Issue apache/nuttx#20145 reported a sensor fetch-watchdog lifetime
regression: sensor_poll() arms a per-subscriber watchdog for
fetch-only sensors with a finite interval, but sensor_close()
freed the subscriber without cancelling it, letting
sensor_fetch_expired() run after free.
Fixed by apache/nuttx#20146, which cancels the watchdog on close.
Add regression coverage in drivertest as suggested by the maintainer:
open a sensor device, set a finite fetch interval, enter the poll
path so the watchdog can be armed, then close while the watchdog
state is relevant. Sleep past the interval so any stray timer would
fire, and reopen to prove teardown was clean. The test skips
gracefully when no sensor device is present, so it is safe on sim
without hardware.
The test does not deterministically reproduce the UAF; it verifies
the observable invariant that repeated poll/close/reopen cycles
complete cleanly and the device remains usable. Under KASAN or
stress, a missing wd_cancel in close would be caught here.
Impact:
* Is new feature added? YES (new regression test coverage in
testing/drivers/drivertest, no existing functionality changed).
* Impact on user, build, hardware, documentation, security,
compatibility? NO, test-only change.
Testing:
* Full build and runtime logs are provided in the PR description.
Assisted-by: Muse Spark:muse-spark-1.3
Assisted-by: Claude:claude-opus
Signed-off-by: Arnav Sharma <2006arnavsharma@gmail.com>
Extend the watchdog drivertest with notifier ordering, duplicate registration, repeated delivery, unregister, NULL-data, and concurrent registration coverage.
Register the watchdog test when either reset-cause or timeout-notifier support is available. Keep hardware watchdog cases gated by reset-cause support and allow notifier-only simulator builds through both Make and CMake.
Keep test state in the watchdog fixture and notifier blocks so callbacks do not depend on shared notifier state.
Assisted-by: OpenAI Codex
Signed-off-by: hanzhijian <hanzhijian@zepp.com>