nuttx/fs/inode
AlmAck 20752312ea fs/inode: bound fdlist_extend() against the requested row
fdlist_extend() grows a task group's descriptor table to 'row' rows of
CONFIG_NFILE_DESCRIPTORS_PER_BLOCK entries each, and guards the growth
against OPEN_MAX:

  if (CONFIG_NFILE_DESCRIPTORS_PER_BLOCK * (orig_rows + 1) > OPEN_MAX)

The check sizes the table at orig_rows + 1, which assumes the caller
only ever grows by a single block.  The function then allocates 'row'
rows, so the two agree only for growth by one.

Callers do skip ahead.  fdlist_dup3() asks for
fd2 / CONFIG_NFILE_DESCRIPTORS_PER_BLOCK + 1, fdlist_dupfile() for the
row holding minfd, and fdlist_copy() for the row holding a parent
descriptor it is duplicating.  Any of those can request a row well past
orig_rows + 1.

Such a request passes the check and the function then allocates and
installs a table with more than OPEN_MAX descriptors.  With the defaults
(8 per block, OPEN_MAX 256) a process holding one row that calls
dup2(fd, 400) ends up with 51 rows, or 408 descriptor slots, against a
256 limit.

Check the row actually being requested.  For single-block growth
row == orig_rows + 1 and the comparison is unchanged.

Signed-off-by: AlmAck <gluca86@gmail.com>
2026-09-17 13:50:27 +08:00
..
CMakeLists.txt fs: migrate to SPDX identifier 2024-11-06 01:58:54 +08:00
fs_files.c fs/inode: bound fdlist_extend() against the requested row 2026-09-17 13:50:27 +08:00
fs_foreachinode.c fs: migrate to SPDX identifier 2024-11-06 01:58:54 +08:00
fs_inode.c sched: add supplementary group IDs (setgroups/getgroups/initgroups) 2026-08-12 16:06:03 -03:00
fs_inodeaddref.c nuttx/atomic: replace atomic_fetch_xxx with atomic_xxx just like zephyr 2026-08-24 13:20:45 +08:00
fs_inodebasename.c fs: migrate to SPDX identifier 2024-11-06 01:58:54 +08:00
fs_inodefind.c nuttx/atomic: replace atomic_fetch_xxx with atomic_xxx just like zephyr 2026-08-24 13:20:45 +08:00
fs_inodefree.c fs: rename PSEUDOFS_SOFTLINKS to FS_LINKS 2026-08-27 01:12:33 +08:00
fs_inodegetpath.c fs: migrate to SPDX identifier 2024-11-06 01:58:54 +08:00
fs_inoderelease.c nuttx/atomic: replace atomic_fetch_xxx with atomic_xxx just like zephyr 2026-08-24 13:20:45 +08:00
fs_inoderemove.c fs: rename PSEUDOFS_SOFTLINKS to FS_LINKS 2026-08-27 01:12:33 +08:00
fs_inodereserve.c fs/inode: propagate inode search errors 2026-09-04 13:50:54 -03:00
fs_inodesearch.c fs/inode: fix relative-path truncation causing wrong EISDIR 2026-08-28 23:07:24 +08:00
inode.h fs/inode: change fs_heap to lib_get_tempbuffer/lib_put_tempbuffer 2026-08-28 12:09:46 +08:00
Make.defs fs: migrate to SPDX identifier 2024-11-06 01:58:54 +08:00