This is an automated email from the ASF dual-hosted git repository.

xiaoxiang781216 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/nuttx.git


The following commit(s) were added to refs/heads/master by this push:
     new f2739fe4f43 arch: bound syscall numbers and nesting in every build
f2739fe4f43 is described below

commit f2739fe4f430004c13046871688f666b32396b1e
Author: Royyan Zahir <[email protected]>
AuthorDate: Wed Sep 30 09:53:32 2026 +0400

    arch: bound syscall numbers and nesting in every build
    
    The table index and the nesting depth were checked by DEBUGASSERT only,
    and arm64 and risc-v let the first number past the table through.
    
    Signed-off-by: Royyan Zahir <[email protected]>
---
 arch/arm/src/armv6-m/arm_svcall.c     | 16 +++++++---------
 arch/arm/src/armv7-a/arm_syscall.c    | 16 +++++++---------
 arch/arm/src/armv7-m/arm_svcall.c     | 16 +++++++---------
 arch/arm/src/armv7-r/arm_syscall.c    | 16 +++++++---------
 arch/arm/src/armv8-m/arm_svcall.c     | 16 +++++++---------
 arch/arm/src/armv8-r/arm_syscall.c    | 16 +++++++---------
 arch/arm64/src/common/arm64_syscall.c |  2 +-
 arch/risc-v/src/common/riscv_swint.c  |  2 +-
 8 files changed, 44 insertions(+), 56 deletions(-)

diff --git a/arch/arm/src/armv6-m/arm_svcall.c 
b/arch/arm/src/armv6-m/arm_svcall.c
index b004d252018..2d6a4b12011 100644
--- a/arch/arm/src/armv6-m/arm_svcall.c
+++ b/arch/arm/src/armv6-m/arm_svcall.c
@@ -30,6 +30,7 @@
 #include <stdint.h>
 #include <string.h>
 #include <assert.h>
+#include <errno.h>
 #include <nuttx/debug.h>
 #include <syscall.h>
 
@@ -311,15 +312,12 @@ int arm_svcall(int irq, void *context, void *arg)
           struct tcb_s *rtcb = this_task();
           int index = rtcb->xcp.nsyscalls;
 
-          /* Verify that the SYS call number is within range */
-
-          DEBUGASSERT(cmd >= CONFIG_SYS_RESERVED && cmd < SYS_maxsyscall);
-
-          /* Make sure that there is a no saved syscall return address.  We
-           * cannot yet handle nested system calls.
-           */
-
-          DEBUGASSERT(index < CONFIG_SYS_NNEST);
+          if (cmd < CONFIG_SYS_RESERVED || cmd >= SYS_maxsyscall ||
+              index >= CONFIG_SYS_NNEST)
+            {
+              regs[REG_R0] = -ENOSYS;
+              break;
+            }
 
           /* Use ip to create a debug frame.
            * we can use gdb backtrace from syscall to user space.
diff --git a/arch/arm/src/armv7-a/arm_syscall.c 
b/arch/arm/src/armv7-a/arm_syscall.c
index bcc9c187be5..09b7f133fd0 100644
--- a/arch/arm/src/armv7-a/arm_syscall.c
+++ b/arch/arm/src/armv7-a/arm_syscall.c
@@ -30,6 +30,7 @@
 #include <stdint.h>
 #include <string.h>
 #include <assert.h>
+#include <errno.h>
 #include <nuttx/debug.h>
 #include <syscall.h>
 
@@ -496,15 +497,12 @@ uint32_t *arm_syscall(uint32_t *regs)
           struct tcb_s *rtcb = this_task();
           int index = rtcb->xcp.nsyscalls;
 
-          /* Verify that the SYS call number is within range */
-
-          DEBUGASSERT(cmd >= CONFIG_SYS_RESERVED && cmd < SYS_maxsyscall);
-
-          /* Make sure that there is a no saved SYSCALL return address.  We
-           * cannot yet handle nested system calls.
-           */
-
-          DEBUGASSERT(index < CONFIG_SYS_NNEST);
+          if (cmd < CONFIG_SYS_RESERVED || cmd >= SYS_maxsyscall ||
+              index >= CONFIG_SYS_NNEST)
+            {
+              regs[REG_R0] = -ENOSYS;
+              break;
+            }
 
           /* Setup to return to dispatch_syscall in privileged mode. */
 
diff --git a/arch/arm/src/armv7-m/arm_svcall.c 
b/arch/arm/src/armv7-m/arm_svcall.c
index 956f1b95b52..ac1ff9deb50 100644
--- a/arch/arm/src/armv7-m/arm_svcall.c
+++ b/arch/arm/src/armv7-m/arm_svcall.c
@@ -30,6 +30,7 @@
 #include <stdint.h>
 #include <string.h>
 #include <assert.h>
+#include <errno.h>
 #include <nuttx/debug.h>
 #include <syscall.h>
 
@@ -313,15 +314,12 @@ int arm_svcall(int irq, void *context, void *arg)
           struct tcb_s *rtcb = this_task();
           int index = rtcb->xcp.nsyscalls;
 
-          /* Verify that the SYS call number is within range */
-
-          DEBUGASSERT(cmd >= CONFIG_SYS_RESERVED && cmd < SYS_maxsyscall);
-
-          /* Make sure that there is a no saved syscall return address.  We
-           * cannot yet handle nested system calls.
-           */
-
-          DEBUGASSERT(index < CONFIG_SYS_NNEST);
+          if (cmd < CONFIG_SYS_RESERVED || cmd >= SYS_maxsyscall ||
+              index >= CONFIG_SYS_NNEST)
+            {
+              regs[REG_R0] = -ENOSYS;
+              break;
+            }
 
           /* Use ip to create a debug frame.
            * we can use gdb backtrace from syscall to user space.
diff --git a/arch/arm/src/armv7-r/arm_syscall.c 
b/arch/arm/src/armv7-r/arm_syscall.c
index a7ac4db2386..cf2563b6ee1 100644
--- a/arch/arm/src/armv7-r/arm_syscall.c
+++ b/arch/arm/src/armv7-r/arm_syscall.c
@@ -29,6 +29,7 @@
 #include <stdint.h>
 #include <string.h>
 #include <assert.h>
+#include <errno.h>
 #include <nuttx/debug.h>
 #include <syscall.h>
 
@@ -485,15 +486,12 @@ uint32_t *arm_syscall(uint32_t *regs)
           struct tcb_s *rtcb = this_task();
           int index = rtcb->xcp.nsyscalls;
 
-          /* Verify that the SYS call number is within range */
-
-          DEBUGASSERT(cmd >= CONFIG_SYS_RESERVED && cmd < SYS_maxsyscall);
-
-          /* Make sure that there is a no saved SYSCALL return address.  We
-           * cannot yet handle nested system calls.
-           */
-
-          DEBUGASSERT(index < CONFIG_SYS_NNEST);
+          if (cmd < CONFIG_SYS_RESERVED || cmd >= SYS_maxsyscall ||
+              index >= CONFIG_SYS_NNEST)
+            {
+              regs[REG_R0] = -ENOSYS;
+              break;
+            }
 
           /* Setup to return to dispatch_syscall in privileged mode. */
 
diff --git a/arch/arm/src/armv8-m/arm_svcall.c 
b/arch/arm/src/armv8-m/arm_svcall.c
index 03ab17d0ce3..5e7a9276126 100644
--- a/arch/arm/src/armv8-m/arm_svcall.c
+++ b/arch/arm/src/armv8-m/arm_svcall.c
@@ -30,6 +30,7 @@
 #include <stdint.h>
 #include <string.h>
 #include <assert.h>
+#include <errno.h>
 #include <nuttx/debug.h>
 #include <syscall.h>
 
@@ -313,15 +314,12 @@ int arm_svcall(int irq, void *context, void *arg)
           struct tcb_s *rtcb = this_task();
           int index = rtcb->xcp.nsyscalls;
 
-          /* Verify that the SYS call number is within range */
-
-          DEBUGASSERT(cmd >= CONFIG_SYS_RESERVED && cmd < SYS_maxsyscall);
-
-          /* Make sure that there is a no saved syscall return address.  We
-           * cannot yet handle nested system calls.
-           */
-
-          DEBUGASSERT(index < CONFIG_SYS_NNEST);
+          if (cmd < CONFIG_SYS_RESERVED || cmd >= SYS_maxsyscall ||
+              index >= CONFIG_SYS_NNEST)
+            {
+              regs[REG_R0] = -ENOSYS;
+              break;
+            }
 
           /* Use ip to create a debug frame.
            * we can use gdb backtrace from syscall to user space.
diff --git a/arch/arm/src/armv8-r/arm_syscall.c 
b/arch/arm/src/armv8-r/arm_syscall.c
index e9b54c382b7..98536a217e3 100644
--- a/arch/arm/src/armv8-r/arm_syscall.c
+++ b/arch/arm/src/armv8-r/arm_syscall.c
@@ -29,6 +29,7 @@
 #include <stdint.h>
 #include <string.h>
 #include <assert.h>
+#include <errno.h>
 #include <nuttx/debug.h>
 #include <syscall.h>
 
@@ -490,15 +491,12 @@ uint32_t *arm_syscall(uint32_t *regs)
           struct tcb_s *rtcb = this_task();
           int index = rtcb->xcp.nsyscalls;
 
-          /* Verify that the SYS call number is within range */
-
-          DEBUGASSERT(cmd >= CONFIG_SYS_RESERVED && cmd < SYS_maxsyscall);
-
-          /* Make sure that there is a no saved SYSCALL return address.  We
-           * cannot yet handle nested system calls.
-           */
-
-          DEBUGASSERT(index < CONFIG_SYS_NNEST);
+          if (cmd < CONFIG_SYS_RESERVED || cmd >= SYS_maxsyscall ||
+              index >= CONFIG_SYS_NNEST)
+            {
+              regs[REG_R0] = -ENOSYS;
+              break;
+            }
 
           /* Setup to return to dispatch_syscall in privileged mode. */
 
diff --git a/arch/arm64/src/common/arm64_syscall.c 
b/arch/arm64/src/common/arm64_syscall.c
index 8e9bc569986..e8a34cf505b 100644
--- a/arch/arm64/src/common/arm64_syscall.c
+++ b/arch/arm64/src/common/arm64_syscall.c
@@ -110,7 +110,7 @@ uintptr_t dispatch_syscall(unsigned int nbr, uintptr_t 
parm1,
 
   /* Valid system call ? */
 
-  if (x0 > SYS_maxsyscall)
+  if (x0 >= SYS_maxsyscall)
     {
       /* Nope, get out */
 
diff --git a/arch/risc-v/src/common/riscv_swint.c 
b/arch/risc-v/src/common/riscv_swint.c
index b5dc855484f..0301d19d77b 100644
--- a/arch/risc-v/src/common/riscv_swint.c
+++ b/arch/risc-v/src/common/riscv_swint.c
@@ -98,7 +98,7 @@ uintptr_t dispatch_syscall(unsigned int nbr, uintptr_t parm1,
 
   /* Valid system call ? */
 
-  if (a0 > SYS_maxsyscall)
+  if (a0 >= SYS_maxsyscall)
     {
       /* Nope, get out */
 

Reply via email to