Apache NuttX is a mature, real-time embedded operating system (RTOS) https://nuttx.apache.org/
Find a file
Junbo Zheng ef37425f71 sched: fix 1-byte overflow in prctl(PR_GET_NAME)
strlcpy() was given sizeof(tcb->name), i.e. CONFIG_TASK_NAME_SIZE + 1,
but the documented caller contract is a buffer of CONFIG_TASK_NAME_SIZE
bytes (include/sys/prctl.h). When a task name is exactly
CONFIG_TASK_NAME_SIZE chars (the normal result of nxtask_setup_name()
truncation), the terminating NUL lands one byte past the caller buffer.
Pass CONFIG_TASK_NAME_SIZE to strlcpy() so the copy is truncated
in-bounds, and drop the stale forced-NUL line left over from the strncpy
era (it ran after the overflow had already happened).

Before:
```
guard byte placed right after a CONFIG_TASK_NAME_SIZE caller buffer
reads 0x00 (expected 0xAA) after the call: strlcpy writes its
terminating NUL one byte past the buffer when the task name is exactly
CONFIG_TASK_NAME_SIZE chars.
```

After:
```
strlcpy(name, tcb->name, CONFIG_TASK_NAME_SIZE) writes at most
CONFIG_TASK_NAME_SIZE bytes; the caller buffer stays intact.
```

Testing:

Simulated (sim:nsh, CONFIG_TASK_NAME_SIZE=31).

Build and run:
```
cmake -B build -DBOARD_CONFIG=sim:nsh -GNinja
cmake --build build -j$(nproc)
echo hello | ./build/nuttx
```
then run "hello" at the NSH prompt.

The test was carried by apps/examples/hello/hello_main.c (scratch only,
not part of this commit); its diff:

```
--- a/examples/hello/hello_main.c
+++ b/examples/hello/hello_main.c
@@ -24,6 +24,8 @@

 #include <nuttx/config.h>
 #include <stdio.h>
+#include <string.h>
+#include <sys/prctl.h>

 /****************************************************************************
  * Public Functions
@@ -35,6 +37,55 @@

 int main(int argc, FAR char *argv[])
 {
+  /* Longest-legal task name: exactly CONFIG_TASK_NAME_SIZE chars, the
+   * normal result of nxtask_setup_name() truncation.
+   */
+
+  static const char longname[] =
+    "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
+
+  /* Caller buffer per the documented prctl(PR_GET_NAME) contract, with a
+   * guard byte immediately after it to detect the 1-byte overflow.
+   */
+
+  struct
+    {
+      char buf[CONFIG_TASK_NAME_SIZE];
+      volatile unsigned char guard;
+    } s;
+
+  _Static_assert(sizeof(longname) - 1 > CONFIG_TASK_NAME_SIZE,
+                 "test name must exceed CONFIG_TASK_NAME_SIZE");
+
   printf("Hello, World!!\n");
+  printf("prctl test: CONFIG_TASK_NAME_SIZE=%d\n", CONFIG_TASK_NAME_SIZE);
+
+  s.guard = 0xaa;
+  s.buf[0] = '\0';
+
+  if (prctl(PR_SET_NAME, (unsigned long)longname) != 0)
+    {
+      printf("prctl test: PR_SET_NAME failed\n");
+      return 1;
+    }
+
+  if (prctl(PR_GET_NAME, (unsigned long)s.buf) != 0)
+    {
+      printf("prctl test: PR_GET_NAME failed\n");
+      return 1;
+    }
+
+  printf("prctl test: guard=0x%02x (expected 0xaa), name len=%zu, "
+         "last char=0x%02x\n",
         s.guard, strlen(s.buf), (unsigned char)s.buf[strlen(s.buf)]);
+
+  if (s.guard != 0xaa)
+    {
+      printf("prctl test: FAIL - terminating NUL written 1 byte past "
+             "the caller buffer\n");
+      return 1;
+    }
+
+  printf("prctl test: PASS - caller buffer intact\n");
   return 0;
 }
```

Before the fix:
```
prctl test: guard=0x00 (expected 0xaa), name len=30, last char=0x00
prctl test: FAIL - terminating NUL written 1 byte past the caller buffer
```

After the fix:
```
prctl test: guard=0xaa (expected 0xaa), name len=30, last char=0x00
prctl test: PASS - caller buffer intact
```

Assisted-by: Claude Code (GLM-5.3) <claude@anthropic.com>
Signed-off-by: Junbo Zheng <zhengjunbo1@xiaomi.com>
2026-09-14 18:51:55 -03:00
.github .github/workflows/build.yml: bump NTFC to 0.0.3 2026-09-14 23:48:49 +08:00
arch arch/arm/stm32: Remove unneccessary ifdef 2026-09-14 18:49:00 -03:00
audio audio: limit the buffer count guard to shared ring requests 2026-08-05 07:58:53 +02:00
binfmt libs/libc/elf, binfmt: Describe the GOT by base and size, not by index. 2026-09-08 16:31:16 -03:00
boards boards/arm/stm32h5/nucleo-h563zi: Configure MPU 2026-09-14 18:49:00 -03:00
cmake cmake: fix undefined function name in parse args error messages 2026-09-11 21:15:22 +08:00
crypto tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
Documentation Documentation/am67: Document GPIO and SPI support on t3-gem-o1. 2026-09-14 18:45:44 -03:00
drivers drivers/sensors: fix nxstyle errors in sensor.c 2026-09-13 10:29:08 +08:00
dummy
fs fs/aio: raise the default AIO_LISTIO_MAX so LTP keeps passing 2026-09-14 17:12:49 -03:00
graphics graphics/nxterm: consume SGR escape sequences 2026-08-23 10:46:02 +08:00
include fs/aio: add configurable AIO_LISTIO_MAX limit 2026-09-14 17:12:49 -03:00
libs libc/aio: loop in aio_suspend() until a listed request completes 2026-09-14 17:12:49 -03:00
mm mm/pgalloc: support 32 KB and 64 KB page sizes 2026-09-10 23:28:43 +08:00
net net/tcp: add configurable delayed ACK threshold 2026-09-08 09:00:19 +08:00
openamp cmake: Use NUTTX(_DIR/_BIN_DIR) instead CMAKE(_SRC_DIR/_BIN_DIR) 2026-08-09 11:13:08 -03:00
pass1 tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
sched sched: fix 1-byte overflow in prctl(PR_GET_NAME) 2026-09-14 18:51:55 -03:00
syscall fs: rename PSEUDOFS_SOFTLINKS to FS_LINKS 2026-08-27 01:12:33 +08:00
tools Documentation, tools/ci: Say where the NXFLAT tools actually come from. 2026-09-13 18:29:40 -03:00
video video/videomode: Fix EDID parsing and formatting of video mode dumps 2026-08-29 11:09:11 -03:00
wireless wireless/bluetooth: fix inverted MTU cap in bt_conn_send() 2026-08-30 10:48:18 -03:00
.asf.yaml github: master branch protection tune. 2025-05-07 18:37:13 -05:00
.codespell-ignore-lines arch/arm: Reserve r10 via ARCHCFLAGS and hoist the PIC module flags. 2026-07-24 23:09:08 +08:00
.codespellrc Revert "zbus: Add linker support and documentation for the zbus port" 2026-08-30 10:45:19 -03:00
.editorconfig .editorconfig: fix character encoding property specification 2025-11-28 19:12:13 +08:00
.gitignore boards/risc-v/eic7700x: Adopt the common board layout. 2026-08-19 01:40:57 +08:00
.gitmessage docs/contributing: Add a commit message template 2025-06-03 17:33:24 +08:00
.pre-commit-config.yaml
.yamllint
AUTHORS AUTHORS: add Jorge Guzman 2026-08-25 08:43:13 -04:00
CMakeLists.txt cmake: reconfigure when .config changes 2026-09-14 18:40:45 -03:00
CONTRIBUTING.md contributing: Add requirement for 'Assisted-by' commit field 2026-07-12 09:42:28 +08:00
INVIOLABLES.md
Kconfig include/nuttx: Add link-time iterable sections infrastructure 2026-08-27 01:04:05 +08:00
LICENSE libs/libdsp: Add Matrix operations 2026-07-11 14:55:59 -03:00
Makefile !boards: enforce secure ROMFS passwd and TEA key setup 2026-07-09 22:41:11 +08:00
NOTICE
README.md ci/testing: Add MemBrowse Integration 2026-06-18 12:07:41 -03:00
ReleaseNotes

POSIX Badge License Issues Tracking Badge Contributors GitHub Build Badge Documentation Badge MemBrowse

Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).

For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.

Getting Started

First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.

Documentation

You can find the current NuttX documentation on the Documentation Page.

Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.

The old NuttX documentation is still available in the Apache wiki.

Supported Boards

NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.

Contributing

If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.

License

The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.