mirror of
https://github.com/apache/nuttx.git
synced 2026-09-28 18:13:53 +00:00
wireless/bluetooth: Reject GATT operations on unconnected peers.
The GATT ioctls looked up a connection by address and then checked only that a connection object existed, not that it had reached CONNECTED. While a connection is still being established conn->att is NULL, and bt_att_create_pdu() dereferenced it to read the ATT MTU, so issuing SIOCBTEXCHANGE, SIOCBTDISCOVER, SIOCBTGATTRD or SIOCBTGATTWR for a peer that is merely pending faulted. Any task with access to the network device can reach that path, and in PROTECTED and KERNEL builds the fault is taken in the kernel on behalf of user code. Require CONNECTED in those four ioctls, releasing the reference the lookup took, and make bt_att_create_pdu() return NULL when there is no ATT context instead of relying on every caller having checked first. Testing: builds for sim:bluetooth with Make; every commit in this series verified to build individually. On sim:bluetooth with CONFIG_BTSAK=y: nsh> ifup bnep0 ifup bnep0...OK nsh> bt bnep0 gatt connect 11:22:33:44:55:66 public Connect pending... nsh> bt bnep0 gatt exchange-mtu 11:22:33:44:55:66 public ERROR: ioctl(SIOCBTEXCHANGE) failed: 107 107 is ENOTCONN, and the shell continues to run; before this change the same sequence terminated the simulator in bt_att_create_pdu(). Signed-off-by: Alan C. Assis <acassis@gmail.com> Assisted-by: Claude Code Opus 5
This commit is contained in:
parent
a6cab8293d
commit
a73bea0653
2 changed files with 94 additions and 58 deletions
|
|
@ -870,15 +870,15 @@ static bool uuid_create(FAR struct bt_uuid_s *uuid,
|
|||
|
||||
switch (data->len)
|
||||
{
|
||||
case 2:
|
||||
uuid->type = BT_UUID_16;
|
||||
uuid->u.u16 = bt_buf_get_le16(data);
|
||||
return true;
|
||||
case 2:
|
||||
uuid->type = BT_UUID_16;
|
||||
uuid->u.u16 = bt_buf_get_le16(data);
|
||||
return true;
|
||||
|
||||
case 16:
|
||||
uuid->type = BT_UUID_128;
|
||||
memcpy(uuid->u.u128, data->data, data->len);
|
||||
return true;
|
||||
case 16:
|
||||
uuid->type = BT_UUID_128;
|
||||
memcpy(uuid->u.u128, data->data, data->len);
|
||||
return true;
|
||||
}
|
||||
|
||||
return false;
|
||||
|
|
@ -1022,14 +1022,14 @@ static uint8_t err_to_att(int err)
|
|||
|
||||
switch (err)
|
||||
{
|
||||
case -EINVAL:
|
||||
return BT_ATT_ERR_INVALID_OFFSET;
|
||||
case -EINVAL:
|
||||
return BT_ATT_ERR_INVALID_OFFSET;
|
||||
|
||||
case -EFBIG:
|
||||
return BT_ATT_ERR_INVALID_ATTRIBUTE_LEN;
|
||||
case -EFBIG:
|
||||
return BT_ATT_ERR_INVALID_ATTRIBUTE_LEN;
|
||||
|
||||
default:
|
||||
return BT_ATT_ERR_UNLIKELY;
|
||||
default:
|
||||
return BT_ATT_ERR_UNLIKELY;
|
||||
}
|
||||
}
|
||||
|
||||
|
|
@ -1871,6 +1871,16 @@ FAR struct bt_buf_s *bt_att_create_pdu(FAR struct bt_conn_s *conn,
|
|||
FAR struct bt_buf_s *buf;
|
||||
FAR struct bt_att_s *att = conn->att;
|
||||
|
||||
/* There is no ATT context until the connection is established, and it
|
||||
* is released again on disconnect.
|
||||
*/
|
||||
|
||||
if (att == NULL)
|
||||
{
|
||||
wlwarn("No ATT context for handle %u\n", conn->handle);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (len + sizeof(op) > att->mtu)
|
||||
{
|
||||
wlwarn("ATT MTU exceeded, max %u, wanted %zu\n", att->mtu, len);
|
||||
|
|
|
|||
|
|
@ -490,6 +490,7 @@ int btnet_ioctl(FAR struct net_driver_s *netdev, int cmd, unsigned long arg)
|
|||
case SIOCBTCONNECT:
|
||||
{
|
||||
FAR struct bt_conn_s *conn;
|
||||
|
||||
conn = bt_conn_create_le(&btreq->btr_rmtpeer);
|
||||
|
||||
if (!conn)
|
||||
|
|
@ -538,55 +539,55 @@ int btnet_ioctl(FAR struct net_driver_s *netdev, int cmd, unsigned long arg)
|
|||
}
|
||||
break;
|
||||
|
||||
/* SIOCGBTINFO: Get Bluetooth device Info. Given the device name,
|
||||
* fill in the btreq_s structure.
|
||||
*
|
||||
* REVISIT: Little more than a stub at present. It does return the
|
||||
* device address associated with the device name which in itself is
|
||||
* important.
|
||||
*/
|
||||
/* SIOCGBTINFO: Get Bluetooth device Info. Given the device name,
|
||||
* fill in the btreq_s structure.
|
||||
*
|
||||
* REVISIT: Little more than a stub at present. It does return the
|
||||
* device address associated with the device name which in itself is
|
||||
* important.
|
||||
*/
|
||||
|
||||
case SIOCGBTINFO:
|
||||
{
|
||||
memset(&btreq->btru.btri, 0, sizeof(btreq->btru.btri));
|
||||
BLUETOOTH_ADDRCOPY(btreq->btr_bdaddr.val, g_btdev.bdaddr.val);
|
||||
btreq->btr_num_cmd = CONFIG_BLUETOOTH_BUFFER_PREALLOC;
|
||||
btreq->btr_num_acl = CONFIG_BLUETOOTH_BUFFER_PREALLOC;
|
||||
btreq->btr_acl_mtu = BLUETOOTH_MAX_MTU;
|
||||
btreq->btr_sco_mtu = BLUETOOTH_MAX_MTU;
|
||||
btreq->btr_max_acl = CONFIG_IOB_NBUFFERS;
|
||||
ret = OK;
|
||||
}
|
||||
break;
|
||||
case SIOCGBTINFO:
|
||||
{
|
||||
memset(&btreq->btru.btri, 0, sizeof(btreq->btru.btri));
|
||||
BLUETOOTH_ADDRCOPY(btreq->btr_bdaddr.val, g_btdev.bdaddr.val);
|
||||
btreq->btr_num_cmd = CONFIG_BLUETOOTH_BUFFER_PREALLOC;
|
||||
btreq->btr_num_acl = CONFIG_BLUETOOTH_BUFFER_PREALLOC;
|
||||
btreq->btr_acl_mtu = BLUETOOTH_MAX_MTU;
|
||||
btreq->btr_sco_mtu = BLUETOOTH_MAX_MTU;
|
||||
btreq->btr_max_acl = CONFIG_IOB_NBUFFERS;
|
||||
ret = OK;
|
||||
}
|
||||
break;
|
||||
|
||||
/* SIOCGBTFEAT
|
||||
* Get Bluetooth BR/BDR device Features. This returns the cached
|
||||
* basic (page 0) and extended (page 1 & 2) features. Only page 0
|
||||
* is valid.
|
||||
* SIOCGBTLEFEAT
|
||||
* Get Bluetooth LE device Features. This returns the cached page
|
||||
* 0-2 features. Only page 0 is value.
|
||||
*/
|
||||
/* SIOCGBTFEAT
|
||||
* Get Bluetooth BR/BDR device Features. This returns the cached
|
||||
* basic (page 0) and extended (page 1 & 2) features. Only page 0
|
||||
* is valid.
|
||||
* SIOCGBTLEFEAT
|
||||
* Get Bluetooth LE device Features. This returns the cached page
|
||||
* 0-2 features. Only page 0 is value.
|
||||
*/
|
||||
|
||||
case SIOCGBTFEAT:
|
||||
case SIOCGBTLEFEAT:
|
||||
{
|
||||
FAR const uint8_t *src;
|
||||
case SIOCGBTFEAT:
|
||||
case SIOCGBTLEFEAT:
|
||||
{
|
||||
FAR const uint8_t *src;
|
||||
|
||||
memset(&btreq->btru.btrf, 0, sizeof(btreq->btru.btrf));
|
||||
if (cmd == SIOCGBTFEAT)
|
||||
{
|
||||
src = g_btdev.features;
|
||||
}
|
||||
else
|
||||
{
|
||||
src = g_btdev.le_features;
|
||||
}
|
||||
memset(&btreq->btru.btrf, 0, sizeof(btreq->btru.btrf));
|
||||
if (cmd == SIOCGBTFEAT)
|
||||
{
|
||||
src = g_btdev.features;
|
||||
}
|
||||
else
|
||||
{
|
||||
src = g_btdev.le_features;
|
||||
}
|
||||
|
||||
memcpy(btreq->btr_features0, src, 8);
|
||||
ret = OK;
|
||||
}
|
||||
break;
|
||||
memcpy(btreq->btr_features0, src, 8);
|
||||
ret = OK;
|
||||
}
|
||||
break;
|
||||
|
||||
/* SIOCBTADVSTART: Set advertisement data, scan response data,
|
||||
* advertisement parameters and start advertising.
|
||||
|
|
@ -718,6 +719,12 @@ int btnet_ioctl(FAR struct net_driver_s *netdev, int cmd, unsigned long arg)
|
|||
wlwarn("WARNING: Peer not connected\n");
|
||||
ret = -ENOTCONN;
|
||||
}
|
||||
else if (conn->state != BT_CONN_CONNECTED)
|
||||
{
|
||||
wlwarn("WARNING: Peer connection not established\n");
|
||||
bt_conn_release(conn);
|
||||
ret = -ENOTCONN;
|
||||
}
|
||||
else
|
||||
{
|
||||
struct btnet_wrstate_s wrstate;
|
||||
|
|
@ -762,10 +769,17 @@ int btnet_ioctl(FAR struct net_driver_s *netdev, int cmd, unsigned long arg)
|
|||
wlwarn("WARNING: Peer not connected\n");
|
||||
ret = -ENOTCONN;
|
||||
}
|
||||
else if (conn->state != BT_CONN_CONNECTED)
|
||||
{
|
||||
wlwarn("WARNING: Peer connection not established\n");
|
||||
bt_conn_release(conn);
|
||||
ret = -ENOTCONN;
|
||||
}
|
||||
else
|
||||
{
|
||||
struct btnet_discoverstate_s dstate;
|
||||
FAR struct bt_gatt_discover_params_s *params;
|
||||
|
||||
memset(&dstate, 0, sizeof(dstate));
|
||||
|
||||
/* Set up the query */
|
||||
|
|
@ -848,6 +862,12 @@ int btnet_ioctl(FAR struct net_driver_s *netdev, int cmd, unsigned long arg)
|
|||
wlwarn("WARNING: Peer not connected\n");
|
||||
ret = -ENOTCONN;
|
||||
}
|
||||
else if (conn->state != BT_CONN_CONNECTED)
|
||||
{
|
||||
wlwarn("WARNING: Peer connection not established\n");
|
||||
bt_conn_release(conn);
|
||||
ret = -ENOTCONN;
|
||||
}
|
||||
else
|
||||
{
|
||||
/* Set up for the read */
|
||||
|
|
@ -919,6 +939,12 @@ int btnet_ioctl(FAR struct net_driver_s *netdev, int cmd, unsigned long arg)
|
|||
wlwarn("WARNING: Peer not connected\n");
|
||||
ret = -ENOTCONN;
|
||||
}
|
||||
else if (conn->state != BT_CONN_CONNECTED)
|
||||
{
|
||||
wlwarn("WARNING: Peer connection not established\n");
|
||||
bt_conn_release(conn);
|
||||
ret = -ENOTCONN;
|
||||
}
|
||||
else
|
||||
{
|
||||
/* Set up for the write */
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue