Fix use-after-free in sk_repl_idle()'s idle-tick VM resolution (FABRIC-3.md §XIII)
Build / build-amd64-iso (push) Waiting to run
Build / build-aarch64-iso (push) Waiting to run
Build / build-riscv64-img (push) Waiting to run

Root-caused a heap-corruption bug that reliably failed WIREBIND identity
attach on the third attach/detach cycle in one boot. sk_console_readline()
and sk_console_getkey() captured `active_vm` once from their caller and
kept passing that same (possibly long-stale) pointer to sk_repl_idle() on
every idle tick serviced while blocked waiting for input. If the VM it
pointed at was killed (WIREBIND detach) mid-block, the existing bailout
only checked a generic "is anyone attached" boolean -- masked as soon as a
different identity attached next -- so blk_vm_flush_all() kept writing
into a freed VM struct sitting on kmalloc's own free list, corrupting the
free list's linked-list metadata itself.

Both idle branches now re-resolve the live active VM fresh from
g_repl_active_vm on every tick, matching the dispatch-side fix already
made for the sibling bug in §XII.3.

Verified: rebuilt amd64, reran the exact three-cycle repro that reliably
corrupted the heap before the fix -- free-list census stayed stable
through the same idle window that previously collapsed to zero. All three
architectures (amd64/aarch64/riscv64) boot clean to the zuse)ok> prompt.

kmalloc_debug_census()/kmalloc_debug_census_bytes() kept as permanent
diagnostic infrastructure; every other temporary probe added during the
investigation was reverted.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EXieurDfDSsDFdnSyusuWo
This commit is contained in:
Robert Allan James
2026-09-10 20:30:41 -04:00
co-authored by Claude Sonnet 5
parent 70421bdd43
commit 9142dda2d6
38 changed files with 236983 additions and 3 deletions
+17
View File
@@ -66,4 +66,21 @@ kmalloc_stats_t kmalloc_get_stats(void);
uintptr_t kmalloc_heap_base_addr(void);
uintptr_t kmalloc_heap_end_addr(void);
/* Debug/diagnostic probe -- free-list census (largest free block, count of
free blocks, count of allocated blocks, total blocks). Kept as permanent
infrastructure (FABRIC-3.md SXIII, 2026-09-10): a cheap O(n) walk over
the free list, useful for any future heap-shape investigation, not just
the one that introduced it. Not called anywhere in the normal boot path
today -- callers add their own log_message() call sites when debugging. */
void kmalloc_debug_census(size_t *out_largest_free, size_t *out_free_count,
size_t *out_used_count, size_t *out_total_blocks);
/* Same precedent as kmalloc_debug_census() above -- sum of free-block bytes
and used-block bytes across the whole free list. The pairing of the two
(block-count census + byte-sum census) is what let FABRIC-3.md SXIII tell
real heap corruption apart from ordinary fragmentation: fragmentation
grows free_count while total_free_bytes stays flat; corruption drops
both together. */
void kmalloc_debug_census_bytes(size_t *out_total_free_bytes, size_t *out_total_used_bytes);
#endif /* STARKERNEL_KMALLOC_H */