fix(platform): OOM null-write in stm32wl File and exception leak in portduino GPIO init (#11456)

- STM32_LittleFS File::_open_dir: the _dir_path allocation was the only
  unchecked malloc in the file, followed immediately by strcpy - an OOM
  became a NULL write, and the half-initialized state (open dir, null
  path) would later feed strlen(NULL) in openNextFile(). Check it and
  unwind the already-opened dir, matching the sibling failure path.

- PortduinoGlue initGPIOPin: if setSilent()/gpioBind() threw after the
  LinuxGPIOPin was constructed, the pointer was lost in the catch
  block. Hold it in a unique_ptr and release only after the gpio table
  takes ownership.
This commit is contained in:
Ben Meadors
2026-08-12 19:13:07 -05:00
committed by GitHub
parent 0739d2a68c
commit 22079ca863
2 changed files with 12 additions and 5 deletions
+3 -3
View File
@@ -845,10 +845,10 @@ int initGPIOPin(int pinNum, const std::string &gpioChipName, int line)
std::string gpio_name = "GPIO" + std::to_string(pinNum);
std::cout << "Initializing " << gpio_name << " on chip " << gpioChipName << std::endl;
try {
GPIOPin *csPin;
csPin = new LinuxGPIOPin(pinNum, gpioChipName.c_str(), line, gpio_name.c_str());
auto csPin = std::make_unique<LinuxGPIOPin>(pinNum, gpioChipName.c_str(), line, gpio_name.c_str());
csPin->setSilent();
gpioBind(csPin);
gpioBind(csPin.get());
csPin.release(); // owned by the gpio table from here on
return ERRNO_OK;
} catch (...) {
const std::type_info *t = abi::__cxa_current_exception_type();
+9 -2
View File
@@ -100,11 +100,18 @@ bool File::_open_dir(char const *filepath)
return false;
}
_is_dir = true;
_dir_path = (char *)rtos_malloc(strlen(filepath) + 1);
if (!_dir_path) {
// match the _dir failure path above: don't leave a half-open dir behind
lfs_dir_close(_fs->_getFS(), _dir);
rtos_free(_dir);
_dir = NULL;
return false;
}
strcpy(_dir_path, filepath);
_is_dir = true;
return true;
}