3a3af8253e
CRITICAL F001 (NETWORKING-AND-DRIVERS-CODE-ASSESSMENT-2026-07-27.md §3.1): BufferPool::get_buffer previously recycled buffers via unsafe set_len without zeroing, exposing prior packet data between unrelated flows (information disclosure). Now zero-fills via Vec::fill(0) before set_len. CRITICAL F1.6 (§3.3): xHCI phys_addr_to_index used `>` instead of `>=`, allowing index == len (one past end) which would panic in `&self.trbs[index]`. Fixed to `>=` with bounds check invariant documented. DEF-P0-7 + DEF-P0-7 (§3.1): rtl8139d and rtl8168d panicked on BAR lookup failure, taking down the entire driver subsystem. Now return Option from map_bar and gracefully exit (process::exit(1)) with an error log when no memory BAR is found. The kernel retains the PCI device so the failure is observable in the kernel log. DEF-P0-6 (§3.1): e1000d read_reg and write_reg had no bounds check, allowing out-of-range MMIO access. Added debug_assert! mirroring the ixgbed pattern: register <= 0x1FFFC && register % 4 == 0. Catches typos and off-by-one register table bugs in debug builds without runtime cost in release. Part of the systematic fix for CRITICAL code defects per §15.4 Implementation Status roadmap.