FreeCalypso > hg > fc-magnetite
view cdg211/prim/mmss.pdf @ 516:1ed9de6c90bd
src/g23m-gsm/sms/sms_for.c: bogus malloc removed
The new error handling code that was not present in TCS211 blob version
contains a malloc call that is bogus for 3 reasons:
1) The memory allocation in question is not needed in the first place;
2) libc malloc is used instead of one of the firmware's proper ways;
3) The memory allocation is made inside a function and then never freed,
i.e., a memory leak.
This bug was caught in gcc-built FreeCalypso fw projects (Citrine
and Selenite) because our gcc environment does not allow any use of
libc malloc (any reference to malloc produces a link failure),
but this code from TCS3.2 is wrong even for Magnetite: if this code
path is executed repeatedly over a long time, the many small allocations
made by this malloc call without a subsequent free will eventually
exhaust the malloc heap provided by the TMS470 environment, malloc will
start returning NULL, and the bogus code will treat it as an error.
Because the memory allocation in question is not needed at all,
the fix entails simply removing it.
author | Mychaela Falconia <falcon@freecalypso.org> |
---|---|
date | Sun, 22 Jul 2018 06:04:49 +0000 |
parents | 56abf6cf8a0b |
children |
line wrap: on
line source
;******************************************************************************** ;*** File : mmss.pdf ;*** Creation : Fri Jun 08 13:57:56 CST 2007 ;*** XSLT Processor : Apache Software Foundation / http://xml.apache.org/xalan-j / supports XSLT-Ver: 1 ;*** Copyright : (c) Texas Instruments AG, Berlin Germany 2002 ;******************************************************************************** ;*** Document Type : Service Access Point Specification ;*** Document Name : mmss ;*** Document No. : 6147.105.97.102 ;*** Document Date : 2002-07-19 ;*** Document Status: BEING_PROCESSED ;*** Document Author: HM ;******************************************************************************** PRAGMA SRC_FILE_TIME "Mon Nov 24 15:49:30 2003" PRAGMA LAST_MODIFIED "2002-07-19" PRAGMA ID_AND_VERSION "6147.105.97.102" CONST MAX_SDU_LEN 1 ; maximum service data unit length VALTAB VAL_ti VAL 0 - 6 "ms originated transaction" VAL 8 - 14 "ms originated transaction" VAL 7 TI_RES_MO "reserved" VAL 15 TI_RES_MT "reserved" VAR cause "MM cause" S VAR l_buf "length in bits" S VAR o_buf "offset in bits" S VAR buf "bit buffer" B VAR ti "transaction identifier" B VAL @p_mmss - VAL_ti@ VAR d1 "dummy, not used" B VAR d2 "dummy, not used" B COMP sdu "Service Data Unit" { l_buf ; length in bits o_buf ; offset in bits buf [MAX_SDU_LEN] ; bit buffer } ; MMSS_ESTABLISH_REQ 0x80000008 ; MMSS_RELEASE_REQ 0x80010008 ; MMSS_DATA_REQ 0x80020008 ; MMSS_DATA_IND 0x80004008 ; MMSS_ERROR_IND 0x80014008 ; MMSS_ESTABLISH_CNF 0x80024008 ; MMSS_ESTABLISH_IND 0x80034008 ; MMSS_RELEASE_IND 0x80044008 PRIM MMSS_ESTABLISH_REQ 0x80000008 { ti ; transaction identifier } PRIM MMSS_RELEASE_REQ 0x80010008 { ti ; transaction identifier } PRIM MMSS_DATA_REQ 0x80020008 { d1 ; dummy d2 ; dummy sdu ; service data unit } PRIM MMSS_DATA_IND 0x80004008 { d1 ; dummy d2 ; dummy sdu ; service data unit } PRIM MMSS_ERROR_IND 0x80014008 { ti ; transaction identifier cause ; error cause } PRIM MMSS_ESTABLISH_CNF 0x80024008 { ti ; transaction identifier } PRIM MMSS_ESTABLISH_IND 0x80034008 { d1 ; dummy d2 ; dummy sdu ; service data unit } PRIM MMSS_RELEASE_IND 0x80044008 { ti ; transaction identifier cause ; release cause }