mirror of
https://github.com/apache/nuttx.git
synced 2026-08-09 14:35:08 +00:00
|
Some checks are pending
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
A mutex records its holder as a task id in the low 31 bits of a word whose top bit means "someone is blocked on this". The id was stored without masking, so an id with its top bit set became a holder with the blocking bit raised. Task ids are normally small and positive, but not always. nxsched_gettid() reports -ESRCH for a context that no longer maps to a running task, and there is a window where that is exactly what the running context is: nxtask_exit() marks the next task ready to run while the dying task is still executing on its own stack, and only then releases the TCB. Freeing the group inside that release takes and drops the group's mutexes, so the lock stores 0xfffffffd and the unlock compares 0x7ffffffd, which are not equal. With assertions enabled the unlock trips its holder check, and every exit of a process that frees memory panics. In a kernel build that is every exit, so no program could be run twice, and running one at all took the shell down with it. Without assertions the failure is silent: the accidental blocking bit sends the unlock looking for a waiter that never existed. Encode the id the same way everywhere it is stored or compared, so that a lock and an unlock from one context agree whatever the id's sign. The masked forms of -1 and -2 would alias the "no holder" and "reset" values, but nxsched_gettid() yields only valid ids and -ESRCH. mm_lock() already sidesteps this window with a note that gettid() may return -ESRCH during a context switch; this gives the generic mutex the same footing rather than a second special case. Test case, on the EIC7700 EVB, which is a kernel build with assertions: nsh> hello Hello, World!! Before, that printed and then panicked in sem_post, taking the shell with it, every time. After, five runs in a row complete and the shell survives. ps over telnet still completes. Assisted-by: Claude:claude-opus-5 Signed-off-by: Justin Hammond <justin@dynam.ac> |
||
|---|---|---|
| .. | ||
| aio | ||
| assert | ||
| audio | ||
| builtin | ||
| ctype | ||
| dirent | ||
| dlfcn | ||
| elf | ||
| errno | ||
| eventfd | ||
| fdt | ||
| fixedmath | ||
| gdbstub | ||
| gnssutils | ||
| grp | ||
| hex2bin | ||
| inttypes | ||
| libgen | ||
| locale | ||
| lzf | ||
| machine | ||
| misc | ||
| net | ||
| netdb | ||
| obstack | ||
| pthread | ||
| pwd | ||
| queue | ||
| regex | ||
| sched | ||
| search | ||
| semaphore | ||
| signal | ||
| spawn | ||
| stdio | ||
| stdlib | ||
| stream | ||
| string | ||
| symtab | ||
| syslog | ||
| termios | ||
| time | ||
| tls | ||
| uio | ||
| unistd | ||
| userfs | ||
| uuid | ||
| wchar | ||
| wctype | ||
| wqueue | ||
| zoneinfo | ||
| .gitignore | ||
| CMakeLists.txt | ||
| Kconfig | ||
| libc.csv | ||
| libc.h | ||
| limits_check.c | ||
| Makefile | ||