<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/bluez.git, branch 5.39</title>
<subtitle>git.kernel.org: pub/scm/bluetooth/bluez.git
</subtitle>
<link rel='alternate' type='text/html' href='http://trove.baserock.org/cgit/delta/bluez.git/'/>
<entry>
<title>Release 5.39</title>
<updated>2016-04-04T22:15:47+00:00</updated>
<author>
<name>Marcel Holtmann</name>
<email>marcel@holtmann.org</email>
</author>
<published>2016-04-04T22:15:47+00:00</published>
<link rel='alternate' type='text/html' href='http://trove.baserock.org/cgit/delta/bluez.git/commit/?id=969cc06e08d613f58b113bbc60c2ba25dfda3b25'/>
<id>969cc06e08d613f58b113bbc60c2ba25dfda3b25</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>lib: Update company identifiers</title>
<updated>2016-04-04T22:06:05+00:00</updated>
<author>
<name>Marcel Holtmann</name>
<email>marcel@holtmann.org</email>
</author>
<published>2016-04-04T22:06:05+00:00</published>
<link rel='alternate' type='text/html' href='http://trove.baserock.org/cgit/delta/bluez.git/commit/?id=49ad9f8632f1b3a48eac355d0008ad163e51447f'/>
<id>49ad9f8632f1b3a48eac355d0008ad163e51447f</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>shared/gatt-server: Add support for long write</title>
<updated>2016-04-04T13:15:08+00:00</updated>
<author>
<name>Łukasz Rymanowski</name>
<email>lukasz.rymanowski@codecoup.pl</email>
</author>
<published>2016-04-02T20:26:47+00:00</published>
<link rel='alternate' type='text/html' href='http://trove.baserock.org/cgit/delta/bluez.git/commit/?id=55bcfbc309ed0c91190aeabd3ba03d20c7da1470'/>
<id>55bcfbc309ed0c91190aeabd3ba03d20c7da1470</id>
<content type='text'>
With this patch long write and nested long write reliable is supported.
GATT server is responsible now to do aggregation of prep write data
for long write session.
Note: We consider long write as the consequtive prepare writes with
continues offsets.

E.g. 1

prep_write: handle 1, offset 0, value_len 10
prep_write: handle 1, offset 10, value_len 10
prep_write: handle 2, offset 0, value_len 10
prep_write: handle 2, offset 10, value_len 10

Will result with following calles to app:

exec_write: handle 1: offset 0, value_len 20
exec_write: handle 2: offset 0, value_len 20

E.g. 2

prep_write: handle 1, offset 0, value_len 10
prep_write: handle 1, offset 2, value_len 5
prep_write: handle 2, offset 0, value_len 10
prep_write: handle 2, offset 4, value_len 5

Will result with following calles to app:

exec_write: handle 1: offset 0, value_len 10
exec_write: handle 1: offset 2, value_len 5
exec_write: handle 2: offset 0, value_len 10
exec_write: handle 2: offset 4, value_len 5

E.g. 3
prep_write: handle 1, offset 0, value_len 10
prep_write: handle 1, offset 5, value_len 5
prep_write: handle 1, offset 10, value_len 6

will result with following calles to app:

exec_write: handle 1, offset 0, value 10
exec_write: handle 1, offset 5, value 11
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
With this patch long write and nested long write reliable is supported.
GATT server is responsible now to do aggregation of prep write data
for long write session.
Note: We consider long write as the consequtive prepare writes with
continues offsets.

E.g. 1

prep_write: handle 1, offset 0, value_len 10
prep_write: handle 1, offset 10, value_len 10
prep_write: handle 2, offset 0, value_len 10
prep_write: handle 2, offset 10, value_len 10

Will result with following calles to app:

exec_write: handle 1: offset 0, value_len 20
exec_write: handle 2: offset 0, value_len 20

E.g. 2

prep_write: handle 1, offset 0, value_len 10
prep_write: handle 1, offset 2, value_len 5
prep_write: handle 2, offset 0, value_len 10
prep_write: handle 2, offset 4, value_len 5

Will result with following calles to app:

exec_write: handle 1: offset 0, value_len 10
exec_write: handle 1: offset 2, value_len 5
exec_write: handle 2: offset 0, value_len 10
exec_write: handle 2: offset 4, value_len 5

E.g. 3
prep_write: handle 1, offset 0, value_len 10
prep_write: handle 1, offset 5, value_len 5
prep_write: handle 1, offset 10, value_len 6

will result with following calles to app:

exec_write: handle 1, offset 0, value 10
exec_write: handle 1, offset 5, value 11
</pre>
</div>
</content>
</entry>
<entry>
<title>client: Fix code style problems</title>
<updated>2016-04-04T10:12:54+00:00</updated>
<author>
<name>Luiz Augusto von Dentz</name>
<email>luiz.von.dentz@intel.com</email>
</author>
<published>2016-04-04T10:12:54+00:00</published>
<link rel='alternate' type='text/html' href='http://trove.baserock.org/cgit/delta/bluez.git/commit/?id=08bca88cd6f39ade8435da005d8afc2bdef01f5f'/>
<id>08bca88cd6f39ade8435da005d8afc2bdef01f5f</id>
<content type='text'>
Only tabs shall be used for indentation.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Only tabs shall be used for indentation.
</pre>
</div>
</content>
</entry>
<entry>
<title>input/hog: Fix crash if uhid is not enabled</title>
<updated>2016-04-02T07:47:35+00:00</updated>
<author>
<name>Szymon Janc</name>
<email>szymon.janc@codecoup.pl</email>
</author>
<published>2016-04-01T19:58:29+00:00</published>
<link rel='alternate' type='text/html' href='http://trove.baserock.org/cgit/delta/bluez.git/commit/?id=eeaa5a1afb181fe0595c7395f3316d683fce86aa'/>
<id>eeaa5a1afb181fe0595c7395f3316d683fce86aa</id>
<content type='text'>
If /dev/uhid is not present bt_hog_new_default() returns NULL.
This was resulting in NULL pointer dereference in attio_connected_cb.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
If /dev/uhid is not present bt_hog_new_default() returns NULL.
This was resulting in NULL pointer dereference in attio_connected_cb.
</pre>
</div>
</content>
</entry>
<entry>
<title>audio: Fix double free</title>
<updated>2016-04-01T14:00:05+00:00</updated>
<author>
<name>Luiz Augusto von Dentz</name>
<email>luiz.von.dentz@intel.com</email>
</author>
<published>2016-04-01T14:00:05+00:00</published>
<link rel='alternate' type='text/html' href='http://trove.baserock.org/cgit/delta/bluez.git/commit/?id=1721258a7d95b8f294d8875ff030eca9b24a2e60'/>
<id>1721258a7d95b8f294d8875ff030eca9b24a2e60</id>
<content type='text'>
Because avdtp_unref can now cause a state change the stream reference
shall be dropped before a2dp_cancel is called otherwise the code may
attempt to unref once more using the same reference:

Invalid read of size 8
   at 0x41F33B: avdtp_set_state (avdtp.c:695)
   by 0x420CE7: connection_lost (avdtp.c:1118)
   by 0x4216C4: avdtp_unref (avdtp.c:1178)
   by 0x418098: source_disconnect (source.c:395)
   by 0x41D417: a2dp_source_disconnect (a2dp.c:2312)
   by 0x49A64B: btd_service_disconnect (service.c:273)
   by 0x49E120: dev_disconn_service (device.c:1325)
   by 0x50E6DAC: g_slist_foreach (in /usr/lib64/libglib-2.0.so.0.4600.2)
   by 0x4A3894: device_request_disconnect (device.c:1357)
   by 0x4A3A3C: dev_disconnect (device.c:1442)
   by 0x4C7F22: process_message.isra.3 (object.c:259)
   by 0x4C877C: generic_message (object.c:1071)
 Address 0x929b0c0 is 16 bytes inside a block of size 1,160 free'd
   at 0x4C29E00: free (vg_replace_malloc.c:530)
   by 0x50CE5ED: g_free (in /usr/lib64/libglib-2.0.so.0.4600.2)
   by 0x42163B: avdtp_free (avdtp.c:1101)
   by 0x42163B: avdtp_unref (avdtp.c:1182)
   by 0x417808: source_set_state (source.c:108)
   by 0x4178F9: avdtp_state_callback (source.c:122)
   by 0x41F386: avdtp_set_state (avdtp.c:698)
   by 0x420CE7: connection_lost (avdtp.c:1118)
   by 0x4216C4: avdtp_unref (avdtp.c:1178)
   by 0x418098: source_disconnect (source.c:395)
   by 0x41D417: a2dp_source_disconnect (a2dp.c:2312)
   by 0x49A64B: btd_service_disconnect (service.c:273)
   by 0x49E120: dev_disconn_service (device.c:1325)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Because avdtp_unref can now cause a state change the stream reference
shall be dropped before a2dp_cancel is called otherwise the code may
attempt to unref once more using the same reference:

Invalid read of size 8
   at 0x41F33B: avdtp_set_state (avdtp.c:695)
   by 0x420CE7: connection_lost (avdtp.c:1118)
   by 0x4216C4: avdtp_unref (avdtp.c:1178)
   by 0x418098: source_disconnect (source.c:395)
   by 0x41D417: a2dp_source_disconnect (a2dp.c:2312)
   by 0x49A64B: btd_service_disconnect (service.c:273)
   by 0x49E120: dev_disconn_service (device.c:1325)
   by 0x50E6DAC: g_slist_foreach (in /usr/lib64/libglib-2.0.so.0.4600.2)
   by 0x4A3894: device_request_disconnect (device.c:1357)
   by 0x4A3A3C: dev_disconnect (device.c:1442)
   by 0x4C7F22: process_message.isra.3 (object.c:259)
   by 0x4C877C: generic_message (object.c:1071)
 Address 0x929b0c0 is 16 bytes inside a block of size 1,160 free'd
   at 0x4C29E00: free (vg_replace_malloc.c:530)
   by 0x50CE5ED: g_free (in /usr/lib64/libglib-2.0.so.0.4600.2)
   by 0x42163B: avdtp_free (avdtp.c:1101)
   by 0x42163B: avdtp_unref (avdtp.c:1182)
   by 0x417808: source_set_state (source.c:108)
   by 0x4178F9: avdtp_state_callback (source.c:122)
   by 0x41F386: avdtp_set_state (avdtp.c:698)
   by 0x420CE7: connection_lost (avdtp.c:1118)
   by 0x4216C4: avdtp_unref (avdtp.c:1178)
   by 0x418098: source_disconnect (source.c:395)
   by 0x41D417: a2dp_source_disconnect (a2dp.c:2312)
   by 0x49A64B: btd_service_disconnect (service.c:273)
   by 0x49E120: dev_disconn_service (device.c:1325)
</pre>
</div>
</content>
</entry>
<entry>
<title>audio/avdtp: Fix code style</title>
<updated>2016-04-01T13:44:16+00:00</updated>
<author>
<name>Luiz Augusto von Dentz</name>
<email>luiz.von.dentz@intel.com</email>
</author>
<published>2016-04-01T13:44:16+00:00</published>
<link rel='alternate' type='text/html' href='http://trove.baserock.org/cgit/delta/bluez.git/commit/?id=158248f20a8d5c106737e4a4e5ad1bf33563c7c2'/>
<id>158248f20a8d5c106737e4a4e5ad1bf33563c7c2</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>build: Make old GATT plugins deprecated</title>
<updated>2016-04-01T11:57:37+00:00</updated>
<author>
<name>Luiz Augusto von Dentz</name>
<email>luiz.von.dentz@intel.com</email>
</author>
<published>2016-03-24T09:15:43+00:00</published>
<link rel='alternate' type='text/html' href='http://trove.baserock.org/cgit/delta/bluez.git/commit/?id=25bce13507dfe9a1df2c10c4efd74190bba0eda5'/>
<id>25bce13507dfe9a1df2c10c4efd74190bba0eda5</id>
<content type='text'>
This disables building plugins that are no longer supported by the core
since the transition to gatt-db. In the future these plugins will have to
be ported to use gatt-db or be removed if the profile can be implemented
using the GATT D-Bus APIs.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This disables building plugins that are no longer supported by the core
since the transition to gatt-db. In the future these plugins will have to
be ported to use gatt-db or be removed if the profile can be implemented
using the GATT D-Bus APIs.
</pre>
</div>
</content>
</entry>
<entry>
<title>audio/avrcp: Fix registering to player events</title>
<updated>2016-04-01T08:07:15+00:00</updated>
<author>
<name>Luiz Augusto von Dentz</name>
<email>luiz.von.dentz@intel.com</email>
</author>
<published>2016-04-01T08:07:15+00:00</published>
<link rel='alternate' type='text/html' href='http://trove.baserock.org/cgit/delta/bluez.git/commit/?id=cc235a8d528b36cad2cf9fe6517d54711613331a'/>
<id>cc235a8d528b36cad2cf9fe6517d54711613331a</id>
<content type='text'>
If controller does not have a player skip registering to events which
requires a player.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
If controller does not have a player skip registering to events which
requires a player.
</pre>
</div>
</content>
</entry>
<entry>
<title>audio/avdtp: Fix crash on outgoing connection failure</title>
<updated>2016-03-31T07:27:33+00:00</updated>
<author>
<name>Szymon Janc</name>
<email>szymon.janc@codecoup.pl</email>
</author>
<published>2016-03-25T15:11:33+00:00</published>
<link rel='alternate' type='text/html' href='http://trove.baserock.org/cgit/delta/bluez.git/commit/?id=3d1a3daa040231b585dcc0cf127ba90e66f4035a'/>
<id>3d1a3daa040231b585dcc0cf127ba90e66f4035a</id>
<content type='text'>
This fix double free if outgoing connection failed. This was due to
connection_lost() being called from avdtp_unref which could result
in another call to connection_lost when session ref is already 0.

Fix this in similar way pairing agent is handled: takes extra reference
before calling callbacks and unref it before exit. Then only unref is
suppose to free session.

connect error: Host is down (112)
profiles/audio/avdtp.c:connection_lost() Disconnected from 00:0C:8A:FB:D4:16
profiles/audio/a2dp.c:discover_cb() err 0xfff000240
profiles/audio/avdtp.c:avdtp_unref() 0x85a88f0: ref=1
src/service.c:change_state() 0x7f7c710: device 00:0C:8A:FB:D4:16 profile
    a2dp-sink state changed: connecting -&gt; disconnected (-11)
src/device.c:device_profile_connected() a2dp-sink Resource temporarily
    unavailable (11)
src/device.c:device_profile_connected() returning response to :1.37
profiles/audio/a2dp.c:setup_unref() 0x85b0380: ref=0
profiles/audio/a2dp.c:setup_free() 0x85b0380
profiles/audio/avdtp.c:avdtp_unref() 0x85a88f0: ref=0
profiles/audio/avdtp.c:connection_lost() Disconnected from 00:0C:8A:FB:D4:16
profiles/audio/a2dp.c:discover_cb() err 0xfff000170
profiles/audio/sink.c:sink_set_state() State changed  /org/bluez/hci0/
    dev_00_0C_8A_FB_D4_16: SINK_STATE_CONNECTING -&gt; SINK_STATE_DISCONNECTED
profiles/audio/a2dp.c:channel_remove() chan 0x85a8780
profiles/audio/avdtp.c:avdtp_free() 0x85a88f0
 Invalid free() / delete / delete[] / realloc()
    at 0x4C29CF0: free (vg_replace_malloc.c:530)
    by 0x50CE5ED: g_free (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x4177E3: finalize_discovery (avdtp.c:1039)
    by 0x41789A: connection_lost (avdtp.c:1114)
    by 0x41A7FD: avdtp_connect_cb (avdtp.c:2339)
    by 0x44CBFB: connect_cb (btio.c:232)
    by 0x50C8E39: g_main_context_dispatch (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x50C91CF: ??? (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x50C94F1: g_main_loop_run (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x40B7B7: main (main.c:687)
  Address 0x85b4c30 is 0 bytes inside a block of size 24 free'd
    at 0x4C29CF0: free (vg_replace_malloc.c:530)
    by 0x50CE5ED: g_free (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x4177E3: finalize_discovery (avdtp.c:1039)
    by 0x41789A: connection_lost (avdtp.c:1114)
    by 0x413EE2: setup_free (a2dp.c:163)
    by 0x413EE2: setup_unref (a2dp.c:178)
    by 0x413F5F: setup_cb_free (a2dp.c:201)
    by 0x41638D: finalize_discover (a2dp.c:346)
    by 0x41638D: discover_cb (a2dp.c:1855)
    by 0x4177DB: finalize_discovery (avdtp.c:1037)
    by 0x41789A: connection_lost (avdtp.c:1114)
    by 0x41A7FD: avdtp_connect_cb (avdtp.c:2339)
    by 0x44CBFB: connect_cb (btio.c:232)
    by 0x50C8E39: g_main_context_dispatch (in /usr/lib64/libglib-2.0.so.0.4600.2)
  Block was alloc'd at
    at 0x4C2A988: calloc (vg_replace_malloc.c:711)
    by 0x50CE530: g_malloc0 (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x4190FB: avdtp_discover (avdtp.c:3186)
    by 0x416C19: a2dp_discover (a2dp.c:1872)
    by 0x413642: sink_setup_stream (sink.c:265)
    by 0x4136C4: sink_connect (sink.c:294)
    by 0x470165: btd_service_connect (service.c:238)
    by 0x47583C: connect_next.isra.18 (device.c:1455)
    by 0x478500: connect_profiles (device.c:1710)
    by 0x48EC4A: process_message.isra.5 (object.c:259)
    by 0x53DD1A2: ??? (in /usr/lib64/libdbus-1.so.3.14.6)
    by 0x53CE733: dbus_connection_dispatch (in /usr/lib64/libdbus-1.so.3.14.6)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This fix double free if outgoing connection failed. This was due to
connection_lost() being called from avdtp_unref which could result
in another call to connection_lost when session ref is already 0.

Fix this in similar way pairing agent is handled: takes extra reference
before calling callbacks and unref it before exit. Then only unref is
suppose to free session.

connect error: Host is down (112)
profiles/audio/avdtp.c:connection_lost() Disconnected from 00:0C:8A:FB:D4:16
profiles/audio/a2dp.c:discover_cb() err 0xfff000240
profiles/audio/avdtp.c:avdtp_unref() 0x85a88f0: ref=1
src/service.c:change_state() 0x7f7c710: device 00:0C:8A:FB:D4:16 profile
    a2dp-sink state changed: connecting -&gt; disconnected (-11)
src/device.c:device_profile_connected() a2dp-sink Resource temporarily
    unavailable (11)
src/device.c:device_profile_connected() returning response to :1.37
profiles/audio/a2dp.c:setup_unref() 0x85b0380: ref=0
profiles/audio/a2dp.c:setup_free() 0x85b0380
profiles/audio/avdtp.c:avdtp_unref() 0x85a88f0: ref=0
profiles/audio/avdtp.c:connection_lost() Disconnected from 00:0C:8A:FB:D4:16
profiles/audio/a2dp.c:discover_cb() err 0xfff000170
profiles/audio/sink.c:sink_set_state() State changed  /org/bluez/hci0/
    dev_00_0C_8A_FB_D4_16: SINK_STATE_CONNECTING -&gt; SINK_STATE_DISCONNECTED
profiles/audio/a2dp.c:channel_remove() chan 0x85a8780
profiles/audio/avdtp.c:avdtp_free() 0x85a88f0
 Invalid free() / delete / delete[] / realloc()
    at 0x4C29CF0: free (vg_replace_malloc.c:530)
    by 0x50CE5ED: g_free (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x4177E3: finalize_discovery (avdtp.c:1039)
    by 0x41789A: connection_lost (avdtp.c:1114)
    by 0x41A7FD: avdtp_connect_cb (avdtp.c:2339)
    by 0x44CBFB: connect_cb (btio.c:232)
    by 0x50C8E39: g_main_context_dispatch (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x50C91CF: ??? (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x50C94F1: g_main_loop_run (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x40B7B7: main (main.c:687)
  Address 0x85b4c30 is 0 bytes inside a block of size 24 free'd
    at 0x4C29CF0: free (vg_replace_malloc.c:530)
    by 0x50CE5ED: g_free (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x4177E3: finalize_discovery (avdtp.c:1039)
    by 0x41789A: connection_lost (avdtp.c:1114)
    by 0x413EE2: setup_free (a2dp.c:163)
    by 0x413EE2: setup_unref (a2dp.c:178)
    by 0x413F5F: setup_cb_free (a2dp.c:201)
    by 0x41638D: finalize_discover (a2dp.c:346)
    by 0x41638D: discover_cb (a2dp.c:1855)
    by 0x4177DB: finalize_discovery (avdtp.c:1037)
    by 0x41789A: connection_lost (avdtp.c:1114)
    by 0x41A7FD: avdtp_connect_cb (avdtp.c:2339)
    by 0x44CBFB: connect_cb (btio.c:232)
    by 0x50C8E39: g_main_context_dispatch (in /usr/lib64/libglib-2.0.so.0.4600.2)
  Block was alloc'd at
    at 0x4C2A988: calloc (vg_replace_malloc.c:711)
    by 0x50CE530: g_malloc0 (in /usr/lib64/libglib-2.0.so.0.4600.2)
    by 0x4190FB: avdtp_discover (avdtp.c:3186)
    by 0x416C19: a2dp_discover (a2dp.c:1872)
    by 0x413642: sink_setup_stream (sink.c:265)
    by 0x4136C4: sink_connect (sink.c:294)
    by 0x470165: btd_service_connect (service.c:238)
    by 0x47583C: connect_next.isra.18 (device.c:1455)
    by 0x478500: connect_profiles (device.c:1710)
    by 0x48EC4A: process_message.isra.5 (object.c:259)
    by 0x53DD1A2: ??? (in /usr/lib64/libdbus-1.so.3.14.6)
    by 0x53CE733: dbus_connection_dispatch (in /usr/lib64/libdbus-1.so.3.14.6)
</pre>
</div>
</content>
</entry>
</feed>
