Skip to content

Commit a17db1c

Browse files
MSVC-MingW: bounds-check interrupt number in FromWindowsThread path
Defect: vPortGenerateSimulatedInterruptFromWindowsThread() in the MSVC-MingW simulator port performs a shift by a caller-supplied interrupt number without range checking it, giving undefined behavior for out-of-range values. Root cause: the function pends an interrupt via ( 1UL << ulInterruptNumber ) into ulPendingInterrupts, but does not verify ulInterruptNumber is within the width of that variable. A value greater than or equal to portMAX_INTERRUPTS makes the shift undefined. The task-context sibling vPortGenerateSimulatedInterrupt() already performs this bounds check. Fix: gate the operation on ( ulInterruptNumber < portMAX_INTERRUPTS ) in addition to the existing xPortRunning check, mirroring the task-context sibling so both entry points are consistent. A host regression test kept outside this repository demonstrates the fault before the change and its absence afterwards (red then green).
1 parent e0b77d6 commit a17db1c

1 file changed

Lines changed: 5 additions & 1 deletion

File tree

portable/MSVC-MingW/port.c

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -637,7 +637,11 @@ void vPortGenerateSimulatedInterrupt( uint32_t ulInterruptNumber )
637637

638638
void vPortGenerateSimulatedInterruptFromWindowsThread( uint32_t ulInterruptNumber )
639639
{
640-
if( xPortRunning == pdTRUE )
640+
/* Reject out-of-range interrupt numbers before the shift below. Mirrors the
641+
* bounds check the task-context sibling vPortGenerateSimulatedInterrupt already
642+
* performs: ( 1UL << ulInterruptNumber ) is undefined when ulInterruptNumber is
643+
* >= portMAX_INTERRUPTS (the width of ulPendingInterrupts). */
644+
if( ( xPortRunning == pdTRUE ) && ( ulInterruptNumber < portMAX_INTERRUPTS ) )
641645
{
642646
/* Can't proceed if in a critical section as pvInterruptEventMutex won't
643647
* be available. */

0 commit comments

Comments
 (0)