Commit graph

178 commits

Author SHA1 Message Date
Alan Carvalho de Assis
843cf6d581 wireless/bluetooth: Validate Number Of Completed Packets event.
Two problems in hci_num_completed_packets().

Number_of_Handles is a single octet, but it was read with BT_LE162HOST(),
which takes the first octet of the handle that follows it as the high
byte.  A one-octet field could therefore produce a loop count of up to
65535.

The loop was then bounded only by that count and not by the data that was
actually received, so it walked past the end of the event, reading handle
and count pairs out of whatever followed it.

Read the field at its declared width, and require the pairs the event
claims to have been received before reading them.

Per-connection credit accounting, which this handler still does not do,
is a separate change.

Ref: Core v6.0, Vol 4, Part E, 7.7.19 (Number Of Completed Packets event)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-25 10:35:51 +02:00
Alan Carvalho de Assis
a73bea0653 wireless/bluetooth: Reject GATT operations on unconnected peers.
The GATT ioctls looked up a connection by address and then checked only
that a connection object existed, not that it had reached CONNECTED.
While a connection is still being established conn->att is NULL, and
bt_att_create_pdu() dereferenced it to read the ATT MTU, so issuing
SIOCBTEXCHANGE, SIOCBTDISCOVER, SIOCBTGATTRD or SIOCBTGATTWR for a peer
that is merely pending faulted.  Any task with access to the network
device can reach that path, and in PROTECTED and KERNEL builds the fault
is taken in the kernel on behalf of user code.

Require CONNECTED in those four ioctls, releasing the reference the
lookup took, and make bt_att_create_pdu() return NULL when there is no
ATT context instead of relying on every caller having checked first.

Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.  On sim:bluetooth with CONFIG_BTSAK=y:

  nsh> ifup bnep0
  ifup bnep0...OK
  nsh> bt bnep0 gatt connect 11:22:33:44:55:66 public
  Connect pending...
  nsh> bt bnep0 gatt exchange-mtu 11:22:33:44:55:66 public
  ERROR:  ioctl(SIOCBTEXCHANGE) failed: 107

107 is ENOTCONN, and the shell continues to run; before this change the
same sequence terminated the simulator in bt_att_create_pdu().

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-24 09:51:44 +02:00
Alan Carvalho de Assis
c728586a48 wireless/bluetooth: Validate event length before parsing HCI events.
hci_event() consumed the event header and dispatched on the event code
without checking that a header had been received, and hci_le_meta_event()
did the same for the subevent code.  Each handler then cast the remaining
buffer to its event structure and read fields out of it, so a short event
was parsed from whatever followed it in memory - including the fields
that identify a connection and carry its encryption state.

Check that the header is present before reading it, that the parameters
the event declares were actually received, and that enough parameters
remain for the structure the selected handler casts to.  Events failing a
check are dropped with a diagnostic rather than parsed.

le_adv_report() continues to do its own checking, because the report
count and the per-report lengths vary within that event.

Ref: Core v6.0, Vol 4, Part E, 5.4.4 (HCI Event packets)
Ref: Core v6.0, Vol 4, Part E, 7.7 (Events)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.  Not yet exercised at runtime - the
scriptable controller injects truncated events separately.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-23 08:58:44 -03:00
Alan Carvalho de Assis
6d04a124c2 wireless/bluetooth: Fix bad aligment
This PR fixes the bad aligment reported by nxstyle.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
2026-09-22 10:07:09 -03:00
Alan Carvalho de Assis
9d12f6ccc6 wireless/bluetooth: Validate the L2CAP header on the first ACL fragment.
bt_conn_receive() read the 4-octet L2CAP header out of the first fragment
of a PDU without checking that 4 octets had been received, and then
computed the outstanding length by subtracting the fragment length from
the declared PDU length.

Two problems follow.  A fragment shorter than the header was parsed from
whatever happened to follow it in the buffer.  And a fragment carrying
more data than the PDU it declares made the subtraction wrap, because
conn->rx_len is 16 bits: the connection was then left expecting up to
65535 further octets, holding the partial PDU and accumulating later
fragments against an expectation that could never be satisfied.

Check that the fragment is long enough to hold a header before reading
it, and that it does not exceed the PDU it declares before computing what
remains.  Drop the fragment and reset the reassembly state otherwise.

Ref: Core v6.0, Vol 3, Part A, 3.1 (B-frame format)
Ref: Core v6.0, Vol 4, Part E, 5.4.2 (HCI ACL Data packets)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.  Not yet exercised at runtime - the
scriptable controller adds the truncated and oversized fragment cases
separately.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-22 10:07:09 -03:00
Alan Carvalho de Assis
5ec51ae6d5 wireless/bluetooth: Validate lengths when parsing advertising reports.
le_adv_report() took the report count and each report's data length from
the event and used them without checking either against the data that was
actually received:

  - the declared data length indexes the RSSI octet, so a length larger
    than the event reads past the end of the buffer;
  - the loop was bounded only by the report count, so a count larger than
    the payload walks off the end of it;
  - bt_buf_consume() only checks its bound with DEBUGASSERT(), so on a
    build without assertions the buffer length underflows rather than
    reporting the problem.

Check that the event is long enough for the count, then check each report
against the remaining length before reading its data or its RSSI, and
stop parsing when a report does not fit.

While here, include the RSSI octet when advancing to the next report.
sizeof() of the report structure does not account for it, because the
data member is a zero-length array, so every report after the first
started one octet early.

Ref: Core v6.0, Vol 4, Part E, 7.7.65.2 (LE Advertising Report event)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.  Not yet exercised at runtime - the
scriptable controller that can inject a malformed report is added
separately.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-19 18:30:43 -03:00
Alan Carvalho de Assis
c95c546c09 wireless/bluetooth: Fix record stride in descriptor discovery response.
att_find_info_rsp() computed the per-record stride with sizeof(info.i16)
and sizeof(info.i128), but "info" is a union of two pointers, so both
expressions evaluate to the pointer width instead of the size of the
record that the response format selects.  The records are 4 octets for a
16-bit UUID and 18 octets for a 128-bit UUID, so the 128-bit path
advanced by 4 (or 8) octets per iteration while reading an 18-octet
record: handles and UUIDs were parsed from the wrong offsets and the walk
ran past the end of the received PDU.  On 64-bit builds the 16-bit path
was wrong too.

Take the stride from the record structures, and require the response to
carry whole records before walking it, since the loop advances one record
at a time and a partial trailing record would be parsed as a whole one.

Ref: Core v6.0, Vol 3, Part F, 3.4.3.2 (ATT_FIND_INFORMATION_RSP)
Testing: sim:bluetooth builds with Make, no new warnings.  Not yet
exercised at runtime; the scriptable controller that can inject a
malformed Find Information Response is added separately.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-18 11:18:36 +08:00
AlmAck
5e92a05dc4 wireless/bluetooth: fix inverted MTU cap in bt_conn_send()
bt_conn_send() splits an outgoing L2CAP PDU into HCI ACL fragments no
larger than g_btdev.le_mtu, the controller's HCI ACL data packet length.
The first fragment caps its length correctly:

  len = remaining;
  if (len > g_btdev.le_mtu)
    {
      len = g_btdev.le_mtu;
    }

The continuation loop below uses '<' instead of '>', so a continuation
shorter than le_mtu has its length raised to le_mtu rather than left
alone.  Both len and remaining are uint16_t, which turns a wrong length
into an underflow:

With le_mtu 251 and a 300-byte PDU, the first fragment takes 251 bytes
and leaves remaining == 49.  The loop then raises len from 49 to 251, so

  memcpy(bt_buf_extend(buf, len), ptr, len);

reads 202 bytes past the end of the source, and

  remaining -= len;

evaluates 49 - 251 as a uint16_t, wrapping to 65334.  On the next
iteration len is 65334, which is not less than le_mtu, so it survives
the cap.  bt_buf_extend() carries only a DEBUGASSERT on tailroom, so
with assertions disabled it adds 65334 to buf->len and returns, and the
memcpy writes 64 KB into a pooled buffer sized for a few hundred bytes.

Only the last fragment of a multi-fragment PDU is normally shorter than
le_mtu, so the first fragmented transmission triggers it.

Signed-off-by: AlmAck <gluca86@gmail.com>
2026-08-30 10:48:18 -03:00
zhangyu117
d7771b6158 nuttx/atomic: replace atomic_fetch_xxx with atomic_xxx just like zephyr
Rename atomic_fetch_add/sub/or/and/xor to atomic_add/sub/or/and/xor
to avoid conflicts with the C/C++ standard library naming. The
atomic_fetch_xxx naming is reserved by the standard; keeping it causes
function name conflicts when source files indirectly include both
<nuttx/atomic.h> and <atomic>/<stdatomic.h>.

Signed-off-by: zhangyu117 <zhangyu117@xiaomi.com>
2026-08-24 13:20:45 +08:00
AbhinavMir
a79734d6df wireless/bluetooth/bt_hcicore.c: Balance conn and buffer refs in hci_acl().
Some checks are pending
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
hci_acl() looked up the connection with bt_conn_lookup_handle(), which
returns a new reference, but never released it. This leaked one conn
reference for every received ACL packet.

bt_conn_receive() also consumes the buffer on every path: it forwards
to l2cap (which releases) or stores the buffer in conn->rx without an
addref. The hci_rx_work() worker then called bt_buf_release() on the
same buffer, which caused a double free or use-after-free.

Take an extra buffer reference for the worker to release, and release
the connection reference from the lookup.

Assisted-by: Fable
Signed-off-by: AbhinavMir <atg271@gmail.com>
2026-08-15 11:51:19 +08:00
Piyush Patle
0dccc8ba21 include/debug.h: Move to include/nuttx/debug.h
debug.h is a NuttX-specific, non-POSIX header. Placing it in the
top-level include/ directory creates naming conflicts with external
projects that define their own debug.h.
This commit moves the canonical header to include/nuttx/debug.h,
following the NuttX convention for non-POSIX/non-standard headers,
and updates all in-tree references.

A backward-compatibility shim is left at include/debug.h that
emits a deprecation #warning and re-includes <nuttx/debug.h>,
allowing out-of-tree code to continue building while migrating.

Signed-off-by: Piyush Patle <piyushpatle228@gmail.com>
2026-04-07 07:50:06 -03:00
Huang Qi
e3eeaefd6d style: Fix "the the" typo across the codebase.
Fix 269 occurrences of duplicate "the" word typo found in 209 files
across source code, header files, and configuration.

Signed-off-by: Huang Qi <huangqi3@xiaomi.com>
2026-03-23 11:07:49 +01:00
chao an
87f134cfaa sched/sleep: replace all Signal-based sleep implement to Scheduled sleep
Nuttx currently has 2 types of sleep interfaces:

1. Signal-scheduled sleep: nxsig_sleep() / nxsig_usleep() / nxsig_nanosleep()
Weaknesses:
a. Signal-dependent: The signal-scheduled sleep method is bound to the signal framework, while some driver sleep operations do not depend on signals.
b. Timespec conversion: Signal-scheduled sleep involves timespec conversion, which has a significant impact on performance.

2. Busy sleep: up_mdelay() / up_udelay()
Weaknesses:
a. Does not actively trigger scheduling, occupy the CPU loading.

3. New interfaces: Scheduled sleep: nxsched_sleep() / nxsched_usleep() / nxsched_msleep() / nxsched_ticksleep()
Strengths:
a. Does not depend on the signal framework.
b. Tick-based, without additional computational overhead.

Currently, the Nuttx driver framework extensively uses nxsig_* interfaces. However, the driver does not need to rely on signals or timespec conversion.
Therefore, a new set of APIs is added to reduce dependencies on other modules.

(This PR also aims to make signals optional, further reducing the code size of Nuttx.)

Signed-off-by: chao an <anchao.archer@bytedance.com>
2025-10-17 14:05:02 +08:00
robert
df058b462e Bluetooth SMP: added support for Legacy pairing (MITM) with passkey
#   1: .codespellrc
  #  /home/runner/work/nuttx/nuttx/nuttx/include/nuttx/uorb.h:307: afte ==> after
   # /home/runner/work/nuttx/nuttx/nuttx/include/nuttx/uorb.h:405: multipled ==> multiplied
    #/home/runner/work/nuttx/nuttx/nuttx/include/nuttx/uorb.h:416: multipled ==> multiplied
    #/home/runner/work/nuttx/nuttx/nuttx/include/nuttx/uorb.h:432: provies ==> provides, proves
    #/home/runner/work/nuttx/nuttx/nuttx/include/nuttx/uorb.h:1173: subcribers ==> subscribers
    #Error: Process completed with exit code 1.
2025-05-28 21:49:08 +08:00
Chongqing Lei
05358e6dd0 wireless/bt_hcicore: Fix H4 header and data buffer length verification.
Driver now validates data and H4 header length against CONFIG_IOB_BUFSIZE.

Signed-off-by: Tomasz 'CeDeROM' CEDRO <tomek@cedro.info>
2025-04-11 15:57:53 +08:00
Chongqing Lei
08c239dcd1 wireless/bt_hcicore: Fix buffer type confusion on missing response.
Fix possible stack corruption on missing command response.

Signed-off-by: Tomasz 'CeDeROM' CEDRO <tomek@cedro.info>
2025-04-11 15:57:53 +08:00
hujun5
a31d983161 bluetooth: miss carrier_[on/off] in bt_netdev
fix regression from https://github.com/apache/nuttx/pull/15237

Signed-off-by: hujun5 <hujun5@xiaomi.com>
2025-02-10 09:01:03 +01:00
hujun5
2c69d62c9a bt_buf: use small lock in wireless/bluetooth/bt_buf.c
reason:
We would like to replace the big lock with a small lock.

Signed-off-by: hujun5 <hujun5@xiaomi.com>
2024-12-18 18:11:08 +08:00
hujun5
bc6bf019dd bt_buf: use small lock to protect bt_bufferlist_s
reason:
We would like to replace the big lock with a small lock.

Signed-off-by: hujun5 <hujun5@xiaomi.com>
2024-12-18 18:10:23 +08:00
hujun5
620f4bc32f bluetooth: rm bd_bifup
Signed-off-by: hujun5 <hujun5@xiaomi.com>
2024-12-17 23:31:24 +08:00
zhangyuan29
060fda032b drivers/net: change netdev_lower_quota_load to macro.
Signed-off-by: zhangyuan29 <zhangyuan29@xiaomi.com>
2024-12-05 13:26:22 +08:00
zhangyuan29
dcea1b90e7 arch_atomic: only support atomic_xx and atomic64_xx function
Modify the kernel to use only atomic_xx and atomic64_xx interfaces,
avoiding the use of sizeof or typeof to determine the type of
atomic operations, thereby simplifying the kernel's atomic
interface operations.

Signed-off-by: zhangyuan29 <zhangyuan29@xiaomi.com>
2024-12-04 14:03:14 +01:00
hujun5
5ed007a0f3 bt_atomic: use atomic macro to replace wireless/bluetooth/bt_atomic.c
Signed-off-by: hujun5 <hujun5@xiaomi.com>
2024-12-04 13:54:45 +08:00
robert
5e8f1eefb0 Bluetooth: improved pairing process and host layer now successfully receives ACL packets 2024-11-10 14:33:52 -03:00
chengkai
b66f1147e6 bluetooth: set bt_driver_register/unregister to xx_set/unset
change bt_driver_register/unregister function name to
bt_driver_set/unset, which would be prepared for bt_driver.h

Signed-off-by: chengkai <chengkai@xiaomi.com>
2024-10-17 18:09:32 +08:00
Alin Jerpelea
db49370189 wireless: migrate to SPDX identifier
Most tools used for compliance and SBOM generation use SPDX identifiers
This change brings us a step closer to an easy SBOM generation.

Signed-off-by: Alin Jerpelea <alin.jerpelea@sony.com>
2024-09-11 19:49:34 +08:00
Petro Karashchenko
d499ac9d58 nuttx: fix multiple 'FAR', 'CODE' and style issues
Signed-off-by: Petro Karashchenko <petro.karashchenko@gmail.com>
2024-08-25 19:22:15 +08:00
Xiang Xiao
2e91c07ca7 Remove the back slash from long literal string
since the back slash is only needed for the long macro definition

Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2024-02-19 16:43:15 +01:00
Lwazi Dube
2dac5e1b6a bluetooth: Prevent btsak from repeatedly showing the same error. 2024-01-14 02:16:48 -08:00
Tiago Medicci Serrano
fe156a40e3 wireless/bluetooth: Add option to set the HCI TX thread affinity
By enabling the config `CONFIG_BLUETOOTH_TXCMD_PINNED_TO_CORE` and
setting the value of `CONFIG_BLUETOOTH_TXCMD_CORE`, it's possible
to pin the HCI TX thread to a specific core on a SMP-enabled setup.
This is necessary for devices that require that the function that
sends data (`bt_send`) to be called from a specific core.
2023-10-24 22:41:44 +08:00
wanggang26
c3ccc30f83 wireless: enable O_CLOEXEC explicit
Signed-off-by: wanggang26 <wanggang26@xiaomi.com>
2023-09-19 09:36:59 +08:00
chao an
5026a96cfa nxstyle: cleanup UTF-8 Unicode to ASCII
Signed-off-by: chao an <anchao@xiaomi.com>
2023-09-18 11:54:17 -04:00
chao an
21d2cc741f wireless/bluetooth: correct judgment conditions
Signed-off-by: chao an <anchao@xiaomi.com>
2023-08-07 03:34:00 -07:00
raiden00pl
52d67a85d0 cmake: add missing bt_services.c 2023-07-10 22:24:44 +08:00
chao an
6ee9ec7656 build: add initial cmake build system
1. Update all CMakeLists.txt to adapt to new layout
2. Fix cmake build break
3. Update all new file license
4. Fully compatible with current compilation environment(use configure.sh or cmake as you choose)

------------------

How to test

From within nuttx/. Configure:

cmake -B build -DBOARD_CONFIG=sim/nsh -GNinja
cmake -B build -DBOARD_CONFIG=sim:nsh -GNinja
cmake -B build -DBOARD_CONFIG=sabre-6quad/smp -GNinja
cmake -B build -DBOARD_CONFIG=lm3s6965-ek/qemu-flat -GNinja

(or full path in custom board) :
cmake -B build -DBOARD_CONFIG=$PWD/boards/sim/sim/sim/configs/nsh -GNinja

This uses ninja generator (install with sudo apt install ninja-build). To build:

$ cmake --build build

menuconfig:

$ cmake --build build -t menuconfig

--------------------------

2. cmake/build: reformat the cmake style by cmake-format

https://github.com/cheshirekow/cmake_format

$ pip install cmakelang

$ for i in `find -name CMakeLists.txt`;do cmake-format $i -o $i;done
$ for i in `find -name *\.cmake`;do cmake-format $i -o $i;done

Co-authored-by: Matias N <matias@protobits.dev>
Signed-off-by: chao an <anchao@xiaomi.com>
2023-07-08 13:50:48 +08:00
Lwazi Dube
a720984eb7 wireless/bluetooth: Add a generic access service.
Make NuttX peripheral visible to BLE apps.
2023-06-05 15:00:23 -03:00
chao an
589d4a9f8e net/semantic/parser: fix compile warning found by sparse
Reference:
https://linux.die.net/man/1/sparse

Signed-off-by: chao an <anchao@xiaomi.com>
2023-05-30 23:00:00 +08:00
Petro Karashchenko
1be4066b3c wireless/bluetooth: fix style issues
Signed-off-by: Petro Karashchenko <petro.karashchenko@gmail.com>
2023-05-19 02:40:38 +08:00
Lwazi Dube
16fc1b47b9 wireless/bluetooth: Support removable bluetooth modules.
This bluetooth stack remains in an inconsistent state when
the bluetooth HCI module is removed. This change adds a
bt_netdev_unregister function that can be used to clean up
after a module is removed. Some global variables are also
set to their default values.
2023-05-07 15:03:01 +08:00
Lwazi Dube
0356d1403d wireless/bluetooth: Initialize private bt_driver_s member. 2023-04-30 00:41:22 +08:00
Petro Karashchenko
756e244b18 wireless/bluetooth: fix double buffer free
Signed-off-by: Petro Karashchenko <petro.karashchenko@gmail.com>
2023-04-24 09:35:58 -07:00
chao an
3a0fdb019d nuttx: replace all ARRAY_SIZE()/ARRAYSIZE() to nitems()
Signed-off-by: chao an <anchao@xiaomi.com>
2023-02-09 20:05:44 +08:00
Xiang Xiao
d5689e070b net/arp: Remove nuttx/net/arp.h
1.move ARPHRD_ETHER to netinet/arp.h
1.move arp_entry_s to net/arp/arp.h
2.move arp_input to nuttx/net/netdev.h

Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2022-12-16 22:10:59 +02:00
chao an
b5507ea9a2 compile/attribute: minor fix for packed struct mismatch
Signed-off-by: chao an <anchao@xiaomi.com>
2022-12-06 03:50:20 +08:00
chao an
3e1c73f8c9 wireless/bluetooth: destroy nxsem properly 2022-11-21 01:15:48 +08:00
anjiahao
a4563b8744 Fix the coding style and typo issue
Signed-off-by: anjiahao <anjiahao@xiaomi.com>
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2022-11-14 09:34:04 +09:00
anjiahao
d07792a343 Initialize global mutext/sem by NXMUTEX_INITIALIZER and SEM_INITIALIZER
Signed-off-by: anjiahao <anjiahao@xiaomi.com>
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2022-11-14 09:34:04 +09:00
yinshengkai
85f727f232 tools: replace INCDIR to Makefile variable
In the past, header file paths were generated by the incdir command
Now they are generated by concatenating environment variables

In this way, when executing makefile, no shell command will be executed,
it will improve the speed of executing makfile
Signed-off-by: yinshengkai <yinshengkai@xiaomi.com>
2022-11-03 19:59:55 +08:00
anjiahao
e1ca516488 use SEM_INITIALIZER inside of NXSEM_INITIALIZER
Signed-off-by: anjiahao <anjiahao@xiaomi.com>
2022-10-22 14:50:48 +08:00
anjiahao
5724c6b2e4 sem:remove sem default protocl
Signed-off-by: anjiahao <anjiahao@xiaomi.com>
2022-10-22 14:50:48 +08:00