mirror of
https://github.com/apache/nuttx.git
synced 2026-09-28 01:53:48 +00:00
Two problems in hci_num_completed_packets(). Number_of_Handles is a single octet, but it was read with BT_LE162HOST(), which takes the first octet of the handle that follows it as the high byte. A one-octet field could therefore produce a loop count of up to 65535. The loop was then bounded only by that count and not by the data that was actually received, so it walked past the end of the event, reading handle and count pairs out of whatever followed it. Read the field at its declared width, and require the pairs the event claims to have been received before reading them. Per-connection credit accounting, which this handler still does not do, is a separate change. Ref: Core v6.0, Vol 4, Part E, 7.7.19 (Number Of Completed Packets event) Testing: builds for sim:bluetooth with Make; every commit in this series verified to build individually. Signed-off-by: Alan C. Assis <acassis@gmail.com> Assisted-by: Claude Code Opus 5 |
||
|---|---|---|
| .. | ||
| bt_atomic.h | ||
| bt_att.c | ||
| bt_att.h | ||
| bt_buf.c | ||
| bt_buf.h | ||
| bt_conn.c | ||
| bt_conn.h | ||
| bt_gatt.c | ||
| bt_hcicore.c | ||
| bt_hcicore.h | ||
| bt_ioctl.c | ||
| bt_ioctl.h | ||
| bt_keys.c | ||
| bt_keys.h | ||
| bt_l2cap.c | ||
| bt_l2cap.h | ||
| bt_netdev.c | ||
| bt_queue.c | ||
| bt_queue.h | ||
| bt_services.c | ||
| bt_smp.c | ||
| bt_smp.h | ||
| bt_uuid.c | ||
| CMakeLists.txt | ||
| Kconfig | ||
| Make.defs | ||