acassis opened a new pull request, #20331:
URL: https://github.com/apache/nuttx/pull/20331

   ## Summary
   
   The GATT ioctls looked up a connection by address and then checked only that 
a connection object existed, not that it had reached CONNECTED. While a 
connection is still being established conn->att is NULL, and 
bt_att_create_pdu() dereferenced it to read the ATT MTU, so issuing 
SIOCBTEXCHANGE, SIOCBTDISCOVER, SIOCBTGATTRD or SIOCBTGATTWR for a peer that is 
merely pending faulted.  Any task with access to the network device can reach 
that path, and in PROTECTED and KERNEL builds the fault is taken in the kernel 
on behalf of user code.
   
   ## Impact
   
   Improvement
   
   ## Testing
   Before: no protection, it crashes:
   
   ```
   xtensa_user_panic: User Exception: EXCCAUSE=001c task: bt
     up_dump_register:    PC: 4205251d
     - EXCCAUSE=0x1c = LoadProhibited (NULL conn->att load).
     - addr2line 0x4205251d → bt_att_create_pdu — the exact function the commit
       named.
     - The bt task panics and the system halts in the assert handler; no prompt
       returns, uname never runs. On real silicon this is a hard CPU fault — 
more
       severe than the sim's process exit.
   ```
   
   After: it returns the right error:
   
   ```
   btnet_ioctl: WARNING:  Peer connection not established
     ERROR:  ioctl(SIOCBTEXCHANGE) failed: 107
   ```
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to