{bp-19770} fs/romfs: fix node cache overflow in directories with >256 entries - #19806
Open
jerpelea wants to merge 1 commit into
Open
{bp-19770} fs/romfs: fix node cache overflow in directories with >256 entries#19806jerpelea wants to merge 1 commit into
jerpelea wants to merge 1 commit into
Conversation
romfs_cachenode() tracked the allocated size of rn_child in a uint8_t while rn_count is a uint16_t. Past 256 entries the size wraps to zero, the grow condition rn_count == num - 1 can never be true again and the array is not reallocated: entries are written beyond the allocation, corrupting the heap. Track the allocated size in a size_t. Signed-off-by: raiden00pl <raiden00@railab.me> Assisted-by: Claude Code
jerpelea
requested review from
acassis,
cederom,
linguini1 and
xiaoxiang781216
August 12, 2026 10:46
acassis
approved these changes
Aug 12, 2026
Contributor
|
the change run out of flash, @jerpelea |
xiaoxiang781216
approved these changes
Aug 12, 2026
Contributor
Author
|
please restart CI after #19814 is merged |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
romfs_cachenode() tracked the allocated size of rn_child in a uint8_t while rn_count is a uint16_t. Past 256 entries the size wraps to zero, the grow condition rn_count == num - 1 can never be true again and the array is not reallocated: entries are written beyond the allocation, corrupting the heap.
Track the allocated size in a size_t.
Impact
RELEASE
Testing
CI