mirror of
https://github.com/apache/nuttx.git
synced 2026-10-11 00:00:24 +00:00
The documentation grew one page at a time, so the tree follows the
history of who wrote what and not the shape of NuttX. Scheduling is
spread over three places, a driver page can sit above the subsystem
that owns it, and the front page lists everything at the same level.
That is a lot to face when all you want to know is where the scheduler
lives.
This change files every page under the code it describes. It is a move,
not a rewrite: outside the ten pages named below, every page keeps the
text that is already in master, and no page's text is deleted.
What it does:
* Groups the table of contents into nine chapters.
* Moves the OS subsystems under os/: scheduling, memory, drivers,
filesystem, networking, IPC, interrupts, libs, time.
* Renames the platform pages to the names the source tree uses, and
derives their tags from the tree instead of by hand.
* Splits guides/ by subject.
* Adds Documentation/redirects.py, with a rule for every page that left
its old path, so old URLs keep working. The redirect page also carries
a link's #anchor across to the new page.
Ten pages have text that is new or rewritten. Nine of them are the
landing page of a chapter, which has to exist for the new structure:
index the front page
os/index OS Design
os/scheduling/index Scheduling
os/interrupts/index Interrupts
os/ipc/index IPC
os/time/index Time and timers
about/index About
developing/index Developing NuttX
ReleaseNotes/index Release notes
The tenth is os/libs/libbuiltin, the only page here with technical
content: libs/libbuiltin/ had no page at all. Five SVG diagrams come
with these pages, hand-written XML with no editor metadata.
Nothing outside Documentation/ is touched.
How it was checked:
* Sphinx builds with -W: no warnings, and no document left outside a
toctree.
* A script, offered in the PR, proves the narrow claim this rests on.
For every page outside the ten named above it erases what a move
touches -- link target, path, tag line, toctree block, table border --
from the whole old text and the whole new text, and requires the two
to be byte for byte identical. It also requires every sentence of a
deleted page to turn up somewhere, and every page that left its old
path to have a redirect, from a URL that existed, to where its content
went. It exits non-zero and names the page if any of that is not true,
and it tests added pages too, so forgetting to declare one cannot make
it pass.
* An independent audit checked 133 factual claims on these ten pages
against the tree, one shell command per claim: 130 confirmed, 1
refuted and fixed here, 2 not checkable.
* tools/checkpatch.sh is clean over the range.
The diff is large because moving a page changes every link that points
to it. Most of it is pure renames, and board pages that gained one tag
line.
Assisted-by: Claude:claude-opus-5
77 lines
2.9 KiB
ReStructuredText
77 lines
2.9 KiB
ReStructuredText
========
|
|
Fortify
|
|
========
|
|
|
|
Overview
|
|
--------
|
|
|
|
A common error in C programs is invoking functions that might exceed memory bounds,
|
|
causing crashes or undefined behavior. Examples include incorrect usage of functions like
|
|
``memcpy`` and ``memset``. `FORTIFY_SOURCE` is a mechanism designed to help developers quickly
|
|
detect and mitigate boundary-related issues caused by improper use of library functions.
|
|
|
|
Support
|
|
-------
|
|
|
|
`FORTIFY_SOURCE` is implemented as a software check by the compiler and is supported across all architectures.
|
|
It works by adding additional validation checks to standard library function calls.
|
|
|
|
Usage
|
|
-----
|
|
|
|
To enable `FORTIFY_SOURCE`, configure the kernel with the following option:
|
|
|
|
``CONFIG_FORTIFY_SOURCE=level``
|
|
|
|
Where `level` can be set as:
|
|
|
|
1. **Compile-time Checks**:
|
|
Detects issues during compilation by analyzing source code.
|
|
|
|
2. **Stack Variable Checks**:
|
|
Extends level 1 by checking stack variables at runtime.
|
|
|
|
3. **Heap Memory Checks**:
|
|
Builds on level 2 by adding checks for memory allocated with ``malloc``.
|
|
(Requires GCC version 12 or later.)
|
|
|
|
FORTIFY_SOURCE Overview
|
|
=======================
|
|
|
|
`FORTIFY_SOURCE` detects potential security vulnerabilities by statically analyzing source code at compile time.
|
|
It replaces standard library function calls with safer versions that include additional boundary checks.
|
|
These safer versions validate the operation's boundaries and the input's validity before performing certain operations.
|
|
|
|
GCC Built-in Functions
|
|
-----------------------
|
|
|
|
The GCC compiler internally implements two key functions for `FORTIFY_SOURCE`:
|
|
|
|
- ``__builtin_object_size``: Determines the size of a statically allocated object.
|
|
- ``__builtin_dynamic_object_size``: Determines the size of dynamically allocated objects (e.g., via ``malloc``).
|
|
|
|
Starting with GCC 12, these functions support retrieving the size of variables allocated with ``malloc``.
|
|
|
|
By passing a variable or buffer as an argument to these functions, the compiler can compute the corresponding size.
|
|
Using this size, it is possible to check for potential out-of-bounds behavior in runtime operations.
|
|
|
|
Example: memcpy Implementation in NuttX
|
|
----------------------------------------
|
|
|
|
The following example demonstrates how `FORTIFY_SOURCE` can be used to enhance security in a ``memcpy``
|
|
implementation in NuttX:
|
|
|
|
.. code-block:: c
|
|
|
|
fortify_function(memcpy)
|
|
FAR void *memcpy(FAR void *dest,
|
|
FAR const void *src,
|
|
size_t n)
|
|
{
|
|
fortify_assert(n <= fortify_size(dest, 0) && n <= fortify_size(src, 0));
|
|
return __real_memcpy(dest, src, n);
|
|
}
|
|
|
|
In this implementation, the ``fortify_assert`` macro ensures that the size of the source and destination buffers
|
|
is sufficient to handle the requested memory operation. If the assertion fails, it indicates a potential buffer
|
|
overflow, helping developers quickly identify and address such vulnerabilities.
|