* [BlueZ 1/3] avrcp: Split off name parsing from parse_*_element()
@ 2026-08-04 12:44 Bastien Nocera
2026-08-04 12:44 ` [BlueZ 2/3] unit: Adapt poc_*_oob.c test into a new test Bastien Nocera
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Bastien Nocera @ 2026-08-04 12:44 UTC (permalink / raw)
To: linux-bluetooth
This will allow us to use the name extraction code in
parse_media_element() and parse_folder_element() separately, such
as in tests.
---
Makefile.plugins | 1 +
profiles/audio/avrcp-parse.c | 47 ++++++++++++++++++++++++++++++++++++
profiles/audio/avrcp-parse.h | 18 ++++++++++++++
profiles/audio/avrcp.c | 26 +++++---------------
4 files changed, 72 insertions(+), 20 deletions(-)
create mode 100644 profiles/audio/avrcp-parse.c
create mode 100644 profiles/audio/avrcp-parse.h
diff --git a/Makefile.plugins b/Makefile.plugins
index ac667beda847..a505fcd6691f 100644
--- a/Makefile.plugins
+++ b/Makefile.plugins
@@ -37,6 +37,7 @@ builtin_modules += avrcp
builtin_sources += profiles/audio/control.h profiles/audio/control.c \
profiles/audio/avctp.h profiles/audio/avctp.c \
profiles/audio/avrcp.h profiles/audio/avrcp.c \
+ profiles/audio/avrcp-parse.h profiles/audio/avrcp-parse.c \
profiles/audio/avrcp-player.c
endif
diff --git a/profiles/audio/avrcp-parse.c b/profiles/audio/avrcp-parse.c
new file mode 100644
index 000000000000..d3d0a070a4da
--- /dev/null
+++ b/profiles/audio/avrcp-parse.c
@@ -0,0 +1,47 @@
+// SPDX-License-Identifier: GPL-2.0-or-later
+/*
+ *
+ * BlueZ - Bluetooth protocol stack for Linux
+ *
+ * Copyright (C) 2026 Red Hat Inc.
+ *
+ *
+ */
+
+#include "avrcp-parse.h"
+#include "src/shared/util.h"
+
+gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
+ char *name, uint16_t *namesize)
+{
+ uint16_t namelen;
+
+ if (len < 13)
+ return FALSE;
+
+ memset(name, 0, NAME_MAX_LEN);
+ *namesize = get_be16(&operands[11]);
+ namelen = MIN(*namesize, NAME_MAX_LEN - 1);
+ if (namelen > 0) {
+ memcpy(name, &operands[13], namelen);
+ strtoutf8(name, namelen);
+ }
+
+ return TRUE;
+}
+
+gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
+ char *name)
+{
+ uint16_t namelen;
+
+ if (len < 12)
+ return FALSE;
+
+ memset(name, 0, NAME_MAX_LEN);
+ namelen = MIN(get_be16(&operands[12]), NAME_MAX_LEN - 1);
+ if (namelen > 0)
+ memcpy(name, &operands[14], namelen);
+
+ return TRUE;
+}
diff --git a/profiles/audio/avrcp-parse.h b/profiles/audio/avrcp-parse.h
new file mode 100644
index 000000000000..d98aab4b2eee
--- /dev/null
+++ b/profiles/audio/avrcp-parse.h
@@ -0,0 +1,18 @@
+// SPDX-License-Identifier: GPL-2.0-or-later
+/*
+ *
+ * BlueZ - Bluetooth protocol stack for Linux
+ *
+ * Copyright (C) 2026 Red Hat Inc.
+ *
+ *
+ */
+
+#include <glib.h>
+
+#define NAME_MAX_LEN 255
+
+gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
+ char *name, uint16_t *namesize);
+gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
+ char *name);
diff --git a/profiles/audio/avrcp.c b/profiles/audio/avrcp.c
index 2194a913580f..af3c72174764 100644
--- a/profiles/audio/avrcp.c
+++ b/profiles/audio/avrcp.c
@@ -52,6 +52,7 @@
#include "avctp.h"
#include "avrcp.h"
+#include "avrcp-parse.h"
#include "control.h"
#include "media.h"
#include "player.h"
@@ -2614,24 +2615,15 @@ static struct media_item *parse_media_element(struct avrcp *session,
struct avrcp_player *player;
struct media_player *mp;
struct media_item *item;
- uint16_t namelen, namesize;
- char name[255];
+ uint16_t namesize;
+ char name[NAME_MAX_LEN];
uint64_t uid;
uint8_t count;
- if (len < 13)
+ if (!parse_media_element_name(operands, len, name, &namesize))
return NULL;
uid = get_be64(&operands[0]);
-
- memset(name, 0, sizeof(name));
- namesize = get_be16(&operands[11]);
- namelen = MIN(namesize, sizeof(name) - 1);
- if (namelen > 0) {
- memcpy(name, &operands[13], namelen);
- strtoutf8(name, namelen);
- }
-
count = operands[13 + namesize];
player = session->controller->player;
@@ -2655,24 +2647,18 @@ static struct media_item *parse_media_folder(struct avrcp *session,
struct avrcp_player *player = session->controller->player;
struct media_player *mp = player->user_data;
struct media_item *item;
- uint16_t namelen;
- char name[255];
+ char name[NAME_MAX_LEN];
uint64_t uid;
uint8_t type;
uint8_t playable;
- if (len < 12)
+ if (!parse_media_folder_name(operands, len, name))
return NULL;
uid = get_be64(&operands[0]);
type = operands[8];
playable = operands[9];
- memset(name, 0, sizeof(name));
- namelen = MIN(get_be16(&operands[12]), sizeof(name) - 1);
- if (namelen > 0)
- memcpy(name, &operands[14], namelen);
-
item = media_player_create_folder(mp, name, type, uid);
if (!item)
return NULL;
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [BlueZ 2/3] unit: Adapt poc_*_oob.c test into a new test
2026-08-04 12:44 [BlueZ 1/3] avrcp: Split off name parsing from parse_*_element() Bastien Nocera
@ 2026-08-04 12:44 ` Bastien Nocera
2026-08-04 12:44 ` [BlueZ 3/3] avrcp: Fix Out-of-Bounds Read in AVRCP GetFolderItems parsing Bastien Nocera
2026-08-04 13:49 ` [BlueZ,1/3] avrcp: Split off name parsing from parse_*_element() bluez.test.bot
2 siblings, 0 replies; 4+ messages in thread
From: Bastien Nocera @ 2026-08-04 12:44 UTC (permalink / raw)
To: linux-bluetooth; +Cc: Elman Shahbazov
Adapt poc_avrcp_oob.c and poc_folder_oob.c into unit tests.
Co-authored-by: Elman Shahbazov <shahbazovelman97@gmail.com>
---
Makefile.am | 9 +++++
unit/test-avrcp-sec.c | 76 +++++++++++++++++++++++++++++++++++++++++++
2 files changed, 85 insertions(+)
create mode 100644 unit/test-avrcp-sec.c
diff --git a/Makefile.am b/Makefile.am
index 19c468d3a504..e3baa4155c1f 100644
--- a/Makefile.am
+++ b/Makefile.am
@@ -660,6 +660,15 @@ unit_test_avrcp_SOURCES = unit/test-avrcp.c \
unit_test_avrcp_LDADD = lib/libbluetooth-internal.la \
src/libshared-glib.la $(GLIB_LIBS)
+unit_tests += unit/test-avrcp-sec
+
+unit_test_avrcp_sec_SOURCES = unit/test-avrcp-sec.c \
+ profiles/audio/avrcp-parse.c \
+ profiles/audio/avrcp-parse.h \
+ src/log.h src/log.c
+unit_test_avrcp_sec_LDADD = lib/libbluetooth-internal.la \
+ src/libshared-glib.la $(GLIB_LIBS)
+
unit_tests += unit/test-hfp
unit_test_hfp_SOURCES = unit/test-hfp.c
diff --git a/unit/test-avrcp-sec.c b/unit/test-avrcp-sec.c
new file mode 100644
index 000000000000..a100b2d68e35
--- /dev/null
+++ b/unit/test-avrcp-sec.c
@@ -0,0 +1,76 @@
+// SPDX-License-Identifier: GPL-2.0-or-later
+/*
+ *
+ * BlueZ - Bluetooth protocol stack for Linux
+ *
+ * Copyright (C) 2026 Red Hat Inc.
+ *
+ *
+ */
+
+#ifdef HAVE_CONFIG_H
+#include <config.h>
+#endif
+
+#include <glib.h>
+
+#include "src/shared/util.h"
+#include "src/shared/tester.h"
+#include "src/log.h"
+
+#include "profiles/audio/avrcp-parse.h"
+
+static void avrcp_element_name_oob(gconstpointer data)
+{
+ char name[255];
+ uint16_t namesize;
+ gboolean ret;
+
+ /* Crafting a malicious payload.
+ * Actual packet length (len) = 14 bytes */
+ uint8_t malicious_packet[14] = {0};
+
+ /* Specify namesize = 1000 (0x03E8 in Big Endian) at offset 11 */
+ malicious_packet[11] = 0x03;
+ malicious_packet[12] = 0xE8;
+
+ /* Launching the PoC. We transmit a 14-byte packet, but namesize=1000... */
+ ret = parse_media_element_name(malicious_packet, sizeof(malicious_packet),
+ name, &namesize);
+ if (ret)
+ tester_test_passed();
+ else
+ tester_test_failed();
+}
+
+static void avrcp_folder_name_oob(gconstpointer data)
+{
+ char name[255];
+ gboolean ret;
+
+ /* Crafting a malicious payload.
+ * Actual packet length (len) = 14 bytes */
+ uint8_t malicious_packet[14] = {0};
+
+ /* Specify namesize = 1000 (0x03E8 in Big Endian) at offset 12 */
+ malicious_packet[12] = 0x03;
+ malicious_packet[13] = 0xE8;
+
+ /* Launching the PoC. We transmit a 14-byte packet, but namesize=1000... */
+ ret = parse_media_folder_name(malicious_packet, sizeof(malicious_packet),
+ name);
+ if (ret)
+ tester_test_passed();
+ else
+ tester_test_failed();
+}
+
+int main(int argc, char *argv[])
+{
+ tester_init(&argc, &argv);
+
+ tester_add("/avrcp-element-name-oob", NULL, NULL, avrcp_element_name_oob, NULL);
+ tester_add("/avrcp-folder-name-oob", NULL, NULL, avrcp_folder_name_oob, NULL);
+
+ return tester_run();
+}
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [BlueZ 3/3] avrcp: Fix Out-of-Bounds Read in AVRCP GetFolderItems parsing
2026-08-04 12:44 [BlueZ 1/3] avrcp: Split off name parsing from parse_*_element() Bastien Nocera
2026-08-04 12:44 ` [BlueZ 2/3] unit: Adapt poc_*_oob.c test into a new test Bastien Nocera
@ 2026-08-04 12:44 ` Bastien Nocera
2026-08-04 13:49 ` [BlueZ,1/3] avrcp: Split off name parsing from parse_*_element() bluez.test.bot
2 siblings, 0 replies; 4+ messages in thread
From: Bastien Nocera @ 2026-08-04 12:44 UTC (permalink / raw)
To: linux-bluetooth; +Cc: Elman Shahbazov
From: Elman Shahbazov <shahbazovelman97@gmail.com>
Co-Authored-by: Bastien Nocera <hadess@hadess.net>
---
profiles/audio/avrcp-parse.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/profiles/audio/avrcp-parse.c b/profiles/audio/avrcp-parse.c
index d3d0a070a4da..251580fd9c55 100644
--- a/profiles/audio/avrcp-parse.c
+++ b/profiles/audio/avrcp-parse.c
@@ -20,8 +20,12 @@ gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
return FALSE;
memset(name, 0, NAME_MAX_LEN);
- *namesize = get_be16(&operands[11]);
+ *namesize = MIN(get_be16(&operands[11]), len - 13);
namelen = MIN(*namesize, NAME_MAX_LEN - 1);
+
+ if (len < 13 + *namesize)
+ return FALSE;
+
if (namelen > 0) {
memcpy(name, &operands[13], namelen);
strtoutf8(name, namelen);
@@ -39,7 +43,8 @@ gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
return FALSE;
memset(name, 0, NAME_MAX_LEN);
- namelen = MIN(get_be16(&operands[12]), NAME_MAX_LEN - 1);
+ namelen = MIN(get_be16(&operands[12]), len - 14);
+ namelen = MIN(namelen, NAME_MAX_LEN - 1);
if (namelen > 0)
memcpy(name, &operands[14], namelen);
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* RE: [BlueZ,1/3] avrcp: Split off name parsing from parse_*_element()
2026-08-04 12:44 [BlueZ 1/3] avrcp: Split off name parsing from parse_*_element() Bastien Nocera
2026-08-04 12:44 ` [BlueZ 2/3] unit: Adapt poc_*_oob.c test into a new test Bastien Nocera
2026-08-04 12:44 ` [BlueZ 3/3] avrcp: Fix Out-of-Bounds Read in AVRCP GetFolderItems parsing Bastien Nocera
@ 2026-08-04 13:49 ` bluez.test.bot
2 siblings, 0 replies; 4+ messages in thread
From: bluez.test.bot @ 2026-08-04 13:49 UTC (permalink / raw)
To: linux-bluetooth, hadess
[-- Attachment #1: Type: text/plain, Size: 54331 bytes --]
This is automated email and please do not reply to this email!
Dear submitter,
Thank you for submitting the patches to the linux bluetooth mailing list.
This is a CI test results with your patch series:
PW Link:https://patchwork.kernel.org/project/bluetooth/list/?series=1140113
---Test result---
Test Summary:
CheckPatch FAIL 1.35 seconds
GitLint PASS 1.23 seconds
BuildEll PASS 20.08 seconds
BluezMake FAIL 465.50 seconds
MakeCheck FAIL 164.46 seconds
MakeDistcheck FAIL 81.94 seconds
CheckValgrind FAIL 77.34 seconds
CheckSmatch FAIL 161.19 seconds
bluezmakeextell FAIL 58.46 seconds
IncrementalBuild FAIL 517.67 seconds
ScanBuild FAIL 186.98 seconds
Details
##############################
Test: CheckPatch - FAIL
Desc: Run checkpatch.pl script
Output:
[BlueZ,2/3] unit: Adapt poc_*_oob.c test into a new test
WARNING:BAD_SIGN_OFF: Non-standard signature: Co-authored-by:
#56:
Co-authored-by: Elman Shahbazov <shahbazovelman97@gmail.com>
WARNING:BLOCK_COMMENT_STYLE: Block comments use a trailing */ on a separate line
#118: FILE: unit/test-avrcp-sec.c:30:
+ * Actual packet length (len) = 14 bytes */
WARNING:LONG_LINE_COMMENT: line length of 83 exceeds 80 columns
#125: FILE: unit/test-avrcp-sec.c:37:
+ /* Launching the PoC. We transmit a 14-byte packet, but namesize=1000... */
WARNING:LONG_LINE: line length of 82 exceeds 80 columns
#126: FILE: unit/test-avrcp-sec.c:38:
+ ret = parse_media_element_name(malicious_packet, sizeof(malicious_packet),
WARNING:BLOCK_COMMENT_STYLE: Block comments use a trailing */ on a separate line
#140: FILE: unit/test-avrcp-sec.c:52:
+ * Actual packet length (len) = 14 bytes */
WARNING:LONG_LINE_COMMENT: line length of 83 exceeds 80 columns
#147: FILE: unit/test-avrcp-sec.c:59:
+ /* Launching the PoC. We transmit a 14-byte packet, but namesize=1000... */
WARNING:LONG_LINE: line length of 81 exceeds 80 columns
#148: FILE: unit/test-avrcp-sec.c:60:
+ ret = parse_media_folder_name(malicious_packet, sizeof(malicious_packet),
WARNING:LONG_LINE: line length of 88 exceeds 80 columns
#160: FILE: unit/test-avrcp-sec.c:72:
+ tester_add("/avrcp-element-name-oob", NULL, NULL, avrcp_element_name_oob, NULL);
WARNING:LONG_LINE: line length of 86 exceeds 80 columns
#161: FILE: unit/test-avrcp-sec.c:73:
+ tester_add("/avrcp-folder-name-oob", NULL, NULL, avrcp_folder_name_oob, NULL);
/github/workspace/src/patch/14730082.patch total: 0 errors, 9 warnings, 91 lines checked
NOTE: For some of the reported defects, checkpatch may be able to
mechanically convert to the typical style using --fix or --fix-inplace.
/github/workspace/src/patch/14730082.patch has style problems, please review.
NOTE: Ignored message types: COMMIT_MESSAGE COMPLEX_MACRO CONST_STRUCT FILE_PATH_CHANGES MISSING_SIGN_OFF PREFER_PACKED SPDX_LICENSE_TAG SPLIT_STRING SSCANF_TO_KSTRTO
NOTE: If any of the errors are false positives, please report
them to the maintainer, see CHECKPATCH in MAINTAINERS.
[BlueZ,3/3] avrcp: Fix Out-of-Bounds Read in AVRCP GetFolderItems parsing
WARNING:BAD_SIGN_OFF: Non-standard signature: Co-Authored-by:
#57:
Co-Authored-by: Bastien Nocera <hadess@hadess.net>
WARNING:BAD_SIGN_OFF: 'Co-authored-by:' is the preferred signature form
#57:
Co-Authored-by: Bastien Nocera <hadess@hadess.net>
/github/workspace/src/patch/14730080.patch total: 0 errors, 2 warnings, 22 lines checked
NOTE: For some of the reported defects, checkpatch may be able to
mechanically convert to the typical style using --fix or --fix-inplace.
/github/workspace/src/patch/14730080.patch has style problems, please review.
NOTE: Ignored message types: COMMIT_MESSAGE COMPLEX_MACRO CONST_STRUCT FILE_PATH_CHANGES MISSING_SIGN_OFF PREFER_PACKED SPDX_LICENSE_TAG SPLIT_STRING SSCANF_TO_KSTRTO
NOTE: If any of the errors are false positives, please report
them to the maintainer, see CHECKPATCH in MAINTAINERS.
##############################
Test: BluezMake - FAIL
Desc: Build BlueZ
Output:
tools/mgmt-tester.c: In function ‘main’:
tools/mgmt-tester.c:13131:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
13131 | int main(int argc, char *argv[])
| ^~~~
unit/test-avdtp.c: In function ‘main’:
unit/test-avdtp.c:766:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
766 | int main(int argc, char *argv[])
| ^~~~
unit/test-avrcp.c: In function ‘main’:
unit/test-avrcp.c:989:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
989 | int main(int argc, char *argv[])
| ^~~~
In file included from profiles/audio/avrcp-parse.c:11:
profiles/audio/avrcp-parse.h:15:35: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:15:54: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:16:19: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
16 | char *name, uint16_t *namesize);
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:17:34: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:17:53: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.c:14:10: error: no previous declaration for ‘parse_media_element_name’ [-Werror=missing-declarations]
14 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~~
profiles/audio/avrcp-parse.c:37:10: error: no previous declaration for ‘parse_media_folder_name’ [-Werror=missing-declarations]
37 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~
cc1: all warnings being treated as errors
make[1]: *** [Makefile:8756: profiles/audio/bluetoothd-avrcp-parse.o] Error 1
make[1]: *** Waiting for unfinished jobs....
make: *** [Makefile:4198: all] Error 2
##############################
Test: MakeCheck - FAIL
Desc: Run Bluez Make Check
Output:
In file included from profiles/audio/avrcp-parse.c:11:
profiles/audio/avrcp-parse.h:15:35: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:15:54: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:16:19: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
16 | char *name, uint16_t *namesize);
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:17:34: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:17:53: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.c:14:10: error: no previous declaration for ‘parse_media_element_name’ [-Werror=missing-declarations]
14 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~~
profiles/audio/avrcp-parse.c:37:10: error: no previous declaration for ‘parse_media_folder_name’ [-Werror=missing-declarations]
37 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~
cc1: all warnings being treated as errors
make[1]: *** [Makefile:7101: profiles/audio/avrcp-parse.o] Error 1
make: *** [Makefile:10884: check] Error 2
##############################
Test: MakeDistcheck - FAIL
Desc: Run Bluez Make Distcheck
Output:
In file included from ../../profiles/audio/avrcp-parse.c:11:
../../profiles/audio/avrcp-parse.h:15:35: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
../../profiles/audio/avrcp-parse.h:15:54: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
../../profiles/audio/avrcp-parse.h:16:19: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
16 | char *name, uint16_t *namesize);
| ^~~~~~~~
| u_int16_t
../../profiles/audio/avrcp-parse.h:17:34: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
../../profiles/audio/avrcp-parse.h:17:53: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
make[2]: *** [Makefile:8756: profiles/audio/bluetoothd-avrcp-parse.o] Error 1
make[2]: *** Waiting for unfinished jobs....
make[1]: *** [Makefile:4198: all] Error 2
make: *** [Makefile:10805: distcheck] Error 1
##############################
Test: CheckValgrind - FAIL
Desc: Run Bluez Make Check with Valgrind
Output:
tools/mgmt-tester.c: In function ‘main’:
tools/mgmt-tester.c:13131:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
13131 | int main(int argc, char *argv[])
| ^~~~
In file included from profiles/audio/avrcp-parse.c:11:
profiles/audio/avrcp-parse.h:15:35: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:15:54: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:16:19: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
16 | char *name, uint16_t *namesize);
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:17:34: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:17:53: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.c:14:10: error: no previous declaration for ‘parse_media_element_name’ [-Werror=missing-declarations]
14 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~~
profiles/audio/avrcp-parse.c:37:10: error: no previous declaration for ‘parse_media_folder_name’ [-Werror=missing-declarations]
37 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~
cc1: all warnings being treated as errors
make[1]: *** [Makefile:8756: profiles/audio/bluetoothd-avrcp-parse.o] Error 1
make[1]: *** Waiting for unfinished jobs....
make: *** [Makefile:10884: check] Error 2
##############################
Test: CheckSmatch - FAIL
Desc: Run smatch tool with source
Output:
src/shared/crypto.c:271:21: warning: Variable length array is used.
src/shared/crypto.c:272:23: warning: Variable length array is used.
src/shared/gatt-helpers.c:764:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:842:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:1335:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:1366:23: warning: Variable length array is used.
src/shared/gatt-server.c:271:25: warning: Variable length array is used.
src/shared/gatt-server.c:614:25: warning: Variable length array is used.
src/shared/gatt-server.c:712:25: warning: Variable length array is used.
src/shared/bap.c:318:25: warning: array of flexible structures
src/shared/bap.c: note: in included file:
./src/shared/ascs.h:88:25: warning: array of flexible structures
src/shared/shell.c: note: in included file (through /usr/include/readline/readline.h):
/usr/include/readline/rltypedefs.h:35:23: warning: non-ANSI function declaration of function 'Function'
/usr/include/readline/rltypedefs.h:36:25: warning: non-ANSI function declaration of function 'VFunction'
/usr/include/readline/rltypedefs.h:37:27: warning: non-ANSI function declaration of function 'CPFunction'
/usr/include/readline/rltypedefs.h:38:29: warning: non-ANSI function declaration of function 'CPPFunction'
src/shared/crypto.c:271:21: warning: Variable length array is used.
src/shared/crypto.c:272:23: warning: Variable length array is used.
src/shared/gatt-helpers.c:764:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:842:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:1335:31: warning: Variable length array is used.
src/shared/gatt-helpers.c:1366:23: warning: Variable length array is used.
src/shared/gatt-server.c:271:25: warning: Variable length array is used.
src/shared/gatt-server.c:614:25: warning: Variable length array is used.
src/shared/gatt-server.c:712:25: warning: Variable length array is used.
src/shared/bap.c:318:25: warning: array of flexible structures
src/shared/bap.c: note: in included file:
./src/shared/ascs.h:88:25: warning: array of flexible structures
src/shared/shell.c: note: in included file (through /usr/include/readline/readline.h):
/usr/include/readline/rltypedefs.h:35:23: warning: non-ANSI function declaration of function 'Function'
/usr/include/readline/rltypedefs.h:36:25: warning: non-ANSI function declaration of function 'VFunction'
/usr/include/readline/rltypedefs.h:37:27: warning: non-ANSI function declaration of function 'CPFunction'
/usr/include/readline/rltypedefs.h:38:29: warning: non-ANSI function declaration of function 'CPPFunction'
tools/mesh-cfgtest.c:1453:17: warning: unknown escape sequence: '\%'
tools/sco-tester.c: note: in included file:
./lib/bluetooth/bluetooth.h:232:15: warning: array of flexible structures
./lib/bluetooth/bluetooth.h:237:31: warning: array of flexible structures
tools/bneptest.c:634:39: warning: unknown escape sequence: '\%'
tools/seq2bseq.c:57:26: warning: Variable length array is used.
tools/obex-client-tool.c: note: in included file (through /usr/include/readline/readline.h):
/usr/include/readline/rltypedefs.h:35:23: warning: non-ANSI function declaration of function 'Function'
/usr/include/readline/rltypedefs.h:36:25: warning: non-ANSI function declaration of function 'VFunction'
/usr/include/readline/rltypedefs.h:37:27: warning: non-ANSI function declaration of function 'CPFunction'
/usr/include/readline/rltypedefs.h:38:29: warning: non-ANSI function declaration of function 'CPPFunction'
client/btpclient/gatt.c: note: in included file:
./src/shared/btp.h:335:41: warning: array of flexible structures
./src/shared/btp.h:340:55: warning: array of flexible structures
./src/shared/btp.h:363:47: warning: array of flexible structures
./src/shared/btp.h:392:42: warning: array of flexible structures
src/advertising.c: note: in included file:
./src/shared/mgmt.h:95:25: error: redefinition of unsigned int enum mgmt_io_capability
src/agent.c: note: in included file:
src/shared/queue.h:19:20: error: redefinition of struct queue_entry
src/adv_monitor.c: note: in included file:
./src/shared/mgmt.h:95:25: error: redefinition of unsigned int enum mgmt_io_capability
unit/avctp.c:505:34: warning: Variable length array is used.
unit/avctp.c:556:34: warning: Variable length array is used.
unit/test-avrcp.c:373:26: warning: Variable length array is used.
unit/test-avrcp.c:398:26: warning: Variable length array is used.
unit/test-avrcp.c:414:24: warning: Variable length array is used.
unit/avrcp-lib.c:1085:34: warning: Variable length array is used.
unit/avrcp-lib.c:1583:34: warning: Variable length array is used.
unit/avrcp-lib.c:1612:34: warning: Variable length array is used.
unit/avrcp-lib.c:1638:34: warning: Variable length array is used.
profiles/audio/avrcp-parse.c: note: in included file:
profiles/audio/avrcp-parse.h:15:43: error: Expected ) in function declarator
profiles/audio/avrcp-parse.h:15:43: error: got *
profiles/audio/avrcp-parse.h:17:42: error: Expected ) in function declarator
profiles/audio/avrcp-parse.h:17:42: error: got *
In file included from profiles/audio/avrcp-parse.c:11:
profiles/audio/avrcp-parse.h:15:35: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:15:54: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:16:19: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
16 | char *name, uint16_t *namesize);
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:17:34: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:17:53: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.c:14:10: error: no previous declaration for ‘parse_media_element_name’ [-Werror=missing-declarations]
14 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~~
profiles/audio/avrcp-parse.c:37:10: error: no previous declaration for ‘parse_media_folder_name’ [-Werror=missing-declarations]
37 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~
cc1: all warnings being treated as errors
make[1]: *** [Makefile:8756: profiles/audio/bluetoothd-avrcp-parse.o] Error 1
make[1]: *** Waiting for unfinished jobs....
make: *** [Makefile:4198: all] Error 2
##############################
Test: bluezmakeextell - FAIL
Desc: Build Bluez with External ELL
Output:
In file included from profiles/audio/avrcp-parse.c:11:
profiles/audio/avrcp-parse.h:15:35: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:15:54: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:16:19: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
16 | char *name, uint16_t *namesize);
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:17:34: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:17:53: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.c:14:10: error: no previous declaration for ‘parse_media_element_name’ [-Werror=missing-declarations]
14 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~~
profiles/audio/avrcp-parse.c:37:10: error: no previous declaration for ‘parse_media_folder_name’ [-Werror=missing-declarations]
37 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~
cc1: all warnings being treated as errors
make[1]: *** [Makefile:8756: profiles/audio/bluetoothd-avrcp-parse.o] Error 1
make[1]: *** Waiting for unfinished jobs....
make: *** [Makefile:4198: all] Error 2
##############################
Test: IncrementalBuild - FAIL
Desc: Incremental build with the patches in the series
Output:
tools/mgmt-tester.c: In function ‘main’:
tools/mgmt-tester.c:13131:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
13131 | int main(int argc, char *argv[])
| ^~~~
unit/test-avdtp.c: In function ‘main’:
unit/test-avdtp.c:766:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
766 | int main(int argc, char *argv[])
| ^~~~
unit/test-avrcp.c: In function ‘main’:
unit/test-avrcp.c:989:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
989 | int main(int argc, char *argv[])
| ^~~~
In file included from profiles/audio/avrcp-parse.c:11:
profiles/audio/avrcp-parse.h:15:35: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:15:54: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:16:19: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
16 | char *name, uint16_t *namesize);
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:17:34: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:17:53: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.c:14:10: error: no previous declaration for ‘parse_media_element_name’ [-Werror=missing-declarations]
14 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~~
profiles/audio/avrcp-parse.c:33:10: error: no previous declaration for ‘parse_media_folder_name’ [-Werror=missing-declarations]
33 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~
cc1: all warnings being treated as errors
make[1]: *** [Makefile:8729: profiles/audio/bluetoothd-avrcp-parse.o] Error 1
make[1]: *** Waiting for unfinished jobs....
make: *** [Makefile:4181: all] Error 2
[BlueZ,1/3] avrcp: Split off name parsing from parse_*_element()
tools/mgmt-tester.c: In function ‘main’:
tools/mgmt-tester.c:13131:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
13131 | int main(int argc, char *argv[])
| ^~~~
unit/test-avdtp.c: In function ‘main’:
unit/test-avdtp.c:766:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
766 | int main(int argc, char *argv[])
| ^~~~
unit/test-avrcp.c: In function ‘main’:
unit/test-avrcp.c:989:5: note: variable tracking size limit exceeded with ‘-fvar-tracking-assignments’, retrying without
989 | int main(int argc, char *argv[])
| ^~~~
In file included from profiles/audio/avrcp-parse.c:11:
profiles/audio/avrcp-parse.h:15:35: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:15:54: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:16:19: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
16 | char *name, uint16_t *namesize);
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:17:34: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:17:53: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.c:14:10: error: no previous declaration for ‘parse_media_element_name’ [-Werror=missing-declarations]
14 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~~
profiles/audio/avrcp-parse.c:33:10: error: no previous declaration for ‘parse_media_folder_name’ [-Werror=missing-declarations]
33 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~
cc1: all warnings being treated as errors
make[1]: *** [Makefile:8729: profiles/audio/bluetoothd-avrcp-parse.o] Error 1
make[1]: *** Waiting for unfinished jobs....
make: *** [Makefile:4181: all] Error 2
##############################
Test: ScanBuild - FAIL
Desc: Run Scan Build
Output:
src/shared/gatt-client.c:447:21: warning: Use of memory after it is freed
gatt_db_unregister(op->client->db, op->db_id);
^~~~~~~~~~
src/shared/gatt-client.c:692:2: warning: Use of memory after it is freed
discovery_op_complete(op, false, att_ecode);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:992:2: warning: Use of memory after it is freed
discovery_op_complete(op, success, att_ecode);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1098:2: warning: Use of memory after it is freed
discovery_op_complete(op, success, att_ecode);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1292:2: warning: Use of memory after it is freed
discovery_op_complete(op, success, att_ecode);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1357:2: warning: Use of memory after it is freed
discovery_op_complete(op, success, att_ecode);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1632:6: warning: Use of memory after it is freed
if (read_db_hash(op)) {
^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1637:2: warning: Use of memory after it is freed
discover_all(op);
^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1693:56: warning: Use of memory after it is freed
notify_data->chrc->ccc_write_id = notify_data->att_id = att_id;
~~~~~~~~~~~~~~~~~~~ ^
src/shared/gatt-client.c:2146:6: warning: Use of memory after it is freed
if (read_db_hash(op)) {
^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:2154:8: warning: Use of memory after it is freed
discovery_op_ref(op),
^~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:3332:2: warning: Use of memory after it is freed
complete_write_long_op(req, success, 0, false);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:3354:2: warning: Use of memory after it is freed
request_unref(req);
^~~~~~~~~~~~~~~~~~
13 warnings generated.
src/shared/rap.c:3554:13: warning: Use of memory after it is freed
attached = queue_find(sessions, NULL, rap);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
src/shared/bap.c:1543:8: warning: Use of memory after it is freed
bap = bt_bap_ref_safe(bap);
^~~~~~~~~~~~~~~~~~~~
src/shared/bap.c:2354:20: warning: Use of memory after it is freed
return queue_find(stream->bap->streams, NULL, stream);
^~~~~~~~~~~~~~~~~~~~
2 warnings generated.
src/shared/gatt-client.c:447:21: warning: Use of memory after it is freed
gatt_db_unregister(op->client->db, op->db_id);
^~~~~~~~~~
src/shared/gatt-client.c:692:2: warning: Use of memory after it is freed
discovery_op_complete(op, false, att_ecode);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:992:2: warning: Use of memory after it is freed
discovery_op_complete(op, success, att_ecode);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1098:2: warning: Use of memory after it is freed
discovery_op_complete(op, success, att_ecode);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1292:2: warning: Use of memory after it is freed
discovery_op_complete(op, success, att_ecode);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1357:2: warning: Use of memory after it is freed
discovery_op_complete(op, success, att_ecode);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1632:6: warning: Use of memory after it is freed
if (read_db_hash(op)) {
^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1637:2: warning: Use of memory after it is freed
discover_all(op);
^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:1693:56: warning: Use of memory after it is freed
notify_data->chrc->ccc_write_id = notify_data->att_id = att_id;
~~~~~~~~~~~~~~~~~~~ ^
src/shared/gatt-client.c:2146:6: warning: Use of memory after it is freed
if (read_db_hash(op)) {
^~~~~~~~~~~~~~~~
src/shared/gatt-client.c:2154:8: warning: Use of memory after it is freed
discovery_op_ref(op),
^~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:3332:2: warning: Use of memory after it is freed
complete_write_long_op(req, success, 0, false);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/shared/gatt-client.c:3354:2: warning: Use of memory after it is freed
request_unref(req);
^~~~~~~~~~~~~~~~~~
13 warnings generated.
src/shared/rap.c:3554:13: warning: Use of memory after it is freed
attached = queue_find(sessions, NULL, rap);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
tools/hciattach.c:817:7: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n'
if ((n = read_hci_event(fd, resp, 10)) < 0) {
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/hciattach.c:865:7: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n'
if ((n = read_hci_event(fd, resp, 4)) < 0) {
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/hciattach.c:887:8: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n'
if ((n = read_hci_event(fd, resp, 10)) < 0) {
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/hciattach.c:909:7: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n'
if ((n = read_hci_event(fd, resp, 4)) < 0) {
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/hciattach.c:930:7: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n'
if ((n = read_hci_event(fd, resp, 4)) < 0) {
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/hciattach.c:974:7: warning: Although the value stored to 'n' is used in the enclosing expression, the value is never actually read from 'n'
if ((n = read_hci_event(fd, resp, 6)) < 0) {
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~
6 warnings generated.
src/shared/bap.c:1543:8: warning: Use of memory after it is freed
bap = bt_bap_ref_safe(bap);
^~~~~~~~~~~~~~~~~~~~
src/shared/bap.c:2354:20: warning: Use of memory after it is freed
return queue_find(stream->bap->streams, NULL, stream);
^~~~~~~~~~~~~~~~~~~~
2 warnings generated.
src/oui.c:50:2: warning: Value stored to 'hwdb' is never read
hwdb = udev_hwdb_unref(hwdb);
^ ~~~~~~~~~~~~~~~~~~~~~
src/oui.c:53:2: warning: Value stored to 'udev' is never read
udev = udev_unref(udev);
^ ~~~~~~~~~~~~~~~~
2 warnings generated.
tools/rfcomm.c:234:3: warning: Value stored to 'i' is never read
i = execvp(cmdargv[0], cmdargv);
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/rfcomm.c:234:7: warning: Null pointer passed to 1st parameter expecting 'nonnull'
i = execvp(cmdargv[0], cmdargv);
^~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/rfcomm.c:354:8: warning: Although the value stored to 'fd' is used in the enclosing expression, the value is never actually read from 'fd'
if ((fd = open(devname, O_RDONLY | O_NOCTTY)) < 0) {
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/rfcomm.c:497:14: warning: Assigned value is garbage or undefined
req.channel = raddr.rc_channel;
^ ~~~~~~~~~~~~~~~~
tools/rfcomm.c:515:8: warning: Although the value stored to 'fd' is used in the enclosing expression, the value is never actually read from 'fd'
if ((fd = open(devname, O_RDONLY | O_NOCTTY)) < 0) {
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
5 warnings generated.
tools/ciptool.c:351:7: warning: 5th function call argument is an uninitialized value
sk = do_connect(ctl, dev_id, &src, &dst, psm, (1 << CMTP_LOOPBACK));
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
src/sdp-xml.c:126:10: warning: Assigned value is garbage or undefined
buf[1] = data[i + 1];
^ ~~~~~~~~~~~
src/sdp-xml.c:306:11: warning: Assigned value is garbage or undefined
buf[1] = data[i + 1];
^ ~~~~~~~~~~~
src/sdp-xml.c:344:11: warning: Assigned value is garbage or undefined
buf[1] = data[i + 1];
^ ~~~~~~~~~~~
3 warnings generated.
tools/sdptool.c:941:26: warning: Result of 'malloc' is converted to a pointer of type 'uint32_t', which is incompatible with sizeof operand type 'int'
uint32_t *value_int = malloc(sizeof(int));
~~~~~~~~~~ ^~~~~~ ~~~~~~~~~~~
tools/sdptool.c:980:4: warning: 1st function call argument is an uninitialized value
free(allocArray[i]);
^~~~~~~~~~~~~~~~~~~
tools/sdptool.c:3777:2: warning: Potential leak of memory pointed to by 'si.name'
return add_service(0, &si);
^~~~~~~~~~~~~~~~~~~~~~~~~~
tools/sdptool.c:4112:4: warning: Potential leak of memory pointed to by 'context.svc'
return -1;
^~~~~~~~~
4 warnings generated.
tools/avtest.c:243:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 3);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:253:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 4);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:262:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 3);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:276:5: warning: Value stored to 'len' is never read
len = write(sk, buf,
^ ~~~~~~~~~~~~~~
tools/avtest.c:283:5: warning: Value stored to 'len' is never read
len = write(sk, buf,
^ ~~~~~~~~~~~~~~
tools/avtest.c:290:5: warning: Value stored to 'len' is never read
len = write(sk, buf,
^ ~~~~~~~~~~~~~~
tools/avtest.c:297:5: warning: Value stored to 'len' is never read
len = write(sk, buf,
^ ~~~~~~~~~~~~~~
tools/avtest.c:309:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 4);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:313:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 2);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:322:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 3);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:326:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 2);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:335:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 3);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:342:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 2);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:364:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 4);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:368:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 2);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:377:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 3);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:381:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 2);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:394:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 4);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:398:5: warning: Value stored to 'len' is never read
len = write(sk, buf, 2);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:405:4: warning: Value stored to 'len' is never read
len = write(sk, buf, 2);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:415:4: warning: Value stored to 'len' is never read
len = write(sk, buf, 2);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:580:3: warning: Value stored to 'len' is never read
len = write(sk, buf, 2);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:588:3: warning: Value stored to 'len' is never read
len = write(sk, buf, invalid ? 2 : 3);
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/avtest.c:602:3: warning: Value stored to 'len' is never read
len = write(sk, buf, 4 + media_transport_size);
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/avtest.c:615:3: warning: Value stored to 'len' is never read
len = write(sk, buf, 3);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:625:3: warning: Value stored to 'len' is never read
len = write(sk, buf, 3);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:637:3: warning: Value stored to 'len' is never read
len = write(sk, buf, 3);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:652:3: warning: Value stored to 'len' is never read
len = write(sk, buf, 3);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:664:3: warning: Value stored to 'len' is never read
len = write(sk, buf, 3);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:673:3: warning: Value stored to 'len' is never read
len = write(sk, buf, 3);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:680:3: warning: Value stored to 'len' is never read
len = write(sk, buf, 2);
^ ~~~~~~~~~~~~~~~~~
tools/avtest.c:716:2: warning: Value stored to 'len' is never read
len = write(sk, buf, AVCTP_HEADER_LENGTH + sizeof(play_pressed));
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
32 warnings generated.
tools/btproxy.c:836:15: warning: Null pointer passed to 1st parameter expecting 'nonnull'
tcp_port = atoi(optarg);
^~~~~~~~~~~~
tools/btproxy.c:839:8: warning: Null pointer passed to 1st parameter expecting 'nonnull'
if (strlen(optarg) > 3 && !strncmp(optarg, "hci", 3))
^~~~~~~~~~~~~~
2 warnings generated.
tools/create-image.c:76:3: warning: Value stored to 'fd' is never read
fd = -1;
^ ~~
tools/create-image.c:84:3: warning: Value stored to 'fd' is never read
fd = -1;
^ ~~
tools/create-image.c:92:3: warning: Value stored to 'fd' is never read
fd = -1;
^ ~~
tools/create-image.c:105:2: warning: Value stored to 'fd' is never read
fd = -1;
^ ~~
4 warnings generated.
tools/check-selftest.c:42:3: warning: Value stored to 'ptr' is never read
ptr = fgets(result, sizeof(result), fp);
^ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
tools/btgatt-client.c:1822:2: warning: Value stored to 'argv' is never read
argv += optind;
^ ~~~~~~
1 warning generated.
tools/btgatt-server.c:1204:2: warning: Value stored to 'argv' is never read
argv -= optind;
^ ~~~~~~
1 warning generated.
tools/gatt-service.c:294:2: warning: 2nd function call argument is an uninitialized value
chr_write(chr, value, len);
^~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
tools/obex-server-tool.c:133:13: warning: Null pointer passed to 1st parameter expecting 'nonnull'
data->fd = open(name, O_WRONLY | O_CREAT | O_NOCTTY, 0600);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
tools/obex-server-tool.c:192:13: warning: Null pointer passed to 1st parameter expecting 'nonnull'
data->fd = open(name, O_RDONLY | O_NOCTTY, 0);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2 warnings generated.
tools/test-runner.c:1367:2: warning: Address of stack memory associated with local variable 'kernel_path' is still referred to by the global variable 'kernel_image' upon returning to the caller. This will be a dangling reference
return EXIT_SUCCESS;
^~~~~~~~~~~~~~~~~~~
1 warning generated.
client/btpclient/btpclientctl.c:402:3: warning: Value stored to 'bit' is never read
bit = 0;
^ ~
client/btpclient/btpclientctl.c:1655:2: warning: Null pointer passed to 2nd parameter expecting 'nonnull'
memcpy(cp->data, ad_data, ad_len);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2 warnings generated.
src/sdp-client.c:353:14: warning: Access to field 'cb' results in a dereference of a null pointer
(*ctxt)->cb = cb;
~~~~~~~~~~~~^~~~
1 warning generated.
src/sdpd-request.c:209:13: warning: Result of 'malloc' is converted to a pointer of type 'char', which is incompatible with sizeof operand type 'uint16_t'
pElem = malloc(sizeof(uint16_t));
^~~~~~ ~~~~~~~~~~~~~~~~
src/sdpd-request.c:237:13: warning: Result of 'malloc' is converted to a pointer of type 'char', which is incompatible with sizeof operand type 'uint32_t'
pElem = malloc(sizeof(uint32_t));
^~~~~~ ~~~~~~~~~~~~~~~~
2 warnings generated.
src/gatt-database.c:1171:10: warning: Value stored to 'bits' during its initialization is never read
uint8_t bits[] = { BT_GATT_CHRC_CLI_FEAT_ROBUST_CACHING,
^~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
src/gatt-client.c:1569:2: warning: Use of memory after it is freed
notify_client_unref(client);
^~~~~~~~~~~~~~~~~~~~~~~~~~~
1 warning generated.
unit/avrcp-lib.c:1968:3: warning: 1st function call argument is an uninitialized value
g_free(text[i]);
^~~~~~~~~~~~~~~
1 warning generated.
unit/avdtp.c:756:25: warning: Use of memory after it is freed
session->prio_queue = g_slist_remove(session->prio_queue, req);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
unit/avdtp.c:763:24: warning: Use of memory after it is freed
session->req_queue = g_slist_remove(session->req_queue, req);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2 warnings generated.
unit/test-util.c:33:8: warning: Potential leak of memory pointed to by 'p1'
p2[0] = 1;
~~~~~~^~~
unit/test-util.c:36:3: warning: Potential leak of memory pointed to by 'p2'
_cleanup_free_ uint8_t *data = NULL;
^~~~~~~~~~~~~~~~~~~~~~~~~~~~
./src/shared/util.h:134:24: note: expanded from macro '_cleanup_free_'
#define _cleanup_free_ _cleanup_(freep)
^
./src/shared/util.h:132:22: note: expanded from macro '_cleanup_'
#define _cleanup_(f) __attribute__((cleanup(f)))
^
unit/test-util.c:42:3: warning: Potential leak of memory pointed to by 'data'
assert(is_null_too == NULL);
^~~~~~~~~~~~~~~~~~~~~~~~~~~
/usr/include/assert.h:108:11: note: expanded from macro 'assert'
((void) sizeof ((expr) ? 1 : 0), __extension__ ({ \
^~~~~~~~~~~~~~~~~~~~~~~
unit/test-util.c:50:2: warning: Potential leak of memory pointed to by 'data'
assert(is_null == NULL);
^~~~~~~~~~~~~~~~~~~~~~~
/usr/include/assert.h:108:11: note: expanded from macro 'assert'
((void) sizeof ((expr) ? 1 : 0), __extension__ ({ \
^~~~~~~~~~~~~~~~~~~~~~~
4 warnings generated.
profiles/audio/avdtp.c:895:25: warning: Use of memory after it is freed
session->prio_queue = g_slist_remove(session->prio_queue, req);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
profiles/audio/avdtp.c:902:24: warning: Use of memory after it is freed
session->req_queue = g_slist_remove(session->req_queue, req);
^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2 warnings generated.
In file included from profiles/audio/avrcp-parse.c:11:
profiles/audio/avrcp-parse.h:15:35: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:15:54: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
15 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:16:19: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
16 | char *name, uint16_t *namesize);
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.h:17:34: error: unknown type name ‘uint8_t’; did you mean ‘u_int8_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~
| u_int8_t
profiles/audio/avrcp-parse.h:17:53: error: unknown type name ‘uint16_t’; did you mean ‘u_int16_t’?
17 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~
| u_int16_t
profiles/audio/avrcp-parse.c:14:10: error: no previous declaration for ‘parse_media_element_name’ [-Werror=missing-declarations]
14 | gboolean parse_media_element_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~~
profiles/audio/avrcp-parse.c:33:10: error: no previous declaration for ‘parse_media_folder_name’ [-Werror=missing-declarations]
33 | gboolean parse_media_folder_name(uint8_t *operands, uint16_t len,
| ^~~~~~~~~~~~~~~~~~~~~~~
cc1: all warnings being treated as errors
make[1]: *** [Makefile:8729: profiles/audio/bluetoothd-avrcp-parse.o] Error 1
make[1]: *** Waiting for unfinished jobs....
profiles/audio/a2dp.c:442:8: warning: Use of memory after it is freed
if (!cb->resume_cb)
^~~~~~~~~~~~~
profiles/audio/a2dp.c:3361:20: warning: Access to field 'starting' results in a dereference of a null pointer (loaded from variable 'stream')
stream->starting = TRUE;
~~~~~~ ^
profiles/audio/a2dp.c:3364:8: warning: Access to field 'suspending' results in a dereference of a null pointer (loaded from variable 'stream')
if (!stream->suspending && stream->suspend_timer) {
^~~~~~~~~~~~~~~~~~
profiles/audio/a2dp.c:3424:22: warning: Access to field 'suspending' results in a dereference of a null pointer (loaded from variable 'stream')
stream->suspending = TRUE;
~~~~~~ ^
4 warnings generated.
profiles/audio/avrcp.c:1969:2: warning: Value stored to 'operands' is never read
operands += sizeof(*pdu);
^ ~~~~~~~~~~~~
1 warning generated.
make: *** [Makefile:4181: all] Error 2
https://github.com/bluez/bluez/pull/2374
---
Regards,
Linux Bluetooth
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-04 13:49 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-04 12:44 [BlueZ 1/3] avrcp: Split off name parsing from parse_*_element() Bastien Nocera
2026-08-04 12:44 ` [BlueZ 2/3] unit: Adapt poc_*_oob.c test into a new test Bastien Nocera
2026-08-04 12:44 ` [BlueZ 3/3] avrcp: Fix Out-of-Bounds Read in AVRCP GetFolderItems parsing Bastien Nocera
2026-08-04 13:49 ` [BlueZ,1/3] avrcp: Split off name parsing from parse_*_element() bluez.test.bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox