base: fix CRITICAL F001 + F1.6 + rtl8139d/rtl8168d panics + e1000d bounds check

CRITICAL F001 (NETWORKING-AND-DRIVERS-CODE-ASSESSMENT-2026-07-27.md §3.1):
BufferPool::get_buffer previously recycled buffers via unsafe set_len
without zeroing, exposing prior packet data between unrelated flows
(information disclosure). Now zero-fills via Vec::fill(0) before set_len.

CRITICAL F1.6 (§3.3): xHCI phys_addr_to_index used `>` instead of
`>=`, allowing index == len (one past end) which would panic in
`&self.trbs[index]`. Fixed to `>=` with bounds check invariant documented.

DEF-P0-7 + DEF-P0-7 (§3.1): rtl8139d and rtl8168d panicked on BAR lookup
failure, taking down the entire driver subsystem. Now return Option
from map_bar and gracefully exit (process::exit(1)) with an error log
when no memory BAR is found. The kernel retains the PCI device so the
failure is observable in the kernel log.

DEF-P0-6 (§3.1): e1000d read_reg and write_reg had no bounds check,
allowing out-of-range MMIO access. Added debug_assert! mirroring the
ixgbed pattern: register <= 0x1FFFC && register % 4 == 0. Catches
typos and off-by-one register table bugs in debug builds without
runtime cost in release.

Part of the systematic fix for CRITICAL code defects per §15.4
Implementation Status roadmap.
This commit is contained in:
Red Bear OS
2026-07-27 15:29:59 +09:00
parent a4a7d1a87c
commit 3a3af8253e
5 changed files with 66 additions and 14 deletions
+20 -5
View File
@@ -79,12 +79,27 @@ impl BufferPool {
let buffer = match self.stack.borrow_mut().pop() {
None => vec![0u8; self.buffers_size],
Some(mut v) => {
// memsetting the buffer with `resize` would be a waste of time
// The recycled Vec still holds the previous packet's bytes
// between its logical length and its capacity. The previous
// implementation called `set_len(capacity)` and handed the
// buffer out without zeroing, which is a persistent
// information-disclosure vector: any consumer that fails to
// fully overwrite the buffer (padding bytes, partial reads)
// would leak prior flows' data on the wire.
//
// Zero the capacity-then-truncate window. The cost is one
// memset of the buffer's capacity; this is acceptable because
// (a) the buffer is hot in cache, (b) the alternative is a
// security boundary violation, and (c) callers may still use
// the buffer with `resize`/`set_len` semantics as before.
let capacity = v.capacity();
// SAFETY: caller must verify the safety contract for this operation
unsafe {
v.set_len(capacity);
}
v.fill(0);
// SAFETY: capacity bytes have just been initialized to 0,
// and the previous allocation lives until the next `Drop` of
// this Vec (the Vec is not dropped, just truncated). The
// returned Vec has length == capacity and all bytes == 0,
// so reads of any prefix are well-defined.
unsafe { v.set_len(capacity) };
v
}
};