Skip to content

[dfsv2] fixup out-of-memory access #8973

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 21, 2024

Conversation

polarvid
Copy link
Contributor

@polarvid polarvid commented May 21, 2024

拉取/合并请求描述:(PR description)

[

为什么提交这份PR (why to submit this PR)

reported by KASAN.

This change addresses a potential out-of-memory access issue in the devfs filesystem component. The issue arises when the rt_malloc function allocates memory for a path string without accounting for the null terminator, leading to undefined behavior.

As the manual documented:

DESCRIPTION
The strlen() function calculates the length of the string pointed to
by s, excluding the terminating null byte ('\0').

你的解决方案是什么 (what is your solution)

To fix this, the memory allocation size was increased by one byte to ensure space for the null terminator. This prevents potential out-of-memory access and ensures proper string termination.

请提供验证的bsp和config (provide the config and bsp)

  • BSP:
  • .config:
  • action:

]

当前拉取/合并请求的状态 Intent for your PR

必须选择一项 Choose one (Mandatory):

  • 本拉取/合并请求是一个草稿版本 This PR is for a code-review and is intended to get feedback
  • 本拉取/合并请求是一个成熟版本 This PR is mature, and ready to be integrated into the repo

代码质量 Code Quality:

我在这个拉取/合并请求中已经考虑了 As part of this pull request, I've considered the following:

  • 已经仔细查看过代码改动的对比 Already check the difference between PR and old code
  • 代码风格正确,包括缩进空格,命名及其他风格 Style guide is adhered to, including spacing, naming and other styles
  • 没有垃圾代码,代码尽量精简,不包含#if 0代码,不包含已经被注释了的代码 All redundant code is removed and cleaned up
  • 所有变更均有原因及合理的,并且不会影响到其他软件组件代码或BSP All modifications are justified and not affect other components or BSP
  • 对难懂代码均提供对应的注释 I've commented appropriately where code is tricky
  • 代码是高质量的 Code in this PR is of high quality
  • 已经使用formatting 等源码格式化工具确保格式符合RT-Thread代码规范 This PR complies with RT-Thread code specification

This change addresses a potential out-of-memory access issue in the
devfs filesystem component. The issue arises when the `rt_malloc`
function allocates memory for a path string without accounting for
the null terminator, leading to undefined behavior.

As the manual documented:

> DESCRIPTION
>   The strlen() function calculates the length of the string pointed to
>   by s, excluding the terminating null byte ('\0').

To fix this, the memory allocation size was increased by one byte
to ensure space for the null terminator. This prevents potential
out-of-memory access and ensures proper string termination.

Signed-off-by: Shell <[email protected]>
@polarvid polarvid marked this pull request as ready for review May 21, 2024 11:05
@polarvid polarvid requested a review from BernardXiong as a code owner May 21, 2024 11:05
@BernardXiong BernardXiong merged commit 5f94786 into RT-Thread:master May 21, 2024
45 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants