<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<html lang="en" style="--code-editor-font: var(--default-mono-font, "GitLab Mono"), JetBrains Mono, Menlo, DejaVu Sans Mono, Liberation Mono, Consolas, Ubuntu Mono, Courier New, andale mono, lucida console, monospace;">
<head>
<meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
<title>
GitLab
</title>
<style data-premailer="ignore" type="text/css">
a { color: #1068bf; }
</style>
<style>img {
max-width: 100%; height: auto;
}
body {
font-size: .875rem;
}
body {
-webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px;
}
body {
font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji"; font-size: inherit;
}
</style>
</head>
<body style="font-size: inherit; -webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px; font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji";">
<div class="content">
<p class="details" style="font-style: italic; color: #626168;">
<a href="https://gitlab.rtems.org/TheSamPrice">Sam Price</a> created a merge request: <a href="https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1441">!1441</a>
</p>
<div class="branch">
Project:Branches: TheSamPrice/rtems:test/psxrealpath01 to rtems/rtos/rtems:main
</div>
<div class="author">
Author: Sam Price
</div>
<div class="assignee">
Assignees:
</div>
<div class="reviewer">
Reviewers:
</div>
<div class="md gl-mt-5" style="position: relative; z-index: 1; color: #3a383f; word-wrap: break-word; margin-top: 1rem;">
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">realpath() has no behavioural test; psxhdrs only checks that it compiles.
This adds one, covering two defects in the vendored
cpukit/libcsupport/src/contrib/realpath.c, which is a FreeBSD 9.1.0
snapshot from 2012-09-18 per the __FBSDID string it still carries.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">Both are fixed in current FreeBSD and neither fix has been picked up:</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">slen = readlink(resolved, symlink, sizeof(symlink));
if (slen == 0) { errno = ENOENT; return (NULL); }
if ((size_t)slen >= sizeof(symlink)) { errno = ENAMETOOLONG; return (NULL); }</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">Empty target. readlink returns the byte count it wrote, so an empty
symlink target gives slen == 0 and the test at realpath.c:227,
symlink[slen - 1], reads one byte before a PATH_MAX stack buffer.
Nothing rejects an empty target on the way in: symlink() passes path1
through untouched, IMFS_symlink allocates strlen(target) + 1 without
inspecting it, and IMFS_readlink returns the count it copied.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">Over-long target. RTEMS reads with sizeof(symlink) - 1, so a longer
target is silently truncated and then resolved as if it were what the
link said. RTEMS does have two ENAMETOOLONG checks, but both are inside
the if (p != NULL) block, so neither fires when the link is the last
component.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">Measured on riscv/mbv, where PATH_MAX is 255:</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">symlink("", "/emptylink") = 0, readlink = 0
realpath("/emptylink/x") = NULL, errno 2
symlink(<271 byte target>, "/longlink") = 0
realpath("/longlink") = NULL, errno 2, where upstream gives ENAMETOOLONG</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">The ENOENT in the second case is the evidence: the target was truncated
to 254 bytes and the truncated path was resolved.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">The test asserts the preconditions and the absence of a silent success,
and reports the rest. With slen == 0 the branch taken depends on the
byte at symlink[-1], which is whatever the adjacent stack holds, so
asserting an expected string would be asserting on undefined behaviour
rather than testing it. It passes as it stands, and keeps passing once
the file is re-imported.</p>
<p dir="auto" style="color: #3a383f; margin: 0px;" align="initial">Co-Authored-By: Claude Opus 5 (1M context) <a href="mailto:noreply@anthropic.com" style="margin-top: 0px;">noreply@anthropic.com</a>
Signed-off-by: Samuel Price <a href="mailto:thesamprice@gmail.com">thesamprice@gmail.com</a></p>
</div>
</div>
<div class="footer" style="margin-top: 10px;">
<p style="font-size: small; color: #626168;">
—
<br>
<a href="https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1441">View it on GitLab</a>.
<br>
You're receiving this email because of your account on <a target="_blank" rel="noopener noreferrer" href="https://gitlab.rtems.org">gitlab.rtems.org</a>. <a href="https://gitlab.rtems.org/-/sent_notifications/5-bdgw5y24z0sjo3cfh5mrde59z-1d/unsubscribe" target="_blank" rel="noopener noreferrer">Unsubscribe</a> from this thread · <a href="https://gitlab.rtems.org/-/profile/notifications" target="_blank" rel="noopener noreferrer" class="mng-notif-link">Manage all notifications</a> · <a href="https://gitlab.rtems.org/help" target="_blank" rel="noopener noreferrer" class="help-link">Help</a>
<span style="color: transparent; font-size: 0; display: none; overflow: hidden; opacity: 0; width: 0; height: 0; max-width: 0; max-height: 0;">
Notification message regarding https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1441 at 1787275826
</span>
<script type="application/ld+json">{"@context":"http://schema.org","@type":"EmailMessage","action":{"@type":"ViewAction","name":"View Merge request","url":"https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1441"}}</script>
</p>
</div>
</body>
</html>