nuttx/sched/group/group_create.c
chao an fdc3c44cc4 sched/group: fix task info heap-use-after-free
tg_info is still in use after task_uninit_info(), unifies
lib_stream_* with life cycle of task info to avoid this issue.

| ==1940861==ERROR: AddressSanitizer: heap-use-after-free on address 0xf47032e0 at pc 0x5676dc4f bp 0xf2f38c68 sp 0xf2f38c58
|
|#10 0xf7abec89 in __asan::__asan_report_load2 (addr=4100993760) at ../../../../src/libsanitizer/asan/asan_rtl.cpp:119
|#11 0x5677356a in nxsem_destroy (sem=0xf47032e0) at semaphore/sem_destroy.c:73
|#12 0x56773695 in sem_destroy (sem=0xf47032e0) at semaphore/sem_destroy.c:120
|#13 0x5676faa2 in nxmutex_destroy (mutex=0xf47032e0) at include/nuttx/mutex.h:126
|#14 0x567a3430 in lib_stream_release (group=0xf4901ba0) at stdio/lib_libstream.c:98
|#15 0x5676da75 in group_release (group=0xf4901ba0) at group/group_leave.c:162
|#16 0x5676e51c in group_leave (tcb=0xf5377740) at group/group_leave.c:360
|#17 0x569fe79b in nxtask_exithook (tcb=0xf5377740, status=0) at task/task_exithook.c:455
|#18 0x569f90b9 in _exit (status=0) at task/exit.c:82
|#19 0x56742680 in exit (status=0) at stdlib/lib_exit.c:61
|#20 0x56a69c78 in iperf_showusage (progname=0xf2f28838 "iperf", exitcode=0) at iperf_main.c:91
|#21 0x56a6a6ec in iperf_main (argc=1, argv=0xf2f28830) at iperf_main.c:140
|#22 0x5679c148 in nxtask_startup (entrypt=0x56a69c78 <iperf_main>, argc=1, argv=0xf2f28830) at sched/task_startup.c:70
|#23 0x56767f58 in nxtask_start () at task/task_start.c:134

Signed-off-by: chao an <anchao@xiaomi.com>
2023-01-11 01:53:59 +08:00

272 lines
7.9 KiB
C

/****************************************************************************
* sched/group/group_create.c
*
* Licensed to the Apache Software Foundation (ASF) under one or more
* contributor license agreements. See the NOTICE file distributed with
* this work for additional information regarding copyright ownership. The
* ASF licenses this file to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance with the
* License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
* WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
* License for the specific language governing permissions and limitations
* under the License.
*
****************************************************************************/
/****************************************************************************
* Included Files
****************************************************************************/
#include <nuttx/config.h>
#include <sched.h>
#include <assert.h>
#include <errno.h>
#include <debug.h>
#include <nuttx/irq.h>
#include <nuttx/fs/fs.h>
#include <nuttx/kmalloc.h>
#include <nuttx/semaphore.h>
#include <nuttx/sched.h>
#include "sched/sched.h"
#include "group/group.h"
#include "tls/tls.h"
/****************************************************************************
* Pre-processor Definitions
****************************************************************************/
/* Is this worth making a configuration option? */
#define GROUP_INITIAL_MEMBERS 4
/****************************************************************************
* Public Data
****************************************************************************/
#if defined(HAVE_GROUP_MEMBERS) || defined(CONFIG_ARCH_ADDRENV)
/* This is the head of a list of all group members */
FAR struct task_group_s *g_grouphead;
#endif
/****************************************************************************
* Private Functions
****************************************************************************/
/****************************************************************************
* Name: group_inherit_identity
*
* Description:
* All inherit the user identity from the parent task group.
*
* Input Parameters:
* group - The new task group.
*
* Returned Value:
* None
*
* Assumptions:
* The parent of the new task is the task at the head of the assigned task
* list for the current CPU.
*
****************************************************************************/
#ifdef CONFIG_SCHED_USER_IDENTITY
static inline void group_inherit_identity(FAR struct task_group_s *group)
{
FAR struct tcb_s *rtcb = this_task();
FAR struct task_group_s *rgroup = rtcb->group;
/* Inherit the user identity from the parent task group. */
DEBUGASSERT(group != NULL);
group->tg_uid = rgroup->tg_uid;
group->tg_gid = rgroup->tg_gid;
}
#else
# define group_inherit_identity(group)
#endif
/****************************************************************************
* Public Functions
****************************************************************************/
/****************************************************************************
* Name: group_allocate
*
* Description:
* Create and a new task group structure for the specified TCB. This
* function is called as part of the task creation sequence. The structure
* allocated and zeroed, but otherwise uninitialized. The full creation
* of the group of a two step process: (1) First, this function allocates
* group structure early in the task creation sequence in order to provide
* a group container, then (2) group_initialize() is called to set up the
* group membership.
*
* Input Parameters:
* tcb - The tcb in need of the task group.
* ttype - Type of the thread that is the parent of the group
*
* Returned Value:
* 0 (OK) on success; a negated errno value on failure.
*
* Assumptions:
* Called during task creation in a safe context. No special precautions
* are required here.
*
****************************************************************************/
int group_allocate(FAR struct task_tcb_s *tcb, uint8_t ttype)
{
FAR struct task_group_s *group;
int ret = -ENOMEM;
DEBUGASSERT(tcb && !tcb->cmn.group);
/* Allocate the group structure and assign it to the TCB */
group = (FAR struct task_group_s *)kmm_zalloc(sizeof(struct task_group_s));
if (!group)
{
return -ENOMEM;
}
#if defined(CONFIG_MM_KERNEL_HEAP)
/* If this group is being created for a privileged thread, then all
* elements of the group must be created for privileged access.
*/
if ((ttype & TCB_FLAG_TTYPE_MASK) == TCB_FLAG_TTYPE_KERNEL)
{
group->tg_flags |= GROUP_FLAG_PRIVILEGED;
}
#endif /* defined(CONFIG_MM_KERNEL_HEAP) */
#ifdef HAVE_GROUP_MEMBERS
/* Allocate space to hold GROUP_INITIAL_MEMBERS members of the group */
group->tg_members = kmm_malloc(GROUP_INITIAL_MEMBERS * sizeof(pid_t));
if (!group->tg_members)
{
goto errout_with_group;
}
/* Number of members in allocation */
group->tg_mxmembers = GROUP_INITIAL_MEMBERS;
#endif
/* Attach the group to the TCB */
tcb->cmn.group = group;
/* Inherit the user identity from the parent task group */
group_inherit_identity(group);
/* Initialize file descriptors for the TCB */
files_initlist(&group->tg_filelist);
/* Alloc task info for group */
ret = task_init_info(group);
if (ret < 0)
{
goto errout_with_member;
}
#ifndef CONFIG_DISABLE_PTHREAD
/* Initialize the pthread join mutex */
nxmutex_init(&group->tg_joinlock);
#endif
#if defined(CONFIG_SCHED_WAITPID) && !defined(CONFIG_SCHED_HAVE_PARENT)
/* Initialize the exit/wait semaphores */
nxsem_init(&group->tg_exitsem, 0, 0);
#endif
return OK;
errout_with_member:
#ifdef HAVE_GROUP_MEMBERS
kmm_free(group->tg_members);
errout_with_group:
#endif
kmm_free(group);
return ret;
}
/****************************************************************************
* Name: group_initialize
*
* Description:
* Add the task as the initial member of the group. The full creation of
* the group of a two step process: (1) First, this group structure is
* allocated by group_allocate() early in the task creation sequence, then
* (2) this function is called to set up the initial group membership.
*
* Input Parameters:
* tcb - The tcb in need of the task group.
*
* Returned Value:
* None.
*
* Assumptions:
* Called during task creation in a safe context. No special precautions
* are required here.
*
****************************************************************************/
void group_initialize(FAR struct task_tcb_s *tcb)
{
FAR struct task_group_s *group;
#if defined(HAVE_GROUP_MEMBERS) || defined(CONFIG_ARCH_ADDRENV)
irqstate_t flags;
#endif
DEBUGASSERT(tcb && tcb->cmn.group);
group = tcb->cmn.group;
/* Allocate mm_map list if required */
mm_map_initialize(&group->tg_mm_map);
#ifdef HAVE_GROUP_MEMBERS
/* Assign the PID of this new task as a member of the group. */
group->tg_members[0] = tcb->cmn.pid;
#endif
/* Save the ID of the main task within the group of threads. This needed
* for things like SIGCHLD. It ID is also saved in the TCB of the main
* task but is also retained in the group which may persist after the main
* task has exited.
*/
group->tg_pid = tcb->cmn.pid;
/* Mark that there is one member in the group, the main task */
group->tg_nmembers = 1;
#if defined(HAVE_GROUP_MEMBERS) || defined(CONFIG_ARCH_ADDRENV)
/* Add the initialized entry to the list of groups */
flags = enter_critical_section();
group->flink = g_grouphead;
g_grouphead = group;
leave_critical_section(flags);
#endif
}