royzah commented on code in PR #20424:
URL: https://github.com/apache/nuttx/pull/20424#discussion_r4154609659
##########
sched/signal/sig_notification.c:
##########
@@ -147,10 +147,23 @@ int nxsig_notification(pid_t pid, FAR struct sigevent
*event,
memcpy(&info.si_value, &event->sigev_value, sizeof(union sigval));
- /* SIGEV_THREAD_ID currently used only by POSIX timer. */
+ if (!GOOD_SIGNO(event->sigev_signo))
Review Comment:
gpio, button and phy_notify store user sigevents unchecked, so this is the
one spot every path goes thru. timer_create checks too, so the caller gets
EINVAL, not a DEBUGVERIFY at expiry.
##########
sched/signal/sig_notification.c:
##########
@@ -147,10 +147,23 @@ int nxsig_notification(pid_t pid, FAR struct sigevent
*event,
memcpy(&info.si_value, &event->sigev_value, sizeof(union sigval));
- /* SIGEV_THREAD_ID currently used only by POSIX timer. */
+ if (!GOOD_SIGNO(event->sigev_signo))
+ {
+ return -EINVAL;
+ }
if (event->sigev_notify & SIGEV_THREAD_ID)
{
+ FAR struct tcb_s *owner = nxsched_get_tcb(pid);
+ FAR struct tcb_s *target =
+ nxsched_get_tcb(event->sigev_notify_thread_id);
Review Comment:
Same, those drivers take SIGEV_THREAD_ID from user space unchecked.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]