jerpelea opened a new pull request, #19634: URL: https://github.com/apache/nuttx/pull/19634
## Summary A crash was observed when running ps: a BusFault in nxtask_argvstr dereferencing tl_argv, because a thread's stack overflow had silently corrupted the TLS region where tl_argv resides. On ARMv8-M with CONFIG_ARMV8M_STACKCHECK_HARDWARE, PSPLIM was set to stack_alloc_ptr -- the bottom of the allocation where TLS begins. The stack grows downward and TLS occupies [stack_alloc_ptr, stack_alloc_ptr + tls_info_size()), so an overflow crossed into TLS and clobbered tl_argv before SP reached the limit, going undetected until code that read the corrupted TLS data (such as ps) hit the bad pointer. Set the limit to stack_alloc_ptr + tls_info_size() -- the top of the TLS region and the usable stack base -- so an overflow faults at the TLS boundary, before any TLS byte is touched. Include <tls/tls.h> for the tls_info_size() macro, which is the value sched reserves for the TLS region via up_stack_frame(). ## Impact RELEASE ## Testing CI -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
