Skip to content

Resolve Coverity security issues across sensors/bluetooth - #6

Open
akanisetti wants to merge 1 commit into
edge-aosp-bsp:celadon/a15/stablefrom
akanisetti:cov-fixes
Open

Resolve Coverity security issues across sensors/bluetooth#6
akanisetti wants to merge 1 commit into
edge-aosp-bsp:celadon/a15/stablefrom
akanisetti:cov-fixes

Conversation

@akanisetti

Copy link
Copy Markdown

Issue types:

  • Overflowed return value
  • Wrong size argument
  • Data race condition
  • Dereference before null check

Changes:

  • Added mutex locking around io_ctx accesses in network_cancel to prevent data race on cancelled flag.
  • Fixed negative int-to-ssize_t casts in iiod-client write/read unlocked functions to avoid overflow on conversion.
  • Changed hardcoded write size from 6 to sizeof(cmd) and added ssize_t cast in net_bluetooth_mgmt command write.
  • Reordered initialization in Sensors::initialize to check mWakeLockQueue before dereferencing mEventQueue for EventFlag creation.

Tracked-On: NIACP3-1397

@akanisetti
akanisetti requested a review from a team June 12, 2026 10:42
@akanisetti
akanisetti force-pushed the cov-fixes branch 3 times, most recently from 55ac479 to 4719b96 Compare June 12, 2026 13:31
…etooth

Issue types:
- Overflowed return value
- Wrong size argument
- Data race condition
- Dereference before null check
- Division or modulo by zero

CIDs:
- 6161277
- 6163648
- 6169560
- 6188213
- 6185842
- 6191870

Changes:
- Fixed all negative int-to-ssize_t error-return conversions in iiod-client paths.
- Replaced hardcoded mgmt command write size with sizeof(cmd) and compatible ssize_t compare.
- Added mutex protection in network_cancel for io_ctx cancellation and cancelled flag updates.
- Reordered Sensors::initialize setup so EventFlag creation occurs only after queue validity checks.
- Start wake-lock thread only on successful initialize() and guard destructor join with joinable().

Tracked-On: NIACP3-1397
Signed-off-by: Anisetti Avinash Krishna <anisetti.avinash.krishna@intel.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant