Commit 1ee3da6b authored by Alain Michaud's avatar Alain Michaud Committed by Greg Kroah-Hartman

Bluetooth: guard against controllers sending zero'd events

[ Upstream commit 08bb4da9 ]

Some controllers have been observed to send zero'd events under some
conditions.  This change guards against this condition as well as adding
a trace to facilitate diagnosability of this condition.
Signed-off-by: default avatarAlain Michaud <alainm@chromium.org>
Signed-off-by: default avatarMarcel Holtmann <marcel@holtmann.org>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
parent 8910d3f0
...@@ -5738,6 +5738,11 @@ void hci_event_packet(struct hci_dev *hdev, struct sk_buff *skb) ...@@ -5738,6 +5738,11 @@ void hci_event_packet(struct hci_dev *hdev, struct sk_buff *skb)
u8 status = 0, event = hdr->evt, req_evt = 0; u8 status = 0, event = hdr->evt, req_evt = 0;
u16 opcode = HCI_OP_NOP; u16 opcode = HCI_OP_NOP;
if (!event) {
bt_dev_warn(hdev, "Received unexpected HCI Event 00000000");
goto done;
}
if (hdev->sent_cmd && bt_cb(hdev->sent_cmd)->hci.req_event == event) { if (hdev->sent_cmd && bt_cb(hdev->sent_cmd)->hci.req_event == event) {
struct hci_command_hdr *cmd_hdr = (void *) hdev->sent_cmd->data; struct hci_command_hdr *cmd_hdr = (void *) hdev->sent_cmd->data;
opcode = __le16_to_cpu(cmd_hdr->opcode); opcode = __le16_to_cpu(cmd_hdr->opcode);
...@@ -5949,6 +5954,7 @@ void hci_event_packet(struct hci_dev *hdev, struct sk_buff *skb) ...@@ -5949,6 +5954,7 @@ void hci_event_packet(struct hci_dev *hdev, struct sk_buff *skb)
req_complete_skb(hdev, status, opcode, orig_skb); req_complete_skb(hdev, status, opcode, orig_skb);
} }
done:
kfree_skb(orig_skb); kfree_skb(orig_skb);
kfree_skb(skb); kfree_skb(skb);
hdev->stat.evt_rx++; hdev->stat.evt_rx++;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment