mirror of
https://github.com/apache/nuttx.git
synced 2026-09-29 18:45:22 +00:00
att_find_info_rsp() computed the per-record stride with sizeof(info.i16) and sizeof(info.i128), but "info" is a union of two pointers, so both expressions evaluate to the pointer width instead of the size of the record that the response format selects. The records are 4 octets for a 16-bit UUID and 18 octets for a 128-bit UUID, so the 128-bit path advanced by 4 (or 8) octets per iteration while reading an 18-octet record: handles and UUIDs were parsed from the wrong offsets and the walk ran past the end of the received PDU. On 64-bit builds the 16-bit path was wrong too. Take the stride from the record structures, and require the response to carry whole records before walking it, since the loop advances one record at a time and a partial trailing record would be parsed as a whole one. Ref: Core v6.0, Vol 3, Part F, 3.4.3.2 (ATT_FIND_INFORMATION_RSP) Testing: sim:bluetooth builds with Make, no new warnings. Not yet exercised at runtime; the scriptable controller that can inject a malformed Find Information Response is added separately. Signed-off-by: Alan C. Assis <acassis@gmail.com> Assisted-by: Claude Code Opus 5 |
||
|---|---|---|
| .. | ||
| bt_atomic.h | ||
| bt_att.c | ||
| bt_att.h | ||
| bt_buf.c | ||
| bt_buf.h | ||
| bt_conn.c | ||
| bt_conn.h | ||
| bt_gatt.c | ||
| bt_hcicore.c | ||
| bt_hcicore.h | ||
| bt_ioctl.c | ||
| bt_ioctl.h | ||
| bt_keys.c | ||
| bt_keys.h | ||
| bt_l2cap.c | ||
| bt_l2cap.h | ||
| bt_netdev.c | ||
| bt_queue.c | ||
| bt_queue.h | ||
| bt_services.c | ||
| bt_smp.c | ||
| bt_smp.h | ||
| bt_uuid.c | ||
| CMakeLists.txt | ||
| Kconfig | ||
| Make.defs | ||