Files
RedBear-OS/drivers/net/rtl8168d
Red Bear OS 3a3af8253e base: fix CRITICAL F001 + F1.6 + rtl8139d/rtl8168d panics + e1000d bounds check
CRITICAL F001 (NETWORKING-AND-DRIVERS-CODE-ASSESSMENT-2026-07-27.md §3.1):
BufferPool::get_buffer previously recycled buffers via unsafe set_len
without zeroing, exposing prior packet data between unrelated flows
(information disclosure). Now zero-fills via Vec::fill(0) before set_len.

CRITICAL F1.6 (§3.3): xHCI phys_addr_to_index used `>` instead of
`>=`, allowing index == len (one past end) which would panic in
`&self.trbs[index]`. Fixed to `>=` with bounds check invariant documented.

DEF-P0-7 + DEF-P0-7 (§3.1): rtl8139d and rtl8168d panicked on BAR lookup
failure, taking down the entire driver subsystem. Now return Option
from map_bar and gracefully exit (process::exit(1)) with an error log
when no memory BAR is found. The kernel retains the PCI device so the
failure is observable in the kernel log.

DEF-P0-6 (§3.1): e1000d read_reg and write_reg had no bounds check,
allowing out-of-range MMIO access. Added debug_assert! mirroring the
ixgbed pattern: register <= 0x1FFFC && register % 4 == 0. Catches
typos and off-by-one register table bugs in debug builds without
runtime cost in release.

Part of the systematic fix for CRITICAL code defects per §15.4
Implementation Status roadmap.
2026-07-27 15:29:59 +09:00
..