From 506a69a03d9a182bee2f308a940c93689011c377 Mon Sep 17 00:00:00 2001 From: Marco Casaroli Date: Wed, 7 Oct 2026 23:45:53 +0200 Subject: [PATCH] fs/v9fs: Do not parse past the end of the mount options. v9fs_client_init() steps over each option with "options += length + 1", to skip the comma after it. The last option has no comma, so the step goes past the terminating NUL, and the loop parses the memory after the string as more options. If that memory has a "trans=" or "uname=", it replaces the option given. For example, NSH keeps the next argument after the options: nsh> mount -t v9fs -o trans=virtio,tag=host trans=x /mnt nsh: mount: mount failed: 2 The parser reads "trans=x", and there is no transport "x". The same thing happens to options in .rodata, as CONFIG_INIT_MOUNT_DATA is. Skip the comma only when there is one. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Marco Casaroli --- fs/v9fs/client.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/fs/v9fs/client.c b/fs/v9fs/client.c index 8f2257b9a3b..e00fdc7cee1 100644 --- a/fs/v9fs/client.c +++ b/fs/v9fs/client.c @@ -1658,7 +1658,13 @@ int v9fs_client_init(FAR struct v9fs_client_s *client, client->msize = atoi(options + 6); } - options += length + 1; + /* The last option has no comma after it */ + + options += length; + if (*options == ',') + { + options++; + } } if (client->msize == 0)