jerpelea opened a new pull request, #20336:
URL: https://github.com/apache/nuttx/pull/20336

   ## Summary
   
   The GATT ioctls looked up a connection by address and then checked only that 
a connection object existed, not that it had reached CONNECTED. While a 
connection is still being established conn->att is NULL, and 
bt_att_create_pdu() dereferenced it to read the ATT MTU, so issuing 
SIOCBTEXCHANGE, SIOCBTDISCOVER, SIOCBTGATTRD or SIOCBTGATTWR for a peer that is 
merely pending faulted.  Any task with access to the network device can reach 
that path, and in PROTECTED and KERNEL builds the fault is taken in the kernel 
on behalf of user code.
   
   Require CONNECTED in those four ioctls, releasing the reference the lookup 
took, and make bt_att_create_pdu() return NULL when there is no ATT context 
instead of relying on every caller having checked first.
   
   Testing: builds for sim:bluetooth with Make; every commit in this series 
verified to build individually.  On sim:bluetooth with CONFIG_BTSAK=y:
   
     nsh> ifup bnep0
     ifup bnep0...OK
     nsh> bt bnep0 gatt connect 11:22:33:44:55:66 public
     Connect pending...
     nsh> bt bnep0 gatt exchange-mtu 11:22:33:44:55:66 public
     ERROR:  ioctl(SIOCBTEXCHANGE) failed: 107
   
   107 is ENOTCONN, and the shell continues to run; before this change the same 
sequence terminated the simulator in bt_att_create_pdu().
   
   ## Impact
   
   RELEASE
   
   ## Testing
   
   CI


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to