[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PULL 9/9] bt: check struct sizes
From: |
Michael Tokarev |
Subject: |
[Qemu-devel] [PULL 9/9] bt: check struct sizes |
Date: |
Fri, 4 Dec 2015 09:57:40 +0300 |
From: Paolo Bonzini <address@hidden>
See http://permalink.gmane.org/gmane.linux.bluez.kernel/36505. For historical
reasons these do not use sizeof, and Coverity caught a mistake in
EVT_ENCRYPT_CHANGE_SIZE.
In addition:
- remove status from create_conn_cancel_cp; the "status" field is only
in rp structs. Note that this means that the OCF_CREATE_CONN_CANCEL
could never have worked (it would have failed the LENGTH_CHECK), but
I am keeping it anyway.
- OCF_READ_LINK_QUALITY similarly could never have worked, but I am
fixing read_link_quality_cp anyway.
- fix inquiry_info which is shorter by one: the kernel has a struct that
is 14 byte long, but not counting the initial num_responses byte which
the kernel parses separately;
- remove extended_inquiry_info altogether, since it's not used and unlike
the other inquiry structs does not have the initial num_responses byte.
Signed-off-by: Paolo Bonzini <address@hidden>
Signed-off-by: Michael Tokarev <address@hidden>
---
include/hw/bt.h | 21 ++++-----------------
1 file changed, 4 insertions(+), 17 deletions(-)
diff --git a/include/hw/bt.h b/include/hw/bt.h
index cb2a7e6..c7c7909 100644
--- a/include/hw/bt.h
+++ b/include/hw/bt.h
@@ -504,7 +504,6 @@ typedef struct {
#define OCF_CREATE_CONN_CANCEL 0x0008
typedef struct {
- uint8_t status;
bdaddr_t bdaddr;
} QEMU_PACKED create_conn_cancel_cp;
#define CREATE_CONN_CANCEL_CP_SIZE 6
@@ -1266,13 +1265,13 @@ typedef struct {
uint8_t status;
uint16_t handle;
} QEMU_PACKED reset_failed_contact_counter_rp;
-#define RESET_FAILED_CONTACT_COUNTER_RP_SIZE 4
+#define RESET_FAILED_CONTACT_COUNTER_RP_SIZE 3
#define OCF_READ_LINK_QUALITY 0x0003
typedef struct {
uint16_t handle;
} QEMU_PACKED read_link_quality_cp;
-#define READ_LINK_QUALITY_CP_SIZE 4
+#define READ_LINK_QUALITY_CP_SIZE 2
typedef struct {
uint8_t status;
@@ -1332,7 +1331,7 @@ typedef struct {
uint8_t dev_class[3];
uint16_t clock_offset;
} QEMU_PACKED inquiry_info;
-#define INQUIRY_INFO_SIZE 14
+#define INQUIRY_INFO_SIZE 15
#define EVT_CONN_COMPLETE 0x03
typedef struct {
@@ -1381,7 +1380,7 @@ typedef struct {
uint16_t handle;
uint8_t encrypt;
} QEMU_PACKED evt_encrypt_change;
-#define EVT_ENCRYPT_CHANGE_SIZE 5
+#define EVT_ENCRYPT_CHANGE_SIZE 4
#define EVT_CHANGE_CONN_LINK_KEY_COMPLETE 0x09
typedef struct {
@@ -1629,18 +1628,6 @@ typedef struct {
} QEMU_PACKED evt_sniff_subrate;
#define EVT_SNIFF_SUBRATE_SIZE 11
-#define EVT_EXTENDED_INQUIRY_RESULT 0x2F
-typedef struct {
- bdaddr_t bdaddr;
- uint8_t pscan_rep_mode;
- uint8_t pscan_period_mode;
- uint8_t dev_class[3];
- uint16_t clock_offset;
- int8_t rssi;
- uint8_t data[240];
-} QEMU_PACKED extended_inquiry_info;
-#define EXTENDED_INQUIRY_INFO_SIZE 254
-
#define EVT_TESTING 0xFE
#define EVT_VENDOR 0xFF
--
2.1.4
- [Qemu-devel] [PULL for-2.5 0/9] Trivial patches for 2015-12-04, Michael Tokarev, 2015/12/04
- [Qemu-devel] [PULL 7/9] scsi: remove scsi_req_free prototype, Michael Tokarev, 2015/12/04
- [Qemu-devel] [PULL 9/9] bt: check struct sizes,
Michael Tokarev <=
- [Qemu-devel] [PULL 5/9] configure: use appropriate code fragment for -fstack-protector checks, Michael Tokarev, 2015/12/04
- [Qemu-devel] [PULL 1/9] util/id: fully allocate names table, Michael Tokarev, 2015/12/04
- [Qemu-devel] [PULL 6/9] gt64xxx: fix decoding of ISD register, Michael Tokarev, 2015/12/04
- [Qemu-devel] [PULL 3/9] configure: Diagnose broken linkers directly, Michael Tokarev, 2015/12/04
- [Qemu-devel] [PULL 2/9] bt: avoid unintended sign extension, Michael Tokarev, 2015/12/04
- [Qemu-devel] [PULL 4/9] crypto: avoid two coverity false positive error reports, Michael Tokarev, 2015/12/04
- [Qemu-devel] [PULL 8/9] typedefs: Put them back into alphabetical order, Michael Tokarev, 2015/12/04
- Re: [Qemu-devel] [PULL for-2.5 0/9] Trivial patches for 2015-12-04, Peter Maydell, 2015/12/04