royzah opened a new pull request, #20415:
URL: https://github.com/apache/nuttx/pull/20415

   Depends on #20412; its commits are included until it merges.
   
   ## Why
   
   In a kernel build a `sem_t` in user memory holds the kernel's wait queue and 
holder list. A process can rewrite them and steer the kernel's list operations, 
and a timeout firing in another process writes through the first process's 
mappings.
   
   ## How
   
   | Change | Does |
   | --- | --- |
   | `sem_shadow.c` | a semaphore in user memory gets a kernel shadow, keyed by 
its physical address and reference counted; wait, post, trywait, reset, destroy 
and protocol act on the shadow |
   | user copy | mirrors value, flags, ceiling and maximum after every 
operation |
   | libc | fast paths skip a shadowed semaphore; `sem_init()` drops a stale 
shadow |
   | `mm_pgfree()` | frees the shadows living in the freed pages |
   | syscalls | reading the value and setting protocol, ceiling or maximum go 
to the kernel in protected and kernel builds; libc links ahead of the proxies, 
so they used the user copy, stale while a waiter blocks |
   
   Flat builds are unchanged.
   
   ## Tested
   
   | Where | Result |
   | --- | --- |
   | `qemu-armv8a:knsh` | `ostest` passes, semaphore test included; `hello` |
   | `rv-virt:knsh64` | `hello`; `ostest` log identical to master's |
   | i.MX93, PX4 kernel build | every semaphore through the shadow; flight 
stack and secure link up |
   
   Before the value fix, `ostest`'s semaphore test hung polling 
`sem_getvalue()` for -2.
   
   `tools/checkpatch.sh` clean.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to