This is an automated email from the ASF dual-hosted git repository.
xiaoxiang781216 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/nuttx.git
The following commit(s) were added to refs/heads/master by this push:
new 9f73ff7e773 arch/arm64: bound pgalloc() to the user heap
9f73ff7e773 is described below
commit 9f73ff7e773347f88eccfc6882f0017392171137
Author: Royyan Zahir <[email protected]>
AuthorDate: Wed Sep 30 09:53:32 2026 +0400
arch/arm64: bound pgalloc() to the user heap
pgalloc() is a syscall in a kernel build. Its start was checked by
DEBUGASSERT only and its end not at all, so a user task could map pages
past ARCH_ADDRENV_VEND.
Signed-off-by: Royyan Zahir <[email protected]>
---
arch/arm64/src/common/arm64_pgalloc.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/src/common/arm64_pgalloc.c
b/arch/arm64/src/common/arm64_pgalloc.c
index 42f35f13a2e..8dcc12f69a4 100644
--- a/arch/arm64/src/common/arm64_pgalloc.c
+++ b/arch/arm64/src/common/arm64_pgalloc.c
@@ -121,10 +121,11 @@ uintptr_t pgalloc(uintptr_t brkaddr, unsigned int npages)
vaddr = brkaddr;
ptlevel = MMU_PGT_LEVEL_MAX;
- /* Sanity checks */
-
- DEBUGASSERT(brkaddr >= addrenv->heapvbase);
- DEBUGASSERT(MM_ISALIGNED(brkaddr));
+ if (brkaddr < addrenv->heapvbase || !MM_ISALIGNED(brkaddr) ||
+ npages > (ARCH_ADDRENV_VEND - brkaddr + 1) / MM_PGSIZE)
+ {
+ return 0;
+ }
for (; npages > 0; npages--)
{