OSDN Git Service
Chris Manton [Thu, 30 Sep 2021 00:49:25 +0000 (17:49 -0700)]
osi: Prevent memory allocations with MSB set
Limit allocations on 32bit to 2 GB
Limit allocations on 64bit to 8 Exabyte
Bug:
197868577
Tag: #refactor
Test: gd/cert/run
Ignore-AOSP-First: Security
Change-Id: I1c347084d7617b1e364a3241f1b37b398a2a6c6a
Hansong Zhang [Thu, 24 Jun 2021 23:52:22 +0000 (23:52 +0000)]
SMP: Reject pairing if public_key.x match am:
9fbf77d1a8 am:
6dd3a7aa69
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
15081352
Change-Id: I10e4fd768a27480bc16939b99f631c574b3042a4
Hansong Zhang [Thu, 24 Jun 2021 23:39:06 +0000 (23:39 +0000)]
SMP: Reject pairing if public_key.x match am:
9fbf77d1a8
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
15081352
Change-Id: I72ba8e45859116cfbcde52cce89bebd7aeaf6289
Hansong Zhang [Mon, 7 Jun 2021 18:06:17 +0000 (11:06 -0700)]
SMP: Reject pairing if public_key.x match
Bug:
189329824
Test: POC
Test: pair an LE device
Change-Id: If6d8a72075f0cf657cadfab033cacffeb22868cb
Tag: #security
Richard Smith [Thu, 6 May 2021 13:14:05 +0000 (13:14 +0000)]
Fix memory overflow. am:
0d93359dbb am:
4feb117a78
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
14424506
Change-Id: If03b2528de76c1be7bba7eb620f31aee5aba80d2
Richard Smith [Thu, 6 May 2021 12:42:06 +0000 (12:42 +0000)]
Fix memory overflow. am:
0d93359dbb
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
14424506
Change-Id: I22f05c6fc477e6b2bbe8af4541a9e69854787216
Richard Smith [Mon, 22 Feb 2021 14:25:43 +0000 (14:25 +0000)]
Fix memory overflow.
Bug:
180939982
Merged-In: I1be3b836e09901c9cc614b02e21ae41b9a1ebfac
Change-Id: I1be3b836e09901c9cc614b02e21ae41b9a1ebfac
Chris Manton [Tue, 6 Apr 2021 23:52:22 +0000 (23:52 +0000)]
[automerger skipped] RESTRICT AUTOMERGE Contain avrc_ctrl_pars_vendor_cmd OOB write am:
4c9874d731 -s ours am:
e59c51d7f9 -s ours
am skip reason: subject contains skip directive
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13954699
Change-Id: I21299d11012b7aae72fc97ce8bc2d6bbbda3b48c
Chris Manton [Tue, 6 Apr 2021 23:27:32 +0000 (23:27 +0000)]
[automerger skipped] RESTRICT AUTOMERGE Contain avrc_ctrl_pars_vendor_cmd OOB write am:
4c9874d731 -s ours
am skip reason: subject contains skip directive
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13954699
Change-Id: Ie63fc83fde2308c3b8dffbf1939867b3e8ec5e7e
TreeHugger Robot [Tue, 6 Apr 2021 22:20:54 +0000 (22:20 +0000)]
Merge "RESTRICT AUTOMERGE Contain avrc_ctrl_pars_vendor_cmd OOB write" into qt-dev
Chris Manton [Tue, 6 Apr 2021 21:11:49 +0000 (21:11 +0000)]
[automerger skipped] RESTRICT AUTOMERGE Contain avrc_ctrl_pars_vendor_cmd OOB write am:
2901716406 -s ours
am skip reason: subject contains skip directive
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13954700
Change-Id: I1a5f213361798d7e22a5827ce1e42249af05aa59
Chris Manton [Sun, 21 Mar 2021 22:51:18 +0000 (15:51 -0700)]
RESTRICT AUTOMERGE Contain avrc_ctrl_pars_vendor_cmd OOB write
Bug:
181860042
Test: net_test_stack
Tag: #security
Ignore-AOSP-First: Security
Change-Id: I5d8d4051a1439ee9f1f04af3dfe6da6d8016e546
Chris Manton [Sun, 21 Mar 2021 22:51:18 +0000 (15:51 -0700)]
RESTRICT AUTOMERGE Contain avrc_ctrl_pars_vendor_cmd OOB write
Bug:
181860042
Test: net_test_stack
Tag: #security
Ignore-AOSP-First: Security
Change-Id: I5d8d4051a1439ee9f1f04af3dfe6da6d8016e546
Chris Manton [Sun, 21 Mar 2021 22:51:18 +0000 (15:51 -0700)]
RESTRICT AUTOMERGE Contain avrc_ctrl_pars_vendor_cmd OOB write
Bug:
181860042
Test: net_test_stack
Tag: #security
Ignore-AOSP-First: Security
Change-Id: I5d8d4051a1439ee9f1f04af3dfe6da6d8016e546
TreeHugger Robot [Wed, 10 Mar 2021 02:37:33 +0000 (02:37 +0000)]
Merge "AVRCP: pass bdaddr by value when use SdpCb" into pi-dev am:
529b824a10
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13516705
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: I2074374898d9695c550034ff48be0a4b8aaa0383
TreeHugger Robot [Wed, 10 Mar 2021 01:55:07 +0000 (01:55 +0000)]
Merge "AVRCP: pass bdaddr by value when use SdpCb" into pi-dev
Myles Watson [Fri, 5 Mar 2021 21:56:15 +0000 (21:56 +0000)]
[automerger skipped] smp: Reject pairing if the public keys match am:
8106ba3798 -s ours am:
75314b8d92 -s ours
am skip reason: Change-Id I0902fdf6bb5c1c7d443fc73fc480d51226fb836b with SHA-1
b7e176df4b is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13522370
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: Idb25a8fc4e94ac3ec87a6fdf398fb311b53d1cdd
Myles Watson [Fri, 5 Mar 2021 21:14:14 +0000 (21:14 +0000)]
[automerger skipped] smp: Reject pairing if the public keys match am:
8106ba3798 -s ours
am skip reason: Change-Id I0902fdf6bb5c1c7d443fc73fc480d51226fb836b with SHA-1
b7e176df4b is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13522370
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: I3d8d7fe30e1b5a805c4717f7c136562eb14f4b72
Myles Watson [Mon, 8 Feb 2021 22:38:57 +0000 (14:38 -0800)]
smp: Reject pairing if the public keys match
Bug:
174886838
Test: pair an LE device
Tag: #security
Change-Id: I0902fdf6bb5c1c7d443fc73fc480d51226fb836b
Merged-In: I0902fdf6bb5c1c7d443fc73fc480d51226fb836b
TreeHugger Robot [Fri, 5 Mar 2021 07:27:29 +0000 (07:27 +0000)]
[automerger skipped] Merge "DO NOT MERGE Add mutex for std::map in btif_av.cc" into pi-dev am:
683f95562b -s ours
am skip reason: subject contains skip directive
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13422723
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: Iad562f0bc9e68b3adc0fc6a4ee6a89bc35f66648
TreeHugger Robot [Fri, 5 Mar 2021 06:58:41 +0000 (06:58 +0000)]
Merge "DO NOT MERGE Add mutex for std::map in btif_av.cc" into pi-dev
TreeHugger Robot [Fri, 5 Mar 2021 06:54:01 +0000 (06:54 +0000)]
Merge "DO NOT MERGE Add mutex for std::map in btif_av.cc" into qt-dev
TreeHugger Robot [Fri, 5 Mar 2021 05:12:39 +0000 (05:12 +0000)]
[automerger skipped] Merge "DO NOT MERGE : Re-land: SMP: Validate remote elliptic curve points" into oc-mr1-dev am:
cfc256e14d -s ours am:
ec2cdfc472 -s ours
am skip reason: subject contains skip directive
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13756432
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: Ifd7eb81d9b7a75384ee20175174550fa06900364
TreeHugger Robot [Fri, 5 Mar 2021 05:12:31 +0000 (05:12 +0000)]
Merge "avrcp: Ignore AVCT commands that are too long" into oc-mr1-dev am:
c89971ccbb am:
c1282f371b
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13490135
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: I4cdb26816f81d622d9aed94f176a7cfd2360b1b8
TreeHugger Robot [Fri, 5 Mar 2021 04:25:22 +0000 (04:25 +0000)]
[automerger skipped] Merge "DO NOT MERGE : Re-land: SMP: Validate remote elliptic curve points" into oc-mr1-dev am:
cfc256e14d -s ours
am skip reason: subject contains skip directive
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13756432
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: Ic2e529ad7118c58426893175823dd3c5cc424817
TreeHugger Robot [Fri, 5 Mar 2021 04:25:17 +0000 (04:25 +0000)]
Merge "avrcp: Ignore AVCT commands that are too long" into oc-mr1-dev am:
c89971ccbb
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13490135
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: I2eb64b02fbecffcb2927dd9a6157822076ec26fb
TreeHugger Robot [Thu, 4 Mar 2021 23:45:46 +0000 (23:45 +0000)]
Merge "DO NOT MERGE : Re-land: SMP: Validate remote elliptic curve points" into oc-mr1-dev
TreeHugger Robot [Thu, 4 Mar 2021 23:18:24 +0000 (23:18 +0000)]
Merge "avrcp: Ignore AVCT commands that are too long" into oc-mr1-dev
Andre Eisenbach [Thu, 1 Mar 2018 21:27:01 +0000 (13:27 -0800)]
DO NOT MERGE : Re-land: SMP: Validate remote elliptic curve points
Fixes:
72377774
Test: net_test_stack_smp (where applicable)
(cherry picked from commit
9181ec28da94705a763edbe60bd2a87e5f882beb)
Change-Id: Ic38ad2f447a6a675025c84fd7746c9124f1eb324
Chienyuan [Mon, 8 Feb 2021 09:27:17 +0000 (17:27 +0800)]
AVRCP: pass bdaddr by value when use SdpCb
TAG: #security
Bug:
174182139
Test: compilation
Ignore-AOSP-First: security fix
Change-Id: Icd34986b6798e39c9b157588b943f5a883745129
Merged-In: I7f5b2a3dd0540a922b64ce213d871d355bd6dac6
Myles Watson [Wed, 3 Mar 2021 23:55:52 +0000 (23:55 +0000)]
smp: Use SMP_TRACE_WARNING am:
4567823871
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13758553
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: I2dab9afcd509f6f5082f69965c065a881e0bb64a
Myles Watson [Wed, 3 Mar 2021 21:49:21 +0000 (13:49 -0800)]
smp: Use SMP_TRACE_WARNING
Bug:
174886838
Test: pair an LE device
Tag: #security
Change-Id: I3c7e0b1dd877dfa29fa0812c6a5e65fcb1d70ea7
Myles Watson [Wed, 3 Mar 2021 19:08:40 +0000 (19:08 +0000)]
smp: Reject pairing if the public keys match am:
b7e176df4b
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13522371
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: If45c76319ea662f40ce02bc8ef9f8d6e2ce9d291
TreeHugger Robot [Wed, 3 Mar 2021 00:51:13 +0000 (00:51 +0000)]
Merge "btif: Return after closing the socket" into qt-dev
Myles Watson [Mon, 8 Feb 2021 22:38:57 +0000 (14:38 -0800)]
smp: Reject pairing if the public keys match
Bug:
174886838
Test: pair an LE device
Tag: #security
Change-Id: I0902fdf6bb5c1c7d443fc73fc480d51226fb836b
Merged-In: I0902fdf6bb5c1c7d443fc73fc480d51226fb836b
Myles Watson [Fri, 5 Feb 2021 01:30:55 +0000 (17:30 -0800)]
avrcp: Ignore AVCT commands that are too long
Bug:
177611958
Test: compilation
Tag: #security
Change-Id: If914b5928cdf16696eb54bfe91c2869cbbf8e36c
Myles Watson [Thu, 4 Feb 2021 20:54:28 +0000 (12:54 -0800)]
btif: Return after closing the socket
Bug:
175686168
Test: poc in bug
Tag: #security
Change-Id: I3af19be9bee9535e67e4dcbc2584d2084656b817
Merged-In: I3af19be9bee9535e67e4dcbc2584d2084656b817
Myles Watson [Wed, 3 Feb 2021 19:41:39 +0000 (19:41 +0000)]
Merge "avrc_copy_packet: Zero initialize packet" into oc-mr1-dev am:
63480b1eee am:
131b92ac3f
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13287217
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: If58ff39a1a996cf7f897204e5f2585589bbd4708
Myles Watson [Wed, 3 Feb 2021 18:51:32 +0000 (18:51 +0000)]
Merge "avrc_copy_packet: Zero initialize packet" into oc-mr1-dev am:
63480b1eee
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13287217
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: Iff120d88c8b6ef4016df7593e4e6fcd42426581a
Myles Watson [Wed, 3 Feb 2021 18:30:15 +0000 (18:30 +0000)]
Merge "avrc_copy_packet: Zero initialize packet" into oc-mr1-dev
Chienyuan [Thu, 28 Jan 2021 06:08:17 +0000 (14:08 +0800)]
DO NOT MERGE Add mutex for std::map in btif_av.cc
TAG: #security
Bug:
169252501
Test: compilation
Ignore-AOSP-First: security fix
Change-Id: I592c0a9c0e77869999357611aa99f3d9bc53b8b6
Chienyuan [Thu, 28 Jan 2021 06:08:17 +0000 (14:08 +0800)]
DO NOT MERGE Add mutex for std::map in btif_av.cc
TAG: #security
Bug:
169252501
Test: compilation
Ignore-AOSP-First: security fix
Change-Id: I592c0a9c0e77869999357611aa99f3d9bc53b8b6
TreeHugger Robot [Fri, 15 Jan 2021 18:00:26 +0000 (18:00 +0000)]
[automerger skipped] Merge "AVRCP: Use calloc to zero reserved fields" into pi-dev am:
52c06e73c1 -s ours
am skip reason: Change-Id I7a30edacf8377a9feecbb988b099d60d69b46f87 with SHA-1
8d461a866a is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13298159
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: Ie23077a7193bc0dd9be6138fa26211949e2253f8
TreeHugger Robot [Fri, 15 Jan 2021 17:20:28 +0000 (17:20 +0000)]
Merge "AVRCP: Use calloc to zero reserved fields" into pi-dev
TreeHugger Robot [Thu, 7 Jan 2021 17:35:10 +0000 (17:35 +0000)]
Merge "Legacy pairing: Reject device with same BD_ADDR" into oc-mr1-dev am:
93346eae3a am:
522313bb33
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13180128
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: I8f8757a8d5049f25b5bade4b5952654ed2317acd
TreeHugger Robot [Thu, 7 Jan 2021 17:35:04 +0000 (17:35 +0000)]
Merge "SDP: Only start discovery once" into oc-mr1-dev am:
a472b9b2b4 am:
76b56c906b
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13202007
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: If2b43895ad5be40059b9a81bf257906a958c40da
Myles Watson [Thu, 7 Jan 2021 17:34:53 +0000 (17:34 +0000)]
[automerger skipped] AVRCP: Use calloc to zero reserved fields am:
8d461a866a -s ours am:
581a008f10
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13204458
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: Ib996cf0eaacc56daaff94a0e80d44e1d5191dbba
TreeHugger Robot [Thu, 7 Jan 2021 17:11:30 +0000 (17:11 +0000)]
Merge "Legacy pairing: Reject device with same BD_ADDR" into oc-mr1-dev am:
93346eae3a
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13180128
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: I326bc7a210baab0d1367ec4ae49d5d76c37a5db8
TreeHugger Robot [Thu, 7 Jan 2021 17:11:24 +0000 (17:11 +0000)]
Merge "SDP: Only start discovery once" into oc-mr1-dev am:
a472b9b2b4
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13202007
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: I8aec47cad617ef5d908677365ffba53dc16c5fb8
Myles Watson [Thu, 7 Jan 2021 17:11:01 +0000 (17:11 +0000)]
[automerger skipped] AVRCP: Use calloc to zero reserved fields am:
8d461a866a -s ours
am skip reason: skipped by user mylesgw
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
13204458
MUST ONLY BE SUBMITTED BY AUTOMERGER
Change-Id: Ide49f779dd1318246564d05173387dc7535e52ae
Myles Watson [Fri, 4 Dec 2020 20:54:27 +0000 (12:54 -0800)]
AVRCP: Use calloc to zero reserved fields
Bug:
174150451
Test: compilation
Tag: #security
Change-Id: I7a30edacf8377a9feecbb988b099d60d69b46f87
(cherry picked from commit
1f169323d335ab0dc260952c2dd3821144448b11)
Merged-In: I7a30edacf8377a9feecbb988b099d60d69b46f87
(cherry picked from commit
8d461a866a12cd3d7d6d68551a5d2a7139fab2b9)
TreeHugger Robot [Wed, 6 Jan 2021 23:30:55 +0000 (23:30 +0000)]
Merge "Legacy pairing: Reject device with same BD_ADDR" into oc-mr1-dev
TreeHugger Robot [Wed, 6 Jan 2021 22:27:31 +0000 (22:27 +0000)]
Merge "SDP: Only start discovery once" into oc-mr1-dev
Hansong Zhang [Fri, 11 Dec 2020 19:56:15 +0000 (11:56 -0800)]
avrc_copy_packet: Zero initialize packet
Bug:
174149901
Change-Id: Iefa41749ebbacd34afaa24131de7ee25d706e23f
Tag: Security
Test: POC
(cherry picked from commit
960c3f3c9a1f912544b92b7a744e22069a0bc27e)
Myles Watson [Fri, 4 Dec 2020 20:54:27 +0000 (12:54 -0800)]
AVRCP: Use calloc to zero reserved fields
Bug:
174150451
Test: compilation
Tag: #security
Change-Id: I7a30edacf8377a9feecbb988b099d60d69b46f87
(cherry picked from commit
1f169323d335ab0dc260952c2dd3821144448b11)
Merged-In: I7a30edacf8377a9feecbb988b099d60d69b46f87
Myles Watson [Fri, 4 Dec 2020 02:54:14 +0000 (18:54 -0800)]
SDP: Only start discovery once
Bug:
174052148
Test: pair with headphones
Tag: #security
Change-Id: I1d014a7b793bb1b66e26652f6696499ea36a6510
(cherry picked from commit
cfa5a74ea90a09e1c7413a25f04332ee2d1e3f21)
Merged-In: I1d014a7b793bb1b66e26652f6696499ea36a6510
Hansong Zhang [Mon, 7 Dec 2020 21:11:10 +0000 (13:11 -0800)]
Legacy pairing: Reject device with same BD_ADDR
Change-Id: If3daec91c3d108a4e7e988608e0600c79ea5f053
Tag: #vulnerability
Test: manual
Bug:
174626251
TreeHugger Robot [Fri, 6 Nov 2020 07:32:10 +0000 (07:32 +0000)]
[automerger skipped] Merge "Fix potential OOB write in libbluetooth" into oc-dev am:
59304cd9d9 am:
16814b34fb -s ours am:
27feab80ac -s ours am:
8679ae4002 -s ours
am skip reason: Change-Id I90834b920d61bfb2df9414a25d73ba40033e4748 with SHA-1
ccbe059808 is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12781555
Change-Id: I8994cd9454395c1ef7e7cd387c342f81e4a7f06e
TreeHugger Robot [Fri, 6 Nov 2020 07:14:25 +0000 (07:14 +0000)]
[automerger skipped] Merge "Fix potential OOB write in libbluetooth" into oc-dev am:
59304cd9d9 am:
16814b34fb -s ours am:
27feab80ac -s ours
am skip reason: Change-Id I90834b920d61bfb2df9414a25d73ba40033e4748 with SHA-1
ccbe059808 is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12781555
Change-Id: Id5df4067761338488fab280586f4c3812c246e8d
TreeHugger Robot [Fri, 6 Nov 2020 06:55:53 +0000 (06:55 +0000)]
[automerger skipped] Merge "Fix potential OOB write in libbluetooth" into oc-dev am:
59304cd9d9 am:
16814b34fb -s ours
am skip reason: Change-Id I90834b920d61bfb2df9414a25d73ba40033e4748 with SHA-1
ccbe059808 is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12781555
Change-Id: I28095eaddb51067420afdc51b3fb8245d65047fc
TreeHugger Robot [Fri, 6 Nov 2020 06:20:17 +0000 (06:20 +0000)]
[automerger skipped] Merge "Fix potential OOB write in libbluetooth" into oc-mr1-dev am:
e1aed6e373 -s ours am:
0a7502bb9a -s ours
am skip reason: Change-Id I90834b920d61bfb2df9414a25d73ba40033e4748 with SHA-1
8216eda074 is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12778874
Change-Id: I0c52de9f785ac2cb9a703adfcc8f19c68b635f69
TreeHugger Robot [Fri, 6 Nov 2020 06:20:08 +0000 (06:20 +0000)]
[automerger skipped] Merge "Fix potential OOB write in libbluetooth" into pi-dev am:
a3296c0750 -s ours
am skip reason: Change-Id I90834b920d61bfb2df9414a25d73ba40033e4748 with SHA-1
26d2f1d06a is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12778873
Change-Id: I59247f8bdb3119e33990038381ac68a85766dd6f
TreeHugger Robot [Fri, 6 Nov 2020 06:20:03 +0000 (06:20 +0000)]
Merge "Fix potential OOB write in libbluetooth" into oc-dev am:
59304cd9d9
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12781555
Change-Id: I905bd02ad475b238005d0589a1c0171d842d7201
TreeHugger Robot [Fri, 6 Nov 2020 06:19:52 +0000 (06:19 +0000)]
[automerger skipped] Merge "Fix potential OOB write in libbluetooth" into oc-mr1-dev am:
e1aed6e373 -s ours
am skip reason: Change-Id I90834b920d61bfb2df9414a25d73ba40033e4748 with SHA-1
8216eda074 is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12778874
Change-Id: I38e0bcf46b33e303fa1ee9e4a5981131935df028
TreeHugger Robot [Fri, 6 Nov 2020 05:51:59 +0000 (05:51 +0000)]
Merge "Fix potential OOB write in libbluetooth" into oc-mr1-dev
TreeHugger Robot [Fri, 6 Nov 2020 05:51:59 +0000 (05:51 +0000)]
Merge "Fix potential OOB write in libbluetooth" into qt-dev
TreeHugger Robot [Fri, 6 Nov 2020 05:51:58 +0000 (05:51 +0000)]
Merge "Fix potential OOB write in libbluetooth" into pi-dev
TreeHugger Robot [Fri, 6 Nov 2020 05:51:58 +0000 (05:51 +0000)]
Merge "Fix potential OOB write in libbluetooth" into oc-dev
Myles Watson [Fri, 6 Nov 2020 02:12:38 +0000 (02:12 +0000)]
[automerger skipped] ACL: Drop broadcasts am:
f91dbe2985 am:
10cfa5e827 am:
e21d07e16e -s ours am:
de31f09430 -s ours
am skip reason: Change-Id Id4231fd7a142d630a2ada0f41a90e01afc011045 with SHA-1
83c32e8e8c is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12951241
Change-Id: I53768da66285cc776fb47931964282ed6211b1b1
Myles Watson [Fri, 6 Nov 2020 01:18:23 +0000 (01:18 +0000)]
[automerger skipped] ACL: Drop broadcasts am:
f91dbe2985 am:
10cfa5e827 am:
e21d07e16e -s ours
am skip reason: Change-Id Id4231fd7a142d630a2ada0f41a90e01afc011045 with SHA-1
83c32e8e8c is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12951241
Change-Id: I2c0a49d927f48b823a808b45aa871768d0fff05c
Myles Watson [Fri, 6 Nov 2020 01:05:27 +0000 (01:05 +0000)]
ACL: Drop broadcasts am:
f91dbe2985 am:
10cfa5e827
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12951241
Change-Id: I2e274a4614d10187586949a742a9d6716778bc28
Myles Watson [Fri, 6 Nov 2020 00:51:32 +0000 (00:51 +0000)]
ACL: Drop broadcasts am:
83c32e8e8c
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12951249
Change-Id: Ib7004546cc8e6dc05b13ca1a009e3c43eeb910b9
Myles Watson [Fri, 6 Nov 2020 00:51:21 +0000 (00:51 +0000)]
ACL: Drop broadcasts am:
f91dbe2985
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12951241
Change-Id: I490deea8c83019ec92f6c76a276c50495cd40cdc
Myles Watson [Thu, 29 Oct 2020 20:05:21 +0000 (13:05 -0700)]
ACL: Drop broadcasts
Bug:
169327567
Test: compiles
Tag: #security
Change-Id: Id4231fd7a142d630a2ada0f41a90e01afc011045
Merged-In: Id4231fd7a142d630a2ada0f41a90e01afc011045
Myles Watson [Thu, 29 Oct 2020 20:05:21 +0000 (13:05 -0700)]
ACL: Drop broadcasts
Bug:
169327567
Test: compiles
Tag: #security
Change-Id: Id4231fd7a142d630a2ada0f41a90e01afc011045
Merged-In: Id4231fd7a142d630a2ada0f41a90e01afc011045
Hansong Zhang [Thu, 8 Oct 2020 19:53:48 +0000 (19:53 +0000)]
Fix a security issue in sdp_server.cc am:
d7573f4fa9 am:
97abd549aa am:
5d2163956a am:
484161c4d9
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12776129
Change-Id: I5af578102b0479225c0d192eee47717a49d4646b
Hansong Zhang [Thu, 8 Oct 2020 19:26:52 +0000 (19:26 +0000)]
Fix a security issue in sdp_server.cc am:
d7573f4fa9 am:
97abd549aa am:
5d2163956a
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12776129
Change-Id: I08de9b5e95e5c65b64ea3153a988c67520932a1e
Hansong Zhang [Thu, 8 Oct 2020 19:14:34 +0000 (19:14 +0000)]
Fix a security issue in sdp_server.cc am:
d7573f4fa9 am:
97abd549aa
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12776129
Change-Id: I1563f2793cc2d637be9935f04d9673e050dd0c67
Hansong Zhang [Thu, 8 Oct 2020 19:00:20 +0000 (19:00 +0000)]
Fix a security issue in sdp_server.cc am:
d7573f4fa9
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12776129
Change-Id: I017650c339df1f8dec41594e9d2d18d7f8d7fc6a
Ted Wang [Tue, 6 Oct 2020 12:20:16 +0000 (20:20 +0800)]
Fix potential OOB write in libbluetooth
Check event id if of register notification command from remote to avoid
OOB write.
Tag: #security
Bug:
168802990
Test: atest net_test_btif
Change-Id: I90834b920d61bfb2df9414a25d73ba40033e4748
Merged-In: I90834b920d61bfb2df9414a25d73ba40033e4748
Ted Wang [Tue, 6 Oct 2020 12:20:16 +0000 (20:20 +0800)]
Fix potential OOB write in libbluetooth
Check event id if of register notification command from remote to avoid
OOB write.
Tag: #security
Bug:
168802990
Test: atest net_test_btif
Change-Id: I90834b920d61bfb2df9414a25d73ba40033e4748
Merged-In: I90834b920d61bfb2df9414a25d73ba40033e4748
Ted Wang [Tue, 6 Oct 2020 12:20:16 +0000 (20:20 +0800)]
Fix potential OOB write in libbluetooth
Check event id if of register notification command from remote to avoid
OOB write.
Tag: #security
Bug:
168802990
Test: atest net_test_btif
Change-Id: I90834b920d61bfb2df9414a25d73ba40033e4748
Merged-In: I90834b920d61bfb2df9414a25d73ba40033e4748
Ted Wang [Tue, 6 Oct 2020 12:20:16 +0000 (20:20 +0800)]
Fix potential OOB write in libbluetooth
Check event id if of register notification command from remote to avoid
OOB write.
Tag: #security
Bug:
168802990
Test: atest net_test_btif
Change-Id: I90834b920d61bfb2df9414a25d73ba40033e4748
Merged-In: I90834b920d61bfb2df9414a25d73ba40033e4748
Hansong Zhang [Tue, 6 Oct 2020 21:48:27 +0000 (14:48 -0700)]
Fix a security issue in sdp_server.cc
Bug:
169342531
Test: POC
Change-Id: I0e8cdb9a00184f62d11fb06bc30f07b2a35bc49e
Chen Chen [Tue, 6 Oct 2020 20:53:43 +0000 (20:53 +0000)]
Check Classic key before cross-key derivation am:
814160abca am:
6cddc6cd87 am:
98e0ae0ef9 am:
7337996317
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12736109
Change-Id: Iaa69ebded8be2055cb9fee48d2d0b2e3ec8365cf
Chen Chen [Tue, 6 Oct 2020 20:16:04 +0000 (20:16 +0000)]
Check Classic key before cross-key derivation am:
814160abca am:
6cddc6cd87 am:
98e0ae0ef9
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12736109
Change-Id: I7d010b57ab226b166d9895d95101056b2f305d31
Chen Chen [Tue, 6 Oct 2020 19:57:19 +0000 (19:57 +0000)]
Check Classic key before cross-key derivation am:
814160abca am:
6cddc6cd87
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12736109
Change-Id: I1391cb656ed035aaec7beb0f2c11e5b3c008f4cc
Chen Chen [Tue, 6 Oct 2020 18:52:36 +0000 (18:52 +0000)]
Check Classic key before cross-key derivation am:
814160abca
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12736109
Change-Id: I10b980c9f480dd9e2f2adb5af47cb23ff99421e6
Chen Chen [Thu, 24 Sep 2020 00:02:58 +0000 (17:02 -0700)]
Check Classic key before cross-key derivation
Bug:
158854097
Test: atest net_test_stack_smp
Tag: #security
Ignore-AOSP-First: Security fix
Exempt-From-Owner-Approval: Already got owner approval,
but somehow it still shows no owner vote
Change-Id: Id88241324e9fb89ef14e50b52eb459a0d81c492b
Chen Chen [Tue, 6 Oct 2020 03:59:41 +0000 (03:59 +0000)]
Check Classic key before cross-key derivation am:
992e25e6b9 am:
eec1a1e896
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12736893
Change-Id: Icfc2e05b44e48cc1ee6dd4594877a85195ea15f0
Chen Chen [Tue, 6 Oct 2020 03:59:33 +0000 (03:59 +0000)]
Check Classic key before cross-key derivation am:
da8aa68903
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12687761
Change-Id: I85a19b10f4f7ac9ec94811d022ed28b2e9a2b848
Chen Chen [Tue, 6 Oct 2020 03:59:17 +0000 (03:59 +0000)]
Check Classic key before cross-key derivation am:
992e25e6b9
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12736893
Change-Id: I7bad5de1a8d79930b54c7075405b75ee466fc3fa
Chen Chen [Thu, 24 Sep 2020 00:02:58 +0000 (17:02 -0700)]
Check Classic key before cross-key derivation
Bug:
158854097
Test: atest net_test_stack_smp
Tag: #security
Ignore-AOSP-First: Security fix
Change-Id: Id88241324e9fb89ef14e50b52eb459a0d81c492b
Chen Chen [Thu, 24 Sep 2020 00:02:58 +0000 (17:02 -0700)]
Check Classic key before cross-key derivation
Bug:
158854097
Test: atest net_test_stack_smp
Tag: #security
Ignore-AOSP-First: Security fix
Change-Id: Id88241324e9fb89ef14e50b52eb459a0d81c492b
Chen Chen [Thu, 24 Sep 2020 00:02:58 +0000 (17:02 -0700)]
Check Classic key before cross-key derivation
Bug:
158854097
Test: atest net_test_stack_smp
Tag: #security
Ignore-AOSP-First: Security fix
Change-Id: Id88241324e9fb89ef14e50b52eb459a0d81c492b
TreeHugger Robot [Mon, 31 Aug 2020 18:02:24 +0000 (18:02 +0000)]
[automerger skipped] Merge "Send a response to an smp security request depending on the callback event" into oc-dev am:
9f1c709363 am:
28de519df5 -s ours am:
9361f12bad -s ours am:
dd0f5d9ae0 -s ours
am skip reason: Change-Id Iadeb25a43b46f615b55a0dfb6e7723e5d1204351 with SHA-1
1570e8de12 is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12448858
Change-Id: Ia2c0620d025a91e2ba4cf0cd4acd5326d71c8522
li-wei.cheng [Mon, 31 Aug 2020 18:02:16 +0000 (18:02 +0000)]
[automerger skipped] Return after removing sample LTK device am:
c6879c3fe5 am:
bf69312868 am:
74ebab6814 -s ours am:
1f118853c5 -s ours
am skip reason: Change-Id Iaa59f3c415dd8066849fd70912fdb83f890229d7 with SHA-1
7c86810c44 is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12325453
Change-Id: I075047a75067503e98c3d2251b03cad2e5a6fefc
Jakub Pawlowski [Mon, 31 Aug 2020 18:02:07 +0000 (18:02 +0000)]
[automerger skipped] Don't persist bonds using sample LTK am:
70411f0877 -s ours am:
f79ba4c65d am:
1c00e23d9f
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12484285
Change-Id: I2b6213a807eedaa840a15813efed81ed17d81e6d
TreeHugger Robot [Mon, 31 Aug 2020 17:18:27 +0000 (17:18 +0000)]
[automerger skipped] Merge "Send a response to an smp security request depending on the callback event" into oc-dev am:
9f1c709363 am:
28de519df5 -s ours am:
9361f12bad -s ours
am skip reason: Change-Id Iadeb25a43b46f615b55a0dfb6e7723e5d1204351 with SHA-1
1570e8de12 is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12448858
Change-Id: I2fb43fe52f2214df67e87dc27ea95ba4f2d4c7fb
li-wei.cheng [Mon, 31 Aug 2020 17:18:20 +0000 (17:18 +0000)]
[automerger skipped] Return after removing sample LTK device am:
c6879c3fe5 am:
bf69312868 am:
74ebab6814 -s ours
am skip reason: Change-Id Iaa59f3c415dd8066849fd70912fdb83f890229d7 with SHA-1
7c86810c44 is in history
Original change: https://googleplex-android-review.googlesource.com/c/platform/system/bt/+/
12325453
Change-Id: I18dee0776a1cfec33193598750f27767e451b054