jerpelea opened a new pull request, #20246:
URL: https://github.com/apache/nuttx/pull/20246

   ## Summary
   
   fdlist_extend() grows a task group's descriptor table to 'row' rows of 
CONFIG_NFILE_DESCRIPTORS_PER_BLOCK entries each, and guards the growth against 
OPEN_MAX:
   
     if (CONFIG_NFILE_DESCRIPTORS_PER_BLOCK * (orig_rows + 1) > OPEN_MAX)
   
   The check sizes the table at orig_rows + 1, which assumes the caller only 
ever grows by a single block.  The function then allocates 'row' rows, so the 
two agree only for growth by one.
   
   Callers do skip ahead.  fdlist_dup3() asks for
   fd2 / CONFIG_NFILE_DESCRIPTORS_PER_BLOCK + 1, fdlist_dupfile() for the row 
holding minfd, and fdlist_copy() for the row holding a parent descriptor it is 
duplicating.  Any of those can request a row well past orig_rows + 1.
   
   Such a request passes the check and the function then allocates and installs 
a table with more than OPEN_MAX descriptors.  With the defaults (8 per block, 
OPEN_MAX 256) a process holding one row that calls dup2(fd, 400) ends up with 
51 rows, or 408 descriptor slots, against a 256 limit.
   
   Check the row actually being requested.  For single-block growth row == 
orig_rows + 1 and the comparison is unchanged.
   
   ## Impact
   
   RELEASE
   
   ## Testing
   
   CI


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to