Message ID | 20230330234425.1064422-1-luiz.dentz@gmail.com |
---|---|
State | New |
Headers | show |
Series | [BlueZ] avrcp: Fix crash while handling unsupported events | expand |
This is automated email and please do not reply to this email! Dear submitter, Thank you for submitting the patches to the linux bluetooth mailing list. This is a CI test results with your patch series: PW Link:https://patchwork.kernel.org/project/bluetooth/list/?series=735621 ---Test result--- Test Summary: CheckPatch FAIL 0.74 seconds GitLint FAIL 0.54 seconds BuildEll PASS 26.44 seconds BluezMake PASS 753.07 seconds MakeCheck PASS 11.41 seconds MakeDistcheck PASS 148.65 seconds CheckValgrind PASS 240.95 seconds CheckSmatch PASS 323.46 seconds bluezmakeextell PASS 96.96 seconds IncrementalBuild PASS 604.17 seconds ScanBuild PASS 962.23 seconds Details ############################## Test: CheckPatch - FAIL Desc: Run checkpatch.pl script Output: [BlueZ] avrcp: Fix crash while handling unsupported events WARNING:COMMIT_LOG_LONG_LINE: Possible unwrapped commit description (prefer a maximum 75 chars per line) #90: #3 0x7fbcb3e51c43 in g_main_context_dispatch (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x55c43) /github/workspace/src/src/13195053.patch total: 0 errors, 1 warnings, 12 lines checked NOTE: For some of the reported defects, checkpatch may be able to mechanically convert to the typical style using --fix or --fix-inplace. /github/workspace/src/src/13195053.patch has style problems, please review. NOTE: Ignored message types: COMMIT_MESSAGE COMPLEX_MACRO CONST_STRUCT FILE_PATH_CHANGES MISSING_SIGN_OFF PREFER_PACKED SPDX_LICENSE_TAG SPLIT_STRING SSCANF_TO_KSTRTO NOTE: If any of the errors are false positives, please report them to the maintainer, see CHECKPATCH in MAINTAINERS. ############################## Test: GitLint - FAIL Desc: Run gitlint Output: [BlueZ] avrcp: Fix crash while handling unsupported events WARNING: I3 - ignore-body-lines: gitlint will be switching from using Python regex 'match' (match beginning) to 'search' (match anywhere) semantics. Please review your ignore-body-lines.regex option accordingly. To remove this warning, set general.regex-style-search=True. More details: https://jorisroovers.github.io/gitlint/configuration/#regex-style-search 14: B1 Line exceeds max length (98>80): " #3 0x7fbcb3e51c43 in g_main_context_dispatch (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x55c43)" 16: B1 Line exceeds max length (90>80): " #5 0x7fbcb3e512b2 in g_main_loop_run (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x552b2)" 18: B1 Line exceeds max length (83>80): " #7 0x559644755606 in mainloop_run_with_signal src/shared/mainloop-notify.c:188" 20: B1 Line exceeds max length (90>80): " #9 0x7fbcb3bafd8f in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58" 22: B1 Line exceeds max length (83>80): " #11 0x5596444e8224 in _start (/usr/local/libexec/bluetooth/bluetoothd+0xf0224)" --- Regards, Linux Bluetooth
Hello: This patch was applied to bluetooth/bluez.git (master) by Luiz Augusto von Dentz <luiz.von.dentz@intel.com>: On Thu, 30 Mar 2023 16:44:25 -0700 you wrote: > From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com> > > The following crash can be observed if the remote peer send and > unsupported event: > > ERROR: AddressSanitizer: heap-use-after-free on address 0x60b000148f11 > at pc 0x559644552088 bp 0x7ffe28b3c7b0 sp 0x7ffe28b3c7a0 > WRITE of size 1 at 0x60b000148f11 thread T0 > #0 0x559644552087 in avrcp_handle_event profiles/audio/avrcp.c:3907 > #1 0x559644536c22 in control_response profiles/audio/avctp.c:939 > #2 0x5596445379ab in session_cb profiles/audio/avctp.c:1108 > #3 0x7fbcb3e51c43 in g_main_context_dispatch (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x55c43) > #4 0x7fbcb3ea66c7 (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0xaa6c7) > #5 0x7fbcb3e512b2 in g_main_loop_run (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x552b2) > #6 0x559644754ab6 in mainloop_run src/shared/mainloop-glib.c:66 > #7 0x559644755606 in mainloop_run_with_signal src/shared/mainloop-notify.c:188 > #8 0x5596445bb963 in main src/main.c:1289 > #9 0x7fbcb3bafd8f in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 > #10 0x7fbcb3bafe3f in __libc_start_main_impl ../csu/libc-start.c:392 > #11 0x5596444e8224 in _start (/usr/local/libexec/bluetooth/bluetoothd+0xf0224) > > [...] Here is the summary with links: - [BlueZ] avrcp: Fix crash while handling unsupported events https://git.kernel.org/pub/scm/bluetooth/bluez.git/?id=f54299a85067 You are awesome, thank you!
diff --git a/profiles/audio/avrcp.c b/profiles/audio/avrcp.c index 80f34c7a77a1..dda9a303fb71 100644 --- a/profiles/audio/avrcp.c +++ b/profiles/audio/avrcp.c @@ -3901,6 +3901,12 @@ static gboolean avrcp_handle_event(struct avctp *conn, uint8_t code, case AVRCP_EVENT_UIDS_CHANGED: avrcp_uids_changed(session, pdu); break; + default: + if (event > AVRCP_EVENT_LAST) { + warn("Unsupported event: %u", event); + return FALSE; + } + break; } session->registered_events |= (1 << event);
From: Luiz Augusto von Dentz <luiz.von.dentz@intel.com> The following crash can be observed if the remote peer send and unsupported event: ERROR: AddressSanitizer: heap-use-after-free on address 0x60b000148f11 at pc 0x559644552088 bp 0x7ffe28b3c7b0 sp 0x7ffe28b3c7a0 WRITE of size 1 at 0x60b000148f11 thread T0 #0 0x559644552087 in avrcp_handle_event profiles/audio/avrcp.c:3907 #1 0x559644536c22 in control_response profiles/audio/avctp.c:939 #2 0x5596445379ab in session_cb profiles/audio/avctp.c:1108 #3 0x7fbcb3e51c43 in g_main_context_dispatch (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x55c43) #4 0x7fbcb3ea66c7 (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0xaa6c7) #5 0x7fbcb3e512b2 in g_main_loop_run (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x552b2) #6 0x559644754ab6 in mainloop_run src/shared/mainloop-glib.c:66 #7 0x559644755606 in mainloop_run_with_signal src/shared/mainloop-notify.c:188 #8 0x5596445bb963 in main src/main.c:1289 #9 0x7fbcb3bafd8f in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58 #10 0x7fbcb3bafe3f in __libc_start_main_impl ../csu/libc-start.c:392 #11 0x5596444e8224 in _start (/usr/local/libexec/bluetooth/bluetoothd+0xf0224) --- profiles/audio/avrcp.c | 6 ++++++ 1 file changed, 6 insertions(+)