Repository navigation
Conversation
Add function to initialize memory table from /proc/self/maps.
Removed commented out documentation for ES BSP memory initialization.
Increased the buffer size for reading lines from /proc/self/maps and updated the error message for clarity.
sylvesterkaczmarek
left a comment
There was a problem hiding this comment.
What should happen when /proc/self/maps contains more than 128 non-mergeable readable/writable ranges? The current code logs a warning and stops parsing, leaving every later valid mapping absent from the PSP table. A normal process with enough DSOs/threads can therefore start rejecting valid addresses based purely on map order. Could this avoid installing a partial map, or use an explicit fallback/error policy when the table capacity is exceeded?
Added overflow handling for memory range parsing and fallback to permissive validation.
|
Hiya @sylvesterkaczmarek thank you for the review, I pushed a fix to prevent installing an incomplete memory map when table capacity is exceeded. If parsing exceeds |
sylvesterkaczmarek
left a comment
There was a problem hiding this comment.
The parser now refuses to install a truncated map: overflow or an empty parse clears the partial table and falls back to the same permissive range used when /proc/self/maps cannot be opened, with a warning. That avoids map-order-dependent false rejections and resolves my concern.
Checklist (Please check before submitting)
(Sent before regarding the older version of the fix in the Checksum repo)
Describe the contribution
Mitigates a root cause of memory related Denial of Service (DoS) vulnerabilities by hardening the
pc-linuxPSP memory validation layer.Previously, the
pc-linuxPSP initialized its memory table with a permissive 0 toSIZE_MAXrange, effectively bypassing all validation and masking potential security risks during development and simulation. This PR replaces that permissive range with a platform native discovery mechanism.Key Changes:
CFE_PSP_InitMemoryTableFromProcMaps(), which parses/proc/self/mapsat startup to identify mapped and accessible memory regions.CFE_PSP_MemValidateRangenow correctly enforces boundaries on Linux, rejecting invalid or unmapped addresses.CFE_PSP_MEM_TABLE_SIZEto 128 to accommodate the fragmented nature of Linux virtual memory maps.Testing performed
pc-linuxPSP to verify total compatibility and correct integration of the new/procdependencies.InitMemoryTableFromProcMapswith console traces to confirm theSysMemoryTableaccurately mirrors the process's real memory map.CFE_PSP_MemValidateRangebehavior by confirming it correctly rejects unmapped addresses (e.g.,0xDEADBEEF) while accepting valid data/stack segments.Expected behavior changes
CFE_PSP_MemValidateRangeon the Linux platform will now correctly return failure (CFE_PSP_INVALID_MEM_ADDR) for non mapped addresses, rather than always returningCFE_PSP_SUCCESS.System(s) tested on
Additional context
Addresses the lack of platform native memory constraints on the
pc-linuxdevelopment platform, providing a security hardened reference for simulation based testing.Fixes:- nasa/cFS#945
Contributor Info