Skip to content

hostmot2: fix bounds of the sserial global duplicate check - #4634

Merged
andypugh merged 1 commit into
LinuxCNC:masterfrom
grandixximo:sserial-globals-dup-check
Oct 4, 2026
Merged

andypugh merged 1 commit into
LinuxCNC:masterfrom
grandixximo:sserial-globals-dup-check

Conversation

@grandixximo

Copy link
Copy Markdown
Contributor

The duplicate check in get_globals_list that tells process records apart from globals runs with i <= num_confs, reading one entry past the confs array, and dereferences chan->confs even when a remote has globals but no process records (confs == NULL), crashing the driver load on such a device. Bound the loop to num_confs, which also skips it safely for a globals-only remote.

One of three candidates for @andypugh's hostmot2 SIGSEGV on master (see #4453, #4632). Split out of #4626.

The loop that tells process records apart from globals ran with
i <= num_confs, reading one entry past the confs array, and
dereferenced chan->confs even when the remote has no process records
at all (confs == NULL), crashing the driver load on such a device.
Bound the loop to num_confs, which also skips it safely for a
globals-only remote.
@andypugh
andypugh merged commit 929be84 into LinuxCNC:master Oct 4, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants