mirror of
https://github.com/apache/nuttx.git
synced 2026-10-02 19:58:01 +00:00
aioc_decant() frees the AIO container and detaches the aiocbp. The I/O workers (aio_read_worker, aio_write_worker, aio_fsync_worker) called it before signaling completion, so aio_signal() and any code touching the container afterwards ran on freed memory. Additionally, if the caller closed the file early the detached container could be reused with a stale file reference. Move aioc_decant() to after aio_signal() and use aioc->aioc_aiocbp directly in the workers. aio_cancel() also had two problems: with no aiocbp it looped over g_aio_pending with a do/while that skipped the list re-entry check, so a failed work_cancel() on an already running I/O caused an endless loop; and an invalid fildes only checked 'fildes < 0' instead of validating the descriptor, so a closed fd was not reported as EBADF. Use a for-loop that always advances and validate the descriptor with file_get()/file_put(). Co-developed-by: wushenhui <wushenhui@xiaomi.com> Signed-off-by: wushenhui <wushenhui@xiaomi.com> Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com> |
||
|---|---|---|
| .. | ||
| aio.h | ||
| aio_cancel.c | ||
| aio_fsync.c | ||
| aio_initialize.c | ||
| aio_queue.c | ||
| aio_read.c | ||
| aio_signal.c | ||
| aio_write.c | ||
| aioc_contain.c | ||
| CMakeLists.txt | ||
| Kconfig | ||
| lio_listio.c | ||
| Make.defs | ||