The GATT ioctls looked up a connection by address and then checked only that a connection object existed, not that it had reached CONNECTED. While a connection is still being established conn->att is NULL, and bt_att_create_pdu() dereferenced it to read the ATT MTU, so issuing SIOCBTEXCHANGE, SIOCBTDISCOVER, SIOCBTGATTRD or SIOCBTGATTWR for a peer that is merely pending faulted. Any task with access to the network device can reach that path, and in PROTECTED and KERNEL builds the fault is taken in the kernel on behalf of user code. Require CONNECTED in those four ioctls, releasing the reference the lookup took, and make bt_att_create_pdu() return NULL when there is no ATT context instead of relying on every caller having checked first. Testing: builds for sim:bluetooth with Make; every commit in this series verified to build individually. On sim:bluetooth with CONFIG_BTSAK=y: nsh> ifup bnep0 ifup bnep0...OK nsh> bt bnep0 gatt connect 11:22:33:44:55:66 public Connect pending... nsh> bt bnep0 gatt exchange-mtu 11:22:33:44:55:66 public ERROR: ioctl(SIOCBTEXCHANGE) failed: 107 107 is ENOTCONN, and the shell continues to run; before this change the same sequence terminated the simulator in bt_att_create_pdu(). Signed-off-by: Alan C. Assis <acassis@gmail.com> Assisted-by: Claude Code Opus 5 |
||
|---|---|---|
| .github | ||
| arch | ||
| audio | ||
| binfmt | ||
| boards | ||
| cmake | ||
| crypto | ||
| Documentation | ||
| drivers | ||
| dummy | ||
| fs | ||
| graphics | ||
| include | ||
| libs | ||
| mm | ||
| net | ||
| openamp | ||
| pass1 | ||
| sched | ||
| syscall | ||
| tools | ||
| video | ||
| wireless | ||
| .asf.yaml | ||
| .codespell-ignore-lines | ||
| .codespellrc | ||
| .editorconfig | ||
| .gitignore | ||
| .gitmessage | ||
| .pre-commit-config.yaml | ||
| .yamllint | ||
| AUTHORS | ||
| CMakeLists.txt | ||
| CONTRIBUTING.md | ||
| INVIOLABLES.md | ||
| Kconfig | ||
| LICENSE | ||
| Makefile | ||
| NOTICE | ||
| README.md | ||
| ReleaseNotes | ||
Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).
For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.
Getting Started
First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.
Documentation
You can find the current NuttX documentation on the Documentation Page.
Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.
The old NuttX documentation is still available in the Apache wiki.
Supported Boards
NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.
Contributing
If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.
License
The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.