mirror of
https://github.com/apache/nuttx.git
synced 2026-10-10 07:40:27 +00:00
Every BATIOC_* case in the gauge upper half calls dev->ops->X() after checking only that the *argument* pointer is non-NULL. The operations themselves are optional -- max1704x.c implements four of the eight, and the in-tree fake gauge leaves chipid and operate NULL -- so asking a gauge for something it does not provide calls through a NULL pointer. On ARM that is not a null dereference but a branch to address 0, which has the Thumb bit clear: the core takes a usage fault with CFSR bit 17, INVSTATE, escalated to a hard fault. From userspace it looks like the program stopped mid-run for no reason, and on a board whose assert path delays before resetting it looks like a hang. Guard all eight. A missing method is now ENOTTY, which is what the default case already returns for an unrecognised command and what a caller can sensibly probe for. Tested on sim:nsh with the fake gauge and a local test app. Before the change, ioctl(BATIOC_CHIPID) kills the simulator with SIGSEGV. After the change, BATIOC_CHIPID and BATIOC_OPERATE return ENOTTY and BATIOC_VOLTAGE still returns the voltage. nucleo-f412zg:nsh with BATTERY_GAUGE, MAX1704X, BQ27426 and BATTERY_FAKE_GAUGE builds. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com> |
||
|---|---|---|
| .. | ||
| battery | ||
| pm | ||
| relay | ||
| supply | ||
| CMakeLists.txt | ||
| Kconfig | ||
| Make.defs | ||