jerpelea opened a new pull request, #19634:
URL: https://github.com/apache/nuttx/pull/19634

   ## Summary
   
   A crash was observed when running ps: a BusFault in nxtask_argvstr 
dereferencing tl_argv, because a thread's stack overflow had silently corrupted 
the TLS region where tl_argv resides.
   
   On ARMv8-M with CONFIG_ARMV8M_STACKCHECK_HARDWARE, PSPLIM was set to 
stack_alloc_ptr -- the bottom of the allocation where TLS begins. The stack 
grows downward and TLS occupies [stack_alloc_ptr, stack_alloc_ptr
   + tls_info_size()), so an overflow crossed into TLS and clobbered tl_argv 
before SP reached the limit, going undetected until code that read the 
corrupted TLS data (such as ps) hit the bad pointer.
   
   Set the limit to stack_alloc_ptr + tls_info_size() -- the top of the TLS 
region and the usable stack base -- so an overflow faults at the TLS boundary, 
before any TLS byte is touched. Include <tls/tls.h> for the tls_info_size() 
macro, which is the value sched reserves for the TLS region via 
up_stack_frame().
   
   ## Impact
   
   RELEASE
   
   ## Testing
   
   CI


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to