xiaoxiang781216 commented on code in PR #20409:
URL: https://github.com/apache/nuttx/pull/20409#discussion_r4157662308


##########
binfmt/binfmt_copyactions.c:
##########
@@ -103,72 +117,75 @@ int binfmt_copyactions(FAR const 
posix_spawn_file_actions_t **copy,
         }
     }
 
-  *copy = buffer = kmm_malloc(size);
+  buffer = kmm_malloc(size);
   if (buffer == NULL)
     {
       return -ENOMEM;
     }
 
-  /* We need to copy and re-organize the flink chain,  be care not modify
-   * the actions it self,  the prev have to point to the last time foreach
-   * item.
-   */
+  *copy = (FAR const posix_spawn_file_actions_t *)buffer;
+  end   = buffer + size;
+  entry = (FAR struct spawn_general_file_action_s *)actions;
 
-  for (entry = (FAR struct spawn_general_file_action_s *)actions,
-       prev = NULL; entry != NULL; entry = entry->flink)
+  for (i = 0; i < count; i++, entry = entry->flink)
     {
-      switch (entry->action)
+      if (entry == NULL)
+        {
+          goto errout;
+        }
+
+      action = entry->action;
+      switch (action)
         {
           case SPAWN_FILE_ACTION_CLOSE:
-            close = buffer;
-            memcpy(close, entry, sizeof(struct spawn_close_file_action_s));
-            close->flink = NULL;
-            if (prev)
-              {
-                prev->flink = (FAR void *)close;
-              }
-
-            prev   = (FAR void *)close;
-            buffer = close + 1;
+            len = sizeof(struct spawn_close_file_action_s);
             break;
 
           case SPAWN_FILE_ACTION_DUP2:
-            dup2 = buffer;
-            memcpy(dup2, entry, sizeof(struct spawn_dup2_file_action_s));
-            dup2->flink = NULL;
-            if (prev)
-              {
-                prev->flink = (FAR void *)dup2;
-              }
-
-            prev   = (FAR void *)dup2;
-            buffer = dup2 + 1;
+            len = sizeof(struct spawn_dup2_file_action_s);
             break;
 
           case SPAWN_FILE_ACTION_OPEN:
-            tmp = (FAR struct spawn_open_file_action_s *)entry;
-            open = buffer;
-            memcpy(open, entry, sizeof(struct spawn_open_file_action_s));
-            open->flink = NULL;
-            if (prev)
-              {
-                prev->flink = (FAR void *)open;
-              }
-
-            strcpy(open->path, tmp->path);
-
-            prev   = (FAR void *)open;
-            buffer = (FAR char *)buffer +
-                     ALIGN_UP(SIZEOF_OPEN_FILE_ACTION_S(strlen(tmp->path)),
-                              sizeof(FAR void *));
+            len = sizeof(struct spawn_open_file_action_s);
             break;
 
           default:
-            break;
+            goto errout;
+        }
+
+      if (len > end - buffer)
+        {
+          goto errout;
+        }
+
+      memcpy(buffer, entry, len);
+      if (action == SPAWN_FILE_ACTION_OPEN)
+        {
+          open = (FAR struct spawn_open_file_action_s *)buffer;
+          src  = (FAR struct spawn_open_file_action_s *)entry;
+          len  = strnlen(src->path, end - buffer - len);
+          memcpy(open->path, src->path, len);
+          open->path[len] = '\0';
+          len = ALIGN_UP(SIZEOF_OPEN_FILE_ACTION_S(len), sizeof(FAR void *));
+        }
+
+      ((FAR struct spawn_general_file_action_s *)buffer)->flink  = NULL;
+      ((FAR struct spawn_general_file_action_s *)buffer)->action = action;
+      if (prev)
+        {
+          prev->flink = (FAR struct spawn_general_file_action_s *)buffer;
         }
+
+      prev    = (FAR struct spawn_general_file_action_s *)buffer;
+      buffer += len;
     }
 
   return OK;
+
+errout:
+  kmm_free((FAR void *)*copy);

Review Comment:
   ```suggestion
     kmm_free(*copy);
   ```



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to