mirror of
https://github.com/espressif/esp-idf.git
synced 2026-09-27 16:56:43 +03:00
Fix multiple wire-format and robustness issues in the DFD client (dfd_cli.c): - handle_capabilities: read oob_retrieval_supported as u8 instead of le32. The server encodes a single byte; le32 over-consumed 3 bytes of the URL scheme list and could over-read the buffer. - handle_upload_status: extract upload_progress from bits 0-6 (& 0x7F) and upload_type from bit 7 (>> 7), matching the server encoding (progress | BIT(7)). The previous >>1 / &0x01 returned wrong values, mis-classified in-band vs OOB, and falsely rejected valid OOB messages with high progress. - handle_dfd_status: correct the transfer-mode byte layout to trans_mode bits 0-1, update_policy bit 2, RFU bits 3-7 (previously read bits 6-7 / 5), and fix the RFU mask to 0xF8. Now matches the struct bitfield definition and the DFD server. - handle_dfd_status: report status+phase and return early when buf->len == 0 (IDLE phase) instead of pulling 10 absent bytes. - bt_mesh_dfd_cli_distribution_start: encode trans_mode/update_policy into bits 0-2 so the server decodes them correctly. - handle_receiver_list: validate buf->len >= entries_cnt * 5 before the loop, and handle entries_cnt == 0 without relying on calloc(0). - handle_receiver_status: pass the status value (not the whole union) to the %d log format, fixing undefined behavior. - dfd_client_recv_status: drop the dead BLE_MESH_DFD_OP_CAPABILITIES_GET case (a client-send opcode) from the receive switch. - bt_mesh_dfd_cli_receivers_add: widen msg_length to uint32_t to avoid uint16_t overflow that bypassed the PDU size guard; add a NULL check for the receivers array. - bt_mesh_dfd_cli_distribution_upload_oob_start: return -EINVAL instead of -1 for consistency with the rest of the file.