linux-bluetooth.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* re: Bluetooth: Add secure flag for mgmt_pin_code_req
@ 2011-09-21  7:08 Dan Carpenter
  2011-09-21 13:17 ` Rymarkiewicz Waldemar
  2011-09-22  5:58 ` [PATCH] Bluetooth: Fix possible NULL pointer dereference Waldemar Rymarkiewicz
  0 siblings, 2 replies; 7+ messages in thread
From: Dan Carpenter @ 2011-09-21  7:08 UTC (permalink / raw)
  To: waldemar.rymarkiewicz; +Cc: linux-bluetooth

Hello Waldemar Rymarkiewicz,

This is a semi-automatic email about new static checker warnings.

Thu Apr 28 12:07:59 2011 +0200
a770bb5aea84: "Bluetooth: Add secure flag for mgmt_pin_code_req"

Leads to the following Smatch complaint:
net/bluetooth/hci_event.c +2189 hci_pin_code_request_evt()
	 error: we previously assumed 'conn' could be null (see line 2177)

net/bluetooth/hci_event.c
  2176		conn = hci_conn_hash_lookup_ba(hdev, ACL_LINK, &ev->bdaddr);
  2177		if (conn && conn->state == BT_CONNECTED) {
                    ^^^^
conn can be NULL.

  2178			hci_conn_hold(conn);
  2179			conn->disc_timeout = HCI_PAIRING_TIMEOUT;
  2180			hci_conn_put(conn);
  2181		}
  2182	
  2183		if (!test_bit(HCI_PAIRABLE, &hdev->flags))
  2184			hci_send_cmd(hdev, HCI_OP_PIN_CODE_NEG_REPLY,
  2185						sizeof(ev->bdaddr), &ev->bdaddr);
  2186		else if (test_bit(HCI_MGMT, &hdev->flags)) {
  2187			u8 secure;
  2188	
  2189			if (conn->pending_sec_level == BT_SECURITY_HIGH)
                            ^^^^^^^^^^^^^^^^^^^^^^^
dereferenced unconditionally here.

  2190				secure = 1;
  2191			else

regards,
dan carpenter

^ permalink raw reply	[flat|nested] 7+ messages in thread
* [PATCH] Bluetooth : Fix possible NULL pointer dereference
@ 2017-06-17 15:45 Thomas Gagneret
  0 siblings, 0 replies; 7+ messages in thread
From: Thomas Gagneret @ 2017-06-17 15:45 UTC (permalink / raw)
  To: Marcel Holtmann, Gustavo Padovan, Johan Hedberg, linux-bluetooth
  Cc: Thomas Gagneret

If we disconnect a device before completing the connection, connection
will no longer be available in connection list, thus conn will be NULL.

Signed-off-by: Thomas Gagneret <tgagneret@witekio.com>
---
 net/bluetooth/hci_conn.c | 15 ++++++---------
 1 file changed, 6 insertions(+), 9 deletions(-)

diff --git a/net/bluetooth/hci_conn.c b/net/bluetooth/hci_conn.c
index dc59eae54717..901731c16136 100644
--- a/net/bluetooth/hci_conn.c
+++ b/net/bluetooth/hci_conn.c
@@ -723,20 +723,17 @@ static void create_le_conn_complete(struct hci_dev *hdev, u8 status, u16 opcode)
 	hci_dev_lock(hdev);
 
 	conn = hci_lookup_le_connect(hdev);
+	if (!conn)
+		goto done;
 
 	if (!status) {
 		hci_connect_le_scan_cleanup(conn);
-		goto done;
+	} else {
+		BT_ERR("HCI request failed to create LE connection: status 0x%2.2x",
+			status);
+		hci_le_conn_failed(conn, status);
 	}
 
-	BT_ERR("HCI request failed to create LE connection: status 0x%2.2x",
-	       status);
-
-	if (!conn)
-		goto done;
-
-	hci_le_conn_failed(conn, status);
-
 done:
 	hci_dev_unlock(hdev);
 }
-- 
2.13.1

^ permalink raw reply related	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2017-06-17 15:45 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-09-21  7:08 Bluetooth: Add secure flag for mgmt_pin_code_req Dan Carpenter
2011-09-21 13:17 ` Rymarkiewicz Waldemar
2011-09-22  5:58 ` [PATCH] Bluetooth: Fix possible NULL pointer dereference Waldemar Rymarkiewicz
2011-09-22  9:51   ` Marcel Holtmann
2011-09-22 10:28     ` Rymarkiewicz Waldemar
2011-09-22 10:58       ` Marcel Holtmann
  -- strict thread matches above, loose matches on Subject: below --
2017-06-17 15:45 [PATCH] Bluetooth : " Thomas Gagneret

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).