nuttx/Documentation/guides/security/fortify.rst
Vinicius May f6ecf80ebb Documentation: brand new layout for NuttX documentation.
The documentation grew one page at a time, so the tree follows the
history of who wrote what and not the shape of NuttX. Scheduling is
spread over three places, a driver page can sit above the subsystem
that owns it, and the front page lists everything at the same level.
That is a lot to face when all you want to know is where the scheduler
lives.

This change files every page under the code it describes. It is a move,
not a rewrite: outside the ten pages named below, every page keeps the
text that is already in master, and no page's text is deleted.

What it does:

* Groups the table of contents into nine chapters.
* Moves the OS subsystems under os/: scheduling, memory, drivers,
  filesystem, networking, IPC, interrupts, libs, time.
* Renames the platform pages to the names the source tree uses, and
  derives their tags from the tree instead of by hand.
* Splits guides/ by subject.
* Adds Documentation/redirects.py, with a rule for every page that left
  its old path, so old URLs keep working. The redirect page also carries
  a link's #anchor across to the new page.

Ten pages have text that is new or rewritten. Nine of them are the
landing page of a chapter, which has to exist for the new structure:

    index                  the front page
    os/index               OS Design
    os/scheduling/index    Scheduling
    os/interrupts/index    Interrupts
    os/ipc/index           IPC
    os/time/index          Time and timers
    about/index            About
    developing/index       Developing NuttX
    ReleaseNotes/index     Release notes

The tenth is os/libs/libbuiltin, the only page here with technical
content: libs/libbuiltin/ had no page at all. Five SVG diagrams come
with these pages, hand-written XML with no editor metadata.

Nothing outside Documentation/ is touched.

How it was checked:

* Sphinx builds with -W: no warnings, and no document left outside a
  toctree.
* A script, offered in the PR, proves the narrow claim this rests on.
  For every page outside the ten named above it erases what a move
  touches -- link target, path, tag line, toctree block, table border --
  from the whole old text and the whole new text, and requires the two
  to be byte for byte identical. It also requires every sentence of a
  deleted page to turn up somewhere, and every page that left its old
  path to have a redirect, from a URL that existed, to where its content
  went. It exits non-zero and names the page if any of that is not true,
  and it tests added pages too, so forgetting to declare one cannot make
  it pass.
* An independent audit checked 133 factual claims on these ten pages
  against the tree, one shell command per claim: 130 confirmed, 1
  refuted and fixed here, 2 not checkable.
* tools/checkpatch.sh is clean over the range.

The diff is large because moving a page changes every link that points
to it. Most of it is pure renames, and board pages that gained one tag
line.

Assisted-by: Claude:claude-opus-5
2026-10-08 01:40:54 +08:00

77 lines
2.9 KiB
ReStructuredText

========
Fortify
========
Overview
--------
A common error in C programs is invoking functions that might exceed memory bounds,
causing crashes or undefined behavior. Examples include incorrect usage of functions like
``memcpy`` and ``memset``. `FORTIFY_SOURCE` is a mechanism designed to help developers quickly
detect and mitigate boundary-related issues caused by improper use of library functions.
Support
-------
`FORTIFY_SOURCE` is implemented as a software check by the compiler and is supported across all architectures.
It works by adding additional validation checks to standard library function calls.
Usage
-----
To enable `FORTIFY_SOURCE`, configure the kernel with the following option:
``CONFIG_FORTIFY_SOURCE=level``
Where `level` can be set as:
1. **Compile-time Checks**:
Detects issues during compilation by analyzing source code.
2. **Stack Variable Checks**:
Extends level 1 by checking stack variables at runtime.
3. **Heap Memory Checks**:
Builds on level 2 by adding checks for memory allocated with ``malloc``.
(Requires GCC version 12 or later.)
FORTIFY_SOURCE Overview
=======================
`FORTIFY_SOURCE` detects potential security vulnerabilities by statically analyzing source code at compile time.
It replaces standard library function calls with safer versions that include additional boundary checks.
These safer versions validate the operation's boundaries and the input's validity before performing certain operations.
GCC Built-in Functions
-----------------------
The GCC compiler internally implements two key functions for `FORTIFY_SOURCE`:
- ``__builtin_object_size``: Determines the size of a statically allocated object.
- ``__builtin_dynamic_object_size``: Determines the size of dynamically allocated objects (e.g., via ``malloc``).
Starting with GCC 12, these functions support retrieving the size of variables allocated with ``malloc``.
By passing a variable or buffer as an argument to these functions, the compiler can compute the corresponding size.
Using this size, it is possible to check for potential out-of-bounds behavior in runtime operations.
Example: memcpy Implementation in NuttX
----------------------------------------
The following example demonstrates how `FORTIFY_SOURCE` can be used to enhance security in a ``memcpy``
implementation in NuttX:
.. code-block:: c
fortify_function(memcpy)
FAR void *memcpy(FAR void *dest,
FAR const void *src,
size_t n)
{
fortify_assert(n <= fortify_size(dest, 0) && n <= fortify_size(src, 0));
return __real_memcpy(dest, src, n);
}
In this implementation, the ``fortify_assert`` macro ensures that the size of the source and destination buffers
is sufficient to handle the requested memory operation. If the assertion fails, it indicates a potential buffer
overflow, helping developers quickly identify and address such vulnerabilities.