-
Notifications
You must be signed in to change notification settings - Fork 2.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[ota] Fix exchange context leak in OTA requestor #20304
Merged
tcarmelveilleux
merged 2 commits into
project-chip:master
from
Damian-Nordic:ota-ec-leak
Jul 6, 2022
Merged
[ota] Fix exchange context leak in OTA requestor #20304
tcarmelveilleux
merged 2 commits into
project-chip:master
from
Damian-Nordic:ota-ec-leak
Jul 6, 2022
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
It turns out that Exchange Context allocated for BDX transfer is not released on completion or connection abort. It is not seen in a happy path that results in applying and rebooting into a new firmware, but may lead to the exchange leak when the transfer is interrupted. Furthermore, if an exchange is never released, a Sleepy End Device never returns to the idle mode, needlessly draining the battery. Signed-off-by: Damian Krolik <damian.krolik@nordicsemi.no>
pullapprove
bot
requested review from
anush-apple,
arkq,
Byungjoo-Lee,
bzbarsky-apple,
carol-apple,
chrisdecenzo,
chshu,
chulspro,
dhrishi,
electrocucaracha,
emargolis,
erjiaqing,
franck-apple,
gjc13,
harsha-rajendran,
hawk248,
isiu-apple,
jelderton,
jepenven-silabs,
jmartinez-silabs,
jtung-apple,
kghost,
lazarkov,
LuDuda,
mlepage-google,
msandstedt,
mspang and
rgoliver
July 5, 2022 14:11
pullapprove
bot
requested review from
selissia,
tcarmelveilleux,
tecimovic,
tehampson,
turon,
vijs,
vivien-apple,
wbschiller,
woody-apple and
xylophone21
July 5, 2022 14:11
PR #20304: Size comparison from 90f32a0 to 76b0d4a Increases (12 builds for cc13x2_26x2, cyw30739, efr32, linux, nrfconnect)
Decreases (3 builds for cc13x2_26x2, esp32)
Full report (41 builds for cc13x2_26x2, cyw30739, efr32, esp32, k32w, linux, mbed, nrfconnect, p6, telink)
|
woody-apple
approved these changes
Jul 5, 2022
tcarmelveilleux
approved these changes
Jul 6, 2022
Damian-Nordic
added a commit
to Damian-Nordic/connectedhomeip
that referenced
this pull request
Jul 11, 2022
andy31415
pushed a commit
that referenced
this pull request
Jul 11, 2022
bzbarsky-apple
pushed a commit
to bzbarsky-apple/connectedhomeip
that referenced
this pull request
Jul 12, 2022
* [ota] Fix exchange context leak It turns out that Exchange Context allocated for BDX transfer is not released on completion or connection abort. It is not seen in a happy path that results in applying and rebooting into a new firmware, but may lead to the exchange leak when the transfer is interrupted. Furthermore, if an exchange is never released, a Sleepy End Device never returns to the idle mode, needlessly draining the battery. Signed-off-by: Damian Krolik <damian.krolik@nordicsemi.no> * Restyled by clang-format Co-authored-by: Restyled.io <commits@restyled.io>
This was referenced Jul 12, 2022
Closed
ArekBalysNordic
pushed a commit
to ArekBalysNordic/connectedhomeip
that referenced
this pull request
Jul 13, 2022
…p#20304)" (project-chip#20563) This reverts commit 757682e.
andy31415
pushed a commit
that referenced
this pull request
Jul 13, 2022
ajwak
pushed a commit
to ajwak/connectedhomeip
that referenced
this pull request
Jul 13, 2022
…p#20304)" (project-chip#20563) This reverts commit 757682e.
bzbarsky-apple
added a commit
that referenced
this pull request
Jul 14, 2022
* [ota] Fix exchange context leak in OTA requestor (#20304) * [ota] Fix exchange context leak It turns out that Exchange Context allocated for BDX transfer is not released on completion or connection abort. It is not seen in a happy path that results in applying and rebooting into a new firmware, but may lead to the exchange leak when the transfer is interrupted. Furthermore, if an exchange is never released, a Sleepy End Device never returns to the idle mode, needlessly draining the battery. Signed-off-by: Damian Krolik <damian.krolik@nordicsemi.no> * Restyled by clang-format Co-authored-by: Restyled.io <commits@restyled.io> * Fix exchange lifetime management in BDXMessenger. * Address review comments. Co-authored-by: Damian Królik <66667989+Damian-Nordic@users.noreply.github.com> Co-authored-by: Restyled.io <commits@restyled.io>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Problem
It turns out that an
ExchangeContext
allocated for BDX transfer is not released on completion or connection abort.It is not seen in a happy path that results in applying and rebooting into a new firmware, but may lead to the exchange leak when the transfer is interrupted.
Furthermore, if an exchange is never released, a Sleepy End Device never returns to the idle mode, needlessly draining
the battery.
Change overview
Release an exchange after completing or aborting an BDX transfer.
Testing
Did smoke tests with killing OTA Provider in the middle of a transfer. Observed that a SED switches back to the idle mode after the BDX timeout.