compression
This commit is contained in:
@@ -74,7 +74,7 @@ int ble_compressed_log_cb_get(uint8_t source, ble_cp_log_buffer_mgmt_t **mgmt)
|
||||
#endif
|
||||
default:
|
||||
assert(0 && "Unsupported log source");
|
||||
break;
|
||||
return -1;
|
||||
}
|
||||
|
||||
for (int i = 0; i < LOG_CP_MAX_LOG_BUFFER_USED_SIMU; i++) {
|
||||
@@ -95,7 +95,7 @@ int ble_compressed_log_cb_get(uint8_t source, ble_cp_log_buffer_mgmt_t **mgmt)
|
||||
|
||||
static inline int ble_compressed_log_buffer_free(ble_cp_log_buffer_mgmt_t *mgmt)
|
||||
{
|
||||
#if BLE_LOG_CP_CONTENT_CHECK_ENBALE
|
||||
#if BLE_LOG_CP_CONTENT_CHECK_ENABLE
|
||||
memset(mgmt->buffer, BLE_LOG_CP_CONTENT_CHECK_VAL, mgmt->idx);
|
||||
#endif
|
||||
mgmt->idx = 0;
|
||||
@@ -107,6 +107,11 @@ static inline
|
||||
int ble_log_compressed_hex_print_internal(ble_cp_log_buffer_mgmt_t *mgmt, uint32_t log_index, size_t args_cnt, va_list args)
|
||||
{
|
||||
uint8_t arg_type = 0;
|
||||
uint16_t header_size = 1 + 2 + (args_cnt + 1) / 2; // header + log_index + size_info
|
||||
|
||||
if (ble_log_cp_buffer_safe_check(mgmt, header_size)) {
|
||||
return -1;
|
||||
}
|
||||
|
||||
ble_log_cp_push_u8(mgmt, LOG_HEADER(LOG_TYPE_HEX_ARGS, args_cnt));
|
||||
ble_log_cp_push_u16(mgmt, log_index);
|
||||
@@ -200,9 +205,12 @@ int ble_log_compressed_hex_print_internal(ble_cp_log_buffer_mgmt_t *mgmt, uint32
|
||||
ble_log_cp_push_u8(mgmt, (uint8_t)tmpv);
|
||||
ble_log_cp_push_u16(mgmt, (uint16_t)(tmpv >> 8));
|
||||
break;
|
||||
case 4:
|
||||
BLE_CP_TRY_PUSH(ble_log_cp_push_u32(mgmt, (uint32_t)u64v));
|
||||
break;
|
||||
default:
|
||||
assert(0);
|
||||
break;
|
||||
return -1;
|
||||
}
|
||||
ble_log_cp_update_half_byte(mgmt, size_info_idx + i/2, ARG_SIZE_TYPE_LZU64, !(i%2));
|
||||
}
|
||||
@@ -212,12 +220,16 @@ int ble_log_compressed_hex_print_internal(ble_cp_log_buffer_mgmt_t *mgmt, uint32
|
||||
break;
|
||||
case ARG_SIZE_TYPE_STR:
|
||||
char *str_p = (char *)va_arg(args, char *);
|
||||
ble_log_cp_push_buf(mgmt, (const uint8_t *)str_p, strlen(str_p) + 1);
|
||||
if (str_p) {
|
||||
BLE_CP_TRY_PUSH(ble_log_cp_push_buf(mgmt, (const uint8_t *)str_p, strlen(str_p) + 1));
|
||||
} else {
|
||||
BLE_CP_TRY_PUSH(ble_log_cp_push_buf(mgmt, (const uint8_t *)"(null str)", sizeof("(null str)")));
|
||||
}
|
||||
break;
|
||||
default:
|
||||
printf("Invalid size %d\n", arg_type);
|
||||
assert(0);
|
||||
break;
|
||||
return -1;
|
||||
}
|
||||
}
|
||||
return 0;
|
||||
@@ -268,7 +280,11 @@ int ble_log_compressed_hex_print_buf(uint8_t source, uint32_t log_index, uint8_t
|
||||
return 0;
|
||||
}
|
||||
|
||||
<<<<<<< HEAD
|
||||
if (buf == NULL && len != 0) {
|
||||
=======
|
||||
if (buf == NULL) {
|
||||
>>>>>>> 3f2b6c97f86 (fix(ble_log): fix unaligned access and buffer safety in log compression)
|
||||
ble_log_cp_push_u8(mgmt, LOG_HEADER(LOG_TYPE_INFO, LOG_TYPE_INFO_NULL_BUF));
|
||||
ble_log_cp_push_u16(mgmt, log_index);
|
||||
ble_compressed_log_output(source, mgmt->buffer, mgmt->idx);
|
||||
|
||||
+7
-9
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -8,6 +8,7 @@
|
||||
|
||||
#include "ble_log.h"
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
|
||||
#define CONCAT(a, b) a##b
|
||||
#define _CONCAT(a, b) CONCAT(a, b)
|
||||
@@ -86,7 +87,7 @@ typedef struct {
|
||||
#define CONTENT_CHECK(idx, buf, except_val, len)
|
||||
#define LENGTH_CHECK(idx, pbuffer_mgmt) do ( if(unlikely((idx) > (pbuffer_mgmt->len))) assert(0 && "Maximum log buffer length exceeded");) while(0)
|
||||
|
||||
#define BLE_LOG_CP_CONTENT_CHECK_ENBALE 0
|
||||
#define BLE_LOG_CP_CONTENT_CHECK_ENABLE 0
|
||||
#define BLE_LOG_CP_CONTENT_CHECK_VAL 0x00
|
||||
|
||||
static inline int ble_log_cp_buffer_safe_check(ble_cp_log_buffer_mgmt_t *pbuf_mgmt, uint16_t write_len)
|
||||
@@ -95,7 +96,7 @@ static inline int ble_log_cp_buffer_safe_check(ble_cp_log_buffer_mgmt_t *pbuf_mg
|
||||
printf("Maximum length of buffer(%p) idx %d write_len %d exceed\n", pbuf_mgmt, pbuf_mgmt->idx, write_len);
|
||||
return -1;
|
||||
}
|
||||
#if BLE_LOG_CP_CONTENT_CHECK_ENBALE
|
||||
#if BLE_LOG_CP_CONTENT_CHECK_ENABLE
|
||||
for (int i = pbuf_mgmt->idx; i < pbuf_mgmt->idx + write_len; i++) {
|
||||
if (pbuf_mgmt->buffer[i] != BLE_LOG_CP_CONTENT_CHECK_VAL) {
|
||||
printf("The value(%02x) in the buffer does not match the expected(%02x)\n", pbuf_mgmt->buffer[i], BLE_LOG_CP_CONTENT_CHECK_VAL);
|
||||
@@ -121,8 +122,7 @@ static inline int ble_log_cp_push_u16(ble_cp_log_buffer_mgmt_t *pbuf_mgmt, uint1
|
||||
if (ble_log_cp_buffer_safe_check(pbuf_mgmt, 2)) {
|
||||
return -1;
|
||||
}
|
||||
uint16_t *p = (uint16_t *)&(pbuf_mgmt->buffer[pbuf_mgmt->idx]);
|
||||
*p = val;
|
||||
memcpy(&(pbuf_mgmt->buffer[pbuf_mgmt->idx]), &val, sizeof(val));
|
||||
pbuf_mgmt->idx+=2;
|
||||
return 0;
|
||||
}
|
||||
@@ -132,8 +132,7 @@ static inline int ble_log_cp_push_u32(ble_cp_log_buffer_mgmt_t *pbuf_mgmt, uint3
|
||||
if (ble_log_cp_buffer_safe_check(pbuf_mgmt, 4)) {
|
||||
return -1;
|
||||
}
|
||||
uint32_t *p = (uint32_t *)&(pbuf_mgmt->buffer[pbuf_mgmt->idx]);
|
||||
*p = val;
|
||||
memcpy(&(pbuf_mgmt->buffer[pbuf_mgmt->idx]), &val, sizeof(val));
|
||||
pbuf_mgmt->idx+=4;
|
||||
return 0;
|
||||
}
|
||||
@@ -143,8 +142,7 @@ static inline int ble_log_cp_push_u64(ble_cp_log_buffer_mgmt_t *pbuf_mgmt, uint6
|
||||
if (ble_log_cp_buffer_safe_check(pbuf_mgmt, 8)) {
|
||||
return -1;
|
||||
}
|
||||
uint64_t *p = (uint64_t *)&(pbuf_mgmt->buffer[pbuf_mgmt->idx]);
|
||||
*p = val;
|
||||
memcpy(&(pbuf_mgmt->buffer[pbuf_mgmt->idx]), &val, sizeof(val));
|
||||
pbuf_mgmt->idx+=8;
|
||||
return 0;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user