Fix use-after-free in sk_repl_idle()'s idle-tick VM resolution (FABRIC-3.md §XIII)
Root-caused a heap-corruption bug that reliably failed WIREBIND identity attach on the third attach/detach cycle in one boot. sk_console_readline() and sk_console_getkey() captured `active_vm` once from their caller and kept passing that same (possibly long-stale) pointer to sk_repl_idle() on every idle tick serviced while blocked waiting for input. If the VM it pointed at was killed (WIREBIND detach) mid-block, the existing bailout only checked a generic "is anyone attached" boolean -- masked as soon as a different identity attached next -- so blk_vm_flush_all() kept writing into a freed VM struct sitting on kmalloc's own free list, corrupting the free list's linked-list metadata itself. Both idle branches now re-resolve the live active VM fresh from g_repl_active_vm on every tick, matching the dispatch-side fix already made for the sibling bug in §XII.3. Verified: rebuilt amd64, reran the exact three-cycle repro that reliably corrupted the heap before the fix -- free-list census stayed stable through the same idle window that previously collapsed to zero. All three architectures (amd64/aarch64/riscv64) boot clean to the zuse)ok> prompt. kmalloc_debug_census()/kmalloc_debug_census_bytes() kept as permanent diagnostic infrastructure; every other temporary probe added during the investigation was reverted. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EXieurDfDSsDFdnSyusuWo
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
70421bdd43
commit
9142dda2d6
@@ -66,4 +66,21 @@ kmalloc_stats_t kmalloc_get_stats(void);
|
||||
uintptr_t kmalloc_heap_base_addr(void);
|
||||
uintptr_t kmalloc_heap_end_addr(void);
|
||||
|
||||
/* Debug/diagnostic probe -- free-list census (largest free block, count of
|
||||
free blocks, count of allocated blocks, total blocks). Kept as permanent
|
||||
infrastructure (FABRIC-3.md SXIII, 2026-09-10): a cheap O(n) walk over
|
||||
the free list, useful for any future heap-shape investigation, not just
|
||||
the one that introduced it. Not called anywhere in the normal boot path
|
||||
today -- callers add their own log_message() call sites when debugging. */
|
||||
void kmalloc_debug_census(size_t *out_largest_free, size_t *out_free_count,
|
||||
size_t *out_used_count, size_t *out_total_blocks);
|
||||
|
||||
/* Same precedent as kmalloc_debug_census() above -- sum of free-block bytes
|
||||
and used-block bytes across the whole free list. The pairing of the two
|
||||
(block-count census + byte-sum census) is what let FABRIC-3.md SXIII tell
|
||||
real heap corruption apart from ordinary fragmentation: fragmentation
|
||||
grows free_count while total_free_bytes stays flat; corruption drops
|
||||
both together. */
|
||||
void kmalloc_debug_census_bytes(size_t *out_total_free_bytes, size_t *out_total_used_bytes);
|
||||
|
||||
#endif /* STARKERNEL_KMALLOC_H */
|
||||
|
||||
Reference in New Issue
Block a user