[Bug] pin_api_attach_irq legacy path publishes hdr and args without IRQ protection
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 72/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- c
- Lĩnh vực
- embedded-iot, operating-systems
Hướng nghiên cứu
Bắt đầu trong components/drivers/pin/dev_pin_dm.c và đọc pin_api_attach_irq() cùng với pin_pic_handle_isr(), tập trung vào đường dẫn legacy được sử dụng khi pin_attach_irq không khả dụng. Theo dõi trình tự cập nhật handler và đối số, sau đó xác minh rằng một ngắt không thể quan sát một cặp bị trộn lẫn và cả đường dẫn legacy lẫn hiện đại vẫn hoạt động.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
RT-Thread Version
v5.3.0 (master branch, commit 54e5164064dd7bf2e3f008109d173c36e45f8f69)
Affected area
Device drivers
Hardware/BSP vendor
Not applicable / Other
Architecture
Not applicable / Other
Board and hardware details
This issue affects any board where the GPIO controller does not implement the pin_attach_irq operation, forcing the code to fall back to the legacy ISR handler path.
Develop Toolchain
Other
Describe the bug
In components/drivers/pin/dev_pin_dm.c, when gpio->ops->pin_attach_irq is NULL (legacy fallback path), the function pin_api_attach_irq() writes the handler pair without masking IRQs:
legacy_isr->hdr = hdr;
legacy_isr->args = args;
Meanwhile, pin_pic_handle_isr() reads these fields from ISR context:
if (legacy_isr->hdr)
{
legacy_isr->hdr(legacy_isr->args);
}
Steps to reproduce the behavior
Race condition scenario:
- Application calls
pin_api_attach_irq()to update the pin interrupt handler - The function writes
legacy_isr->hdr = new_handler - Before writing
legacy_isr->args = new_args, a pin interrupt fires pin_pic_handle_isr()executes and callsnew_handler(old_args)with mismatched arguments
This can lead to:
- Incorrect argument being passed to the new handler
- Potential crashes if the new handler expects a different argument type/structure
- Unpredictable behavior
Expected behavior
The handler function pointer and its argument should be updated atomically. Either both should reflect the old values, or both should reflect the new values. No intermediate state should be visible to the ISR.
Other additional context
Affected code path: This bug only applies to the legacy fallback path when the GPIO controller does not implement the pin_attach_irq operation. Modern controllers that provide this operation are not affected.
Root cause: The two stores (hdr and args) are not atomic. On any architecture, an interrupt can occur between them.
Suggested fix: Protect the critical section with IRQ masking:
rt_base_t level = rt_hw_interrupt_disable();
legacy_isr->hdr = hdr;
legacy_isr->args = args;
rt_hw_interrupt_enable(level);
Or use the pin lock with rt_spin_lock_irqsave if appropriate.
Note: The volatile qualifier does not make the pair of stores atomic against interrupts.
- Ngôn ngữ chính
- C
- Star
- 12.3k
- Fork
- 5.5k
- Merge trung bình
- 4 ngày 11 giờ
- Pull request đã merge (30 ngày)
- 33
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của RT-Thread/rt-thread
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
RT-Thread/rt-thread#11818 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
BSP BSP: Loongson bug RT-Smart
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
RT-Thread/rt-thread#11717 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Arch: RISC-V BSP BSP: HPMicro bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
RT-Thread/rt-thread#11687 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
RT-Thread/rt-thread#11472 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug] Heap Buffer Overflow in FinSH `msh_auto_complete_path` via Oversized InputCó thể đã có người làm @Acen28 đã nhận 6 ngày trước. Đang mởArch: ARM/AArch64 BSP BSP: STM32 bug Component component: finsh in progress
RT-Thread/rt-thread#11839 · 3 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của RT-Thread/rt-thread
Issue tương tự
-
feature request
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
BasedHardware/omi#20271 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
ImageMagick/ImageMagick#8994 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area/ysql kind/bug priority/medium
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
yugabyte/yugabyte-db#34552 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
flux-framework/flux-coral2#509 ·