mtdconfig_unregister_by_path() opened the device with file_open(), which runs mtdconfig_open() and therefore holds dev->lock for the whole lifetime of the temporary file reference. It then destroyed the mutex and freed the private device structure while that reference was still open, so the subsequent file_close() reached mtdconfig_close(), which performs nxmutex_unlock() on freed memory. Destroying a held mutex and unlocking it after free corrupt the heap; on sim this crashes deterministically in the next allocation (EXC_BAD_ACCESS in mm_malloc). Both file_close() and unregister_driver() return values were also discarded and the function unconditionally returned OK, masking legitimate errors. Reorder the teardown to close -> unregister -> destroy/free and propagate errors, so that: - file_close() (driver close callback and inode release) runs while the private device structure is still valid, releasing the exclusive access taken by mtdconfig_open(), - the private structure is destroyed and freed only after unregister_driver() succeeds. On failure the inode (and with it i_private) may still be referenced, so freeing would be wrong. Returning the error also honors the documented API contract (zero on success, negated errno on failure). This matches the established close -> unregister -> teardown ordering used by e.g. bchdev_unregister(). Verified with sim:configdata plus a register/unregister lifetime exercise in examples/configdata: 934706/934706 checks pass with the fix; with the fix stashed the same run dies with SIGSEGV right after mtdconfig_unregister_by_path() returns. Fixes: https://github.com/apache/nuttx/issues/20166 Signed-off-by: Arnav Sharma <2006arnavsharma@gmail.com> |
||
|---|---|---|
| .github | ||
| arch | ||
| audio | ||
| binfmt | ||
| boards | ||
| cmake | ||
| crypto | ||
| Documentation | ||
| drivers | ||
| dummy | ||
| fs | ||
| graphics | ||
| include | ||
| libs | ||
| mm | ||
| net | ||
| openamp | ||
| pass1 | ||
| sched | ||
| syscall | ||
| tools | ||
| video | ||
| wireless | ||
| .asf.yaml | ||
| .codespell-ignore-lines | ||
| .codespellrc | ||
| .editorconfig | ||
| .gitignore | ||
| .gitmessage | ||
| .pre-commit-config.yaml | ||
| .yamllint | ||
| AUTHORS | ||
| CMakeLists.txt | ||
| CONTRIBUTING.md | ||
| INVIOLABLES.md | ||
| Kconfig | ||
| LICENSE | ||
| Makefile | ||
| NOTICE | ||
| README.md | ||
| ReleaseNotes | ||
Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).
For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.
Getting Started
First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.
Documentation
You can find the current NuttX documentation on the Documentation Page.
Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.
The old NuttX documentation is still available in the Apache wiki.
Supported Boards
NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.
Contributing
If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.
License
The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.