fs/v9fs: Do not parse past the end of the mount options.

v9fs_client_init() steps over each option with "options += length + 1",
to skip the comma after it.  The last option has no comma, so the step
goes past the terminating NUL, and the loop parses the memory after the
string as more options.  If that memory has a "trans=" or "uname=", it
replaces the option given.

For example, NSH keeps the next argument after the options:

  nsh> mount -t v9fs -o trans=virtio,tag=host trans=x /mnt
  nsh: mount: mount failed: 2

The parser reads "trans=x", and there is no transport "x".  The same
thing happens to options in .rodata, as CONFIG_INIT_MOUNT_DATA is.

Skip the comma only when there is one.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
This commit is contained in:
Marco Casaroli 2026-10-07 23:45:53 +02:00 • committed by Xiang Xiao
parent 58bd942b35
commit 506a69a03d

View file

@ -1658,7 +1658,13 @@ int v9fs_client_init(FAR struct v9fs_client_s *client,
client->msize = atoi(options + 6);
}
options += length + 1;
/* The last option has no comma after it */
options += length;
if (*options == ',')
{
options++;
}
}
if (client->msize == 0)