All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] sdp: Prevent integer underflow in string attribute length calculation
@ 2026-10-07 19:48 Hui Peng
  2026-10-07 23:54 ` bluez.test.bot
  0 siblings, 1 reply; 2+ messages in thread
From: Hui Peng @ 2026-10-07 19:48 UTC (permalink / raw)
  To: Marcel Holtmann, Johan Hovold, Luiz Augusto von Dentz
  Cc: linux-bluetooth, Hui Peng

In lib/bluetooth/sdp.c, attribute string length calculations subtract
sizeof(uint8_t) from d->unitSize (e.g. d->unitSize - sizeof(uint8_t)).
When d->unitSize is 0 or less than sizeof(uint8_t), this subtraction
underflows in 32-bit integer arithmetic to a negative/huge length value,
passing invalid sizes to memory allocation and length extraction
functions.

Add explicit lower-bound guards to ensure that when
d->unitSize <= sizeof(uint8_t), the calculated string length is safely
set to 0.

Assisted-by: Antigravity
---
 lib/bluetooth/sdp.c | 16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

diff --git a/lib/bluetooth/sdp.c b/lib/bluetooth/sdp.c
index 1e027f9..a750274 100644
--- a/lib/bluetooth/sdp.c
+++ b/lib/bluetooth/sdp.c
@@ -730,7 +730,10 @@ static int sdp_get_data_size(sdp_buf_t *buf, sdp_data_t *d)
 	case SDP_URL_STR8:
 	case SDP_URL_STR16:
 	case SDP_URL_STR32:
-		data_size = d->unitSize - sizeof(uint8_t);
+		if (d->unitSize > sizeof(uint8_t))
+			data_size = d->unitSize - sizeof(uint8_t);
+		else
+			data_size = 0;
 		break;
 	case SDP_SEQ8:
 	case SDP_SEQ16:
@@ -1524,7 +1527,8 @@ static void *sdp_data_value(sdp_data_t *data, uint32_t *len)
 	case SDP_TEXT_STR32:
 		val = data->val.str;
 		if (len)
-			*len = data->unitSize - sizeof(uint8_t);
+			*len = (data->unitSize > sizeof(uint8_t)) ?
+				(data->unitSize - sizeof(uint8_t)) : 0;
 		break;
 	case SDP_ALT8:
 	case SDP_ALT16:
@@ -4852,7 +4856,8 @@ int sdp_set_supp_feat(sdp_record_t *rec, const sdp_list_t *sf)
 			case SDP_TEXT_STR8:
 			case SDP_TEXT_STR16:
 				vals[j] = data->val.str;
-				lengths[j] = data->unitSize - sizeof(uint8_t);
+				lengths[j] = (data->unitSize > sizeof(uint8_t)) ?
+					(data->unitSize - sizeof(uint8_t)) : 0;
 				break;
 			case SDP_ALT8:
 			case SDP_ALT16:
@@ -4929,7 +4934,8 @@ int sdp_get_supp_feat(const sdp_record_t *rec, sdp_list_t **seqp)
 			case SDP_TEXT_STR8:
 			case SDP_TEXT_STR16:
 				val = dd->val.str;
-				length = dd->unitSize - sizeof(uint8_t);
+				length = (dd->unitSize > sizeof(uint8_t)) ?
+					(dd->unitSize - sizeof(uint8_t)) : 0;
 				break;
 			case SDP_UINT8:
 			case SDP_UINT16:
-- 
2.47.3

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* RE: sdp: Prevent integer underflow in string attribute length calculation
  2026-10-07 19:48 [PATCH] sdp: Prevent integer underflow in string attribute length calculation Hui Peng
@ 2026-10-07 23:54 ` bluez.test.bot
  0 siblings, 0 replies; 2+ messages in thread
From: bluez.test.bot @ 2026-10-07 23:54 UTC (permalink / raw)
  To: linux-bluetooth, benquike

[-- Attachment #1: Type: text/plain, Size: 55695 bytes --]

This is automated email and please do not reply to this email!

Dear submitter,

Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/series/1181104/

---Test result---

Test Summary:
CheckPatch                    FAIL      0.41 seconds
GitLint                       PASS      0.29 seconds
BuildEll                      PASS      17.24 seconds
BluezMake                     FAIL      285.68 seconds
MakeCheck                     FAIL      2.62 seconds
MakeDistcheck                 PASS      127.20 seconds
CheckValgrind                 FAIL      88.94 seconds
CheckSmatch                   FAIL      151.90 seconds
bluezmakeextell               FAIL      59.22 seconds
TestFunctional                ERROR     286.09 seconds
IncrementalBuild              FAIL      281.73 seconds
ScanBuild                     FAIL      266.22 seconds

Details
##############################
Test: CheckPatch - FAIL
Desc: Run checkpatch.pl script
Output:
sdp: Prevent integer underflow in string attribute length calculation
WARNING:LONG_LINE: line length of 81 exceeds 80 columns
#148: FILE: lib/bluetooth/sdp.c:4859:
+				lengths[j] = (data->unitSize > sizeof(uint8_t)) ?

/home/runner/work/bluez/bluez/src/patch/14872886.patch total: 0 errors, 1 warnings, 38 lines checked

NOTE: For some of the reported defects, checkpatch may be able to
      mechanically convert to the typical style using --fix or --fix-inplace.

/home/runner/work/bluez/bluez/src/patch/14872886.patch has style problems, please review.

NOTE: Ignored message types: COMMIT_MESSAGE COMPLEX_MACRO CONST_STRUCT FILE_PATH_CHANGES MISSING_SIGN_OFF PREFER_PACKED SPDX_LICENSE_TAG SPLIT_STRING SSCANF_TO_KSTRTO

NOTE: If any of the errors are false positives, please report
      them to the maintainer, see CHECKPATCH in MAINTAINERS.


##############################
Test: BluezMake - FAIL
Desc: Build BlueZ
Output:

tools/mgmt-tester.c: In function ‘main’:
tools/mgmt-tester.c:13440:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
13440 | int main(int argc, char *argv[])
      |     ^~~~
unit/test-avdtp.c: In function ‘main’:
unit/test-avdtp.c:766:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
  766 | int main(int argc, char *argv[])
      |     ^~~~
unit/test-avrcp.c: In function ‘main’:
unit/test-avrcp.c:1382:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
 1382 | int main(int argc, char *argv[])
      |     ^~~~
lib/bluetooth/sdp.c: In function ‘sdp_get_data_size’:
lib/bluetooth/sdp.c:733:33: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
  733 |                 if (d->unitSize > sizeof(uint8_t))
      |                                 ^
lib/bluetooth/sdp.c: In function ‘sdp_data_value’:
lib/bluetooth/sdp.c:1530:48: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 1530 |                         *len = (data->unitSize > sizeof(uint8_t)) ?
      |                                                ^
lib/bluetooth/sdp.c: In function ‘sdp_set_supp_feat’:
lib/bluetooth/sdp.c:4859:62: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4859 |                                 lengths[j] = (data->unitSize > sizeof(uint8_t)) ?
      |                                                              ^
lib/bluetooth/sdp.c: In function ‘sdp_get_supp_feat’:
lib/bluetooth/sdp.c:4937:56: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4937 |                                 length = (dd->unitSize > sizeof(uint8_t)) ?
      |                                                        ^
cc1: all warnings being treated as errors
make[1]: *** [Makefile:7146: lib/bluetooth/sdp.lo] Error 1
make[1]: *** Waiting for unfinished jobs....
unit/test-rap.c: In function ‘main’:
unit/test-rap.c:997:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
  997 | int main(int argc, char *argv[])
      |     ^~~~
make: *** [Makefile:4246: all] Error 2
##############################
Test: MakeCheck - FAIL
Desc: Run Bluez Make Check
Output:

lib/bluetooth/sdp.c: In function ‘sdp_get_data_size’:
lib/bluetooth/sdp.c:733:33: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
  733 |                 if (d->unitSize > sizeof(uint8_t))
      |                                 ^
lib/bluetooth/sdp.c: In function ‘sdp_data_value’:
lib/bluetooth/sdp.c:1530:48: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 1530 |                         *len = (data->unitSize > sizeof(uint8_t)) ?
      |                                                ^
lib/bluetooth/sdp.c: In function ‘sdp_set_supp_feat’:
lib/bluetooth/sdp.c:4859:62: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4859 |                                 lengths[j] = (data->unitSize > sizeof(uint8_t)) ?
      |                                                              ^
lib/bluetooth/sdp.c: In function ‘sdp_get_supp_feat’:
lib/bluetooth/sdp.c:4937:56: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4937 |                                 length = (dd->unitSize > sizeof(uint8_t)) ?
      |                                                        ^
cc1: all warnings being treated as errors
make[1]: *** [Makefile:7146: lib/bluetooth/sdp.lo] Error 1
make: *** [Makefile:10984: check] Error 2
##############################
Test: CheckValgrind - FAIL
Desc: Run Bluez Make Check with Valgrind
Output:

tools/mgmt-tester.c: In function ‘main’:
tools/mgmt-tester.c:13440:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
13440 | int main(int argc, char *argv[])
      |     ^~~~
lib/bluetooth/sdp.c: In function ‘sdp_get_data_size’:
lib/bluetooth/sdp.c:733:33: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
  733 |                 if (d->unitSize > sizeof(uint8_t))
      |                                 ^
lib/bluetooth/sdp.c: In function ‘sdp_data_value’:
lib/bluetooth/sdp.c:1530:48: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 1530 |                         *len = (data->unitSize > sizeof(uint8_t)) ?
      |                                                ^
lib/bluetooth/sdp.c: In function ‘sdp_set_supp_feat’:
lib/bluetooth/sdp.c:4859:62: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4859 |                                 lengths[j] = (data->unitSize > sizeof(uint8_t)) ?
      |                                                              ^
lib/bluetooth/sdp.c: In function ‘sdp_get_supp_feat’:
lib/bluetooth/sdp.c:4937:56: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4937 |                                 length = (dd->unitSize > sizeof(uint8_t)) ?
      |                                                        ^
cc1: all warnings being treated as errors
make[1]: *** [Makefile:7146: lib/bluetooth/sdp.lo] Error 1
make[1]: *** Waiting for unfinished jobs....
make: *** [Makefile:10984: check] Error 2
##############################
Test: CheckSmatch - FAIL
Desc: Run smatch tool with source
Output:

src/shared/crypto.c:271:21: warning: Variable length array is used.
src/shared/crypto.c:272:23: warning: Variable length array is used.
src/shared/gatt-helpers.c:764:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:842:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:1335:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:1366:23: warning: Variable length array is used.
src/shared/bap.c:318:25: warning: array of flexible structures
src/shared/bap.c: note: in included file:
./src/shared/ascs.h:88:25: warning: array of flexible structures
src/shared/shell.c: note: in included file (through /usr/include/x86_64-linux-gnu//sys/ioctl.h, /usr/include/x86_64-linux-gnu//sys/epoll.h, src/shared/mainloop.h):
/usr/include/x86_64-linux-gnu//sys/ttydefaults.h:55:9: warning: preprocessor token CTRL redefined
src/shared/shell.c: note: in included file (through /usr/include/readline/keymaps.h, /usr/include/readline/readline.h):
/usr/include/readline/chardefs.h:51:9: this was the original definition
src/shared/crypto.c:271:21: warning: Variable length array is used.
src/shared/crypto.c:272:23: warning: Variable length array is used.
src/shared/gatt-helpers.c:764:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:842:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:1335:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:1366:23: warning: Variable length array is used.
src/shared/bap.c:318:25: warning: array of flexible structures
src/shared/bap.c: note: in included file:
./src/shared/ascs.h:88:25: warning: array of flexible structures
src/shared/shell.c: note: in included file (through /usr/include/x86_64-linux-gnu//sys/ioctl.h, /usr/include/x86_64-linux-gnu//sys/epoll.h, src/shared/mainloop.h):
/usr/include/x86_64-linux-gnu//sys/ttydefaults.h:55:9: warning: preprocessor token CTRL redefined
src/shared/shell.c: note: in included file (through /usr/include/readline/keymaps.h, /usr/include/readline/readline.h):
/usr/include/readline/chardefs.h:51:9: this was the original definition
tools/mesh-cfgtest.c:1453:17: warning: unknown escape sequence: '\%'
tools/sco-tester.c: note: in included file:
./lib/bluetooth/bluetooth.h:232:15: warning: array of flexible structures
./lib/bluetooth/bluetooth.h:237:31: warning: array of flexible structures
tools/bneptest.c:634:39: warning: unknown escape sequence: '\%'
tools/seq2bseq.c:57:26: warning: Variable length array is used.
client/btpclient/gatt.c: note: in included file:
./src/shared/btp.h:338:41: warning: array of flexible structures
./src/shared/btp.h:343:55: warning: array of flexible structures
./src/shared/btp.h:366:47: warning: array of flexible structures
./src/shared/btp.h:395:42: warning: array of flexible structures
src/advertising.c: note: in included file:
./src/shared/mgmt.h:95:25: error: redefinition of unsigned int enum mgmt_io_capability
src/agent.c: note: in included file:
src/shared/queue.h:19:20: error: redefinition of struct queue_entry
src/adv_monitor.c: note: in included file:
./src/shared/mgmt.h:95:25: error: redefinition of unsigned int enum mgmt_io_capability
unit/avctp.c:505:34: warning: Variable length array is used.
unit/avctp.c:556:34: warning: Variable length array is used.
unit/test-avrcp.c:374:26: warning: Variable length array is used.
unit/test-avrcp.c:399:26: warning: Variable length array is used.
unit/test-avrcp.c:415:24: warning: Variable length array is used.
unit/avrcp-lib.c:1085:34: warning: Variable length array is used.
unit/avrcp-lib.c:1583:34: warning: Variable length array is used.
unit/avrcp-lib.c:1612:34: warning: Variable length array is used.
unit/avrcp-lib.c:1638:34: warning: Variable length array is used.
src/advertising.c: note: in included file:
./src/shared/mgmt.h:95:25: error: redefinition of unsigned int enum mgmt_io_capability
src/agent.c: note: in included file:
src/shared/queue.h:19:20: error: redefinition of struct queue_entry
src/adv_monitor.c: note: in included file:
./src/shared/mgmt.h:95:25: error: redefinition of unsigned int enum mgmt_io_capability
src/main.c: note: in included file (through src/device.h):
./src/shared/queue.h:19:20: error: redefinition of struct queue_entry
mesh/mesh-io-mgmt.c:525:67: warning: Variable length array is used.
lib/bluetooth/sdp.c: In function ‘sdp_get_data_size’:
lib/bluetooth/sdp.c:733:33: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
  733 |                 if (d->unitSize > sizeof(uint8_t))
      |                                 ^
lib/bluetooth/sdp.c: In function ‘sdp_data_value’:
lib/bluetooth/sdp.c:1530:48: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 1530 |                         *len = (data->unitSize > sizeof(uint8_t)) ?
      |                                                ^
lib/bluetooth/sdp.c: In function ‘sdp_set_supp_feat’:
lib/bluetooth/sdp.c:4859:62: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4859 |                                 lengths[j] = (data->unitSize > sizeof(uint8_t)) ?
      |                                                              ^
lib/bluetooth/sdp.c: In function ‘sdp_get_supp_feat’:
lib/bluetooth/sdp.c:4937:56: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4937 |                                 length = (dd->unitSize > sizeof(uint8_t)) ?
      |                                                        ^
src/shared/crypto.c:271:21: warning: Variable length array is used.
src/shared/crypto.c:272:23: warning: Variable length array is used.
cc1: all warnings being treated as errors
make[1]: *** [Makefile:7146: lib/bluetooth/sdp.lo] Error 1
make[1]: *** Waiting for unfinished jobs....
make: *** [Makefile:4246: all] Error 2
##############################
Test: bluezmakeextell - FAIL
Desc: Build Bluez with External ELL
Output:

lib/bluetooth/sdp.c: In function ‘sdp_get_data_size’:
lib/bluetooth/sdp.c:733:33: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
  733 |                 if (d->unitSize > sizeof(uint8_t))
      |                                 ^
lib/bluetooth/sdp.c: In function ‘sdp_data_value’:
lib/bluetooth/sdp.c:1530:48: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 1530 |                         *len = (data->unitSize > sizeof(uint8_t)) ?
      |                                                ^
lib/bluetooth/sdp.c: In function ‘sdp_set_supp_feat’:
lib/bluetooth/sdp.c:4859:62: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4859 |                                 lengths[j] = (data->unitSize > sizeof(uint8_t)) ?
      |                                                              ^
lib/bluetooth/sdp.c: In function ‘sdp_get_supp_feat’:
lib/bluetooth/sdp.c:4937:56: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4937 |                                 length = (dd->unitSize > sizeof(uint8_t)) ?
      |                                                        ^
cc1: all warnings being treated as errors
make[1]: *** [Makefile:7146: lib/bluetooth/sdp.lo] Error 1
make[1]: *** Waiting for unfinished jobs....
make: *** [Makefile:4246: all] Error 2
##############################
Test: TestFunctional - ERROR
Desc: Run test-functional
Output:
Failed to build BlueZ:
Failed to build BlueZ
##############################
Test: IncrementalBuild - FAIL
Desc: Incremental build with the patches in the series
Output:

tools/mgmt-tester.c: In function ‘main’:
tools/mgmt-tester.c:13440:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
13440 | int main(int argc, char *argv[])
      |     ^~~~
unit/test-avdtp.c: In function ‘main’:
unit/test-avdtp.c:766:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
  766 | int main(int argc, char *argv[])
      |     ^~~~
unit/test-avrcp.c: In function ‘main’:
unit/test-avrcp.c:1382:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
 1382 | int main(int argc, char *argv[])
      |     ^~~~
lib/bluetooth/sdp.c: In function ‘sdp_get_data_size’:
lib/bluetooth/sdp.c:733:33: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
  733 |                 if (d->unitSize > sizeof(uint8_t))
      |                                 ^
lib/bluetooth/sdp.c: In function ‘sdp_data_value’:
lib/bluetooth/sdp.c:1530:48: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 1530 |                         *len = (data->unitSize > sizeof(uint8_t)) ?
      |                                                ^
lib/bluetooth/sdp.c: In function ‘sdp_set_supp_feat’:
lib/bluetooth/sdp.c:4859:62: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4859 |                                 lengths[j] = (data->unitSize > sizeof(uint8_t)) ?
      |                                                              ^
lib/bluetooth/sdp.c: In function ‘sdp_get_supp_feat’:
lib/bluetooth/sdp.c:4937:56: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4937 |                                 length = (dd->unitSize > sizeof(uint8_t)) ?
      |                                                        ^
cc1: all warnings being treated as errors
make[1]: *** [Makefile:7146: lib/bluetooth/sdp.lo] Error 1
make[1]: *** Waiting for unfinished jobs....
unit/test-rap.c: In function ‘main’:
unit/test-rap.c:997:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
  997 | int main(int argc, char *argv[])
      |     ^~~~
make: *** [Makefile:4246: all] Error 2
sdp: Prevent integer underflow in string attribute length calculation

tools/mgmt-tester.c: In function ‘main’:
tools/mgmt-tester.c:13440:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
13440 | int main(int argc, char *argv[])
      |     ^~~~
unit/test-avdtp.c: In function ‘main’:
unit/test-avdtp.c:766:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
  766 | int main(int argc, char *argv[])
      |     ^~~~
unit/test-avrcp.c: In function ‘main’:
unit/test-avrcp.c:1382:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
 1382 | int main(int argc, char *argv[])
      |     ^~~~
lib/bluetooth/sdp.c: In function ‘sdp_get_data_size’:
lib/bluetooth/sdp.c:733:33: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
  733 |                 if (d->unitSize > sizeof(uint8_t))
      |                                 ^
lib/bluetooth/sdp.c: In function ‘sdp_data_value’:
lib/bluetooth/sdp.c:1530:48: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 1530 |                         *len = (data->unitSize > sizeof(uint8_t)) ?
      |                                                ^
lib/bluetooth/sdp.c: In function ‘sdp_set_supp_feat’:
lib/bluetooth/sdp.c:4859:62: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4859 |                                 lengths[j] = (data->unitSize > sizeof(uint8_t)) ?
      |                                                              ^
lib/bluetooth/sdp.c: In function ‘sdp_get_supp_feat’:
lib/bluetooth/sdp.c:4937:56: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4937 |                                 length = (dd->unitSize > sizeof(uint8_t)) ?
      |                                                        ^
cc1: all warnings being treated as errors
make[1]: *** [Makefile:7146: lib/bluetooth/sdp.lo] Error 1
make[1]: *** Waiting for unfinished jobs....
unit/test-rap.c: In function ‘main’:
unit/test-rap.c:997:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
  997 | int main(int argc, char *argv[])
      |     ^~~~
make: *** [Makefile:4246: all] Error 2
##############################
Test: ScanBuild - FAIL
Desc: Run Scan Build
Output:

src/shared/gatt-client.c:457:21: warning: Use of memory after it is freed [unix.Malloc]
  457 |         gatt_db_unregister(op->client->db, op->db_id);
      |                            ^~~~~~~~~~
src/shared/gatt-client.c:702:2: warning: Use of memory after it is freed [unix.Malloc]
  702 |         discovery_op_complete(op, false, att_ecode);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1108:2: warning: Use of memory after it is freed [unix.Malloc]
 1108 |         discovery_op_complete(op, success, att_ecode);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1302:2: warning: Use of memory after it is freed [unix.Malloc]
 1302 |         discovery_op_complete(op, success, att_ecode);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1367:2: warning: Use of memory after it is freed [unix.Malloc]
 1367 |         discovery_op_complete(op, success, att_ecode);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1642:6: warning: Use of memory after it is freed [unix.Malloc]
 1642 |         if (read_db_hash(op)) {
      |             ^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1647:2: warning: Use of memory after it is freed [unix.Malloc]
 1647 |         discover_all(op);
      |         ^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1703:56: warning: Use of memory after it is freed [unix.Malloc]
 1703 |         notify_data->chrc->ccc_write_id = notify_data->att_id = att_id;
      |                                           ~~~~~~~~~~~~~~~~~~~ ^
src/shared/gatt-client.c:2156:6: warning: Use of memory after it is freed [unix.Malloc]
 2156 |         if (read_db_hash(op)) {
      |             ^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:2164:8: warning: Use of memory after it is freed [unix.Malloc]
 2164 |                                                         discovery_op_ref(op),
      |                                                         ^~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:3350:2: warning: Use of memory after it is freed [unix.Malloc]
 3350 |         complete_write_long_op(req, success, 0, false);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:3372:2: warning: Use of memory after it is freed [unix.Malloc]
 3372 |         request_unref(req);
      |         ^~~~~~~~~~~~~~~~~~
12 warnings generated.
src/shared/rap.c:3344:30: warning: Assigned value is uninitialized [core.uninitialized.Assign]
 3344 |                         out->tone_pct[k].i_sample = tone_pct_i[k];
      |                                                   ^ ~~~~~~~~~~~~~
src/shared/rap.c:4291:13: warning: Use of memory after it is freed [unix.Malloc]
 4291 |         attached = queue_find(sessions, NULL, rap);
      |                    ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2 warnings generated.
src/shared/bap.c:1543:8: warning: Use of memory after it is freed [unix.Malloc]
 1543 |         bap = bt_bap_ref_safe(bap);
      |               ^~~~~~~~~~~~~~~~~~~~
src/shared/bap.c:2359:20: warning: Use of memory after it is freed [unix.Malloc]
 2359 |         return queue_find(stream->bap->streams, NULL, stream);
      |                           ^~~~~~~~~~~~~~~~~~~~
2 warnings generated.
src/shared/gatt-client.c:457:21: warning: Use of memory after it is freed [unix.Malloc]
  457 |         gatt_db_unregister(op->client->db, op->db_id);
      |                            ^~~~~~~~~~
src/shared/gatt-client.c:702:2: warning: Use of memory after it is freed [unix.Malloc]
  702 |         discovery_op_complete(op, false, att_ecode);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1108:2: warning: Use of memory after it is freed [unix.Malloc]
 1108 |         discovery_op_complete(op, success, att_ecode);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1302:2: warning: Use of memory after it is freed [unix.Malloc]
 1302 |         discovery_op_complete(op, success, att_ecode);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1367:2: warning: Use of memory after it is freed [unix.Malloc]
 1367 |         discovery_op_complete(op, success, att_ecode);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1642:6: warning: Use of memory after it is freed [unix.Malloc]
 1642 |         if (read_db_hash(op)) {
      |             ^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1647:2: warning: Use of memory after it is freed [unix.Malloc]
 1647 |         discover_all(op);
      |         ^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1703:56: warning: Use of memory after it is freed [unix.Malloc]
 1703 |         notify_data->chrc->ccc_write_id = notify_data->att_id = att_id;
      |                                           ~~~~~~~~~~~~~~~~~~~ ^
src/shared/gatt-client.c:2156:6: warning: Use of memory after it is freed [unix.Malloc]
 2156 |         if (read_db_hash(op)) {
      |             ^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:2164:8: warning: Use of memory after it is freed [unix.Malloc]
 2164 |                                                         discovery_op_ref(op),
      |                                                         ^~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:3350:2: warning: Use of memory after it is freed [unix.Malloc]
 3350 |         complete_write_long_op(req, success, 0, false);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:3372:2: warning: Use of memory after it is freed [unix.Malloc]
 3372 |         request_unref(req);
      |         ^~~~~~~~~~~~~~~~~~
12 warnings generated.
src/shared/rap.c:3344:30: warning: Assigned value is uninitialized [core.uninitialized.Assign]
 3344 |                         out->tone_pct[k].i_sample = tone_pct_i[k];
      |                                                   ^ ~~~~~~~~~~~~~
src/shared/rap.c:4291:13: warning: Use of memory after it is freed [unix.Malloc]
 4291 |         attached = queue_find(sessions, NULL, rap);
      |                    ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2 warnings generated.
tools/hciattach_ath3k.c:530:9: warning: File position of the stream might be 'indeterminate' after a failed operation. Can cause undefined behavior [unix.Stream]
  530 |                         if (!fgets(byte, 3, stream))
      |                              ^~~~~~~~~~~~~~~~~~~~~~
tools/hciattach_ath3k.c:530:9: warning: Read function called when stream is in EOF state. Function has no effect [unix.Stream]
  530 |                         if (!fgets(byte, 3, stream))
      |                              ^~~~~~~~~~~~~~~~~~~~~~
2 warnings generated.
tools/hciattach.c:817:7: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n' [deadcode.DeadStores]
  817 |         if ((n = read_hci_event(fd, resp, 10)) < 0) {
      |              ^   ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/hciattach.c:865:7: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n' [deadcode.DeadStores]
  865 |         if ((n = read_hci_event(fd, resp, 4)) < 0) {
      |              ^   ~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/hciattach.c:887:8: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n' [deadcode.DeadStores]
  887 |                 if ((n = read_hci_event(fd, resp, 10)) < 0) {
      |                      ^   ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/hciattach.c:909:7: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n' [deadcode.DeadStores]
  909 |         if ((n = read_hci_event(fd, resp, 4)) < 0) {
      |              ^   ~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/hciattach.c:930:7: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n' [deadcode.DeadStores]
  930 |         if ((n = read_hci_event(fd, resp, 4)) < 0) {
      |              ^   ~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/hciattach.c:974:7: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n' [deadcode.DeadStores]
  974 |         if ((n = read_hci_event(fd, resp, 6)) < 0) {
      |              ^   ~~~~~~~~~~~~~~~~~~~~~~~~~~~
6 warnings generated.
src/oui.c:50:2: warning: Value stored to 'hwdb' is never read [deadcode.DeadStores]
   50 |         hwdb = udev_hwdb_unref(hwdb);
      |         ^      ~~~~~~~~~~~~~~~~~~~~~
src/oui.c:53:2: warning: Value stored to 'udev' is never read [deadcode.DeadStores]
   53 |         udev = udev_unref(udev);
      |         ^      ~~~~~~~~~~~~~~~~
2 warnings generated.
src/shared/bap.c:1543:8: warning: Use of memory after it is freed [unix.Malloc]
 1543 |         bap = bt_bap_ref_safe(bap);
      |               ^~~~~~~~~~~~~~~~~~~~
src/shared/bap.c:2359:20: warning: Use of memory after it is freed [unix.Malloc]
 2359 |         return queue_find(stream->bap->streams, NULL, stream);
      |                           ^~~~~~~~~~~~~~~~~~~~
2 warnings generated.
tools/rfcomm.c:234:3: warning: Value stored to 'i' is never read [deadcode.DeadStores]
  234 |                 i = execvp(cmdargv[0], cmdargv);
      |                 ^   ~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/rfcomm.c:234:7: warning: Null pointer passed to 1st parameter expecting 'nonnull' [core.NonNullParamChecker]
  234 |                 i = execvp(cmdargv[0], cmdargv);
      |                     ^~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/rfcomm.c:354:8: warning: Although the value stored to 'fd' is used in the enclosing expression, the value is never actually read from 'fd' [deadcode.DeadStores]
  354 |                 if ((fd = open(devname, O_RDONLY | O_NOCTTY)) < 0) {
      |                      ^    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/rfcomm.c:473:6: warning: The 1st argument to 'getsockname' is -1 but should be >= 0 [unix.StdCLibraryFunctions]
  473 |         if (getsockname(nsk, (struct sockaddr *)&laddr, &alen) < 0) {
      |             ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/rfcomm.c:497:14: warning: Assigned value is uninitialized [core.uninitialized.Assign]
  497 |         req.channel = raddr.rc_channel;
      |                     ^ ~~~~~~~~~~~~~~~~
tools/rfcomm.c:515:8: warning: Although the value stored to 'fd' is used in the enclosing expression, the value is never actually read from 'fd' [deadcode.DeadStores]
  515 |                 if ((fd = open(devname, O_RDONLY | O_NOCTTY)) < 0) {
      |                      ^    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
6 warnings generated.
tools/ciptool.c:351:7: warning: 5th function call argument is an uninitialized value [core.CallAndMessage]
  351 |         sk = do_connect(ctl, dev_id, &src, &dst, psm, (1 << CMTP_LOOPBACK));
      |              ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
tools/sdptool.c:941:26: warning: Result of 'malloc' is converted to a pointer of type 'uint32_t', which is incompatible with sizeof operand type 'int' [unix.MallocSizeof]
  941 |                         uint32_t *value_int = malloc(sizeof(int));
      |                         ~~~~~~~~~~            ^~~~~~ ~~~~~~~~~~~
tools/sdptool.c:980:4: warning: 1st function call argument is an uninitialized value [core.CallAndMessage]
  980 |                         free(allocArray[i]);
      |                         ^~~~~~~~~~~~~~~~~~~
tools/sdptool.c:3777:2: warning: Potential leak of memory pointed to by 'si.name' [unix.Malloc]
 3777 |         return add_service(0, &si);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~
tools/sdptool.c:4112:4: warning: Potential leak of memory pointed to by 'context.svc' [unix.Malloc]
 4112 |                         return -1;
      |                         ^~~~~~~~~
4 warnings generated.
src/sdp-xml.c:129:10: warning: Assigned value is uninitialized [core.uninitialized.Assign]
  129 |                 buf[1] = data[i + 1];
      |                        ^ ~~~~~~~~~~~
src/sdp-xml.c:309:11: warning: Assigned value is uninitialized [core.uninitialized.Assign]
  309 |                         buf[1] = data[i + 1];
      |                                ^ ~~~~~~~~~~~
src/sdp-xml.c:347:11: warning: Assigned value is uninitialized [core.uninitialized.Assign]
  347 |                         buf[1] = data[i + 1];
      |                                ^ ~~~~~~~~~~~
3 warnings generated.
tools/rfcomm-tester.c:410:6: warning: The 1st argument to 'bind' is -1 but should be >= 0 [unix.StdCLibraryFunctions]
  410 |         if (bind(sk, (struct sockaddr *) &addr, sizeof(addr)) < 0) {
      |             ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/rfcomm-tester.c:428:8: warning: The 1st argument to 'connect' is -1 but should be >= 0 [unix.StdCLibraryFunctions]
  428 |         err = connect(sk, (struct sockaddr *) &addr, sizeof(addr));
      |               ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2 warnings generated.
tools/avtest.c:243:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  243 |                                 len = write(sk, buf, 3);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:253:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  253 |                                 len = write(sk, buf, 4);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:262:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  262 |                                 len = write(sk, buf, 3);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:276:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  276 |                                 len = write(sk, buf,
      |                                 ^     ~~~~~~~~~~~~~~
  277 |                                                 3 + sizeof(media_transport));
      |                                                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/avtest.c:283:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  283 |                                 len = write(sk, buf,
      |                                 ^     ~~~~~~~~~~~~~~
  284 |                                                 1 + media_transport_size);
      |                                                 ~~~~~~~~~~~~~~~~~~~~~~~~~
tools/avtest.c:290:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  290 |                                 len = write(sk, buf,
      |                                 ^     ~~~~~~~~~~~~~~
  291 |                                                 1 + media_transport_size);
      |                                                 ~~~~~~~~~~~~~~~~~~~~~~~~~
tools/avtest.c:297:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  297 |                                 len = write(sk, buf,
      |                                 ^     ~~~~~~~~~~~~~~
  298 |                                                 2 + media_transport_size);
      |                                                 ~~~~~~~~~~~~~~~~~~~~~~~~~
tools/avtest.c:309:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  309 |                                 len = write(sk, buf, 4);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:313:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  313 |                                 len = write(sk, buf, 2);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:322:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  322 |                                 len = write(sk, buf, 3);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:326:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  326 |                                 len = write(sk, buf, 2);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:335:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  335 |                                 len = write(sk, buf, 3);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:342:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  342 |                                 len = write(sk, buf, 2);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:364:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  364 |                                 len = write(sk, buf, 4);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:368:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  368 |                                 len = write(sk, buf, 2);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:377:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  377 |                                 len = write(sk, buf, 3);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:381:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  381 |                                 len = write(sk, buf, 2);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:394:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  394 |                                 len = write(sk, buf, 4);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:398:5: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  398 |                                 len = write(sk, buf, 2);
      |                                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:405:4: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  405 |                         len = write(sk, buf, 2);
      |                         ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:415:4: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  415 |                         len = write(sk, buf, 2);
      |                         ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:580:3: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  580 |                 len = write(sk, buf, 2);
      |                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:588:3: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  588 |                 len = write(sk, buf, invalid ? 2 : 3);
      |                 ^     ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/avtest.c:602:3: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  602 |                 len = write(sk, buf, 4 + media_transport_size);
      |                 ^     ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/avtest.c:615:3: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  615 |                 len = write(sk, buf, 3);
      |                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:625:3: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  625 |                 len = write(sk, buf, 3);
      |                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:637:3: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  637 |                 len = write(sk, buf, 3);
      |                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:652:3: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  652 |                 len = write(sk, buf, 3);
      |                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:664:3: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  664 |                 len = write(sk, buf, 3);
      |                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:673:3: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  673 |                 len = write(sk, buf, 3);
      |                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:680:3: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  680 |                 len = write(sk, buf, 2);
      |                 ^     ~~~~~~~~~~~~~~~~~
tools/avtest.c:716:2: warning: Value stored to 'len' is never read [deadcode.DeadStores]
  716 |         len = write(sk, buf, AVCTP_HEADER_LENGTH + sizeof(play_pressed));
      |         ^     ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
32 warnings generated.
tools/create-image.c:76:3: warning: Value stored to 'fd' is never read [deadcode.DeadStores]
   76 |                 fd = -1;
      |                 ^    ~~
tools/create-image.c:84:3: warning: Value stored to 'fd' is never read [deadcode.DeadStores]
   84 |                 fd = -1;
      |                 ^    ~~
tools/create-image.c:92:3: warning: Value stored to 'fd' is never read [deadcode.DeadStores]
   92 |                 fd = -1;
      |                 ^    ~~
tools/create-image.c:105:2: warning: Value stored to 'fd' is never read [deadcode.DeadStores]
  105 |         fd = -1;
      |         ^    ~~
tools/create-image.c:108:2: warning: Null pointer passed to 1st parameter expecting 'nonnull' [core.NonNullParamChecker]
  108 |         fprintf(fp, HDR_FMT, HDR_MAGIC, ino, mode, 0, 0, 1, 0,
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  109 |                 (uintmax_t) st.st_size, 0, 0, 0, 0, namelen + 1, 0, name);
      |                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/create-image.c:188:2: warning: Null pointer passed to 1st parameter expecting 'nonnull' [core.NonNullParamChecker]
  188 |         fclose(fp);
      |         ^~~~~~~~~~
6 warnings generated.
tools/btgatt-client.c:1822:2: warning: Value stored to 'argv' is never read [deadcode.DeadStores]
 1822 |         argv += optind;
      |         ^       ~~~~~~
1 warning generated.
tools/btgatt-server.c:1204:2: warning: Value stored to 'argv' is never read [deadcode.DeadStores]
 1204 |         argv -= optind;
      |         ^       ~~~~~~
1 warning generated.
tools/check-selftest.c:42:3: warning: Value stored to 'ptr' is never read [deadcode.DeadStores]
   42 |                 ptr = fgets(result, sizeof(result), fp);
      |                 ^     ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
tools/gatt-service.c:294:2: warning: 2nd function call argument is an uninitialized value [core.CallAndMessage]
  294 |         chr_write(chr, value, len);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
In file included from tools/obex-server-tool.c:17:
In file included from /usr/include/fcntl.h:342:
/usr/include/x86_64-linux-gnu/bits/fcntl2.h:76:10: warning: Null pointer passed to 1st parameter expecting 'nonnull' [core.NonNullParamChecker]
   76 |   return __open_alias (__path, __oflag, __mode);
      |          ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
client/btpclient/btpclientctl.c:402:3: warning: Value stored to 'bit' is never read [deadcode.DeadStores]
  402 |                 bit = 0;
      |                 ^     ~
client/btpclient/btpclientctl.c:1655:2: warning: Null pointer passed to 2nd parameter expecting 'nonnull' [core.NonNullParamChecker]
 1655 |         memcpy(cp->data, ad_data, ad_len);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2 warnings generated.
src/sdp-client.c:353:14: warning: Access to field 'cb' results in a dereference of a null pointer [core.NullDereference]
  353 |         (*ctxt)->cb = cb;
      |         ~~~~~~~~~~~~^~~~
1 warning generated.
src/sdpd-request.c:209:13: warning: Result of 'malloc' is converted to a pointer of type 'char', which is incompatible with sizeof operand type 'uint16_t' [unix.MallocSizeof]
  209 |                                 pElem = malloc(sizeof(uint16_t));
      |                                         ^~~~~~ ~~~~~~~~~~~~~~~~
src/sdpd-request.c:237:13: warning: Result of 'malloc' is converted to a pointer of type 'char', which is incompatible with sizeof operand type 'uint32_t' [unix.MallocSizeof]
  237 |                                 pElem = malloc(sizeof(uint32_t));
      |                                         ^~~~~~ ~~~~~~~~~~~~~~~~
2 warnings generated.
src/gatt-client.c:1572:2: warning: Use of memory after it is freed [unix.Malloc]
 1572 |         notify_client_unref(client);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
src/sdp-xml.c:129:10: warning: Assigned value is uninitialized [core.uninitialized.Assign]
  129 |                 buf[1] = data[i + 1];
      |                        ^ ~~~~~~~~~~~
src/sdp-xml.c:309:11: warning: Assigned value is uninitialized [core.uninitialized.Assign]
  309 |                         buf[1] = data[i + 1];
      |                                ^ ~~~~~~~~~~~
src/sdp-xml.c:347:11: warning: Assigned value is uninitialized [core.uninitialized.Assign]
  347 |                         buf[1] = data[i + 1];
      |                                ^ ~~~~~~~~~~~
3 warnings generated.
unit/avdtp.c:756:25: warning: Use of memory after it is freed [unix.Malloc]
  756 |                 session->prio_queue = g_slist_remove(session->prio_queue, req);
      |                                       ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
unit/avdtp.c:763:24: warning: Use of memory after it is freed [unix.Malloc]
  763 |                 session->req_queue = g_slist_remove(session->req_queue, req);
      |                                      ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2 warnings generated.
unit/avrcp-lib.c:1968:3: warning: 1st function call argument is an uninitialized value [core.CallAndMessage]
 1968 |                 g_free(text[i]);
      |                 ^~~~~~~~~~~~~~~
unit/avrcp-lib.c:3510:4: warning: Address of stack memory associated with local variable 'val' is still referred to by the caller variable 'iov' upon returning to the caller.  This will be a dangling reference [core.StackAddressEscape]
 3503 |         struct media_item val[AVRCP_MEDIA_ATTRIBUTE_LAST];
      |         ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 3504 | 
 3505 |         for (i = 0; i < number; i++) {
 3506 |                 uint16_t len = 0;
 3507 | 
 3508 |                 if (attrs[i] > AVRCP_MEDIA_ATTRIBUTE_LAST ||
 3509 |                                 attrs[i] == AVRCP_MEDIA_ATTRIBUTE_ILLEGAL)
 3510 |                         return false;
      |                         ^~~~~~~~~~~~
unit/avrcp-lib.c:3526:2: warning: Address of stack memory associated with local variable 'val' is still referred to by the caller variable 'iov' upon returning to the caller.  This will be a dangling reference [core.StackAddressEscape]
 3503 |         return true;
      |         ^~~~~~~~~~~
3 warnings generated.
unit/test-util.c:33:8: warning: Potential leak of memory pointed to by 'p1' [unix.Malloc]
   33 |         p2[0] = 1;
      |         ~~~~~~^~~
unit/test-util.c:36:3: warning: Potential leak of memory pointed to by 'p2' [unix.Malloc]
   36 |                 _cleanup_free_ uint8_t *data = NULL;
      |                 ^~~~~~~~~~~~~~~~~~~~~~~~~~~~
./src/shared/util.h:134:24: note: expanded from macro '_cleanup_free_'
  134 | #define _cleanup_free_ _cleanup_(freep)
      |                        ^
./src/shared/util.h:132:22: note: expanded from macro '_cleanup_'
  132 | #define _cleanup_(f) __attribute__((cleanup(f)))
      |                      ^
unit/test-util.c:42:3: warning: Potential leak of memory pointed to by 'data' [unix.Malloc]
   42 |                 assert(is_null_too == NULL);
      |                 ^~~~~~~~~~~~~~~~~~~~~~~~~~~
/usr/include/assert.h:170:11: note: expanded from macro 'assert'
  170 |   ((void) sizeof ((expr) ? 1 : 0), __extension__ ({                     \
      |           ^~~~~~~~~~~~~~~~~~~~~~~
3 warnings generated.
profiles/audio/media.c:1134:7: warning: Use of memory after it is freed [unix.Malloc]
 1134 |                 if (req->cb != pac_select_cb) {
      |                     ^~~~~~~
1 warning generated.
profiles/audio/avctp.c:1589:3: warning: Use of memory after it is freed [unix.Malloc]
 1589 |                 avctp_disconnected(server->sessions->data);
      |                 ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
profiles/audio/a2dp.c:442:8: warning: Use of memory after it is freed [unix.Malloc]
  442 |                 if (!cb->resume_cb)
      |                      ^~~~~~~~~~~~~
profiles/audio/a2dp.c:3395:20: warning: Access to field 'starting' results in a dereference of a null pointer (loaded from variable 'stream') [core.NullDereference]
 3395 |                 stream->starting = TRUE;
      |                 ~~~~~~           ^
profiles/audio/a2dp.c:3398:8: warning: Access to field 'suspending' results in a dereference of a null pointer (loaded from variable 'stream') [core.NullDereference]
 3398 |                 if (!stream->suspending && stream->suspend_timer) {
      |                      ^~~~~~~~~~~~~~~~~~
profiles/audio/a2dp.c:3458:22: warning: Access to field 'suspending' results in a dereference of a null pointer (loaded from variable 'stream') [core.NullDereference]
 3458 |                 stream->suspending = TRUE;
      |                 ~~~~~~             ^
4 warnings generated.
profiles/audio/avdtp.c:895:25: warning: Use of memory after it is freed [unix.Malloc]
  895 |                 session->prio_queue = g_slist_remove(session->prio_queue, req);
      |                                       ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
profiles/audio/avdtp.c:902:24: warning: Use of memory after it is freed [unix.Malloc]
  902 |                 session->req_queue = g_slist_remove(session->req_queue, req);
      |                                      ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2 warnings generated.
profiles/audio/avrcp.c:1934:2: warning: Value stored to 'operands' is never read [deadcode.DeadStores]
 1934 |         operands += sizeof(*pdu);
      |         ^           ~~~~~~~~~~~~
1 warning generated.
src/sdpd-request.c:209:13: warning: Result of 'malloc' is converted to a pointer of type 'char', which is incompatible with sizeof operand type 'uint16_t' [unix.MallocSizeof]
  209 |                                 pElem = malloc(sizeof(uint16_t));
      |                                         ^~~~~~ ~~~~~~~~~~~~~~~~
src/sdpd-request.c:237:13: warning: Result of 'malloc' is converted to a pointer of type 'char', which is incompatible with sizeof operand type 'uint32_t' [unix.MallocSizeof]
  237 |                                 pElem = malloc(sizeof(uint32_t));
      |                                         ^~~~~~ ~~~~~~~~~~~~~~~~
2 warnings generated.
src/sdp-client.c:353:14: warning: Access to field 'cb' results in a dereference of a null pointer [core.NullDereference]
  353 |         (*ctxt)->cb = cb;
      |         ~~~~~~~~~~~~^~~~
1 warning generated.
src/sdp-xml.c:129:10: warning: Assigned value is uninitialized [core.uninitialized.Assign]
  129 |                 buf[1] = data[i + 1];
      |                        ^ ~~~~~~~~~~~
src/sdp-xml.c:309:11: warning: Assigned value is uninitialized [core.uninitialized.Assign]
  309 |                         buf[1] = data[i + 1];
      |                                ^ ~~~~~~~~~~~
src/sdp-xml.c:347:11: warning: Assigned value is uninitialized [core.uninitialized.Assign]
  347 |                         buf[1] = data[i + 1];
      |                                ^ ~~~~~~~~~~~
3 warnings generated.
src/gatt-client.c:1572:2: warning: Use of memory after it is freed [unix.Malloc]
 1572 |         notify_client_unref(client);
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
gobex/gobex-header.c:95:2: warning: Null pointer passed to 2nd parameter expecting 'nonnull' [core.NonNullParamChecker]
   95 |         memcpy(to, from, count);
      |         ^~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
gobex/gobex-transfer.c:424:7: warning: Use of memory after it is freed [unix.Malloc]
  424 |         if (!g_slist_find(transfers, transfer))
      |              ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
mesh/main.c:162:3: warning: Value stored to 'optarg' is never read [deadcode.DeadStores]
  162 |                 optarg += strlen("auto");
      |                 ^         ~~~~~~~~~~~~~~
1 warning generated.
lib/bluetooth/sdp.c: In function ‘sdp_get_data_size’:
lib/bluetooth/sdp.c:733:33: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
  733 |                 if (d->unitSize > sizeof(uint8_t))
      |                                 ^
lib/bluetooth/sdp.c: In function ‘sdp_data_value’:
lib/bluetooth/sdp.c:1530:48: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 1530 |                         *len = (data->unitSize > sizeof(uint8_t)) ?
      |                                                ^
lib/bluetooth/sdp.c: In function ‘sdp_set_supp_feat’:
lib/bluetooth/sdp.c:4859:62: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4859 |                                 lengths[j] = (data->unitSize > sizeof(uint8_t)) ?
      |                                                              ^
lib/bluetooth/sdp.c: In function ‘sdp_get_supp_feat’:
lib/bluetooth/sdp.c:4937:56: error: comparison of integer expressions of different signedness: ‘int’ and ‘long unsigned int’ [-Werror=sign-compare]
 4937 |                                 length = (dd->unitSize > sizeof(uint8_t)) ?
      |                                                        ^
cc1: all warnings being treated as errors
make[1]: *** [Makefile:7146: lib/bluetooth/sdp.lo] Error 1
make[1]: *** Waiting for unfinished jobs....
lib/bluetooth/hci.c:93:4: warning: Value stored to 'ptr' is never read [deadcode.DeadStores]
   93 |                         ptr += sprintf(ptr, "%s", m->str);
      |                         ^      ~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
gdbus/watch.c:226:3: warning: Attempt to free released memory [unix.Malloc]
  226 |                 g_free(l->data);
      |                 ^~~~~~~~~~~~~~~
1 warning generated.
make: *** [Makefile:4246: all] Error 2


https://github.com/bluez/bluez/pull/2632

---
Regards,
Linux Bluetooth


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-07 23:54 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-07 19:48 [PATCH] sdp: Prevent integer underflow in string attribute length calculation Hui Peng
2026-10-07 23:54 ` bluez.test.bot

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.