PTS test GATT/CL/GAD/BV-03-C published a service starting at handle 0xfffd and ending at 0xffff. This resets the next_handle to 0 in gatt_db_insert_service() instead of setting it to 0x10000. Other services are added later. This could end-up by a crash in db_hash_update() if not enough space has been allocated for hash.iov and some entries are overwritten. Next_handle can be replaced by a last_handle variable which will not loop over. This can be replaced by queue_peek_tail() and computing the value, but keeping last_handle will avoid this sort of lookup. Add a unit test to check regression. v1 -> v2: Replace next_handle by last_handle Check empty db using gatt_db_isempty(db) instead of next_handle == 0 Add robustness unit test to check that gatt_db_get_hash() doesn't crash v2 -> v3: Fix line length checkpatch errors v3 -> v4: Update commit comment to explain reason for keeping last_handle Split unit test to its own commit Rephrase db setup comment in unit test Frédéric Danis (2): shared/gatt-db: Fix munmap_chunk invalid pointer unit/test-gatt: Add unordered setup db test src/shared/gatt-db.c | 19 ++++++------ unit/test-gatt.c | 73 +++++++++++++++++++++++++++++++++++++++++++- 2 files changed, 82 insertions(+), 10 deletions(-) -- 2.34.1