<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<html lang="en" style="--code-editor-font: var(--default-mono-font, "GitLab Mono"), JetBrains Mono, Menlo, DejaVu Sans Mono, Liberation Mono, Consolas, Ubuntu Mono, Courier New, andale mono, lucida console, monospace;">
<head>
<meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
<title>
GitLab
</title>

<style data-premailer="ignore" type="text/css">
a { color: #1068bf; }
</style>

<style>img {
max-width: 100%; height: auto;
}
body {
font-size: .875rem;
}
body {
-webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px;
}
body {
font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji"; font-size: inherit;
}
</style>
</head>
<body style="font-size: inherit; -webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px; font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji";">
<div class="content">

<p class="details" style="font-style: italic; color: #626168;">
<a href="https://gitlab.rtems.org/TheSamPrice">Sam Price</a> created a merge request: <a href="https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1442">!1442</a>
</p>
<div class="branch">
Project:Branches: TheSamPrice/rtems:rfs/reject-zero-max-held-bufs to rtems/rtos/rtems:main
</div>
<div class="author">
Author: Sam Price
</div>
<div class="assignee">
Assignees: 
</div>
<div class="reviewer">
Reviewers: 
</div>
<div class="md gl-mt-5" style="position: relative; z-index: 1; color: #3a383f; word-wrap: break-word; margin-top: 1rem;">
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">Mounting RFS with max-held-bufs=0 dereferences a NULL pointer on the
first buffer release.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">rtems_rfs_buffer_handle_release evicts a held buffer when</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">(fs->release_count + fs->release_modified_count) >= fs->max_held_buffers</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">taking it from fs->release when release_count is the larger and from
fs->release_modified otherwise, then doing buffer->user = (void*)0 at
rtems-rfs-buffer.c:274 with no NULL test.  rtems_chain_get_unprotected
returns NULL for an empty chain by design.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">For max_held_buffers >= 1 the guard implies at least one count is
non-zero and the branch selects the queue holding it, so the result is
never NULL.  At zero the guard is 0 >= 0, true on the first release with
both queues still empty; 0 > 0 is false so the else branch runs;
fs->release_modified_count-- underflows from 0 to UINT32_MAX; and the
NULL reaches :274.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">The value is a mount option and nothing range checked it: the parser used
strtoul straight into the local and rtems_rfs_fs_open assigned it
unchecked.  Zero held buffers is not a meaningful configuration, so
reject it where it is parsed.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">GCC's -fanalyzer reports the dereference at rtems-rfs-buffer.c:274.
Testing the chain result there is worth doing regardless, but on its own
it converts the dereference into a silently skipped eviction and leaves
the counter underflow, so the option is validated instead.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">The failure was easy to misread.  Before this change the mount does fail,
with EIO, which looks like the option being rejected.  It is not: EIO is
what rtems_rfs_buffer_bdbuf_release returns after rtems_bdbuf_release is
handed the NULL, so it is the defect reported downstream of
buffer->user = (void*)0 having already run on a NULL pointer.  It did not
fault only because address zero is mapped on the test target.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">fsrfsmaxheld01 is added with the fix.  It mounts with no options, with
max-held-bufs=5 and with max-held-bufs=1, all of which must succeed, then
with max-held-bufs=0 and requires EINVAL.  The controls matter: at one the
first release sees 0 >= 1 and evicts nothing, which puts the boundary
exactly where the arithmetic says it is.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">Measured on riscv/mbv: EIO before, EINVAL after, test passing.</p>
<p dir="auto" style="color: #3a383f; margin: 0px;" align="initial">Co-Authored-By: Claude Opus 5 (1M context) <a href="mailto:noreply@anthropic.com" style="margin-top: 0px;">noreply@anthropic.com</a>
Signed-off-by: Samuel Price <a href="mailto:thesamprice@gmail.com">thesamprice@gmail.com</a></p>
</div>

</div>
<div class="footer" style="margin-top: 10px;">
<p style="font-size: small; color: #626168;">

<br>
<a href="https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1442">View it on GitLab</a>.
<br>
You're receiving this email because of your account on <a target="_blank" rel="noopener noreferrer" href="https://gitlab.rtems.org">gitlab.rtems.org</a>. <a href="https://gitlab.rtems.org/-/sent_notifications/5-b4e6j0u1cfuvfaslhxaxg41ni-1d/unsubscribe" target="_blank" rel="noopener noreferrer">Unsubscribe</a> from this thread · <a href="https://gitlab.rtems.org/-/profile/notifications" target="_blank" rel="noopener noreferrer" class="mng-notif-link">Manage all notifications</a> · <a href="https://gitlab.rtems.org/help" target="_blank" rel="noopener noreferrer" class="help-link">Help</a>
<span style="color: transparent; font-size: 0; display: none; overflow: hidden; opacity: 0; width: 0; height: 0; max-width: 0; max-height: 0;">
Notification message regarding https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1442 at 1787275827
</span>
<script type="application/ld+json">{"@context":"http://schema.org","@type":"EmailMessage","action":{"@type":"ViewAction","name":"View Merge request","url":"https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1442"}}</script>


</p>
</div>
</body>
</html>