Commit a17db1c
committed
MSVC-MingW: bounds-check interrupt number in FromWindowsThread path
Defect: vPortGenerateSimulatedInterruptFromWindowsThread() in the MSVC-MingW
simulator port performs a shift by a caller-supplied interrupt number without
range checking it, giving undefined behavior for out-of-range values.
Root cause: the function pends an interrupt via ( 1UL << ulInterruptNumber )
into ulPendingInterrupts, but does not verify ulInterruptNumber is within the
width of that variable. A value greater than or equal to portMAX_INTERRUPTS
makes the shift undefined. The task-context sibling
vPortGenerateSimulatedInterrupt() already performs this bounds check.
Fix: gate the operation on ( ulInterruptNumber < portMAX_INTERRUPTS ) in
addition to the existing xPortRunning check, mirroring the task-context sibling
so both entry points are consistent.
A host regression test kept outside this repository demonstrates the fault
before the change and its absence afterwards (red then green).1 parent e0b77d6 commit a17db1c
1 file changed
Lines changed: 5 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
637 | 637 | | |
638 | 638 | | |
639 | 639 | | |
640 | | - | |
| 640 | + | |
| 641 | + | |
| 642 | + | |
| 643 | + | |
| 644 | + | |
641 | 645 | | |
642 | 646 | | |
643 | 647 | | |
| |||
0 commit comments