mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(ble_log): fix unaligned access and buffer safety in log compression
This commit is contained in:
@@ -74,7 +74,7 @@ int ble_compressed_log_cb_get(uint8_t source, ble_cp_log_buffer_mgmt_t **mgmt)
|
|||||||
#endif
|
#endif
|
||||||
default:
|
default:
|
||||||
assert(0 && "Unsupported log source");
|
assert(0 && "Unsupported log source");
|
||||||
break;
|
return -1;
|
||||||
}
|
}
|
||||||
|
|
||||||
for (int i = 0; i < LOG_CP_MAX_LOG_BUFFER_USED_SIMU; i++) {
|
for (int i = 0; i < LOG_CP_MAX_LOG_BUFFER_USED_SIMU; i++) {
|
||||||
@@ -95,7 +95,7 @@ int ble_compressed_log_cb_get(uint8_t source, ble_cp_log_buffer_mgmt_t **mgmt)
|
|||||||
|
|
||||||
static inline int ble_compressed_log_buffer_free(ble_cp_log_buffer_mgmt_t *mgmt)
|
static inline int ble_compressed_log_buffer_free(ble_cp_log_buffer_mgmt_t *mgmt)
|
||||||
{
|
{
|
||||||
#if BLE_LOG_CP_CONTENT_CHECK_ENBALE
|
#if BLE_LOG_CP_CONTENT_CHECK_ENABLE
|
||||||
memset(mgmt->buffer, BLE_LOG_CP_CONTENT_CHECK_VAL, mgmt->idx);
|
memset(mgmt->buffer, BLE_LOG_CP_CONTENT_CHECK_VAL, mgmt->idx);
|
||||||
#endif
|
#endif
|
||||||
mgmt->idx = 0;
|
mgmt->idx = 0;
|
||||||
@@ -107,6 +107,11 @@ static inline
|
|||||||
int ble_log_compressed_hex_print_internal(ble_cp_log_buffer_mgmt_t *mgmt, uint32_t log_index, size_t args_cnt, va_list args)
|
int ble_log_compressed_hex_print_internal(ble_cp_log_buffer_mgmt_t *mgmt, uint32_t log_index, size_t args_cnt, va_list args)
|
||||||
{
|
{
|
||||||
uint8_t arg_type = 0;
|
uint8_t arg_type = 0;
|
||||||
|
uint16_t header_size = 1 + 2 + (args_cnt + 1) / 2; // header + log_index + size_info
|
||||||
|
|
||||||
|
if (ble_log_cp_buffer_safe_check(mgmt, header_size)) {
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
|
||||||
ble_log_cp_push_u8(mgmt, LOG_HEADER(LOG_TYPE_HEX_ARGS, args_cnt));
|
ble_log_cp_push_u8(mgmt, LOG_HEADER(LOG_TYPE_HEX_ARGS, args_cnt));
|
||||||
ble_log_cp_push_u16(mgmt, log_index);
|
ble_log_cp_push_u16(mgmt, log_index);
|
||||||
@@ -200,9 +205,12 @@ int ble_log_compressed_hex_print_internal(ble_cp_log_buffer_mgmt_t *mgmt, uint32
|
|||||||
ble_log_cp_push_u8(mgmt, (uint8_t)tmpv);
|
ble_log_cp_push_u8(mgmt, (uint8_t)tmpv);
|
||||||
ble_log_cp_push_u16(mgmt, (uint16_t)(tmpv >> 8));
|
ble_log_cp_push_u16(mgmt, (uint16_t)(tmpv >> 8));
|
||||||
break;
|
break;
|
||||||
|
case 4:
|
||||||
|
BLE_CP_TRY_PUSH(ble_log_cp_push_u32(mgmt, (uint32_t)u64v));
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
assert(0);
|
assert(0);
|
||||||
break;
|
return -1;
|
||||||
}
|
}
|
||||||
ble_log_cp_update_half_byte(mgmt, size_info_idx + i/2, ARG_SIZE_TYPE_LZU64, !(i%2));
|
ble_log_cp_update_half_byte(mgmt, size_info_idx + i/2, ARG_SIZE_TYPE_LZU64, !(i%2));
|
||||||
}
|
}
|
||||||
@@ -212,12 +220,16 @@ int ble_log_compressed_hex_print_internal(ble_cp_log_buffer_mgmt_t *mgmt, uint32
|
|||||||
break;
|
break;
|
||||||
case ARG_SIZE_TYPE_STR:
|
case ARG_SIZE_TYPE_STR:
|
||||||
char *str_p = (char *)va_arg(args, char *);
|
char *str_p = (char *)va_arg(args, char *);
|
||||||
ble_log_cp_push_buf(mgmt, (const uint8_t *)str_p, strlen(str_p) + 1);
|
if (str_p) {
|
||||||
|
BLE_CP_TRY_PUSH(ble_log_cp_push_buf(mgmt, (const uint8_t *)str_p, strlen(str_p) + 1));
|
||||||
|
} else {
|
||||||
|
BLE_CP_TRY_PUSH(ble_log_cp_push_buf(mgmt, (const uint8_t *)"(null str)", sizeof("(null str)")));
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
printf("Invalid size %d\n", arg_type);
|
printf("Invalid size %d\n", arg_type);
|
||||||
assert(0);
|
assert(0);
|
||||||
break;
|
return -1;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
return 0;
|
return 0;
|
||||||
@@ -268,7 +280,11 @@ int ble_log_compressed_hex_print_buf(uint8_t source, uint32_t log_index, uint8_t
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
<<<<<<< HEAD
|
||||||
if (buf == NULL && len != 0) {
|
if (buf == NULL && len != 0) {
|
||||||
|
=======
|
||||||
|
if (buf == NULL) {
|
||||||
|
>>>>>>> 3f2b6c97f86 (fix(ble_log): fix unaligned access and buffer safety in log compression)
|
||||||
ble_log_cp_push_u8(mgmt, LOG_HEADER(LOG_TYPE_INFO, LOG_TYPE_INFO_NULL_BUF));
|
ble_log_cp_push_u8(mgmt, LOG_HEADER(LOG_TYPE_INFO, LOG_TYPE_INFO_NULL_BUF));
|
||||||
ble_log_cp_push_u16(mgmt, log_index);
|
ble_log_cp_push_u16(mgmt, log_index);
|
||||||
ble_compressed_log_output(source, mgmt->buffer, mgmt->idx);
|
ble_compressed_log_output(source, mgmt->buffer, mgmt->idx);
|
||||||
|
|||||||
+7
-9
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2025 Espressif Systems (Shanghai) CO LTD
|
* SPDX-FileCopyrightText: 2025-2026 Espressif Systems (Shanghai) CO LTD
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: Apache-2.0
|
* SPDX-License-Identifier: Apache-2.0
|
||||||
*/
|
*/
|
||||||
@@ -8,6 +8,7 @@
|
|||||||
|
|
||||||
#include "ble_log.h"
|
#include "ble_log.h"
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
|
#include <string.h>
|
||||||
|
|
||||||
#define CONCAT(a, b) a##b
|
#define CONCAT(a, b) a##b
|
||||||
#define _CONCAT(a, b) CONCAT(a, b)
|
#define _CONCAT(a, b) CONCAT(a, b)
|
||||||
@@ -86,7 +87,7 @@ typedef struct {
|
|||||||
#define CONTENT_CHECK(idx, buf, except_val, len)
|
#define CONTENT_CHECK(idx, buf, except_val, len)
|
||||||
#define LENGTH_CHECK(idx, pbuffer_mgmt) do ( if(unlikely((idx) > (pbuffer_mgmt->len))) assert(0 && "Maximum log buffer length exceeded");) while(0)
|
#define LENGTH_CHECK(idx, pbuffer_mgmt) do ( if(unlikely((idx) > (pbuffer_mgmt->len))) assert(0 && "Maximum log buffer length exceeded");) while(0)
|
||||||
|
|
||||||
#define BLE_LOG_CP_CONTENT_CHECK_ENBALE 0
|
#define BLE_LOG_CP_CONTENT_CHECK_ENABLE 0
|
||||||
#define BLE_LOG_CP_CONTENT_CHECK_VAL 0x00
|
#define BLE_LOG_CP_CONTENT_CHECK_VAL 0x00
|
||||||
|
|
||||||
static inline int ble_log_cp_buffer_safe_check(ble_cp_log_buffer_mgmt_t *pbuf_mgmt, uint16_t write_len)
|
static inline int ble_log_cp_buffer_safe_check(ble_cp_log_buffer_mgmt_t *pbuf_mgmt, uint16_t write_len)
|
||||||
@@ -95,7 +96,7 @@ static inline int ble_log_cp_buffer_safe_check(ble_cp_log_buffer_mgmt_t *pbuf_mg
|
|||||||
printf("Maximum length of buffer(%p) idx %d write_len %d exceed\n", pbuf_mgmt, pbuf_mgmt->idx, write_len);
|
printf("Maximum length of buffer(%p) idx %d write_len %d exceed\n", pbuf_mgmt, pbuf_mgmt->idx, write_len);
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
#if BLE_LOG_CP_CONTENT_CHECK_ENBALE
|
#if BLE_LOG_CP_CONTENT_CHECK_ENABLE
|
||||||
for (int i = pbuf_mgmt->idx; i < pbuf_mgmt->idx + write_len; i++) {
|
for (int i = pbuf_mgmt->idx; i < pbuf_mgmt->idx + write_len; i++) {
|
||||||
if (pbuf_mgmt->buffer[i] != BLE_LOG_CP_CONTENT_CHECK_VAL) {
|
if (pbuf_mgmt->buffer[i] != BLE_LOG_CP_CONTENT_CHECK_VAL) {
|
||||||
printf("The value(%02x) in the buffer does not match the expected(%02x)\n", pbuf_mgmt->buffer[i], BLE_LOG_CP_CONTENT_CHECK_VAL);
|
printf("The value(%02x) in the buffer does not match the expected(%02x)\n", pbuf_mgmt->buffer[i], BLE_LOG_CP_CONTENT_CHECK_VAL);
|
||||||
@@ -121,8 +122,7 @@ static inline int ble_log_cp_push_u16(ble_cp_log_buffer_mgmt_t *pbuf_mgmt, uint1
|
|||||||
if (ble_log_cp_buffer_safe_check(pbuf_mgmt, 2)) {
|
if (ble_log_cp_buffer_safe_check(pbuf_mgmt, 2)) {
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
uint16_t *p = (uint16_t *)&(pbuf_mgmt->buffer[pbuf_mgmt->idx]);
|
memcpy(&(pbuf_mgmt->buffer[pbuf_mgmt->idx]), &val, sizeof(val));
|
||||||
*p = val;
|
|
||||||
pbuf_mgmt->idx+=2;
|
pbuf_mgmt->idx+=2;
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
@@ -132,8 +132,7 @@ static inline int ble_log_cp_push_u32(ble_cp_log_buffer_mgmt_t *pbuf_mgmt, uint3
|
|||||||
if (ble_log_cp_buffer_safe_check(pbuf_mgmt, 4)) {
|
if (ble_log_cp_buffer_safe_check(pbuf_mgmt, 4)) {
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
uint32_t *p = (uint32_t *)&(pbuf_mgmt->buffer[pbuf_mgmt->idx]);
|
memcpy(&(pbuf_mgmt->buffer[pbuf_mgmt->idx]), &val, sizeof(val));
|
||||||
*p = val;
|
|
||||||
pbuf_mgmt->idx+=4;
|
pbuf_mgmt->idx+=4;
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
@@ -143,8 +142,7 @@ static inline int ble_log_cp_push_u64(ble_cp_log_buffer_mgmt_t *pbuf_mgmt, uint6
|
|||||||
if (ble_log_cp_buffer_safe_check(pbuf_mgmt, 8)) {
|
if (ble_log_cp_buffer_safe_check(pbuf_mgmt, 8)) {
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
uint64_t *p = (uint64_t *)&(pbuf_mgmt->buffer[pbuf_mgmt->idx]);
|
memcpy(&(pbuf_mgmt->buffer[pbuf_mgmt->idx]), &val, sizeof(val));
|
||||||
*p = val;
|
|
||||||
pbuf_mgmt->idx+=8;
|
pbuf_mgmt->idx+=8;
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user