Issue created by Sang Woo Kim: 
https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5668



## Summary

POSIX says `F_DUPFD` returns the lowest available descriptor greater than or 
equal to the third argument, and answers `EINVAL` if that argument is negative 
or not a valid descriptor number. `vfcntl()` in 
`cpukit/libcsupport/src/fcntl.c` never reads the argument — it calls 
`duplicate_iop( iop )`, which takes the next free iop. Measured on `6` and 
`main`, arm/xilinx_zynq_a9_qemu, 64 iops, descriptors 3..14 free:

```
fcntl(s, F_DUPFD, 40)   -> 4     (POSIX: >= 40)
fcntl(s, F_DUPFD, 72)   -> 8     (72 > rtems_libio_number_iops; POSIX: EINVAL)
fcntl(s, F_DUPFD, -1)   -> 9     (POSIX: EINVAL)
```

A caller that uses the argument to move a descriptor out of a range gets one 
inside it, and no error. Descriptors are handed out in free-list order, so the 
result is not the lowest available either.

If #5667 adds `F_DUPFD_CLOEXEC` it takes the same body, so whatever 
`duplicate_iop()` grows to accept serves both.

## Steps to reproduce

```c
int s = open("/dev/console", O_RDWR);
int d = fcntl(s, F_DUPFD, 40);   /* the next free descriptor, not >= 40 */
```

-- 
View it on GitLab: https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5668
You're receiving this email because of your account on gitlab.rtems.org. 
Unsubscribe from this thread: 
https://gitlab.rtems.org/-/sent_notifications/4-8tewdqlwxnpbmj745jpxdo1m5-1d/unsubscribe
 | Manage all notifications: https://gitlab.rtems.org/-/profile/notifications | 
Help: https://gitlab.rtems.org/help


_______________________________________________
bugs mailing list
[email protected]
http://lists.rtems.org/mailman/listinfo/bugs

Reply via email to