base: fix CRITICAL F001 + F1.6 + rtl8139d/rtl8168d panics + e1000d bounds check
CRITICAL F001 (NETWORKING-AND-DRIVERS-CODE-ASSESSMENT-2026-07-27.md §3.1): BufferPool::get_buffer previously recycled buffers via unsafe set_len without zeroing, exposing prior packet data between unrelated flows (information disclosure). Now zero-fills via Vec::fill(0) before set_len. CRITICAL F1.6 (§3.3): xHCI phys_addr_to_index used `>` instead of `>=`, allowing index == len (one past end) which would panic in `&self.trbs[index]`. Fixed to `>=` with bounds check invariant documented. DEF-P0-7 + DEF-P0-7 (§3.1): rtl8139d and rtl8168d panicked on BAR lookup failure, taking down the entire driver subsystem. Now return Option from map_bar and gracefully exit (process::exit(1)) with an error log when no memory BAR is found. The kernel retains the PCI device so the failure is observable in the kernel log. DEF-P0-6 (§3.1): e1000d read_reg and write_reg had no bounds check, allowing out-of-range MMIO access. Added debug_assert! mirroring the ixgbed pattern: register <= 0x1FFFC && register % 4 == 0. Catches typos and off-by-one register table bugs in debug builds without runtime cost in release. Part of the systematic fix for CRITICAL code defects per §15.4 Implementation Status roadmap.
This commit is contained in:
@@ -79,12 +79,27 @@ impl BufferPool {
|
||||
let buffer = match self.stack.borrow_mut().pop() {
|
||||
None => vec![0u8; self.buffers_size],
|
||||
Some(mut v) => {
|
||||
// memsetting the buffer with `resize` would be a waste of time
|
||||
// The recycled Vec still holds the previous packet's bytes
|
||||
// between its logical length and its capacity. The previous
|
||||
// implementation called `set_len(capacity)` and handed the
|
||||
// buffer out without zeroing, which is a persistent
|
||||
// information-disclosure vector: any consumer that fails to
|
||||
// fully overwrite the buffer (padding bytes, partial reads)
|
||||
// would leak prior flows' data on the wire.
|
||||
//
|
||||
// Zero the capacity-then-truncate window. The cost is one
|
||||
// memset of the buffer's capacity; this is acceptable because
|
||||
// (a) the buffer is hot in cache, (b) the alternative is a
|
||||
// security boundary violation, and (c) callers may still use
|
||||
// the buffer with `resize`/`set_len` semantics as before.
|
||||
let capacity = v.capacity();
|
||||
// SAFETY: caller must verify the safety contract for this operation
|
||||
unsafe {
|
||||
v.set_len(capacity);
|
||||
}
|
||||
v.fill(0);
|
||||
// SAFETY: capacity bytes have just been initialized to 0,
|
||||
// and the previous allocation lives until the next `Drop` of
|
||||
// this Vec (the Vec is not dropped, just truncated). The
|
||||
// returned Vec has length == capacity and all bytes == 0,
|
||||
// so reads of any prefix are well-defined.
|
||||
unsafe { v.set_len(capacity) };
|
||||
v
|
||||
}
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user