jerpelea opened a new pull request, #19650: URL: https://github.com/apache/nuttx/pull/19650
## Summary A task does not necessarily own an address environment. tcb->addrenv_own is set only by addrenv_attach(), which is reached only from addrenv_allocate(); a kernel thread never allocates one, and in a protected build nothing does -- there is a single address space for the whole system and the architecture's up_addrenv_*() are stubs. addrenv_own is then NULL for every task, always. That a task may have no address environment is already an expected state. addrenv_switch() returns OK when tcb->addrenv_curr is NULL and addrenv_drop() returns early, and every caller of addrenv_select() checks addrenv_own != NULL before calling in: nxsched_get_stateinfo(), nxtask_argvstr(), proc_groupenv() and the arm, arm64, risc-v and tricore up_check_tcbstack(). addrenv_take() and addrenv_give() are the only two that dereference unconditionally. addrenv_join() calls addrenv_take(ptcb->addrenv_own) without a check, so pthread_create() faults on &((struct addrenv_s *)NULL)->refs whenever the calling task has no address environment. With CONFIG_DEBUG_ASSERTIONS off the same access silently corrupts low memory instead. Handle NULL in both, the way the rest of the file already does. addrenv_give() returns a non-zero count for the NULL case so that callers never conclude an absent address environment has become unreferenced and should be destroyed. ## Impact RELEASE ## Testing CI -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
