mirror of
https://github.com/apache/nuttx.git
synced 2026-10-07 22:35:22 +00:00
ttyname_r() passed the caller buffer straight to fcntl(F_GETPATH) whenever buflen >= TTY_NAME_MAX, but every FIOC_FILEPATH handler writes the path bounded by PATH_MAX and ignores the caller buffer size. A tty registered under a nested /dev path, or reached through rpmsgfs, has a path longer than TTY_NAME_MAX and overwrote the caller buffer, silently corrupting memory behind a zero return code. The small-buffer branch had the same defect against its own stack local char name[TTY_NAME_MAX]. Gate the direct write on PATH_MAX instead and stage the path through a PATH_MAX path buffer obtained via lib_get_tempbuffer(), returning ERANGE when it does not fit. Verified on sim:nsh with a test driver registered at an 85-character tty path: pre-fix, ttyname_r(buf, TTY_NAME_MAX) returned 0 and smashed the canaries behind the buffer, and the small-buffer branch panicked; post-fix both cases return ERANGE with the canaries intact. Assisted-by: Claude Code (glm-5.3) <claude@anthropic.com> Signed-off-by: Junbo Zheng <zhengjunbo1@xiaomi.com> |
||
|---|---|---|
| .. | ||
| libbuiltin | ||
| libc | ||
| libdsp | ||
| libm | ||
| libnx | ||
| libxx | ||
| CMakeLists.txt | ||