nuttx/sched/task/task_prctl.c

210 lines
5.8 KiB
C
Raw Normal View History

/****************************************************************************
* sched/task/task_prctl.c
*
* SPDX-License-Identifier: Apache-2.0
*
* Licensed to the Apache Software Foundation (ASF) under one or more
* contributor license agreements. See the NOTICE file distributed with
* this work for additional information regarding copyright ownership. The
* ASF licenses this file to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance with the
* License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
* WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
* License for the specific language governing permissions and limitations
* under the License.
*
****************************************************************************/
/****************************************************************************
* Included Files
****************************************************************************/
#include <nuttx/config.h>
#include <sys/prctl.h>
#include <stdarg.h>
#include <string.h>
#include <errno.h>
#include <nuttx/debug.h>
#include <nuttx/sched.h>
#include "sched/sched.h"
#include "task/task.h"
/****************************************************************************
* Public Functions
****************************************************************************/
/****************************************************************************
* Name: prctl
*
* Description:
* prctl() is called with a first argument describing what to do (with
* values PR_* defined above) and with additional arguments depending on
* the specific command.
*
* Returned Value:
* The returned value may depend on the specific command. For PR_SET_NAME
* and PR_GET_NAME, the returned value of 0 indicates successful operation.
* On any failure, -1 is retruend and the errno value is set appropriately.
*
* EINVAL The value of 'option' is not recognized.
* EFAULT optional arg1 is not a valid address.
* ESRCH No task/thread can be found corresponding to that specified
2014-04-13 14:32:20 -06:00
* by optional arg1.
*
****************************************************************************/
int prctl(int option, ...)
{
va_list ap;
int errcode;
va_start(ap, option);
switch (option)
{
2017-08-14 17:19:27 -06:00
case PR_SET_NAME:
case PR_GET_NAME:
case PR_SET_NAME_EXT:
case PR_GET_NAME_EXT:
#if CONFIG_TASK_NAME_SIZE > 0
2017-08-14 17:19:27 -06:00
{
/* Get the prctl arguments */
FAR char *name = va_arg(ap, FAR char *);
FAR struct tcb_s *tcb;
int pid = 0;
if (option == PR_SET_NAME_EXT ||
option == PR_GET_NAME_EXT)
{
pid = va_arg(ap, int);
}
2017-08-14 17:19:27 -06:00
2020-03-08 05:51:34 -07:00
/* Get the TCB associated with the PID (handling the special case
* of pid==0 meaning "this thread")
2017-08-14 17:19:27 -06:00
*/
if (pid == 0)
2017-08-14 17:19:27 -06:00
{
tcb = this_task();
}
else
{
tcb = nxsched_get_tcb(pid);
2017-08-14 17:19:27 -06:00
}
/* An invalid pid will be indicated by a NULL TCB returned from
* nxsched_get_tcb()
2017-08-14 17:19:27 -06:00
*/
if (tcb == NULL)
2017-08-14 17:19:27 -06:00
{
serr("ERROR: Pid does not correspond to a task: %d\n", pid);
errcode = ESRCH;
goto errout;
}
/* A pointer to the task name storage must also be provided */
if (name == NULL)
2017-08-14 17:19:27 -06:00
{
serr("ERROR: No name provide\n");
errcode = EFAULT;
goto errout;
}
/* Now get or set the task name */
if (option == PR_SET_NAME || option == PR_SET_NAME_EXT)
2017-08-14 17:19:27 -06:00
{
/* Ensure that tcb->name will be null-terminated, truncating if
* necessary.
*/
strlcpy(tcb->name, name, sizeof(tcb->name));
2017-08-14 17:19:27 -06:00
tcb->name[CONFIG_TASK_NAME_SIZE] = '\0';
}
else
{
/* The returned value will be null-terminated, truncating if
* necessary.
*/
sched: fix 1-byte overflow in prctl(PR_GET_NAME) strlcpy() was given sizeof(tcb->name), i.e. CONFIG_TASK_NAME_SIZE + 1, but the documented caller contract is a buffer of CONFIG_TASK_NAME_SIZE bytes (include/sys/prctl.h). When a task name is exactly CONFIG_TASK_NAME_SIZE chars (the normal result of nxtask_setup_name() truncation), the terminating NUL lands one byte past the caller buffer. Pass CONFIG_TASK_NAME_SIZE to strlcpy() so the copy is truncated in-bounds, and drop the stale forced-NUL line left over from the strncpy era (it ran after the overflow had already happened). Before: ``` guard byte placed right after a CONFIG_TASK_NAME_SIZE caller buffer reads 0x00 (expected 0xAA) after the call: strlcpy writes its terminating NUL one byte past the buffer when the task name is exactly CONFIG_TASK_NAME_SIZE chars. ``` After: ``` strlcpy(name, tcb->name, CONFIG_TASK_NAME_SIZE) writes at most CONFIG_TASK_NAME_SIZE bytes; the caller buffer stays intact. ``` Testing: Simulated (sim:nsh, CONFIG_TASK_NAME_SIZE=31). Build and run: ``` cmake -B build -DBOARD_CONFIG=sim:nsh -GNinja cmake --build build -j$(nproc) echo hello | ./build/nuttx ``` then run "hello" at the NSH prompt. The test was carried by apps/examples/hello/hello_main.c (scratch only, not part of this commit); its diff: ``` --- a/examples/hello/hello_main.c +++ b/examples/hello/hello_main.c @@ -24,6 +24,8 @@ #include <nuttx/config.h> #include <stdio.h> +#include <string.h> +#include <sys/prctl.h> /**************************************************************************** * Public Functions @@ -35,6 +37,55 @@ int main(int argc, FAR char *argv[]) { + /* Longest-legal task name: exactly CONFIG_TASK_NAME_SIZE chars, the + * normal result of nxtask_setup_name() truncation. + */ + + static const char longname[] = + "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789"; + + /* Caller buffer per the documented prctl(PR_GET_NAME) contract, with a + * guard byte immediately after it to detect the 1-byte overflow. + */ + + struct + { + char buf[CONFIG_TASK_NAME_SIZE]; + volatile unsigned char guard; + } s; + + _Static_assert(sizeof(longname) - 1 > CONFIG_TASK_NAME_SIZE, + "test name must exceed CONFIG_TASK_NAME_SIZE"); + printf("Hello, World!!\n"); + printf("prctl test: CONFIG_TASK_NAME_SIZE=%d\n", CONFIG_TASK_NAME_SIZE); + + s.guard = 0xaa; + s.buf[0] = '\0'; + + if (prctl(PR_SET_NAME, (unsigned long)longname) != 0) + { + printf("prctl test: PR_SET_NAME failed\n"); + return 1; + } + + if (prctl(PR_GET_NAME, (unsigned long)s.buf) != 0) + { + printf("prctl test: PR_GET_NAME failed\n"); + return 1; + } + + printf("prctl test: guard=0x%02x (expected 0xaa), name len=%zu, " + "last char=0x%02x\n", s.guard, strlen(s.buf), (unsigned char)s.buf[strlen(s.buf)]); + + if (s.guard != 0xaa) + { + printf("prctl test: FAIL - terminating NUL written 1 byte past " + "the caller buffer\n"); + return 1; + } + + printf("prctl test: PASS - caller buffer intact\n"); return 0; } ``` Before the fix: ``` prctl test: guard=0x00 (expected 0xaa), name len=30, last char=0x00 prctl test: FAIL - terminating NUL written 1 byte past the caller buffer ``` After the fix: ``` prctl test: guard=0xaa (expected 0xaa), name len=30, last char=0x00 prctl test: PASS - caller buffer intact ``` Assisted-by: Claude Code (GLM-5.3) <claude@anthropic.com> Signed-off-by: Junbo Zheng <zhengjunbo1@xiaomi.com>
2026-09-13 17:38:40 +08:00
strlcpy(name, tcb->name, CONFIG_TASK_NAME_SIZE);
2017-08-14 17:19:27 -06:00
}
}
break;
#else
2017-08-14 17:19:27 -06:00
serr("ERROR: Option not enabled: %d\n", option);
errcode = ENOSYS;
goto errout;
#endif
case PR_SET_DUMPABLE:
case PR_GET_DUMPABLE:
#ifdef CONFIG_SCHED_USER_IDENTITY
{
FAR struct tcb_s *tcb = this_task();
if (tcb == NULL || tcb->group == NULL)
{
errcode = ESRCH;
goto errout;
}
if (option == PR_GET_DUMPABLE)
{
va_end(ap);
return (tcb->group->tg_flags & GROUP_FLAG_DUMPABLE) != 0;
}
if (va_arg(ap, int) != 0)
{
if (tcb->group->tg_euid != 0)
{
errcode = EPERM;
goto errout;
}
tcb->group->tg_flags |= GROUP_FLAG_DUMPABLE;
}
else
{
tcb->group->tg_flags &= ~GROUP_FLAG_DUMPABLE;
}
}
break;
#else
serr("ERROR: Option not enabled: %d\n", option);
errcode = ENOSYS;
goto errout;
#endif
2017-08-14 17:19:27 -06:00
default:
serr("ERROR: Unrecognized option: %d\n", option);
errcode = EINVAL;
goto errout;
}
/* Not reachable unless CONFIG_TASK_NAME_SIZE is > 0. NOTE: This might
* change if additional commands are supported.
*/
#if CONFIG_TASK_NAME_SIZE > 0
va_end(ap);
return OK;
#endif
errout:
va_end(ap);
set_errno(errcode);
return ERROR;
}