royzah commented on code in PR #20409:
URL: https://github.com/apache/nuttx/pull/20409#discussion_r4145896809
##########
binfmt/binfmt_copyactions.c:
##########
@@ -64,24 +70,32 @@ int binfmt_copyactions(FAR const posix_spawn_file_actions_t
**copy,
FAR const posix_spawn_file_actions_t *actions)
{
FAR struct spawn_general_file_action_s *entry;
- FAR struct spawn_general_file_action_s *prev;
- FAR struct spawn_close_file_action_s *close;
+ FAR struct spawn_general_file_action_s *prev = NULL;
FAR struct spawn_open_file_action_s *open;
- FAR struct spawn_open_file_action_s *tmp;
- FAR struct spawn_dup2_file_action_s *dup2;
- FAR void *buffer;
- int size = 0;
-
+ FAR struct spawn_open_file_action_s *src;
+ enum spawn_file_actions_e action;
+ FAR char *buffer;
+ FAR char *end;
+ size_t size = 0;
+ size_t len;
+ int count = 0;
+ int i;
+
+ *copy = NULL;
if (actions == NULL)
{
- *copy = NULL;
return OK;
}
for (entry = (FAR struct spawn_general_file_action_s *)actions;
entry != NULL;
entry = entry->flink)
{
+ if (++count > MAX_FILE_ACTIONS)
Review Comment:
List lives in user memory, so a flink pointing back loops kernel walk
forever
256 is the same cap argv already has (MAX_EXEC_ARGS)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]