mirror of
https://github.com/apache/nuttx.git
synced 2026-09-29 10:34:23 +00:00
att_find_info_rsp() computed the per-record stride with sizeof(info.i16) and sizeof(info.i128), but "info" is a union of two pointers, so both expressions evaluate to the pointer width instead of the size of the record that the response format selects. The records are 4 octets for a 16-bit UUID and 18 octets for a 128-bit UUID, so the 128-bit path advanced by 4 (or 8) octets per iteration while reading an 18-octet record: handles and UUIDs were parsed from the wrong offsets and the walk ran past the end of the received PDU. On 64-bit builds the 16-bit path was wrong too. Take the stride from the record structures, and require the response to carry whole records before walking it, since the loop advances one record at a time and a partial trailing record would be parsed as a whole one. Ref: Core v6.0, Vol 3, Part F, 3.4.3.2 (ATT_FIND_INFORMATION_RSP) Testing: sim:bluetooth builds with Make, no new warnings. Not yet exercised at runtime; the scriptable controller that can inject a malformed Find Information Response is added separately. Signed-off-by: Alan C. Assis <acassis@gmail.com> Assisted-by: Claude Code Opus 5 |
||
|---|---|---|
| .. | ||
| bluetooth | ||
| ieee802154 | ||
| pktradio | ||
| CMakeLists.txt | ||
| Kconfig | ||
| Makefile | ||