royzah opened a new pull request, #20415: URL: https://github.com/apache/nuttx/pull/20415
Depends on #20412; its commits are included until it merges. ## Why In a kernel build a `sem_t` in user memory holds the kernel's wait queue and holder list. A process can rewrite them and steer the kernel's list operations, and a timeout firing in another process writes through the first process's mappings. ## How | Change | Does | | --- | --- | | `sem_shadow.c` | a semaphore in user memory gets a kernel shadow, keyed by its physical address and reference counted; wait, post, trywait, reset, destroy and protocol act on the shadow | | user copy | mirrors value, flags, ceiling and maximum after every operation | | libc | fast paths skip a shadowed semaphore; `sem_init()` drops a stale shadow | | `mm_pgfree()` | frees the shadows living in the freed pages | | syscalls | reading the value and setting protocol, ceiling or maximum go to the kernel in protected and kernel builds; libc links ahead of the proxies, so they used the user copy, stale while a waiter blocks | Flat builds are unchanged. ## Tested | Where | Result | | --- | --- | | `qemu-armv8a:knsh` | `ostest` passes, semaphore test included; `hello` | | `rv-virt:knsh64` | `hello`; `ostest` log identical to master's | | i.MX93, PX4 kernel build | every semaphore through the shadow; flight stack and secure link up | Before the value fix, `ostest`'s semaphore test hung polling `sem_getvalue()` for -2. `tools/checkpatch.sh` clean. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
