mirror of
https://github.com/apache/nuttx.git
synced 2026-08-01 20:28:58 +00:00
A task does not necessarily own an address environment. tcb->addrenv_own is set only by addrenv_attach(), which is reached only from addrenv_allocate(); a kernel thread never allocates one, and in a protected build nothing does -- there is a single address space for the whole system and the architecture's up_addrenv_*() are stubs. addrenv_own is then NULL for every task, always. That a task may have no address environment is already an expected state. addrenv_switch() returns OK when tcb->addrenv_curr is NULL and addrenv_drop() returns early, and every caller of addrenv_select() checks addrenv_own != NULL before calling in: nxsched_get_stateinfo(), nxtask_argvstr(), proc_groupenv() and the arm, arm64, risc-v and tricore up_check_tcbstack(). addrenv_take() and addrenv_give() are the only two that dereference unconditionally. addrenv_join() calls addrenv_take(ptcb->addrenv_own) without a check, so pthread_create() faults on &((struct addrenv_s *)NULL)->refs whenever the calling task has no address environment. With CONFIG_DEBUG_ASSERTIONS off the same access silently corrupts low memory instead. Handle NULL in both, the way the rest of the file already does. addrenv_give() returns a non-zero count for the NULL case so that callers never conclude an absent address environment has become unreferenced and should be destroyed. Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com> Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| addrenv.c | ||
| CMakeLists.txt | ||
| Make.defs | ||