The new CONFIG_FS_AIO_LISTIO_MAX option defaults to 10 and lio_listio()
now rejects nent > {AIO_LISTIO_MAX} with EINVAL. The LTP release pinned
by apps/testing/ltp (20230516) submits 256 requests in a single batch from
conformance/interfaces/lio_listio/2-1.c, so ltp_interfaces_lio_listio_2_1
now fails on every configuration that enables CONFIG_TESTING_LTP
(sim:citest, rv-virt:citest, sim:posix_test):
lio_listio/2-1.c Error at lio_listio() 22: Invalid argument
The EINVAL check itself is required by POSIX, so keep it and raise the
default instead; the limit no longer costs memory because the requests are
linked through the aiocb's own lio_link.
While here, keep _POSIX_AIO_LISTIO_MAX at its POSIX-mandated value of 2
and let AIO_LISTIO_MAX carry the configurable implementation limit.
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
aio_fsync()/aio_read()/aio_write()/lio_listio() initialized
aiocbp->lio_link with list_initialize(), which makes the node
self-referential (prev = next = &node). aio_signal() tests
list_in_list(&lio_link) to detect lio_listio batches, so it wrongly
entered the lio_listio completion path for every standalone AIO
operation and notified through the uninitialized
lio_sigevent/lio_sigwork.
With CONFIG_SIG_EVTHREAD=y, garbage lio_sigevent.sigev_notify ==
SIGEV_THREAD caused nxsig_notification() to queue &lio_sigwork.work
onto the low-priority work queue with garbage func/value. After the
aiocb was freed, the dangling work_s was dispatched with worker=NULL,
crashing in work_dispatch().
Fix: initialize lio_link with list_clear_node() (prev = next = NULL)
so list_in_list() returns false for non-lio_listio operations and
aio_signal() skips the lio_listio path.
While there, reject a NULL aiocbp in aio_fsync(): POSIX Issue 6 no
longer defines a NULL special case, and the old DEBUGASSERT() panicked
debug builds.
Co-developed-by: dengwenqi <dengwenqi@xiaomi.com>
Co-developed-by: fangxinyong <fangxinyong@xiaomi.com>
Signed-off-by: fangxinyong <fangxinyong@xiaomi.com>
Signed-off-by: dengwenqi <dengwenqi@xiaomi.com>
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
lio_listio() links each aiocbp->lio_link into its batch list before
submitting the I/O, but submitted the operations through the public
aio_read()/aio_write(), which re-initialized lio_link and destroyed
the list membership. With an aiocb pre-filled with garbage (as in
ostest), the completion path then walked an invalid list.
Extract aio_read_internal()/aio_write_internal() that skip the
lio_link setup; aio_read()/aio_write() initialize lio_link (and
reject a NULL aiocbp) before calling the internal functions, while
lio_listio() calls the internal functions directly to preserve its
own lio_link setup. For entries that are not part of a batch,
lio_listio() self-initializes lio_link instead.
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
aio_fsync() never initialized aiocbp->lio_link, but the reworked
aio_signal() tests list_in_list(&lio_link) on every completion. With
an uninitialized (or zero-filled) lio_link the behavior was
unpredictable; initialize the node so standalone fsync operations are
self-consistent.
Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
Per POSIX, aio_read() and aio_write() must return -1 and set errno to
EINVAL when the request cannot be queued (aio_reqprio < 0,
aio_offset < 0), and the error must also be retrievable via
aio_error(). Conversely, when queuing fails with a bad file
descriptor, the error belongs to the asynchronous operation: the
functions must return 0 and report EBADF through aio_error().
- Merge the offset/reqprio checks and return ERROR with errno set,
after storing the result in aio_result for aio_error().
- Drop the aio_fildes < 0 early return: a closed descriptor is now
caught by fcntl()/aio_queue() and reported through aio_result with
the function returning OK.
- aio_error(): report -EINVAL (failed validation) through errno
instead of returning it as an error value.
Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
aioc_decant() frees the AIO container and detaches the aiocbp. The
I/O workers (aio_read_worker, aio_write_worker, aio_fsync_worker)
called it before signaling completion, so aio_signal() and any code
touching the container afterwards ran on freed memory. Additionally,
if the caller closed the file early the detached container could be
reused with a stale file reference. Move aioc_decant() to after
aio_signal() and use aioc->aioc_aiocbp directly in the workers.
aio_cancel() also had two problems: with no aiocbp it looped over
g_aio_pending with a do/while that skipped the list re-entry check, so
a failed work_cancel() on an already running I/O caused an endless
loop; and an invalid fildes only checked 'fildes < 0' instead of
validating the descriptor, so a closed fd was not reported as EBADF.
Use a for-loop that always advances and validate the descriptor with
file_get()/file_put().
Co-developed-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
lio_listio() never validated 'nent' against {AIO_LISTIO_MAX}, so a
batch larger than the documented limit was silently accepted, and the
hard-coded _POSIX_AIO_LISTIO_MAX value of 2 was too small for real
workloads (LTP uses 10 entries per call).
Add the FS_AIO_LISTIO_MAX Kconfig option (default 10), use it for
_POSIX_AIO_LISTIO_MAX in include/limits.h, validate 'nent' in
lio_listio(), and report the limit through sysconf(_SC_AIO_LISTIO_MAX).
Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
POSIX declares lio_listio() as:
int lio_listio(int, struct aiocb *restrict const [restrict], int,
struct sigevent *restrict);
Update the prototype in include/aio.h (and the implementation and
libc.csv entry) accordingly, and drop the parameter names from the
other aio_* prototypes for consistency.
Signed-off-by: guoshichao <guoshichao@xiaomi.com>
When a queued operation fails immediately (bad fd, EINVAL, or a failed
aio_read/aio_write submission), lio_listio() unconditionally deleted
the aiocbp from the request list. In LIO_WAIT mode (or when no sig was
requested) the lio_link nodes were never linked into the list, so
list_delete() corrupted memory and crashed.
Only unlink the node when it was actually linked, i.e. when
mode == LIO_NOWAIT and a sigevent was provided.
Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
When lio_listio() is called with LIO_NOWAIT and a non-NULL sig, and no
I/O could be queued (or all entries are LIO_NOP/NULL), the completion
notification dereferences a NULL aiocbp picked from an empty iteration,
crashing nxsig_notification().
Scan the list for any non-NULL entry before delivering the
notification, and skip it entirely when the list contains only NULL
entries.
Signed-off-by: zhengyu16 <zhengyu16@xiaomi.com>
Previously, lio_listio() called aio_read()/aio_write() to submit the
I/O and only then initialized the per-request notification state
(aio_priv based), so a worker thread could complete an operation before
that state was set up (thread-unsafe), and the completion notification
hijacked the per-request sigevent machinery.
Rework the implementation: lio_listio() now links every aiocb of the
batch into a list (lio_link) before any I/O is submitted. When an
operation completes, aio_signal() removes its node from the list under
aio_lock() and delivers the lio_listio completion notification only
when the list becomes empty. The unused aio_priv field is replaced by
the lio_link/lio_sigevent/lio_sigwork fields in struct aiocb.
Co-developed-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
lio_listio() submits I/O through the internal aio_read/aio_write
helpers and is only built when CONFIG_FS_AIO is enabled. Keeping it in
libs/libc splits one subsystem across two directories and forces fs/aio
to export internal interfaces to the libc build.
Move the file (and its two build system entries) from libs/libc/aio to
fs/aio so that the whole AIO implementation lives in one place.
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
Fix blank-line-after-declarations and switch-case alignment issues in fs/fat files touched by the unlink-while-open change, including pre-existing violations in the same regions. No functional change.
Signed-off-by: Arnav Sharma <2006arnavsharma@gmail.com>
Add a FAT local canonical open-file object to maintain shared state between multiple open handles of the same file. When an open file is unlinked, remove its directory entry but defer freeing the FAT cluster chain until the last open reference is closed. The shared object maintains the file size, starting cluster, directory-entry location, reference count, and pending-delete state. This avoids identifying open deleted files solely by their cluster number and correctly handles empty files, multiple opens, dup(), rename, and directory or cluster reuse. Pending deleted files no longer write metadata back to a removed or reused directory entry, while fstat(), truncate(), sync(), and subsequent writes continue to operate on the shared in-memory state. The implementation is kept within fs/fat and does not introduce a generic VFS inode mechanism. Fixes: #20037
Signed-off-by: Arnav Sharma <2006arnavsharma@gmail.com>
An ET_DYN object is loaded into one allocation with its data behind its
text, because its data references sit at a fixed distance from the code
that makes them. An FDPIC object does not work that way: it reaches its
data through a base register, so the two segments can be placed wherever
suits, and the point of the format is that the read-only one is left on
the media and executed there while only the writable one is copied. One
copy of the text then serves every instance.
So libelf_load() grows a second case. The object announces itself in the
OS/ABI byte, which is noted once in libelf_loadhdrs() rather than
re-derived; e_flags cannot be used for this, as an FDPIC object's are an
unremarkable EABI version and testing them would reject every valid
module. Text is taken from the media address plus the segment's own file
offset -- the same arithmetic the ET_REL path already does with
sh_offset -- and libelf_loadfile() does not read it. If the filesystem
cannot show its media, the loader copies the text to RAM instead. The
module then loses the shared text and the flash saving, but it runs.
Obtaining that address needs two mechanisms, and they are not
interchangeable. A compacting filesystem can move a file's blocks, so it
hands out an address only with a pin that holds them still and expects
the pin back; xipfs is the one in tree. A filesystem whose layout never
changes has nothing to hold and answers FIOC_XIPBASE with a bare address;
romfs and tmpfs are those. libelf_xipacquire() asks for the pin first,
because a filesystem that needs one is not safe without it, and
libelf_unload() gives it back. The loader asks for a pin only if it can
hold one, or the pin would stay for ever.
The pin is thus not specific to FDPIC. Any module that executes in place
from a compacting filesystem takes one, and gives it back at unload.
mmap() is not used, though both filesystems implement it. The mapping
would be recorded against whichever task called the loader, while the
release happens when the module's own task exits, which is a different
group -- so the pin would outlive the module and the extent would never
become movable again.
Unloading has to change with placement: the existing path frees only
textalloc because ET_DYN had a single allocation, which would leak an
FDPIC object's data and free media the filesystem only lent us.
Nothing here runs for a non-FDPIC object; every branch is behind the flag
and the single-allocation path is untouched. Built and booted
mps3-an547:picostest, which is CONFIG_ELF with CONFIG_PIC, with no change
in behaviour.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
vsnprintf() returns the total formatted string length even when truncated to info->line. Passing this untruncated length to procfs_memcpy causes a read beyond the 64-byte line staging buffer.
Fixes#20011
Signed-off-by: Hritik Naik <hritiknaik16@gmail.com>
inode_reserve() previously continued processing all negative return
values from inode_search(). Only -ENOENT indicates that the target
inode is absent and creation may continue.
Propagate other search errors through the existing cleanup path to
avoid continuing inode creation with invalid insertion metadata.
Assisted-by: GitHub Copilot
Signed-off-by: Megha Rajput <i.meghar.2408@gmail.com>
Fix coding style violations detected by CI whole-file nxstyle scan:
- fs/smartfs/smartfs_utils.c: add missing braces after if (L334),
fix bad alignment (L414), fix switch brace alignment (L1531)
- fs/hostfs/hostfs.c: add blank line after declaration (L576)
These are pre-existing style issues in master, not introduced by
this PR, but reported because CI checks the entire touched file.
Signed-off-by: yukangzhi <yukangzhi@xiaomi.com>
When inode_find() for path2 fails due to ENAMETOOLONG (or ELOOP),
the else branch incorrectly falls through to the EXDEV check based
on whether target is a mountpoint. This causes link() to report
EXDEV for overly long path2, violating POSIX which requires
ENAMETOOLONG in this case.
Fix by propagating the original inode_find() error code when it is
not ENOENT or ENOTDIR (i.e., not a simple "path does not exist"
condition).
Signed-off-by: yukangzhi <yukangzhi@xiaomi.com>
Root cause: _inode_search() built the absolute form of a relative
path with snprintf(buf, PATH_MAX, "%s/%s", cwd, path), silently
truncating it when cwd + "/" + path exceeded PATH_MAX. The truncated
buffer was then handed to _inode_canonicalize(), which collapsed
".." segments against the wrong cut-off suffix. A valid relative
path of PATH_MAX-1 bytes (legal per pathconf(_PC_PATH_MAX)) could
thus collapse onto a directory and open() returned EISDIR instead
of resolving the file.
Fix: size the temp buffer to hold the full uncanonicalized
"<cwd>/<path>" form so canonicalization sees the complete path.
lib_get_tempbuffer falls back to a malloc'd buffer when the size
exceeds PATH_MAX (CONFIG_LIBC_TEMPBUFFER_MALLOC). The existing
PATH_MAX check in _inode_canonicalize() still rejects any
canonicalized result that is too long, so ENAMETOOLONG semantics
are preserved.
Signed-off-by: dengwenqi <dengwenqi@xiaomi.com>
Since _inode_canonicalize() now resolves all "." and ".." segments
in the common VFS layer before inode search, the relpath passed to
each filesystem will never contain ".." segments. Remove the
now-dead ".." handling code from individual filesystem layers and
the inode search internals.
Files modified (redundant ".." path resolution removed):
- fs/hostfs/hostfs.c: remove depth-tracking escape check in
hostfs_mkpath(), simplify to direct path concatenation.
- fs/rpmsgfs/rpmsgfs.c: same as hostfs, remove depth-tracking in
rpmsgfs_mkpath().
- fs/smartfs/smartfs_utils.c: remove "." and ".." segment checks
in smartfs_finddirentry(), de-indent the remaining search logic.
- fs/inode/fs_inodesearch.c: remove _inode_isdotdot() function,
simplify _compute_path_depth() to only count forward segments,
remove dead else-if branch in _inode_search().
Files NOT modified (and why):
- fs/littlefs/littlefs/lfs.c: third-party upstream library (git
submodule), must not be modified locally.
- fs/fatfs/fatfs/source/ff.c: third-party upstream library.
- fs/lwext4/lwext4/src/ext4*.c: third-party upstream library.
- fs/cromfs/fs_cromfs.c: handles "." and ".." as directory entries
(structural, not path resolution), so its code stays.
- fs/vfs/fs_symlink.c: constructs relative paths containing ".."
(writes, not parses relpath).
Signed-off-by: yukangzhi <yukangzhi@xiaomi.com>
Add _inode_canonicalize() to remove '.' and '..' segments from the
absolute path before the inode tree traversal begins. This fixes the
case where paths containing '..' that resolve back to a mountpoint
root (e.g., /tmp/subdir/..) were not being handed to the filesystem.
Previously, _compute_path_depth() returned 0 for such paths, causing
the VFS to skip the mountpoint and attempt to find 'subdir' in the
pseudo filesystem -- which fails with ENOTDIR.
With canonicalization, /tmp/subdir/.. becomes /tmp before the search,
so the mountpoint is correctly matched. This fixes chdir('..'),
stat('../..'), opendir('../..'), and similar operations from within
mountpoint subdirectories.
The implementation uses an in-place two-pointer algorithm with no
additional stack allocation, safe for NuttX's small kernel stacks.
Signed-off-by: yukangzhi <yukangzhi@xiaomi.com>
Fix two POSIX compliance issues in mountptrename():
1. When old and new are hard links to the same file (same st_dev and
st_ino), POSIX requires rename() to succeed without removing either
link. Previously, NuttX would unlink(new) then rename(old, new),
effectively losing one link. Fix by comparing inode identity before
any destructive operation.
2. When new is a subdirectory of old (e.g., rename('a', 'a/b')), POSIX
requires EINVAL. Previously, NuttX would rmdir(new) first, then the
filesystem's rename() would fail -- but new was already deleted,
causing data loss. Fix by detecting the subdirectory relationship
(newrelpath starts with oldrelpath + '/') before any rmdir/unlink.
Signed-off-by: yukangzhi <yukangzhi@xiaomi.com>
The loop condition 'namelen <= NAME_MAX' allowed filenames of
NAME_MAX+1 characters to pass validation. When the filename segment
reached exactly NAME_MAX+1 chars and was at the end of the path
string, the loop exited due to *path == '\0' and returned OK instead
of -ENAMETOOLONG.
Fix by moving the NAME_MAX check inside the loop body with an
immediate return on violation. Also fix the post-loop return to
explicitly check pathlen >= PATH_MAX instead of relying on *path
which conflated the two exit conditions.
Before: creat() with 97-char filename (NAME_MAX=96) succeeded
After: creat() with 97-char filename correctly returns ENAMETOOLONG
Signed-off-by: yukangzhi <yukangzhi@xiaomi.com>
Replace fs_heap_malloc/free with lib_get_tempbuffer/lib_put_tempbuffer
in smartfs_finddirentry(). This aligns smartfs with the common VFS
tempbuffer allocation pattern and is a prerequisite for the
canonicalization cleanup that removes redundant ".." handling from
individual filesystem layers.
Signed-off-by: zhaoxingyu1 <zhaoxingyu1@xiaomi.com>
Add missing blank lines after declarations and fix one bad alignment
in hostfs/rpmsgfs-related files. These are pre-existing style issues
flagged by CI's whole-file nxstyle check when our PR touches these
files. No logic change (git diff -w is blank-line-only additions).
Signed-off-by: yukangzhi <yukangzhi@xiaomi.com>
Migrate hostfs path buffer allocation from fs_heap and stack
arrays to lib_get_tempbuffer/lib_put_tempbuffer.
Signed-off-by: zhaoxingyu1 <zhaoxingyu1@xiaomi.com>
Replace the global `g_lock` with a per-filesystem `fs->fs_lock`
to improve concurrency for multi-mount scenarios.
Signed-off-by: buxiasen <buxiasen@xiaomi.com>
The _inode_checkpath function uses `namelen < NAME_MAX` to validate
path segment lengths. When a filename is exactly NAME_MAX characters
long and is followed by more path segments (e.g. /dir/), the loop
exits with namelen == NAME_MAX before processing the '/' separator,
causing a spurious ENAMETOOLONG error.
Per POSIX, NAME_MAX is the maximum number of bytes in a filename not
including the terminating null, so a filename of exactly NAME_MAX
characters is valid. Change the condition to `namelen <= NAME_MAX`
so the loop can process the trailing '/' separator and correctly
reset namelen for the next path segment.
Signed-off-by: wangxingxing <wangxingxing@xiaomi.com>
Add a helper _inode_checkpath() that validates the path before the
search: it returns -ENOENT for an empty path and -ENAMETOOLONG when any
single path component exceeds NAME_MAX or the whole path exceeds
PATH_MAX. inode_search() now runs this check first so that oversized
paths and file names are rejected with the correct POSIX error code.
Signed-off-by: guohao15 <guohao15@xiaomi.com>
Add support for resolving relative path components (in particular the
".." parent references) during the inode search. A helper
_compute_path_depth() computes the remaining path depth so that a mount
point is only treated as the terminal node when the depth is positive,
and "../" components walk back up to the parent inode.
Signed-off-by: zhaoxingyu1 <zhaoxingyu1@xiaomi.com>
Replace the fs_heap_asprintf()/fs_heap_free() based allocation of the
path buffer in the inode search with the lib_get_tempbuffer()/
lib_put_tempbuffer() pool. Fixed PATH_MAX sized temporary buffers avoid
per-call heap allocation and keep the buffer allocator consistent with
the rest of the path-resolution code.
Signed-off-by: zhaoxingyu1 <zhaoxingyu1@xiaomi.com>
While walking the path components, a non-final component must refer to a
directory. When descending into a child, verify the parent inode is a
pseudo directory; if it is not, stop the search and return -ENOTDIR as
required by POSIX for a path prefix that is not a directory.
Signed-off-by: zhengyu16 <zhengyu16@xiaomi.com>
An empty pathname does not name any inode. Return -ENOENT early in
inode_search() when the path is an empty string, instead of continuing
into the search logic with a zero-length path.
Signed-off-by: zhengyu16 <zhengyu16@xiaomi.com>
When resolving a symbolic link target, call the public inode_search()
instead of the internal _inode_search() so that the link target path is
first formatted (leading '/' handling and relative-path conversion)
before the lookup. This ensures link targets are resolved through the
same normalization path as ordinary lookups.
Signed-off-by: zhengyu16 <zhengyu16@xiaomi.com>
Add an lstat method to mountpt_operations so that mounted file systems
can report link metadata without dereferencing symbolic links.
In mountptrename() and stat_recursive(), prefer lstat() over stat()
when it is available so that rename() and the non-following stat path
operate on the link itself rather than its target, matching POSIX
semantics.
Signed-off-by: zhengyu16 <zhengyu16@xiaomi.com>
resolve rename{7}:
On a call to rename(old, new), when the old argument points to the pathname of a directory, if the directory named by the new argument exists and is empty it shall be removed and old renamed to new.
resolve rename{23}:
EEXIST or ENOTEMPTY in errno and a return value of -1 on a call to rename(old, new) when the link named by new is a directory containing
entries other than dot and dot-dot. The named files are not changed.
Signed-off-by: zhengyu16 <zhengyu16@xiaomi.com>
1. add three func to mountpt_operations:
link
symlink
readlink
2. modify fs_link、fs_symlink、fs_readlink for mountpt
Signed-off-by: zhengyu16 <zhengyu16@xiaomi.com>
The link support is no longer limited to the pseudo file system and now
covers both soft (symbolic) links and hard links across the VFS. Rename
the configuration option PSEUDOFS_SOFTLINKS to the more accurate FS_LINKS
and update all references in the source, headers, Kconfig, documentation
and board defconfigs accordingly.
This is a configuration rename; any out-of-tree defconfig that still
selects PSEUDOFS_SOFTLINKS must be updated to FS_LINKS.
Signed-off-by: zhengyu16 <zhengyu16@xiaomi.com>
Rename atomic_fetch_add/sub/or/and/xor to atomic_add/sub/or/and/xor
to avoid conflicts with the C/C++ standard library naming. The
atomic_fetch_xxx naming is reserved by the standard; keeping it causes
function name conflicts when source files indirectly include both
<nuttx/atomic.h> and <atomic>/<stdatomic.h>.
Signed-off-by: zhangyu117 <zhangyu117@xiaomi.com>
romfs_seek() clamps the computed position to the file size when it
exceeds rf_size, but never checks for a negative result. lseek(fd,
offset, SEEK_SET/SEEK_CUR/SEEK_END) with an offset that produces a
negative position (e.g. a negative SEEK_SET offset, or a SEEK_CUR/
SEEK_END offset more negative than the current position/file size)
is written straight into filep->f_pos.
The subsequent romfs_read() computes
`rf->rf_startoffset + filep->f_pos` into a uint32_t, so a negative
f_pos wraps around to a huge unsigned offset, and romfs_hwread()'s
XIP path memcpy()s from rm_xipbase plus that offset -- an
out-of-bounds read far past the mapped flash region.
Add the same "if (position < 0) return -EINVAL" guard already used
by fs/fat/fs_fat32.c's seek function, before the existing
end-of-file clamp.
Signed-off-by: yi chen <94xhn1@gmail.com>
Assisted-by: Claude:claude-sonnet-5
Supports the UNIX setuid-on-exec sudo helper. Documents the model,
generates an extra ROMFS user and /etc/sudoers for a non-root test,
reports BINFS modes from the builtin table so ls -l matches execute
bits, and skips NULL environment entries when sanitizing a setuid exec.
Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
This can be used on small systems to save RAM if the SHM object
doesn't need to be cache-aligned.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
For kernel builds where CONFIG_ARCH_TEXT_VBASE is set to 0, allow a NULL
buffer in file_readv() to prevent ELF binary loading failures for
binaries located at address 0.
This fix was originally introduced in #18830, but was inadvertently
reverted by someone unaware that platforms with CONFIG_ARCH_TEXT_VBASE
equal to 0 cannot function at all without it. This commit restores the
necessary check to prevent regressions in zero-based text kernel
configurations. Most platforms remain completely unaffected since only
about 5 boards utilize a text virtual base of zero.
Signed-off-by: Lwazi Dube <lwazeh@gmail.com>
inode_nextname() already skipped a '.' segment mid-path (e.g. "./foo"),
but only checked for a '/' right after it -- a path ending in a bare
'.' (e.g. "/foo/.", or "." itself once AT_FDCWD resolution prepends
$PWD) fell through and was looked up as a literal child named ".",
which no real node is ever named, failing with ENOENT.
This broke every "operate on the current directory" idiom relative
paths rely on: bare `ls`, `stat .`, `cd .`, etc., all failed outright
even though the equivalent absolute path worked fine. Found while
testing the Toybox port's interactive REPL, but this is generic VFS
path resolution, not Toybox-specific.
Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Sonnet 5 <noreply@anthropic.com>
Track supplementary GIDs per task group, wire setgroups/getgroups
syscalls when CONFIG_SCHED_NGROUPS > 0, and honor them in DAC checks
via nxsched_has_gid(). When NGROUPS is 0, libc provides getgroups/
setgroups stubs. initgroups() fails instead of silently truncating
when membership exceeds CONFIG_SCHED_NGROUPS.
Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>