已合并
osMemoryPoolNew中 uint32_t 乘法溢出导致校验使用截断小值,触发内核堆越界写入。 #1149
yang-pangyuan创建于 6月23日
osMemoryPoolNew中 uint32_t 乘法溢出导致校验使用截断小值,触发内核堆越界写入。 #1149
已合并
yang-pangyuan创建于 6月23日
yang-pangyuan成员
6月23日

相关的Issue

https://gitcode.com/openharmony/kernel_liteos_m/issues/976

原因(目的、解决的问题等)

osMemoryPoolNew中 uint32_t 乘法溢出导致校验使用截断小值,触发内核堆越界写入。

描述(做了什么,变更了什么)

增加乘法溢出校验

测试用例(新增、改动、可能影响的功能)

是否涉及对外变更(典型的如:对外API规格变更、新增对外接口等等)

否,不涉及对外变更

是否需要同步至release(如:3.0LTS ... )分支?

likedislike
Pull Request已成功合入, 合并人@openharmony_ci
(感谢 yang-pangyuan 的贡献)
Yyang-pangyuan成员
6月23日 关联了issue:vul-1069454204063453184
openharmony_ciopenharmony_ci成员
6月23日 添加了label:waiting_on_author
openharmony_ci
openharmony_ci成员
6月23日 评论:

感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接


Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.

likedislike
openharmony_ciopenharmony_ci成员
6月23日 添加了label:dco检查成功
yang-pangyuan成员
6月23日 评论:

start build

likedislike
openharmony_ci
openharmony_ci成员
6月23日 评论:

首次触发
门禁构建开始,包含静态检查、代码编译【Emulator_5.1.0-Release编译】,预计在60分钟内完成,门禁结果会同步发送到注册邮箱。您可以通过如下链接跟踪门禁进展:http://dcp.openharmony.cn/workbench/cicd/detail/6a39f71164650f998b90a14b/runlist

likedislike
openharmony_ciopenharmony_ci成员
6月23日 添加了label:编译成功
openharmony_ciopenharmony_ci成员
6月23日 添加了label:静态检查成功
openharmony_ciopenharmony_ci成员
6月23日 通过测试
openharmony_ci
openharmony_ci成员
6月23日 评论:

代码门禁通过
您可以通过如下链接查看门禁报告:http://dcp.openharmony.cn/workbench/cicd/detail/6a39f71164650f998b90a14b/runlist

静态检查:

# check type result report
1 codeCheck pass >>>

编译测试:
# Device build result package
1 Emulator_5.1.0-Release success >>>

likedislike
openharmony_ciopenharmony_ci成员
6月23日 删除了label:waiting_on_author
openharmony_ciopenharmony_ci成员
6月23日 添加了label:waiting_for_review
openharmony_ci
openharmony_ci成员
6月23日 评论:

您好,Committer @JerryH1011 @LeonChan525 @zhu-sheng-le ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。


Hello, Committer @JerryH1011 @LeonChan525 @zhu-sheng-le . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.

likedislike
Zzhu-sheng-le成员
6月25日 通过审查
openharmony_ci
openharmony_ci成员
6月25日 评论:

验证结果已超过12小时,之前验证结果无效,自动重新触发构建,请关注最新验证结果

likedislike
openharmony_ci
openharmony_ci成员
6月25日 评论:

start build

likedislike
openharmony_ciopenharmony_ci成员
6月25日 删除了label:编译成功
openharmony_ciopenharmony_ci成员
6月25日 删除了label:静态检查成功
openharmony_ci
openharmony_ci成员
6月25日 评论:

上次构建已超过12小时,重新全量验证,重置所有关联PR的验证状态
门禁构建开始,包含静态检查、代码编译【Emulator_5.1.0-Release编译】,预计在60分钟内完成,门禁结果会同步发送到注册邮箱。您可以通过如下链接跟踪门禁进展:http://dcp.openharmony.cn/workbench/cicd/detail/None/runlist

likedislike
openharmony_ciopenharmony_ci成员
6月25日 添加了label:静态检查失败
openharmony_ci
openharmony_ci成员
6月25日 评论:

代码门禁未通过
您可以通过如下链接查看门禁报告:http://dcp.openharmony.cn/workbench/cicd/detail/6a3c81bf64650f998b8ca61b/runlist

静态检查:

# check type result report
1 codeCheck code check time out >>>

编译测试:
# Device build result package
1 Emulator_5.1.0-Release pending NA

likedislike
openharmony_ciopenharmony_ci成员
6月25日 删除了label:waiting_for_review
openharmony_ciopenharmony_ci成员
6月25日 添加了label:waiting_on_author
openharmony_dcp
openharmony_dcp成员
7月21日 评论:

您好, @yang-pangyuan 该PR需要您响应,已过去25天未响应,请根据检视意见进行修改,如5天内未响应检视意见,此PR会被自动关闭。关闭后的PR,如有需要,您可以自行打开该PR。

likedislike
yang-pangyuan成员
7月23日 评论:

start build

likedislike
openharmony_ciopenharmony_ci成员
7月23日 删除了label:静态检查失败
openharmony_ci
openharmony_ci成员
7月23日 评论:

上次构建已超过12小时,重新全量验证,重置所有关联PR的验证状态
门禁构建开始,包含静态检查,预计在60分钟内完成,门禁结果会同步发送到注册邮箱。您可以通过如下链接跟踪门禁进展:http://dcp.openharmony.cn/workbench/cicd/detail/6a61804064650f998b1f0fb0/runlist

likedislike
openharmony_ciopenharmony_ci成员
7月23日 添加了label:静态检查成功
openharmony_ciopenharmony_ci成员
7月23日 通过测试
openharmony_ci
openharmony_ci成员
7月23日 评论:

代码门禁通过
您可以通过如下链接查看门禁报告:http://dcp.openharmony.cn/workbench/cicd/detail/6a61804064650f998b1f0fb0/runlist

静态检查:

# check type result report
1 codeCheck pass >>>

likedislike
openharmony_ciopenharmony_ci成员
7月23日 删除了label:waiting_on_author
openharmony_ciopenharmony_ci成员
7月23日 添加了label:waiting_for_review
openharmony_ci
openharmony_ci成员
7月23日 评论:

您好,Committer @JerryH1011 @LeonChan525 @zhu-sheng-le ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。


Hello, Committer @JerryH1011 @LeonChan525 @zhu-sheng-le . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.

likedislike
openharmony_ciopenharmony_ci成员
7月23日 合入了pull request,合并节点 SHA:c17be50e4a77c7997ca49ff6b9b8687d6c79667d
openharmony_ciopenharmony_ci成员
7月23日 删除了label:waiting_for_review
openharmony_ciopenharmony_ci成员
7月23日 添加了label:merged