mirror of
https://github.com/apache/nuttx.git
synced 2026-10-08 14:55:18 +00:00
ttyname_r() passed the caller buffer straight to fcntl(F_GETPATH) whenever buflen >= TTY_NAME_MAX, but every FIOC_FILEPATH handler writes the path bounded by PATH_MAX and ignores the caller buffer size. A tty registered under a nested /dev path, or reached through rpmsgfs, has a path longer than TTY_NAME_MAX and overwrote the caller buffer, silently corrupting memory behind a zero return code. The small-buffer branch had the same defect against its own stack local char name[TTY_NAME_MAX]. Gate the direct write on PATH_MAX instead and stage the path through a PATH_MAX path buffer obtained via lib_get_tempbuffer(), returning ERANGE when it does not fit. Verified on sim:nsh with a test driver registered at an 85-character tty path: pre-fix, ttyname_r(buf, TTY_NAME_MAX) returned 0 and smashed the canaries behind the buffer, and the small-buffer branch panicked; post-fix both cases return ERANGE with the canaries intact. Assisted-by: Claude Code (glm-5.3) <claude@anthropic.com> Signed-off-by: Junbo Zheng <zhengjunbo1@xiaomi.com> |
||
|---|---|---|
| .. | ||
| CMakeLists.txt | ||
| lib_cfmakeraw.c | ||
| lib_cfspeed.c | ||
| lib_isatty.c | ||
| lib_tcdrain.c | ||
| lib_tcflow.c | ||
| lib_tcflush.c | ||
| lib_tcgetattr.c | ||
| lib_tcgetpgrp.c | ||
| lib_tcgetsid.c | ||
| lib_tcsendbreak.c | ||
| lib_tcsetattr.c | ||
| lib_tcsetpgrp.c | ||
| lib_ttyname.c | ||
| lib_ttynamer.c | ||
| Make.defs | ||