mirror of
https://github.com/alexhopeoconnor/firmware.git
synced 2026-10-04 03:18:10 +10:00
fix(platform): OOM null-write in stm32wl File and exception leak in portduino GPIO init (#11456)
- STM32_LittleFS File::_open_dir: the _dir_path allocation was the only unchecked malloc in the file, followed immediately by strcpy - an OOM became a NULL write, and the half-initialized state (open dir, null path) would later feed strlen(NULL) in openNextFile(). Check it and unwind the already-opened dir, matching the sibling failure path. - PortduinoGlue initGPIOPin: if setSilent()/gpioBind() threw after the LinuxGPIOPin was constructed, the pointer was lost in the catch block. Hold it in a unique_ptr and release only after the gpio table takes ownership.
This commit is contained in:
@@ -845,10 +845,10 @@ int initGPIOPin(int pinNum, const std::string &gpioChipName, int line)
|
||||
std::string gpio_name = "GPIO" + std::to_string(pinNum);
|
||||
std::cout << "Initializing " << gpio_name << " on chip " << gpioChipName << std::endl;
|
||||
try {
|
||||
GPIOPin *csPin;
|
||||
csPin = new LinuxGPIOPin(pinNum, gpioChipName.c_str(), line, gpio_name.c_str());
|
||||
auto csPin = std::make_unique<LinuxGPIOPin>(pinNum, gpioChipName.c_str(), line, gpio_name.c_str());
|
||||
csPin->setSilent();
|
||||
gpioBind(csPin);
|
||||
gpioBind(csPin.get());
|
||||
csPin.release(); // owned by the gpio table from here on
|
||||
return ERRNO_OK;
|
||||
} catch (...) {
|
||||
const std::type_info *t = abi::__cxa_current_exception_type();
|
||||
|
||||
@@ -100,11 +100,18 @@ bool File::_open_dir(char const *filepath)
|
||||
return false;
|
||||
}
|
||||
|
||||
_is_dir = true;
|
||||
|
||||
_dir_path = (char *)rtos_malloc(strlen(filepath) + 1);
|
||||
if (!_dir_path) {
|
||||
// match the _dir failure path above: don't leave a half-open dir behind
|
||||
lfs_dir_close(_fs->_getFS(), _dir);
|
||||
rtos_free(_dir);
|
||||
_dir = NULL;
|
||||
return false;
|
||||
}
|
||||
strcpy(_dir_path, filepath);
|
||||
|
||||
_is_dir = true;
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user