mirror of
https://github.com/apache/nuttx.git
synced 2026-08-04 22:00:21 +00:00
ASAN trace:
...
==32087==ERROR: AddressSanitizer: heap-buffer-overflow on address 0xf4502120 at pc 0x56673ca3 bp 0xff9b6a08 sp 0xff9b69f8
WRITE of size 1 at 0xf4502120 thread T0
#0 0x56673ca2 in strcpy string/lib_strcpy.c:64
0xf4502120 is located 0 bytes to the right of 8224-byte region [0xf4500100,0xf4502120)
allocated by thread T0 here:
#0 0xf7a60f54 in malloc (/usr/lib32/libasan.so.4+0xe5f54)
#1 0x5667725d in up_create_stack sim/up_createstack.c:135
#2 0x56657ed8 in nxthread_create task/task_create.c:125
#3 0x566580bb in kthread_create task/task_create.c:297
#4 0x5665935f in work_start_highpri wqueue/kwork_hpthread.c:149
#5 0x56656f31 in nx_workqueues init/nx_bringup.c:181
#6 0x56656fc6 in nx_bringup init/nx_bringup.c:436
#7 0x56656e95 in nx_start init/nx_start.c:809
#8 0x566548d4 in main sim/up_head.c:95
#9 0xf763ae80 in __libc_start_main (/lib/i386-linux-gnu/libc.so.6+0x18e80)
CALLSTACK:
#8 0xf79de7a5 in __asan_report_store1 () from /usr/lib32/libasan.so.4
#9 0x565fd4d7 in strcpy (dest=0xf4a02121 "", src=0xf5c00895 "k") at string/lib_strcpy.c:64
#10 0x565e4eb2 in nxtask_setup_stackargs (tcb=0xf5c00810, argv=0x0) at task/task_setup.c:570
#11 0x565e50ff in nxtask_setup_arguments (tcb=0xf5c00810, name=0x5679e580 "hpwork", argv=0x0) at task/task_setup.c:714
#12 0x565e414e in nxthread_create (name=0x5679e580 "hpwork", ttype=2 '\002', priority=224, stack=0x0, stack_size=8192, entry=0x565e54e1 <work_hpthread>, argv=0x0) at task/task_create.c:143
#13 0x565e42e3 in kthread_create (name=0x5679e580 "hpwork", priority=224, stack_size=8192, entry=0x565e54e1 <work_hpthread>, argv=0x0) at task/task_create.c:297
#14 0x565e5557 in work_start_highpri () at wqueue/kwork_hpthread.c:149
#15 0x565e3e32 in nx_workqueues () at init/nx_bringup.c:181
#16 0x565e3ec7 in nx_bringup () at init/nx_bringup.c:436
#17 0x565e3d96 in nx_start () at init/nx_start.c:809
#18 0x565e3195 in main (argc=1, argv=0xffe6b954, envp=0xffe6b95c) at sim/up_head.c:95
Change-Id: I096f7952aae67d055daa737e967242eb217ef8ac
Signed-off-by: chao.an <anchao@xiaomi.com>
132 lines
4.9 KiB
C
132 lines
4.9 KiB
C
/****************************************************************************
|
|
* arch/xtensa/src/common/xtensa_stackframe.c
|
|
*
|
|
* Copyright (C) 2016 Gregory Nutt. All rights reserved.
|
|
* Author: Gregory Nutt <gnutt@nuttx.org>
|
|
*
|
|
* Redistribution and use in source and binary forms, with or without
|
|
* modification, are permitted provided that the following conditions
|
|
* are met:
|
|
*
|
|
* 1. Redistributions of source code must retain the above copyright
|
|
* notice, this list of conditions and the following disclaimer.
|
|
* 2. Redistributions in binary form must reproduce the above copyright
|
|
* notice, this list of conditions and the following disclaimer in
|
|
* the documentation and/or other materials provided with the
|
|
* distribution.
|
|
* 3. Neither the name NuttX nor the names of its contributors may be
|
|
* used to endorse or promote products derived from this software
|
|
* without specific prior written permission.
|
|
*
|
|
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
|
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
|
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
|
|
* FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
|
* COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
|
|
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
|
|
* BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
|
|
* OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
|
|
* AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
|
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN
|
|
* ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
|
* POSSIBILITY OF SUCH DAMAGE.
|
|
*
|
|
****************************************************************************/
|
|
|
|
/****************************************************************************
|
|
* Included Files
|
|
****************************************************************************/
|
|
|
|
#include <nuttx/config.h>
|
|
|
|
#include <sys/types.h>
|
|
#include <stdint.h>
|
|
#include <sched.h>
|
|
#include <debug.h>
|
|
|
|
#include <nuttx/arch.h>
|
|
|
|
#include "xtensa.h"
|
|
|
|
/****************************************************************************
|
|
* Pre-processor Macros
|
|
****************************************************************************/
|
|
|
|
/* XTENSA requires at least a 4-byte stack alignment. For floating point
|
|
* use, however, the stack must be aligned to 8-byte addresses.
|
|
*/
|
|
|
|
#ifdef CONFIG_LIBC_FLOATINGPOINT
|
|
# define STACK_ALIGNMENT 8
|
|
#else
|
|
# define STACK_ALIGNMENT 4
|
|
#endif
|
|
|
|
/* Stack alignment macros */
|
|
|
|
#define STACK_ALIGN_MASK (STACK_ALIGNMENT-1)
|
|
#define STACK_ALIGN_DOWN(a) ((a) & ~STACK_ALIGN_MASK)
|
|
#define STACK_ALIGN_UP(a) (((a) + STACK_ALIGN_MASK) & ~STACK_ALIGN_MASK)
|
|
|
|
/****************************************************************************
|
|
* Public Functions
|
|
****************************************************************************/
|
|
|
|
/****************************************************************************
|
|
* Name: up_stack_frame
|
|
*
|
|
* Description:
|
|
* Allocate a stack frame in the TCB's stack to hold thread-specific data.
|
|
* This function may be called anytime after up_create_stack() or
|
|
* up_use_stack() have been called but before the task has been started.
|
|
*
|
|
* Thread data may be kept in the stack (instead of in the TCB) if it is
|
|
* accessed by the user code directly. This includes such things as
|
|
* argv[]. The stack memory is guaranteed to be in the same protection
|
|
* domain as the thread.
|
|
*
|
|
* The following TCB fields will be re-initialized:
|
|
*
|
|
* - adj_stack_size: Stack size after removal of the stack frame from
|
|
* the stack
|
|
* - adj_stack_ptr: Adjusted initial stack pointer after the frame has
|
|
* been removed from the stack. This will still be the initial value
|
|
* of the stack pointer when the task is started.
|
|
*
|
|
* Input Parameters:
|
|
* - tcb: The TCB of new task
|
|
* - frame_size: The size of the stack frame to allocate.
|
|
*
|
|
* Returned Value:
|
|
* - A pointer to bottom of the allocated stack frame. NULL will be
|
|
* returned on any failures. The alignment of the returned value is
|
|
* the same as the alignment of the stack itself.
|
|
*
|
|
****************************************************************************/
|
|
|
|
FAR void *up_stack_frame(FAR struct tcb_s *tcb, size_t frame_size)
|
|
{
|
|
/* Align the frame_size */
|
|
|
|
frame_size = STACK_ALIGN_UP(frame_size);
|
|
|
|
/* Is there already a stack allocated? Is it big enough? */
|
|
|
|
if (!tcb->stack_alloc_ptr || tcb->adj_stack_size <= frame_size)
|
|
{
|
|
return NULL;
|
|
}
|
|
|
|
/* Save the adjusted stack values in the struct tcb_s */
|
|
|
|
tcb->adj_stack_ptr = (uint8_t *)tcb->adj_stack_ptr - frame_size;
|
|
tcb->adj_stack_size -= frame_size;
|
|
|
|
/* Reset the initial stack pointer (A1) */
|
|
|
|
tcb->xcp.regs[REG_A1] = (uint32_t)tcb->adj_stack_ptr;
|
|
|
|
/* And return the pointer to the allocated region */
|
|
|
|
return tcb->adj_stack_ptr;
|
|
}
|