Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 836b47e6 authored by Luiz Augusto von Dentz's avatar Luiz Augusto von Dentz Committed by Greg Kroah-Hartman
Browse files

Bluetooth: SCO: Fix sco_send_frame returning skb->len



commit 037ce005af6b8a3e40ee07c6e9266c8997e6a4d6 upstream.

The skb in modified by hci_send_sco which pushes SCO headers thus
changing skb->len causing sco_sock_sendmsg to fail.

Fixes: 0771cbb3b97d ("Bluetooth: SCO: Replace use of memcpy_from_msg with bt_skb_sendmsg")
Tested-by: default avatarTedd Ho-Jeong An <tedd.an@intel.com>
Signed-off-by: default avatarLuiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: default avatarMarcel Holtmann <marcel@holtmann.org>
Cc: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent aa2d34ca
Loading
Loading
Loading
Loading
+6 −4
Original line number Diff line number Diff line
@@ -282,16 +282,17 @@ static int sco_connect(struct hci_dev *hdev, struct sock *sk)
static int sco_send_frame(struct sock *sk, struct sk_buff *skb)
{
	struct sco_conn *conn = sco_pi(sk)->conn;
	int len = skb->len;

	/* Check outgoing MTU */
	if (skb->len > conn->mtu)
	if (len > conn->mtu)
		return -EINVAL;

	BT_DBG("sk %p len %d", sk, skb->len);
	BT_DBG("sk %p len %d", sk, len);

	hci_send_sco(conn->hcon, skb);

	return skb->len;
	return len;
}

static void sco_recv_frame(struct sco_conn *conn, struct sk_buff *skb)
@@ -731,7 +732,8 @@ static int sco_sock_sendmsg(struct socket *sock, struct msghdr *msg,
		err = -ENOTCONN;

	release_sock(sk);
	if (err)

	if (err < 0)
		kfree_skb(skb);
	return err;
}