acassis opened a new pull request, #20243: URL: https://github.com/apache/nuttx/pull/20243
## Summary The hci_event() consumed the event header and dispatched on the event code without checking that a header had been received, and hci_le_meta_event() did the same for the subevent code. Each handler then cast the remaining buffer to its event structure and read fields out of it, so a short event was parsed from whatever followed it in memory - including the fields that identify a connection and carry its encryption state. Check that the header is present before reading it, that the parameters the event declares were actually received, and that enough parameters remain for the structure the selected handler casts to. Events failing a check are dropped with a diagnostic rather than parsed. le_adv_report() continues to do its own checking, because the report count and the per-report lengths vary within that event. ## Impact Improvement ## Testing before: ``` nsh> bt bnep0 scan start hci_event: event 62 le_adv_report: Adv number of reports 1 le_adv_report: 5A:05:D9:40:02:CC (public) event 0, len 28, rssi -69 dBm hci_event: event 62 le_adv_report: Adv number of reports 1 le_adv_report: 5A:05:D9:40:02:CC (public) event 4, len 14, rssi -70 dBm ... ``` - LE Meta Events dispatched: **108** - Advertising reports parsed: **108** - Length-guard messages: **0** — the guard code does not exist in this build. after: ``` nsh> bt bnep0 scan start hci_event: event 62 le_adv_report: Adv number of reports 1 le_adv_report: 5A:05:D9:40:02:CC (public) event 0, len 28, rssi -70 dBm hci_event: event 62 le_adv_report: Adv number of reports 1 le_adv_report: 5A:05:D9:40:02:CC (public) event 4, len 14, rssi -71 dBm ... ``` - LE Meta Events dispatched: **85** (a different scan window; not significant) - Advertising reports parsed: **85** - **Valid events wrongly rejected by the new guard: 0.** -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
